Solarwinds is still dealing with the reputation damage and fallout today from that breach. People don’t forget about this stuff. the lawsuits will likely be hitting crowdstrike for years to come
HN user
rtev
About to be acquired by Google for $23 billion as well!
It’s supposedly only accessible to LocalSystem. If they were to encrypt it, it could just be decrypted anyway. Still, it’s a huge liability and a major blunder by Microsoft.
Sam is a very famous security researcher, so I would be shocked if he wasn’t making upwards of $350,000 a year. These articles he writes make him a significant amount of money via reputation boost.
This appears to be what happens when rich people that don’t need houses buy them anyway as investments. There should be laws preventing a person from owning more than three houses in the United States.
Yahoo returns thousands of results for dorking queries where Kagi and Google return an identical list of 5-6 results. Pretty disappointing for me as a paying customer to learn that Kagi is basically a Google wrapper
Anyone know why this is happening?
error: subprocess-exited-with-error python3 setup.py egg_info did not run successfully.
A vendor pays to have their software included in this competition, where many of the world’s best offensive security pros compete.
Looks like the “hack” on Twitter was just a botched rollout as suspected?
Weeks after defcon, I saw they had a job listing asking for someone with Bluetooth experience and experience preventing denial of service attacks. Sounds like they finally hired someone that knew what was going on here.
Lucidrains also created the much-missed EpicMafia, which still doesn’t have a good replacement after shutting down. Exceptionally skilled person!
This is the most sus thing I’ve read in a long time
i don’t feel that this is true in the slightest.
so many critical exploits use the same characters and lengths as intended inputs. Also, if firewalls were a replacement for secure code, no one would be talking about memory safety.
I don’t think it is.
Microsoft has a track record for delaying fixes and marking important issues as “not a bug”, so I’m less impressed with their security.
As terrible a corporation as Oracle is, their security response team has been one of the most effective and fast-paced I’ve ever reported to. With that said, they pay nothing to researchers, so Gitlab certainly shows they care more about security.
The reason you see so many critical Gitlab security fixes is because they take security so seriously.
They pay huge bounties for security vulnerabilities in their products, so they get the best researchers responsibly disclosing bugs.
Typescript applications suffer from many of these vulnerabilities. JS apps have a specific class of critical vulnerabilities as well, prototype pollution. If I had to write a web application with security in mind, I personally would pick Python. It’s possible to make mistakes in any language though, and the environment an app is deployed in can independently introduce many vulnerabilities.
It’s very weird that out of 95 comments in this thread (at the time of writing), practically half of them are one person.
LastPark has child predators under the bridge that the park officials haven’t noticed yet
I should have added “/s”
This is all just a scam run by Big Cow to get some tasty Asian flavors in the trough.
While I generally agree with this, it totally misses the mark by leaving out Chrome. As long as Chrome dominates the web, Google stays on top
I have yet to hear a convincing threat model for this actually representing a vulnerability. I don’t think there is one.
Tavis Ormandy is one of the leading security experts in the world. Here’s a blog post that highlights a number of the risks related to password manager extensions: https://lock.cmpxchg8b.com/passmgrs.html
Taking it down doesn’t make flight tracking infeasible, just moderately less accessible. Any sufficiently motivated attacker is going to be able to get the information without a problem. Isn’t it better to have the information more public to increase awareness?
I’ve also really enjoyed seeing how much negativity these peoples’ wasteful habits receive. That’s just me personally though.
Much of the risk associated with password managers is only applicable when using the browser extensions. I know it’s a minor inconvenience, but I would advise sticking with the lack of extension.
Very cool, thank you for sharing! Not only does ROP facilitate traditional binary exploitation, but it’s also used in cutting-edge evasive techniques. By abusing ROP instead of direct calls, red teamers are able to heavily obfuscate activities from endpoint detection and response.
Sounds like you’ve landed on the wrong path of the last of Erikson’s stages.
Did you read the article?
Reading quickly with deep comprehension is a superpower. Arts and culture of reading aside, kids that don’t read much limit themselves in the pace they can learn and advance.
This is awesome.