(safe) Unsecure security

172 readers
1 users here now

(un) Security - Who will guard the guards?

founded 3 years ago
MODERATORS
126
 
 

Heh, who will guard the guards?

127
 
 

Beating the dead horse?

128
129
 
 

LOL.

Nothing is safe.

130
 
 

Nothing is secure.

131
 
 

TruthFinder and Instant Checkmate are subscription-based services allowing customers to perform background checks on other people. When conducting background checks, the sites will use publicly scraped data, federal, state, and court records, criminal records, social media, and other sources.

132
 
 

In 2016, DARPA ran a similarly styled event for artificial intelligence (AI). One hundred teams entered their systems into the Cyber Grand Challenge. After completing qualifying rounds, seven finalists competed at the DEFCON hacker convention in Las Vegas. The competition occurred in a specially designed test environment filled with custom software that had never been analyzed or tested. The AIs were given 10 hours to find vulnerabilities to exploit against the other AIs in the competition and to patch themselves against exploitation. A system called Mayhem, created by a team of Carnegie-Mellon computer security researchers, won. The researchers have since commercialized the technology, which is now busily defending networks for customers like the U.S. Department of Defense.

There was a traditional human–team capture-the-flag event at DEFCON that same year. Mayhem was invited to participate. It came in last overall, but it didn’t come in last in every category all of the time.

133
 
 

Tracked as CVE-2023-22501, the vulnerability has a critical severity score of 9.4, as calculated by Atlassian. It could be used to target bot accounts in particular, due to their frequent interactions with other users and their increased likelihood to be included in Jira issues or requests or receiving emails with a "View Request" link - either condition being necessary for acquiring signup tokens.

134
 
 

All this data somewhere in the wrong hands (I mean - ODIN intelligence) "lost"

135
 
 

Check your 2FA implementations

136
 
 

Some useful information on hw security keys

137
 
 

Check the comments as well

138
 
 

Bad luck, but good report.

139
 
 

“It was disturbing that they didn’t even try to protect the data,” Mr. Marx said, referring to the U.S. military. “They didn’t care about the risk, or they ignored the risk.”

140
141
 
 

hello password managers :)

142
1
ZDI-22-1690 (www.zerodayinitiative.com)
submitted 2 years ago by [email protected] to c/[email protected]
 
 

10 out of 10. Christmas is coming early this year.

143
 
 

Should open source it already ;)

144
 
 

IMHO this will be more and more frequent in the future.

145
 
 

Interesting..

146
 
 

A helpful reminder, thanks.

147
148
149
 
 

nice catch