tribut

joined 3 years ago
[–] tribut@infosec.pub 0 points 6 days ago (5 children)

Cleatext signing (having the signature and data in the same file) is broken in many ways. It is possible to put unsigned data at the top of the file in a way that sha256sum will use it. Watch the 39c3 GPG talk if your interested in the gory details.

The solution is to use detached signatures (checksum.txt and checksum.txt.gpg to verify that). This makes sure that all of checksum.txt is actually covered by the signature.

[–] tribut@infosec.pub 40 points 4 weeks ago (1 children)

That is, by far, one of the saddest pieces of text I have read in a while.

[–] tribut@infosec.pub 2 points 1 month ago

Theres good reason to dislike cloud gaming in general, but the geforce flatpak is actually solid. Trivial to install, just works.

[–] tribut@infosec.pub 0 points 2 months ago

Except it does not actually appear on CISA's KEV list?

https://www.cisa.gov/known-exploited-vulnerabilities-catalog

[–] tribut@infosec.pub 3 points 3 months ago (1 children)

That's a different project...

[–] tribut@infosec.pub 0 points 4 months ago* (last edited 4 months ago)

This has nothing to do with meshcore as a protocol, the problem is that some HA addons don't treat untrusted input properly. The malicious name could have been transmitted via meshtastic or carrier pigeon, if another addon did the same dumb thing.

[–] tribut@infosec.pub 9 points 4 months ago

You see, our orphan crushing machine is ✨ made in europe ✨

[–] tribut@infosec.pub 3 points 6 months ago

No. Just like systemd.

[–] tribut@infosec.pub 4 points 6 months ago

Booking.com (at least in Germany) only useagic links for some time now. I hate it.

[–] tribut@infosec.pub 8 points 7 months ago (1 children)

I really appreciate your marketing. You're good at this.

[–] tribut@infosec.pub 14 points 7 months ago

No, sir. That's an inline table, sir. That is clearly totally different, sir!

view more: next ›