Tag: security
-
Halifax Leaked My Financial Information... (Again)
For the second time in two years, Halifax wrote to me about my credit card... but sent the letter to entirely the wrong person, leaking my personal financial information.
-
That time I got locked-in at the V&A
I just realised that I never shared this anecdote online before -
One time, I got locked-in at the V&A Museum after closing-time. I'd been there for a museums & cultural institutions event and I'd probably had a few too many glasses of champagne before I excused myself to return to my hotel. Unfortunately in my โฆ -
Exploiting Fail2ban "portscan" permablocks over HTTP for denial-of-service
On a forum they and I share, Loebas suggested that I should be careful doing portscans in case I hit e.g. fail2ban rules. I counter that such rulesets would be a terrible idea (and are therefore uncommon), and provide a specific demonstration of how an attacker can turn them against the site's legitimate users!
-
Chrome again exempts Google from user site data settings
Jeff Johnson observes that Google Chrome has AGAIN started ignoring user privacy settings specifically for .google.com domains. This leads me to ask, not for the first time, why are there still so many people using Chrome as their daily driver, when there are so many perfectly-good alternatives that don't feed the beast in the same way?
-
Your 'App' Could Have Been a Webpage (so I fixed it for you...)
I was asked to install a mobile app to get access to the itinerary of a trip to Disneyland I'm taking with the kids. Fuck that noise: couldn't it have just been a Web page? An hour of reverse-engineering later, it is, and it's superior in virtually every way to the "app" that it replaces.
-
Exploiting Thoughtcrime in LLMs
New malware variants seem to include source code comments about how to build WMDs, presumably in an effort to hamper analysis by AI-based tools. I find myself wondering if the same technique can be used by authors to "protect" their work, too...
-
Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked
Meta decided to replace a lot of their tech support with a chatbot. Which meant giving that chatbot the power to manipulate data. Which meant, to the surprise of nobody whatsoever, that hackers tricked the chatbot into giving them access to other people's accounts.
-
NHS England rushes to hide software over AI hacking fears
New Scientist reports that the NHS are closed-sourcing a lot of their code, out of fear that AIs like Mythos will facilitate easier exploitation of their systems if they don't. Which is pretty-much... completely backwards thinking.
-
Why Security Engineering needs a Hacker Mentality
Security engineering is about a lot of things, but the best security engineers show the 'hacker mindset' characteristics of curiosity and imagination. Here's an example of how I found an XSS vulnerability in a forum, mostly by accident, and how curiosity was the key.
-
Run your own WireGuard VPN
I stopped paying for VPN services a decade ago and I haven't looked back. When I 'need' a VPN service, I just spin one up on cheap VM services, and then I throw it away when I'm done. It's cheaper and more-customisable... and if the UK goes ahead with an idea to age-gate VPN services, it might soon become more-convenient too.
-
How an RM Nimbus Taught Me a Hacker Mentality
Thirty to thirty-five years ago, as a young and curious hacker, I broke out of the restrictions on my secondary school's computer lab and briefly achieved rockstar popularity amongst peers who, through my tools, could now play videogames instead of doing their coursework. But their interest in the results of my exploits were incompatible with my interest in the sheet joy of discovery... and, inevitably, this meant trouble.
-
Why does SSH send 100 packets per keystroke?
Nolen Royalty wrote an interesting piece about diagnosing a quirky SSH-related issue, and I found it both interesting and inspiring.
-
It Is A War Out There - Take Control of Your Supply Lines with HtDTY
Andrew Stephens reminds us to HtDTY (Host the Damn Thing Yourself) to reduce the risk of supply chain attacks and improve privacy. But I think the argument goes further than this.
-
Hive's Password Policy Makes Me Cry
Hive's password form can't decide whether you need 8+ or 12+ characters, gives misleading error messages and... requires that you use a 'special character' except most special characters (including most common punctuation) is secretly banned, and gives you a misleading error message if you try to use it. Do better, Hive!
-
Is it possible to allow sideloading *and* keep users safe?
Terence Eden's upset at Google's proposed changes to Android to further lock-down the ecosystem, and I'm concerned too.











