Skip to content

Dan Q

    • Articles
    • Everything
    • Notes
    • Reposts (shares)
    • Checkins (geo*)
    • Videos
    • Reviews
    • Comics
    • Tags
    • Stats
    • Subscribe
    • Blogroll
  • About
    • Semi-standard "slash pages" you might like to explore:
    • /about
    • /blank
    • /blogroll
    • /colophon
    • /contact
    • /cv
    • /events
    • /license
    • /pfp
    • /postcards
    • /privacy
    • /salary
    • /shh
    • /slashes
    • /stats
    • /subscribe
    • /where
    • Hide posts of type:
    • Choose how Dan's dressed:
    • Hair
    • T-Shirt
  • Contact
  • Podcast

Tag: security

  • Image representing post: I'd Like to Change my Mother's Maiden Name

    I'd Like to Change my Mother's Maiden Name

    LastPass users are having to cycle their passwords in the light of a recent security incident. That might well include their "security question" answers, which necessarily leads to some amusing conversations.

    Read more - about 3 minutes (581 words)

    • Article
    • 6 comments
    • posted 5 January, 2023
  • Screenshot showing @dan@danq.me's Mastodon account as the verified owner of website DanQ.me.

    Reply to Decentralization and verification

    Dan replies to Derek Kedziora's blog post, arguing that identity verification on Mastodon is, for the most part, a problem already solved.

    Read more - about 3 minutes (481 words)

    • Reply
    • 6 comments
    • posted 15 November, 2022
  • Matching a target ENF series with a section of a reference series

    How to date a recording using background electrical noise

    Robert Heaton shares some specifics of EMF forensics, and Dan reconsiders an idea he had years ago for a hardware spoofer.

    Read more (476 words)

    • Reply
    • 1 comment
    • posted 7 November, 2022
  • Hey @VOXI_UK! There's a security #vulnerability in your website. An attacker can (a) exfiltrate mobile numbers and (b) authenticate bypassing OTP.
    Not sure who to talk to about ethical disclosure. Let me know?

    Read more (35 words)

    • Note
    • 2 comments
    • posted 8 June, 2022
  • Internet Explorer window showing https://YourBank.com@786590867/ in the address bar.

    Can I use HTTP Basic Auth in URLs?

    Dan dives into HTTP Basic Authentication, its history, and how modern browsers support it, with a focus on URL-based credential passing.

    Read more - about 14 minutes (3099 words)

    • Article
    • 3 comments
    • posted 7 September, 2021
  • Text message: "Follow this link to download your free Lloyds Bank Mobile Banking app. http://www.lloydsbank.com/mobileapp"

    Hey @LloydsBank! 2009 called and asked if you're done sending your customers links to unencrypted HTTP endpoints yet. How do you feel about switching this to a HTTPS link rather than relying on an interceptable/injectable HTTP request?

    Read more (37 words)

    • Note
    • 5 comments
    • posted 11 May, 2021
  • Image representing post: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer from an app's perspective

    Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer from an app's perspective

    Moxie Marlinspike "acquires" a Cellebrite UFED and hacks it, with all the delight and sarcasm you'd expect. Dan partially-translates.

    Read more (448 words)

    • Repost
    • of this original
    • 4 comments
    • posted 27 April, 2021
  • Big List of Naughty Strings


    # Reserved Strings
    #
    # Strings which may be used elsewhere in code
    undefined
    undef
    null
    NULL

    ...

    then
    constructor
    \
    \\

    # Numeric Strings
    #
    # Strings which can be interpreted as numeric
    0
    1
    1.00
    $1.00
    1/2
    1E2

    ...


    Max Woolf
    Max has produced a list of "naughty strings": things you might try injecting into your systems along with any fuzz testing you're doing to check for common errors in escaping, processing, casting, โ€ฆ

    Read more (169 words)

    • Repost
    • of this original
    • posted 21 April, 2021
  • Google One VPN announcement, featuring the words "US Only"

    Why using Google VPN is a terrible idea

    Google are launching a VPN service. The Proton team say why that's bad, and Dan takes a more-sarcastic look at the issue.

    Read more (451 words)

    • Repost
    • 1 comment
    • posted 3 November, 2020
  • Encrypted email identified in Thunderbird having gone through ProtonMail Bridge

    Displaying ProtonMail Encryption Status in Thunderbird

    Dan releases his first Thunderbird plugin, for improving integration with ProtonMail Bridge.

    Read more (333 words)

    • Article
    • 5 comments
    • posted 6 October, 2020
  • Image representing post: When you browse Instagram and find former Australian Prime Minister Tony Abbott's passport number

    When you browse Instagram and find former Australian Prime Minister Tony Abbott's passport number

    The hacker known as "Alex" spots that Quantas expose all kinds of data to barely-authenticated customers.

    Read more (100 words)

    • Repost
    • posted 19 September, 2020
  • Third-party libraries and security issues

    A month or so ago Chris Ferdinandi recommended that developers avoid third-party libraries for security reasons. Dan partially-agrees, but feels the need to explain where and why he disagrees too.

    Read more - about 3 minutes (661 words)

    • Repost
    • 9 comments
    • posted 6 April, 2020
  • Edge Canary showing an "Always allow [this website] to open links of this type..." checkbox

    Bypassing AppProtocol Prompts

    The MS Edge team are working on a security feature relating to websites launching applications, and it's a great move.

    Read more (161 words)

    • Repost
    • posted 12 March, 2020
  • "Hacker" Dan Q

    Evolving Computer Words: "Hacker"

    Of all evolving computer words, "hacker" is perhaps the most-loaded and controversial. Dan explores how it's changed and whether it can ever return to its original meaning.

    Read more - about 8 minutes (1751 words)

    • Article
    • 7 comments
    • posted 23 December, 2019
  • Third party

    Jeremy Keith wonders if the Web would have third-party cookies and JS at all if it were invented today, and Dan weighs in.

    Read more (435 words)

    • Repost
    • posted 15 November, 2019

Posts navigation

Older posts
Newer posts

Get in Touch

I'd love to hear from you! Why not...

  • email me on blog@danq.me?
    (my spam filter is aggressive, so use a good subject line, i.e. not just "hello"; encrypt your email if you like)
  • say hi on Mastodon, where I'm @dan@danq.me?
  • send a letter or postcard to
    Dan Q, Unit 159610, PO Box 7169, Poole, BH15 9EL, UK
  • reach out some other way?
  • ยฉ Dan Q 1998-2026
  • Creative CommonsAttributionNon-Commercial except where stated (how to use)
  • powered by BloqClassicPressHTML5CSS3
  • privacy
  • Read articles, checkins, notes, reposts, and more...
  • @dan@danq.me
  • contact
  • subscribe
  • Dan Q
  • Creative Commons Attribution Non-Commercial license
  • ClassicPress
  • CSS is awesome
  • Created by a human, not by AI
  • LGBTQ+ pride flag (2018 progress variant)
  • Polyamory flag
  • Say no to Web3
  • Mastodon (it's like email... no, come back!)
  • Tested on Firefox
  • Best viewed on the Internet
  • PHP
  • Ruby
  • Debian
  • Caddy (webserver)
  • Find me on Melonland
  • Check out my GitHub
  • Three Rings - by volunteers, for volunteers, since 2002
  • I'm a fucking webmaster
  • Looks best at: any resolution!