Tag: security
-
I'd Like to Change my Mother's Maiden Name
LastPass users are having to cycle their passwords in the light of a recent security incident. That might well include their "security question" answers, which necessarily leads to some amusing conversations.
-
Reply to Decentralization and verification
Dan replies to Derek Kedziora's blog post, arguing that identity verification on Mastodon is, for the most part, a problem already solved.
-
How to date a recording using background electrical noise
Robert Heaton shares some specifics of EMF forensics, and Dan reconsiders an idea he had years ago for a hardware spoofer.
-
Hey @VOXI_UK! There's a security #vulnerability in your website. An attacker can (a) exfiltrate mobile numbers and (b) authenticate bypassing OTP.
Not sure who to talk to about ethical disclosure. Let me know? -
Can I use HTTP Basic Auth in URLs?
Dan dives into HTTP Basic Authentication, its history, and how modern browsers support it, with a focus on URL-based credential passing.
-
Hey @LloydsBank! 2009 called and asked if you're done sending your customers links to unencrypted HTTP endpoints yet. How do you feel about switching this to a HTTPS link rather than relying on an interceptable/injectable HTTP request?
-
Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer from an app's perspective
Moxie Marlinspike "acquires" a Cellebrite UFED and hacks it, with all the delight and sarcasm you'd expect. Dan partially-translates.
-
Big List of Naughty Strings
# Reserved Strings
#
# Strings which may be used elsewhere in code
undefined
undef
null
NULL
...
then
constructor
\
\\
# Numeric Strings
#
# Strings which can be interpreted as numeric
0
1
1.00
$1.00
1/2
1E2
...
Max Woolf
Max has produced a list of "naughty strings": things you might try injecting into your systems along with any fuzz testing you're doing to check for common errors in escaping, processing, casting, โฆ -
Why using Google VPN is a terrible idea
Google are launching a VPN service. The Proton team say why that's bad, and Dan takes a more-sarcastic look at the issue.
-
Displaying ProtonMail Encryption Status in Thunderbird
Dan releases his first Thunderbird plugin, for improving integration with ProtonMail Bridge.
-
When you browse Instagram and find former Australian Prime Minister Tony Abbott's passport number
The hacker known as "Alex" spots that Quantas expose all kinds of data to barely-authenticated customers.
-
Third-party libraries and security issues
A month or so ago Chris Ferdinandi recommended that developers avoid third-party libraries for security reasons. Dan partially-agrees, but feels the need to explain where and why he disagrees too.
-
Bypassing AppProtocol Prompts
The MS Edge team are working on a security feature relating to websites launching applications, and it's a great move.
-
Evolving Computer Words: "Hacker"
Of all evolving computer words, "hacker" is perhaps the most-loaded and controversial. Dan explores how it's changed and whether it can ever return to its original meaning.
-
Third party
Jeremy Keith wonders if the Web would have third-party cookies and JS at all if it were invented today, and Dan weighs in.









![Edge Canary showing an "Always allow [this website] to open links of this type..." checkbox](https://bcdn.danq.me/_q26u/2020/03/teamswithcb.png#16834)
