security
253 stories and discussions about security, aggregated from every source we track.
Why passkeys are a step back for personal security: examining account lockout risks, platform lock-in, hardware key limits, and fragile recovery flows.
It started innocently enough. I saw a tweet about a new product offering from one of my favorite companies, Cloudflare. Neat! I clicked through to the site and there it is: And huzzah!, my preferre…
<p>Additional context: <a href="https://www.youtube.com/watch?v=M1si1y5lvkk" rel="ugc">https://www.youtube.com/watch?v=M1si1y5lvkk</a></p> <p>No abstract.</p>
Before code review even starts, agents let us build custom tooling and formal models. Here’s how six months of building with AI agents helped us find real issues in our Miden zkVM audit.
Why passkeys are a step back for personal security: examining account lockout risks, platform lock-in, hardware key limits, and fragile recovery flows.
I’ve spent the last few weeks working with the security architecture of the nRF54L series from Nordic Semiconductor (in case you missed it, I recently joined Nordic!). While doing so, I have engaged my typical…
consumer-grade hardware can run an LLM that hacks the planet. we can stop it, but we don't have much time.
<p>According to the Wikipedia article <a href="https://en.wikipedia.org/wiki/USB_C#Cables" rel="ugc">https://en.wikipedia.org/wiki/USB_C#Cables</a></p> <blockquote> <p>USB-C 3.1 cables are considered full-featured USB-C cables. They are electronically marked <strong>cables that contain a chip</strong> with an ID function based on the configuration channel and vendor-defined messages (VDM) from the USB Power Delivery 2.0 specification. Cable length should be ≤ 2 m for Gen 1 or ≤ 1 m for Gen2. <strong>Electronic ID chip</strong> provides information about product/vendor, cable connectors, USB signalling protocol (2.0, Gen1, Gen 2), passive/active construction, use of VCONN power, supported VBUS current, latency, RX/TX directionality, SOP controller mode, and <strong>hardware/firmware version.</strong></p> </blockquote> <p>Is anyone here aware of USB-C cable teardowns, or analysis of the chips inside? I'm concerned about the security implications of an infected USB cable.</p>
The creators of Meow hash made security claims; we break them all.
Most developers already know this rule: Don't run code from a repository you don't...
SAML, the XML-based authentication protocol that birthed the SSO industry, is fundamentally flawed due to XML complexity, canonicalization issues, enveloped signatures, and design ossification, making it vulnerable to…
<p><a href="http://www.cs.vu.nl/~ast/intel/" rel="ugc">link</a></p> <p>Here are the updated parts:</p> <blockquote> <p>Note added later: Some people have pointed out online that if MINIX had a GPL license, Intel might not have used it since then it would have had to publish the modifications to the code. Maybe yes, maybe no, but the modifications were no doubt technical issues involving which mode processes run in, etc. My understanding, however, is that the small size and modular microkernel structure were the primary attractions. Many people (including me) don't like the idea of an all-powerful management engine in there at all (since it is a possible security hole and a dangerous idea in the first place), but that is Intel's business decision and a separate issue from the code it runs. A company as big as Intel could obviously write its own OS if it had to. My point is that big companies with lots of resources and expertise sometimes use microkernels, especially in embedded systems. The L4 microkernel has been running inside smartphone chips for years. I certainly hope Intel did thorough security hardening and testing before deploying the chip, since apparently an older version of MINIX was used. Older versions were primarily for education and newer ones were for high availability. Military-grade security was never a goal.</p> <p>Second note added later: The online discussion got completely sidetracked from my original points as noted above. For the record, I would like to state that when Intel contacted me, they didn't say what they were working on. Companies rarely talk about future products without NDAs. I figured it was a new Ethernet chip or graphics chip or something like that. If I had suspected they might be building a spy engine, I certainly wouldn't have cooperated, even though all they wanted was reducing the memory footprint (= chip area for them). I think creating George Orwell's 1984 is an extremely bad idea, even if Orwell was off by about 30 years. People should have complete control over their own computers, not Intel and not the government. In the U.S. the Fourth Amendment makes it very clear that the government is forbidden from searching anyone's property without a search warrant. Many other countries have privacy laws that are in the same spirit. Putting a possible spy in every computer is a terrible development.</p> </blockquote>
Uncensored AI models or those fine-tuned for cybersecurity tasks. - JoasASantos/Offensive-Security-AI-Models
Introduction I've been on a bit of a floppy disc protection odyssey recently. This will probably be the last floppy disc related post for so...
This post is a copy of tweets by Zooko Wilcox-O'Hearn . SHA256 was designed by the NSA. BLAKE (the original) and BLAKE3 were designed by Jean-Philippe Aumasson
Linux has quite some security mechanisms. So let's look at some of them and rate them by usability and power.
<p>Context: I'm the author of the Rust patch</p>
🔐 No funding. No team. No mentor. No enterprise lab. Just a 13-year-old developer, an HP...
Stemming from a security researcher and his team proposing a new Linux Security Module (LSM) three years ago and it not being accepted to the mainline kernel, he raised issue over the lack of review/action to Linus…
<p>While this article doesn't go into technical details it does highlight the risk that ordinary mail users face when using HTML based email.</p>
Security Bulletins that relate to Netflix Open Source - Netflix/security-bulletins
Tesla has two cars, the S60 and the S75, that are physically more or less identical, but one costs $8500 more than the other. The cheaper car ($66K base price)
<p>(Mods: I feel like there's almost no conversation to be had here <em>except</em> on security grounds. Feel free to remove tag if considered non-applicable.)</p>
The more I watch and read about the Hugging Face incident, the more it fascinates me. 1,200 agents...
AI can generate the implementation. Your architecture still has to decide what that implementation is...
Cal.com just closed their source code, arguing AI has made open source too dangerous. After 13 years of building Discourse in public, we're staying open. Here's why.
We scanned 7,040 directory-listed U.S. local-business websites for security headers. Half met none of seven criteria. Full report, data and code.
On November 25th, one of our engineers was compromised by the Shai-Hulud npm supply chain worm. Here's what happened, how we responded, and what we've changed.
ATLOCK — built by one 13-year-old, with no one in his corner TL;DR: I'm 13. I've built...
This document specifies new identifiers and a challenge for the Automatic Certificate Management Environment (ACME) protocol which allows validating the identity of a device using attestation. This document updates RFC…
This post looks back at PL-related ideas raised in a 1995 discussion about software security, and sees many have gone on to practical adoption.