security

253 stories and discussions about security, aggregated from every source we track.

1.

Why passkeys are a step back for personal security: examining account lockout risks, platform lock-in, hardware key limits, and fragile recovery flows.

825 points•ethanhawksley•13 days ago•792 comments•
3.

It started innocently enough. I saw a tweet about a new product offering from one of my favorite companies, Cloudflare. Neat! I clicked through to the site and there it is: And huzzah!, my preferre…

135 points•kevincox•about 2 months ago•15 comments
4.

<p>Additional context: <a href="https://www.youtube.com/watch?v=M1si1y5lvkk" rel="ugc">https://www.youtube.com/watch?v=M1si1y5lvkk</a></p> <p>No abstract.</p>

129 points•theelx•6 months ago•64 comments
5.

Before code review even starts, agents let us build custom tooling and formal models. Here’s how six months of building with AI agents helped us find real issues in our Miden zkVM audit.

85 points•aray07•9 days ago•12 comments•
6.

Why passkeys are a step back for personal security: examining account lockout risks, platform lock-in, hardware key limits, and fragile recovery flows.

71 points•eduard•12 days ago•53 comments
7.

I&rsquo;ve spent the last few weeks working with the security architecture of the nRF54L series from Nordic Semiconductor (in case you missed it, I recently joined Nordic!). While doing so, I have engaged my typical…

60 points•hasheddan•9 days ago•17 comments•
8.

consumer-grade hardware can run an LLM that hacks the planet. we can stop it, but we don't have much time.

57 points•apropos•11 days ago•58 comments
10.

<p>According to the Wikipedia article <a href="https://en.wikipedia.org/wiki/USB_C#Cables" rel="ugc">https://en.wikipedia.org/wiki/USB_C#Cables</a></p> <blockquote> <p>USB-C 3.1 cables are considered full-featured USB-C cables. They are electronically marked <strong>cables that contain a chip</strong> with an ID function based on the configuration channel and vendor-defined messages (VDM) from the USB Power Delivery 2.0 specification. Cable length should be ≤ 2 m for Gen 1 or ≤ 1 m for Gen2. <strong>Electronic ID chip</strong> provides information about product/vendor, cable connectors, USB signalling protocol (2.0, Gen1, Gen 2), passive/active construction, use of VCONN power, supported VBUS current, latency, RX/TX directionality, SOP controller mode, and <strong>hardware/firmware version.</strong></p> </blockquote> <p>Is anyone here aware of USB-C cable teardowns, or analysis of the chips inside? I'm concerned about the security implications of an infected USB cable.</p>

51 points•chadski•over 9 years ago•13 comments
11.
48 points•atmosx•about 16 hours ago•23 comments
12.

The creators of Meow hash made security claims; we break them all.

48 points•soatok•about 5 years ago•12 comments
15.

Most developers already know this rule: Don't run code from a repository you don't...

35 points•robertadam987_•12 days ago•9 comments
16.

SAML, the XML-based authentication protocol that birthed the SSO industry, is fundamentally flawed due to XML complexity, canonicalization issues, enveloped signatures, and design ossification, making it vulnerable to…

34 points•fanf•8 days ago•1 comment
17.

<p><a href="http://www.cs.vu.nl/~ast/intel/" rel="ugc">link</a></p> <p>Here are the updated parts:</p> <blockquote> <p>Note added later: Some people have pointed out online that if MINIX had a GPL license, Intel might not have used it since then it would have had to publish the modifications to the code. Maybe yes, maybe no, but the modifications were no doubt technical issues involving which mode processes run in, etc. My understanding, however, is that the small size and modular microkernel structure were the primary attractions. Many people (including me) don't like the idea of an all-powerful management engine in there at all (since it is a possible security hole and a dangerous idea in the first place), but that is Intel's business decision and a separate issue from the code it runs. A company as big as Intel could obviously write its own OS if it had to. My point is that big companies with lots of resources and expertise sometimes use microkernels, especially in embedded systems. The L4 microkernel has been running inside smartphone chips for years. I certainly hope Intel did thorough security hardening and testing before deploying the chip, since apparently an older version of MINIX was used. Older versions were primarily for education and newer ones were for high availability. Military-grade security was never a goal.</p> <p>Second note added later: The online discussion got completely sidetracked from my original points as noted above. For the record, I would like to state that when Intel contacted me, they didn't say what they were working on. Companies rarely talk about future products without NDAs. I figured it was a new Ethernet chip or graphics chip or something like that. If I had suspected they might be building a spy engine, I certainly wouldn't have cooperated, even though all they wanted was reducing the memory footprint (= chip area for them). I think creating George Orwell's 1984 is an extremely bad idea, even if Orwell was off by about 30 years. People should have complete control over their own computers, not Intel and not the government. In the U.S. the Fourth Amendment makes it very clear that the government is forbidden from searching anyone's property without a search warrant. Many other countries have privacy laws that are in the same spirit. Putting a possible spy in every computer is a terrible development.</p> </blockquote>

34 points•av•almost 9 years ago•1 comment
18.
34 points•pyk•about 10 years ago•7 comments
20.

Uncensored AI models or those fine-tuned for cybersecurity tasks. - JoasASantos/Offensive-Security-AI-Models

31 points•soltanov•2 days ago•9 comments•
22.

Introduction I've been on a bit of a floppy disc protection odyssey recently. This will probably be the last floppy disc related post for so...

29 points•susam•almost 6 years ago•7 comments
25.
26 points•layer8•10 days ago•28 comments•
26.

This post is a copy of tweets by Zooko Wilcox-O'Hearn . SHA256 was designed by the NSA. BLAKE (the original) and BLAKE3 were designed by Jean-Philippe Aumasson

26 points•inactive-user•almost 3 years ago•26 comments
27.

Linux has quite some security mechanisms. So let's look at some of them and rate them by usability and power.

25 points•runxiyu•10 months ago•15 comments
28.

<p>Context: I'm the author of the Rust patch</p>

25 points•ChrisDenton•over 2 years ago•21 comments
29.

🔐 No funding. No team. No mentor. No enterprise lab. Just a 13-year-old developer, an HP...

23 points•akhourianmolkumar•3 days ago•11 comments
30.

Stemming from a security researcher and his team proposing a new Linux Security Module (LSM) three years ago and it not being accepted to the mainline kernel, he raised issue over the lack of review/action to Linus…

23 points•laktak•10 months ago•0 comments
32.

<p>While this article doesn't go into technical details it does highlight the risk that ordinary mail users face when using HTML based email.</p>

22 points•fcbsd•about 9 years ago•7 comments
35.

Security Bulletins that relate to Netflix Open Source - Netflix/security-bulletins

20 points•alynpost•over 7 years ago•2 comments
36.
20 points•maikel•about 10 years ago•2 comments
37.

Tesla has two cars, the S60 and the S75, that are physically more or less identical, but one costs $8500 more than the other. The cheaper car ($66K base price)

20 points•JordiGH•over 10 years ago•9 comments
41.

<p>(Mods: I feel like there's almost no conversation to be had here <em>except</em> on security grounds. Feel free to remove tag if considered non-applicable.)</p>

19 points•kivikakk•over 10 years ago•12 comments
42.

The more I watch and read about the Hugging Face incident, the more it fascinates me. 1,200 agents...

18 points•hiper2d•8 days ago•6 comments
43.
44.

AI can generate the implementation. Your architecture still has to decide what that implementation is...

17 points•kenwalger•1 day ago•4 comments
46.

Cal.com just closed their source code, arguing AI has made open source too dangerous. After 13 years of building Discourse in public, we're staying open. Here's why.

16 points•hongminhee•6 months ago•0 comments
49.

We scanned 7,040 directory-listed U.S. local-business websites for security headers. Half met none of seven criteria. Full report, data and code.

15 points•terrybyte•6 days ago•9 comments•
50.
15 points•sethmlarson•over 3 years ago•0 comments
52.

On November 25th, one of our engineers was compromised by the Shai-Hulud npm supply chain worm. Here's what happened, how we responded, and what we've changed.

14 points•hoistbypetard•10 months ago•1 comment
53.
14 points•quad•almost 5 years ago•1 comment
55.

ATLOCK — built by one 13-year-old, with no one in his corner TL;DR: I'm 13. I've built...

13 points•akhourianmolkumar•4 days ago•1 comment
56.

This document specifies new identifiers and a challenge for the Automatic Certificate Management Environment (ACME) protocol which allows validating the identity of a device using attestation. This document updates RFC…

13 points•Foxboron•10 months ago•2 comments
58.
13 points•atoponce•over 3 years ago•8 comments
60.

This post looks back at PL-related ideas raised in a 1995 discussion about software security, and sees many have gone on to practical adoption.

13 points•artem•over 10 years ago•0 comments

Related topics