#CyperSecurity

sgued.fr/blog/need-csrf-token/

You should still use CSRF tokens. SameSite is not the same definition as Cross-Origin, so SameSite=Lax does not protect from CSRF coming from a "neighbor" subdomain.

#Security #CyperSecurity #CSRF #WebSecurity

SevorisSevoris
2024-09-20

W.r.t leaking user information and permitting JavaScript injection over their backend, a thought that just struck me:

Also more generally I must remark - okay, so you have all of these fancy social browser features. So far so understandable.

Why exactly is this wrapped in a giant pull-all-the-time paradigm instead of pushing local updates to people and having their browsers run queries for important information locally?

and

Lars Marowsky-BrĂ©e đŸ˜·larsmb@mastodon.online
2024-04-01

I can't wrap my head around how almost all of the #xz reporting focuses on the failures of #opensource.
Yeah, sure, but ...

Good luck finding such an attack in proprietary code.
Via the cliché paid off/blackmailed employee, hacked dev servers/repos, or via capitalism's favorite cost-cutting measure: a remote "offshored" contracted temporary developer (or nowadays, embedded into some LLM output).

If anything, Open Source Security has *worked*.

#cypersecurity #OSS

2024-03-10

Microsoft is being hacked and nobody cares. There are no consequences. If you rely on #Linux and #foss and it goes wrong, it's your fault. If you rely on #Microsoft and it goes wrong, it's Microsoft's fault. Win-win.

#cypersecurity #cozybear

msrc.microsoft.com/blog/2024/0

John Leonardjohnleonard
2024-01-08

MoD cybersecurity worst in Whitehall, figures reveal

The UK Ministry of Defence has by far the worst protected IT systems of any Whitehall department, with 11 "red-rated" systems.

computing.co.uk/news/4161325/m

CoreSeccoresec
2023-12-26

So Weihnachten sitzen alle zusammen und lösen und ich lese ein paper wie Informatiker sodoku lösen...

Ach und ich schaue mir verschiedene UniversitÀten an

Kann jemand eine fĂŒr empfehlen :P

2023-11-29

Just saw that there is currently a No Starch press HumbleBundle deal. Never bought one before, but this one looks interesting. Anybody has some experience or opinions?

humblebundle.com/books/hacking

#cypersecurity #ebook #ethicalhacking

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst