Pinned toot

I post about technical topics here, especially , , . My other account social.tchncs.de/@WPalant is for German-language non-technical stuff.

It seems that he has shut down most of his websites hosting copycat content, that’s good news. Yes, even the one with copyright message replaced by “See you in court.” However, he has set up a new fake company website and a Twitter account for it. 🙄

Show thread

Another upcoming disclosure deadline in less than four weeks. Universal XSS in a browser extension, really bad. The vendor managed to produce two releases in the time but no fix for the critical issue. Sent out a reminder… 🙄

The Print Friendly & PDF browser extension allowed any website to completely take over the extension. Considerable attack surface remains, and Firefox version is still vulnerable (exploitation slightly more complicated there).

palant.info/2021/04/13/print-f

Guess what: the extension vendor who took almost three months to address a critical vulnerability, cutting it very close to the deadline, only did some minor surface polishing. The underlying issues are still present and I better don’t look too closely. Disclosure tomorrow. 😬

Don’t get me wrong, deepfakes are a concern. But apparently not big enough a concern yet that we need to worry about a mom manipulating videos in order to harass her daughter’s competition. Harassment with a real video is enough to get her indicted.

dailydot.com/debug/deepfake-va

So whoever compromised the PHP source code repository did so by pushing via HTTPS with password-based auth. They had to guess usernames. Sounds like a password reuse issue: the password leaked elsewhere, so they didn’t know the matching username.

portswigger.net/daily-swig/php

So apparently the leaked data of 533 million Facebook users came from a 2019 breach that wasn’t previously disclosed after all. Not just that, Facebook chose not to notify the users affected either. Yes, totally reasonable and responsible behavior, as you would expect.

wired.com/story/facebook-data-

Noticed that a former follower blocked me. Weird, what did I do? Oh, I retweeted something about the harm RMS has done and is still doing…

People, choosing heroes means also reconsidering the choice sometimes. Some turn out to be awful human beings when you take a closer look.

Great blog post, explaining how linked list questions in job interviews had their time and place in the 80s. Also showing how the cargo culting likely happened which made them still popular today despite being largely pointless.

hillelwayne.com/post/linked-li

What we need is software that users can rely on, that will act in their best interest rather than monetize them behind their backs. Clearly, Free Software failed to define ethical aspects of software, and we now know why. So maybe ethicalsource.dev/ is the right answer.

Show thread

While at it, could we consider moving beyond Free Software? I’m increasingly convinced that it is a dead end we wasted decades on. GNU/Linux is used everywhere, yet it gives users exactly zero leverage. Having access to those mountains of code is no gain, it’s almost useless.

After loosing RSS feeds again in Thunderbird I got fed up and reported the bug. Looks like it has good chances to get fixed! bugzilla.mozilla.org/show_bug.

Free Software Foundation Europe is severing its ties to FSF. Yes, at this stage it’s the only right decision.

fsfe.org/news/2021/news-202103

Stumbled upon a (legitimate) website that managed to drive up Firefox memory usage by 2 GB and almost hang the entire UI before I closed the tab. And Firefox spent around five minutes working on freeing all that memory. I feel an urge to dissect it and figure out what they did…

For anybody concerned that my previous article on Amazon Assistant only discussed potential threats: here is the actual data being collected for “analytics” purposes. Lots of it and linked to the user’s Amazon account.

palant.info/2021/03/22/follow-

I’m writing a follow-up on Amazon Assistant, will hopefully be finished today. There is more to this story…

I keep looking for something making this considerably more advanced than the proxy modules I implemented for PfP (5 kB of code). Yes, somewhat pointless privilege checking – a trivial addition. Yes, publish/subscribe model for events – not a big deal either. Nothing there…

Show thread

There are factories creating exactly one type of object. Superclasses with exactly one subclass. And lots of message serializers – one module for each type of message. Didn’t anybody think of generalizing message creation? But lots of pointless generalization here.

Show thread

I’m still looking into Amazon Assistant code a bit, and the overengineering level of this whole thing is astonishing. The UBPClient library is 760 kB of code which are duplicated all over the place. Merely for communication between different frames.

palant.info/2021/03/08/how-ama

Show older
Infosec Exchange

A Mastodon instance for info/cyber security-minded people.