Pulse of Truth

This magazine is not receiving updates (last activity 0 day(s) ago). Subscribe to start receiving updates.

Renegade , in How Google’s 90-day TLS certificate validity proposal will affect enterprises

Article takes a long time to say very little.

SteveTech , in Critical Rust flaw enables Windows command injection attacks

I'm not sure why everyone's focusing in on Rust, this seems like a general Windows issue to me, thus affecting most major languages.

Original Report: BatBadBut: You can't securely execute commands on Windows

PlexSheep ,

Yeah it seems weirdly specific. Also, if you pass user input to command args directly, you are asking for trouble.

"An attacker able to control the arguments passed to the spawned process could execute arbitrary shell commands by bypassing the escaping. The severity of this vulnerability is critical if you are invoking batch files on Windows with untrusted arguments. No other platform or use is affected."

According to the article the following other langs are affected:

  • Erlang (documentation update)
  • Go (documentation update)
  • Haskell (patch available)
  • Java (won’t fix)
  • Node.js (patch will be available)
  • PHP (patch will be available)
  • Python (documentation update)
  • Ruby (documentation update)

Seems like most languages don't even treat this as a real security vulnerability?

Alexstarfire , in LG releases updates for vulnerabilities that could allow hackers to gain access to TVs

I've got a pretty foolproof way to prevent my TV from being hacked. Don't give it internet access.

BetaDoggo_ , in We now have a better look at what’s inside the Humane AI pin

It's a generic sbc, who could have guessed?

fizzyvelcro , in Google survey: 63% of IT and security pros believe AI will improve corporate cybersecurity

… according to a new study of 2,486 information technology and security professionals, conducted by Google Cloud and the Cloud Security Alliance.

This just in: People working with AI say AI is good

reflectedodds , in 60% of small businesses are concerned about cybersecurity threats

I bet the poll was like "Are you worried about cyber attacks on your business? Yes or no"

Deadend , in Google sues two crypto app makers over allegedly vast “pig butchering” scheme

Maybe Google should consider blocking promotion of NFT/Crypto since it’s scams all the way down.

Greyghoster , in Cookie consent choices are just being ignored by some websites

I don’t think that anyone actually believes that all sites obey cookies consents. Do the best you can and use Firefox or some other that limits your exposure.

Maalus ,

Sure. But 90%?

Greyghoster ,

It comes down to who’s monitoring and how many significant fines are being issued.

alex_02 , in New acoustic attack determines keystrokes from typing patterns
@alex_02@infosec.pub avatar

Looked at this a while ago. This has been a study for a while. Def interesting, but it requires time to train the model, and also it doesn't work on just any keyboard. Also isn't accurate always with figuring out what was typed and takes a lot of guesswork with machine learning.

xor ,

you should probably read the article, it's different than other methods:

What makes the attack different compared to other approaches is that it can reach a typing prediction accuracy of 43% (on average) even when:

-the recordings contain environmental noise
-the recorded typing sessions for the same -target took place on different keyboard models
-the recordings were taken using a low-quality microphone
-the target is free to use any typing style

still only useful in extremely limited situations though... but it is neat that it uses timing of key strokes over the different sounds of each one...

alex_02 ,
@alex_02@infosec.pub avatar

Thanks for saying the same thing just differently.

xor ,

and also it doesn't work on just any keyboard.

i contradicted you and put that section in bold...
maybe just be less defensive and take it as the innocuous comment it was....

alex_02 ,
@alex_02@infosec.pub avatar

Ok buddy. You're either a dumbass or you have such an inflated ego that you're illiterate or just couldn't be arsed to read my original comment. Before this became more mainstream, I actually looked into it and read a number of papers on how it works. It doesn't work on just any keyboard because it requires to be able to pick up the keys using sound, which a lot of membranes ones would be extremely difficult to do. Also, you have to factor in the surrounding noises as well. In a controlled lab yes it is much easier to do, but the technology is just not there yet and there is a guy who has been doing acoustic key logging research for years, and it still required a ML model that has to be trained for it to even start deciphering the keystrokes. I trust that guy over a moron with a cliché username such as xor. Now fuck off and come back when you actually know what you're talking about.

xor ,

i stopped reading at "dumbass"

seriously just... you're a [redacted]

this is not the same technique that you read about... it's **new, nove**l, and works on timing not the sound of the keyboard

just read

idiot

alex_02 ,
@alex_02@infosec.pub avatar

i stopped reading at “dumbass”

seriously just… you’re a [redacted]

this is not the same technique that you read about… it’s new, novel, and works on timing not the sound of the keyboard

just read

idiot

Yknow, I tried to be nice before, but clearly you're more useless and pathetic than the idiots at the bottom "reacting" to content on YouTube. I pointed out how stupid your response was, but clearly you proved my point that you're illiterate.

If you can't be bothered to read the full comments (you probably did and just trying to make it seem as if you didn't), then don't bother replying, cunt. See, unlike you, I don't redact my words and bitch call me whatever you wanted in redacted. Please do because I don't care what a useless shitbag such as yourself says, since we can get more intelligence from Fox News. Go cry to your mother. Nobody needs your immature, almond sized brain responses. Your ego is so fragile that it makes glass bombproof, and you're a cesspool worse than aids. GTFO because nobody wants your pathetic waste of space of an existence on here.

xor ,

lol, your dime store, generic insults don't work...

you're pretty sad, honestly

alex_02 ,
@alex_02@infosec.pub avatar

At least I don't redact what I say like a coward. Cope and seethe, loser.

xor ,

at least i don't write paragraphs of lame non-sequiter insults and then pretend like the other person is "seething" with anger....
super duper cliche, btw

you're so fragile a minor correction sends you into a tantrum of denial and insults...

like a fragile narcissist who can't cope with their own mediocrity

alex_02 ,
@alex_02@infosec.pub avatar

There is a term that we call you: pseudo-intellect. The only one that is getting butt hurt is you, and now it is just funny. The blocking button is there for a reason. Learn to use it. Also, you didn't correct me at all, and your stupidity is both cringe and hilarious. Cope and seethe.

xor ,

cope and seethe, loser

alex_02 ,
@alex_02@infosec.pub avatar

Thank you! I do apologize, your parents never loved you. ^_^

Also, good job. You didn't redact whatever to try to insult me.

OppositeOfOxymoron , in Google sues two crypto app makers over allegedly vast “pig butchering” scheme

Yeah, Google's big, but they're not 'take on the chinese mob' big.

mystik , in Google Proposes Method for Stopping Multifactor Runaround

As long as the device can do this operation without a connection or permission from Google, Apple, Microsoft, or anyone else besides the user in question, this is great.

GregoryTheGreat , in Report Slams Microsoft for Security Blunders in Chinese Hack

Is that a body slam or one of those heavily over used hype title words that are utterly meaningless?

viking , in IBIS hotel check-in terminal keypad-code leakage
@viking@infosec.pub avatar
answersplease77 , in Singapore Widens Crypto Rules to Cover Custody, More Transfers

you mean introduced more taxes?

tacosanonymous , in House of Representatives bans the use of Copilot over security concerns

Truly doing the Lord's work.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • pulse_of_truth@infosec.pub
  • test
  • worldmews
  • mews
  • All magazines