Posts
2469
Following
662
Followers
1486
"I'm interested in all kinds of astronomy."
[RSS] We Patched CVE-2024-38030, Found Another Windows Themes Spoofing Vulnerability (0day)

https://blog.0patch.com/2024/10/we-patched-cve-2024-38030-found-another.html
0
0
0
repeated

Microsoft On the Issues: Google’s Shadow Campaigns
In a pot calling the kettle black moment, Microsoft is accusing Google of antitrust practices such as creating an astroturf lobbying organization. Since the author is a Corporate Vice President (CVP), Deputy General Counsel at Microsoft, there's some weight behind such an accusation on Microsoft's public blog. As a consumer with no skin in the game, this is a grab-the-popcorn moment. Let them fight.

0
2
0
@infosecdj @RGB_Lights @dcoderlt Nobody says it's OK to abuse. I'm saying it's best to prevent abuse and that it's not OK to let the abuse to continue for years.
1
0
0
@schrotthaufen @RGB_Lights That's not a reason for us to make (and reinforce) the same confusion.
0
0
0
@schrotthaufen @RGB_Lights Cookie banners are not paywalls, let's not confuse the two issues...
2
0
0
@dcoderlt @RGB_Lights This has been going on for years even before the UA war (a bit higher prio in all areas), and this is part of the reason why I can't accept the abuse argument: if this is abuse, why has nobody done anything about it?
1
0
1
@RGB_Lights Proponents say that cookie banners are deliberate abuse of the regulation (to condition users to accept whatever, I think?). IMO if the regulation allows abuse of this extent it is not a good regulation.
2
0
5
repeated

Serious question. Can anyone tell me how we are safer / better for the cookie warning clicking I have to do on the internet? Advertisers still own your browsing habits and the world expends a collective bazillion hours a week on a needless friction.

3
1
0
[RSS] Privilege escalation through TPM Sniffing when BitLocker PIN is enabled

https://blog.scrt.ch/2024/10/28/privilege-escalation-through-tpm-sniffing-when-bitlocker-pin-is-enabled/
0
0
1
repeated

Give Me the Green Light Part 1: Hacking Traffic Control Systems https://www.redthreatsec.com/blog/greenlightspart1

0
1
0
Retrofitting encrypted firmware is a Bad Idea™

https://haxx.in/posts/wtm-wtf/
0
0
0
repeated

Thirteen years ago I found "a bad babe" in Windows

https://daniel.haxx.se/blog/2011/10/28/whos-0xabadbabe-and-why/

1
1
0
repeated

In our new blogpost we guide you through the process of improving the tools available for WCF services over the net.tcp binding:

https://blog.silentsignal.eu/2024/10/28/wcf-net.tcp-pentest/

We created a brand new based parser and implemented transformations so messages can be manipulated and replayed with .

1
3
0
repeated

are YOU making a website with INFORMATION?

it needs a date. if its not just a list of links... it needs A DATE.

yes your blog, youre recipe edit etc NEEDS A DATE..

please, can we get this right

5
15
0
repeated
Edited 10 months ago

I had to deal with a freshly unboxed Android phone, and the flipping *clock* app, that was installed by default, came with a privacy policy.

I discovered this because the clock started crying that it couldn't work properly without Google Play Services.

I don't care what the privacy policy was for. I am tired. A clock app does not need to be in a position to have any privacy policy more involved than "we collect and report no data".

The clock is now disabled.

I am so tired of this.

4
11
0
repeated

Don't mention explodey stuff near TSA. Noted ✅

4
11
2
Show older