The Best Security Is When We All Agree To Keep Everything Secret (Except The Secrets) - NAKIVO Backup & Replication (CVE-2024-48248) - watchTowr Labs https://labs.watchtowr.com/the-best-security-is-when-we-all-agree-to-keep-everything-secret-except-the-secrets-nakivo-backup-replication-cve-2024-48248/
There are numerous times where I think "if that person simply had better aim, the world would be so very different".
But then I remember that where we are right now globally is not down to one or two evil people - but the result of rot in many social, economic, and governmental systems. The people we think are making evil choices are avatars for the system, more than individuals.
We have to fix the systems.
EDIT: They're still evil assholes. I just mean they're replacable, not unique.
Mildly amusing: this Aussie dude got fed up with people parking in his driveway so he installed a motion-activated sprinkler.
The swift strict memory safety proposal has been accepted: https://forums.swift.org/t/accepted-se-0458-opt-in-strict-memory-safety-checking/78116
We found out that machines performed 7% better if we trapped them in an endless loop of profound existential anguish
Time spent getting the vulnerable software and deploying it: ~10 hours
Time spent writing the exploit: 14 minutes
“Chrome Browser Exploitation: from zero to heap sandbox escape - Matteo Malvica - NDC Security 2025" https://www.youtube.com/watch?v=RL2po1swXO4
JSON Web Keys have a very peculiar property. It is a cryptographic key serialization format where public and private keys look almost the same. The only difference is that private keys contain more values. This means one can accidentally use a private key instead of a public key. Which works, but isn't very secure.
After my recent presentation at the @owasp_de Day, I was asked to have a look at OpenID Connect keys. Which are, well, in JWK format. I guess you can see where this is going.
https://blog.hboeck.de/archives/909-Mixing-up-Public-and-Private-Keys-in-OpenID-Connect-deployments.html
Project: golang/go https://github.com/golang/go
File: src/net/url/url.go:201 https://github.com/golang/go/blob/refs/tags/go1.23.4/src/net/url/url.go#L201
func unescape(s string, mode encoding) (string, error)
SVG:
dark https://tmr232.github.io/function-graph-overview/render/?github=https%3A%2F%2Fgithub.com%2Fgolang%2Fgo%2Fblob%2Frefs%2Ftags%2Fgo1.23.4%2Fsrc%2Fnet%2Furl%2Furl.go%23L201&colors=dark
light https://tmr232.github.io/function-graph-overview/render/?github=https%3A%2F%2Fgithub.com%2Fgolang%2Fgo%2Fblob%2Frefs%2Ftags%2Fgo1.23.4%2Fsrc%2Fnet%2Furl%2Furl.go%23L201&colors=light
Tech billionaires demanded Donald Trump use the power of the US government to pressure other countries not to crack down on them.
Now Trump is pulling out of a global tax agreement and threatening tariffs against countries that pass digital services taxes targeting multinational tech companies.
https://www.disconnect.blog/p/silicon-valley-is-enlisting-trump