DeepFakes - an emerging cyber threat to worry about in 2019.
Start-Up is developing technology to detect #deepfake videos.
https://t.co/f26iLdwPVl Question remains on how effective their efforts will be?
I published the source code and (commented) example exploits for my #35C3CTF macOS browser exploitation challenges: https://t.co/jbX90g3t0i congrats to @qwertyoruiopz and @i41nbeer for solving all parts (and winning the CTF)! :) #35c3
I'm grateful @insiniasec used a security bug and highlighted it's effectiveness to force a fix to widely known hole. @Twitter should act to protect the platform and users. The only crime here is that you're all arguing over junk/stunt hacking. Shodan is as intrusive daily.
@Vegaskid1337 @insiniasec They have known since 2011. The true sign of insanity is doing the same thing again and again while expecting different results.
I’ll never understand vendors that prohibit public disclosure after a vulnerability is fixed. If it’s fixed, let other vendors learn from the mistake. Why hide it?
@0x4A757A@BufferBandit@insiniasec You could trust the source, the source gets MITM’d and then you have the same issue all over again. There are many issues in this case but fundamental one is trusting the input, more specifically the value of sender telco number.
@0x4A757A@BufferBandit@insiniasec Twitter trusting that input led to the impact you saw and the very reason you sent this tweet. Case in point. Validating identity is the FIX, trusting input is the ISSUE. If they tried to validate and fail, then you would be correct saying it’s a validation issue but they don’t.
@0x4A757A@BufferBandit@insiniasec I didn’t suggest or say that at all. Of course data has to be supplied, I am talking about trusting it blindly like they do.
@0x4A757A@BufferBandit@insiniasec If you don’t check what is input to a program you can’t secure it. I agree its lack of auth/access control too but fundamentally the issue arises from trusting client data to invoke an action.
We are at war. We are authorised to carry out these actions under cyber war directive 300012. All members are elite soldiers of the 671st grey-hat commando unit.
@BufferBandit@insiniasec@InsiniaSRT The vuln works by texting twitter obh the user (src=user, dst=twitter). It definitely works https://t.co/VWQQJ7H0iR