Proud that my work on cross-blockchain analysis at @uniinnsbruck made it into a @USENIXSecurity 20 paper. See https://t.co/YOONrVnmT3 for details.
Many thanks to everyone involved, esp. @maltemoeser, @random_walker & my thesis advisors Rainer Böhme and Michael Fröwis. #usesec20
Information security research has long established three best practices for websites to help users pick stronger passwords. In a new study, we reverse engineered 120 popular English language websites, and found that only 15 (!) of them follow these guidelines. 🧵
@C0axx The Thinkpad T480 has 2 RAM slots and supports 64GB, while still being somewhat portable. Don't know about newer models though, I think most have soldered RAM nowadays.
👀 "This is essentially a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings)." https://t.co/FhcIJ5scbM
Very informative thread on the log4j vulnerability. Blocking outbound LDAP and RMI requests on your firewall seems to be one effective countermeasure (among others). #log4j
10 #Log4Shell Facts vs Fiction: a 🧵
1. 1.x is NOT vuln to this RCE. While it doesn't have another RCE, it requires access to send serialized data to a listener ON the log server. This is much MUCH harder to exploit and kind of rare for a Log4j server to be running.
Excited to share a small thing I've been working on: fast tooling for detecting misconfigured session implementations in web apps.
CookieMonster rapidly finds misconfigured secret keys in applications using Laravel, Flask, JWTs, and more!
https://t.co/d94hjmn3Vm
The Trojan Source vulnerability allows supply-chain attacks on software written in C, C++, Go, Java, Javascript, Python and Rust. We're releasing details after a 99-day coordinated disclosure period, and some of these compilers will be patched quickly. See https://t.co/tO4xIU5Ncw
I’ve been doing a bit of work recently, attacking laptops that are protected by Microsoft Bitlocker drive encryption.
Join me on a journey where we break into this CEO’s laptop to steal company secrets and plant malware.
There are only 10 days left until the Let's Encrypt root certificate expires and there are still questions over what the impact will be! Full details here: https://t.co/GuGvqyeosN
In my thesis I found that the privacy of #blockchain users can be hurt across chains using cross-chain address clustering. For more details, watch the video I recorded for the “Inday Students 2020” event of the Computer Science Institute at @uniinnsbruck. https://t.co/HbJC5uiutx