A MAC is not a Hash; this confusion caused an interesting bug in AMD. Shoutout to @_MatteoRizzo for the excellent find last year. I’ve been wanting to write this for a while; my analysis of the interesting cryptography concepts - https://t.co/Gk7e5CYNhv
@dinodaizovi This is a very good idea to keep secrets out of agent sandboxes; although it implies the proxy likely has to be able to intercept and decrypt TLS, making it a single point of failure!
@SusanPolgar Black queen to f5 , white move rook / bishop to e4, black knight to f4, white pawn take out black knight at f4, black queen to h3, white rook to e3 , take out using black pawn … check-mate in a few moves!
@anirudhology@system_monarch@anirudhology good blog post - this is one of the most pragmatic answers I’ve seen. Aside from this, dPOP is another way of making a stolen token useless, but it’s a newer protocol that must be explicitly implemented https://t.co/U9YXeKXeQh
@penberg@mgill25 I’ve used ocaml to build a compiler - this was for a university project; I hated it initially but towards the end understood some of its strengths especially wrt pattern matching etc Shameless plug - https://t.co/QXSbPstdgu
Day 2 of #ZeroDayQuest brought together brilliant minds from around the world for more hands-on hacking and meaningful community connections. Catch the energy in our recap video!
@secbughunter@tinderj_@ZenOneSec@0xdea
I’m hiring security engineers for my team at Microsoft to help secure the Azure cloud. Looking for senior security engineers with experience in AppSec/Security Architecture/OS security/web security!
DM for any questions!
Interested? : https://t.co/VnF3nf940m
@mohol_murlidhar@RamMNK OTP verification renders the service unusable for those that need it. Most airports across the world provide free WiFi without requiring an OTP/ mobile verification. I implore you to consider this to improve customer experience across airports in India.
@AAI_Official@MoCA_GoI why do airports in India require OTP verification before accessing airport WiFi? Travelers that actually need WiFi are unlikely to have an Indian phone no. Those with an Indian phone no most probably have mobile data and don’t need WiFi.
@nstfkc If using redis for sessions, I presume the redis cache must be shared across your web servers, no ? (Else how would sessions work across servers?) To prevent a bad client from forcing db/redis lookup with bad sessionIds maybe JWT validate first and then lookup redis ? Thoughts?
@dinodaizovi Nice idea to use additional authenticated data to bind extra context. @dinodaizovi I *think* even if some columns cannot be encrypted, the same idea could be extended via (say) hmac to mitigate injections? Would love to read a blog post if available!
@priynshuratnakr Very surprised to see no questions being asked about the security / privacy implications of this app being able to read sms, urls etc. seems contradictory to the original claims about e-commerce data collections.