Skip Navigation
InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)SO
Posts
9
Comments
3
Joined
2 yr. ago
  • That is very true.
    \ I do think that there's more depth to it than that. For example, dealing with it on the end of the terminal will probably break compatibility, and dealing with it on the app end will require every single dev to start sanitizing this. The challenges are real.

  • appsec @infosec.pub
    solidsnail @infosec.pub
    cybersecurity @infosec.pub
    solidsnail @infosec.pub
    appsec @infosec.pub
    solidsnail @infosec.pub
    blog.solidsnail.com It’s not a Feature, It’s a Vulnerability

    It takes a special kind of person to name a company after their own body part. Fortunately the Microsoft Security Response Center doesn’t seem to have inherited that kind of mentality, because when I have reported not a bug but a feature as a vulnerability - they accepted it.

    It’s not a Feature, It’s a Vulnerability

    cross-posted from: https://infosec.pub/post/5707149

    I talk about a report I've made to MSRC in the beginning of the year regarding vscode.

    It's a bit different. There's no in depth technical stuff, because I basically just reported the feature, not a bug.

    cybersecurity @infosec.pub
    solidsnail @infosec.pub
    blog.solidsnail.com It’s not a Feature, It’s a Vulnerability

    It takes a special kind of person to name a company after their own body part. Fortunately the Microsoft Security Response Center doesn’t seem to have inherited that kind of mentality, because when I have reported not a bug but a feature as a vulnerability - they accepted it.

    It’s not a Feature, It’s a Vulnerability

    I talk about a report I've made to MSRC in the beginning of the year regarding vscode.

    It's a bit different. There's no in depth technical stuff, because I basically just reported the feature, not a bug.

    Exploit Development @infosec.pub
    solidsnail @infosec.pub

    cross-posted from: https://infosec.pub/post/2466014

    This is my first write-up, on a vulnerability I discovered in iTerm2 (RCE). Would love to hear opinions on this. I tried to make the writing engaging.

    cybersecurity @infosec.pub
    solidsnail @infosec.pub

    cross-posted from: https://infosec.pub/post/2466014

    This is my first write-up, on a vulnerability I discovered in iTerm2 (RCE). Would love to hear opinions on this. I tried to make the writing engaging.

    /c/cybersecurity - Cybersecurity News & Discussion @lemmy.ml
    solidsnail @infosec.pub

    cross-posted from: https://infosec.pub/post/2466014

    This is my first write-up, on a vulnerability I discovered in iTerm2 (RCE). Would love to hear opinions on this. I tried to make the writing engaging.

    Security @programming.dev
    solidsnail @infosec.pub

    cross-posted from: https://infosec.pub/post/2466014

    This is my first write-up, on a vulnerability I discovered in iTerm2 (RCE). Would love to hear opinions on this. I tried to make the writing engaging.

    appsec @infosec.pub
    solidsnail @infosec.pub

    This is my first write-up, on a vulnerability I discovered in iTerm2 (RCE). Would love to hear opinions on this. I tried to make the writing engaging.

  • I think they're lacking explanation of what the data means.

    This can be very nuanced, and dependent on your goals.

    For example, in the context of fingerprinting, sometimes it's better to provide fake data instead of no data, because that itself can be a unique characteristic.