https://sgued.fr/blog/need-csrf-token/

You should still use CSRF tokens. SameSite is not the same definition as Cross-Origin, so SameSite=Lax does not protect from CSRF coming from a "neighbor" subdomain.

#Security #CyperSecurity #CSRF #WebSecurity

You should still use CSRF tokens

You may think that thanks to cookies being set to SameSite=Lax by default, CSRF (Cross-Site Request Forgery) is mostly a solved problem, but It's not and CSRF tokens are still good practice to implement.

SGued

W.r.t #ArcBrowser leaking user information and permitting JavaScript injection over their backend, a thought that just struck me:

Also more generally I must remark - okay, so you have all of these fancy social browser features. So far so understandable.

Why exactly is this wrapped in a giant pull-all-the-time paradigm instead of pushing local updates to people and having their browsers run queries for important information locally?

#cypersecurity and #webdev

I can't wrap my head around how almost all of the #xz reporting focuses on the failures of #opensource.
Yeah, sure, but ...

Good luck finding such an attack in proprietary code.
Via the cliché paid off/blackmailed employee, hacked dev servers/repos, or via capitalism's favorite cost-cutting measure: a remote "offshored" contracted temporary developer (or nowadays, embedded into some LLM output).

If anything, Open Source Security has *worked*.

#cypersecurity #OSS

Microsoft is being hacked and nobody cares. There are no consequences. If you rely on #Linux and #foss and it goes wrong, it's your fault. If you rely on #Microsoft and it goes wrong, it's Microsoft's fault. Win-win.

#cypersecurity #cozybear

https://msrc.microsoft.com/blog/2024/03/update-on-microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/

Update on Microsoft Actions Following Attack by Nation State Actor Midnight Blizzard | MSRC Blog | Microsoft Security Response Center

Update on Microsoft Actions Following Attack by Nation State Actor Midnight Blizzard

FBI, UK National Crime Agency Say They Have Disrupted LockBit Hacking Gang

A coalition of international law enforcement agencies, including the FBI and UK National Crime Agency, said they have disrupted LockBit, one of the most prolific hacker groups of all time, including shutting down websites the organization used for ransomware payments.

Bloomberg

MoD cybersecurity worst in Whitehall, figures reveal

The UK Ministry of Defence has by far the worst protected IT systems of any Whitehall department, with 11 "red-rated" systems.

https://www.computing.co.uk/news/4161325/mod-cybersecurity-worst-whitehall-figures-reveal

#uk #technews #cni #mod #infosec #cypersecurity #ukpol #ukgov

MoD cybersecurity worst in Whitehall, figures reveal

The UK Ministry of Defence has by far the worst protected IT systems of any Whitehall department, with 11 "red-rated" systems.

So Weihnachten sitzen alle zusammen und lösen #sudoku und ich lese ein paper wie Informatiker sodoku lösen...

Ach und ich schaue mir verschiedene #fernstudiums UniversitÀten an

Kann jemand eine fĂŒr #bachelor #Cypersecurity empfehlen :P

Just saw that there is currently a No Starch press HumbleBundle deal. Never bought one before, but this one looks interesting. Anybody has some experience or opinions?

https://www.humblebundle.com/books/hacking-2023-no-starch-books

#cypersecurity #ebook #ethicalhacking

Humble Tech Book Bundle: Hacking 2023 by No Starch

Learn about the art and science of hacking with this library of tech ebooks. Pay what you want & support charity!

Humble Bundle