26 Followers
80 Following
48 Posts
I try to security. Cat dad, enthusiast of all things car.

Oh boy. Apparently things are not good at Delinea around Thycotic. I just checked and the cloud version appears to be patched for this - after security incident.

https://straightblast.medium.com/all-your-secrets-are-belong-to-us-a-delinea-secret-server-authn-authz-bypass-adc26c800ad3

#threatintel

“All Your Secrets Are Belong To Us” — A Delinea Secret Server AuthN/AuthZ Bypass

Delinea Secret Server is a privileged access management (PAM) solution that helps organizations secure, manage, and monitor privileged accounts and access across their IT infrastructure. Accessing…

Medium

@GossiTheDog Expanding on the Delinea issue, it this is almost certainly related to a vulnerability they disclosed yesterday: https://trust.delinea.com/?tcuUid=17aaf4ef-ada9-46d5-bf97-abd3b07daae3

They're claiming that they've found no evidence of exploitation...so far anyway.

Delinea | Trust Center

See how Delinea manages their security program.

Delinea

Hey @GossiTheDog could be the beginning of a fun breach over at Delinea: https://status.delinea.com/

No idea how large their Cloud customer base is, but Secret Server would be a very valuable target...

I can’t tell you how angry this makes me feel for this maintainer.

I don’t know who Jigar Kumar is, or what the motivation was behind the emails that the author is referencing, but I can tell you if I was trying to get a bad actor in as a trusted developer, this is how I would approach it.

Good post.

https://robmensching.com/blog/posts/2024/03/30/a-microcosm-of-the-interactions-in-open-source-projects/

A Microcosm of the interactions in Open Source projects | RobMensching.com

Originally a thread on Twitter about the xz/liblzma vulnerability, when I finished typing it, I realized I had a real world slice of Open Source interaction that deserved more attention.

Apparently Meta has been contacting some instance admins about their plans for the fediverse. I am not sure whether to be happy or sad, but they didn’t contact me.

I am seeing a rift emerging in the fediverse that is a bit reminiscent of my own CISA episode back in November of 2022. At the time, the people who objected fell into two overlapping camps:

ACABs that couldn’t see past CISA’s placement in the DHS and simply object to the concept of any law enforcement affiliated person being on the fedi (NB: there are a LOT of them here and they’re all over the fediverse)

Instance admins that wanted to protect their constituents from the surveillance that comes along with DHS.

While the context is materially different, the Meta situation seems to come down on similar lines: conceptual rejection of Meta because of who Meta is; and a concern for the privacy of one’s fedi-data.

Regarding the former point, I think it is fundamental to the fediverse for people and instances to be able to pick who they want to participate with, almost for whatever reason. If there are people who really dislike bald guys, I’m one to block. The latter reason is more problematic. As with the DHS situation, Meta creating an account or an instance is really not an effective way to conduct a surveillance operation (either to send people to jail or to show them ads) - not on an infrastructure that has oodles of open APIs that make it far easier to collect data using direct connections vs creating an instance.

Said another way, the lack of a branded Meta or CISA account or instance is not an indication that such data extraction isn’t happening. We generally wouldn’t know if it were.

I’ve heard the “embrace/extend/extinguish” accusation about every 6 months in the 7+ years I’ve been here. The company that bought Pawoo was going to take over the fediverse. Medium was going to be installing paywalls and feeding ads across the fediverse. Vivaldi and Mozilla were going to bring so much trash into our timelines that we should just preemptively block them.

If I, or any instance admin, finds that Meta or any other company is surreptitiously collecting data from our instances, we will take action. I will highlight that suspending instances and accounts won’t be very effective here - we would have to implement firewall level blocks, assuming we can identify where they are coming from. And I doubt it will be coming from a branded instance. Sadly, even this is trivial to work around if they connect to a relay or set up an account on an instance that doesn’t isn’t blocked. The major concern, of course, is that your fedi data is linked to a record they maintain about you in their own databases, and then use your content to help tailor ads as you visit other parts of the internet.

If we identify that an instance is behaving badly, of course they are going to get suspended, just as happens today. But be aware that this only prevents YOU from seeing THEIR content. If Meta does set up an instance and start spamming out ads, that is exactly what will happen.

In the mean time, if you want to block Meta owned domains and instances who aren’t blocking Meta owned domains and instances who are not blocking instances who are not blocking meta owned domains, that’s ok.

For me, I am going to wait until I know more to make a decision.

One of the main tragedies of #Reddit decline is that it was one of the last big bulwarks against #SEO-driven enshittification of the web, which’ll only get worse now with LLMs.

I don’t want to know the 7 Best Soundbars for Gaming in 2023, I want to know if a Nintendo Switch can pass its 5.1 PCM signal through a TV and out via the HDMI eARC port fully intact.

Anyway, good article on what all this decline means: https://defector.com/the-last-page-of-the-internet

The Last Page Of The Internet | Defector

Gradually over the last decade, Reddit went from merely embarrassing but occasionally amusing, to actively harmful, to—mainly by accident—essential. As the platform that swallowed niche message boards, it became home to numerous small communities of surprisingly helpful enthusiasts, and grew into a repository of arcane knowledge about, and instantly available first-hand expertise on, a staggering […]

If your $dayjob is at all related to security, I'd love to hear from you about what type of mobile phone you currently rely on.

I've never really seen a data-based breakdown of the answer to this question, and I'm genuinely curious. Thanks!

p.s. if you vote, please also boost this poll!

iPhone
53.7%
Google Pixel
21.4%
Samsung
10.4%
Other Android
14.5%
Poll ended at .

May I have your attention, please? May I have your attention, please?

We are proud to announce the first release of the year 2023.

Please welcome ScummVM 2.7.0 – "The Real Slim Shader".

New games. New platforms. New bugfixes - and a new way to experience your games in a way you have either never seen before or at least not within the last 20 years.

https://www.scummvm.org/news/20230226/

#scummvm #retrogaming

ScummVM

ScummVM is a collection of game engines for playing classic graphical RPGs and point-and-click adventure games on modern hardware.

Just a heads up if you followed SANS on Twitter and were waiting for their Mastadon account to be created, here it is: @SANSInstituteOfficial

On Tuesday morning, the Supreme Court will be hearing oral arguments in Gonzalez v. Google, a Section 230 case that could radically change the Internet.

To prepare for it, start with my Section 230 primer: http://bit.ly/410TKMc

Then, read my amicus brief in the case: http://bit.ly/3ktalY0