GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    buherator (buherator@infosec.place)'s status on Thursday, 13-Feb-2025 23:40:53 JST buherator buherator
    Re: CVE-2025-0108

    Can we agree that "X-Trust-Me-Bro: $boolean" headers set by reverse proxies are an anti-pattern?

    If so, what is the best practice?
    In conversation about 4 months ago from infosec.place permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Thursday, 13-Feb-2025 23:40:52 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to

      @buherator Just encode the data with a JWT.

      (lest anyone take this seriously, I am shitposting here...)

      In conversation about 4 months ago permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Friday, 14-Feb-2025 00:31:52 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to

      @buherator JWT being a great complex insecure solution 😁

      In conversation about 4 months ago permalink
    • Embed this notice
      buherator (buherator@infosec.place)'s status on Friday, 14-Feb-2025 00:31:53 JST buherator buherator
      in reply to
      • Ryan Castellucci :nonbinary_flag:
      @ryanc I was actually thinking whether some (not so) fancy crypto could be used to pass some instead of a bool that the attacker can't forge, then realized reverse proxy configs are not exactly designed to implement such transformations in the first place :)

      Nonetheless, this is an illustrative example that unless we point to some robust solution ppl *will* come up with complex but insecure solutions (see also Schneier's Law).
      In conversation about 4 months ago permalink
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Friday, 14-Feb-2025 01:09:28 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to

      @buherator lulz driven development

      In conversation about 4 months ago permalink
    • Embed this notice
      buherator (buherator@infosec.place)'s status on Friday, 14-Feb-2025 01:09:29 JST buherator buherator
      in reply to
      • Ryan Castellucci :nonbinary_flag:
      @ryanc X-Trust-Me-Bro: {"alg":"nOnE"...} vulns would be pretty funny actually :) let's hope we'll never get there though...
      In conversation about 4 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.