There's so much I don't understand in Dashlane's disclosure that an attack on its user accounts resulted in the threat actor obtaining 20 encrypted vaults.
What does it mean to brute force 2fa? Are we talking about TOTPs? That doesn't make sense because TOTPs change every 30-90 seconds, so there's no way for an attacker to meaningfully exhaust key space before it resets all over -- unless the attacker has the ability to pump all 7,700 combinations in <90 seconds, and DL doesn't have any sort of rate limiting.
Also, if the attacker is brute forcing 2fa, doesn't that by necessity mean the attacker already defeated the first factor? How did that occur?
I don't know if my confusion is the result of me not knowing the how the Dashlane product works or if it's just Dashlane being opaque.
Wow, the cynicism in this thread is off the charts. Google's aggressive accelleration of its internal PQC deadline has gotten the attention of a bunch of very smart people working in the field. You may think it's propaganda, but lots of us are wondering what Google knows is coming down the pike that the rest of us don't. It'd be an error to let this development go unreported.
Wow, TeamPCP is hacking open-source developers faster than we can report on them. The latest (that I'm aware of, anyway) is LiteLLM. They worked with Trivy but didn't bother to change their credentials after Trivy was hacked, despite an ample amount of advice to do so.
Folks, if any of you used LiteLLM, now is the time to change your credentials, in an atomic way. Now, as in immediately.
Tire pressure "transmissions are sent without any encryption or secure mechanisms and include a unique identifier. This allows anyone with affordable equipment like a low-cost spectrum receiver and a standard off-the-shelf antenna to capture and track them throughout time and space."
I'm curious to know what people think about Anthropic's claim that Claude found 500 high-severity vulnerabilities in open-source packages. Has anyone confirmed that these vulns were indeed high-severity and hadn't been discovered before? Is this development as big a deal as Anthropic says? Any other critiques?
I appreciate everyone who has taken time to respond. Unfortunately, some of the responses demonstrate how much many of us privacy-minded technologists live in ivory towers and have no idea how hard it is to get the rest of the world to take on the added friction of switching.
Even people with the most to lose continue to support and rely heavily on:
-- Google -- Slack -- Meta -- Microsoft -- Apple -- Too many others to list
These orgs cozy up to authoritarianism. They terminate your account for any reason or no reaso at all. They shove AI down your throat.
And yet, my workplace, union, and so many of the orgs I value and need keep using them and have no plans to ween themselves off. Yes, I realize current dynamics make all of this inevitable.
So I'm left feeling hopeless and helpless, which is a terrible place to be.
A techbro desperate for cash is detained for 13 hours after leaving a non-functioning, vibe-coded anti-fraud device in a Swiss hotel lobby during the Davos conf
The International Association of Cryptologic Research has cancelled the results of its annual leadership election after an official lost an encryption key needed to unlock results stored in a "hyper-secure election system."
Microsoft says in the post (see toot above) that the agent isn't enabled by default and that only experienced users should enable it. What are these users to do to prevent the attacks Microsoft is warning of?
"Additionally, agentic AI applications introduce novel security risks, such as cross-prompt injection (XPIA), where malicious content embedded in UI elements or documents can override agent instructions, leading to unintended actions like data exfiltration or malware installation."