Christ is my all
1808 stories
·
3 followers

Biden Announces Plan To Win Over Young Voters By Getting Rid Of Blockbuster Movie Rental Late Fees

1 Share

WASHINGTON, D.C. β€” In a bold move aimed at tackling one of the most pressing issues facing the next generation, President Biden has unveiled his latest executive action: a plan to eliminate late fees for Blockbuster movie rentals.

Read the whole story
rtreborb
2 days ago
reply
San Antonio, TX
Share this story
Delete

College admissions

1 Share
Read the whole story
rtreborb
2 days ago
reply
San Antonio, TX
Share this story
Delete

Security Vulnerability of HTML Emails

1 Comment and 3 Shares

This is a newly discovered email vulnerability:

The email your manager received and forwarded to you was something completely innocent, such as a potential customer asking a few questions. All that email was supposed to achieve was being forwarded to you. However, the moment the email appeared in your inbox, it changed. The innocent pretext disappeared and the real phishing email became visible. A phishing email you had to trust because you knew the sender and they even confirmed that they had forwarded it to you.

This attack is possible because most email clients allow CSS to be used to style HTML emails. When an email is forwarded, the position of the original email in the DOM usually changes, allowing for CSS rules to be selectively applied only when an email has been forwarded.

An attacker can use this to include elements in the email that appear or disappear depending on the context in which the email is viewed. Because they are usually invisible, only appear in certain circumstances, and can be used for all sorts of mischief, I’ll refer to these elements as kobold letters, after the elusive sprites of mythology.

I can certainly imagine the possibilities.

Read the whole story
rtreborb
7 days ago
reply
San Antonio, TX
Share this story
Delete
1 public comment
freeAgent
7 days ago
reply
Make email text again.
Los Angeles, CA

Trump Says His Position On Abortion Is Whichever One Will Get Him Elected

1 Share

PALM BEACH, FL β€” In a brilliant political maneuver designed to ensure he wins the election, former President Donald Trump said his position on abortion is whichever one will get him elected.

Read the whole story
rtreborb
7 days ago
reply
San Antonio, TX
Share this story
Delete

Pope Francis issues strong statements opposing gender transition, surrogacy, and abortion

1 Share

I am pleased to report that we have a rare Pope Francis W.

Read the whole story
rtreborb
7 days ago
reply
San Antonio, TX
Share this story
Delete

xz Utils Backdoor

3 Shares

The cybersecurity world got really lucky last week. An intentionally placed backdoor in xz Utils, an open-source compression utility, was pretty much accidentally discovered by a Microsoft engineer—weeks before it would have been incorporated into both Debian and Red Hat Linux. From ArsTehnica:

Malicious code added to xz Utils versions 5.6.0 and 5.6.1 modified the way the software functions. The backdoor manipulated sshd, the executable file used to make remote SSH connections. Anyone in possession of a predetermined encryption key could stash any code of their choice in an SSH login certificate, upload it, and execute it on the backdoored device. No one has actually seen code uploaded, so it’s not known what code the attacker planned to run. In theory, the code could allow for just about anything, including stealing encryption keys or installing malware.

It was an incredibly complex backdoor. Installing it was a multi-year process that seems to have involved social engineering the lone unpaid engineer in charge of the utility. More from ArsTechnica:

In 2021, someone with the username JiaT75 made their first known commit to an open source project. In retrospect, the change to the libarchive project is suspicious, because it replaced the safe_fprint function with a variant that has long been recognized as less secure. No one noticed at the time.

The following year, JiaT75 submitted a patch over the xz Utils mailing list, and, almost immediately, a never-before-seen participant named Jigar Kumar joined the discussion and argued that Lasse Collin, the longtime maintainer of xz Utils, hadn’t been updating the software often or fast enough. Kumar, with the support of Dennis Ens and several other people who had never had a presence on the list, pressured Collin to bring on an additional developer to maintain the project.

There’s a lot more. The sophistication of both the exploit and the process to get it into the software project scream nation-state operation. It’s reminiscent of Solar Winds, although (1) it would have been much, much worse, and (2) we got really, really lucky.

I simply don’t believe this was the only attempt to slip a backdoor into a critical piece of Internet software, either closed source or open source. Given how lucky we were to detect this one, I believe this kind of operation has been successful in the past. We simply have to stop building our critical national infrastructure on top of random software libraries managed by lone unpaid distracted—or worse—individuals.

Another explainer.

Read the whole story
rtreborb
7 days ago
reply
San Antonio, TX
Share this story
Delete
Next Page of Stories