Topics - Deozaan [ switch to compact view ]

Pages: prev1 ... 20 21 22 23 24 [25] 26 27 28 29 30 ... 93next
121
I (mostly) stopped using LastPass a couple years ago for reasons unrelated to this, but it seems multiple password-leaking vulnerabilities (and other dangerous exploits) have been discovered recently:

LastPass works by storing your passwords in the cloud. It provides browser extensions that connect to your LastPass account and automatically fill out your saved login details when you surf to your favorite sites.

However, due to the discovered vulnerabilities, simply browsing a malicious website would be enough to hand over all your LastPass passphrases to strangers. The weak LastPass script uncovered by Ormandy could be exploited by tricking it into granting access to the manager's internal data. It can also be potentially abused to execute commands on the victim's computer – Ormandy demonstrated this by running calc.exe simply by opening a webpage.

Even though I no longer use LastPass for new passwords, my account still has many old passwords I haven't updated in a while, and I have kept the extension installed because of that, since it seems to work more reliably than the extension for the password manager I switched to. So maybe it's time for me to fully ditch LastPass.

122
General Software Discussion / XYplorer is not responding.
« on: March 14, 2017, 09:20 PM »
NOTE: This thread was originally a reply in the Windows now has banner ads thread, and was moved here in an attempt to keep that other thread on topic. The original conversation is below:



But maybe it's time to re-evaluate XYplorer and see what all the hubbub is about.

Nope. I still can't do XYplorer. It frequently locks up on me for several seconds at a time.

123
General Software Discussion / Windows Explorer now has banner ads
« on: March 11, 2017, 02:27 PM »
I opened up Windows Explorer just now and was greeted by this:

Windows Explorer Ad.png

124
Cloudflare released an incident report detailing a recent discovery and patching of a bug which leaked data in rare instances. This leaked data includes passwords and other sensitive information.

Virtually every site that uses Cloudflare was possibly affected, meaning that basically you should change your passwords everywhere and make sure you have 2FA enabled where possible. EDIT: See further replies to this thread for clarification on potentially affected sites.

I'm on mobile so it's too much work for me to make things pretty right now, but here are pertinent links:

Cloudflare incident report: https://blog.cloudflare.com/incident-report-on-memory-leak-caused-by-cloudflare-parser-bug/

List of sites (possibly) affected: https://github.com/pirate/sites-using-cloudflare

125
Living Room / SHA1 is dead - First known collision exploit discovered
« on: February 23, 2017, 06:53 PM »
Cryptographers refer to the attack disclosed Thursday as an "identical-prefix" collision, meaning it allows the attacker to create two distinct messages that have the same hash value. This variety is less powerful than the "chosen-prefix" MD5 collision carried out by Flame. In the latter case, attackers can target one or more existing files, such as the digital certificate that a company uses to authenticate its update mechanism. Despite the collision against SHA1 being less powerful, cryptography experts said any real-world identical-prefix attack represented a game-over event for a hashing function.

"In crypto we have the idea that hash function collisions should be really hard to find, even if they're 'useless,'" said Johns Hopkins University professor Matt Green, speaking generally about collisions before he learned the specifics of the new SHA1 attack. A real-world collision attack "is the equivalent of finding out that your scalpel wasn't sterilized properly. It may not verifiably have germs on it, but the whole instrument is considered unsafe."

Read more here:
https://arstechnica.com/security/2017/02/at-deaths-door-for-years-widely-used-sha1-function-is-now-dead/

Pages: prev1 ... 20 21 22 23 24 [25] 26 27 28 29 30 ... 93next
Go to full version