udunadan
An open-eyed man falling into the well of weird warring state machines. I mostly speak on (offensive) cybersecurity issues.
- 82 Posts
- 15 Comments
udunadan@infosec.pubOPMtoExploit Development@infosec.pub•[Chrome ITW sandbox escape] Integer overflow in SkSLVMCodeGenerator (skia)English2·2 years agoAbsolutely no problem, happy if you liked it!
udunadan@infosec.pubOPMtoExploit Development@infosec.pub•[Chrome ITW sandbox escape] Integer overflow in SkSLVMCodeGenerator (skia)English1·2 years agoThe issue had been made public only on July 25. The point of sharing the bug isn’t notifying users to patch their browsers but to inform browser vulnerability researchers of a valuable data point.
udunadan@infosec.pubOPMtoExploit Development@infosec.pub•CVE-2023-2033: Chrome [0-day] JIT optimisation issueEnglish2·2 years agoIt was an ITW 0-day at the moment of reporting and has probably retained the issue header from back then which I had copied.
udunadan@infosec.pubOPMtoExploit Development@infosec.pub•TALOS-2023-1757 Foxit Reader Field OnBlur event use-after-free vulnerabilityEnglish1·2 years agoA bunch of other Foxit vulns here: https://talosintelligence.com/vulnerability_reports
udunadan@infosec.pubOPMtoExploit Development@infosec.pub•Fuzzing a Pixel 3a Kernel with SyzkallerEnglish2·2 years agoPopped up on my Twitter feed somewhere
udunadan@infosec.pubtoDiscussions related to Infosec.pub@infosec.pub•Lemmy Security Vulnerability: XSS In the WildEnglish1·2 years agoThanks for notifying us!
udunadan@infosec.pubto Asklemmy@lemmy.ml•Reddit Refugees on Lemmy, how are you guys liking lemmy so far?English6·2 years agoThe content is really bounded by tech stuff, but I guess that’s due to migration being important for tech-savvy users. It is true that appending “reddit” to search queries and following the results is still inevitable (but hey, libreddit and teddit still work). But vibe is completely different, very organic, very active, I like it a lot. I think there is a lot of potential in this feeling of authentic communication. Let’s hope it grows.
Lemmy is much better replacement for Reddit than Mastodon is for Twitter.
udunadan@infosec.pubtoDiscussions related to Infosec.pub@infosec.pub•Lemmy Security Vulnerability: XSS In the WildEnglish1·2 years agodeleted by creator
udunadan@infosec.pubtoDiscussions related to Infosec.pub@infosec.pub•This is Fine: Optimism & Emergency in the P2P NetworkEnglish5·2 years agoWell, the malicious actors can setup their own instances as well and exploit the inherent trust between the participants by design. P2P sold as security property in the scenario where participants are unknown and multiple in numbers is misconception. It does not square well with basic security mindfulness, and shouldn’t be taken as improvement in that regard.
I think that federation and all this stuff is not about improving security, it is a form of grassroots communication based on certain principles. If you need security, you use other tools, and treat these things as public, hostile spaces.
udunadan@infosec.pubto cybersecurity@infosec.pub•What are you working on WednesdayEnglish1·2 years agodeleted by creator
udunadan@infosec.pubtoDiscussions related to Infosec.pub@infosec.pub•Threadiversal Travel - A guide for Lemmy, Kbin and general Reddit off-rampingEnglish5·2 years agoSuch guides should probably warn that instances run by volunteers do not have dedicated security teams and that OPSEC has to be adjusted accordingly. Not that centralized services are essentially safer (they are juicier targets), but nevertheless it is still important to remember.
udunadan@infosec.pubtoDiscussions related to Infosec.pub@infosec.pub•Apologies for the problemsEnglish4·2 years agoThanks, Jerry!
udunadan@infosec.pubto cybersecurity@infosec.pub•Future of /c/cybersecurity and thoughts/suggestions for the community.English3·2 years agoI plan to spend time solely on this instance. I’m not interested in anything else in terms of anything involving both r/w or just w kind of access (for general questions requiring googling I still go to reddit). I don’t think there is a need in other instances if your interests are niche (like infosec). I’m more than satisfied with what I see here and I hope to keep it this way. It is a viable alternative to /r/netsec, but maybe as an aggregator, not a platform for feedback.
udunadan@infosec.pubtoDiscussions related to Infosec.pub@infosec.pub•trouble commenting on any federated threadEnglish1·2 years agoSame same.
udunadan@infosec.pubtoSecurity News@infosec.pub•Reddit hackers threaten to leak data.English3·2 years agoIt’s a spam, appeared in /c/exploitdev as well.
udunadan@infosec.pubtoDiscussions related to Infosec.pub@infosec.pub•Security & privacy on this instance / lemmy as a whole?English1·2 years agoUse Signal, use Tor, as they say.
Glad to be of use!