home.social

#blackhat2024 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #blackhat2024, aggregated by home.social.

fetched live
  1. #Signal #Developer Explains Why Early Encrypted Messaging Tools Flopped
    #MoxieMarlinspike criticized early #encryption software's user-unfriendly design at #BlackHat2024, admitting he and others initially failed to consider non-technical users' needs. Speaking with #BlackHat founder #JeffMoss, He said tools like #PrettyGoodPrivacy (#PGP) wrongly assumed users would adopt complex practices like keyservers and signing keys over dinner. "We were just wrong," Marlinspike said
    pcmag.com/news/signal-develope

  2. #Signal #Developer Explains Why Early Encrypted Messaging Tools Flopped
    #MoxieMarlinspike criticized early #encryption software's user-unfriendly design at #BlackHat2024, admitting he and others initially failed to consider non-technical users' needs. Speaking with #BlackHat founder #JeffMoss, He said tools like #PrettyGoodPrivacy (#PGP) wrongly assumed users would adopt complex practices like keyservers and signing keys over dinner. "We were just wrong," Marlinspike said
    pcmag.com/news/signal-develope

  3. Explains Why Early Encrypted Messaging Tools Flopped
    criticized early software's user-unfriendly design at , admitting he and others initially failed to consider non-technical users' needs. Speaking with founder , He said tools like (#PGP) wrongly assumed users would adopt complex practices like keyservers and signing keys over dinner. "We were just wrong," Marlinspike said
    pcmag.com/news/signal-develope

  4. #Signal #Developer Explains Why Early Encrypted Messaging Tools Flopped
    #MoxieMarlinspike criticized early #encryption software's user-unfriendly design at #BlackHat2024, admitting he and others initially failed to consider non-technical users' needs. Speaking with #BlackHat founder #JeffMoss, He said tools like #PrettyGoodPrivacy (#PGP) wrongly assumed users would adopt complex practices like keyservers and signing keys over dinner. "We were just wrong," Marlinspike said
    pcmag.com/news/signal-develope

  5. #Signal #Developer Explains Why Early Encrypted Messaging Tools Flopped
    #MoxieMarlinspike criticized early #encryption software's user-unfriendly design at #BlackHat2024, admitting he and others initially failed to consider non-technical users' needs. Speaking with #BlackHat founder #JeffMoss, He said tools like #PrettyGoodPrivacy (#PGP) wrongly assumed users would adopt complex practices like keyservers and signing keys over dinner. "We were just wrong," Marlinspike said
    pcmag.com/news/signal-develope

  6. Orange Tsai's Black Hat USA 2024 research revealed architectural vulnerabilities in Apache HTTP Server, identifying three types of "Confusion Attacks" exploiting inconsistencies between Httpd modules.

    These led to 9 new vulnerabilities and 20 exploitation techniques, including bypassing access controls and arbitrary file access outside the web root. The findings highlight challenges in balancing backward compatibility with security in long-standing open-source projects.

    Akamai proactively collaborated with Tsai before his presentation, implementing preemptive protections against these vulnerabilities in their App & API Protector web application firewall service.

    Orange Tsai's Research findings: blog.orange.tw/2024/08/confusi

    Blackhat Presentation: i.blackhat.com/BH-US-24/Presen

    Akami acknowledgement and mitigations: akamai.com/blog/security-resea

    #infosec #blackhat2024 #cybersecurity #apache

  7. Orange Tsai's Black Hat USA 2024 research revealed architectural vulnerabilities in Apache HTTP Server, identifying three types of "Confusion Attacks" exploiting inconsistencies between Httpd modules.

    These led to 9 new vulnerabilities and 20 exploitation techniques, including bypassing access controls and arbitrary file access outside the web root. The findings highlight challenges in balancing backward compatibility with security in long-standing open-source projects.

    Akamai proactively collaborated with Tsai before his presentation, implementing preemptive protections against these vulnerabilities in their App & API Protector web application firewall service.

    Orange Tsai's Research findings: blog.orange.tw/2024/08/confusi

    Blackhat Presentation: i.blackhat.com/BH-US-24/Presen

    Akami acknowledgement and mitigations: akamai.com/blog/security-resea

    #infosec #blackhat2024 #cybersecurity #apache

  8. Orange Tsai's Black Hat USA 2024 research revealed architectural vulnerabilities in Apache HTTP Server, identifying three types of "Confusion Attacks" exploiting inconsistencies between Httpd modules.

    These led to 9 new vulnerabilities and 20 exploitation techniques, including bypassing access controls and arbitrary file access outside the web root. The findings highlight challenges in balancing backward compatibility with security in long-standing open-source projects.

    Akamai proactively collaborated with Tsai before his presentation, implementing preemptive protections against these vulnerabilities in their App & API Protector web application firewall service.

    Orange Tsai's Research findings: blog.orange.tw/2024/08/confusi

    Blackhat Presentation: i.blackhat.com/BH-US-24/Presen

    Akami acknowledgement and mitigations: akamai.com/blog/security-resea

    #infosec #blackhat2024 #cybersecurity #apache

  9. Orange Tsai's Black Hat USA 2024 research revealed architectural vulnerabilities in Apache HTTP Server, identifying three types of "Confusion Attacks" exploiting inconsistencies between Httpd modules.

    These led to 9 new vulnerabilities and 20 exploitation techniques, including bypassing access controls and arbitrary file access outside the web root. The findings highlight challenges in balancing backward compatibility with security in long-standing open-source projects.

    Akamai proactively collaborated with Tsai before his presentation, implementing preemptive protections against these vulnerabilities in their App & API Protector web application firewall service.

    Orange Tsai's Research findings: blog.orange.tw/2024/08/confusi

    Blackhat Presentation: i.blackhat.com/BH-US-24/Presen

    Akami acknowledgement and mitigations: akamai.com/blog/security-resea

    #infosec #blackhat2024 #cybersecurity #apache

  10. Orange Tsai's Black Hat USA 2024 research revealed architectural vulnerabilities in Apache HTTP Server, identifying three types of "Confusion Attacks" exploiting inconsistencies between Httpd modules.

    These led to 9 new vulnerabilities and 20 exploitation techniques, including bypassing access controls and arbitrary file access outside the web root. The findings highlight challenges in balancing backward compatibility with security in long-standing open-source projects.

    Akamai proactively collaborated with Tsai before his presentation, implementing preemptive protections against these vulnerabilities in their App & API Protector web application firewall service.

    Orange Tsai's Research findings: blog.orange.tw/2024/08/confusi

    Blackhat Presentation: i.blackhat.com/BH-US-24/Presen

    Akami acknowledgement and mitigations: akamai.com/blog/security-resea

    #infosec #blackhat2024 #cybersecurity #apache

  11. Blue teamers attending #defcon2024 #blackhat2024 : YEA! AWESOME!

    Blue teamers not attending: Ugh...all these new vulns...

  12. Blue teamers attending #defcon2024 #blackhat2024 : YEA! AWESOME!

    Blue teamers not attending: Ugh...all these new vulns...

  13. Blue teamers attending #defcon2024 #blackhat2024 : YEA! AWESOME!

    Blue teamers not attending: Ugh...all these new vulns...

  14. Braving the heat for #BlackHat2024? Come find EFF in the Business Hall! We’re in the 4400 section in the AI Zone 🤖 eff.org/event/eff-black-hat-us