#insecurebydesign — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #insecurebydesign, aggregated by home.social.
-
Fun times, if I'm reading this right #minio decided to stop publishing new docker images one day before releasing their CVSS 8.8 privilege escalation.
I understand the VC's want their money back but making it hard for people to do security upgrades must be one of top ways to put your company valuation on fire.
Ok if the decision was made beforehand. But this is software, you can always walk back things.
https://github.com/minio/minio/issues/21647
https://github.com/minio/minio/releases/tag/RELEASE.2025-10-15T17-29-55Z
-
Fun times, if I'm reading this right #minio decided to stop publishing new docker images one day before releasing their CVSS 8.8 privilege escalation.
I understand the VC's want their money back but making it hard for people to do security upgrades must be one of top ways to put your company valuation on fire.
Ok if the decision was made beforehand. But this is software, you can always walk back things.
https://github.com/minio/minio/issues/21647
https://github.com/minio/minio/releases/tag/RELEASE.2025-10-15T17-29-55Z
-
The same company that got a lot of companies pwned when they left gaping holes in their MOVEit software is back at it, this time with a completely exploitable ftp server.
The only solution here is for this company's customers to sue it out of existence. They clearly don't know what they're doing. #infosec #insecurebydesign
https://arstechnica.com/security/2023/10/active-attacks-exploiting-ws_ftp-pose-a-grave-threat-to-the-internet/ -
The same company that got a lot of companies pwned when they left gaping holes in their MOVEit software is back at it, this time with a completely exploitable ftp server.
The only solution here is for this company's customers to sue it out of existence. They clearly don't know what they're doing. #infosec #insecurebydesign
https://arstechnica.com/security/2023/10/active-attacks-exploiting-ws_ftp-pose-a-grave-threat-to-the-internet/ -
@Nitchevo j'ai réglé le problème : j'ai copié ma clé privée dans un message 'important' sur gmail et j'utilise le gestionnaire de mots de passe intégré à chrome pour me connecter, comme ça pas besoin de m'en souvenir quand je suis chez des copains...
#SecurityBasics #InsecureByDesign -
Gosh, this is one of my pet peeves. Bad job #Hallmark for enforcing a MAXIMUM password length of 15 characters.
-
Gosh, this is one of my pet peeves. Bad job #Hallmark for enforcing a MAXIMUM password length of 15 characters.
-
It's depressing how many popular packages getting started guides include piping curl output directly to a shell.
That's the quickest way I lose trust in a package. #InsecureByDesign