Normal view
-
ZDNet | security RSS
- I found the best Memorial Day phone deals, and it's your last chance to save big on a new device
Last chance for these Memorial Day TV deals at Amazon and Best Buy
-
ZDNet | security RSS
- One of the most user-friendly Linux distros I've ever used is also one of the most secure
One of the most user-friendly Linux distros I've ever used is also one of the most secure
-
The Register - Security
- MyPillow must decide whether to be firm or soft as ransomware crims demand pay
MyPillow must decide whether to be firm or soft as ransomware crims demand pay
Internet Starts to Return in Iran After 3-Month Blackout
-
ZDNet | security RSS
- I built my own Wi-Fi router with a Raspberry Pi for Starlink and solar control - here's how
I built my own Wi-Fi router with a Raspberry Pi for Starlink and solar control - here's how
-
ZDNet | security RSS
- I've used Chrome, Edge, and Safari for years - here's why Firefox is the better browser for most people
I've used Chrome, Edge, and Safari for years - here's why Firefox is the better browser for most people
-
/r/netsec - Information Security News & Discussion
- Navigating Lax Load Balancers: When an Intersection Gets You Inside
Navigating Lax Load Balancers: When an Intersection Gets You Inside
I quit ChatGPT for a free, private, and local AI called Ollama - here's why
MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries
-
ZDNet | security RSS
- I compared the 100x zoom cameras on Samsung, Google, and Motorola phones - this model won
I compared the 100x zoom cameras on Samsung, Google, and Motorola phones - this model won
-
/r/netsec - Information Security News & Discussion
- Encrypted DNS in 2026: DoH, DoT, DoQ and DoH3 protocol comparison โ including DNS hijacking attack vectors and what each protocol actually prevents
Encrypted DNS in 2026: DoH, DoT, DoQ and DoH3 protocol comparison โ including DNS hijacking attack vectors and what each protocol actually prevents
The security angle on encrypted DNS is often oversimplified. DoH prevents ISP-level snooping and basic DNS hijacking, but doesn't protect against a compromised resolver. DoT is easier to detect and block, which has real implications for threat actors trying to exfiltrate via DNS. DoQ is interesting from a security perspective because QUIC's connection ID migration makes traffic correlation harder. Article includes benchmark data and practical server config โ but mostly written for the "which threat model does each protocol address" question.
[link] [comments]
-
/r/netsec - Information Security News & Discussion
- OTP lockout state leaked valid-code signal, enabling OLX account takeover
OTP lockout state leaked valid-code signal, enabling OLX account takeover
I published a technical write-up on an old OLX account takeover issue.
The core bug was an OTP correctness leak inside the rate-limit state.
After repeated invalid OTP attempts, the application showed a lockout message. However, blocked submissions did not become response-equivalent.
Invalid codes during lockout still produced the invalid-code signal.
The valid code during lockout removed that signal while keeping the lockout message.
That made the lockout state act as an oracle for whether the OTP was correct.
The broader impact came from reuse of the verification flow across account paths, including recovery/reset-style flows, plus weak session revocation behavior after password change.
The write-up focuses on the response-difference behavior, why the validity window mattered, how the issue escalated to account takeover, and why lockout states must stop leaking success/failure information.
[link] [comments]
-
ZDNet | security RSS
- I found the best Memorial Day Apple deals still available: Save on iPad, Apple Watch, and more
I found the best Memorial Day Apple deals still available: Save on iPad, Apple Watch, and more
-
ZDNet | security RSS
- Last chance on Memorial Day laptop deals: Save on Apple, Dell, Lenovo, and more
Last chance on Memorial Day laptop deals: Save on Apple, Dell, Lenovo, and more
How I make my solar panels last long enough to pay for themselves
-
ZDNet | security RSS
- Avoid these 8 solar mistakes that cut your power output in half - I learned the hard way
Avoid these 8 solar mistakes that cut your power output in half - I learned the hard way
-
ZDNet | security RSS
- I wore Google's Fitbit Air for a week, and it gives the Whoop a serious run for its money
I wore Google's Fitbit Air for a week, and it gives the Whoop a serious run for its money
-
/r/netsec - Information Security News & Discussion
- Analyzing the Taiwan High-Speed Rail (THSR) TETRA incident (part 1)
Analyzing the Taiwan High-Speed Rail (THSR) TETRA incident (part 1)
Experts pour cold borscht on Farage's Russian hack claim