🦞🌯 Lobster Roll

All LHN/.~Ars
RSS

Showing stories from 2024-09. View all

NewestOldestTop ScoredMost Discussed
Meet DAVE: Discord’s new end-to-end encryption for audio and video (discord.com)
Meet DAVE: Discord’s New End-to-End Encryption for Audio & Video (discord.com)
Update on Native Matrix interoperability with WhatsApp (matrix.org)
Cellguard: Analyze and observe cellular networks to detect surveillance (cellguard.seemoo.de)
Race conditions in Linux Kernel perf events (binarygecko.com)
Fuzzers vs Games (addisoncrump.info)
Inside Elon Musk’s mushrooming security apparatus (nytimes.com)
Web Security Basics (with htmx) (htmx.org)
pyrtls: rustls-based modern TLS for Python (github.com)
Zero-Click Calendar invite — Critical zero-click vulnerability chain in macOS (mikko-kenttala.medium.com)
FreeBSD 11.0+ Kernel LPE: Userspace Mutexes (umtx) Use-After-Free Race Condition (accessvector.net)
Specification and Model-checking of the ZKsync Governance Protocol (protocols-made-fun.com)
Friends don’t let friends reuse nonces (blog.trailofbits.com)
Microsoft Windows MSI Installer - Repair to SYSTEM - A detailed journey (sec-consult.com)
Vulnerability Disclosure of Feeld (dating app) (fortbridge.co.uk)
GoFetch: Will people ever learn? (microkerneldude.org)
The Mines of Kakadûm (bughunters.google.com)
We spent $20 to achieve RCE and accidentally became the admins of .MOBI (labs.watchtowr.com)
The “email is authentication” pattern (rubenerd.com)
OpenSSH Keystroke Obfuscation Bypass (crzphil.github.io)
Signatures are like backups (alexgaynor.net)
Deep Dive into RCU Race Condition: Analysis of TCP-AO UAF (CVE-2024–27394) (blog.theori.io)
Data security help - SOC2ish
Nix 2.24+ is vulnerable to (remote) privilege escalation (puckipedia.com)
Nobody Cares About Security (adatosystems.com)
The Insecurity of Debian (unix.foo)
Build a simple fuzzer: Part 1 (carstein.github.io)
Baiting the bot (conspirator0.substack.com)
Cracking an old ZIP file to help open source the ANC's "Operation Vula" secret crypto code (blog.jgc.org)
Navy chiefs conspired to get themselves illegal warship Wi-Fi (navytimes.com)
also: [ArsTechnica](https://arstechnica.com/security/2024/09/sailors-hid-an-unauthorized-starlink-on-the-deck-of-a-us-warship-and-lied-about-it/)