🦞🌯 Lobster Roll

Thread

DNS security is a decades-old issue that shows no signs of being fully resolved. Here's a quick overview of some of the problems with proposed solutions and the best way to move forward. (hpe.com)

Stories related to "DNS security is a decades-old issue that shows no signs of being fully resolved. Here's a quick overview of some of the problems with proposed solutions and the best way to move forward." across the full archive.

DNS security is a decades-old issue that shows no signs of being fully resolved. Here's a quick overview of some of the problems with proposed solutions and the best way to move forward. (hpe.com)
New security issue affecting Java SE 7 Update 7 (full JVM sandbox bypass) (seclists.org)
Enhancing digital certificate security (fake *.google.com SSL cert issued) (googleonlinesecurity.blogspot.de)
Google Study Shows Security Questions Aren’t All That Secure (techcrunch.com)
goto fail; // exploring two decades of transport layer insecurity [32c3] (youtube.com)
Uncorrectable freedom and security issues on x86 platforms (mail.fsfeurope.org)
Tavis Ormandy: a critical security issue in a bathroom scale (twitter.com)
Major Remote SSH Security Issue in CoreOS Linux Alpha, Subset of Users Affected (coreos.com)
Freedom and privacy/security issues on mobile phones (replicant.us)
If you configure a program to run in Windows 2000 compatibility mode, then it is also vulnerable to Windows 2000 security issues (blogs.msdn.microsoft.com)
New Intel AMT Security Issue Lets Hackers Gain Full Control of Laptops in 30 Seconds (thehackernews.com)
New Samba Security Issue: Authenticated Users Can Change Anyone's Password (samba.org)
Follow-up: Configuration files as a canary for security issues
A little over a year ago I posted a story called ["Configuration files are a canary, warning us of potential security issues"](https://lobste.rs/s/to8wpr/configuration_files_are_canary_warning). My basic argument was that it was fundamentally bad for security to have people growing software stacks b...
Software Security is a Programming Languages Issue (pl-enthusiast.net)
Systematic Parsing of X.509: Eradicating Security Issues with a Parse Tree (arxiv.org)
Abstract: "X.509 certificate parsing and validation is a critical task which has shown consistent lack of effectiveness, with practical attacks being reported with a steady rate during the last 10 years. In this work we analyze the X.509 standard and provide a grammar description of it amenable to t...
Microsoft: 70 percent of all security bugs are memory safety issues (zdnet.com)
Security Issue with Bluetooth Low Energy (BLE) Titan Security Keys (security.googleblog.com)
Security Issues with PGP Signatures and Linux Package Management (blog.hboeck.de)
Critical Security Issue identified in iTerm2 as part of Mozilla Open Source Audit (blog.mozilla.org)
Lint an npm or yarn lockfile to analyze and detect security issues (github.com)
Twitter for Android Security Issue (privacy.twitter.com)
The Intel® Converged Security and Management Engine IOMMU Hardware Issue – CVE-2019-0090 (intel.com)
Common security issues with cryptocurrency websites and APIs (introvertmac.wordpress.com)
Scanning Infrastructure as Code for Security Issues (blog.christophetd.fr)
Security Issues in Perl IP Address distros (blog.urth.org)
Security issues related to the npm registry (github.blog)
Using FreeBSD pkg audit to Investigate Known Security Issues (klarasystems.com)
This busy-loop is not a security issue (libcurl) (daniel.haxx.se)
Security alert: Attack campaign involving stolen OAuth user tokens issued to two third-party integrators (github.blog)
Various Linux Kernel WLAN security issues (RCE/DOS) found (lwn.net)