Most modern phones have SE(Secure Element) or virtualized secure zone(ARM Trustzone) which can act as de-facto key.
Google already uses it to great success(most people are clueless to that though)
207 karma · joined April 29, 2020
Most modern phones have SE(Secure Element) or virtualized secure zone(ARM Trustzone) which can act as de-facto key.
Google already uses it to great success(most people are clueless to that though)
2FA is very useful against phishing:
https://security.googleblog.com/2019/05/new-research-how-eff...
deployment of a keylogger means your host is compromised, from there you can do so much you really don't need someone's password...
2FA is for plain phishing attacks. building phishing attacks against 2FA is significantly harder and usually easier to detect\protect from.
They only last for 30 seconds, requiring better infrastructure(automated logins) which also tremendously helps with detection.
The vast majority of phishing is just storing passwords for later attempts.
TOTP by design can be stronger than password. the seed can be pseudo-randomly generated therefore you cannot guess the code without it, even if you have previously generated codes.
EV's will allow countries to be less reliant on foreign fossils, improving stability.
It is a shame though, that nuclear isn't promoted.
Nuclear + good battery tech is a game changer.
Pwning the app will only provide access to whatever permission it has and we are still sandboxed.
Pwning a kernel module\driver will provide access to everything whether its messaging, call logs, pictures etc. we are not sandboxed, we don't need an LPE exploit.
I think the priority is clear.
you're already root.
you can access any component without much restriction.
How the data is stored has nothing to do with this
You don't need to access the messages app in order to get access to the messages.
it's the opposite actually, the messaging app needs permissions for the system level messaging component.
you can pretty much access whatever you want.
The point of these apps is that I can get content(picture, message, video etc) to your local device and it get processed.
At the end of the day, it is still an app with app level permissions, sandbox etc.
Kernel\Kernel modules are far more likely to be written as they allow for vastly more access than an app.
Instant-Messaging = Worthy target for exploits.
Just like web-browsers get exploited after years of patching.
Many services from banks to healthcare utilize SMS as a main way of communicating with end-users. many rely on dynamic numbers.
Moreover, spoofing SMS messages is not that hard.
Messaging apps whether it is SMS or alternatives like whatsapp, telegram etc. will always offer a powerful vector to infect devices.
it doesn't work
AMD is re-surging with great technology, they already chipped away some market share in key sectors and I see that continuing for a while.
TSMC has closed the gap and exceeded Intel in manufacturing, Samsung is not too far behind. Intel is no longer the market leader in chip fabrication.
Nvidia is buying ARM and aiming to start competing in the CPU space, with their GPU leadership that could be huge.
x86 is starting to lose it's complete dominance & new players coming in(Apple M1, RISC-V, Nuvia, Ampere)
Cloud vendors are starting to build their own chips and tech instead of buying them(Graviton, TPU)
I see Intel still being profitable and stable but losing their truly unprecedented grasp on the industry.
the first option is rather simple, assuming we have a good psuedo-random generator with low bias margins. we get:
A-Z,a-z,0-9 = 58 options, Length = 16
58^16/2 is the target.
Second option is weaker IMO because we know that plain brute-force is rarely being used today for anything over 13~14 characters.
We mostly use masks\dictionaries to try common passwords, phrases, sequences. So even if there's a very small chance that someone would have some kind of heuristic rule that targets Finnish orthography\honology, it is still more likely than someone successfully brute-forcing 16 random chars+numbers.
Another interesting observation is that fact that it contains common English words by chance. things like rock or tent. those can increase the chance of a dictionary success(our 32 chars starts breaking apart) whereas the 16 chars are random so in nature there are less prone to contain common English words
Many times data is exfiltrated beforehand, backups are deleted. If someone went the trouble of compromising a 3rd party software vendor, he knows what he is doing.
So if it has some predictable structure, statistical attributes etc, it can be exploited to reduce the search space and therefore can be weaker than the actual raw entropy.
Does that matter in the real world? I don't think so.
Psuedo-random is always better because anything else usually follows a pattern that can be exploited(sequence, structure, words, statistical bias)
If we can't make assumptions about the secret, the only solution is plain brute-force when it comes to the number of characters squared the length of the password.
Encryption? what kind of KDF are you using? probably something old and quite brittle when it comes to hardware cracking.
sit this one down boy
If you generate long elaborate passwords then they can resist some of these flaws but the point is you don't want to introduce a flaw when they are simpler and better solutions out there.
Mistakes are natural, you want to provide the utmost resistance to such exploits which can stack up to become viable.
More than anything, it proved that their model is flawed.
Just the number of gov agencies that are forced to stop working with them is a major blow.
People short-squeezing stocks, shooting their "value" by 30x in 2 hours making them millionaires.
Hedge funds manipulating stocks to meet their portfolios
IPO's in billions of dollars for new, non-profitable startups just because of hype. when you look at the balance sheet it makes no sense.
The market is volatile and inflated, it is as clear as day. Whether there will be a crash? that's beyond my level.
Remote monitoring\management? in COVID year? just 3.5%
that's horrendous
As if stock market is a perfect representation of a company performance, it is highly distorted\manipulated market.
SolarWind is fucked, they have a massive drop in new customers, I work with dozens of companies that are now plan to completely abandon their suites(those things take time).
Insurance is a trap. once you read the small letters, they don't fully cover the damage, usually only direct. Some have refused to pay due to some shady conditions that they insert into contracts to deceive customers(like any other insurance sector)
PHC was far more mature in many ways over AES.
Argon2d has better resistance to TMTO and hardware accelerated cracking due to the data-depending memory access.
Side-channels attacks are not practical in many scenarios and won't be the easiest way to extract secrets in them.
Local hashing of any sort without external interaction is better with argon2d for better cracking resistance.
Those are great on paper, but in practice you either have a much easier way to extract those secrets with the amount of access you need for a side channel attack or they are too unreliable to truly leverage.
Many solutions use argon2d with great success.
- Stable\known CPUs, most vendors are used to Intel.
- Infrastructure\Support, Intel has a lot more infrastructure to support customers\contracts
- Long cycles, servers are more complex to replace and contracts can span multiple years.
- Compatibility, many rely on Intel specific features or are afraid to try their solution on a different CPU vendor.
- Relationships\Market Share, Intel still is a far bigger brand with more prestige