I’m the boss! Please enjoy my finely curated links.

  • 6 Posts
  • 8 Comments
Joined 11 months ago
cake
Cake day: July 31st, 2023

help-circle

  • Some necessary caveats: This kind of attack can only be pulled off in relatively narrow circumstances by a dedicated attacker. Segal said the user would need to have installed a malicious browser extension or be in transit and use public Wi-Fi where their traffic could be intercepted and decrypted through a MITM attack.

    Well, okay. Maybe there’s something new here, but despite the many paragraphs of exposition, this sounds like exactly the sort of cookie stealing attack that’s been possible for decades.

    Is the big breakthrough here that somebody realized FIDO doesn’t change that? Like, uh, no kidding? What’s new?










  • Not saying it’s nothing, but most of the time I’m using the VPN to access something on a network that’s not publicly accessible, so sending my traffic to the local network won’t do much either.

    But if you’re using a VPN to get out of the local network, maybe this is concerning.

    Cute attack, though. I like it.