https://blog.erratasec.com/2008/06/blizzard.html
Errata Security: Blizzard
http://eu.blizzard.com/en/press/080626-ba.html Blizzard is going to sell a One Time Password device. I suppose I should comment about securi...
errata securityblizzard
https://blog.erratasec.com/2010/04/vuln-disclosure-is-rude.html?showComment=1272153578454
Errata Security: Vuln Disclosure is Rude
It's amazing that after all this time, our community has not come to grips with "vulnerability disclosure". Last weekend, a lot of people tw...
errata securityvulndisclosurerude
https://blog.erratasec.com/2017/06/how-intercept-outed-reality-winner.html?showComment=1496772588672
Errata Security: How The Intercept Outed Reality Winner
Today, The Intercept released documents on election tampering from an NSA leaker. Later, the arrest warrant request for an NSA contractor ...
errata securitythe interceptoutedrealitywinner
https://blog.erratasec.com/2014/07/nsa-walk-mile-in-their-shoes.html?showComment=1404997108274
Errata Security: NSA: walk a mile in their shoes
While this is mostly a technical blog, our most popular posts deal with cyber-rights, supporting Snowden, Weev, and Swartz. Yet sometimes I...
walk a mileerrata securitynsashoes
https://blog.erratasec.com/2018/10/systemd-is-bad-parsing-and-should-feel.html
Errata Security: Systemd is bad parsing and should feel bad
Systemd has a remotely exploitable bug in its DHCPv6 client . That means anybody on the local network can send you a packet and take control...
errata securitysystemdbadparsingfeel
https://blog.erratasec.com/2007/05/public-wifi-vs-3g-mobile-broadband.html
Errata Security: Public wifi vs 3G mobile broadband
Wireless sans wifi In my last post, I pointed out that public wifi is too dangerous to use. Web/2.0 is fundamentally insecure around eavesdr...
errata securitypublic wifivsmobilebroadband
https://blog.erratasec.com/2007/02/bill-gates-fights-back-against-evil.html?showComment=1170650160000
Errata Security: Bill Gates fights back against an evil corp?!?!
UPDATE: For a response to John Gruber check here . For more discussion on the lack of security features in OSX, check here . http://apple.sl...
errata securitybill gatesfightsbackevil
https://blog.erratasec.com/2017/03/some-comments-on-wikileaks-ciavault7.html?showComment=1489623317848&m=0
Errata Security: Some comments on the Wikileaks CIA/#vault7 leak
I thought I'd write up some notes about the Wikileaks CIA "#vault7" leak. This post will be updated frequently over the next 24 hours. Th...
errata securityon thecommentswikileakscia
https://blog.erratasec.com/2017/03/some-comments-on-wikileaks-ciavault7.html?showComment=1603851878803
Errata Security: Some comments on the Wikileaks CIA/#vault7 leak
I thought I'd write up some notes about the Wikileaks CIA "#vault7" leak. This post will be updated frequently over the next 24 hours. Th...
errata securityon thecommentswikileakscia
https://blog.erratasec.com/2008/08/booting-oswa-on-eee-pc-with-sd-flash.html?showComment=1219243380000
Errata Security: Booting OSWA on Eee PC with SD flash
These are some notes for making a bootable SD flash card for my Eee PC from the " OSWA Assistant " bootable CD. A bootable or "live" CD is...
errata securityeee pcbootingsdflash
https://blog.erratasec.com/2009/02/importance-of-being-canonical.html?showComment=1602891217312
Errata Security: The Importance of Being Canonical
Wikipedia defines "canonical" as " reduced to the simplest and most significant form possible without loss of generality . It is " often use...
errata securitythe importancecanonical
https://blog.erratasec.com/2017/03/some-comments-on-wikileaks-ciavault7.html?showComment=1489414506340
Errata Security: Some comments on the Wikileaks CIA/#vault7 leak
I thought I'd write up some notes about the Wikileaks CIA "#vault7" leak. This post will be updated frequently over the next 24 hours. Th...
errata securityon thecommentswikileakscia
https://blog.erratasec.com/2016/03/how-media-really-created-trump_26.html?showComment=1459063723689
Errata Security: How the media really created Trump
This NYTimes op-ed claims to diagnose the press's failings with regard to Trump, but in its first sentence demonstrates how little press un...
errata securitythe mediareallycreatedtrump
https://blog.erratasec.com/2015/02/extracting-superfish-certificate.html?showComment=1424381856167&m=0
Errata Security: Extracting the SuperFish certificate
I extracted the certificate from the SuperFish adware and cracked the password (" komodia ") that encrypted it. I discuss how down below. T...
errata securityextractingsuperfishcertificate
https://blog.erratasec.com/2007/11/more-rtsp.html?showComment=1196392920000
Errata Security: More RTSP
WabiSabiLabi answered my question on their blog in no uncertain terms. The exploit for sale on their site is not the same as the RTSP exp...
errata securityrtsp
https://blog.erratasec.com/2021/07/ransomware-quis-custodiet-ipsos-custodes.html
Errata Security: Ransomware: Quis custodiet ipsos custodes
Many claim that "ransomware" is due to cybersecurity failures. It's not really true. We are adequately protecting users and computers. The f...
errata securityransomwarequisipsoscustodes
https://blog.erratasec.com/2017/06/how-intercept-outed-reality-winner.html?showComment=1497540617946&m=0
Errata Security: How The Intercept Outed Reality Winner
Today, The Intercept released documents on election tampering from an NSA leaker. Later, the arrest warrant request for an NSA contractor ...
errata securitythe interceptoutedrealitywinner
https://blog.erratasec.com/2014/09/bash-shellshock-bug-is-wormable.html?showComment=1411763338766&m=0
Errata Security: Bash 'shellshock' bug is wormable
Early results from my scan: there's about 3000 systems vulnerable just on port 80, just on the root "/" URL, without Host field. That doesn'...
errata securitybashshellshockbug
https://blog.erratasec.com/2017/03/some-comments-on-wikileaks-ciavault7.html?showComment=1604868105738
Errata Security: Some comments on the Wikileaks CIA/#vault7 leak
I thought I'd write up some notes about the Wikileaks CIA "#vault7" leak. This post will be updated frequently over the next 24 hours. Th...
errata securityon thecommentswikileakscia
https://blog.erratasec.com/2019/01/passwords-in-file.html
Errata Security: Passwords in a file
My dad is on some sort of committee for his local home owners association. He asked about saving all the passwords in a file stored on Micro...
errata securitypasswordsfile
https://blog.erratasec.com/2011/03/comodo-hacker-releases-his-manifesto.html?showComment=1602421805232
Errata Security: The Comodo hacker releases his manifesto
Somebody claiming to be the "Comodo hacker" has released a statement here http://pastebin.com/74KXCaEZ , decompiled code here http://pasteb...
errata securitycomodohackerreleasesmanifesto
https://blog.erratasec.com/2018/11/masscan-and-massive-address-lists.html
Errata Security: Masscan and massive address lists
I saw this go by on my Twitter feed. I thought I'd blog on how masscan solves the same problem. If you do @nmap scanning with big excl...
errata securitymasscanmassiveaddresslists
https://blog.erratasec.com/2014/05/wordpress-unsafe-at-any-speed.html?showComment=1401528870077
Errata Security: WordPress: unsafe at any speed
EFF technologist (and creator/maintainer of cool privacy tools), Yan Zhu noticed that WordPress still does not secure their session cookie...
errata securitywordpressunsafespeed
https://blog.erratasec.com/2015/02/extracting-superfish-certificate.html?showComment=1424368056841&m=0
Errata Security: Extracting the SuperFish certificate
I extracted the certificate from the SuperFish adware and cracked the password (" komodia ") that encrypted it. I discuss how down below. T...
errata securityextractingsuperfishcertificate
https://blog.erratasec.com/2008/01/why-olpc-promotes-terrorism.html?showComment=1200943620000
Errata Security: Why the OLPC promotes terrorism
When you see a hobo starving in the street, there are two things you can do. One is to ask the hobo what he would like to eat. The second is...
errata securityolpcpromotesterrorism
https://blog.erratasec.com/2015/02/extracting-superfish-certificate.html
Errata Security: Extracting the SuperFish certificate
I extracted the certificate from the SuperFish adware and cracked the password (" komodia ") that encrypted it. I discuss how down below. T...
errata securityextractingsuperfishcertificate
https://blog.erratasec.com/2012/02/wikileaks-to-go-mobile-not-app.html
Errata Security: Wikileaks to go mobile (Not an app)
The Sealand platform that was home to the data haven HavenCo . The infamous site Wikileaks is looking to move its operations to...
errata securityto gowikileaksmobileapp
https://blog.erratasec.com/2009/05/star-trek-sucked.html?showComment=1262186395713
Errata Security: Star Trek Sucked
Everyone else is going to love the new Star Trek movie, but not me. It's got great visuals, great casting, great acting, great editing, and...
errata securitystar treksucked
https://blog.erratasec.com/2016/10/politifact-yes-we-can-fact-check-kaines.html?showComment=1477660443697
Errata Security: Politifact: Yes we can fact check Kaine's email
This Politifact post muddles over whether the Wikileaks leaked emails have been doctored , specifically the one about Tim Kaine being picked...
yes we canerrata securityfact checkpolitifact
https://blog.erratasec.com/2017/01/about-that-giuliani-website.html?m=0
Errata Security: About that Giuliani website...
Rumors are that Trump is making Rudy Giuliani some sort of "cyberczar" in the new administration. Therefore, many in the cybersecurity scann...
errata securityabout thatgiuliani
https://blog.erratasec.com/2016/02/some-notes-on-apple-decryption-san.html?showComment=1455879482834
Errata Security: Some notes on Apple decryption San Bernadino phone
Today, a judge ordered Apple to help the FBI decrypt the San Bernadino shooter's iPhone 5C. Specifically: disable the auto-erase that hap...
errata securitysome noteson applesan bernadinodecryption
https://blog.erratasec.com/2007/06/niiiice.html?showComment=1181653440000
Errata Security: Niiiice...
**PLEASE DO NOT POST A COMMENT IF ITS ABOUT SAFARI IN BETA** These bugs have been verified in the current PRODUCTION copy on OSX (Safari 2.0...
errata security
https://blog.erratasec.com/2016/11/yes-fbi-can-review-650000-emails-in-8.html
Errata Security: Yes, the FBI can review 650,000 emails in 8 days
In today's news, Comey announces the FBI have reviewed all 650,000 emails found on Anthony Wiener's computer and determined there's nothing ...