This Week in Security: Unicode, Truecrypt, and NPM Vulnerabilities

Unicode, the wonderful extension to to ASCII that gives us gems like “✈”, “⌨”, and “☕”, has had some unexpected security ramifications. The most common problems with Unicode are visual security issues, like character confusion between letters. For example, the English “M” (U+004D) is indistinguishable from the Cyrillic “М” (U+041C). …read more

Continue reading This Week in Security: Unicode, Truecrypt, and NPM Vulnerabilities

Severe Auth Bypass and Priv-Esc Vulnerabilities Disclosed in OpenBSD

OpenBSD, an open-source operating system built with security in mind, has been found vulnerable to four new high-severity security vulnerabilities, one of which is an old-school type authentication bypass vulnerability in BSD Auth framework.

The other… Continue reading Severe Auth Bypass and Priv-Esc Vulnerabilities Disclosed in OpenBSD

OpenBSD Multiple Authentication Vulnerabilities

Multiple authentication vulnerabilities in OpenBSD have been disclosed by Qualys Research Labs. The vulnerabilities are assigned following CVEs: CVE-2019-19522, CVE-2019-19521, CVE-2019-19520, CVE-2019-19519. OpenBSD developers have confirmed the vulne… Continue reading OpenBSD Multiple Authentication Vulnerabilities

UNIX Co-Founder Ken Thompson’s BSD Password Has Finally Been Cracked

A 39-year-old password of Ken Thompson, the co-creator of the UNIX operating system among, has finally been cracked that belongs to a BSD-based system, one of the original versions of UNIX, which was back then used by various computer science pioneers…. Continue reading UNIX Co-Founder Ken Thompson’s BSD Password Has Finally Been Cracked

Learning path to more advanced security knowledge? (security in OS-context mostly) [on hold]

Some background:
I obtained an Msc degree in scientific computing 7 years ago.
Since then I’ve been working in government IT as an IT / business analist.
My exposure to enterprise IT is mostly conceptual from discussions with… Continue reading Learning path to more advanced security knowledge? (security in OS-context mostly) [on hold]