Stop saying "log into a portal." Sounds way too cool for what's happening.
jviide.iki.fi
@jviide.iki.fi
cybersecurity charlatan ⋅ quadratic blowhard
"it looks like you're using an adblocker to visit our site." yep! ha ha! it rocks!
I love a deranged setup on /r/homelab where the question is always “why did you make this and what can it achieve?”, and the answer to both is invariably “I don’t know.”
there is essentially no downside to passkeys that are not also a downside to strong passwords, and a _lot_ of upsides.
So basically a) phishing is really bad b) email is very bad and SMS is worse c) public key cryptography is really good d) 2FA methods is an active insult to our collective intelligence e) 2FA is fragile and relies on external infra f) SSO == single point of failure g) SSO is not very single
To this day, I still don't understand what problems passkeys are trying to solve. Consumers just want to use one password for everything - thats been known forever. In enterprise, the answer is SSO via OIDC. Simple, secure, requires only one password, can enforce 2FA, ties to your OS.
“food for thought” buddy my thoughts don’t need any food at all. been trying to starve them fuckers for years and they still keep doing the thing
if your "containment" is "telling the robot to be a good boy" you're not a serious person
Coordinated disclosure is mostly waiting quietly, followed by one day of pointing at the release notes. And today's the day! The first vuln mentioned in the blog post was reported by Yours Truly 🙂 github.com/vercel/next....
Denial of Service in App Router using Server Actions
## Impact Crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same pro...
github.com
Following our move to scheduled, pre-announced security updates, the July release is out. This release addresses several security issues in Next.js 16 and 15. Update to 16.2.11 (Active LTS) or 15.5.21 (Maintenance LTS) now. nextjs.org/blog/july-2... x.com/nextjs/stat...
I sometimes wonder how many "local" containerized services are accidentally exposed to the internet because of this. See also: docs.docker.com/engine/netwo...
I just got one of the most poorly designed messages in a game ever.
∧_∧ (。・ω・。)つ━☆・*。 ⊂ ノ ・hack゜+. しーJ °。+ *'¨) .· '¸.·the*'¨) ¸.·*¨) (¸.·' planet(¸.·'*
I just realized it's called Silicon Valley because they do silly cons.
My PR isn’t a ”buggy mess”! It’s a postmodernist masterpiece, free from the shackles of authorial intent!
in retrospect we probably encouraged too many kids to be the change they wanted to see in the world
Did some optimizations today. Now it doesn't work AND it's very fast 🔥🔥🔥
We interrupt our regularly scheduled programming to bring you this important message.