urn:uuid:c9e6cf53-c741-5de5-89b5-5cd48df7a6ce
Topic: Security – Ctrl blog
Daniel Aleksandersen
https://www.daniel.priv.no/
Copyright © 2023 Daniel Aleksandersen.
https://www.ctrl.blog/assets/logo/logo-square.svg
2023-08-08T12:56:00Z
weekly
10
urn:uuid:d17dde9e-ee38-47d3-b639-41ed8f29bc71
2023-08-08T12:56:00Z
2023-08-08T12:56:00Z
The trouble with decommissioning a used FIDO security key
The trouble with decommissioning a used <abbr title='Fast IDentity Online'>FIDO</abbr> security key
You can’t throw out your worn-out USB security keys when you can’t recall what locks they’re for. Physical security tokens come with their own problems.
<p>Five years ago, I wrote about adopting security keys — small second-factor authentication token devices — to secure some of my most precious online accounts. In that article, I foresaw a future problem and detailed how I planned to mitigate it. The future is now, and I did not heed my own advice. 🤦♂️</p> <p><a href="https://www.ctrl.blog/entry/security-key-decommission.html">Read more …</a></p>
urn:uuid:70607ead-1938-43b0-ba58-f4a0a34ef953
2023-02-05T21:38:00Z
2023-02-05T21:38:00Z
Norway’s BankID undermines anti-phishing best practices
An easily-spoofed iframe embedded onto every random online merchant’s websites is not a safe place to enter my bank password! Is it really BankID‽
<p>Imagine a privatized nationwide authentication system used to access government services, confirm contracts and online payments, and everything else. Now, imagine that the system was designed to be extra friendly to imitation and credential theft (“phishing”). Here’s everything wrong with Norway’s BankID authentication system.</p> <p><a href="https://www.ctrl.blog/entry/bankid-iframe-phishing.html">Read more …</a></p>
urn:uuid:4669d1b8-8be9-45a2-b305-f696c6d025a6
2022-04-27T04:01:00Z
2022-04-27T04:01:00Z
SELinux is unmanageable; just turn it off if it gets in your way
I’ve been an SELinux complexity apologist for years. Lately, I’ve concluded that every implementation with difficult-to-configure policies is just unmanageable.
<p>Security-Enhanced Linux (SELinux) is a type of Mandatory Access Control (MAC) in the Linux kernel. It can prevent software from performing unexpected — such as abusive or malicious actions — on your Linux systems. However, … it’s also an unmanageable mess, and I have a much greater understanding of why people recommend that people disable it.</p> <p><a href="https://www.ctrl.blog/entry/selinux-unmanageable.html">Read more …</a></p>
urn:uuid:22a5151e-766e-4181-b92a-4ec32248cbbc
2022-04-03T14:10:00Z
2022-04-03T14:10:00Z
Should you trust a third-party bootloader to run newer MacOS versions?
OpenCore lets you run the latest MacOS on unsupported Apple legacy hardware (and PCs). But software that bypasses security restrictions requires a lot of trust.
<p>Apple periodically drops support for its older hardware, and customers get left with an increasingly insecure and outdated system. The Hackintosh scene, a community dedicated to running MacOS on unsupported hardware, might help extend the life of your Mac. However, can you trust its community-developed software to the same degree as you blindly trust Apple?</p> <p><a href="https://www.ctrl.blog/entry/macos-opencore-trust.html">Read more …</a></p>
urn:uuid:9df4acbd-d7cd-42b9-9ce3-1b18645be810
2021-11-30T19:13:00Z
2021-11-30T19:13:00Z
Closing the open redirect vulnerability in the Libravatar ecosystem
I found an open redirect vulnerability in the Libravatar specification. An open-source avatar hosting API could be abused to redirect to untrusted websites.
<p>Libravatar is a decentralized open-source alternative to Gravatar – the avatar image service. Last week, I noticed an URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability (CWE-601) in the Libravatar application programming interface (API) specification.</p> <p><a href="https://www.ctrl.blog/entry/libravatar-open-redirect.html">Read more …</a></p>