urn:uuid:c9e6cf53-c741-5de5-89b5-5cd48df7a6ce Topic: Security – Ctrl blog Daniel Aleksandersen https://www.daniel.priv.no/ Copyright © 2023 Daniel Aleksandersen. https://www.ctrl.blog/assets/logo/logo-square.svg 2023-08-08T12:56:00Z weekly 10 urn:uuid:d17dde9e-ee38-47d3-b639-41ed8f29bc71 2023-08-08T12:56:00Z 2023-08-08T12:56:00Z The trouble with decommissioning a used FIDO security key The trouble with decommissioning a used <abbr title='Fast IDentity Online'>FIDO</abbr> security key You can’t throw out your worn-out USB security keys when you can’t recall what locks they’re for. Physical security tokens come with their own problems. <p>Five years ago, I wrote about adopting security keys — small second-factor authentication token devices — to secure some of my most precious online accounts. In that article, I foresaw a future problem and detailed how I planned to mitigate it. The future is now, and I did not heed my own advice. 🤦‍♂️</p> <p><a href="https://www.ctrl.blog/entry/security-key-decommission.html">Read more …</a></p> urn:uuid:70607ead-1938-43b0-ba58-f4a0a34ef953 2023-02-05T21:38:00Z 2023-02-05T21:38:00Z Norway’s BankID undermines anti-phishing best practices An easily-spoofed iframe embedded onto every random online merchant’s websites is not a safe place to enter my bank password! Is it really BankID‽ <p>Imagine a privatized nationwide authentication system used to access government services, confirm contracts and online payments, and everything else. Now, imagine that the system was designed to be extra friendly to imitation and credential theft (“phishing”). Here’s everything wrong with Norway’s BankID authentication system.</p> <p><a href="https://www.ctrl.blog/entry/bankid-iframe-phishing.html">Read more …</a></p> urn:uuid:4669d1b8-8be9-45a2-b305-f696c6d025a6 2022-04-27T04:01:00Z 2022-04-27T04:01:00Z SELinux is unmanageable; just turn it off if it gets in your way I’ve been an SELinux complexity apologist for years. Lately, I’ve concluded that every implementation with difficult-to-configure policies is just unmanageable. <p>Security-Enhanced Linux (SELinux) is a type of Mandatory Access Control (MAC) in the Linux kernel. It can prevent software from performing unexpected — such as abusive or malicious actions — on your Linux systems. However, … it’s also an unmanageable mess, and I have a much greater understanding of why people recommend that people disable it.</p> <p><a href="https://www.ctrl.blog/entry/selinux-unmanageable.html">Read more …</a></p> urn:uuid:22a5151e-766e-4181-b92a-4ec32248cbbc 2022-04-03T14:10:00Z 2022-04-03T14:10:00Z Should you trust a third-party bootloader to run newer MacOS versions? OpenCore lets you run the latest MacOS on unsupported Apple legacy hardware (and PCs). But software that bypasses security restrictions requires a lot of trust. <p>Apple periodically drops support for its older hardware, and customers get left with an increasingly insecure and outdated system. The Hackintosh scene, a community dedicated to running MacOS on unsupported hardware, might help extend the life of your Mac. However, can you trust its community-developed software to the same degree as you blindly trust Apple?</p> <p><a href="https://www.ctrl.blog/entry/macos-opencore-trust.html">Read more …</a></p> urn:uuid:9df4acbd-d7cd-42b9-9ce3-1b18645be810 2021-11-30T19:13:00Z 2021-11-30T19:13:00Z Closing the open redirect vulnerability in the Libravatar ecosystem I found an open redirect vulnerability in the Libravatar specification. An open-source avatar hosting API could be abused to redirect to untrusted websites. <p>Libravatar is a decentralized open-source alternative to Gravatar – the avatar image service. Last week, I noticed an URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability (CWE-601) in the Libravatar application programming interface (API) specification.</p> <p><a href="https://www.ctrl.blog/entry/libravatar-open-redirect.html">Read more …</a></p>