Deleted the tweet about the crypto bug because there's conflicting info on its scope. Some people are tweeting at me saying it's viable for TLS interception, but MS Security Portal only mentions file signature spoofing. Going to go do some digging.
-
Prikaži ovu nit
-
Odgovor korisniku/ci @MalwareTechBlog
From the portal advisory: "A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software."
1 reply 4 proslijeđena tweeta 30 korisnika označava da im se sviđa -
Odgovor korisnicima @argvee @MalwareTechBlog
It is weird that the official advisory is so focussed on code signing.
5 replies 0 proslijeđenih tweetova 40 korisnika označava da im se sviđa -
This is helpful: https://media.defense.gov/2020/Jan/14/2002234275/-1/-1/0/CSA-WINDOWS-10-CRYPT-LIB-20190114.PDF …
44 proslijeđena tweeta 102 korisnika označavaju da im se sviđa
Odgovor korisnicima @DAlperovitch @taviso i sljedećem broju korisnika:
The real question is, did the NSA get a bug bounty?
15:14 - 14. sij 2020.
0 replies
1 proslijeđeni tweet
6 korisnika označava da im se sviđa
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.