lexi <img src=x onerror=alert(1)>

41.8K posts

lexi <img src=x onerror=alert(1)> banner
lexi <img src=x onerror=alert(1)>

lexi <img src=x onerror=alert(1)>

@1lexxi

not around here anymore lol. previous statements may not represent me correctly anymore

it/its | she/her Katılım Kasım 2018
3.4K Takip Edilen1.6K Takipçiler
Emmett
Emmett@Emmett31539642·
I think it has to do more with the encryption as well as being open source. to me, open source is a HUGE mistake. you can have the GPL all you want to but any dev can yank that license at anytime. the simple fact that this huge hack happened on a commercial app speaks volumes and says that even open source w/encryption is not as secure as claimed, let's take PGP for example, two sides one with the E key, one with the DE key. that method should have been applied to all these damn stupid apps. Keys are what makes even police comm systems secure with that encryption. People such as @unixpill have no true idea of what secure really means or entails. Plus he doesn't take the time to read EVERYTHING. PGP is the oldest and most secure way of comms on the net today. and it has not wained. that alone speaks volumes.
English
6
1
0
1.8K
Sooraj
Sooraj@iAnonymous3000·
You don’t need to trust Signal. That’s the whole point. The protocol is open source. The clients are open source. The server is open source. Independent cryptographers have audited the Signal Protocol repeatedly, and it remains the gold standard for end-to-end encryption. Signal also supports reproducible builds - meaning you can compile the source code yourself and verify it produces the exact same binary distributed on app stores. Trust is for closed systems.
English
105
252
4.1K
228.4K
lexi <img src=x onerror=alert(1)>
fun fact! if you followed these instructions exactly without any mistakes you'd be vulnerable to one of the gpg dot fail attacks lol
English
1
0
10
441
lexi <img src=x onerror=alert(1)>
@RayRedacted held my first big talk at the biggest hacker event in europe on the biggest stage a few days ago (about the gpg dot fail research project) as well. mindblowing experience. can only recommend holding infosec talks, life changing stuff
English
0
0
0
65
Ray [REDACTED]
Ray [REDACTED]@RayRedacted·
I have literally watched this guy's career rocket from wanting a good infosec job to OMGAreYourFrickingKiddingMe . I gotta admit that I am extremely proud of my minibar analogy, too. Its at https colon slash slash redact dot link slash minibar
KL4R10N (Previously S4T4N)@KL4R10N

In 2021, I was very skeptical about submitting my first CFP, and @RayRedacted pushed me to just do it. Before that, I didn't know him personally. But from that day onwards, He has been my undeclared mentor.

English
2
1
8
1.3K
celeste
celeste@vmfunc·
@1lexxi wait correct me if i'm wrong but the detached sig attack is conceptually the same class as the 2007 core security unsigned data injection vuln? gpg "fixed" that by limiting to one message per run but the underlying problem (verification and output are separate codepaths that can desync) was never architecturally solved 17 years later same bug class different packet arrangement??
English
1
0
8
1.3K
lexi <img src=x onerror=alert(1)> retweetledi
️
@crackticker·
s/o @1lexxi who managed to pay someone to smuggle them from the US as a gift for the gang
@crackticker

my chud children

English
3
1
47
2.5K
mjones (@numinit)
mjones (@numinit)@_numinit·
@RossComputerGuy @grhmc BTW git signing using GnuPG looks fine *for now* (check out git cat-file -p). Basically anything in detached mode (so separate asc sig file) is probably not vulnerable to this particular fresh hell. FWIW I was able to spoof a clearsign I made a while ago, with a mod to the PoC
English
1
0
2
143
lexi <img src=x onerror=alert(1)>
@HSVSphere @dpc_pw hi yes author of the talk here. please for the love of god stop using pgp and if you must use sequoia; i personally have worked on better hardware support (#note_2861549967" target="_blank" rel="nofollow noopener">gitlab.com/sequoia-pgp/se…). you can already use your yubikeys with rust only software today (even though it's still alpha)!
English
0
0
5
232
HSVSphere
HSVSphere@HSVSphere·
@dpc_pw Sequoia also suffers from a non-critical security issue, but that is because of the pgp specification - aka a wontfix in both of these programs Idk, soon
English
2
0
9
3.7K