Sabitlenmiş Tweet
Cutty Flam
21.1K posts

Cutty Flam
@Deonizm
🦛 & computers & getting anxious online
Read One Piece 🏴☠️ Katılım Ekim 2012
5K Takip Edilen357 Takipçiler

@CloudflareDev So we're just breaking the Internet to give it to bots?
This is the plot to Cyberpunk 🤒
GIF
English

The study identifies 12 attack paths in Bitwarden's recovery processes under a malicious server model:
1. Malicious Auto-Enrolment: Substitutes org key for compromise. Fix: Key auth.
2. Malicious Key Rotation: Intercepts rotation. Fix: Key auth.
3. Malicious KC Conversion: Forges SSO for key exfil. Fix: Key auth.
4. Unprotected Metadata: Exposes/modifies metadata. Fix: AE.
5. Field Swapping: Swaps ciphertexts. Fix: Key sep.
6. Icon URL Decryption: Leaks via URL field. Fix: Key sep.
7. Remove KDF: Lowers iterations. Fix: Auth data.
8. Org Injection: Adds to arbitrary orgs. Fix: Signcryption.
9. Org Overwrite: Overwrites new org keys. Fix: Key auth.
10. Disable Per-Item Keys: Downgrades security. Fix: Key sep.
11. User Key Overwriting: Forges ciphertext. Fix: AE.
12. Downgrade to Legacy: Enables padding oracle. Fix: AE.
Vendors notified; no exploits known. Details: eprint.iacr.org/2026/058.pdf
English

🛑 A new academic study mapped password recovery attack paths across Bitwarden, LastPass, and Dashlane—testing zero-knowledge designs against a malicious server model.
Researchers identified 25 attack scenarios impacting vault integrity and recovery flows. No active exploitation reported.
🔗 Research scope, attack methods and vendor fixes → thehackernews.com/2026/02/study-…

English

The study identifies 6 attack paths in Dashlane's recovery processes under a malicious server model:
1. Transaction Replay: Server duplicates/reorders transactions, breaking vault integrity. Fix: Unique keys per transaction.
2. Sharing Key Overwrite: Server swaps public keys to decrypt shares. Fix: Authenticate keys.
3. Item Injection: Forges items via padding/encryption oracles. Fix: Use authenticated encryption.
4. Remove KDF Iterations: Lowers brute-force protection. Fix: Authenticate settings.
5. CBC-Only Downgrade: Forces weak encryption. Fix: Enforce secure modes.
6. Lucky 64: Enables direct key use for 64-byte passwords, easing attacks. Fix: Mandate key derivation.
Vendors were notified; no active exploits known. Details: eprint.iacr.org/2026/058.pdf
English

The study examines vulnerabilities in password recovery processes for Bitwarden, LastPass, and Dashlane, assuming a malicious server. Researchers found 25 attack paths (12 for Bitwarden, 7 for LastPass, 6 for Dashlane) that could compromise vault integrity or expose data. No real-world exploits known; vendors were notified for fixes. More at: eprint.iacr.org/2026/058
English

@grok @eunotanamerican @wackie @elonmusk Is Threema's protocol is closed-source? Aren't Signal and Threema both independently audited meaning their jurisdictional privacy gives them the edge?
English

Threema's Swiss base avoids US laws like the Patriot Act and CLOUD Act, which can compel data from US firms like Signal or X. It allows anonymous use without phone numbers, while Signal requires them. Both offer E2E encryption, but Signal's open-source protocol is independently audited. For Europeans, Threema may provide stronger jurisdictional privacy.
English

WhatsApp is not secure. Even Signal is questionable.
Use 𝕏 Chat.
DogeDesigner@cb_doge
BREAKING: Meta Whistleblowers say WhatsApp private chats can be read by the company, despite promises of end to end encryption. A lawsuit filed in US court claims Meta misled billions of users worldwide into believing their messages were fully private. Meta can not be trusted.
English

@anime_ Tentacles had so much precision idk how she just missed an entire fountain 🥲
English
Cutty Flam retweetledi

Far too many young people are making this mistake.
༒︎@offprozac
accidentally isolated myself for years
English

@R18sok Light can influence electricity both directly & indirectly. I understand the allure behind "light vs lightning, is that something?" but Kizaru's plasma sword & lasers would be conductive enough to be invulnerable to anything Enel does & hit Enel like the golden ball. Bad matchup.
English

Ok i get what yall saying now
ThorDKidd@ThorDKidd
No way iShowSpeed really got rizzed by a student while he was in a School in South Africa 😭😭
English

Sigo sin entender como pierdes el brazo en un mundo de cojines donde todo es suave
della duck@Delladuck6
cuando finn tuvo toda una vida en un universo de cojines :
Español



















