ikakavas at infosec dot exchange

7.6K posts

ikakavas at infosec dot exchange

ikakavas at infosec dot exchange

@ilektrojohn

All things Identity and Security - Principal product security engineer @elastic

Thessaloniki, Greece Katılım Haziran 2008
714 Takip Edilen2.2K Takipçiler
asanso
asanso@asanso·
Sorry Netflix. Can’t wait
asanso tweet media
English
1
0
5
538
ikakavas at infosec dot exchange
@mperedim @hellenicpolice Είμαστε και εμείς που είχαμε κλείσει ραντεβού πριν 4 μήνες και όταν τελικά ζυγωνε η ώρα δεν μπορούσαμε να πάμε αλλά δεν είχαμε και επιλογή να ακυρώσουμε για να ανοίξει το slot
Ελληνικά
1
0
0
75
Nikos Fertakis
Nikos Fertakis@nikosfertakis·
I’m 75 pages into A Fire Upon the Deep and it already has god-level AIs, faster than light travel, middle-age worlds with telepathic creatures, tree-like animals with speech, and a red-bearded barbarian. It’s like Asimov and Tolkien had a child.
English
1
1
1
275
ikakavas at infosec dot exchange retweetledi
Sébastien Guilloux
Sébastien Guilloux@_sebgl·
I’ll be speaking at KubeCon next week about how we’ve redesigned our multi-CSP multi-region Cloud platform at Elastic to embrace Kubernetes. Come learn about unusual ways to build K8s controllers!
English
0
7
12
4.1K
Frozzipies
Frozzipies@frozzipies·
@xeraa @elastic Actually i have another bug report on elastic assets with a high severity. This report status is not on triaged or waiting an action from the internal team. It still on validation phase from h1 analyst. But the problem is, the analyst is not responding my report for about 10 days
Frozzipies tweet media
English
1
0
0
182
Frozzipies
Frozzipies@frozzipies·
@elastic Check your hackerone please. I have two reports that have been abandoned for almost 3 weeks. The status of my report is triaged, and Im still waiting for the Elastic internal team to make a decision to my report :(
English
1
0
0
115
ikakavas at infosec dot exchange
@InsecureNature email claim as a unique ID is a badly misconfigured oAuth2/OIDC implementation and the burden _is_ on the RP to get it right. Moving to SAML for instance, has the same risks. Email will be released as a SAML attribute too and if SPs decide to use it.. same issue.
English
0
0
0
61
ikakavas at infosec dot exchange
@InsecureNature :wave: given that it is (should be) a well known property of the email scope (the oidc spec describes it in #ClaimStability" target="_blank" rel="nofollow noopener">openid.net/specs/openid-c… and as you pointed out, Google mentions it in the docs - as did MS ), why do you consider this an issue in the OP and not in the RP side ? Using 1/2
English
2
0
0
255
Dylan
Dylan@InsecureNature·
🎥I did a much deeper breakdown of Google's Oauth problems on YouTube if anyone's interested youtu.be/r-2OjL8u9VI
YouTube video
YouTube
English
1
2
29
4.4K
ikakavas at infosec dot exchange retweetledi
Howie Hua
Howie Hua@howie_hua·
My best explanation of parallel lines:
Howie Hua tweet media
English
52
1.1K
10.5K
571.5K
ikakavas at infosec dot exchange
@raTxMole Thanks! Έχω δει και εγώ κανα δυο US αλλά έλεγα μήπως γλυτωσω το πήγαινε έλα του κινητού αν υπάρχει κάτι αξιόπιστο εδώ
Ελληνικά
0
0
0
55
raTmole
raTmole@raTxMole·
@ilektrojohn Αν θέλεις τα data σου, δεν θα σου πρότεινα κανέναν Ελλάδα... Δες STS Telecom ststele.com/mail-in/ Και ipadrehab.com Είναι US αλλά κάνουν θαύματα
Ελληνικά
1
0
0
71
ikakavas at infosec dot exchange
#gr έχει κανείς εμπειρία από κάποια εταιρεία που κάνει data recovery από κινητα στην Ελλάδα ; iPhone που κάνει bootloop (βλάβη από νερό). Έχω δοκιμάσει τα τυπικά μαγαζιά επισκευών κλπ
Ελληνικά
2
0
0
739
ikakavas at infosec dot exchange
Being old : In an arctic monkeys show dancing by myself with Teddy Picker while the crowd discusses “it’s one of the old ones huh?”
English
0
0
3
650
ikakavas at infosec dot exchange retweetledi
The Offspring
The Offspring@offspring·
The Offspring tweet media
ZXX
776
8K
92.1K
6.5M
ikakavas at infosec dot exchange retweetledi
GRNET
GRNET@grnet_gr·
Δείτε την "Ανακοίνωση ΕΔΥΤΕ σχετικά με τις επιθέσεις στην Τράπεζα Θεμάτων" εδώ: grnet.gr/2023/06/03/ann…
GRNET tweet media
Ελληνικά
2
18
41
16.7K
ikakavas at infosec dot exchange
Which begs the question: Wouldn’t it be in Oracle’s best interest (it’s within its capabilities for sure) to release this information alongside the CPU? cc @seanjmullan
English
0
0
0
293
ikakavas at infosec dot exchange
TL;DR CVE-2023-21930 seems to be about TLS truncation attacks against TLS1.3 - Oracle credits Ben Smyth - Ben Smyth, A. Pironti have published about this type of attacks linkedin.com/pulse/what-tls… 1/2
ikakavas at infosec dot exchange@ilektrojohn

Hey Oracle can you be a little more vague with the CVEs you release in your CPUs ? oracle.com/security-alert… Boilerplate statements every quarter.. Anyone has additional info on CVE-2023-21930 ?

English
1
2
3
1.7K
ikakavas at infosec dot exchange retweetledi
OpenSSF
OpenSSF@openssf·
We're accepting applications through April 25th for a remote, paid, 12-week summer mentorship through the brand new Alpha-Omega Security Research Mentorship Program. Apply at: mentorship.lfx.linuxfoundation.org/project/4df8fa…
OpenSSF tweet media
English
0
6
10
1.9K