Skip to main content
 

Recasting Algorithmic bias as security vulnerabilities with specific harms and a bug bounty is brilliant! Now I want a "Project Zero" team to go out and find these.

https://hackerone.com/twitter-algorithmic-bias

 

Verifying my Knowledge Panel.

Didn't expect to have to Include a selfie with my ID.

Remembering people that used to have fake IDs just to buy booze it seems like a bit of security theater...





 

MLS provides a security layer for group messaging applications with from two to a large number of clients. It is meant to protect against eavesdropping, tampering, and message forgery.

Whoa, Ratchet trees...

https://tools.ietf.org/html/draft-barnes-mls-protocol-00

 

CitC on mac, really hope security kittens are in my favor..

https://g3doc.corp.google.com/devtools/srcfs/g3doc/mac-citc.md









 

On my 3rd Nexus 6p. Things I have learned:

- Always upgrade the new phone to the latest build or backup/restore breaks. (With security updates that meant *6* restarts.)
- Good time to prune unused Apps.
- Don't forget to recache: Play Music playlists and Maps Offline data.
- Open each app one-by-one to get rid of "Okay, got it" prompts.

Things that are still painful:
- Entering long 20 character passwords in apps
- Transferring TOTPs in Authenticator











 

ZeroTier looks really, nice. Sadly I suspect it violates many security kittens...


https://www.zerotier.com/blog/?p=833






 

Anyone from Security team want to sign on to this? Cory Doctorow asked me to send it onwards.


https://www.eff.org/deeplinks/2016/03/security-researchers-tell-w3c-protect-researchers-who-investig...






 

So I was just saying to myself wouldn't it be great if we could have incognito iframes and behold! there it is..  iframe sandbox's unique origin solves that problem...

Anyone using this in practice?  I'd love to use this as a way to serve up 3P content and supply the appropriate user information directly from the parent via postMessage to avoid user-overlap confusion.


http://www.html5rocks.com/en/tutorials/security/sandboxed-iframes/






 

Security Escalation help?

We found about 1m users that are infected with a chrome extension that rewrites search result pages (See http://b/7465588).  We've gotten some good help on some of the issues, but I feel like I haven't gotten the right people involved to deal with this properly.

- Can we notify those 1m users that they are infected?
- Can we detect that this extension is running on the SRP and stop it?

I can't tell who on Search to raise this issue to, and I cannot see who would coordinate an outreach program to the poor folks that are getting a crappy chrome experience due to the dodgy extension...

Thanks









 

A bit tired of wordpress security issues. I've had to help friends get upgraded after they got _pharma'd_ and today the LinkedIn blog was compromised. What's funny is that they reset my LinkedIn account in addition to my WP account..

[and no I didn't realize that I still had access to the LinkedIn blog :)]









 

Take your Security vitamins!

Security reviews may seem unpleasant, but they're really important to defend our users against the bad folks out there and just plain unintentional sloppiness.

I have to commend the team, their diligence revealed some hair raising issues in a SaaS partner that could have had disastrous consequences for us and all of said partner's customers.

[image CC BY-NC-SA from http://www.flickr.com/photos/teeves/]


https://plus.google.com/photos/107786897865850743842/albums/5717225082897424049/5717225079236654674






 

Shindig security tokens can be made into bearer tokens without much difficulty re: http://ff.im/jtlYP