Please tell your friends about federated social media site that speaks several fediverse protocols thus serving as a hub uniting them, hubzilla.eskimo.com, also check out friendica.eskimo.com, federated
macroblogging social media site, mastodon.eskimo.com a federated microblogging site, and yacy.eskimo.com an uncensored federated search engine. All Free!
@dangoodin The TOTPs I've used timed out in 30 seconds. I agree with Ian that allowing any key material to leak to a log is bush league. I agree with Proton that this is not a high impact problem (if attacker is "inside" your phone you're in rough shape).
and still people are stupid enough to believe that the rest of their products definitely aren't at LEAST that bad, and just hidden behind closed doors.
BTW, their "AI" Lumo? Leaks like a fucking sieve and is anything but private or secure.
Oh, and this keeps happening. Over and over and over again.
BUT IT'S DEFINITELY NOT A PATTERN, THE NAZI-SUPPORTING CEO IS ONE OF THE GOOD GUYS!
am I reading this right that it logged the secrets only to the mobile device? So a threat actor would need remote or physical access to the phone in order to exploit this?
Dan Goodin
in reply to Ian Campbell π΄ • • •Ian Campbell π΄
in reply to Dan Goodin • • •@dangoodin Something like that, yep.
But leaking secrets in logs as plaintext is a very well-known pitfall that shouldn't make it to prod.
Marcus
in reply to Ian Campbell π΄ • • •Dan Goodin
in reply to Marcus • • •Yes, you just nailed it.
Ian Campbell π΄
in reply to Dan Goodin • • •RootWyrm πΊπ¦
in reply to Ian Campbell π΄ • • •and still people are stupid enough to believe that the rest of their products definitely aren't at LEAST that bad, and just hidden behind closed doors.
BTW, their "AI" Lumo? Leaks like a fucking sieve and is anything but private or secure.
Oh, and this keeps happening. Over and over and over again.
BUT IT'S DEFINITELY NOT A PATTERN, THE NAZI-SUPPORTING CEO IS ONE OF THE GOOD GUYS!
Ian Campbell π΄
Unknown parent • • •dan
in reply to Ian Campbell π΄ • • •Ian Campbell π΄
in reply to dan • • •@dan Yep, and that's a fair point as far as exploitability goes.
But not logging secrets to logs is basic, 101-level engineering, and they shipped this to prod.
SpaceLifeForm
in reply to Ian Campbell π΄ • • •Bill
in reply to Ian Campbell π΄ • • •Eemon
in reply to Ian Campbell π΄ • • •