Quantcast
Channel: User Tom - Information Security Stack Exchange
Browsing index pages (51 articles)
↧

Answer by Tom for Do pentesters need to be able to fix their findings for...

I've heard that some companies expect pentesters to fixvulnerabilities themselves.Heard where and what exactly did it say?Because I think you misunderstood something. As a customer, I expect that the...

View Article


Comment by Tom on How can I check password strength client-side?

@JimTheFrog it's definitely more secure than "password" or "12345". I still wouldn't use it for my inline banking. Would you?

View Article


Comment by Tom on How are all public computers (libraries, etc.) not full of...

Of course you can find examples where someone just bought a cheap PC and set it up with default settings. In that case, the answer is: "They are, and nobody cares." - but in many places people do care...

View Article

Comment by Tom on What's the best format or way to generate a short-lived...

client-side hashing is usually done with a challenge-response mechanism.

View Article

Answer by Tom for Is loss of availability automatically a security incident?

It depends on your definition.If you're going the ISO 27001 or other ISMS route, you somewhere define your security goals. If availability or rather a certain level of availability is defined as a...

View Article


Comment by Tom on Should user's password strength be assessed at client or at...

Sure you can. But why bother when they're already out on the Internet in plain?

View Article

Answer by Tom for Why is much harder to encrypt emails, compared to web pages?

Your assumption is wrong.Your e-mails actually are encrypted the same way that web pages are. It's just that there are two hops, not one.Due to the asynchronous nature of e-mail, it gets delivered...

View Article

Comment by Tom on Passphrase generator using German word list and Python's...

@phunsoft if they need to type it in, yes. If they need to use it multiple times, yes. If they need it once and will likely copy&paste, it doesn't matter.

View Article


Comment by Tom on HTTP: how likely are you to be compromised by using it just...

@JonBentley I never assumed that the site stores the TRANSMISSION. You are right that my scenario doesn't work for credit cards if the site doesn't store them. The other scenario is a password, and the...

View Article


Comment by Tom on How to deal with monitoring software on a personal PC used...

@Jan they are either ignorant or shrug off the risk. In either case, if it happens it is likely that OP will be blamed for it, not the lack of proper security.

View Article

Comment by Tom on How to deal with monitoring software on a personal PC used...

It's not just lowest bidder, it's also lowest security. Many security policies I've written explicitly disallow BYOD because it means additional security hassle. They're cutting corners here, and...

View Article

Comment by Tom on How to deal with monitoring software on a personal PC used...

An employer worried about screen shots should be told that smartphone cameras are a thing.

View Article

Comment by Tom on Is this idea for secure password storage a good one?

@security_paranoid I pointed out that you just posted it not to shame you, but to show you the contradiction in your own statements - you realise that a security idea should be checked by many others,...

View Article


Comment by Tom on How does Facebook Pixel's new first-party cookie work?

similar question elsewhere: stackoverflow.com/questions/71778566/…

View Article

Comment by Tom on Choosing laptop brand for company

@MikeB state-actor placed backdoors are valuable commodities. They won't be used for a run-of-the-mill ransomware campaign. And once they're no longer 0-days, there are usually OS-level workarounds.

View Article


Answer by Tom for I'd like to upload photos anonymously

What is your threat model and who do you want to remain anonymous towards?For ordinary users, removing all the meta-data from a photo (such as the EXIF data) would do the job.For advanced users capable...

View Article

Answer by Tom for bruteforce local software's password

Frame challenge: The reason these tools don't exist is that it is generally easier to do traditional cracking, i.e. finding the place in the code where it tests and branches and replace that with a NOP...

View Article


Answer by Tom for Our fingerprint were leaked from the vulnerable voting...

Yes, you should be worried, but not as much as you think.Your data being available digitally means that it is a lot easier for a possible attacker to abuse it than the many other attack paths, which...

View Article

Answer by Tom for Are JWT refresh tokens in browser really that bad?

After some research and thinking, this is pretty much how I've implemented it.I agree with your reasoning, and the access/refresh token is fairly well established best practice.Your mechanics should...

View Article

Answer by Tom for Realistically, how likely it is to have a computer...

Perhaps this was naivety on my side, but I usually thought thatbrowsing the web is (supposed to be?) a relatively safe thing to do(barring stupidities such as downloading & running cracks). But now...

View Article
Browsing index pages (51 articles)


Latest Images