Answer by Tom for Do pentesters need to be able to fix their findings for...
I've heard that some companies expect pentesters to fixvulnerabilities themselves.Heard where and what exactly did it say?Because I think you misunderstood something. As a customer, I expect that the...
View ArticleComment by Tom on How can I check password strength client-side?
@JimTheFrog it's definitely more secure than "password" or "12345". I still wouldn't use it for my inline banking. Would you?
View ArticleComment by Tom on How are all public computers (libraries, etc.) not full of...
Of course you can find examples where someone just bought a cheap PC and set it up with default settings. In that case, the answer is: "They are, and nobody cares." - but in many places people do care...
View ArticleComment by Tom on What's the best format or way to generate a short-lived...
client-side hashing is usually done with a challenge-response mechanism.
View ArticleAnswer by Tom for Is loss of availability automatically a security incident?
It depends on your definition.If you're going the ISO 27001 or other ISMS route, you somewhere define your security goals. If availability or rather a certain level of availability is defined as a...
View ArticleComment by Tom on Should user's password strength be assessed at client or at...
Sure you can. But why bother when they're already out on the Internet in plain?
View ArticleAnswer by Tom for Why is much harder to encrypt emails, compared to web pages?
Your assumption is wrong.Your e-mails actually are encrypted the same way that web pages are. It's just that there are two hops, not one.Due to the asynchronous nature of e-mail, it gets delivered...
View ArticleComment by Tom on Passphrase generator using German word list and Python's...
@phunsoft if they need to type it in, yes. If they need to use it multiple times, yes. If they need it once and will likely copy&paste, it doesn't matter.
View ArticleComment by Tom on HTTP: how likely are you to be compromised by using it just...
@JonBentley I never assumed that the site stores the TRANSMISSION. You are right that my scenario doesn't work for credit cards if the site doesn't store them. The other scenario is a password, and the...
View ArticleComment by Tom on How to deal with monitoring software on a personal PC used...
@Jan they are either ignorant or shrug off the risk. In either case, if it happens it is likely that OP will be blamed for it, not the lack of proper security.
View ArticleComment by Tom on How to deal with monitoring software on a personal PC used...
It's not just lowest bidder, it's also lowest security. Many security policies I've written explicitly disallow BYOD because it means additional security hassle. They're cutting corners here, and...
View ArticleComment by Tom on How to deal with monitoring software on a personal PC used...
An employer worried about screen shots should be told that smartphone cameras are a thing.
View ArticleComment by Tom on Is this idea for secure password storage a good one?
@security_paranoid I pointed out that you just posted it not to shame you, but to show you the contradiction in your own statements - you realise that a security idea should be checked by many others,...
View ArticleComment by Tom on How does Facebook Pixel's new first-party cookie work?
similar question elsewhere: stackoverflow.com/questions/71778566/…
View ArticleComment by Tom on Choosing laptop brand for company
@MikeB state-actor placed backdoors are valuable commodities. They won't be used for a run-of-the-mill ransomware campaign. And once they're no longer 0-days, there are usually OS-level workarounds.
View ArticleAnswer by Tom for I'd like to upload photos anonymously
What is your threat model and who do you want to remain anonymous towards?For ordinary users, removing all the meta-data from a photo (such as the EXIF data) would do the job.For advanced users capable...
View ArticleAnswer by Tom for bruteforce local software's password
Frame challenge: The reason these tools don't exist is that it is generally easier to do traditional cracking, i.e. finding the place in the code where it tests and branches and replace that with a NOP...
View ArticleAnswer by Tom for Our fingerprint were leaked from the vulnerable voting...
Yes, you should be worried, but not as much as you think.Your data being available digitally means that it is a lot easier for a possible attacker to abuse it than the many other attack paths, which...
View ArticleAnswer by Tom for Are JWT refresh tokens in browser really that bad?
After some research and thinking, this is pretty much how I've implemented it.I agree with your reasoning, and the access/refresh token is fairly well established best practice.Your mechanics should...
View ArticleAnswer by Tom for Realistically, how likely it is to have a computer...
Perhaps this was naivety on my side, but I usually thought thatbrowsing the web is (supposed to be?) a relatively safe thing to do(barring stupidities such as downloading & running cracks). But now...
View Article