Avatar

solidsnail

solidsnail@infosec.pub
Joined
10 posts • 6 comments
Direct message

That is very true.
I do think that there’s more depth to it than that. For example, dealing with it on the end of the terminal will probably break compatibility, and dealing with it on the app end will require every single dev to start sanitizing this. The challenges are real.

permalink
report
parent
reply

I think they’re lacking explanation of what the data means.

This can be very nuanced, and dependent on your goals.

For example, in the context of fingerprinting, sometimes it’s better to provide fake data instead of no data, because that itself can be a unique characteristic.

permalink
report
reply

I feel like I’m a bit lacking when it comes to finding race condition vulnerabilities. Any tips on that?

permalink
report
reply

Took them 5 years to fix a critical vulnerability.

Really shows their concern for security.

permalink
report
parent
reply