the grugq's newsletter

Subscribe
Archives
November 3, 2024

November 3, 2024

November 3, 2024

reminder that the bcrypt hash function ignores input above a certain length! so if you do bcrypt(username || password) for some reason, a sufficiently long username will make it accept any password. to fix this you can sha256 the input first. https://t.co/UqqSFsT2kh

โ€” yan (@bcrypt) November 2, 2024

Until October 30, Okta generated "the cache key" by using bcrypt to "hash a combined string of userId + username + password", which allowed full password auth bypass for usernames of 52+ bytes and apparently required only partial knowledge of the password for other long usernames https://t.co/TOrNGIqVAD

โ€” Solar Designer (@solardiz) November 3, 2024


https://t.co/H680f6K6c8 Hacking the Edges of Knowledge: LLMs, Vulnerabilities, and the Quest for Understanding

โ€” Dave Aitel (@daveaitel) November 2, 2024


#SpyNews - week 44 (October 26-November 2):
A summary of 83 espionage-related stories from week 44 coming from ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡ฆ๐Ÿ‡ซ๐Ÿ‡ฎ๐Ÿ‡ท๐Ÿ‡ฎ๐Ÿ‡ถ๐Ÿ‡จ๐Ÿ‡ณ๐Ÿ‡ฌ๐Ÿ‡ท๐Ÿ‡น๐Ÿ‡ท๐Ÿ‡ท๐Ÿ‡บ๐Ÿ‡บ๐Ÿ‡ฆ๐Ÿ‡ฎ๐Ÿ‡ฑ๐Ÿ‡จ๐Ÿ‡พ๐Ÿ‡ง๐Ÿ‡ฉ๐Ÿ‡ฎ๐Ÿ‡น๐Ÿ‡ฐ๐Ÿ‡ต๐Ÿ‡ฐ๐Ÿ‡ท๐Ÿ‡ซ๐Ÿ‡ท๐Ÿ‡ฉ๐Ÿ‡ช๐Ÿ‡ต๐Ÿ‡ฑ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ง๐Ÿ‡ช๐Ÿ‡ฑ๐Ÿ‡ง๐Ÿ‡ธ๐Ÿ‡พ๐Ÿ‡จ๐Ÿ‡ญ๐Ÿ‡น๐Ÿ‡ฏ๐Ÿ‡ฏ๐Ÿ‡ต๐Ÿ‡ป๐Ÿ‡ณ๐Ÿ‡ฎ๐Ÿ‡ณ๐Ÿ‡จ๐Ÿ‡ฆ๐Ÿ‡พ๐Ÿ‡ช๐Ÿ‡ฑ๐Ÿ‡ป๐Ÿ‡ญ๐Ÿ‡บ๐Ÿ‡ต๐Ÿ‡ธ๐Ÿ‡ณ๐Ÿ‡ฑ๐Ÿ‡ฆ๐Ÿ‡ฟ๐Ÿ‡ฆ๐Ÿ‡บ๐Ÿ‡ฒ๐Ÿ‡ฆ๐Ÿ‡ช๐Ÿ‡ฌ๐Ÿ‡ฏ๐Ÿ‡ด๐Ÿ‡ป๐Ÿ‡ช๐Ÿ‡ฆ๐Ÿ‡ช๐Ÿ‡ง๐Ÿ‡พ https://t.co/452TDG6nyE#OSINT #HUMINT #SIGINT #spy #espionage

โ€” Spy Collection (@SpyCollection1) November 3, 2024


meanwhile on Google pic.twitter.com/raaX72jA8g

โ€” nixCraft ๐Ÿง (@nixcraft) November 2, 2024


I'm pretty sure the Chinese govt released this explicitly to slow down AI development in the West. They have excellent homegrown models, better than the older Llamas, it's the only actual explanation. pic.twitter.com/PoyXyMb8Pe

โ€” rohit (@krishnanrohit) November 2, 2024


Vatican, Israel implicated in Italy hacking scandal, leaked files reveal

Well, thatโ€™s an unusual pairing.

This seems sensationalist for the actual stories.

Italian intelligence firm Equalizeโ€ฆis accused of working for Israeli intelligence and the Vatican, police wiretaps leaked to Italian media show.

Thatโ€™s scary!

The job was a cyber operation against Russian targets, including President Vladimir Putin's unidentified "right-hand man," and unearthing the financial trail leading from the bank accounts of wealthy figures to the Russian mercenary group Wagner. The information was then supposed to be passed on to the Vatican.

Oh. That sounds entirely reasonable. Not the sort of thing that was implied earlier, but letโ€™s carry on.

The Israelis offered to hand over intelligence material as well:

โ€ฆoffered the Italian firm information that could help one of Equalizerโ€™s alleged clients, the Italian energy giant Eni, with information on the โ€œillicit trafficking of Iranian gas with Italian companies.โ€

Again, that sounds like a very reasonable operation. Help an Italian energy company stop the โ€œillicit trafficking of Iranian gasโ€ to Italian companies. Someone should probably look into that. The trafficking.

Whatever the case is regarding the company Equalize and their activities, it seems the Israel + Vatican angle is not problematic and just being hyped for clicks.

Vatican, Israel implicated in Italy hacking scandal, leaked files reveal โ€“ POLITICO

Police wiretaps show the sprawling global nature of an investigation into Milan-based private detectives and their clients.


Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X