6

In his groundbreaking new research, HTTP/1.1 Must Die: The Desync Endgame, Kettle challenges the security community to completely rethink its approach to request smuggling. He argues that, in practical terms, it's nigh on impossible to consistently and reliably determine the boundaries between HTTP/1.1 requests, especially when implemented across the chains of interconnected systems that comprise modern web architectures. Mistakes such as parsing discrepancies are inevitable, and when using upstream HTTP/1.1, even the tiniest of bugs often have critical security impact, including complete site takeover.

This research demonstrates unequivocally that patching individual implementations will never be enough to eliminate the threat of request smuggling. Using upstream HTTP/2 offers a robust solution.

I just read this article in a marketing blog from portswigger, the maker of the penetration testing tool burp suite.

Can someone with more insight explain what we're supposed to do? Completely disabling HTTP/1.1 is probably not doable for many organisations.

52
Ivanti (feddit.org)
15
submitted 5 months ago by cron@feddit.org to c/imageai@sh.itjust.works

Made with Mistral / Le Chat.

create a funny 4 panel comic, how to draw a lion. panels 1-3 contain extremely basic shapes of the lion, panel 4 the finished, colored lion. this comic should be fun because the step from 3 to 4 will be ridiculously hard.

111

Love it when someone falls for phishing, gives away their login, and just… says nothing. Really helpful.

18
submitted 5 months ago by cron@feddit.org to c/asklemmy@lemmy.world
49
submitted 5 months ago by cron@feddit.org to c/imageai@sh.itjust.works

As a fun experiment, I asked ChatGPT to create an image of me based on my chat history. I've been chatting with it for a while, so it has some ideas. Here is an example prompt that you could use to try this too:

Create an image of how you imagine me to look based solely on our chat history. Estimate my age, gender, hairstyle, skin tone, body type, clothing, and background scene. Use clues from my personality, interests, and writing style to visualize a realistic portrait.

If you use ChatGPT, feel free to share how the AI imagines you to look - based solely on your conversations!

91
70
submitted 5 months ago by cron@feddit.org to c/asklemmy@lemmy.world

And what can other leaders learn from it?

60
submitted 5 months ago by cron@feddit.org to c/asklemmy@lemmy.world

Please share your success stories :)

132
submitted 5 months ago by cron@feddit.org to c/imageai@sh.itjust.works

Just as an experiment, it appears that drawing maps isn't one of the strengths of AI.

Made with le chat, ChatGPT does a little better.

53
submitted 6 months ago* (last edited 6 months ago) by cron@feddit.org to c/sysadmin@lemmy.world

From a simple KeePass database to enterprise credential management solutions—what’s your setup at work?

[-] cron@feddit.org 90 points 7 months ago

The "conservative party" is the CDU/CSU, and even though they won, they just had their second worst result since the 1950s.

[-] cron@feddit.org 61 points 8 months ago* (last edited 8 months ago)

found a bug ;)

Edit: where is the link?

8
I hate passwords (feddit.org)
submitted 8 months ago* (last edited 8 months ago) by cron@feddit.org to c/cybersecuritymemes@lemmy.world

How on earth can you both not accept the password I copied from my password safe and tell me that I cannot use the same pasaword again?

[-] cron@feddit.org 67 points 9 months ago

Or even worse, six hours of video making LED christmas lights look like the incandescent light from 30 years ago.

[-] cron@feddit.org 120 points 10 months ago* (last edited 10 months ago)

If it's a civil and interesting discussion, why not?

[-] cron@feddit.org 120 points 11 months ago

The worst are apps that send ads through notifications.

[-] cron@feddit.org 65 points 1 year ago

When I started using linux 15 years ago, my friend recommended to keep a windows partition for gaming. At least for me, I have deleted windows a few years ago and I'm not looking back.

[-] cron@feddit.org 88 points 1 year ago

Oh I had the same thought. Whoever limits password length probably has many other shitty security practices.

[-] cron@feddit.org 149 points 1 year ago

Apparently, this is true.

Just WTF.

[-] cron@feddit.org 62 points 1 year ago* (last edited 1 year ago)

On a personal note, I'm annoyed that our national ID app doesn't work with graphene OS.

There are workarounds by patching out the security check from the app and sideloading the newly created app, but that is just annoying and has to be repeated for every update.

I just don't see how rigorose device checks that lock out graphene users, but allow any Android 8.0+ device (where security support ended more than 3 years ago) make ANY sense.

Edit: I tried it again today, it now lets me skip with a warning about the bootloader.

[-] cron@feddit.org 121 points 1 year ago

The site provides a nice TL,DR:

  • Efforts like Graphene OS face increasing pressure from apps that refuse to run on non-standard Android.
  • The custom ROM project characterizes Google’s approach to device attestation as incomplete and flawed.
  • Graphene OS is prepared to take legal action if Google won’t let it pass Play Integrity checks.
[-] cron@feddit.org 67 points 1 year ago

I just tried this exact prompt with bing image creator.

The result looks like my first tries with photoshop:

[-] cron@feddit.org 91 points 1 year ago

Whenever YouTube changes something, newpipe adapts to it within one or two days. Thanks to the devs!

view more: next ›

cron

joined 1 year ago