Подтвердите e-mail

Для публикаций, комментариев, реакций и сообщений подтвердите адрес.

Профиль

Dan Goodin

Профиль Vively

Cybersecurity Reporter, Ars Technica: https://arstechnica.com/author/dan-goodin/ Hungry for tips. Text me on Signal: DanArs.82. "The world isn’t run by weapons anymore, or energy, or money. It’s run by little 1s and 0s, little bits of data."

A quantum-resistant cryptography algorithm that was under consideration to become an official US standard has been taken out of the running after an Anthropic security model helped find a flaw that rendered it broken. arstechnica.com/security/202...

Mythos attack on 3rd-round PQC algorithm candidate puts it out of commissionHAWK withstood years of testing that had yet to uncover a fatal weakness found through Mythos.arstechnica.com
0195

You too can turn a Bluetooth device into a PC-pwning proxy arstechnica.com/security/202...

How a USB-connected speaker can infect a PC without ever being touchedSeller of the Sound Blaster Katana V2X doesn't consider the behavior a vulnerability.arstechnica.com
0224

If it wasn't already, 2FA spraying is now a thing, as Dashlane users now know. arstechnica.com/security/202...

Dashlane explains how attackers managed to download encrypted password vaultsBy targeting large numbers of users, attackers increased their chances of success.arstechnica.com
1101

Can’t make sense of Dashlane’s vault theft notification? You’re not alone. arstechnica.com/security/202...

Can't make sense of Dashlane's vault theft notification? You're not alone.Security advisory leaves out key details. Dashlane maintains complete silence.arstechnica.com
040

Anybody know of any Linux distributions that have released fixes for Dirty Frag?

173

I just donated to SPLC because the work it does makes the world a safer and more just place. Please do the same if able.

The Washington Post

The Southern Poverty Law Center, an organization founded to promote racial justice in the South, said it is facing a Justice Department investigation including possible criminal charges over its past use of paid informants to infiltrate extremist groups.

0113

With growing focus on the threat quantum computing poses to crucial and widely used forms of encryption, @filippo.abyssdomain.expert wants to make one thing clear: Contrary to popular mythology that refuses to die, AES 128 is perfectly fine in a post-quantum world arstechnica.com/security/202...

Contrary to popular superstition, AES 128 is just fine in a post-quantum worldA stubborn misconception is hampering the already hard work of quantum readiness.arstechnica.com
0346

“Transitioning the Internet to post-quantum, especially for digital signatures, is a massive undertaking. By setting a 2029 goal, they are giving themselves some slack. If they target 2035 and miss by 2 years, we are getting uncomfortably close to the danger zone.” arstechnica.com/security/202...

Recent advances push Big Tech closer to the Q-Day danger zoneHere's which players are winning the race to transition to post-quantum crypto.arstechnica.com
071

Now, there's a 3rd Rowhammer attack on Nvidia GPUs that gains CPU root even when IOMMU is enabled. My story has been updated throughout. arstechnica.com/security/202...

New Rowhammer attacks give complete control of machines running Nvidia GPUsBoth GDDRHammer and GeForge hammer GPU memory in ways that compromise the CPU.arstechnica.comDan Goodin

The cost and shortage of GPUs means they're frequently shared among dozens of users in cloud environments. 2 new Rowhammer attacks demonstrate how a malicious user can gain full root control of the host machine running high-performance Nvidia GPU cards. arstechnica.com/security/202...

141

The cost and shortage of GPUs means they're frequently shared among dozens of users in cloud environments. 2 new Rowhammer attacks demonstrate how a malicious user can gain full root control of the host machine running high-performance Nvidia GPU cards. arstechnica.com/security/202...

New Rowhammer attacks give complete control of machines running Nvidia GPUsBoth GDDRHammer and GeForge hammer GPU memory in ways that compromise the CPU.arstechnica.com
1218

Building a utility-scale quantum computer that can crack one of the most vital cryptosystems—elliptic curves—doesn’t require nearly the resources anticipated just a year or two ago, two independently written whitepapers have concluded. arstechnica.com/security/202...

Quantum computers need vastly fewer resources than thought to break vital encryptionNo, the sky isn't falling, but Q Day is coming, and it won't be as expensive as thought.arstechnica.com
072

Google is dramatically shortening its readiness deadline for the arrival of Q Day, the point at which existing quantum computers can break public-key algorithms that secure decades’ worth of secrets belonging to militaries, banks, and nearly every individual on earth arstechnica.com/security/202...

Google bumps up Q Day deadline to 2029, far sooner than previously thoughtCompany warns entire industry to move off RSA and EC more quickly.arstechnica.com
21713

I was lucky enough to cover Cindy Cohn's trailblazing work BEFORE she joined @eff . Here's one of several stories I wrote about her when she was still an associate attorney in private practice.

091

Burner accounts on social media sites can increasingly be analyzed to identify the pseudonymous users who post to them using AI in research that has far-reaching consequences for privacy on the Internet, researchers said. arstechnica.com/security/202...

LLMs can unmask pseudonymous users at scale with surprising accuracyPseudonymity has never been perfect for preserving privacy. Soon it may be pointless.arstechnica.com
173

That guest SSID you set up for your neighbors may not be as secure as you think arstechnica.com/security/202...

New AirSnitch attack breaks Wi-Fi encryption in homes, offices, and enterprisesThat guest network you set up for your neighbors may not be as secure as you think.arstechnica.com
185

Contrary to what password managers say, a server compromise can mean game over. arstechnica.com/security/202...

Password managers' promise that they can't see your vaults isn't always trueContrary to what password managers say, a server compromise can mean game over.arstechnica.com
0128

If throngs of people handed over their IDs in exchange for a vanity blue check from a pro-authoritarian site, what reason is there to think Discord users won't do the same?

0140

Two security professionals who were arrested in 2019 after performing an authorized security assessment of a county courthouse in Iowa will receive $600,000 to settle a lawsuit they brought alleging wrongful arrest and defamation. arstechnica.com/security/202...

County pays $600,000 to pentesters it arrested for assessing courthouse securitySettlement comes more than 6 years after Gary DeMercurio and Justin Wynn's ordeal began.arstechnica.com
1145

Moxie Marlinspike—the engineer who set a new standard for private messaging with the creation of the Signal Messenger—is now aiming to revolutionize AI chatbots in a similar way. arstechnica.com/security/202...

Signal creator Moxie Marlinspike wants to do for AI what he did for messagingIntroducing Confer, an end-to-end AI assistant that just works.arstechnica.com
22012

In 15 minutes, NY AG Letitia James will participate in the Conde Nast union rally supporting the immediate reinstatement of 4 of our colleagues who were illegally fired in a union-busting move. If you're near WTC in Manhattan, please come and show your support.

0122
Показать ещё