Security Leftovers
-
LWN ☛ Coker: The CUPS vulnerability
Debian Developer Russell Coker has written up an analysis of the remote exploit of CUPS announced in September:
He seems to have a different experience to me of reporting bugs, I have had plenty of success getting bugs fixed without hyping them. I just report the bug, wait a while, and it gets fixed. [...] I was quite confident that my systems wouldn't be at any risk.
When it was published my opinion was proven to be correct, it turned out to be a series of CUPS bugs.
-
OpenSSF (Linux Foundation) ☛ OpenSSF Adds Minder as a Sandbox Project to Simplify the Integration and Use of Open Source Security Tools
Today, I’m excited to announce that Stacklok is contributing our Minder open source project to the Open Source Security Foundation (OpenSSF). Minder makes it simpler for developers and security teams to adopt a policy-based approach to open source software security; it reduces noise, alerts to risk only when necessary, auto-remediates inconsistencies and spans the entire software development lifecycle.
-
LWN ☛ Security updates for Tuesday
Security updates have been issued by Debian (exim4) and SUSE (chromium, openssl-1_1, and openssl-3).
-
PC World ☛ Security flaws found in all Nvidia GeForce GPUs. Update drivers ASAP!
Graphics card manufacturer Nvidia is currently issuing a warning to all owners of GeForce GPUs. According to an Nvidia security bulletin, several security vulnerabilities requiring urgent attention have been discovered in the company’s own display drivers and other software.
A total of eight vulnerabilities are listed, all of them with a “High” severity rating. If you have an Nvidia GeForce GPU, you need to act now.
-
Dark Reading ☛ Recurring Windows Flaw Could Expose User Credentials
Now a zero-day, the vulnerability enables NTLM hash theft, an issue that Microsoft has already fixed twice before.
-
Integrity/Availability/Authenticity
-
Tech Central (South Africa) ☛ The case for digital identity in South Africa
South Africa has become fertile ground for cybercrime. According to a new report by the CSIR, 47% of organisations reported experiencing between one and five cybersecurity incidents in the past year, “underscoring the persistent threat landscape”.
A key recommendation: improve digital identity management and implement robust solutions to protect users online.
A digital identity is an electronic form of identification, including biometric information, that can be used to interact with governments, businesses and other organisations online. It is a key enabler of digital transformation and offers a range of benefits, from improving service delivery to enhancing security.
-
Pierre 'delroth' Bourdon ☛ delroth's homepage - One weird trick to get the whole planet to send abuse complaints to your best friend(s)
Turns out, it’s pretty trivial to send packets to various destinations on the Internet with a fake source IP address (of course, the destination IP needs to be correct, since it determines… the destination). Many ISPs adhere to the Best Current Practice (BCP) 38, which can be summarized by the following: “if you peer with a network, you should only allow them to send IP packets using IP address you expect from them”. Unfortunately, that filtering can often only be done early on in a packet’s route to its destination. Once the packet gets to a large transit provider, their peers expect that provider to carry traffic from the whole internet to them, and thus are not able to do any meaningful filtering.
Which means, if you just find one transit provider which doesn’t do BCP38 filtering… you can send IP packets tagged with any source IP you want! And unfortunately, even though the origins of BCP38 date back to 1998… there are still network providers 25 years later that don’t implement it. APNIC has a great article from last year on the subject.
-
-
Transparency/Investigative Reporting
-
The Dissenter ☛ Columbus Ends Campaign Against Data Breach Whistleblower
The City of Columbus agreed to a "permanent injunction” with cybersecurity specialist Connor Goodwolf and withdrew a lawsuit against him.
-