Security Leftovers

-
Nissan Source Code Leaks Due to Embarrassing Security Fail
The North American unit belonging to the Japanese carmaker was using a Bitbucket Git server “secured” with the default login credentials (username: admin, password: admin), thus exposing the source code of mobile apps, the internal core mobile library, sales and marketing research tools and data, client services, the dealer portal, and even tools related to connected car services.
-
Misconfigured Git servers lead to Nissan data leak
The researcher also found details on Nissan’s internal core mobile library, NCAR/ICAR services, client acquisition and retention tools, sale/market research tools and data, various marketing tools, and vehicle logistics portal.
The leak stemmed from a Git server that was left visible online with its default username and password combo of “admin.” Nissan is probing the leak, and the Git server was taken offline after the data started disseminating on Monday via Telegram channels and [cracking] forums.
-
The Most Backdoor-Looking Bug I've Ever Seen
This is the story of a bug that was discovered and fixed in Telegram’s self-rolled cryptographic protocol about sever years ago. The bug didn’t get any press, and no one seems to know about it, probably because it was only published in Russian.
To this day, it’s the most backdoor-looking bug I’ve ever seen.
Google Translate does a good enough job on the original article, which is still available on Habr, but I’m going to walk you through it along with some context.
-

- Login or register to post comments
Printer-friendly version- 3089 reads
PDF version
More in Tux Machines
- Highlights
- Front Page
- Latest Headlines
- Archive
- Recent comments
- All-Time Popular Stories
- Hot Topics
- New Members
digiKam 7.7.0 is released
After three months of active maintenance and another bug triage, the digiKam team is proud to present version 7.7.0 of its open source digital photo manager. See below the list of most important features coming with this release.
|
Dilution and Misuse of the "Linux" Brand
|
Samsung, Red Hat to Work on Linux Drivers for Future Tech
The metaverse is expected to uproot system design as we know it, and Samsung is one of many hardware vendors re-imagining data center infrastructure in preparation for a parallel 3D world.
Samsung is working on new memory technologies that provide faster bandwidth inside hardware for data to travel between CPUs, storage and other computing resources. The company also announced it was partnering with Red Hat to ensure these technologies have Linux compatibility.
|
today's howtos
|








.svg_.png)
Content (where original) is available under CC-BY-SA, copyrighted by original author/s.

Recent comments
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago