tribut
@tribut@infosec.pub
This is a remote user, information on this page may be incomplete. View at Source ↗
- Comment on The gpg.fail aftermath: On responsible disclosure, GPG, and the state of security in 2026 4 days ago:
Cleatext signing (having the signature and data in the same file) is broken in many ways. It is possible to put unsigned data at the top of the file in a way that sha256sum will use it. Watch the 39c3 GPG talk if your interested in the gory details.
The solution is to use detached signatures (checksum.txt and checksum.txt.gpg to verify that). This makes sure that all of checksum.txt is actually covered by the signature.
- Comment on Patch now: CISA warns of actively exploited Linux kernel zero-day (CVE-2026-43456) 2 months ago:
Except it does not actually appear on CISA’s KEV list?
- Comment on Privacy and Security Risks in the eSIM Ecosystem [pdf] 1 year ago:
- Comment on AI-Generated Malware in Panda Image Hides Persistent Linux Threat 1 year ago:
If you haven’t heard of polyglots, you might enjoy every talk by Ange Albertini. Start here (they are all awesome): …ccc.de/…/31c3_-_5930_-_en_-_saal_6_-_20141229140…
- Comment on Could you fcking not. 1 year ago:
You missed the part where the first step was
a) Euthanize Spider