Stop. Truncating. Hashes.
https://www.phoronix.com/news/OpenWrt-Compromised-ASU-Builds
This profile might be incomplete.
Open on infosec.exchange stacksmashingYouTube:
Personal infoAbout:
I'm an IT security researcher, and sometimes I make videos about that! Contact: contact@stacksmashing.net
Wall 2 posts
Stop. Truncating. Hashes. https://www.phoronix.com/news/OpenWrt-Compromised-ASU-Builds In german we donât say âsecurity researcherâ, instead we say âHacker-Heinisâđ
Show previous comments
@stacksmashing this deserves a German reply that cannot be accurately translated: "Heul doch!" @stacksmashing that Apple-mentality: âThey didnât advertise that as a feature, it must be impossibleâ. Iâm joking, but it is kinda what you get. A product that does everything itâs meant to do well (As long as support lasts), but nothing extra. |
We run this security-sensitive service but only keep the logs for 7 daysđ
Obviously hindsight is 20/20, but a good example on why at companies I always want as much log retention as possible.
@stacksmashing I like to link people this if they think it's too difficult to brute-force a short hash prefix lol https://github.com/zegl/extremely-linear
@stacksmashing @Lyude isn't finding truncated SHA-256 hash collisions literally how bitcoin mining works