Click here to Skip to main content
15,884,237 members

The Insider News

   

The Insider News is for breaking IT and Software development news. Post your news, your alerts and your inside scoops. This is an IT news-only forum - all off-topic, non-news posts will be removed. If you wish to ask a programming question please post it here.

Get The Daily Insider direct to your mailbox every day. Subscribe now!

 
GeneralRe: Low ceremony, high value: a tour of minimal APIs in .NET 6 Pin
Marc Clifton10-Jun-21 6:21
mvaMarc Clifton10-Jun-21 6:21 
NewsMany workers wish their employer was more empathetic Pin
Kent Sharkey9-Jun-21 8:31
staffKent Sharkey9-Jun-21 8:31 
GeneralRe: Many workers wish their employer was more empathetic Pin
Nelek9-Jun-21 8:48
protectorNelek9-Jun-21 8:48 
News<format> in Visual Studio 2019 version 16.10 Pin
Kent Sharkey9-Jun-21 8:31
staffKent Sharkey9-Jun-21 8:31 
NewsNot Windows 11? New Windows 10 name scheme hinted in Microsoft docs Pin
Kent Sharkey9-Jun-21 6:46
staffKent Sharkey9-Jun-21 6:46 
GeneralRe: Not Windows 11? New Windows 10 name scheme hinted in Microsoft docs Pin
Nelek9-Jun-21 8:47
protectorNelek9-Jun-21 8:47 
NewsHackers can mess with HTTPS connections by sending data to your email server Pin
Kent Sharkey9-Jun-21 6:46
staffKent Sharkey9-Jun-21 6:46 
GeneralRe: Hackers can mess with HTTPS connections by sending data to your email server Pin
Randor 9-Jun-21 8:43
professional Randor 9-Jun-21 8:43 
Hmmmm,

Maybe this is a good time to let you know that the paragraph below is referring to sites like codeproject that utilizes free TLS services.
The scenario isn't as farfetched as some people might think. New research, in fact, found that roughly 14.4 million webservers use a domain name that's compatible with the cryptographic credential of either an email or FTP server belonging to the same organization.
It's a simple and easy to understand concept:

Step 1.) Observe that codeproject is transparently using https://codeproject.global.ssl.fastly.net/[^]
Step 2.) Observe that the site certificate 'Subject Alternative Names' field contains *.freetls.fastly.net and *.global.ssl.fastly.net
Step 3.) Setup your free TLS account over at Fastly[^]. e.g. your.name.for.example.global.ssl.fastly.net
Step 4.) Observe that because the TLS negotiation checks for the match '*.global.ssl.fastly.net' that you can substitute site resources from your.name.for.example.global.ssl.fastly.net without a certificate warning.

The next steps might require an existing vertical position on the target (or destination) networks. A successful attack would result in running any javascript of your choice inside the target browser.
NewsHumans are ready to take advantage of benevolent AI Pin
Kent Sharkey8-Jun-21 10:31
staffKent Sharkey8-Jun-21 10:31 
GeneralRe: Humans are ready to take advantage of benevolent AI Pin
Joe Woodbury8-Jun-21 17:08
professionalJoe Woodbury8-Jun-21 17:08 
GeneralRe: Humans are ready to take advantage of benevolent AI Pin
David O'Neil8-Jun-21 17:46
professionalDavid O'Neil8-Jun-21 17:46 
JokeRe: Humans are ready to take advantage of benevolent AI Pin
Daniel Pfeffer8-Jun-21 20:54
professionalDaniel Pfeffer8-Jun-21 20:54 
GeneralRe: Humans are ready to take advantage of benevolent AI Pin
Nelek9-Jun-21 8:43
protectorNelek9-Jun-21 8:43 
GeneralRe: Humans are ready to take advantage of benevolent AI Pin
Dan Neely10-Jun-21 2:34
Dan Neely10-Jun-21 2:34 
NewsGraphene could allow hard drives to hold 10 times more data Pin
Kent Sharkey8-Jun-21 10:31
staffKent Sharkey8-Jun-21 10:31 
GeneralRe: Graphene could allow hard drives to hold 10 times more data Pin
Joe Woodbury8-Jun-21 17:13
professionalJoe Woodbury8-Jun-21 17:13 
GeneralRe: Graphene could allow hard drives to hold 10 times more data Pin
David O'Neil8-Jun-21 17:47
professionalDavid O'Neil8-Jun-21 17:47 
GeneralRe: Graphene could allow hard drives to hold 10 times more data Pin
Kent Sharkey8-Jun-21 19:41
staffKent Sharkey8-Jun-21 19:41 
NewsHere's how one mistake took down a huge chunk of the internet this morning Pin
Kent Sharkey8-Jun-21 10:31
staffKent Sharkey8-Jun-21 10:31 
JokeRe: Here's how one mistake took down a huge chunk of the internet this morning Pin
Bernhard Hiller8-Jun-21 20:08
Bernhard Hiller8-Jun-21 20:08 
GeneralRe: Here's how one mistake took down a huge chunk of the internet this morning Pin
Nelek9-Jun-21 8:37
protectorNelek9-Jun-21 8:37 
NewsOhio sues Google, claims tech giant should be regulated as public utility Pin
Kent Sharkey8-Jun-21 9:31
staffKent Sharkey8-Jun-21 9:31 
NewsThe top-ranking HTML editor on Google is an SEO scam Pin
Kent Sharkey8-Jun-21 9:31
staffKent Sharkey8-Jun-21 9:31 
GeneralRe: The top-ranking HTML editor on Google is an SEO scam Pin
Joe Woodbury8-Jun-21 17:20
professionalJoe Woodbury8-Jun-21 17:20 
GeneralRe: The top-ranking HTML editor on Google is an SEO scam Pin
David O'Neil8-Jun-21 17:49
professionalDavid O'Neil8-Jun-21 17:49 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.