Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Posts
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
You too can turn a Bluetooth device into a PC-pwning proxy
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
If it wasn't already, 2FA spraying is now a thing
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Can’t make sense of Dashlane’s vault theft notification? You’re not alone.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
There's so much I don't understand in Dashlane's disclosure that an attack on its user accounts resulted in the threat actor obtaining 20 encrypted vaults.
What does it mean to brute force 2fa? Are we talking about TOTPs? That doesn't make sense because TOTPs change every 30-90 seconds, so there's no way for an attacker to meaningfully exhaust key space before it resets all over -- unless the attacker has the ability to pump all 7,700 combinations in <90 seconds, and DL doesn't have any sort of rate limiting.
Also, if the attacker is brute forcing 2fa, doesn't that by necessity mean the attacker already defeated the first factor? How did that occur?
I don't know if my confusion is the result of me not knowing the how the Dashlane product works or if it's just Dashlane being opaque.
Can anyone help me read the tea leaves?
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Are MP3 players even a thing these days? What are some good brands/models?
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Can anyone help me find my AirTag attached keys? The FindMy app shows me their general location, which is a large public building where I last had them. When I go on site, my app is mostly unable to see them at all. Occasionally my app seems to be able to see a very weak signal but I can't seem to zero in on it. This is driving me nuts. I've looking now for two weeks. Anybody got tips?
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Would this move by Debian, requiring byte-for-byte reproducible builds, have caught any real-world supply chain attacks seen in the past?
https://itsfoss.com/news/debian-makes-reproducible-builds-mandatory/
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Anybody know of any Linux distributions that have released fixes for Dirty Frag?
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
There's a ton of skepticism over the true value of AI-assisted vulnerability discovery, and with good reason. Maybe the new details Mozilla has revealed don't tip the scales in favor of it being beneficial, but people should at least sift through them in good faith and with an open mind before declaring all of them bullshit.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
If you could ask any question to Mozilla concerning last month's The Zero-days are Numbered post, what would it be?
https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
With growing focus on the threat quantum computing poses to crucial and widely used forms of encryption, @filippo@abyssdomain.expert wants to make one thing perfectly clear: Contrary to popular mythology that refuses to die, AES 128 is perfectly fine in a post-quantum world
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Can someone explain @filippo@abyssdomain.expert's post to me like I'm a 5-year-old?
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Transitioning the Internet to post-quantum, especially for digital signatures, is a massive undertaking. By setting a 2029 goal, they are giving themselves some slack. If they target 2035 and miss by 2 years, we are getting uncomfortably close to the danger zone.”
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
I'm trying to understand a bit more about CVE-2026-33579, the critical vulnerability in OpenClaw. To exploit, an attacker needs low-level paring privilege permissions. How does one acquire such privileges? Can anyone do it? I'm asking because I want to understand what's required for an attacker to exploit.
Feel free to ping me at DanArs.82, or drop an answer here.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Google is dramatically shortening its deadline readiness for the arrival of Q Day, the point at which existing quantum computers can break public-key cryptography algorithms that secure decades’ worth of secrets belonging to militaries, banks, governments, and nearly every individual on earth.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
I was lucky enough to cover Cindy Cohn's trailblazing work BEFORE she joined @eff@mastodon.social . Here's one of several stories I wrote about her when she was still an associate attorney in private practice.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Wow, TeamPCP is hacking open-source developers faster than we can report on them. The latest (that I'm aware of, anyway) is LiteLLM. They worked with Trivy but didn't bother to change their credentials after Trivy was hacked, despite an ample amount of advice to do so.
Folks, if any of you used LiteLLM, now is the time to change your credentials, in an atomic way. Now, as in immediately.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Does anybody with a STRONG BACKGROUND IN WEBSITE PRIVACY have time to vet this research? Are TikTok and Meta pixels REALLY doing the things claimed? I'm concerned it may be overstating things in an attempt to sell its tag monitoring tools.
https://jscrambler.com/blog/beyond-analytics-tiktok-meta-ad-pixels
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Dear readers. If you're not willing to support the families of those you want to read then we regretfully will be preventing you from obtaining our work for free.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
If I hear one more person say that Beyonce isn't a real country singer/song writer and should stay in her own RnB/hip-hop lane I'm going to lose it.
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.