Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ Polish Blogger Sued After Revealing Security Issue In Encrypted Messenger

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š Polish Blogger Sued After Revealing Security Issue In Encrypted Messenger


๐Ÿ’ก Newskategorie: IT Security Nachrichten
๐Ÿ”— Quelle: it.slashdot.org

An anonymous reader quotes a report from The Record: The company behind the UseCrypt Messenger encrypted instant messaging application filed a lawsuit last month against a Polish security researcher for publishing an article that exposed a vulnerability in the app's user invite mechanism. The lawsuit targets Tomasz Zieliski, the editor of Informatyk Zakadowy, a Polish blog dedicated to IT topics, and denounces one of the site's articles, published in October 2020. The article describes how Zielinski found that in some cases, when UseCrypt Messenger users wanted to invite a friend to the app, the application used an insecure domain (autofwd.com) to send out user invitations. Zielinski found that besides running on an insecure HTTP connection, the AutoFWD.com website was also vulnerable to SQL injection and cross-site scripting (XSS) vulnerabilities that would have allowed anyone to hijack the site and then read or tamper with UseCrypt invitations. But while the authors of the AutoFWD.com website admitted to the security weaknesses in their service and shut down their website, Zieliski received a firm rebuttal of his research from V440 SA, the legal entity behind the UseCrypt Messenger. In a message the company sent Zieliski a day after his blog post went live, they claimed his research contained "false information." In a message the company sent Zieliski a day after his blog post went live, they claimed his research contained "false information." V440 SA said their app did not use the AutoFWD.com service to handle user invitations but instead relied on an in-house solution hosted on the get.usecryptmessenger.com domain. But in a subsequent update, Zieliski claims that the UseCrypt team was lying and that, in reality, they silently patched their app to remove the AutoFWD.com from its user invite mechanism after his research was posted online and were merely trying to dismiss his findings, even after he notified them in advance of his research. To make matters worse, V440 SA had reportedly filed criminal complaints against not only Zielinksi's blog but also against Niebezpiecznik and Zaufana Trzecia Strona, two other Polish IT security blogs, claiming that the three were working as part of an "organized criminal group." "Requests to remove articles, requests for apologies and other letters from law firms addressed to our editors will not make us stop being interested in a certain issue," the editors of the Polish blogs said in a joint statement. It's currently unknown if there is actually a criminal investigation underway against the three sites or if this is just an intimidation tactic.

Read more of this story at Slashdot.

...



๐Ÿ“Œ Polish Blogger Sued After Revealing Security Issue In Encrypted Messenger


๐Ÿ“ˆ 99.68 Punkte

๐Ÿ“Œ Encrypted Malware - A blog post I made as a fledgling security blogger, let me know what you think.


๐Ÿ“ˆ 28.1 Punkte

๐Ÿ“Œ The new Facebook Messenger Beta adds features, polish, and a dark mode


๐Ÿ“ˆ 26.56 Punkte

๐Ÿ“Œ Undercover reporter tells all after working for a Polish troll farm


๐Ÿ“ˆ 24.33 Punkte

๐Ÿ“Œ KDE is Slick. Coming back after years. Some more polish needed and it feels prime time.


๐Ÿ“ˆ 24.33 Punkte

๐Ÿ“Œ Ex-soldier pleads guilty to terror crime after not revealing iPhone PIN


๐Ÿ“ˆ 23.08 Punkte

๐Ÿ“Œ Ex-soldier pleads guilty to terror crime after not revealing iPhone PIN


๐Ÿ“ˆ 23.08 Punkte

๐Ÿ“Œ Google suspends Trends emails after revealing murder suspectโ€™s name


๐Ÿ“ˆ 23.08 Punkte

๐Ÿ“Œ After Strava, Polar is Revealing the Homes of Soldiers and Spies


๐Ÿ“ˆ 23.08 Punkte

๐Ÿ“Œ google in hot water after not revealing it had hidden a secret...


๐Ÿ“ˆ 23.08 Punkte

๐Ÿ“Œ google in hot water after not revealing it had hidden a secret...


๐Ÿ“ˆ 23.08 Punkte

๐Ÿ“Œ Take off Copilot Designer from web: a Microsoft Engineer after revealing it can produce extremely inappropriate content


๐Ÿ“ˆ 23.08 Punkte

๐Ÿ“Œ Blogger Post Title Parsing Error Issue


๐Ÿ“ˆ 23.06 Punkte

๐Ÿ“Œ Tor Winds Down Its Encrypted Messenger App 3 Years After Launch


๐Ÿ“ˆ 22.94 Punkte

๐Ÿ“Œ Apple Sued Over 2016 MacBook Pro 'Stage Lighting' Issue


๐Ÿ“ˆ 21.94 Punkte

๐Ÿ“Œ Should /boot be encrypted on an encrypted linux system?


๐Ÿ“ˆ 21.73 Punkte

๐Ÿ“Œ Hardware Encrypted Drive with Tails OS and Software Encrypted Persistence


๐Ÿ“ˆ 21.73 Punkte

๐Ÿ“Œ Encrypted Email: How to Send Encrypted Email (Outlook, Gmail iOS, Android, OSX or Webmail)


๐Ÿ“ˆ 21.73 Punkte

๐Ÿ“Œ Facebook sued hours after announcing security breach


๐Ÿ“ˆ 21.03 Punkte

๐Ÿ“Œ Health Clinic Sued Three Days after Announcing Massive Security Breach


๐Ÿ“ˆ 21.03 Punkte

๐Ÿ“Œ Health Clinic Sued Three Days after Announcing Massive Security Breach


๐Ÿ“ˆ 21.03 Punkte

๐Ÿ“Œ Zillow Drops Complaint Against Blogger After Backlash Over Copyright Claim


๐Ÿ“ˆ 20.24 Punkte

๐Ÿ“Œ Blogger Stabbed To Death After Internet Abuse Seminar


๐Ÿ“ˆ 20.24 Punkte

๐Ÿ“Œ Ah, um, let's see. Yup... Fortnite CEO is still mad at Google for revealing security hole early


๐Ÿ“ˆ 20.08 Punkte

๐Ÿ“Œ Taj Hotels Faces Data Breach, Revealing Data of 1.5 Million Customers - IT Security News


๐Ÿ“ˆ 20.08 Punkte

๐Ÿ“Œ Lastpass released the first annual, โ€œ2018 global password security report,โ€ revealing true password behaviors in the workplace.


๐Ÿ“ˆ 20.08 Punkte

๐Ÿ“Œ Polish banks hit by malware sent through hacked financial regulator


๐Ÿ“ˆ 19.4 Punkte

๐Ÿ“Œ Demystifying targeted malware used against Polish banks


๐Ÿ“ˆ 19.4 Punkte

๐Ÿ“Œ Polish Banks Hacked via Malware Coming from Financial Regulator


๐Ÿ“ˆ 19.4 Punkte

๐Ÿ“Œ Polish Kidnapper Tried Selling British Model on Dark Web


๐Ÿ“ˆ 19.4 Punkte

๐Ÿ“Œ Enigma message crack honours pioneering Polish codebreakers


๐Ÿ“ˆ 19.4 Punkte

๐Ÿ“Œ Huawei Sacks Polish Sales Director Over Spying Allegations


๐Ÿ“ˆ 19.4 Punkte

๐Ÿ“Œ Polish Banks Hacked using Malware Planted on their own Government Site


๐Ÿ“ˆ 19.4 Punkte











matomo