Security Flaws with Apple's Two-Factor Authentication (2019)

Background Apple has made recent updates to its two-factor authentication system. Important parts of this system are undocumented, and thi... | Continue reading


@privacylog.blogspot.com | 2 years ago

The Ethics of Not Disclosing Vulnerabilities

From Moxie Marlinspike in the Signal blog : We are of course willing to responsibly disclose the specific vulnerabilities we know about to C... | Continue reading


@privacylog.blogspot.com | 3 years ago

What Happens When You Send a Zero-Day to a Bank? (2017)

UPDATE 2017-04-22: Corrected confusing wording, thank you Sujan. Fixed typos, thank you jacquesm, komali2, LanceH. In October 2008, shortly... | Continue reading


@privacylog.blogspot.com | 3 years ago

The Second SHA-1 Hash Collision

These are two small files which are different but have the same SHA-1 sum. And we're breaking the news here on Privacy Log. File 1 — f92... | Continue reading


@privacylog.blogspot.com | 4 years ago