Stefan Viehböck's Avatar

Stefan Viehböck

@sviehb.bsky.social

11 Followers  |  29 Following  |  1 Posts  |  Joined: 30.12.2023  |  1.561

Latest posts by sviehb.bsky.social on Bluesky

Preview
Mixing up Public and Private Keys in OpenID Connect deployments - Hanno's blog This blog is written by Hanno Böck. Unless noted otherwise, its content is licensed as CC0.

Hanno Böck (of badkeys.info among other projects) posted an interesting article about OpenID Connect implementations that mix up their public and private keys:

25.02.2025 19:55 — 👍 2    🔁 2    💬 1    📌 0
Preview
A Missed Opportunity: Addressing Weak Password Hashing in VxWorks The security of embedded systems running Real-Time Operating Systems (RTOS) like Wind River VxWorks is vital in high stakes sectors such as OT, defense, and aviation.

VxWorks 6.9 uses SHA-256 + salt but with only one iteration 🤦‍♂️ this was implemented in response to CVE-2010-2965 by
@hdm.io Check out the full disclosure drama: sec-consult.com/blog/detail/...

27.01.2025 15:26 — 👍 5    🔁 2    💬 1    📌 0

@sviehb is following 20 prominent accounts