Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. We've come to an icky time in security when the concern about using outdated, unpatched software starts to become overshadowed by the fear of downloading some backdoored update.

We've come to an icky time in security when the concern about using outdated, unpatched software starts to become overshadowed by the fear of downloading some backdoored update.

Scheduled Pinned Locked Moved Uncategorized
21 Posts 20 Posters 3 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • briankrebs@infosec.exchangeB This user is from outside of this forum
    briankrebs@infosec.exchangeB This user is from outside of this forum
    briankrebs@infosec.exchange
    wrote last edited by
    #1

    We've come to an icky time in security when the concern about using outdated, unpatched software starts to become overshadowed by the fear of downloading some backdoored update.

    noplasticshower@infosec.exchangeN 20002ist@thepit.social2 sraars@hippodon.comS docpop@mastodon.socialD notasnek@infosec.exchangeN 16 Replies Last reply
    2
    0
    • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

      We've come to an icky time in security when the concern about using outdated, unpatched software starts to become overshadowed by the fear of downloading some backdoored update.

      noplasticshower@infosec.exchangeN This user is from outside of this forum
      noplasticshower@infosec.exchangeN This user is from outside of this forum
      noplasticshower@infosec.exchange
      wrote last edited by
      #2

      @briankrebs I guess the only real answer is building secure software in the first place

      1 Reply Last reply
      0
      • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

        We've come to an icky time in security when the concern about using outdated, unpatched software starts to become overshadowed by the fear of downloading some backdoored update.

        20002ist@thepit.social2 This user is from outside of this forum
        20002ist@thepit.social2 This user is from outside of this forum
        20002ist@thepit.social
        wrote last edited by
        #3

        @briankrebs

        Link Preview Image
        1 Reply Last reply
        0
        • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

          We've come to an icky time in security when the concern about using outdated, unpatched software starts to become overshadowed by the fear of downloading some backdoored update.

          sraars@hippodon.comS This user is from outside of this forum
          sraars@hippodon.comS This user is from outside of this forum
          sraars@hippodon.com
          wrote last edited by
          #4

          @briankrebs Return to abacus.

          jt_rebelo@ciberlandia.ptJ 1 Reply Last reply
          0
          • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

            We've come to an icky time in security when the concern about using outdated, unpatched software starts to become overshadowed by the fear of downloading some backdoored update.

            docpop@mastodon.socialD This user is from outside of this forum
            docpop@mastodon.socialD This user is from outside of this forum
            docpop@mastodon.social
            wrote last edited by
            #5

            @briankrebs this vibe is perfectly captured in Benn Jordan's video about finding malware in UniTree robot dogs https://www.youtube.com/watch?v=lA8WuXDXfcI

            futuristicrobert@infosec.exchangeF 1 Reply Last reply
            0
            • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

              We've come to an icky time in security when the concern about using outdated, unpatched software starts to become overshadowed by the fear of downloading some backdoored update.

              notasnek@infosec.exchangeN This user is from outside of this forum
              notasnek@infosec.exchangeN This user is from outside of this forum
              notasnek@infosec.exchange
              wrote last edited by
              #6

              @briankrebs doesn't this mean that a motivated bad actor could compromise Microsoft/Apple/Google/Amazon and break the world? Stongarm the nerds, then push out some diabolical patch.

              cyanautik@infosec.exchangeC 1 Reply Last reply
              0
              • R relay@relay.mycrowd.ca shared this topic
              • sraars@hippodon.comS sraars@hippodon.com

                @briankrebs Return to abacus.

                jt_rebelo@ciberlandia.ptJ This user is from outside of this forum
                jt_rebelo@ciberlandia.ptJ This user is from outside of this forum
                jt_rebelo@ciberlandia.pt
                wrote last edited by
                #7

                @sraars "someone stole the beads!" 😆 @briankrebs

                1 Reply Last reply
                0
                • docpop@mastodon.socialD docpop@mastodon.social

                  @briankrebs this vibe is perfectly captured in Benn Jordan's video about finding malware in UniTree robot dogs https://www.youtube.com/watch?v=lA8WuXDXfcI

                  futuristicrobert@infosec.exchangeF This user is from outside of this forum
                  futuristicrobert@infosec.exchangeF This user is from outside of this forum
                  futuristicrobert@infosec.exchange
                  wrote last edited by
                  #8

                  @docpop @briankrebs Benn Jordan is a national treasure.

                  1 Reply Last reply
                  0
                  • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                    We've come to an icky time in security when the concern about using outdated, unpatched software starts to become overshadowed by the fear of downloading some backdoored update.

                    kirakira@furry.engineerK This user is from outside of this forum
                    kirakira@furry.engineerK This user is from outside of this forum
                    kirakira@furry.engineer
                    wrote last edited by
                    #9

                    @briankrebs i feel like a lesson from xz was that it's actually good if there exist professional nerds whose needs are met and who aren't overworked or micromanaged so they have the space to needle and poke things. i'm sure someone with a linkedin acct is going "ai could fix this" but we're this deep into ai and this fix is apparently arriving on the same schedule as that exponential rise in software quality

                    briankrebs@infosec.exchangeB 1 Reply Last reply
                    0
                    • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                      We've come to an icky time in security when the concern about using outdated, unpatched software starts to become overshadowed by the fear of downloading some backdoored update.

                      kbal@fedia.ioK This user is from outside of this forum
                      kbal@fedia.ioK This user is from outside of this forum
                      kbal@fedia.io
                      wrote last edited by
                      #10

                      For a while now I've been waiting a couple of days to let everyone else try the updates first, unless it's to patch something specific. What happens if everyone starts waiting for everyone else?

                      1 Reply Last reply
                      0
                      • kirakira@furry.engineerK kirakira@furry.engineer

                        @briankrebs i feel like a lesson from xz was that it's actually good if there exist professional nerds whose needs are met and who aren't overworked or micromanaged so they have the space to needle and poke things. i'm sure someone with a linkedin acct is going "ai could fix this" but we're this deep into ai and this fix is apparently arriving on the same schedule as that exponential rise in software quality

                        briankrebs@infosec.exchangeB This user is from outside of this forum
                        briankrebs@infosec.exchangeB This user is from outside of this forum
                        briankrebs@infosec.exchange
                        wrote last edited by
                        #11

                        @kirakira all valid. I feel like we have learned 1000 lessons since xz on how not to do software security, most especially with countless devs having their NPM and/or GitHub repos completely pwned or silently backdoored. This is happening on a somewhat industrial scale from a variety of threat actors in real time, and some of them are finding great success in subverting the pipelines of companies that sell security software!

                        1 Reply Last reply
                        1
                        0
                        • R relay@relay.infosec.exchange shared this topic
                        • notasnek@infosec.exchangeN notasnek@infosec.exchange

                          @briankrebs doesn't this mean that a motivated bad actor could compromise Microsoft/Apple/Google/Amazon and break the world? Stongarm the nerds, then push out some diabolical patch.

                          cyanautik@infosec.exchangeC This user is from outside of this forum
                          cyanautik@infosec.exchangeC This user is from outside of this forum
                          cyanautik@infosec.exchange
                          wrote last edited by
                          #12

                          @notasnek @briankrebs *cough* 20240718 *cough* as a PoC for that?

                          1 Reply Last reply
                          0
                          • R relay@relay.publicsquare.global shared this topic
                          • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                            We've come to an icky time in security when the concern about using outdated, unpatched software starts to become overshadowed by the fear of downloading some backdoored update.

                            clickhere@mastodon.ieC This user is from outside of this forum
                            clickhere@mastodon.ieC This user is from outside of this forum
                            clickhere@mastodon.ie
                            wrote last edited by
                            #13

                            @briankrebs Thus has been my icky time for some years now.. 😩

                            1 Reply Last reply
                            0
                            • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                              We've come to an icky time in security when the concern about using outdated, unpatched software starts to become overshadowed by the fear of downloading some backdoored update.

                              krypt3ia@infosec.exchangeK This user is from outside of this forum
                              krypt3ia@infosec.exchangeK This user is from outside of this forum
                              krypt3ia@infosec.exchange
                              wrote last edited by
                              #14

                              @briankrebs As it was foretold...

                              1 Reply Last reply
                              0
                              • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                We've come to an icky time in security when the concern about using outdated, unpatched software starts to become overshadowed by the fear of downloading some backdoored update.

                                mostlytato@mstdn.socialM This user is from outside of this forum
                                mostlytato@mstdn.socialM This user is from outside of this forum
                                mostlytato@mstdn.social
                                wrote last edited by
                                #15

                                @briankrebs
                                You have reminded me that I need a new phone. Damn.

                                1 Reply Last reply
                                0
                                • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                  We've come to an icky time in security when the concern about using outdated, unpatched software starts to become overshadowed by the fear of downloading some backdoored update.

                                  hopelessdemigod@mstdn.socialH This user is from outside of this forum
                                  hopelessdemigod@mstdn.socialH This user is from outside of this forum
                                  hopelessdemigod@mstdn.social
                                  wrote last edited by
                                  #16

                                  @briankrebs

                                  Is it the point in history where we go back to the Commodore 64?

                                  1 Reply Last reply
                                  0
                                  • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                    We've come to an icky time in security when the concern about using outdated, unpatched software starts to become overshadowed by the fear of downloading some backdoored update.

                                    stekopf@mstdn.socialS This user is from outside of this forum
                                    stekopf@mstdn.socialS This user is from outside of this forum
                                    stekopf@mstdn.social
                                    wrote last edited by
                                    #17

                                    @briankrebs

                                    I anyway have #UpdateAngst all the time because of new bugs, loss personal data like bookmarks/favourites, worse interfaces, more ads, the usual enshitification, and now backdoors. 🥳

                                    1 Reply Last reply
                                    0
                                    • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                      We've come to an icky time in security when the concern about using outdated, unpatched software starts to become overshadowed by the fear of downloading some backdoored update.

                                      quatermasstools@infosec.exchangeQ This user is from outside of this forum
                                      quatermasstools@infosec.exchangeQ This user is from outside of this forum
                                      quatermasstools@infosec.exchange
                                      wrote last edited by
                                      #18

                                      @briankrebs redundant “backdoored” in there

                                      1 Reply Last reply
                                      0
                                      • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                        We've come to an icky time in security when the concern about using outdated, unpatched software starts to become overshadowed by the fear of downloading some backdoored update.

                                        snyperwolf@kind.socialS This user is from outside of this forum
                                        snyperwolf@kind.socialS This user is from outside of this forum
                                        snyperwolf@kind.social
                                        wrote last edited by
                                        #19

                                        @briankrebs Well said!

                                        1 Reply Last reply
                                        0
                                        • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                          We've come to an icky time in security when the concern about using outdated, unpatched software starts to become overshadowed by the fear of downloading some backdoored update.

                                          S This user is from outside of this forum
                                          S This user is from outside of this forum
                                          sharkfie@infosec.exchange
                                          wrote last edited by
                                          #20

                                          @briankrebs I've been feeling this lately with regards to most software updates (for personal usage), continuous enshittification is a factor too

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups