04. Web Communications and Vulnerabilities

News of the week

https://www.socialmediatoday.com/news/twitter-reports-new-security-flaw-which-has-led-to-the-exposure-of-54-mill/629037/

Feature: connecting to people whose email and phone number you know.

Flaw allowed association of anonymous accounts with emails and phone numbers.

Introduced June 2021, disclosed after 6 months by security researcher, announced August 2022.

Web Communication

Encryption works. Properly implemented strong crypto systems are one of the few things that you can rely on. Unfortunately, endpoint security is so terrifically weak that NSA can frequently find ways around it.

Edward Snowden

Encryption works. The problem is everything else.

OSI model protocols:

URL format:

   Unqualified hostname
          |--|
  https://foo.bar.example.com:443/some/path/to/a/file?query=cat
  |___|       |   |_________|
 Scheme       | Second-level domain
              |_____________|
                 Subdomain

OWASP Top 10

Open Web Application Security Project

A07:2021 – Identification and Authentication Failures

Insecure Design

Security flaws caused by:

Secure design lifecycle as a drier: