7 ms·
The simplicity of this exploit demonstrates something profound. The most dangerous things in life are not hidden deep in the weeds. Rather, they stare us in the
by the7nd 10y ago
The simplicity of this exploit demonstrates something profound. The most dangerous things in life are not hidden deep in the weeds. Rather, they stare us in the face in the most obvious spots. It isn't the unknown that presents the biggest threat. It is the known that we never gave a second look.
- 1812calif 10y agoheart disease vs. terrorism. it seems to be an unfortunate emergent behavior of groups of humans.
- witty_username 10y agoI noticed that if it's a fire that kills many people it's only a one day news; while if it's a bomb that kills one everybody's afraid.
- enraged_camel 10y agoIt's not the number of casualties that scares people, but rather the nature of the threat. Fires have existed for several millennia. Our ancestors who built and lived in the very first settlements suffered from their homes/stores occasionally burning down. We know what types of conditions increase risk of fires and we know how to minimize those risks and put the fires out when they occur. Bombs on the other hand are unpredictable. They also cause their damage instantly and there is no way to minimize or prevent it. You can escape from a burning building, or if stuck, wrap a piece of wet cloth around your mouth to minimize the amount of smoke you breathe while you wait for rescue. You can't outrun an explosion. That's why people are a lot more scared of bombs than they are of fires (or car accidents, for that matter, which kill many more people than both fires and bombs combined).
- tttttttttttt 10y agoI think perception of danger = amount of times hearing people die from doing act / amount of times doing act. So flying is much higher than diving: People drive much more than they fly (a few times a year vs twice a day) and hear about air-crashes (9/11, Malaysia Airlines) more than car crashes. It's the brain playing games with us
- 0xcde4c3db 10y agoAvailability bias is definitely one aspect, but I think a big part of it is also how easy it is to tell a story that separates oneself from the victims (this often takes the form of victim blaming, but not necessarily). It's easy to tell yourself the story of how heart attacks happen to people with different lifestyles or genetics, or how car crashes happen to drivers who are less attentive, or how violent crime happens to people who live in other neighborhoods. It's a lot harder to tell yourself the story of how you'll avoid the plane with the latent mechanical fault or how you'll never be at a gathering place that would make an attractive terrorist target.
- bostik 10y agoThe cardinal rule of security is: you never, ever, trust anything the client sends. This bypass is a perfect example. Although author doesn't mention which interception proxy he used, I'm 99% sure it was Burp. Replaying modified content is trivial.
- gant 10y agoEven with a free software tool like mitmproxy modifying requests is trivial. You don't even need Burp.
- Vendan 10y agothe free version of burp is completely capable of doing this, and so much more
- ikeboy 10y agoI've seen multiple major financial companies vulnerable to modification of the page that could be done entirely in inspect element.
- Hasz 10y agoFiddler also has this capability
- closeparen 10y ago>you never, ever, trust anything the client sends. The author likely wrote code that correctly validates "for all security questions a correct answer is given" and just forgot about the part where "for-all propositions are trivially true of the empty set." It's easy to read a for loop for what it's intended as - a loop - and not think about "what if we never enter it at all?"
- geocar 10y agoIf we think well, we need to have loops, we might be feeling despair right now, however array languages don't need loops! I can write: min test each args and I can do the same in JavaScript, it's just uglier: args.map(test).reduce(function(x,y){return Math.min(x,y)}) Writing in a functional style makes this kind of programming slightly less onerous, but it still feels strange in languages that are a bad fit.