3 ms·
This is a well-written, interesting article. I especially like the non-alarmist tone to it ("Considering the inherent weaknesses and numerous limitations, this
by planb 3y ago
This is a well-written, interesting article. I especially like the non-alarmist tone to it ("Considering the inherent weaknesses and numerous limitations, this attack isn't practical.")
- danielbln 3y agoIn another universe, this would be "FINGERBleed", along with a snazzy website and logo.
- nicce 3y agoReminds me of https://www.hertzbleed.com/ https://www.hertzbleed.com/ There still hasn’t been any known reported case where this would be possible or used. Very impractical.
- pjerem 3y agoI’m not sure. This allows to test wether hostnames exists on your network. It’s maybe not an issue for a unique hostname but what about fixed hostnames or default hostnames that are common in the IoT world. This allows a website to secretly guess if you own a given device. It’s even worse used in a targeted attack : if you know some devices of the network, you can guess that the connected user is on the targeted network.