4 ms·
Anyone in that position knows not to use Skype. Anyone in that position that was using Skype was likely picked up ages ago because their threat modeling is clea
by notif1 3y ago
Anyone in that position knows not to use Skype. Anyone in that position that was using Skype was likely picked up ages ago because their threat modeling is clearly trash.
- kube-system 3y agoThat's not a reason to discount this as a real vulnerability. Most hacks in the real world are due to mistakes in security hygiene. Because most people aren't security experts, and even those who are, are human. They make mistakes, do things in a hurry sometimes, and don't know everything. Novel, high-skilled attacks are uncommon.
- notif1 3y agoIt's certainly a real vulnerability just not a particularly impactful one. Claiming that it's going to get people killed is unnecessarily inflammatory rhetoric that makes you look like you don't know what you're talking about. Claiming that novel, high-skilled attacks are uncommon when they're inherently challenging to have visibility of confirms that you don't know what you're talking about.
- kube-system 3y agoI'm not saying (and didn't say) that's a likely outcome of this particular bug. I'm posing the example as something that could be done with an IP address, because I'm pushing back at the assertion that IP addresses aren't useful for anything. They aren't useful for criminal hackers looking for a random untargeted machine to compromise. But they're useful for targeted scenarios like the example I gave.