4 ms·
jonhohle, thanks. Do you know of examples of when milliseconds are part of the session tokens or accounts being created has been exploited?
by andrewmatte 3y ago
jonhohle, thanks. Do you know of examples of when milliseconds are part of the session tokens or accounts being created has been exploited?
- tgv 3y agoThe German tank production capacity was estimated by serial numbers of captured tanks. There are ways to read all kinds of information by observing energy usage. High resolution time and sequence data undoubtedly reveal more than you’d like.
- CSDude 3y agoMost of our lives as boring SaaS etc. software developer will not be near as exciting as this, but of course you may never know. I parsed the EV chargers APIs where I live (using Frida in Android) and one of the fields returned the daily revenue and profit.
- t0mas88 3y agoCould be quite useful information to competing charger networks or in future M&A discussions. I've seen a project for a trading firm that inferred all kinds of traffic and revenue numbers for companies before their quarterly earnings were made public. It wasn't perfect, but knowing with a certain confidence level whether the numbers were going to be better or worse than estimate was profitable for them.
- kozak 3y agoHere in Ukraine trying to estimate enemy's drone and missile production capacities by serial numbers of their parts is quite a mundane task these days.
- tgv 3y agoSure, for many places it doesn't really matter, but if your URLs or user ids can be seen/scraped by others, you might expose some commercially interesting information to competitors. And the indexing argument isn't really compelling, is it? You lose very little by sticking to fully random UUIDs.
- BWStearns 3y agoI could imagine using the timestamp segment of publicly observable ids to estimate activity patterns in an organization. Probably not super crucial and there are probably easier ways in most cases but it could be a big deal at the right moment and for the right target. This could be like a more refined version of PIZZAINT (where you can detect impending policy/operational movements by the quantity of food deliveries to a government organization).
- rhaps0dy 3y agoIs PIZZAINT real? I thought it was a joke. How do you even find out how much pizza is being delivered?
- BWStearns 3y agoIn ye olden days you had a minion sitting in a car watching the front gate with a notepad and enough cigarettes to last the night. Pizza itself might be a bit of a joke but looking for non-operational behavioral changes is absolutely real. The Cuban missile crisis was started in part because soviets played soccer and Cubans played baseball and the presence of soccer fields helped confirm soviet presence (in enough numbers to bother making rec centers). A more advanced version might be the public Strava data leaking US base layouts and locations or Strava helping the Ukrainians kill a Russian submarine commander. Edit to add: you could also just figure out where your target orders pizza from and pay one of the dudes working there to tell you when there’s a spike in deliveries to your target.
- littlestymaar 3y ago> soviets played soccer and Cubans played baseball It's a Henri Kissinger's quote, but it's not accurate: Cubans do in fact play football. Also this quote wasn't from the 1962 Cuban missile crisis, but to another event in 1970. That being said, it is true that the US intelligence got warned by the construction of football fields (or maybe even more so by the lack of baseball grounds). https://www.cracked.com/article_31335_that-time-soccer-fields-nearly-caused-another-cuban-missile-crisis.html https://www.cracked.com/article_31335_that-time-soccer-field...
- tarjei_huse 3y agoI know of people who used leaked customer ids in public facing chatbot solutions (like Intercom) to estimate how fast their competitors were growing and/or how many customers they had.
- thinkharderdev 3y agoHow would you do that with UUIDv7 though? I see how using sequential IDs would obviously leak that information, but if all you leak is the timestamp the ID was generated, how do you then infer anything about the rate of ID generation?