Dan Goodin
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
If it wasn't already, 2FA spraying is now a thing
With growing focus on the threat quantum computing poses to crucial and widely used forms of encryption, @filippo@abyssdomain.expert wants to make one thing perfectly clear: Contrary to popular mythology that refuses to die, AES 128 is perfectly fine in a post-quantum world
Are MP3 players even a thing these days? What are some good brands/models?
There's so much I don't understand in Dashlane's disclosure that an attack on its user accounts resulted in the threat actor obtaining 20 encrypted vaults.
What does it mean to brute force 2fa? Are we talking about TOTPs? That doesn't make sense because TOTPs change every 30-90 seconds, so there's no way for an attacker to meaningfully exhaust key space before it resets all over -- unless the attacker has the ability to pump all 7,700 combinations in <90 seconds, and DL doesn't have any sort of rate limiting.
Also, if the attacker is brute forcing 2fa, doesn't that by necessity mean the attacker already defeated the first factor? How did that occur?
I don't know if my confusion is the result of me not knowing the how the Dashlane product works or if it's just Dashlane being opaque.
Can anyone help me read the tea leaves?
You too can turn a Bluetooth device into a PC-pwning proxy
Google is dramatically shortening its deadline readiness for the arrival of Q Day, the point at which existing quantum computers can break public-key cryptography algorithms that secure decades’ worth of secrets belonging to militaries, banks, governments, and nearly every individual on earth.
Does anybody with a STRONG BACKGROUND IN WEBSITE PRIVACY have time to vet this research? Are TikTok and Meta pixels REALLY doing the things claimed? I'm concerned it may be overstating things in an attempt to sell its tag monitoring tools.
https://jscrambler.com/blog/beyond-analytics-tiktok-meta-ad-pixels
There's a ton of skepticism over the true value of AI-assisted vulnerability discovery, and with good reason. Maybe the new details Mozilla has revealed don't tip the scales in favor of it being beneficial, but people should at least sift through them in good faith and with an open mind before declaring all of them bullshit.
Dear readers. If you're not willing to support the families of those you want to read then we regretfully will be preventing you from obtaining our work for free.
Would this move by Debian, requiring byte-for-byte reproducible builds, have caught any real-world supply chain attacks seen in the past?
https://itsfoss.com/news/debian-makes-reproducible-builds-mandatory/
Can’t make sense of Dashlane’s vault theft notification? You’re not alone.
I was lucky enough to cover Cindy Cohn's trailblazing work BEFORE she joined @eff@mastodon.social . Here's one of several stories I wrote about her when she was still an associate attorney in private practice.
If I hear one more person say that Beyonce isn't a real country singer/song writer and should stay in her own RnB/hip-hop lane I'm going to lose it.
Transitioning the Internet to post-quantum, especially for digital signatures, is a massive undertaking. By setting a 2029 goal, they are giving themselves some slack. If they target 2035 and miss by 2 years, we are getting uncomfortably close to the danger zone.”
I'm trying to understand a bit more about CVE-2026-33579, the critical vulnerability in OpenClaw. To exploit, an attacker needs low-level paring privilege permissions. How does one acquire such privileges? Can anyone do it? I'm asking because I want to understand what's required for an attacker to exploit.
Feel free to ping me at DanArs.82, or drop an answer here.
If you could ask any question to Mozilla concerning last month's The Zero-days are Numbered post, what would it be?
https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/
Anybody know of any Linux distributions that have released fixes for Dirty Frag?
Can anyone help me find my AirTag attached keys? The FindMy app shows me their general location, which is a large public building where I last had them. When I go on site, my app is mostly unable to see them at all. Occasionally my app seems to be able to see a very weak signal but I can't seem to zero in on it. This is driving me nuts. I've looking now for two weeks. Anybody got tips?


