TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Security researchers 'destroy' Microsoft ASP.NET security

52 pointsby dfj225over 14 years ago

5 comments

pragmaticover 14 years ago
Can anyone provide any more solid details? This article seems to be a lot of hyperbole ("totally destroys") with little fact.<p><i>The error message provides a small tidbit of information about how ASP.NET decrypts messages. With enough of these error messages it is possible to decrypt the message in its entirety.</i><p>What message? The cookie itself?
评论 #1701730 未加载
评论 #1701746 未加载
评论 #1701913 未加载
评论 #1701716 未加载
darwinGodover 14 years ago
Alex Payne (One of Twitter's earlier employees..) had written a nice article on why he does not work in Infomartion Security, quite a while ago.<p><a href="http://al3x.net/2008/12/31/why-not-infosec.html" rel="nofollow">http://al3x.net/2008/12/31/why-not-infosec.html</a><p>..the core point being,about how little attention genuine, path-breaking work gets, if security researchers DO NOT make an attempt to publicise it,quite radically.<p>These sure are not some random guys making a bold claim.. that work has been published in Usenix!
cryptbeover 14 years ago
The video is out <a href="http://www.youtube.com/watch?v=yghiC_U2RaM" rel="nofollow">http://www.youtube.com/watch?v=yghiC_U2RaM</a>
markgamacheover 14 years ago
Totally irresponsible journalism. This is not all or .NET or even a tiny fraction. It is one control that will be rapidly patched.<p>This allows the end user to decrypt their own "encrypted" cookie, not an attacker. At best, if the web app writers were stupid and put truly exploitable data in the cookie, they'd be effected.<p>It is horrible that MS missed this, but calling .NET broken is probably actionable libel.
评论 #1702104 未加载
评论 #1703592 未加载
评论 #1702013 未加载
brettbenderover 14 years ago
At least now the next time a client wants me to do something in .NET I have a good excuse to gently persuade them to something else (until this gets patched, at least).
评论 #1701813 未加载
评论 #1701770 未加载
评论 #1701726 未加载