Is Elon Musk a Security Expert? - ThreatWire

แชร์
ฝัง
  • เผยแพร่เมื่อ 6 มิ.ย. 2024
  • ⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️
    @endingwithali →
    Twitch: / endingwithali
    Twitter: / endingwithali
    TH-cam: / @endingwithali
    Everywhere else: links.ali.dev
    Want to work with Ali? endingwithalicollabs@gmail.com
    [❗] Join the Patreon→ / threatwire
    0:00 Intro
    00:10 1 - NextJS Vulnerabilities Discovered
    02:06 2 - New Technique Allows VPN Bypass
    04:31 3 - FIDO2 Flaw Exposes MITM Attack
    05:51 4 - Signal Vs Telegram
    08:24 5 - Outro
    LINKS
    🔗 Story 1: NextJS Vulnerabilities Discovered
    portswigger.net/web-security/...
    github.com/advisories/GHSA-77...
    github.com/advisories/GHSA-fr...
    cybersecuritynews.com/next-js...
    🔗 Story 2: New Technique Allows VPN Bypass
    www.leviathansecurity.com/blo...
    cybersecuritynews.com/tunnelv...
    🔗 Story 3: FIDO2 Flaw Exposes MITM Attack
    www.silverfort.com/blog/using...
    gbhackers.com/fid02-mitm-vuln...
    🔗 Story 4: Signal Vs Telegram
    www.city-journal.org/article/...
    www.ccn.com/news/technology/t...
    www.businessinsider.com/elon-...
    / 1787589564917490059
    news.ycombinator.com/item?id=...
    nitter.poast.org/matthew_d_gr...
    ____________________________________________
    Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community - where all hackers belong.
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 134

  • @neverendingstudent
    @neverendingstudent 22 วันที่ผ่านมา +20

    From the perspective of helping to increase public awareness of AI capabilities, I appreciate the ploy of '1 of our stories is AI generated, can you tell which?' AI has gotten scary capable, and is only improving. Definitely important for people to have as up-to-date as possible an understanding of what it can and is being used for.

    • @Nichrysalis
      @Nichrysalis 22 วันที่ผ่านมา

      The advent of generative AI combined with quantum computing genuinely concerns me for how this could be used to manipulate media.

  • @LordDemonos
    @LordDemonos 22 วันที่ผ่านมา +8

    Thank you for giving us security news in a clear and professional manner.

  • @meh.7539
    @meh.7539 22 วันที่ผ่านมา +58

    Signal. No question.

    • @bobbyjohnson116
      @bobbyjohnson116 22 วันที่ผ่านมา +4

      Meshtastic

    • @inund8
      @inund8 22 วันที่ผ่านมา +5

      Yall are responding with answers not allowed by the question. Signal is way less sketch than Telegram, but y'all are right that we shouldn't exclude other alternatives.

    • @glowingone1774
      @glowingone1774 22 วันที่ผ่านมา +1

      Matrix, but its founding is also shady, ex 8200 types, but you can still self host it i guess
      XMPP+OMEMO, tox and briar are all better options

    • @meh.7539
      @meh.7539 22 วันที่ผ่านมา

      @@inund8 I didn't say "exclusively". I just don't have questions about using it.

    • @dracula7779
      @dracula7779 21 วันที่ผ่านมา +1

      Neither, no phone easy

  • @skirk16
    @skirk16 18 วันที่ผ่านมา +1

    Didn't know you were an SE from MIT, that's so cool! Your inherent interest in the topic was more than enough qualification, but it's awesome to know you're thriving in your career space as well!

  • @frankey3732
    @frankey3732 21 วันที่ผ่านมา +2

    How about plaintext messages saved locally?
    Signal has transport encryption; messages on clients are not encrypted.
    This means you can read and exfiltrate messages if you get to the machine.
    Or if your machine gets compromised.

  • @chadddada
    @chadddada 22 วันที่ผ่านมา +1

    Thanks for the heads up on NextJS!

  • @QR5-cyber-exp
    @QR5-cyber-exp 22 วันที่ผ่านมา +3

    Showing my age here….. but back in the 90’s (in Australia) we weren’t allowed to release a communications service unless it was “interceptable” by the Signals Directorate (with appropriate authorization). Seems like an eon ago now.

  • @jsaenzMusic
    @jsaenzMusic 22 วันที่ผ่านมา

    So glad I found your channel! You're news is the ish!

  • @lossless4129
    @lossless4129 20 วันที่ผ่านมา

    Getting better every single show, loving it. Keep it rolling!

  • @mytechnotalent
    @mytechnotalent 22 วันที่ผ่านมา +18

    Great one Ali! I vote Signal, hands down.

  • @AnonMedic
    @AnonMedic 22 วันที่ผ่านมา +1

    I used AI to write part of an article on my news website, and asked friends to guess what part AI wrote.
    So I absolutely love that you're doing the same thing with threatwire.

  • @brettlaw4346
    @brettlaw4346 22 วันที่ผ่านมา +3

    Signal - The assumption that the app source code is that app being installed is a big one. There are also host device compromises like the keyboard, general hacking, etc. Not sure if signal uses a secure terminal and trusted execution environment, otherwise you could have some buffer reads from other applications.

  • @QR5-cyber-exp
    @QR5-cyber-exp 22 วันที่ผ่านมา

    Great summary. I love the connect back to previous research.

  • @jamesdriscoll1658
    @jamesdriscoll1658 22 วันที่ผ่านมา +9

    The FIDO 2 story was written by AI

    • @jmr
      @jmr 22 วันที่ผ่านมา

      My guess as well!

    • @jmr
      @jmr 21 วันที่ผ่านมา +1

      @@asksearchknock I'm not trying to pick out the AI. I'm trying to pick out Ali. I think it might be more consistent to find hints of her writing then whatever is left must be the AI.

  • @mrmarkom
    @mrmarkom 22 วันที่ผ่านมา +2

    Great work Ali! I could not guess the story - every time I though I can guess it, I was not really sure. Btw, which AI did you use to write this story ? Keep up great work!

  • @paulw3182
    @paulw3182 21 วันที่ผ่านมา

    Great video, mom's advice still rings true ' Be humble, and take compliments while you can' - Its wonderful your making Threatwire your own, keep up the excellent work - Your coding channel is interesting.

  • @jasonirvin6782
    @jasonirvin6782 22 วันที่ผ่านมา +3

    Thanks friend good stuff!

  • @cZar_Void
    @cZar_Void 22 วันที่ผ่านมา +14

    "New Technique Allows VPN Bypass" absolutely has to be the GPT story. The concluding words were a bit off.

    • @pcislocked
      @pcislocked 22 วันที่ผ่านมา

      yup...

    • @jmr
      @jmr 22 วันที่ผ่านมา

      I've given up trying to detect AI and switched to trying to detect Ali. I think it's the Fido story this week.

  • @jaybrooks1098
    @jaybrooks1098 20 วันที่ผ่านมา +3

    Let me let everybody in on a secret. There's no such thing as a secure chat.

    • @andrefriedelnyc
      @andrefriedelnyc 15 วันที่ผ่านมา

      Let ME let you in on a little secret: If you encrypt your messages with PGP standard implementation, then you too can experience an environment that can only be viewed with the decryption key... and unless a quantuum computer is used to brute-force a decryption key, you're safe. If it's good enough for military and state secrets, I'd wager it's good enough for you too...

  • @MrGFYne1337357
    @MrGFYne1337357 22 วันที่ผ่านมา +19

    lol, (my take) ALI -- "thanks for calling me pretty, But don't forget, I'm an M.I.T. grad. and I'll pwn you in seconds." 😅

  • @somethingelse25
    @somethingelse25 22 วันที่ผ่านมา

    Found the signal and telegram story interesting and also the VPN one too. Thank you! Hopefully I'll be able to do a career in Cyber Security. ☕

  • @paulw3182
    @paulw3182 19 วันที่ผ่านมา

    Your tweet " Look at my code and then tell me I'm pretty" Awesome! Your analysis of MIT vs the real world is spot-on. It's impressive you began coding so late, so many just give up. What is your take on the BreachForums 'cartoons"

  • @_mrcrypt
    @_mrcrypt 22 วันที่ผ่านมา +1

    Thanks for the infos! 🍷😎🏴‍☠️

  • @repairstudio4940
    @repairstudio4940 22 วันที่ผ่านมา

    Thanks Ali! 🎉

  • @linuxliaison
    @linuxliaison 20 วันที่ผ่านมา

    Kudos to you for being able to read out those numbers over and over :P

  • @awesomesauce804
    @awesomesauce804 19 วันที่ผ่านมา +1

    Good stuff. I appreciate that you stood up to the "cute" comments. Unfortunately this is something you will probably need to be firm about for your entire career. Great content. Keep up the good work.

  • @mrldtj
    @mrldtj 22 วันที่ผ่านมา +2

    😂 I'm a subscriber but that title did make me chuckle.

  • @isaacyukon5869
    @isaacyukon5869 13 วันที่ผ่านมา

    00 You mean people don't read RFCs starting with RFC72 anymore? 11 RFC72 is a requirement.

  • @tech1238
    @tech1238 21 วันที่ผ่านมา

    Good vid thanks

  • @sanantohomie
    @sanantohomie 22 วันที่ผ่านมา +1

    Ali the mic needs a foamy top or something, i can hear scratching sounds OR post process the audio to remove the scratchy noises

  • @azryelkelly7851
    @azryelkelly7851 21 วันที่ผ่านมา

    Nice ASMR hair rubbing the microphone throughout the whole video. 😜 Guessing there's no MIT sound tech on staff. Love the videos!

  • @kilosan
    @kilosan 22 วันที่ผ่านมา +4

    Is Shannon coming back once in a month?

    • @jmr
      @jmr 22 วันที่ผ่านมา

      Shannon is doing her own channel. I don't know anything about any guest appearances though.

  • @asificam1
    @asificam1 22 วันที่ผ่านมา +1

    Much as I see the advantage of password-less logins. I dislike them because now you have single factor authentication since the server can't be sure the user has a PIN even if they ask the USB key to require one, and your USB key has to store discoverable credentials. I prefer the U2F model since they use the same math but the credentials are not discoverable, and since they're not stored on the key, they're able to be used for an infinite number of logins. But since U2F is assumed to be a second factor, you now have a forced use of a thing you know and a thing you have in order to log in which is (in my opinion) much better than handing the thing you know to the key to handle, especially if everyone has a USB key in the future.

    • @jmr
      @jmr 22 วันที่ผ่านมา

      I would argue using an authentication key as a second factor is superior but for different reasons. How do you think they will discover your credentials on the key?

    • @asificam1
      @asificam1 22 วันที่ผ่านมา

      @@jmr Passwordless login uses what are called "discoverable credentials". They occupy a "slot" and most keys today have only a limited number of slots. So most people will need to have several keys just to log in via passwordless methods if this catches on.
      As to how discoverable the "discoverable credentials" are, I have not looked into this, I know that I can list them all if I have the key, but I would assume (and hope) that FIDO2 says that the key will only return a credential for a matching account or at least domain. However, someone who has the key can see where it goes which means no plausible deniability, and if there is a bug that allows the PIN to be bypassed or the pin try limit removed, or a leak of the pin another way like by writing it down and losing it, well, now the attacker has the key and knows where it goes.
      However, with U2F, the credentials are encrypted on the key and sent to the server. so only the right key can use them, but there is no way to prove that a key opens an account without trying every single account and seeing which ones work... even if there is no PIN or the PIN is bypassed (sometimes U2F has PINS too though) if an attacker has access to the key... they don't know which of the several billion locks it opens... not all that helpful for them and gives me time to react by deleting that user's key.

  • @Blessed_2_Be_Born_In_America
    @Blessed_2_Be_Born_In_America 3 วันที่ผ่านมา

    All I know is signal sucks for sharing videos with its 50MB filesize limit.
    Telegrams limit is 4GB.
    My YT gymnastics channel wouldn't be possible on signal.

  • @itsdeonlol
    @itsdeonlol 22 วันที่ผ่านมา

    W episode Ali!!!

  • @mohamedissa9760
    @mohamedissa9760 20 วันที่ผ่านมา

    The story about VPN DHCP bug was written by an AI

  • @loves2tinker
    @loves2tinker 21 วันที่ผ่านมา

    Might be interesting to see you and chstgpt 4o have a discussion about the security landscape (instead of reporting important news. That way you can flex your knowledge so people see more of your career side.

  • @itzdm0r3
    @itzdm0r3 21 วันที่ผ่านมา

    I think the story about signal is the "fake" one.

  • @herauthon
    @herauthon 22 วันที่ผ่านมา

    Bummr.. there is DHCP/DNS noise - i have to check my cave

  • @debugin1227
    @debugin1227 22 วันที่ผ่านมา +1

    Signal for the win

  • @blueskyresearch6701
    @blueskyresearch6701 18 วันที่ผ่านมา

    What about pgp messages shared via sftp.
    If you're really concerned with being secure don't trust other people's servers or backends.
    Also if you can manage it a modern flash drive can hold a one time pad large enough to serve a life time of communication.

    • @blueskyresearch6701
      @blueskyresearch6701 18 วันที่ผ่านมา

      Should also add this should all be done with a properly configured OS such as TAILS.
      The problem with the diy approach is you likely wind up with scratch files of plain text and if not done on the correct os also plain text fragments in virtual memory swap files.
      So you do need something that encrypts from the keyboard to the destination, you can't expect everyone to configure firewalls and routers so you do need some minimal backend to handle firewall traversal.
      Also there is just the matter of remaining anonymous so you should run this all over something like tor. Is tor still considered secure?

  • @fastmover45
    @fastmover45 22 วันที่ผ่านมา +2

    Signal FTW

  • @TheGrigerz
    @TheGrigerz 22 วันที่ผ่านมา +2

    😮

  • @IshaqIbrahim3
    @IshaqIbrahim3 21 วันที่ผ่านมา

    Timeline: 5:35 Man in the MIDDLE! 🤣

  • @S.C.D.
    @S.C.D. 21 วันที่ผ่านมา

    💓

  • @richardlee3253
    @richardlee3253 12 วันที่ผ่านมา

    How do you use signal if the smart phones have a cellular cpu with higher priority on the bus?! We are all sitting in the back of the data bus on our smart phones. What can you hide from people with that kind of backdoor? And then there is the continual backdoors in wifi, bluetooth, usb, etc. its a big joke.

  • @LP-fy8wr
    @LP-fy8wr 20 วันที่ผ่านมา

    The entire dam thing sounds like AI.

  • @THEMithrandir09
    @THEMithrandir09 21 วันที่ผ่านมา

    Telegrams encryption was made by 5 math dudes and isn't opensource, so insecure by default. If you're worried use matrix.

  • @Tech-NO-City
    @Tech-NO-City 21 วันที่ผ่านมา

    I need your help plugging in my ethernet cable

  • @youtubevanced8789
    @youtubevanced8789 22 วันที่ผ่านมา

    I LOVE ALI ❤❤❤

  • @vasquezjesus1020
    @vasquezjesus1020 13 วันที่ผ่านมา

    Gamer the movie is irl?

  • @jmr
    @jmr 22 วันที่ผ่านมา

    Fido story is AI. I think what I've learned from the one AI story a week game is not that I can't tell them apart but that OUR HOST IS ALSO AI! Duh, duh, duh! 😆 /teasing.

  • @netoeli
    @netoeli 22 วันที่ผ่านมา +4

    man elon is the expert on everything , hes got skills for this and that, the dude can do it all, he also does all his shopping! amazing

  • @MatthewCallier
    @MatthewCallier 22 วันที่ผ่านมา +1

    Another awesome episode.

  • @su8z3r03
    @su8z3r03 22 วันที่ผ่านมา +1

    @2:07

  • @WickdPerfekT
    @WickdPerfekT 20 วันที่ผ่านมา

    Defcon is canceled.

  • @inund8
    @inund8 22 วันที่ผ่านมา

    Love the shirt! But Ali, are you sure you can't make yourself look bigger? Like resize yourself so you take up more of the frame? Or rearrange your furniture so you be closer or have the camera pointed lower? You just look so small and short and it is a widdle bit distracting. Which is a shame since everything else feels very high production and well reported!

  • @CapuiICazzu
    @CapuiICazzu 22 วันที่ผ่านมา +1

    Im not sure what the this has to do with elon musk im assuming its the signal stuff

    • @asksearchknock
      @asksearchknock 21 วันที่ผ่านมา

      7:55 Elmo decided to tweet about signal, once again showing the world just how little he knows about anything

    • @CapuiICazzu
      @CapuiICazzu 21 วันที่ผ่านมา +1

      @@asksearchknock yeah thought so thx for timestamp

  • @SkillfulHacking
    @SkillfulHacking 22 วันที่ผ่านมา +5

    How about don't commit crime instead of don't get caught. 😢

    • @dcquence
      @dcquence 7 วันที่ผ่านมา

      Don't get caught by the threat actors, not, don't get caught doing illegal stuff.

  • @mrvincefox
    @mrvincefox 22 วันที่ผ่านมา +3

    Clickbait using Elon musk in title

  • @stevenpugh5412
    @stevenpugh5412 20 วันที่ผ่านมา

    I think the Elon Musk story was AI: absolutely idiotic for him to get involved.
    How’s that quote go “better to be thought a fool than tweet and remove all doubt”. Of course the same could be said about this comment…

  • @OurSpaceshipEarth
    @OurSpaceshipEarth 19 วันที่ผ่านมา

    Anyone heard FTX can pay it's customers they are LOADED hahaa

  • @GuyMassicotte
    @GuyMassicotte 22 วันที่ผ่านมา +1

    No one can pretend to be a security expert until they are minimaly able to detect and block pegasus;)

  • @ardawanx
    @ardawanx 8 วันที่ผ่านมา

    Lol. Congratulations to JS fans

  • @dazztee
    @dazztee 22 วันที่ผ่านมา +6

    Ali is Awwsome Hak5 got a upgrade

  • @hiamealhilwa6684
    @hiamealhilwa6684 22 วันที่ผ่านมา

    😘

  • @davidholliday6772
    @davidholliday6772 22 วันที่ผ่านมา +2

    I deleted Signal over 2 years ago .

  • @C.J...
    @C.J... 22 วันที่ผ่านมา +3

    ❤DIMPLES!❤ nice 70s get up girl.

  • @endingwithali
    @endingwithali 22 วันที่ผ่านมา +4

    clickbait title GOTCHA ;)

  • @briannunya2838
    @briannunya2838 22 วันที่ผ่านมา

    Ad freeeeeeeeee

  • @HomeBurger
    @HomeBurger 20 วันที่ผ่านมา

    Notice how Ali speaks slowly and uses smaller words when talking to the javascript viewers. Gotta know your audience.
    disclaimer: this is a joke

  • @asksearchknock
    @asksearchknock 21 วันที่ผ่านมา

    Great job on standing up for yourself and I hope that the community will support you I’m telling anyone who makes inappropriate comments where to go. I’m 100% behind you - Us rats 🐀 got to stick together

  • @wandererx86
    @wandererx86 22 วันที่ผ่านมา +2

    wack title

  • @AlexRodriguez-ci8ro
    @AlexRodriguez-ci8ro 22 วันที่ผ่านมา

    Where is Shannon

    • @donamills
      @donamills 22 วันที่ผ่านมา

      She dedicated her time to her own channel.

  • @carsonjamesiv2512
    @carsonjamesiv2512 21 วันที่ผ่านมา

    TECHNOLOGY IS 😃 == 😡

  • @Proxyone444
    @Proxyone444 22 วันที่ผ่านมา

    ALI is LOVE

  • @christopherjosephsimmons
    @christopherjosephsimmons 22 วันที่ผ่านมา

    I'm your 711

  • @UNcommonSenseAUS
    @UNcommonSenseAUS 22 วันที่ผ่านมา +1

    Whats funny is this show going down the toiket.

    • @asksearchknock
      @asksearchknock 21 วันที่ผ่านมา

      You know being here is not mandatory right? There are loads of other channels you could go and watch yet you come here and then moan. Why would you watch a channel you don’t like?

  • @kevinm3751
    @kevinm3751 22 วันที่ผ่านมา +1

    He build PayPal, so yea I would say he is a security expert!

  • @Private-GtngxNMBKvYzXyPq
    @Private-GtngxNMBKvYzXyPq 21 วันที่ผ่านมา

    nolE has it bass ackwards.

  • @ActiveResearchYouTube
    @ActiveResearchYouTube 22 วันที่ผ่านมา +3

    What's ur OF tho?

  • @aboselaiman
    @aboselaiman 21 วันที่ผ่านมา +1

    With these Dimples I can't pay attention to what she is saying.

    • @asksearchknock
      @asksearchknock 21 วันที่ผ่านมา +2

      I assume then you also missed the part where she reminded you she’s an MIT educated software engineer and your comments are not welcome or appropriate.

  • @ronak3600
    @ronak3600 22 วันที่ผ่านมา +3

    Change the host!!!

  • @budminer0077
    @budminer0077 19 วันที่ผ่านมา

    It was the cute ai generated dimples

  • @cardrivingdude
    @cardrivingdude 22 วันที่ผ่านมา +8

    Triggered by your title. Muskrat is an expert at having daddy money, and opening his wallet. That's about it. Don't believe me?
    Take a look at his original ideas.
    "hYpErLoOP"

    • @xyanide0101
      @xyanide0101 22 วันที่ผ่านมา

      Looks like someone is woke, or got roasted by shorting tesla, or maybe both.

    • @cardrivingdude
      @cardrivingdude 21 วันที่ผ่านมา

      @@asksearchknock I'm shocked at the number of people that have no idea how the world works. They must picture Muskrat rolling up his sleeves and just "building a rocket".