• Kissaki@programming.dev
    link
    fedilink
    arrow-up
    5
    ·
    12 hours ago

    Looking into the mentioned unforgivable vulnerabilities and stubborn weaknesses published by CISA:

    Unforgivable Vulnerabilities (PDF)

    Given the above criteria, following are some candidates for unforgivable vulnerabilities that satisfy all (or most) of the criteria for an unforgivable vulnerability. […]

    1. Buffer overflow using long strings of "A" characters in:
      • a. Username/password during authentication
      • b. File or directory name
      • c. Arguments to most common features of the product or product class
    2. XSS using well-formed <script> tags, especially in the:
      • a. Username/password of an authentication routine
      • b. Body, subject, title, or to/from of a message
    3. SQL injection using ' in the:
      • a. Username/password of an authentication routine
      • b. "id" or other identifier field
      • c. Numeric field
    4. Remote file inclusion from direct input such as:
      • a. include($_GET['dir'] . "/config.inc");
    5. Directory traversal using "../.." or "/a/b/c" in GET or SEND commands of frequently-used file sharing functionality (e.g., a GET in a web/FTP server, or a send-file command in a chat client)
    6. World-writable critical files:
      • a. Executables
      • b. Libraries
      • c. Configuration files
    7. Direct requests of administrator scripts
    8. Grow-your-own crypto
    9. Authentication bypass using "authenticated=1" cookie/form field
    10. TOCTOU race condition – symlink
    11. Privilege escalation launching "help" (Windows)
    12. Hard-coded or undocumented account/password
    13. Unchecked length/width/height/size values passed to malloc()/calloc()

    Stubborn Weaknesses

    CWE-ID Description 2023 Rank
    CWE-787 Out-of-bounds Write 1
    CWE-79 Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) 2
    CWE-89 Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) 3
    CWE-416 Use After Free 4
    CWE-78 Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) 5
    CWE-20 Improper Input Validation 6
    CWE-125 Out-of-bounds Read 7
    CWE-22 Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) 8
    CWE-352 Cross-Site Request Forgery (CSRF) 9
    CWE-476 NULL Pointer Dereference 12
    CWE-287 Improper Authentication 13
    CWE-190 Integer Overflow or Wraparound 14
    CWE-502 Deserialization of Untrusted Data 15
    CWE-119 Improper Restriction of Operations within Bounds of a Memory Buffer 17
    CWE-798 Use of Hard-coded Credentials 18
  • slazer2au@lemmy.world
    link
    fedilink
    arrow-up
    41
    arrow-down
    1
    ·
    23 hours ago

    So make executives personality liable for data losses.

    That is the only way to make change happen. Execs have the final say, they get the final fine.

    • deadbeef79000@lemmy.nz
      link
      fedilink
      arrow-up
      24
      arrow-down
      3
      ·
      23 hours ago

      Or remove the concept of a limited liability company: so that the directors must take responsibility. They’re the ones directing the executive anyway.

      It wouldn’t need any special carve out in law: other than the laws covering the structure of corporations.

      • tyler@programming.dev
        link
        fedilink
        arrow-up
        13
        arrow-down
        1
        ·
        21 hours ago

        If you did that you’d destroy every small business in America in a heartbeat. Nobody would do anything that could have any sort of perceived risk because anything you do could result in you losing literally everything in your life, your house, your car, everything you own.

    • Kissaki@programming.dev
      link
      fedilink
      arrow-up
      2
      arrow-down
      1
      ·
      13 hours ago

      It’s not the exact thing; it just makes it worse. For many people, it’s personality and psychology; they go the path of least resistance and don’t care about much besides their main goals. Whether you embed it in capitalism or not, these fundamental causes remain.

      Do you have an economic or social system in mind where it would be solved or better?

      • supersquirrel@lemmy.caOP
        link
        fedilink
        arrow-up
        1
        ·
        7 hours ago

        Do you have an economic or social system in mind where it would be solved or better?

        Democratic Socialism

    • supersquirrel@lemmy.caOP
      link
      fedilink
      arrow-up
      4
      arrow-down
      1
      ·
      23 hours ago

      Well that and the associated failure of tech culture in Silicon Valley and elsewhere to understand the important of organizing in the workplace not only to improve the quality of working conditions so you can truly show up and feel supported to do good work you are proud of… but also to ensure that the industry at a basic level remains functional and ethical.

      If you look at the primary motivating reasons of a lot of industries striking in the US, it often has to do with a universal anger and grief that basic aspects of their work are being undermined by carelessness, nursing is a good example of that.

      Tech workers had a moment of incredible cultural and material power there, and they failed to translate that into a set of truly professional standards and become something like engineering, plumbing or land surveying, something with a license, a set of high standards that are grounded in a philosophy of doing good honest work… like how doctors have.

      This invited in the subsequent dehumanization of tech workers in the last 20 years and the rise of AI further rationalizing more dehumanization and devaluing of tech work.

      • Walters, Fern@bookwyr.me
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        1
        ·
        22 hours ago

        failure of tech culture in Silicon Valley and elsewhere to understand the important of organizing in the workplace not only to improve the quality of working conditions so you can truly show up and feel supported to do good work you are proud of… but also to ensure that the industry at a basic level remains functional and ethical.

        which were sabotaged by Silicon Valley bourgeoisie. Silicon Valley never ceased being anti-unions, fired at-will, colluded with other firms so you wouldn’t get hired elsewhere. Organizing could never grassroot in blue Texas.

        and they failed to translate that into a set of truly professional standards and become something like engineering, plumbing or land surveying, something with a license, a set of high standards that are grounded in a philosophy of doing good honest work… like how doctors have.

        I am starting to feel like you’re not aware how successful the bourgeoisie have destroyed every single grassroots organization in the <img src=“https://hexbear.net/pictrs/image/6dedb145-206a-4b35-ab5e-c9e41e1130c7.png” alt=“Amerikkka” width=“24” height=“auto”>, but unlike other blue collared labours, they allowed their Nazi doctorsstandards to remain. Did you earnestly believe doctors in the <img src=“https://hexbear.net/pictrs/image/6dedb145-206a-4b35-ab5e-c9e41e1130c7.png” alt=“Amerikkka” width=“24” height=“auto”> weren’t still running Nazi experiments domestically after WWII?

        dehumanization of tech workers in the last 20 years and the rise of AI further rationalizing more dehumanization and devaluing of tech work.

        Reframe your narrative, <img src=“https://hexbear.net/pictrs/image/6dedb145-206a-4b35-ab5e-c9e41e1130c7.png” alt=“Amerikkka” width=“24” height=“auto”> never ceased dehumanization campaigns. Esp. in tech.