Most Popular

1500 questions
41
votes
2 answers

Did a Huawei modem just try to do a Man-In-The-Middle attack on me?

I have a replica of Huawei B535-333 LTE modem. While I was working from home on my computer I randomly got a security alert saying that certificate for connection with outlook.office365.com was issued by untrusted company and the certificate name…
gtu
  • 513
  • 1
  • 2
  • 6
41
votes
5 answers

How can you trust that there is no backdoor in your hardware?

We know that Intel processors have one (ME) so it is definitely possible. In general, how could you even trust a piece of hardware like a CPU or network card, even if the manufacturer says there is no backdoor? For software, it is easy since you can…
MasterYi
  • 413
  • 4
  • 4
41
votes
14 answers

How to safely save passwords for a future administrator?

I am the volunteer IT administrator for a local non-profit organization. The organization has a few systems - specifically security cameras, network hardware, and telephones - that have local administrator accounts to manage them. Right now, I am…
Moshe Katz
  • 1,360
  • 1
  • 11
  • 17
41
votes
4 answers

why a client authentication is not commonly performed in the TLS protocol?

Is there any reason for this other than key/certificate management on the client-side?
naresh
  • 645
  • 1
  • 7
  • 7
41
votes
4 answers

What alternatives are there to the existing Certificate Authority system for SSL?

Whilst the current CA system works very well for a lot of people, it does put a lot of power into individual CAs' hands, and makes a CA hack potentially devastating for customers and business. What alternatives are there to certificate authorities,…
Polynomial
  • 135,049
  • 43
  • 306
  • 382
41
votes
9 answers

What are the potential risks of leaving a device in public, but locked?

Let's say you're in a public café, or conference, where you trust your device won't be stolen if you go to the bathroom for 5 minutes, but you don't trust it might not be tampered with. What are the potential security risks I might run into here,…
Zee
  • 529
  • 1
  • 4
  • 7
41
votes
7 answers

Security risks of user generated HTML?

I am creating a website that allows people to upload HTML content. Currently these are the tags that are banned: