Month: September 2021

How to prevent CSRF attacks in ASP.NET Core

Cross-site request forgery (CSRF) is an attack that tricks an end user into executing undesirable actions while logged into a web application. Taking advantage of the authenticated user’s permissions, a CSRF attack dupes the victim into performing specific actions that benefit the attacker. For example, a CSRF attack could be used to make a purchase

Read More
Get started with SvelteKit

So-called metaframeworks like Next.js and Gatsby have taken off in the last few years. This article introduces you to one of the most recent examples, the SvelteKit framework for Svelte. Like Next.js before it, SvelteKit provides an all-in-one, full-stack platform for building reactive web apps. SvelteKit is the successor to Sapper, the previous generation of

Read More
Amazon settles with two former employee activists, Emily Cunningham and Maren Costa, over accusations it illegally fired them for organizing (Karen Weise/New York Times)

Karen Weise / New York Times: Amazon settles with two former employee activists, Emily Cunningham and Maren Costa, over accusations it illegally fired them for organizing  —  Amazon has settled with two of its most prominent internal critics, staving off a public hearing over accusations that the company illegally fired the pair …

Read More
US and EU will cooperate across various tech areas, including AI, semiconductors, and supply chain security, to ensure sensitive technologies are not misused (Campbell Kwan/ZDNet)

Campbell Kwan / ZDNet: US and EU will cooperate across various tech areas, including AI, semiconductors, and supply chain security, to ensure sensitive technologies are not misused  —  The new US-EU Trade and Technology Council aims to keep an eye on how sensitive technologies are used.

Read More
GM announces Ultifi, a software platform for its cars that will enable OTA updates, in-car subscription services, and more, rolling out in 2023 (Andrew J. Hawkins/The Verge)

Andrew J. Hawkins / The Verge: GM announces Ultifi, a software platform for its cars that will enable OTA updates, in-car subscription services, and more, rolling out in 2023  —  Ultifi will start rolling out to GM vehicles in 2023  —  General Motors announced a new “end-to-end” software platform for its cars called …

Read More
Apparent flaw allows hackers to steal money from a locked iPhone, when a Visa card is set up with Apple Pay Express Transit

Security researchers today announced findings surrounding a vulnerability with Visa cards, specifically when a Visa card is set as the default card for Express Transit in Apple Pay on the iPhone (this feature is named Express Travel in the UK). The demo shared by The Telegraph showed that a hacker could trick the contactless system

Read More
Researchers: a flaw in Apple Pay lets attackers make a Visa payment with a locked iPhone in Express Transit mode; Apple calls it “a concern with a Visa system” (BBC)

BBC: Researchers: a flaw in Apple Pay lets attackers make a Visa payment with a locked iPhone in Express Transit mode; Apple calls it “a concern with a Visa system”  —  Large unauthorised contactless payments can be made on locked iPhones by exploiting how an Apple Pay feature designed …

Read More
iOS 15 sees some Siri requests disappear

It includes asking Siri about voicemails and call history… What you need to know Apple seems to have removed some Siri functions in iOS 15. Users can no longer ask the assistant about voicemails or call history. The change has had an impact on people who rely on these features for accessibility purposes. Multiple reports

Read More