Blog

Microsoft's Docs.com is sharing dangerously sensitive personal files, information

If you use Microsoft’s Docs.com to store personal documents, stop reading this and make sure you aren’t inadvertently leaking your private information to the world. Microsoft sets any documents uploaded to the document sharing site as public by default—though it appears that many users aren’t aware of it. That means anyone can search Docs.com for sensitive

Read More
Critical flaw alert! Stop using JSON encryption

A vulnerability in a JSON-based web encryption protocol could allow attackers to retrieve private keys. Cryptography experts have advised against developers using JSON Web Encryption (JWE) in their applications in the past, and this vulnerability illustrates those very dangers. Software libraries implementing the JWE, or RFC 7516, specification suffer from a classic Invalid Curve Attack,

Read More