Cloudflare/Security-Audit-Skill
Cloudflare's security audit skill repository provides tools for assessing and improving security measures. It is hosted on GitHub and includes code, documentation, and community support. (github.com)
A leaked set of filesystem images from an in-use Flock automatic license-plate recognition camera reveals a device running an end-of-life software stack and containing obvious operational secrets. The camera’s Android build (sdk 27, release 8.1) reported a security patch date of 2018-06-05 and its kernel is Linux 3.18.71, leaving it unpatched for many years and exposed to publicly known exploits such as CVE-2021-1905 (Adreno GPU use-after-free) and CVE-2018-9568 (kernel socket type confusion), among others. The firmware images include system and boot partitions (e.g., partitions/24_system.img and partitions/21_boot.img) that make these versions trivial to verify, and a vendor response pointed to a vulnerability disclosure process rather than an immediate mitigation.
The firmware and persist/media partitions also contain hard-coded and plaintext credentials that link the device to Flock’s production infrastructure. A shared library bundled into dozens of Flock apps exposes an x-api-key embedded in CameraSettings; that key is sufficient to request per-device Auth0 client_id/client_secret pairs from hpnotiq.flocksafety.com, and those secrets were found in persist/auth0/auth0_cred. Logs stored (and only lightly protected) in media partitions include the camera’s MAC, thousands of provisioning calls, GPS coordinates (43.10151313, -88.05270186) and a serial number, pinpointing a camera on N Mayfair Rd in Wauwatosa, WI. The combined flaws enable backend impersonation and token minting and raise significant privacy and security concerns for deployed ALPR systems.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.
Cloudflare's security audit skill repository provides tools for assessing and improving security measures. It is hosted on GitHub and includes code, documentation, and community support. (github.com)
Signing keys used to verify US driver's license barcodes can be recovered, which may undermine their security. The process of retrieving these cryptographic keys raises concerns about the integrity of license verification systems. (ryan.science)
An ex-Microsoft engineer explained the origin of the 'FCKGW' Windows XP product key, which became notorious among software pirates. The key was originally a placeholder or internal code before being widely used illegally by users. (pcgamer.com)
Pangram offers an AI detection tool that accurately identifies AI-generated text and images, trusted by universities and global brands. It uses natural language processing and pattern analysis to distinguish between human and AI content with over 99.9% accuracy, verified by third-party researchers. (pangram.com)
A cartel of tech CEOs is attempting to control AI development through safety measures and regulations, potentially hindering competition and innovation. Critics argue that such efforts could give established companies an unfair advantage while slowing progress on beneficial AI applications. (fractalsofchange.substack.com)
ProPublica obtained IRS data revealing that many of the wealthiest Americans, including Jeff Bezos and Elon Musk, pay little or no federal income tax despite their massive wealth. The records provide an unprecedented look into their financial activities, challenging the idea that the wealthy contribute proportionally to taxes. (propublica.org)
Today's best Hacker News stories, summarized and screenshotted, one email a day.