TLS 1.0 and TLS 1.1 Deprecated by the IETF
The IETF announced that TLS 1.0 (RFC 2246) and TLS 1.1 (RFC 4346) are formally deprecated. These versions lack support for current and recommended cryptographic algorithms and mechanisms.
57 posts
The IETF announced that TLS 1.0 (RFC 2246) and TLS 1.1 (RFC 4346) are formally deprecated. These versions lack support for current and recommended cryptographic algorithms and mechanisms.

Firefox announced that Firefox 87 introduces a stricter, more privacy-preserving default referrer policy. From now on, Firefox will trim path and query string information from the Referer header by default, preventing sites from accidentally leaking sensitive user data.

This is a decade-old vulnerability in the sudo tool that can grant any local user root access on Unix-based systems, including macOS Big Sur and earlier. Improper operation grants root privileges to arbitrary local users. To trigger it, a user only needs to rewrite argv[0] or create a symbolic link.

Recently a user on the V2EX forum reported that their security software caught the PC version of WeChat scanning browser history, and that browser cookies were involved. They included a screen recording catching it in the act.

The Google Chrome team sent an email to Linux distribution developers: starting March 15, 2021, Chromium derivatives will no longer be able to use Google APIs such as Google Sync. For the sake of user account security, Google is cutting off third-party access to its APIs.

DDoS attacks are painful for individuals and for small and medium internet companies alike — even some large enterprises struggle with them. Here's my own take on how Cloudflare, a top-tier CDN and security vendor, absorbs DDoS attacks.

Younger readers may not have a clear idea of what makes an input method "smart". Long ago, input methods were mostly standard ones — Smart ABC, for instance — where the candidate order never changed no matter what you typed. Today's input methods adjust based on the context of what you type and how often you use it, so it feels like the input method understands you. Behind that, your privacy is quietly being invaded.

Regarding this outage, some netizens claimed that, due to the pandemic, servers in various regions had been stolen. However, this claim has now been debunked — it was just a Photoshopped image.

Yesterday GitHub suffered a large-scale outage. Microsoft responded that, due to the pandemic, servers in various regions had been stolen. Microsoft also said it is doing everything it can to recover the servers and hopes to retrieve the servers and data as soon as possible.

After strengthening the address bar in 2018, Google Chrome hid the HTTP protocol field and the WWW field by default. In Chrome 85, Google again adds a series of new flags aimed at removing the full URL from the address bar.
