Ñо¿ÍŶÓÑÝʾʹÓà MITM ÈÆ¹ý FIDO2 ÍøÂç´¹ÂÚ·À»¤

Ðû²¼Ê±¼ä 2024-05-07
1. Ñо¿ÍŶÓÑÝʾʹÓà MITM ÈÆ¹ý FIDO2 ÍøÂç´¹ÂÚ·À»¤


5ÔÂ6ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬FIDO2 ÊÇÎÞÃÜÂëÉí·ÝÑéÖ¤µÄÏÖ´úÉí·ÝÑéÖ¤×éÊõÓï¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ìËÙÉí·ÝÔÚÏß (FIDO) ͬÃË¿ª·¢ËüÀ´È¡´ú¹Å°åÒÑÖªÃÜÂëµÄʹÓ㬣¬£¬£¬£¬£¬£¬£¬²¢ÌṩһÖÖʹÓÃÎïÀí»òǶÈëʽÃÜÔ¿¾ÙÐÐÉí·ÝÑéÖ¤µÄÇå¾²ÒªÁì¡£¡£¡£¡£¡£¡£ÖÚËùÖÜÖª£¬£¬£¬£¬£¬£¬£¬£¬FIDO2 ¿ÉÒÔ±£» £»£»£»£»¤ÈËÃÇÃâÊÜÖÐÐÄÈË (MITM)¡¢ÍøÂç´¹ÂÚºÍ»á»°Ð®ÖÆ¹¥»÷¡£¡£¡£¡£¡£¡£FIDO2 Éí·ÝÑéÖ¤Á÷³ÌÓÉÓÃÓÚ¿Í»§¶ËÒÀÀµ·½ (RP)£¨¼´ÔÆÓ¦ÓóÌÐòͨѶ£©µÄ WebAuthn API ¹æ·¶ºÍÓÃÓÚÓ²¼þͨѶµÄ¿Í»§¶Ëµ½Éí·ÝÑéÖ¤Æ÷ (CTAP) ЭÒé×é³É¡£¡£¡£¡£¡£¡£Õû¸öÀú³ÌÓÉä¯ÀÀÆ÷ÖÎÀí£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨Á½¸öÉí·ÝÑéÖ¤°ì·¨£º×°±¸×¢²áºÍÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£Ö®ÒÔÊÇÕâÑù½á¹¹£¬£¬£¬£¬£¬£¬£¬£¬ÊÇÓÉÓÚ FIDO2 »ùÓÚ¹«Ô¿¼ÓÃÜ»úÖÆ¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿Í»§¶ËÔÚ´Ë´¦ÌìÉú˽ԿºÍ¹«Ô¿£¬£¬£¬£¬£¬£¬£¬£¬²¢½«ºóÕß·¢ËÍ»Ø RP ÒÔÔڵǼʱ¾ÙÐÐÊðÃûÑéÖ¤¡£¡£¡£¡£¡£¡£FIDO ¿ÉÒÔÓÃ×÷µ¥¸öÓ¦ÓóÌÐò»òÁªºÏÓ¦ÓóÌÐòµÄÉí·ÝÑéÖ¤ÒªÁì¡£¡£¡£¡£¡£¡£¹ØÓÚÄÇЩ²»ÖªµÀµÄÈËÀ´Ëµ£¬£¬£¬£¬£¬£¬£¬£¬ÁªºÏÊÇÖ¸Óɵ¥¸öÉí·ÝÌṩÉÌ (IdP) ÖÎÀíµÄ¶à¸ö²»Ïà¹ØÓ¦ÓóÌÐòµÄµ¥µãµÇ¼ (SSO)¡£¡£¡£¡£¡£¡£  


https://securityboulevard.com/2024/05/using-mitm-to-bypass-fido2-phishing-resistant-protection/


2. ¹ú¼ÊÌØÉâ×éÖ¯½«Ó¡¶ÈÄáÎ÷ÑÇÁÐÎªÌØ¹¤Èí¼þÖÐÐÄ


5ÔÂ6ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬¹ú¼ÊÌØÉâ×éÖ¯Ç徲ʵÑéÊÒµÄ×îÐÂÑо¿Åú×¢£¬£¬£¬£¬£¬£¬£¬£¬Ó¡¶ÈÄáÎ÷ÑÇÊÇ¼à¿Ø¹¤¾ßºÍ¹©Ó¦É̵ÄÐÂÐËÖÐÐÄ¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯·¢Ã÷ÁË´Ó 2017 Ä굽ȥÄê´ÓÒÔÉ«ÁС¢Ï£À°¡¢ÐÂ¼ÓÆÂºÍÂíÀ´Î÷Ñǵȹú¼ÒÏòÓ¡¶ÈÄáÎ÷ÑÇÏúÊÛºÍÔËÊä¸ß¶ÈÇÖÈëÐÔÌØ¹¤Èí¼þºÍÆäËû¼à¿ØÊÖÒÕµÄÖ¤¾Ý¡£¡£¡£¡£¡£¡£¾Ý±¨µÀ£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩ¼à¿Ø¹¤¾ßÊôÓÚ¡°Q Cyber Technologies£¨Óë NSO Group Ïà¹Ø£©¡¢Intellexa ²ÆÍÅ¡¢Saito Tech£¨Ò²³ÆÎª Candiru£©¡¢FinFisher ¼°ÆäÈ«×Ê×Ó¹«Ë¾ Raedarius M8 Sdn Bhd ºÍ Wintego Systems¡±µÈ¹«Ë¾¡£¡£¡£¡£¡£¡£¹ú¼ÊÌØÉâ×éÖ¯»¹ÏêϸÏÈÈÝÁËÓëÕë¶ÔÓ¡¶ÈÄáÎ÷ÑÇСÎÒ˽¼ÒµÄÌØ¹¤Èí¼þƽ̨Ïà¹ØµÄÖÖÖÖ¶ñÒâÓòÃûºÍÍøÂç»ù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£¹ú¼ÊÌØÉâ×éÖ¯ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ËäÈ»ÕâЩÓòÃûÄ£ÄâÁËÕþµ³ºÍýÌå»ú¹¹£¬£¬£¬£¬£¬£¬£¬£¬µ«ÏÖÔÚÉв»ÇåÎúË­ÊÇÕæÕýµÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¹ú¼ÊÌØÉâ×éÖ¯µÄ±¨¸æ³Æ£¬£¬£¬£¬£¬£¬£¬£¬Ìع¤Èí¼þÏòÀ´±»Õþ¸®ÊµÌåÓÃÀ´Õë¶ÔÃñ¼äÉç»áºÍ¼ÇÕߣ¬£¬£¬£¬£¬£¬£¬£¬Òò´Ë¹ØÓÚ¹«ÃñȨÁ¦Êܵ½ÇÖÕ¼µÄÓ¡¶ÈÄáÎ÷ÑÇÀ´Ëµ£¬£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÌØÊâÁîÈ˵£ÐĵÄ¡£¡£¡£¡£¡£¡£ 


https://www.darkreading.com/cybersecurity-operations/amnesty-international-cites-indonesia-as-spyware-hub


3. ·¨¹Ù˼Á¿¶Ô¹È¸èÆÆËðÄÚ²¿Ì¸Ìì¼Í¼¾ÙÐÐÖÆ²Ã


5ÔÂ4ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Ôڹȸ袶ϰ¸ÉóѶµÄµÚ¶þÌìÁ˰¸³Â´Ê¼´½«¿¢ÊÂʱ£¬£¬£¬£¬£¬£¬£¬£¬ÃÀ¹úµØÇø·¨¹Ù°¢Ã×ÌØ¡¤Ã·Ëþ (Amit Mehta) ȨºâÁËÊÇ·ñÓ¦¸Ã¶ÔÃÀ¹ú˾·¨²¿Ëù˵µÄ¹È¸è¡°ÀýÐС¢°´ÆÚºÍÕý³£Ïú»Ù¡±Ö¤¾Ý¾ÙÐÐÖÆ²Ã¡£¡£¡£¡£¡£¡£¹È¸è±»Ö¸¿ØÖƶ©ÁËÒ»ÏîÕþ²ß£¬£¬£¬£¬£¬£¬£¬£¬Ö¸Ê¾Ô±¹¤ÔÚÌÖÂÛÃô¸Ð»°ÌâʱĬÈϹرÕ̸Ìì¼Í¼£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨¹È¸èµÄÊÕÈë·ÖÏíºÍÒÆ¶¯Ó¦ÓóÌÐò·Ö·¢Ð­Òé¡£¡£¡£¡£¡£¡£ÃÀ¹ú˾·¨²¿ºÍÖÝ×ÜÉó²é³¤ÒÔΪ£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩЭÒéÖ¼ÔÚά³Ö¹È¸èÔÚËÑË÷ÁìÓòµÄ¢¶Ïְλ¡£¡£¡£¡£¡£¡£¾ÝÃÀ¹ú˾·¨²¿³Æ£¬£¬£¬£¬£¬£¬£¬£¬¹È¸è²»µ«ÔÚÊÓ²ìʱ´ú²¢ÇÒÔÚËßËÏʱ´úÏú»ÙÁËDZÔÚµÄÊýÊ®Íò¸ö̸Ìì»á»°¡£¡£¡£¡£¡£¡£ÔÚÃÀ¹ú˾·¨²¿·¢Ã÷¸ÃÕþ²ßºó£¬£¬£¬£¬£¬£¬£¬£¬¹È¸è²Å×èÖ¹ÁËÕâÖÖ×ö·¨¡£¡£¡£¡£¡£¡£Ë¾·¨²¿µÄ״ʦ¿ÏÄá˼¡¤¶¡Ôó (Kenneth Dintzer) ÖÜÎ叿Ëß÷Ëþ£¬£¬£¬£¬£¬£¬£¬£¬Ë¾·¨²¿ÒÔΪ·¨ÔºÓ¦¸ÃµÃ³öÕâÑùµÄ½áÂÛ£ºÓëÀúÊ·¾ÙÐн»Á÷Åú×¢ÎúÒþ²ØÐÅÏ¢µÄ·´¾ºÕùÒâͼ£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËûÃÇÖªµÀ×Ô¼ºÎ¥·´ÁË·´Â¢¶Ï·¨¡£¡£¡£¡£¡£¡£


https://arstechnica.com/tech-policy/2024/05/judge-mulls-sanctions-over-googles-shocking-destruction-of-internal-chats/


4. 2023ÄêGoogle×èÖ¹228Íò¸ö¶ñÒâappÔÚGoogle PlayÐû²¼


4ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ 2023 Ä꣬£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ×èÖ¹ÁË 228 Íò¸öÎ¥·´Õþ²ßµÄÓ¦ÓóÌÐòÔÚ Google Play ÉÏÐû²¼£¬£¬£¬£¬£¬£¬£¬£¬²¿·Ö¹é¹¦ÓÚÎÒÃǶÔеĺÍˢеÄÇå¾²¹¦Ð§¡¢Õþ²ß¸üÐÂÒÔ¼°ÏȽøµÄ»úеѧϰºÍÓ¦ÓóÌÐòÉóºËÁ÷³ÌµÄͶ×Ê¡£¡£¡£¡£¡£¡£ÎÒÃÇ»¹ÔöÇ¿ÁË¿ª·¢ÕßÈëÖ°ºÍÉóºËÁ÷³Ì£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ¿ª·¢ÕßÊ״ν¨ÉèÆä Play ÕÊ»§Ê±ÐèÒª¸ü¶àÉí·ÝÐÅÏ¢¡£¡£¡£¡£¡£¡£¼ÓÉ϶ÔÉó²é¹¤¾ßºÍÁ÷³ÌµÄͶ×Ê£¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃǸüÓÐÓõØÊ¶±ðÁ˲»Á¼ÐÐΪÕߺÍڲƭÍŻ£¬£¬£¬£¬£¬£¬£¬²¢Õ¥È¡ÁË 33.3 Íò¸ö²»Á¼ÕÊ»§½øÈë Play£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩÕÊ»§ÒÑÈ·ÒÔΪ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÒ»ÔÙÑÏÖØÎ¥·´Õþ²ß¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬½ü 20 Íò¸öÓ¦ÓóÌÐòÌá½»±»¾Ü¾ø»òÐÞ¸´£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÈ·±£×¼È·Ê¹Óúǫ́λÖûò¶ÌÐÅ»á¼ûµÈÃô¸ÐȨÏÞ¡£¡£¡£¡£¡£¡£ÎªÁË×ÊÖú´ó¹æÄ£±£» £»£»£»£»¤Óû§Òþ˽£¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇÓë SDK ÌṩÉÌÏàÖú£¬£¬£¬£¬£¬£¬£¬£¬ÏÞÖÆÃô¸ÐÊý¾Ý»á¼ûºÍ¹²Ïí£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÔöǿӰÏì 79 Íò¶à¸öÓ¦ÓóÌÐòµÄÁè¼Ý 31 ¸ö SDK µÄÒþ˽״̬¡£¡£¡£¡£¡£¡£ÎÒÃÇ»¹ÏÔ×ÅÀ©Õ¹ÁËGoogle Play SDK Ë÷Òý£¬£¬£¬£¬£¬£¬£¬£¬¸ÃË÷ÒýÏÖÔÚº­¸ÇÁË Android Éú̬ϵͳÖнü 600 Íò¸öÓ¦ÓóÌÐòËùʹÓÃµÄ SDK¡£¡£¡£¡£¡£¡£ÕâÒ»Ãû¹óµÄ×ÊÔ´¿É×ÊÖú¿ª·¢Ö°Ô±×ö³ö¸üºÃµÄ SDK Ñ¡Ôñ¡¢Ìá¸ßÓ¦ÓóÌÐòÖÊÁ¿²¢×îºéÁ÷ƽµØ½µµÍ¼¯³ÉΣº¦¡£¡£¡£¡£¡£¡£


https://security.googleblog.com/2024/04/how-we-fought-bad-apps-and-bad-actors-in-2023.html


5. Á½¸ö¼«ÓÒÒíýÌåÍøÕ¾Ôâµ½ºÚ¿Í¹¥»÷ºÍÆÆËð


5ÔÂ3ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Á½¼Ò¼«ÓÒÒíýÌåÍøÕ¾Ôâµ½ºÚ¿Í¹¥»÷ºÍÆÆË𣬣¬£¬£¬£¬£¬£¬£¬¶©ÔÄÕßºÍÆäÄÚ²¿ÍøÕ¾Êý¾Ý±»Ð¹Â¶£¬£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»´ÎÏÔ×ųöÓÚÕþÖÎÄîÍ·µÄ¹¥»÷µÄÒ»²¿·Ö¡£¡£¡£¡£¡£¡£ÏÖÔÚÉÐδ¹ûÕæÉù³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ£¬£¬£¬£¬£¬£¬£¬£¬µ«ÕâÖÁÉÙÊDZ¾ÖܵڶþÆð¿´ËƳöÓÚÕþÖÎÄîÍ·µÄºÚ¿Í¹¥»÷¡£¡£¡£¡£¡£¡£ÒÑÍùÔø·¢¶¯¹ý³öÓÚÕþÖÎÄîÍ·µÄ¹¥»÷µÄÍøÂç·¸·¨×éÖ¯SiegedSecÉù³Æ¶ÔÎÛÃûÕÑÖøµÄ Westboro ½þÐÅ»á½ÌÌ÷¢¶¯Á˹¥»÷¡£¡£¡£¡£¡£¡£Ã»Óм£ÏóÅú×¢ÕâÁ½ÆðÊÂÎñÓйØÁª¡£¡£¡£¡£¡£¡£Human Events ÊÇÒ»¼Ò½¨ÉèÓÚ 1944 ÄêµÄÊØ¾ÉÅÉÐÂÎÅ»ú¹¹£¬£¬£¬£¬£¬£¬£¬£¬ÓÚ 2022 Äê 5 ÔÂÊÕ¹ºÁËPost Millennial¡£¡£¡£¡£¡£¡£ÕâÁ½¸ö×éÖ¯µÄÍøÕ¾¾ùÖ¸³ö£¬£¬£¬£¬£¬£¬£¬£¬ËüÃÇÊÇÓÉÕþÖÎýÌ幫˾ (Political Media, Inc. ) Éè¼ÆºÍά»¤µÄ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÊÇÒ»¼ÒλÓÚ¸¥¼ªÄáÑÇÖݵġ°ÖÐÓÒÒíÐÂýÌå×Éѯ¹«Ë¾¡±£¬£¬£¬£¬£¬£¬£¬£¬ÌṩµÄЧÀͰüÀ¨ÄÚÈÝÖÎÀíϵͳ¡¢ÍøÒ³Éè¼Æ¡¢µç×ÓÓʼþЧÀͺÍÓªÏú¡£¡£¡£¡£¡£¡£ 


https://cyberscoop.com/far-right-websites-hacked-and-defaced/


6. Å·ÖÞÐ̾¯×éÖ¯¹Ø±Õ12¸öÕ©Æ­ºô½ÐÖÐÐIJ¢¾Ð²¶¶à¸öÏÓÒÉÈË


5ÔÂ3ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Å·ÖÞÐ̾¯×éÖ¯Ïòµ¼µÄÒ»ÏîÃûΪ¡°Å˶àÀ­¡±µÄÐж¯ÒѾ­¹Ø±ÕÁËÊ®¼¸¸öµç»°Õ©Æ­ÖÐÐÄ£¬£¬£¬£¬£¬£¬£¬£¬²¢¾Ð²¶ÁË 21 ÃûÏÓÒÉÈË¡£¡£¡£¡£¡£¡£¾¯·½Ô¤¼Æ£¬£¬£¬£¬£¬£¬£¬£¬ÕâÒ»Ðж¯×èÖ¹ÁË·¸·¨·Ö×Ó´ÓÊܺ¦ÕßÉíÉÏÆ­È¡Áè¼Ý 1000 ÍòÅ·Ôª¡£¡£¡£¡£¡£¡£¸Ã·¸·¨ÍøÂçÔÚ°¢¶û°ÍÄáÑÇ¡¢²¨Ë¹ÄáÑǺͺÚÈû¸çάÄÇ¡¢¿ÆË÷ÎÖºÍÀè°ÍÄÛÔËÓªºô½ÐÖÐÐÄ£¬£¬£¬£¬£¬£¬£¬£¬ÌìÌì½Óµ½¡°Êýǧ¸ö¡±Õ©Æ­µç»°£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨¼Ù¾¯Ô±µç»°¡¢Í¶×ÊÕ©Æ­ºÍÀËÂþÕ©Æ­¡£¡£¡£¡£¡£¡£ÈôÊDz»Êǵ¹úµÄÒ»ÃûÒøÐгöÄÉÔ±£¬£¬£¬£¬£¬£¬£¬£¬ÇÔÔô¿ÉÄÜ»áÆ­×߸ü¶àµÄÊܺ¦Õß¡£¡£¡£¡£¡£¡£Å˶àÀ­Ðж¯Ê¼ÓÚ 2023 Äê 12 Ô£¬£¬£¬£¬£¬£¬£¬£¬ÆäʱһÃûÖ÷¹ËÒªÇó¸¥À³±¤µÄÒ»Ãû³öÄÉÔ±ÌáÈ¡Áè¼Ý 100,000 Å·Ôª£¨107,247 ÃÀÔª£©µÄÏֽ𡣡£¡£¡£¡£¡£ÕâÒ»ÇëÇóÉæ¼°µ½ÒøÐÐÊÂÇéÖ°Ô±£¬£¬£¬£¬£¬£¬£¬£¬ËûÃǺܿì¾ÍµÃÖª¸Ã¿Í»§ÂäÈëÁ˼پ¯Ô±µÄȦÌס£¡£¡£¡£¡£¡£ÕâÖÖÀàÐ͵ÄÚ²Æ­Éæ¼°·¸·¨·Ö×Ó×Ô³ÆÊÇÖ´·¨Ö°Ô±£¬£¬£¬£¬£¬£¬£¬£¬ÆÈʹÊܺ¦ÕßÖ§¸¶Ò»´ó±ÊÇ®¡ª¡ªÍ¨³£ÊǻѳÆËûÃÇ´í¹ýÁËÐéαµÄ¿ªÍ¥ÈÕÆÚ£¬£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÃæÁپв¶Á£¬£¬£¬£¬£¬£¬£¬³ý·ÇËûÃÇÖ§¸¶·£¿£¿£¿£¿£¿£¿î£¬£¬£¬£¬£¬£¬£¬£¬»òÕ߯äËûһЩ±àÔìµÄ¹ÊÊ¡£¡£¡£¡£¡£¡£


https://www.theregister.com/2024/05/03/operation_pandora_europol/