Ryan Victory · @beerandraptors
1 followers · 1 posts · Server infosec.exchange

Make it easier to find malware targeting your users: If you’re designing (or redesigning) your web presence and it includes login or authentication functionality of some sort, consider making your authentication cookie names unique to your system.

For example, instead of calling your authentication cookie “auth” or “session,” maybe call it “blue_tiger_cub” (completely contrived example). Now, if you’re hunting for credtheft or infostealing malware targeting your brand, your searches just got a whole lot more targeted.

This does have me thinking though…could you rotate the authentication cookie name on a regular basis?

Or maybe we could just move away from cookies for session management and use an extended version of something like to sign every single request, but I digress…

#webauthn #malware #webauthentication #cookies #securityarchitecture #threathunting #yara

Last updated 2 years ago

Ryan Victory · @beerandraptors
1 followers · 1 posts · Server infosec.exchange

Make it easier to find malware targeting your users: If you’re designing (or redesigning) your web presence and it includes login or authentication functionality of some sort, consider making your authentication cookie names unique to your system.
For example, instead of calling your authentication cookie “auth” or “session,” maybe call it “blue_tiger_cub” (completely contrived example). Now, if you’re hunting for credtheft or infostealing malware targeting your brand, your searches just got a whole lot more targeted.
This does have me thinking though…could you rotate the authentication cookie name on a regular basis?
Or maybe we could just move away from cookies for session management and use an extended version of something like to sign every single request, but I digress…

#webauthn #malware #webauthentication #cookies #securityarchitecture #threathunting #yara

Last updated 2 years ago

Symfony Station · @symfonystation
449 followers · 2109 posts · Server phpc.social

This is outstanding though lengthy. Understanding Authentication In Websites: A Banking Analogy via Smashing Magazine. smashingmagazine.com/2023/01/a

#webauthentication

Last updated 2 years ago

Se7h 💻 🐃 🐧 · @Se7h
375 followers · 4399 posts · Server mastodon.xyz
Laurent Espitallier · @frenchhope
402 followers · 10793 posts · Server framapiaf.org

RT @mozhacks@twitter.com: We're excited to see the API and FIDO U2F support ship in Firefox 60! 🎉
Cannot wait until then? Try it out in @FirefoxNightly@twitter.com & read the intro from @JamesPugJones@twitter.com & @ttaubert@twitter.com why should you be excited too! hacks.mozilla.org/2018/01/usin

#webauthentication

Last updated 7 years ago