frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

New downgrade attack can bypass FIDO auth in Microsoft Entra ID

https://www.bleepingcomputer.com/news/security/new-downgrade-attack-can-bypass-fido-auth-in-microsoft-entra-id/
13•mikece•1h ago

Comments

moi2388•1h ago
Pff.. again an Entra ID security flaw? It’s incredibly how sloppy their single auth solution is..
Loudergood•53m ago
Safari on Windows? That browser hasn't been supported since 2012...
lousken•51m ago
What if you have conditional access policy requiring phishing resistant auth to be able to login?
parliament32•49m ago
It's not clear who this is an attack for.. organizations that have implemented phishing-resistant MFA will already have CA policy to block any sign-ins that don't have the required authentication strength (that same "You can't get there from here" message users in unsupported browsers get). Maybe it's effective if the organization is in the middle of a rollout, where FIDO is enabled but old MFA methods haven't been disabled yet?

EDIT: This is actually called out in the article:

> The attack sequence relies on the existence of an alternative authentication method (usually MFA), besides FIDO, for the targeted user account. But luckily, this tends to be the case with FIDO implementations, as most admins prefer to maintain a practical option for account recovery.

Most orgs will have TAP for account recovery, but that's not really phishable for other reasons.

dvno42•48m ago
Since this relies on simulating safari as the broswer, I wonder if a conditional access policy enforcing browser selection would help mitigate this.

While only realistic for a small number of users, I've started enforcing users of privileged tools to go through a wireguard instance before being allowed to access Azure hosted tools that rely on Entra auth. Services I publish then have a ingress whitelist of said wireguard VM.

Management of IP numbers by peg-DHCP (1998)

https://datatracker.ietf.org/doc/html/rfc2322
1•sjmulder•1m ago•0 comments

Max Read's 'A Literary History of Fake Texts in Apple's Marketing Materials'

https://daringfireball.net/2025/08/max_read_literary_history_fake_apple_texts
1•Bogdanp•3m ago•0 comments

Z-Wave Reborn – Home Assistant Connect ZWA-2

https://www.home-assistant.io/blog/2025/08/13/home-assistant-connect-zwa-2/
1•mike-cardwell•4m ago•0 comments

Is McKinsey losing its crown to AI? [video]

https://www.youtube.com/watch?v=QXAXNcRs7gQ
1•mgh2•6m ago•0 comments

Amazon Ads Multi-Touch Attribution

https://arxiv.org/abs/2508.08209
1•dakial1•7m ago•0 comments

Show HN: Cinematic Rolplay with Wan 2.2

https://www.reveriedr.com
1•amit0365•7m ago•0 comments

Ask HN: Is there an AI that can read code aloud and explain it?

2•djfobbz•9m ago•0 comments

Evals as Code: CI for LLMs with Dagger

https://dagger.io/blog/evals-as-code
2•shad42•10m ago•1 comments

Ask HN: Is https://web.whatsapp.com/ loading for you atm?

1•gjvc•10m ago•1 comments

A Good Find

https://justinjackson.ca/good-find
1•mooreds•12m ago•0 comments

If You Could Fix One Thing About AI Search, What Would It Be?

1•zyruh•13m ago•0 comments

Eca: Editor Code Assistant – AI pair programming capabilities agnostic of editor

https://github.com/editor-code-assistant/eca
1•simonpure•15m ago•0 comments

Show HN: Deploy Any Web App Directly from Claude Code

https://disco.cloud/blog/deploy-any-web-app-directly-from-claude-code/
1•gregsadetsky•16m ago•0 comments

The Tulpa in Your Pocket

https://default.blog/p/the-tulpa-in-your-pocket
1•exolymph•17m ago•0 comments

Water Cremation (Alkaline Hydrolysis)

https://en.wikipedia.org/wiki/Water_cremation
1•1659447091•17m ago•0 comments

Temporary tattoo could detect an unwanted drug in your drink

https://phys.org/news/2025-07-temporary-tattoo-unwanted-drug.html
3•wglb•22m ago•1 comments

How I Use Computers Now [video]

https://www.youtube.com/watch?v=x-sW4sKZocA
1•abhi_kr•23m ago•0 comments

Memento Mori (Short Story)

https://en.wikipedia.org/wiki/Memento_Mori_(short_story)
1•mooreds•23m ago•0 comments

Meta's superintelligence isn't here yet but its AI bets are already paying off

https://www.cnn.com/2025/07/30/tech/meta-ai-superintelligence-earnings
1•heresie-dabord•23m ago•0 comments

NIST Finalizes 'Lightweight Cryptography' Standard to Protect Small Devices

https://www.nist.gov/news-events/news/2025/08/nist-finalizes-lightweight-cryptography-standard-protect-small-devices
9•gnabgib•26m ago•0 comments

Tony Hoare on record handling. (1965)

https://dl.acm.org/doi/10.5555/1061032.1061041
2•fanf2•27m ago•1 comments

Job board for hidden PERM jobs (H1B)

https://twitter.com/JobsNowPR/status/1955441813579321352
1•exolymph•29m ago•0 comments

Tensor Auto Demo Video

https://www.youtube.com/watch?v=nJaJi5F6cak
1•didip•31m ago•0 comments

Show HN: Videolangua – end-to-end video translate and subtitle/ dub

https://videolangua.com/
1•3Sophons•31m ago•0 comments

A Conjecture Regarding SMT Instability [pdf]

https://ceur-ws.org/Vol-4008/SMT_paper21.pdf
1•luu•32m ago•0 comments

Humans, not glacial transport, brought bluestones to Stonehenge (new research)

https://phys.org/news/2025-07-humans-glacial-brought-bluestones-stonehenge.html
2•wglb•32m ago•1 comments

Edcapit Presented Its Project at Keiretsu Forum Texas (USA)

https://www.edcapit.com/2025/08/12/📢-edcapit-presented-its-project-at-keiretsu-forum-texas-usa/
1•edcapit•34m ago•3 comments

All Souls exam questions and the limits of machine reasoning

https://resobscura.substack.com/p/all-souls-exam-questions-and-the
2•benbreen•35m ago•0 comments

The quiet work of changing your mind

https://mfelix.org/stories/quiet-work-of-changing-your-mind/
1•objcts•37m ago•0 comments

Gemini rolling out personalization based on your chat history

https://arstechnica.com/ai/2025/08/google-gemini-will-now-learn-from-your-chats-unless-you-tell-it-not-to/
2•nevir•38m ago•0 comments