OpenBlow Multiple Deanonymizat... Note

OpenBlow Multiple Deanonymization Vulnerabilities

Posted by Red Nanaki via Fulldisclosure on Jul 02OpenBlow Multiple Deanonymization Vulnerabilities Summary A production deployment was observed (HTTP archive of a full, real whistleblower submission) to route its anonymous reporting flow through Google. The intake CAPTCHA is Google reCAPTCHA, enforced as a mandatory, server-validated gate on report submission, and the UI additionally pulls a web font from fonts.gstatic.com. As a result, every prospective whistleblower's browser makes...