<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Share your calls! Even if you don't want to! in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Share-your-calls-Even-if-you-don-t-want-to/m-p/43945#M5337</link>
    <description>&lt;P&gt;An iPhone app, called Acr call recorder, allows you to record your phone calls.&amp;nbsp; A lot of people find this handy.&amp;nbsp; (I'm not quite sure why.&amp;nbsp; When I'm done with a call, I've got notes and action items, but I don't need the whole call.&amp;nbsp; But, to each his or her own ...)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Well, apparently &lt;A href="https://nakedsecurity.sophos.com/2021/03/11/how-confidential-are-your-calls-this-iphone-app-shared-them-with-everyone/" target="_blank" rel="noopener"&gt;it's quite insecure&lt;/A&gt;.&amp;nbsp; For one thing, it stores you calls in the cloud.&amp;nbsp; For another, it uses no authentication when it retrieves them.&amp;nbsp; It also uses insecure direct object referencing (IDOR), and so, with a little guesswork and experimentation, anybody can retrieve any calls at all from the system.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By the way, the "community," for the most part, also uses IDOR.&amp;nbsp; Now, most of the "community" is open to the world, so this is hardly a problem (or news), but I detailed some of it in &lt;A href="https://community.isc2.org/t5/Tech-Talk/An-experiment-in-re-URLing/m-p/34471#M2902" target="_blank" rel="noopener"&gt;another posting&lt;/A&gt;, and even turn it to my advantage.&amp;nbsp; For example, that other posting is at&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.isc2.org/t5/Tech-Talk/An-experiment-in-re-URLing/m-p/34471#M2902" target="_blank" rel="noopener"&gt;https://community.isc2.org/t5/Tech-Talk/An-experiment-in-re-URLing/m-p/34471#M2902&lt;/A&gt;&lt;/P&gt;&lt;P&gt;but you can also get it if you specify&amp;nbsp;&lt;A href="https://community.isc2.org/t5/T/A/m-p/34471" target="_blank" rel="noopener"&gt;https://community.isc2.org/t5/T/A/m-p/34471&lt;/A&gt;.&amp;nbsp; There are significant sections of the URL that really do nothing, and can be modified.&amp;nbsp; As another example, the URL for this post is&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.isc2.org/t5/Industry-News/Share-your-calls-Even-if-you-don-t-want-to/m-p/43945#M5337" target="_blank"&gt;https://community.isc2.org/t5/Industry-News/Share-your-calls-Even-if-you-don-t-want-to/m-p/43945#M5337&lt;/A&gt;&lt;/P&gt;&lt;P&gt;but you can also use&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.isc2.org/t5/I/S/m-p/43945" target="_blank"&gt;https://community.isc2.org/t5/I/S/m-p/43945&lt;/A&gt;, or even&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.isc2.org/t5/something/somethingelse/m-p/43945" target="_blank"&gt;https://community.isc2.org/t5/something/somethingelse/m-p/43945&lt;/A&gt;.&amp;nbsp; In general, this is bad practice, since it can allow for misuse of the disregarded fields.&amp;nbsp; I could, for example, imply that this posting came from the "Careers" section of the "community" by specifying&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.isc2.org/t5/Career/Must-know/m-p/43945" target="_blank" rel="noopener"&gt;https://community.isc2.org/t5/Career/Must-know/m-p/43945&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Mar 2021 18:30:00 GMT</pubDate>
    <dc:creator>rslade</dc:creator>
    <dc:date>2021-03-12T18:30:00Z</dc:date>
    <item>
      <title>Share your calls! Even if you don't want to!</title>
      <link>https://community.isc2.org/t5/Industry-News/Share-your-calls-Even-if-you-don-t-want-to/m-p/43945#M5337</link>
      <description>&lt;P&gt;An iPhone app, called Acr call recorder, allows you to record your phone calls.&amp;nbsp; A lot of people find this handy.&amp;nbsp; (I'm not quite sure why.&amp;nbsp; When I'm done with a call, I've got notes and action items, but I don't need the whole call.&amp;nbsp; But, to each his or her own ...)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Well, apparently &lt;A href="https://nakedsecurity.sophos.com/2021/03/11/how-confidential-are-your-calls-this-iphone-app-shared-them-with-everyone/" target="_blank" rel="noopener"&gt;it's quite insecure&lt;/A&gt;.&amp;nbsp; For one thing, it stores you calls in the cloud.&amp;nbsp; For another, it uses no authentication when it retrieves them.&amp;nbsp; It also uses insecure direct object referencing (IDOR), and so, with a little guesswork and experimentation, anybody can retrieve any calls at all from the system.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By the way, the "community," for the most part, also uses IDOR.&amp;nbsp; Now, most of the "community" is open to the world, so this is hardly a problem (or news), but I detailed some of it in &lt;A href="https://community.isc2.org/t5/Tech-Talk/An-experiment-in-re-URLing/m-p/34471#M2902" target="_blank" rel="noopener"&gt;another posting&lt;/A&gt;, and even turn it to my advantage.&amp;nbsp; For example, that other posting is at&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.isc2.org/t5/Tech-Talk/An-experiment-in-re-URLing/m-p/34471#M2902" target="_blank" rel="noopener"&gt;https://community.isc2.org/t5/Tech-Talk/An-experiment-in-re-URLing/m-p/34471#M2902&lt;/A&gt;&lt;/P&gt;&lt;P&gt;but you can also get it if you specify&amp;nbsp;&lt;A href="https://community.isc2.org/t5/T/A/m-p/34471" target="_blank" rel="noopener"&gt;https://community.isc2.org/t5/T/A/m-p/34471&lt;/A&gt;.&amp;nbsp; There are significant sections of the URL that really do nothing, and can be modified.&amp;nbsp; As another example, the URL for this post is&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.isc2.org/t5/Industry-News/Share-your-calls-Even-if-you-don-t-want-to/m-p/43945#M5337" target="_blank"&gt;https://community.isc2.org/t5/Industry-News/Share-your-calls-Even-if-you-don-t-want-to/m-p/43945#M5337&lt;/A&gt;&lt;/P&gt;&lt;P&gt;but you can also use&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.isc2.org/t5/I/S/m-p/43945" target="_blank"&gt;https://community.isc2.org/t5/I/S/m-p/43945&lt;/A&gt;, or even&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.isc2.org/t5/something/somethingelse/m-p/43945" target="_blank"&gt;https://community.isc2.org/t5/something/somethingelse/m-p/43945&lt;/A&gt;.&amp;nbsp; In general, this is bad practice, since it can allow for misuse of the disregarded fields.&amp;nbsp; I could, for example, imply that this posting came from the "Careers" section of the "community" by specifying&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.isc2.org/t5/Career/Must-know/m-p/43945" target="_blank" rel="noopener"&gt;https://community.isc2.org/t5/Career/Must-know/m-p/43945&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 18:30:00 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Share-your-calls-Even-if-you-don-t-want-to/m-p/43945#M5337</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2021-03-12T18:30:00Z</dc:date>
    </item>
  </channel>
</rss>

