Public Pentest Report Archives - 7ASecurity Blog https://7asecurity.com/blog/ Helping you secure apps and websites Wed, 30 Oct 2024 09:24:02 +0000 en-US hourly 1 https://7asecurity.com/blog/contents/uploads/2019/06/favicon.ico Public Pentest Report Archives - 7ASecurity Blog https://7asecurity.com/blog/ 32 32 SecureDrop Security Audit by 7ASecurity https://7asecurity.com/blog/2024/10/securedrop-security-audit/ Tue, 29 Oct 2024 08:29:07 +0000 About SecureDrop SecureDrop is an open source whistleblower submission system that media organizations and NGOs can install to accept anonymous, secure documents from sources. It receives documents via the Tor network (a distributed network of relays that help protect users’ privacy), records only the date and time of the transfer, and enables recipients to view submissions in its …

The post SecureDrop Security Audit by 7ASecurity appeared first on 7ASecurity Blog.

]]>
7ASecurity Completes Disguiser Framework Audit https://7asecurity.com/blog/2024/03/7asecurity-completes-disguiser-framework-audit/ Wed, 06 Mar 2024 08:03:47 +0000 About Disguiser   Disguiser is a novel framework that enables end-to-end measurement for accurately and comprehensively investigating global internet censorship practices. It’s challenging to conduct large-scale internet censorship measurement, as it involves triggering censors through artificial requests and identifying abnormalities from corresponding responses. Due to the lack of “ground truth” on the expected responses from legitimate services, …

The post 7ASecurity Completes Disguiser Framework Audit appeared first on 7ASecurity Blog.

]]>
DEfO-2 OpenSSL HPKE PR Security Audit https://7asecurity.com/blog/2023/12/defo-2-openssl-hpke-pr-security-audit/ Wed, 06 Dec 2023 11:31:19 +0000 DEfO is developing an implementation of the Encrypted ClientHello (ECH) mechanism for OpenSSL. This effectively closes a privacy loophole in the Transport Layer Security protocol. Project Overview The DEfO project is developing an implementation of the encrypted ClientHello (ECH) mechanism for OpenSSL, which is a widely used library that provides an implementation of the Transport …

The post DEfO-2 OpenSSL HPKE PR Security Audit appeared first on 7ASecurity Blog.

]]>