# spoofing

Published articles for spoofing.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE

DevFeed: [The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](<https://devfeed.tech/articles/the-machine-with-many-faces-post-exploitation-identity-misuse-in-spiffe-spire-7753.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/>)

Author: Eviatar Garzi

Published: 2026-09-10T10:00:43Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [identity](<https://devfeed.tech/tags/identity.md>), [json](<https://devfeed.tech/tags/json.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [linux](<https://devfeed.tech/tags/linux.md>), [malware](<https://devfeed.tech/tags/malware.md>), [node](<https://devfeed.tech/tags/node.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [research](<https://devfeed.tech/tags/research.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [spiffe](<https://devfeed.tech/tags/spiffe.md>), [spire](<https://devfeed.tech/tags/spire.md>), [spoof](<https://devfeed.tech/tags/spoof.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>), [tool](<https://devfeed.tech/tags/tool.md>)

### AI overview

Research on a post-exploitation technique in which root access to a Kubernetes node can let an attacker spoof cgroup metadata used by SPIRE workload attestation, impersonate co-located workloads, and obtain SVIDs.

### Source excerpt

Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities. The post The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE appeared first on Unit 42.

## 10+ best practices to improve your email deliverability

DevFeed: [10+ best practices to improve your email deliverability](<https://devfeed.tech/articles/10-best-practices-to-improve-your-email-deliverability-16106.md>)

Original publisher: [Read original article](<https://www.twilio.com/en-us/blog/insights/8-best-practices-to-improve-your-email-deliverability>)

Author: Jesse Sumrak

Published: 2026-09-09T00:00:00Z

Content type: tutorial

Language: en

Sources: [Twilio Blog](<https://devfeed.tech/sources/twilio-blog.md>)

Topics: [email](<https://devfeed.tech/topics/email.md>), [SendGrid](<https://devfeed.tech/topics/sendgrid.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [best-practices](<https://devfeed.tech/tags/best-practices.md>), [deliverability](<https://devfeed.tech/tags/deliverability.md>), [domain](<https://devfeed.tech/tags/domain.md>), [email](<https://devfeed.tech/tags/email.md>), [industry-insights](<https://devfeed.tech/tags/industry-insights.md>), [marketing](<https://devfeed.tech/tags/marketing.md>), [sendgrid](<https://devfeed.tech/tags/sendgrid.md>), [spam](<https://devfeed.tech/tags/spam.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [subscriber](<https://devfeed.tech/tags/subscriber.md>)

### AI overview

This tutorial explains email deliverability and presents more than ten practices for improving inbox placement, including domain authentication, double opt-in, non-spammy subject lines, list cleaning, and avoiding spam traps. It also distinguishes delivery from deliverability and discusses sender reputation and subscriber engagement.

### Source excerpt

Email deliverability determines whether your messages reach inboxes or spam folders. Follow these 10+ best practices to improve your deliverability rates.

## The day after the zero-days

DevFeed: [The day after the zero-days](<https://devfeed.tech/articles/the-day-after-the-zero-days-10852.md>)

Original publisher: [Read original article](<https://blog.apnic.net/2026/08/28/the-day-after-the-zero-days/>)

Author: Niels Provos

Published: 2026-08-28T04:42:57Z

Content type: opinion

Language: en

Sources: [APNIC Blog](<https://devfeed.tech/sources/apnic-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Orchestration](<https://devfeed.tech/topics/orchestration.md>), [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Code](<https://devfeed.tech/topics/code.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [anthropic](<https://devfeed.tech/topics/anthropic.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Frontier Model](<https://devfeed.tech/topics/frontier-model.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [ai](<https://devfeed.tech/tags/ai.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [guest-post](<https://devfeed.tech/tags/guest-post.md>), [model](<https://devfeed.tech/tags/model.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [tech-matters](<https://devfeed.tech/tags/tech-matters.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

### AI overview

The article reflects on three decades of vulnerability research, contrasting a historically manual TCP source-routing spoofing discovery with an AI-assisted discovery of a long-standing OpenBSD kernel bug. It argues that vulnerability discovery is primarily an orchestration problem, demonstrates the capability with the open-source IronCurtain framework and several language models, and warns that defenders and attackers should assume capability parity.

### Source excerpt

Guest Post: Patching faster cannot keep up with AI-driven discovery. Leverage structural invariants to make bug classes irrelevant.

## Time: The cornerstone of digital sovereignty and independence

DevFeed: [Time: The cornerstone of digital sovereignty and independence](<https://devfeed.tech/articles/time-the-cornerstone-of-digital-sovereignty-and-independence-10840.md>)

Original publisher: [Read original article](<https://blog.apnic.net/2026/08/18/time-the-cornerstone-of-digital-sovereignty-and-independence/>)

Author: Luca Cicchelli

Published: 2026-08-18T01:45:10Z

Content type: article

Language: en

Sources: [APNIC Blog](<https://devfeed.tech/sources/apnic-blog.md>)

Topics: [digital sovereignty](<https://devfeed.tech/topics/digital-sovereignty.md>), [systems](<https://devfeed.tech/topics/systems.md>), [1.1.1.1](<https://devfeed.tech/topics/1-1-1-1.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [5G](<https://devfeed.tech/topics/5g.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [5g](<https://devfeed.tech/tags/5g.md>), [ai](<https://devfeed.tech/tags/ai.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [digital-sovereignty](<https://devfeed.tech/tags/digital-sovereignty.md>), [energy](<https://devfeed.tech/tags/energy.md>), [gnss](<https://devfeed.tech/tags/gnss.md>), [guest-post](<https://devfeed.tech/tags/guest-post.md>), [ixps](<https://devfeed.tech/tags/ixps.md>), [operational](<https://devfeed.tech/tags/operational.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [systems](<https://devfeed.tech/tags/systems.md>), [tech-matters](<https://devfeed.tech/tags/tech-matters.md>), [time](<https://devfeed.tech/tags/time.md>)

### AI overview

Time is presented as a foundational requirement for digital sovereignty and independent operation. The article explains how synchronized time supports telecommunications, finance, energy, cloud and AI systems, and transport, while dependence on GNSS introduces risks from interference, jamming, and spoofing.

### Source excerpt

Guest Post: Though often overlooked, time underpins telecommunications, finance, energy, cloud, AI, and transport systems. As dependence on GNSS increases, organizations need resilient, traceable time sources to strengthen cybersecurity, improve operational continuity, and support digital sovereignty.

## Kimwolf v7: An Evolution of the Kimwolf Botnet

DevFeed: [Kimwolf v7: An Evolution of the Kimwolf Botnet](<https://devfeed.tech/articles/kimwolf-v7-an-evolution-of-the-kimwolf-botnet-7752.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/>)

Author: Asher Davila, Chris Navarrete and Doel Santos

Published: 2026-08-11T10:00:16Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [Kimwolf v7](<https://devfeed.tech/topics/kimwolf-v7.md>), [Android](<https://devfeed.tech/topics/android.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Internet of things](<https://devfeed.tech/topics/iot.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Ethereum Name Service (ENS)](<https://devfeed.tech/topics/ens.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [Blockchain](<https://devfeed.tech/topics/blockchain.md>), [Routing (disambiguation)](<https://devfeed.tech/topics/routing.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [android-apk](<https://devfeed.tech/tags/android-apk.md>), [blockchain](<https://devfeed.tech/tags/blockchain.md>), [c2](<https://devfeed.tech/tags/c2.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [devices](<https://devfeed.tech/tags/devices.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [http](<https://devfeed.tech/tags/http.md>), [iot-botnets](<https://devfeed.tech/tags/iot-botnets.md>), [kimwolf-v7](<https://devfeed.tech/tags/kimwolf-v7.md>), [linux](<https://devfeed.tech/tags/linux.md>), [malware](<https://devfeed.tech/tags/malware.md>), [network](<https://devfeed.tech/tags/network.md>), [networks](<https://devfeed.tech/tags/networks.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [routing](<https://devfeed.tech/tags/routing.md>), [rpc](<https://devfeed.tech/tags/rpc.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>)

### AI overview

Kimwolf v7 is an Android and IoT botnet variant that adds HTTP/2-based DDoS flooding with browser fingerprinting, Ethereum Name Service resolution for C2 addresses, and Tor-backed routing to improve infrastructure resilience. The article also describes its targeting of Android TV devices and exploitation of unauthenticated ADB instances.

### Source excerpt

Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared first on Unit 42.

## Inside an AI coal mine security camera network powered by plaintext passwords

DevFeed: [Inside an AI coal mine security camera network powered by plaintext passwords](<https://devfeed.tech/articles/inside-an-ai-coal-mine-security-camera-network-powered-by-plaintext-passwords-32622.md>)

Original publisher: [Read original article](<https://eaton-works.com/2026/07/08/coal-india-camera-hack/>)

Author: Eaton

Published: 2026-07-08T17:07:38Z

Content type: opinion

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [API](<https://devfeed.tech/topics/api.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [breach](<https://devfeed.tech/tags/breach.md>), [browser](<https://devfeed.tech/tags/browser.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [security](<https://devfeed.tech/tags/security.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This security write-up examines Coal India's Project DigiCoal camera-monitoring platform, developed by DeepSight AI Labs and Accenture. It reports that the RPI Dashboard exposed user accounts and plaintext, weak, duplicated passwords through an unauthenticated API. The article also describes bypassing client-side access controls to view camera alerts and feeds across seven coal mines.

### Source excerpt

Coal India's intelligent CCTV platform developed by DeepSight AI Labs and Accenture had plaintext passwords and no API authentication.

## What's New in Android Security and Privacy in 2026

DevFeed: [What's New in Android Security and Privacy in 2026](<https://devfeed.tech/articles/what-s-new-in-android-security-and-privacy-in-2026-7635.md>)

Original publisher: [Read original article](<https://blog.google/security/whats-new-in-android-security-privacy-2026/>)

Author: Eugene Liderman

Published: 2026-05-12T17:00:00Z

Content type: article

Language: en

Sources: [Security](<https://devfeed.tech/sources/security.md>)

Topics: [Android](<https://devfeed.tech/topics/android.md>), [Android Security](<https://devfeed.tech/topics/android-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [On-device AI](<https://devfeed.tech/topics/on-device-ai.md>), [Chrome](<https://devfeed.tech/topics/chrome.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [android](<https://devfeed.tech/tags/android.md>), [android-security](<https://devfeed.tech/tags/android-security.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [none](<https://devfeed.tech/tags/none.md>), [on-device-ai](<https://devfeed.tech/tags/on-device-ai.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

The article describes planned Android security and privacy enhancements for 2026, including verified financial calls to combat spoofed banking scams. Android can verify incoming calls through participating financial apps and automatically end calls that are not genuine. It also highlights expanded Live Threat Detection, which uses on-device AI to analyze app behavior and warn about suspicious activity.

### Source excerpt

New Android security and privacy features

## A cunning predator: How Silver Fox preys on Japanese firms this tax season

DevFeed: [A cunning predator: How Silver Fox preys on Japanese firms this tax season](<https://devfeed.tech/articles/a-cunning-predator-how-silver-fox-preys-on-japanese-firms-this-tax-season-8328.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/cunning-predator-how-silver-fox-preys-japanese-firms-tax-season/>)

Author: Dominik Breitenbacher Takahiro Sajima

Published: 2026-03-27T07:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [business](<https://devfeed.tech/tags/business.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [finance](<https://devfeed.tech/tags/finance.md>), [government](<https://devfeed.tech/tags/government.md>), [japan](<https://devfeed.tech/tags/japan.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>)

### AI overview

Silver Fox is conducting a targeted spearphishing campaign against Japanese manufacturers and other businesses during tax-filing and organizational-change season. The attackers use convincing tax- and HR-themed emails, links, and attachments to exploit expected business communications and increase the likelihood of compromise.

### Source excerpt

Silver Fox is back in Japan, spoofing tax and HR emails timed to the one season when no one thinks twice about opening them

## Taxing times: Top IRS scams to look out for in 2026

DevFeed: [Taxing times: Top IRS scams to look out for in 2026](<https://devfeed.tech/articles/taxing-times-top-irs-scams-to-look-out-for-in-2026-8411.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/scams/taxing-times-top-irs-scams-look-out-2026/>)

Author: Phil Muncaster

Published: 2026-02-10T10:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [malware](<https://devfeed.tech/tags/malware.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [scams](<https://devfeed.tech/tags/scams.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [tax](<https://devfeed.tech/tags/tax.md>), [tax-return](<https://devfeed.tech/tags/tax-return.md>)

### AI overview

The article outlines common IRS and tax-return scams, including impersonation through phone, email, text, and social media; demands for urgent payment; requests for personal or financial information; fraudulent refund claims; and attempts to deliver malware. It also warns that AI-assisted scams can make deceptive messages and calls harder to recognize.

### Source excerpt

It's time to file your tax return. And cybercriminals are lurking to make an already stressful period even more edgy.

## Drowning in spam or scam emails? Here's probably why

DevFeed: [Drowning in spam or scam emails? Here's probably why](<https://devfeed.tech/articles/drowning-in-spam-or-scam-emails-here-s-probably-why-8351.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/cybersecurity/drowning-spam-scam-emails-why/>)

Author: Phil Muncaster

Published: 2026-01-27T10:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [obfuscation](<https://devfeed.tech/topics/obfuscation.md>), [pii](<https://devfeed.tech/topics/pii.md>), [data](<https://devfeed.tech/topics/data.md>), [Internet](<https://devfeed.tech/topics/internet.md>), [Netflix](<https://devfeed.tech/topics/netflix.md>)

Tags: [cybercrime](<https://devfeed.tech/tags/cybercrime.md>), [data](<https://devfeed.tech/tags/data.md>), [digital-security](<https://devfeed.tech/tags/digital-security.md>), [internet](<https://devfeed.tech/tags/internet.md>), [malware](<https://devfeed.tech/tags/malware.md>), [obfuscation](<https://devfeed.tech/tags/obfuscation.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [pii](<https://devfeed.tech/tags/pii.md>), [scam](<https://devfeed.tech/tags/scam.md>), [security](<https://devfeed.tech/tags/security.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>)

### AI overview

This article explains why inboxes can suddenly be flooded with spam and scam emails. It identifies data breaches, leaked personal information, updated phishing kits, spam-filter bypasses, and targeted campaigns as possible causes, and describes risks including credential theft, financial fraud, and malware installation.

### Source excerpt

Has your inbox recently been deluged with unwanted and even outright malicious messages? Here are 10 possible reasons - and how to stem the tide.

## Postfix on Kubernetes: A Step-by-Step Email Guide

DevFeed: [Postfix on Kubernetes: A Step-by-Step Email Guide](<https://devfeed.tech/articles/postfix-on-kubernetes-a-step-by-step-email-guide-28524.md>)

Original publisher: [Read original article](<https://blog.risingstack.com/postfix-on-kubernetes-a-step-by-step-email-guide/>)

Author: RisingStack Engineering

Published: 2025-09-25T04:12:00Z

Content type: tutorial

Language: en

Sources: [RisingStack](<https://devfeed.tech/sources/risingstack.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [email](<https://devfeed.tech/topics/email.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [email](<https://devfeed.tech/tags/email.md>), [guide](<https://devfeed.tech/tags/guide.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [postfix](<https://devfeed.tech/tags/postfix.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>)

### AI overview

A step-by-step guide to running a Postfix email server on Kubernetes. It explains the infrastructure and email-authentication requirements, including a fixed outbound IP address, a domain, PTR and SPF records, and DKIM and DMARC configuration.

### Source excerpt

You are in the process of putting together your application. While designing your authorization solution, you realize you will need to send emails to potential clients.Using a third-party service (like SendGrid or Mailgun) to cover your needs for now looks pretty attractive. After all, you don't have any users yet, they offer free tiers, and [...] The post Postfix on Kubernetes: A Step-by-Step Email Guide appeared first on RisingStack Engineering.

## Types of VoIP Hacking and Countermeasures

DevFeed: [Types of VoIP Hacking and Countermeasures](<https://devfeed.tech/articles/types-of-voip-hacking-and-countermeasures-4510.md>)

Original publisher: [Read original article](<https://feeds.feedblitz.com/~/923262890/0/baeldung/cs>)

Author: Georgios Nanos

Published: 2025-08-15T02:31:46Z

Content type: tutorial

Language: en

Sources: [Baeldung - CS](<https://devfeed.tech/sources/baeldung-cs.md>)

Topics: [Security Attacks](<https://devfeed.tech/topics/security-attacks.md>), [Security](<https://devfeed.tech/topics/security.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>), [Networks](<https://devfeed.tech/topics/networks.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Internet](<https://devfeed.tech/topics/internet.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [ip](<https://devfeed.tech/tags/ip.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [rtp](<https://devfeed.tech/tags/rtp.md>), [security](<https://devfeed.tech/tags/security.md>), [security-attacks](<https://devfeed.tech/tags/security-attacks.md>), [security-security-attacks](<https://devfeed.tech/tags/security-security-attacks.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [voice](<https://devfeed.tech/tags/voice.md>)

### AI overview

This tutorial explains how Voice over Internet Protocol (VoIP) carries digitized voice as data packets and examines common attacks against VoIP systems, including eavesdropping and SIP registration hijacking. It also discusses risks such as packet interception, identity spoofing, service disruption, and exposure of unencrypted signaling and audio traffic, while outlining the need for encryption, authentication, and monitoring.

### Source excerpt

Learn about security attacks and measures regarding the Voice-over-IP technology. The post Types of VoIP Hacking and Countermeasures first appeared on Baeldung on Computer Science. Related Stories Introduction to Differential Privacy in Deep Learning Models What Is CSRF? Network Time Protocol: Security and Authentication

## IBGP Source Interface Selection Still Requires Configuration

DevFeed: [IBGP Source Interface Selection Still Requires Configuration](<https://devfeed.tech/articles/ibgp-source-interface-selection-still-requires-configuration-11104.md>)

Original publisher: [Read original article](<https://blog.ipspace.net/2024/12/ibgp-source-interface-trivia/>)

Published: 2024-12-10T07:32:00Z

Content type: article

Language: en

Sources: [ipSpace.net blog](<https://devfeed.tech/sources/ipspace-net-blog.md>)

Topics: [BGP](<https://devfeed.tech/topics/bgp.md>), [networking](<https://devfeed.tech/topics/networking.md>), [configuration](<https://devfeed.tech/topics/configuration.md>)

Tags: [bgp](<https://devfeed.tech/tags/bgp.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [ip](<https://devfeed.tech/tags/ip.md>), [networking](<https://devfeed.tech/tags/networking.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [tcp](<https://devfeed.tech/tags/tcp.md>)

### AI overview

The article explains that FRRouting does not automatically select the correct source interface for IBGP sessions. Because BGP runs over TCP and IBGP commonly uses loopback addresses, the router must be configured to send TCP SYN packets with the appropriate loopback source address.

### Source excerpt

A fellow networking engineer recently remarked, "FRRouting automatically selects the correct [IBGP] source interface even when not configured explicitly." TL&DR: No, it does not. You were just lucky. Basics first1. BGP runs over TCP sessions. One of the first things a router does when establishing a BGP session with a configured neighbor is to open a TCP session with the configured neighbor's IP address. Read more ...

## Homographic Spoofing: a new Ruby toolkit

DevFeed: [Homographic Spoofing: a new Ruby toolkit](<https://devfeed.tech/articles/homographic-spoofing-a-new-ruby-toolkit-33502.md>)

Original publisher: [Read original article](<https://dev.37signals.com/homographic-spoofing/>)

Author: Jacopo Beschi

Published: 2024-06-25T17:00:00Z

Content type: tutorial

Language: en

Sources: [37signals Dev](<https://devfeed.tech/sources/37signals-dev.md>)

Topics: [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Ruby](<https://devfeed.tech/topics/ruby.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [email](<https://devfeed.tech/topics/email.md>), [domain](<https://devfeed.tech/topics/domain.md>), [ASCII](<https://devfeed.tech/topics/ascii.md>)

Tags: [ascii](<https://devfeed.tech/tags/ascii.md>), [domain](<https://devfeed.tech/tags/domain.md>), [email](<https://devfeed.tech/tags/email.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [ruby](<https://devfeed.tech/tags/ruby.md>), [security](<https://devfeed.tech/tags/security.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>)

### AI overview

This article explains homograph attacks, in which visually similar Unicode characters are used to spoof identities in domains or email. It describes browser and email-client protections using Punycode and UTS #39, then introduces an open-source Ruby gem implementing those guidelines for IDNs and email addresses.

### Source excerpt

What is a homograph attack and how to protect from it with a new gem.

## How to install dnscrypt-proxy on Debian Linux 11/12

DevFeed: [How to install dnscrypt-proxy on Debian Linux 11/12](<https://devfeed.tech/articles/how-to-install-dnscrypt-proxy-on-debian-linux-11-12-41934.md>)

Original publisher: [Read original article](<https://www.cyberciti.biz/faq/installing-dnscrypt-proxy-on-debian-linux/>)

Author: Vivek Gite

Published: 2024-05-13T12:23:14Z

Content type: tutorial

Language: en

Sources: [nixCraft: Linux Tips, Hacks, Tutorials, And Ideas In Blog Format (RSS/FEED)](<https://devfeed.tech/sources/nixcraft-linux-tips-hacks-tutorials-and-ideas-in-blog-format-rss-feed.md>)

Topics: [Debian](<https://devfeed.tech/topics/debian.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Security](<https://devfeed.tech/topics/security.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [free software](<https://devfeed.tech/topics/free-software.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [systemd](<https://devfeed.tech/topics/systemd.md>), [Virtual Private Network](<https://devfeed.tech/topics/vpn.md>)

Tags: [configuration](<https://devfeed.tech/tags/configuration.md>), [debian-linux](<https://devfeed.tech/tags/debian-linux.md>), [dns](<https://devfeed.tech/tags/dns.md>), [dnscrypt-proxy](<https://devfeed.tech/tags/dnscrypt-proxy.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [install](<https://devfeed.tech/tags/install.md>), [intermediate](<https://devfeed.tech/tags/intermediate.md>), [ipv4](<https://devfeed.tech/tags/ipv4.md>), [ipv6](<https://devfeed.tech/tags/ipv6.md>), [linux](<https://devfeed.tech/tags/linux.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>)

### AI overview

A tutorial for installing and configuring dnscrypt-proxy on Debian Linux 11 and 12. It covers package installation, systemd service management, socket binding for IPv4 and IPv6 addresses, and verification of the DNS service.

### Source excerpt

DNSCrypt-proxy is an open-source and free software designed to encrypt DNS traffic, thus protecting it from eavesdropping and manipulation. This is also useful to evade DNS censorship when DNSCrypt-proxy is configured correctly with Wireguard or OpenVPN. Further, DNSCrypt-proxy can configured to block malware, trackers, and internet ads. In Debian 11 and 12, using DNSCrypt-proxy can enhance privacy and security by preventing DNS spoofing attacks, DNS hijacking, and surveillance of DNS traffic. It ensures that DNS queries are encrypted, authenticated, and secure, thereby safeguarding users' browsing activities and sensitive information. Let us see how to install dnscrypt-proxy on Debian Linux 11 and 12. Love this? sudo share_on: Twitter - Facebook - LinkedIn - Whatsapp - Reddit The post How to install dnscrypt-proxy on Debian Linux 11/12 appeared first on nixCraft.

## Port Scan with Spoofed IP Addresses

DevFeed: [Port Scan with Spoofed IP Addresses](<https://devfeed.tech/articles/port-scan-with-spoofed-ip-addresses-30831.md>)

Original publisher: [Read original article](<https://hookrace.net/blog/port-scan-with-spoofed-ip-addresses/>)

Published: 2024-03-18T23:00:00Z

Content type: opinion

Language: en

Sources: [Dennis Felsing](<https://devfeed.tech/sources/dennis-felsing.md>)

Topics: [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [networking](<https://devfeed.tech/topics/networking.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [game-servers](<https://devfeed.tech/tags/game-servers.md>), [incident](<https://devfeed.tech/tags/incident.md>), [network](<https://devfeed.tech/tags/network.md>), [networking](<https://devfeed.tech/tags/networking.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>)

### AI overview

The article describes how spoofed-source port scans can cause abuse reports to be misattributed to a victim's VPS, potentially leading a hoster to suspend or terminate the server. It presents the scenario in a satirical, adversarial tone and discusses defensive traffic-blocking measures.

### Source excerpt

Or how to make naïve hosters shut down your victim's server. Do you want to bring down your victim's game servers? Do they host their game servers on cheap VPSes at hosters who are not that experienced with networking? Is running an actual DoS against the server too expensive and illegal for you? Just grab a server for yourself from a questionable hoster with IP address spoofing allowed on their network. Next run a port scan using nmap (man page) with a spoofed source address (-S or -D for multiple decoys) using your victim's IP address(es). As the target of the port scan choose a university with a cybersecurity department that likes to send security incident reports to abuse mail addresses. To the target university of the port scan it will look like the scan came from your victim, since you are spoofing their IP address, so they will send a serious sounding email to the victim's hoster: As a consequence your victim's VPS will most likely be shut down for a few hours or even days. To prevent this your victim will try to block all of their incoming and outgoing TCP traffic on their VPS, and also block the reporting university's IP range entirely: $ iptables -L Chain INPUT (policy ACCEPT) target prot opt source destination DROP all -- 147.251.0.0/16 anywhere DROP tcp -- anywhere anywhere tcp ctstate NEW multiport dports !27685,6546,ssh Chain OUTPUT (policy ACCEPT) target prot opt source destination DROP all -- anywhere 147.251.0.0/16 And yet you can rerun your port scan against the university's network every day, which will trigger automatic abuse mails to the victim's hoster, who will still trust these abuse mails more than the victim, since the hoster is unlikely to be able to monitor the network traffic of the VPS to check if those packets actually originated there. At some point the hoster will be so annoyed that they simply terminate the VPS and throw out the customer, victory! Congratulations, you have brought down some small-fish game servers in the DDNet commu

## Reflecting on Threats: The Frame

DevFeed: [Reflecting on Threats: The Frame](<https://devfeed.tech/articles/reflecting-on-threats-the-frame-36953.md>)

Original publisher: [Read original article](<https://shostack.org/blog/reflecting-on-threats-the-frame/>)

Author: Adam

Published: 2023-04-10T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [systems](<https://devfeed.tech/topics/systems.md>), [standard](<https://devfeed.tech/topics/standard.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [bug](<https://devfeed.tech/topics/bug.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [YAML](<https://devfeed.tech/topics/yaml.md>)

Tags: [bug](<https://devfeed.tech/tags/bug.md>), [code](<https://devfeed.tech/tags/code.md>), [password](<https://devfeed.tech/tags/password.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [standard](<https://devfeed.tech/tags/standard.md>), [yaml](<https://devfeed.tech/tags/yaml.md>)

### AI overview

The author reflects on how the framing and subtitle of the Threats book shaped its content. The article discusses the value of shared engineering terminology and argues that common understandings, standards, and available tools can support more consistent threat assessment and evaluation of software flaws.

### Source excerpt

Reflecting on the framing of the Threats book

## Threats Book is Complete

DevFeed: [Threats Book is Complete](<https://devfeed.tech/articles/threats-book-is-complete-37059.md>)

Original publisher: [Read original article](<https://shostack.org/blog/threats-books-complete/>)

Author: Adam

Published: 2023-01-17T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [Parser](<https://devfeed.tech/topics/parser.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>)

Tags: [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [parsing](<https://devfeed.tech/tags/parsing.md>), [security](<https://devfeed.tech/tags/security.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>)

### AI overview

The author announces that Threats Book is complete and explains its serious focus on helping readers understand security threats. The book covers STRIDE, predictability and randomness, parsing and corruption, and kill chains, including a redefinition of the "E" in STRIDE as Expansion of Authority.

### Source excerpt

The serious side of the book

## Threats: The Table of Contents

DevFeed: [Threats: The Table of Contents](<https://devfeed.tech/articles/threats-the-table-of-contents-37062.md>)

Original publisher: [Read original article](<https://shostack.org/blog/threats-table-of-contents/>)

Author: Adam

Published: 2023-01-16T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [spoofing](<https://devfeed.tech/topics/spoofing.md>)

Tags: [books](<https://devfeed.tech/tags/books.md>), [contents](<https://devfeed.tech/tags/contents.md>), [guide](<https://devfeed.tech/tags/guide.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [table](<https://devfeed.tech/tags/table.md>)

### AI overview

The article presents the table of contents for Threats: What Every Engineer Should Learn From Star Wars. It explains that the book covers threats such as spoofing and authenticity, with each chapter organized around the threat, mechanisms, scenarios or technologies, and defenses. The book is announced as available for preorder and sale on January 25th.

### Source excerpt

Like the Force, each threat has a light side, and a dark side.

## GPT-3

DevFeed: [GPT-3](<https://devfeed.tech/articles/gpt-3-36812.md>)

Original publisher: [Read original article](<https://shostack.org/blog/gpt-3-threat-modeling/>)

Author: Adam

Published: 2022-12-09T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>), [Library](<https://devfeed.tech/topics/library.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Back end](<https://devfeed.tech/topics/backend.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [backend](<https://devfeed.tech/tags/backend.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [client](<https://devfeed.tech/tags/client.md>), [gpt](<https://devfeed.tech/tags/gpt.md>), [gpt-3](<https://devfeed.tech/tags/gpt-3.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [libraries](<https://devfeed.tech/tags/libraries.md>), [library](<https://devfeed.tech/tags/library.md>), [service](<https://devfeed.tech/tags/service.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>)

### AI overview

The article reports that GPT-3 was used to generate sample STRIDE threat libraries for backend-to-backend services in Kubernetes and client-side threats. It notes that the output may be imperfect and requires human judgment.

### Source excerpt

Text captured from GPT-3

## The Threats book is complete

DevFeed: [The Threats book is complete](<https://devfeed.tech/articles/the-threats-book-is-complete-37057.md>)

Original publisher: [Read original article](<https://shostack.org/blog/threats-announce/>)

Author: Adam

Published: 2022-12-08T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Parsing](<https://devfeed.tech/topics/parsing.md>), [Computing](<https://devfeed.tech/topics/computing.md>)

Tags: [book](<https://devfeed.tech/tags/book.md>), [complete](<https://devfeed.tech/tags/complete.md>), [parsing](<https://devfeed.tech/tags/parsing.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [security](<https://devfeed.tech/tags/security.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>)

### AI overview

The author announces that the Threats book is complete and describes its goal of making security and threat concepts accessible to engineers who are not security specialists. The article discusses topics including privilege, permissions, safe parsing, and STRIDE-related spoofing examples.

### Source excerpt

Threats is almost in bookstores

## Update on DoS Attacks against our Online Game

DevFeed: [Update on DoS Attacks against our Online Game](<https://devfeed.tech/articles/update-on-dos-attacks-against-our-online-game-30814.md>)

Original publisher: [Read original article](<https://hookrace.net/blog/dos-attacks-update/>)

Published: 2022-05-15T22:00:00Z

Content type: article

Language: en

Sources: [Dennis Felsing](<https://devfeed.tech/sources/dennis-felsing.md>)

Topics: [spoofing](<https://devfeed.tech/topics/spoofing.md>), [servers](<https://devfeed.tech/topics/servers.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>), [client](<https://devfeed.tech/topics/client.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [https](<https://devfeed.tech/tags/https.md>), [ipv4](<https://devfeed.tech/tags/ipv4.md>), [ipv6](<https://devfeed.tech/tags/ipv6.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [server](<https://devfeed.tech/tags/server.md>), [servers](<https://devfeed.tech/tags/servers.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [udp](<https://devfeed.tech/tags/udp.md>)

### AI overview

This update describes ongoing DoS attacks against the open-source DDraceNetwork online game. It explains how spoofed UDP connection attempts overload single-threaded game servers and outlines an HTTPS-based IP whitelist, along with limitations involving capacity, IPv4, IPv6, and ISP address translation.

### Source excerpt

In my previous post 8 months ago I described how our open source online game DDraceNetwork has been suffering under DoS attacks for about 8 years, basically since its inception. Recently the attacks have gotten much worse, forcing us to work on further approaches. Since many players made suggestions recently, I'm writing this blog post to summarize what we are attempting and to ask for help again. These traffic graphs are from two of the servers we are running, note the logarithmic x-axis. Each spike represents an incoming DoS attack, as you can see some of them last for nearly a day. Recently the attacks have been relatively weak in terms of incoming bandwidth, using spoofed IP addresses imitating our UDP-based connection process. At first the CPU gets overloaded since the server suddenly has to try and handle hundreds of thousands of connection attempts per second. Since our game servers are mostly running on cheap VPSes and each game server runs single-threaded, it is quite easy to overload a system in this manner. HTTPS-based Whitelist To prevent spoofing we collect all players' IP addresses and whitelist those. Since we also develop the game client, we can modify the client to connect to a server via HTTPs for this whitelisting. The iptables rules and ipset setup on the game servers for this whitelist look something like this: ipset create official iphash ipset create whitelist-ip iphash iptables -N serverinfo iptables -A serverinfo -m hashlimit --hashlimit-above 40/s --hashlimit-mode dstport --hashlimit-name si_dstport -j DROP iptables -N game iptables -A game -m set --match-set official src -j ACCEPT iptables -A game -m set --match-set whitelist-ip src -m u32 --u32 "38=0x67696533" -j serverinfo iptables -A game -m set --match-set whitelist-ip src -m u32 --u32 "38=0x66737464" -j serverinfo iptables -A game -m set --match-set whitelist-ip src -j ACCEPT # Still allow non-whitelisted players when there is no attack iptables -A game -m limit --limit 10000 -j ACCEP

## GNSS Jamming and Spoofing, aka Galileo's Authentication Algorithm Part 3

DevFeed: [GNSS Jamming and Spoofing, aka Galileo's Authentication Algorithm Part 3](<https://devfeed.tech/articles/gnss-jamming-and-spoofing-aka-galileo-s-authentication-algorithm-part-3-36407.md>)

Original publisher: [Read original article](<https://berthub.eu/articles/posts/galileos-authentication-algorithm-part-3/>)

Published: 2020-09-13T09:49:53Z

Content type: tutorial

Language: en

Sources: [Bert Hubert's writings](<https://devfeed.tech/sources/bert-hubert-s-writings.md>)

Topics: [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>), [navigation](<https://devfeed.tech/topics/navigation.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>)

Tags: [aviation](<https://devfeed.tech/tags/aviation.md>), [gnss](<https://devfeed.tech/tags/gnss.md>), [gps](<https://devfeed.tech/tags/gps.md>), [navigation](<https://devfeed.tech/tags/navigation.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>)

### AI overview

Part 3 of a series on OSNMA, the proposed Galileo Navigation Message Authentication protocol, explaining GNSS jamming and spoofing, the threat model, and related detection and mitigation concerns.

### Source excerpt

Welcome to part 3 of my series on OSNMA, the proposed Galileo Navigation Message Authentication protocol. This part can be read independently from part 1 and part 2, but it might be useful to read the introduction to part 1. This post attempts to explain GPS (GNSS) jamming and spoofing, so it might be a useful read even if you don't care about Galileo or its authentication. As usual, I've been helped tremendously by Daniel Estévez & many other researchers and Galileo professionals, and again I am very greatful for all the links, corrections, suggestions and knowledge you provided.

## Galileo's Proposed Authentication Algorithm: Part 1

DevFeed: [Galileo's Proposed Authentication Algorithm: Part 1](<https://devfeed.tech/articles/galileo-s-proposed-authentication-algorithm-part-1-36405.md>)

Original publisher: [Read original article](<https://berthub.eu/articles/posts/galileos-authentication-algorithm-part-1/>)

Published: 2020-08-13T18:50:09Z

Content type: article

Language: en

Sources: [Bert Hubert's writings](<https://devfeed.tech/sources/bert-hubert-s-writings.md>)

Topics: [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>), [integrity](<https://devfeed.tech/topics/integrity.md>), [Provable security](<https://devfeed.tech/topics/provable-security.md>), [Network](<https://devfeed.tech/topics/network.md>)

Tags: [cryptography](<https://devfeed.tech/tags/cryptography.md>), [gnss](<https://devfeed.tech/tags/gnss.md>), [receiver](<https://devfeed.tech/tags/receiver.md>), [rf](<https://devfeed.tech/tags/rf.md>), [series](<https://devfeed.tech/tags/series.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>)

### AI overview

This first part of a series explains Galileo's proposed Open Service Navigation Message Authentication (OSNMA), focusing on the TESLA cryptographic scheme and its role in improving trust in GNSS messages. It notes that message authentication cannot by itself prevent sophisticated RF spoofing, but is an important step toward detecting unauthenticated or altered data.

### Source excerpt

Position, velocity and time (PVT) information can be a 'nice to have', but in other circumstances knowing place and time has legal or military importance as well. Heavy vehicles for example are typically outfitted with tachographs that track driver speed and/or location. This has importance for rest regulations, but also to check if loads are actually from where they say they are. Our Global Navigation Satellite Systems so far are broadcasting unauthenticated data, at least to civilian users.

[Next page](<https://devfeed.tech/tags/spoofing.md?cursor=WyIyMDIwLTA4LTEzVDE4OjUwOjA5KzAwOjAwIiwgIjI2ZTQ2MDk3LWU4NzMtNDgxZC1hMWI5LTEyN2ZlMDE0NThlYiJd>)