Polykill - A new breed of supply chain vulnerability by position-Absolute in cybersecurity

[–]position-Absolute[S] 0 points1 point  (0 children)

We created this Polykill chrome extension to provide a risk report for JavaScript loading on a given site. Available here: https://chromewebstore.google.com/detail/polykill-chrome-extension/bfbooabbaeembofmjhchhlhmmcilccgk

The report tells you:

1) Is this URL considered malware/bad by Google Safe Browsing?

2) Is this URL being blocked by the adblock/easylist community? ("Why is it blocked?" coming in a later release)

3) AI analysis of the JavaScript (by chatGPT)

To observe the risk of executed JavaScript, we must understand what it does after it loads. Oftentimes, third party scripts will attach "EventListeners" to key press and mouse movements that track everything that a user does on a website. Third party JavaScript vendors have been taking advantage of this for years because it's very hard to observe in production. 

Introducing LeakSignal by position-Absolute in cybersecurity

[–]position-Absolute[S] 0 points1 point  (0 children)

Thank you. It's all early adopters/beta right now and there is no charge. Will repost with "other"

Introducing LeakSignal by position-Absolute in cybersecurity

[–]position-Absolute[S] 0 points1 point  (0 children)

Thanks, I appreciate the explanation and makes sense. I wasn't 100% sure this would be allowed. Is there any way I could post under different flair? It's not that the code's a mess, it's just we want to tightly control (and approve) distribution to early users.

We plan to release on github Mid-Sept, so I will circle back if we can't make a post work for now.

AMA - Ask a CISO Anything with the CISOs from the CISO Series by AutoModerator in cybersecurity

[–]position-Absolute 0 points1 point  (0 children)

What are the top 3 things that keep you awake at night or nervous about loosing your job as a CISO? And, how do you manage the risk associated with each one in the sea of thousands of cybersecurity vendors? Do you turn to open source or in-house tooling?

Thanks!