The Vulnerability Sitting in Front of Government Websites
In early August, in a sublet apartment on the eighth floor of a high-rise in central Tel Aviv, Aviv Yahav, a vulnerability researcher, opened a debugger and watched a memory address filled with zeros where it should have held a cryptographic secret. The affected system was a Fortinet FortiWeb appliance, a web application firewall deployed by thousands of organizations across the public and private sectors. The missing bytes were the secret used to derive session keys for authenticated user sessions.