Keeping you and your family safe online is a top priority at YouTube. Today on Safer Internet Day, we’re sharing some of the ways we work to keep YouTube safe, and how you can be more in control of your YouTube experience. From built-in protections to …
The YouTube AdBlitz Champion of 2020 is…
The confetti may have hit the field for the Kansas City Chiefs, but the Big Game isn’t over for the ads. Fans have been watching and re-watching their favorites from in-and-out of the game on YouTube AdBlitz, and it’s finally time to reveal our top fiv…
State of the Union 2020: Live on YouTube
From breaking news to key moments, people around the world have been able to access important content and news through YouTube. As President Trump begins his fourth year in office, YouTube continues this tradition. Like we have in the past, YouTube wil…
How YouTube supports elections
As the 2020 election season kicks into high gear in the United States, people will visit YouTube to learn about the candidates and watch the election season unfold. Over the last few years, we’ve increased our efforts to make YouTube a more reliable so…
YouTube Originals announces new documentary, “Coachella: 20 Years in the Desert." Premieres March 31.
In celebration of Coachella’s 20th anniversary, YouTube Originals is partnering with Coachella Valley Music and Arts Festival for a feature-length documentary, “Coachella: 20 Years in the Desert.” It is set to premiere March 31. The announcement comes …
Better protecting kids’ privacy on YouTube
Last September, we announced a series of changes to better protect kids and their privacy on YouTube and to address concerns raised by the U.S. Federal Trade Commission (FTC). Specifically, that all creators will be required to designate their content …
Mac Pro向けの新アクセサリのカラーは黒とシルバー
これまでずっと、Appleのキーボードとマウスの色は白とシルバーでの仕上げでした。しかし、iMac …
[mongoose] Improper Input Validation in Automattic Mongoose
Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype attribute is ignored. For example, adding “_bsontype”:”a” can sometimes interfere with a query filter. NOTE: th…
[netaddr] netaddr before 1.5.3 and 2.0.4 has Incorrect Default Permissions
The netaddr gem before 1.5.3 and 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 permissions in the target filesystem.
References
https://nvd.nist.gov/vuln/detail/CVE-2019-17383
https://github.com/dspinhir…
[org.apache.tapestry:tapestry-core] Timing attack on HMAC signature comparison in Apache Tapestry
The code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side channel for the comparison of the HMAC signatures. This could lead to remote code execution if an attacker is able to determine the corr…