chiefgyk3d, (edited ) to random
@chiefgyk3d@social.chiefgyk3d.com avatar

I’m very close to finishing my personal laptop which is using @QubesOS on my @purism Librem 14. I just have to rotate passwords and setup my @bitwarden and @protonprivacy email and password manager. I even have @yubico for most of my TOTP. Need to sync Monero, login to various account and move my passwords from KeePassXC and I plan to keep my work, personal, and TOTP in separate systems.

#infosec

percepticon, to Cybersecurity
@percepticon@ioc.exchange avatar
percepticon, to Cybersecurity
@percepticon@ioc.exchange avatar
redqueen, to Cybersecurity

We're looking for a junior web developer in Rust or Python. This opening is ideal for mid-career folks transitioning to infosec (including bootcamp grads), someone looking for an entry-level role, or as an internship.

We make a B2B SaaS security/compliance tool which helps managed service providers protect & support their small business clients.

Remote, US-only. Equal-opportunity employer. Please read the job description carefully. No robots: humans only. www.redqueendynamics.com/careers

Rairii, to infosec

let's smash the brittle glass that is windows boot security again!

Introducing dubious disk (CVE-2022-30203, CVE-2023-21560, CVE-2023-28269, CVE-2023-28249, and more...), the Porygon-Z that's super effective against Secure Boot!

Writeup with exploitro is linked above (came third in Field-FX 2024 Wild compo!).

Exploiting this bug leads to code execution in the context of a boot application, which defeats Secure Boot, BitLocker on the OS partition (code execution is obtained either at a point where the payload can still derive keys via TPM, or when the derived keys are in memory), and measured boot (code execution is obtained before the running boot application really measures much of anything to TPM PCRs).

Microsoft has to this point taken over two years and five attempts to fix this issue.

percepticon, to Cybersecurity
@percepticon@ioc.exchange avatar
chiefgyk3d, to infosec
@chiefgyk3d@social.chiefgyk3d.com avatar

So tomorrow is going to suck I need upgrade my PfSense firewall and apparently there is a bug that requires a reinstall to get it fixed as the partition was too small. Then I can get around to setting up @protonprivacy and @bitwarden but I am keeping @keepassxc for the TOTP MFA, because I don’t want to store those in the same password manager. Also rotating all passwords and setting up new Yubikeys then migrating from Ledger to Trezor

Flipboard, (edited ) to fediverse
@Flipboard@flipboard.social avatar

It’s #NewstodonFriday! It’s been another busy week for the many newsrooms who have an active presence in the #fediverse, and we’re highlighting their work in the thread below. If you like what you see, follow the profiles and boost their stories.

If you’re a journo or newsroom that we don’t know about or if there’s a newsroom you’d love to put on our radar, please let us know in the comments.
⤵️

#News #Newstodon #Media #Journalism #FollowFriday

Flipboard, (edited )
@Flipboard@flipboard.social avatar

@josephcox has written a book, “Dark Wire,” about an encrypted messaging service app called Anom, which is used by drug traffickers but was infiltrated by the FBI and Australian Federal Police (AFP). @404mediaco has published this extract about how a kidnapping was both planned and foiled on Anom.

https://flip.it/pVx8Wm

#Technology #Encryption #InfoSec #Media @bookstodon #NewstodonFriday #Newstodon

shellsharks, to infosec
@shellsharks@shellsharks.social avatar

The return of #infosec / #cybersecurity #followfriday! Some great accounts I've discovered from the past week ⬇️

  • @m19o
  • @scottarc.blog@scottarc.blog
  • @pulls
  • @webjedi

...and my regularly recurring segment on folks from neat instances across the Fediverse :fediverse: …

Drop 'em all a follow!

chiefgyk3d, to Twitch
@chiefgyk3d@social.chiefgyk3d.com avatar

It took some tinkering but got @QubesOS reinstalled during my #Twitch stream on my @purism Librem 14. Had to rework some of the steps based off documentation to get the #Monero with wallet isolation going. Basically grabbed the tar ball and extracted it to a folder in the template Qube and then had the systemd run that. VPN is setup with @mullvadnet and I am loving the GUI updates to Qubes now marking Dark mode easier except for a few places. #infosec

image/jpeg
image/jpeg
image/jpeg

percepticon, to Cybersecurity
@percepticon@ioc.exchange avatar

Researchers crack 11-year-old password, recover $3 million in bitcoin https://arstechnica.com/?p=2027419&utm_source=dlvr.it&utm_medium=mastodon

chiefgyk3d, to infosec
@chiefgyk3d@social.chiefgyk3d.com avatar

Live now on Twitch with More Qubes OS setup | Monero, Signal, Discord, and more | Cybersecurity and Chill | Gaming on Linux. Join in: https://twitch.tv/chiefgyk3d #TechTalk #Infosec #Linux #Cybersecurity #Streamer

percepticon, to Cybersecurity
@percepticon@ioc.exchange avatar
percepticon, to Cybersecurity
@percepticon@ioc.exchange avatar
wall_e, to infosec
@wall_e@ioc.exchange avatar

To whomever needs to hear this:

✨ Thou shalt not look inside a JWTs payload before its signature has been validated ✨

All you will find there is pain, misery, and CVEs

...THAT OTHER PEOPLE NOW HAVE TO TRACK IN THEIR SYSTEMS, FFS!!1! 😡

percepticon, to Cybersecurity
@percepticon@ioc.exchange avatar

RIP ICQ: Remembering a classic messaging app that was way ahead of its time https://arstechnica.com/?p=2027215&utm_source=dlvr.it&utm_medium=mastodon

neurovagrant, to infosec
@neurovagrant@masto.deoan.org avatar

Oh this domain looks fun. HMRC is most familiar to me as "His/Her Majesty's Revenue & Customs" - which is the title of gov[.]uk

hmrc-authentications[.]com

Registrar: CNOBIN (rebranded bizcn, so, China)
IP&NS: Cloudflared
First seen: 2024-06-04

simplenomad, to infosec
@simplenomad@rigor-mortis.nmrc.org avatar

The new wave of LLM-based AI is very much like Viagra. Originally invented to treat high blood pressure and angina, it was discovered that Viagra could help with reluctant boners. I'll let you work out whether this analogy is good or bad, but I'll just say I'm seeing a lot of dick waving when it comes to AI....

Lazarou, to Cybersecurity
@Lazarou@mastodon.social avatar

Just because Rishi and Keir were talking about the nation's security this week on their election campaigns it doesn't mean either of them will acknowledge the MAJOR cybersecurity incident effecting the NHS right now.

It's just words, they don't intend to live up to them, just say them and hope that we believe them

https://www.theguardian.com/technology/article/2024/jun/05/russian-group-behind-london-hospitals-cyber-attack-says-expert

grumpybozo, to infosec
@grumpybozo@toad.social avatar

Seen on the MailOp list. A putative joke from Tobias Fiebig.
I’m not sure that I’d put BGP before mail in this hierarchy, but that's mostly because others around me handle it as well as can be expected in a world with the likes of Cogent and Tata swinging their dicks at each other.

bogo, to infosec
@bogo@hapyyr.com avatar

A few more days left to @devconf_cz. I am looking forward to talking about and maybe meeting some nice people!

Who else is going to be there?

tech, to tech
@tech@unfufadoo.net avatar
percepticon, to Cybersecurity
@percepticon@ioc.exchange avatar
Lazarou, to UKpolitics
@Lazarou@mastodon.social avatar

While our politicians are prancing about on stage making performances some serious shit is going down with the NHS and the Nation's cybersecurity, not that anyone in charge seems to care.

I don't work in Infosec, but there are paragraphs in this article which will horrify them because of the mess the hack has revealed.
As a patient in the effected area, this is MY data that's flying around thanks to Russia 😡

https://www.theguardian.com/society/article/2024/jun/05/london-nhs-hospitals-revert-to-paper-records-in-wake-of-russian-cyber-attack

percepticon, to Cybersecurity
@percepticon@ioc.exchange avatar

Malaysia stakes claim to become semiconductor superpower by luring $100bn investment from … somewhere https://go.theregister.com/feed/www.theregister.com/2024/05/30/malaysia_semiconductor_plan/?utm_source=dlvr.it&utm_medium=mastodon

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • InstantRegret
  • mdbf
  • ethstaker
  • magazineikmin
  • cubers
  • rosin
  • thenastyranch
  • Youngstown
  • osvaldo12
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • provamag3
  • Durango
  • everett
  • tacticalgear
  • modclub
  • anitta
  • cisconetworking
  • tester
  • ngwrru68w68
  • GTA5RPClips
  • normalnudes
  • megavids
  • Leos
  • lostlight
  • All magazines