Mer__edith, to random
@Mer__edith@mastodon.world avatar

Where I speak some advantages Signal has over the bigger richer rest of tech:

“We don’t have to be full of shit. We’re not a surveillance company. I’m not trying to pretend Facebook is good. I don’t have to toe a party line that is divorced from reality”

https://restofworld.org/2023/signal-president-meredith-whittaker-messaing-privacy/

kkarhan,

@anarchopunk_girl @fla @Mer__edith @signalapp

#Signal also doesn't provide value to me beyond what #XMPP + #OMEMO & #eMail + #PGP/MIME can offer for decades now.

Instead it creates shitty dependencies to #Google - #APIs that have no legitimate reason to exist and their unwillingness to allow #SelfHosting makes it worse than a default #Zulip installation in terms of #InfoSec, #OPsec, #ComSec & #ITsec.
https://zulip.com/why-zulip/

gcluley, to Cybersecurity
@gcluley@mastodon.green avatar

One of the world's largest online travel agencies, Booking.com, is being used by fraudsters to trick hotel guests into handing over their payment card details.

How do I know? The fraudsters tried the trick with me.

https://grahamcluley.com/fraudsters-target-booking-com-customers-claiming-hotel-stay-could-be-cancelled/

kkarhan,

@gcluley I guess #Booking.com needs to learn how to #ITsec, #InfoSec, #OpSec & #ComSec their shit, cuz I've yet to hear of a similar exploit on #HRS.com ...

#JustSaying

retrohistories, to random
@retrohistories@digipres.club avatar

To protect your privacy and shield yourself against 0-days and malicious advertisers, an adblocker is an important part of your security stance.

The FBI, NSA, CISA, and UK National Cyber Security Centre all recommend adblocking as a protective measure.

You'd never disable your firewall or antivirus because a site asked you to. NEVER DO THIS WITH YOUR ADBLOCKER.

That's the only pertinent point here. Everything else is noise.

kkarhan,

@retrohistories +9001%

, , & is not negotiable.

Remember: Shitsites have the shorter lever because they need you more than you need them!

Also feel free to check out some quality blocklists...

https://github.com/greyhat-academy/lists.d/blob/main/blocklists.list.tsv

bsi, to random German
@bsi@social.bund.de avatar

it-sa 2023 in Nürnberg: Großer Andrang in unserer Speaker’s Corner beim Vortrag „Cyber-Angriffe abwehren: Wie auch KMU sich effektiv schützen können“

Manuel Bach, Leiter des Referates „Cyber-Sicherheit für KMU“, stellte die aktuelle Bedrohungslage für kleine und mittlere Unternehmen dar, gab Tipps und Tricks zum Schutz vor Cyber-Angriffen und stellte den neuen CyberRisiko-Check vor. Den Vortrag gibt’s noch einmal am Donnerstag, 12.10.2023 um 11.15 Uhr live beim BSI, Halle 7a, Stand 618.

kkarhan,

@bsi #WasFehlt ist ein klares Bekenntnis zu sicheren & datenschutzkonformen Alternativen zu #Govware aus dem außereuropäischen Ausland.

Aber das würde bedeuten dass deutsche Behörden sich eingestehen müssten, dass deren #ITsec, #InfoSec, #OpSec & #ComSec für die Tonne ist.

Grüße an die Leute von #Bundesdruckerei / #xecuro welche #MicrosoftTeams nutzen als hätte es #Snowden, #Prism und #CloudAct nie gegeben!

https://www.youtube.com/watch?v=_7583HNrZJs via @investigate_eu

mattblaze, to random
@mattblaze@federate.social avatar

Reminder about Mastodon "private" messages. Aside from not being end-end-encrypted (and so visible to instance administrators), they CC anyone @-mentioned ANYWHERE in the body of the message (not just those listed at the start).

They are now called "private mentions" rather than "private messages", but if you don't fully understand the semantics, this behavior may be unexpected and/or cause unpleasant side effects.

MagusNet, (edited )
monkeyflower, to tech
michael, to iOS
@michael@thms.uk avatar

Huh. iOS 17 allows you to keep using your old passcode for 72 hours after you’ve changed it.

That seems like a non-ideal thing to do by default. And it certainly seems like something that should be highlighted really prominently when changing the passcode 🤔

https://support.apple.com/en-us/HT213849

#ios #apple #password #InfoSec #opsec

gmate8, to opsec

Don't forget to update your stuff, especially regarding image related software #webp #vulnerability #opsec

larusargentatus, to BadInternetBills

Currently trying to build a Threat Intelligence compilation from diferent resources for Activists and Journalist (RSS feeds).

Right Now:

I am trying to compile specially around: legislation, surveillance, police tactics against opositors

Does anyone have other suggestions add?

#threatintel #activism #journalism #opsec #security

ianonymous3000, to privacy
@ianonymous3000@mastodon.social avatar

Check out @GrapheneOS, DivestOS, @LineageOS, @iode, @e_mydata comparison chart by Sandbag6736 from Techlore forum. Personal preferences play a big role. 🔍📱 #AndroidROMs #privacy #opsec #cybersecurityawareness

Feel free to comment if there’s any inaccuracies.

noelreports, to random Dutch
@noelreports@mstdn.social avatar
Powerfromspace1,
@Powerfromspace1@mstdn.social avatar

@noelreports silence 🤫 is golden #opsec

gerowen, to Facebook
@gerowen@mastodon.social avatar

If you ever want to feel depressed about humanity, just do a search for things like on your social media platform of choice. I found this one on . This guy works for a bank.

Don't be this guy. He could be impersonated, or this picture could be used as a template to forge a fake ID complete with a valid barcode to gain access to bank facilities or infrastructure.

I censored the bar code and ID#, they were visible in the original.

monkeyflower, to Canada

"Canada Post breaking law by gathering info from envelopes and parcels, privacy watchdog says"

And also breaking my Canadian heart. 🍁💔

https://www.theglobeandmail.com/canada/article-canada-post-breaking-law-by-gathering-info-from-envelopes-parcels/

#Canada #privacy #infosec #opsec

avoidthehack, to privacy

Inside #ShadowDragon, The Tool That Lets ICE Monitor Pregnancy Tracking Sites and Fortnite Players

What a piece by @404mediaco

ShadowDragon: Feeding the mass surveillance machine by tracking people who play Fortnite (and probably, I guess, other popular online games), scraping images from BabyCenter (a site for expectant parents), and social media sites for the Black community, the bodybuilding community, and others.

ShadowDragon also has the capability to monitor/scrape information from hundreds of social media sites/games/websites. Who plays a game and expects to end up in an ICE database?

This is insane.

You are being watched.

#privacy #privacymatters #opsec

https://www.404media.co/inside-shadowdragon-ice-babycenter-pregnancy-fortnite-black-planet/

gianmarcogg03, to telegram

#Telegram strikes again with documents from Dutch authorities saying that they can request hidden phone numbers and IP addresses at any time. Again, Telegram still claims on their homepage that they never gave up any data when that's not true at all, also for past requests like the one from the German police a while back.

https://cyberwarzone.com/dutch-police-can-access-hidden-telegram-numbers/

#Security #Privacy #OpSec #FreeSoftware #OpenSource

avoidthehack, to privacy

Revealed: The Country that Secretly Wiretapped the World for the FBI

Lithuania.

#privacy #cybersecurity #opsec

https://www.404media.co/revealed-the-country-that-secretly-wiretapped-the-world-for-the-fbi/

runarcn, to Cybersecurity

Any of you fedi wizards that know of good account to follow to learn more about #cybersecurity, #infosec, #opsec etc? I'd follow the tags, but I've often found that following big tags drowns my entire feed in one topic

netzpolitik_feed, to random German
@netzpolitik_feed@chaos.social avatar

Der Digital Markets Act der EU soll sicherstellen, dass große IT-Firmen ihre Marktmacht gegenüber anderen nicht unfair ausnutzen. Nun hat die EU-Kommission 6 Firmen zu "Gatekeepern" erklärt. Ein IT-Riese glänzt durch Abwesenheit. https://netzpolitik.org/2023/digitale-gatekeeper-einer-fehlt-im-club-der-grossen/

kkarhan,

@Pabamiti @Natanox @nomain @netzpolitik_feed
Wäre #ITsc, #OnfoSec, #OpSec & #ComSec mit "Installier' / nutz' #Signal / Threema / ... !) abgeharkt wären sehr viele Leute arbeitslos und OK-Elemente sürden nicht gebusted werden!

arstechnica, to random
@arstechnica@mastodon.social avatar

Hack of a Microsoft corporate account led to Azure breach by Chinese hackers

Other failures along the way included a signing key improperly appearing in a crash dump.

https://arstechnica.com/security/2023/09/hack-of-a-microsoft-corporate-account-led-to-azure-breach-by-chinese-hackers/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

pacanukeha,
skykiss, to adsb
@skykiss@sfba.social avatar

Dear Xi,

We are watching you.

The Wing Loong-10 is a series of ChiCom unmanned aerial vehicles of the High-Altitude Long Endurance type, featuring some stealth characteristics. As of 2017, it is being developed by the Chengdu Aircraft Industry Group for reconnaissance and precision strike missions.

  1. Looks to have landed at Foshan (ZGFS)

  2. CAIG Wing Loong-10 UAV using callsign 00CA6181 and hex code passing over Hezhou

  3. Chi likes to fly it at 39,400 next to Taiwan. At that altitude, this platform had a complete view of the entire island of Taiwan for about an hour and a half. 1/2

image/png
image/png

mickmeally,

@skykiss Listed as a 'Private Owner' so nothing to see here! 😜 🇹🇼

Innocently whistling GIF

thegrugq, to opsec

If you’re interested in OPSEC you’ll find this talk extremely informative. Lots of important information on how to operate safely.

https://www.youtube.com/watch?v=9XaYdCdwiWU

#OpSec

geist, to random German
@geist@troet.cafe avatar

"Wir müssen in der Detektion umfassend und in der Reaktion schneller werden".
Bla Blubb. Macht mal mit Microschrott und allen Daten auf US Servern auch noch.
Thema Cyberangriffe auf die deutsche kapitale Idiotie im DLF. Muss doch lachen.

kkarhan,

@geist Sorry, aber dass Microsoft nicht wegen illegaler Agententätigkeit für einen ausländischen Geheimdienst zwangsweise geschlossen und des Landes verwiesen wurde sagt doch alles über die lachhafte #ITsec, #InfoSec, #OpSec & #ComSec der Bundesregierungen aus...

sqrt2, to random
@sqrt2@chaos.social avatar

no comment

kkarhan,

@sqrt2 the only winning move is not to use #Microsoft Products like #Windows!

#AllGAFAMsAreBad #AllGAFAMsAreEvil #PRISM #ITsec #InfoSec #OpSec #ComSec

avoidthehack, to Cybersecurity

U.S. Hacks QakBot, Quietly Removes Botnet Infections

@briankrebs

Qakbot has been... dismantled?

Qakbot was originally a banking trojan but is (was?) the most popular malware loader (1st stage/dropper/however you want to call it).

FBI and company got access to the Qakbot botnet + recovered over 6.5 million stolen #passwords and credentials. Data shared with @haveibeenpwned

#cybersecurity #security #opsec

https://krebsonsecurity.com/2023/08/u-s-hacks-qakbot-quietly-removes-botnet-infections/

threatresearch, to infosec

I'd really like to know why some of the most important and influential conferences have decided that it's totally a-OK to host their event in the kingdom of Saudi Arabia, whose leader personally ordered his security staff to detain, and torture to death a US-based reporter who exposed corruption in the kingdom.

If you feel strongly that the industry should stand by its principles, demand that Informa PLC end the practice of hosting in Saudi Arabia.

kkarhan,

@threatresearch as a has been a for decades.

The sheer fact that they choose to host their event in a location that would literally murder me for existing [and I'm just a white heterocisbinary dude] disqualifies said conference from being anything but a that'll make it trivial for the islamofacist regime to earmark anyone with any , , and skills for with like as well as ...

  • All
  • Subscribed
  • Moderated
  • Favorites
  • provamag3
  • InstantRegret
  • mdbf
  • ethstaker
  • magazineikmin
  • GTA5RPClips
  • rosin
  • thenastyranch
  • Youngstown
  • osvaldo12
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • JUstTest
  • Durango
  • everett
  • cisconetworking
  • Leos
  • normalnudes
  • cubers
  • modclub
  • ngwrru68w68
  • tacticalgear
  • megavids
  • anitta
  • tester
  • lostlight
  • All magazines