detroit_yeet, to opsec

RE: #Kolektiva server being compromised

Here are 5 things I do to avoid putting myself, my account, and my data at risk when something like this happens:

  • Assume that it WILL happen at some point (or that it's already happening without my knowledge)
  • Use a VPN (Proton has a good free plan https://protonvpn.com/) or Tor (https://www.torproject.org/)
  • Use the free smartphone app Authy for two-factor authentication (works with Twitch, Discord, Mastodon, Tw*tter, and more) https://authy.com/
  • Use the free and open-source password manager Bitwarden to remember and randomly generate passwords up to 128 characters long https://bitwarden.com/ (KeePass https://keepass.info/ is also FOSS but doesn't sync between devices)
  • Use DuckDuckGo's free email service to sign up for things, which hides my real email address and removes email trackers that tell the sender my location https://duckduckgo.com/email/

If you do all this, someone who hacks into or steals the server your data is hosted on won't be able to figure out who you are irl, won't have your IP address, won't know your real email address, and will have no chance of getting into your account.

I also use LibreWolf and the Privacy Badger and NoScript extensions to thwart fingerprinting attempts, but that's less relevant here.

#Opsec #infosec

ligniform, to privacy

I post this every time there's a big jump in new users but here goes:
Now that you're making a new account, do you really need to use the same username that you use everywhere else? It makes it very easy to find you.
Does adding your country/state/city add anything to your profile other than making finding you easier?
Please be mindful of what you post friends, a new account is a good time to think about how much you want to share publicly (Bare in mind that a 'private' account works very differently here).

Just a few and personal tips. Practice good and have fun!

hrefna, to opsec
@hrefna@hachyderm.io avatar

It seems timely to talk about what #OpSec is rather than just what it isn't.

OPSEC is about preventing leaks of metadata or auxiliary data in order to prevent revealing your underlying secret. OPSEC is about preventing an adversary from determining your actions from things that are not information about the operation itself.

OPSEC is a process, not a plugin.

For example, if you are worried about plans around an action leaking out, OPSEC asks about elements such as:

hrefna, to opsec
@hrefna@hachyderm.io avatar

@kvuzet

I don't think it is a simplification

is:

  1. A process, not a product
  2. About preventing inferences about your data from metadata or auxiliary data
  3. Is about building a culture of security

OpSec is not "make sure you talk about your crimes in a secure channel," OpSec is "don't share a shitposting group with the people you do crimes with," and "don't have everyone take PTO the day after you plan your op." It's "don't have a countdown to when you see your spouse."

@kkarhan

hrefna, to opsec
@hrefna@hachyderm.io avatar

I ask that the people who are talking about how "OPSEC means encrypting your data" learn one (1) thing about #OPSEC.

-.-

Just like. If you are going to use the term, at least please read the wikipedia page on it first. https://en.wikipedia.org/wiki/Operations_security

kkarhan, to infosec

@kvuzet no.

Exercise #ITsec, #InfoSec, #OpSec & #ComSec always rigorously, because #metadata will be used against you...

AufstandLastGen, to random German

Komm zum 💯 für Bayern Vorbereitungstreffen!

Im August werden wir in Bayern protestieren und Widerstand gegen den tödlichen gesellschaftlichen Kurs leisten. Egal wie der Staat reagiert, auch wenn er uns einsperrt!

Dafür suchen wir 💯 Menschen

https://uni-passau.zoom.us/j/61193381542?pwd=dW1jdWZVdk9FeVhIS3lFTjhTUXllQT09

kkarhan,

@AufstandLastGen Und was dann?

Ich bezweifle dass dabei was rauskommt aus gut ausschlachtbare Propaganda die zur eurer Kriminalisierung genutzt werden kann...

Aber hey, überrascht micht gern positiv damit, dass ihr mal #ITsec, #InfoSec, #OpSec & #ComSec ernst nehmt und nicht euch und eure Unterstützer*innen so heftig self-d0xxed, dass es ein #WontAttend bleibt?

kkarhan, to languagelearning

So that's how the #French #Police cracked shit...

Thanks @tails for the info:
https://tails.boum.org/security/argon2id/index.en.html

I guess a lot of people now have their weekends f**ked because they gonna need to re-encrypt shit.

Gladly I'm not affected as I user 128-digit passwords wherever possible...
https://github.com/kkarhan/misc-scripts/blob/260f087c8337417c69f94787358abf4faf5090f9/bash/.bash_aliases#L5

But a lot of you folks may be!

Please check your crypto settings NOW!

#ITsec #OpSec #InfoSec #ComSec #FullDiskEncryption #LUKS #Linux #Encryption #Data

D64eV, to random German
@D64eV@d-64.social avatar

Aus Fehlern das Falsche gelernt. Der Bundestag hat auf Wunsch des BMI & Nancy Faeser das Beamtengesetz geändert, damit die neue Präsidentin des BSI, Claudia Plattner, jederzeit in den Ruhestand versetzt werden kann. Eine beunruhigende Entwicklung. Das BSI steht unter Fachaufsicht des BMI. Das ist ein Problem. Denn Sicherheitsbehörden haben oft ein Interesse daran, IT-Sicherheitslücken offenzuhalten, zum Beispiel um Staatstrojaner einzusetzen. 1/

kkarhan,

@D64eV Allein deshalb muss das @bsi vom @bmi entkoppelt werden denn der #Interessenskonflikt schadet der #NatSec genauso wie #ITsec, #InfoSec, #OpSec & #ComSec!

vowe, to random German

deleted_by_author

  • Loading...
  • kkarhan,

    @vowe #DESHALB immer alle #Metadaten u.a. [#EXIF] entfernen und idealerweise anonym via z.B. #ExifRecherche u.ä. #antifaschistisch|e Gruppen leaken lassen...

    #ITsec #InfoSec #OpSec #ComSec

    #FilmNazis

    avoidthehack, to security

    “How do I improve my personal online ?”

    Three easy steps:

    • Use a password manager (lengthy, complex, unique )
    • Use multi factor authentication (ideally TOTP/authenticator app or FIDO2/hardware keys)
    • Keep your / firmware updated.

    https://avoidthehack.com/getting-started-cybersecurity

    avoidthehack, to cryptocurrency

    Prominent exchange infected with previously unseen Mac

    The exchange is unnamed as of posting.

    Malware "JokerSpy" can exfiltrate private data and download malicious files (likely for further compromise)

    https://arstechnica.com/security/2023/06/prominent-cryptocurrency-exchange-infected-with-previously-unseen-mac-malware/

    sanjaymenon, to opsec
    @sanjaymenon@mastodon.social avatar
    avoidthehack, to macos

    Secure Time Synchronization on #macOS

    From friends at PrivSec

    A guide for securely using ChronyControl to setup NTS on a local (virtual) #Linux server.

    #opsec #cybersecurity #ntp #virtualization

    https://privsec.dev/posts/macos/secure-time-synchronization-on-macos/

    avoidthehack, to android

    Anatsa #Android trojan now steals banking info from users in US, UK

    Primary distribution is in the #Google Play Store

    Steals bank account credentials, credit card info, other payment information.

    Not everything in any app store is safe. Be aware!

    #cybersecurity #infosec #privacy #opsec #security

    https://www.bleepingcomputer.com/news/security/anatsa-android-trojan-now-steals-banking-info-from-users-in-us-uk/

    avoidthehack, to Cybersecurity

    Why browser extension games need access to all websites

    From @WPalant

    Browser extension games requesting potentially dangerous permissions in the browser, to include search hijacking and code injection.

    Apparently many of these extensions are benign (in the sense the malicious code doesn't run initially) at first, but have placeholder code for future potentially malicious updates. Yikes.

    https://palant.info/2023/06/14/why-browser-extension-games-need-access-to-all-websites/

    avoidthehack, to privacy

    SMS Phishers Harvested Phone Numbers, Shipment Data from UPS Tracking Tool

    Benign (and "good") tools can be used to carry out phishing campaigns, such as this #smishing campaign targeting Canadian users who've placed legitimate orders with legitimate retailers.

    #privacy #cybersecurity #privacymatters #opsec

    https://krebsonsecurity.com/2023/06/sms-phishers-harvested-phone-numbers-shipment-data-from-ups-tracking-tool/

    @briankrebs

    avoidthehack, to iOS

    Avoidthehack updates mobile browser recommendations.

    Tried to simplify recommendations for #ios and #android, removing some previously recommended #browsers.

    iOS: https://avoidthehack.com/best-privacy-browsers-ios

    Android: https://avoidthehack.com/best-privacy-browsers-android

    #privacy #security #opsec #privacymatters

    avoidthehack, to privacy

    Skiff upgrades Pro Plan and rebuilds Mailbox import feature.

    Skiff pro gives 200GB storage, 3 custom domains, 15 aliases.

    Mail import features allows importing from and , and takes any mbox or .eml file for more universal email importing.

    jbzfn, to Russia
    @jbzfn@mastodon.social avatar

    Remember to hide your phone number / identity when clicking on #telegram links.

    Scammers and trollfarms never sleep. This situation is perfect to hook a bunch of westerners, especially journalists trying to get exclusive news.

    #Russia #Wagner #Opsec

    YourAnonRiots, to Cybersecurity Japanese

    #LockBit #ransomware has extorted $91 million from U.S. organizations, conducting hundreds of attacks since 2020. The cyber threat is evolving and disruptive, targeting critical sectors.

    Are you prepared for the next attack?

    https://thehackernews.com/2023/06/lockbit-ransomware-extorts-91-million.html

    #cybersecurity

    kkarhan,

    @YourAnonRiots OFC because I do have proper #ITsec, #OpSec, #InfoSec & #ComSec in place to enshure it doesn't happen...

    avoidthehack, to cryptocurrency

    New Information Stealer ‘Mystic Stealer’ Rising to Fame

    Like most info stealers out there, steals passwords, cookies, credit card info, and #cryptocurrency wallet extensions in browsers.

    Can take screenshots + gather system information.

    #malware #cybersecurity #security #opsec

    https://www.securityweek.com/new-information-stealer-mystic-stealer-rising-to-fame/

    avoidthehack, to android

    #Android #spyware camouflaged as #VPN, chat apps on Google Play

    • Primarily distributed as targeted attacks via WhatsApp and Telegram
    • Collects contact and location info

    Not everything in app stores is safe

    Beware of links directing you to download an app (even from the app store) if not sent from the official source/developer of the app

    #cybersecurity #infosec #security #opsec

    https://www.bleepingcomputer.com/news/security/android-spyware-camouflaged-as-vpn-chat-apps-on-google-play/

    avoidthehack, to opensource

    Google Threatens to Kill #opensource #youtube Front-End Invidious for Letting You Watch Videos without Tracking or Ads

    Not a conspiracy theorist... but now all of a sudden, after years (or rather, the "rise of #ai "), Big Tech wants to change/enforce API rules/pricing/you name it. Hmmm...

    #privacy #privacymatters #opsec

    https://tutanota.com/blog/google-youtube-invidious-privacy-alternative

    avoidthehack, to Cybersecurity

    Asus Patches Highly Critical #WiFi #Router Flaws

    Not patching could lead to malicious actors carrying out code execution (telling your device what to do), denial of service (making it unavailable for routine use), information disclosure and authentication bypass.

    #cybersecurity #security #patch #opsec

    https://www.securityweek.com/asus-patches-highly-critical-wifi-router-flaws/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • provamag3
  • InstantRegret
  • mdbf
  • ethstaker
  • magazineikmin
  • GTA5RPClips
  • rosin
  • thenastyranch
  • Youngstown
  • osvaldo12
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • JUstTest
  • Durango
  • everett
  • cisconetworking
  • Leos
  • normalnudes
  • cubers
  • modclub
  • ngwrru68w68
  • tacticalgear
  • megavids
  • anitta
  • tester
  • lostlight
  • All magazines