dominiksteiger, to random German
@dominiksteiger@swiss.social avatar
HistoPol,
@HistoPol@mastodon.social avatar

@dominiksteiger

#Security nightmare:

#Microsoft’s new #Windows11 feature, #Recall, makes the #SciFi movie #TotalRecall almost look like a fairy tale by comparison.

Everything you ever saw or wrote on your device, even if deleted, will remain in definitely remain available and searchable for users of the device, including #hackers.
Opting out requires work.

Also, in my view, I doubt that it is #GDPDR compliant in its current form.
Beware.

Excellent analysis:

https://swiss.social/@dominiksteiger/112551118126679215

Nonilex, to Arizona
@Nonilex@masto.ai avatar
Nonilex,
@Nonilex@masto.ai avatar

Opponents say the ballot measure will do nothing to improve or prevent seekers from arriving. Instead, they say, it will replicate the paranoia & turmoil that & communities experienced after Gov signed , a divisive state -enforcement passed by in 2010 that came to be known as the “show me your papers law.” That law sparked years of protests & litigation, & has since been partially struck down.

piofthings, to microsoft
@piofthings@mastodon.social avatar
simplenomad, to Wyze
@simplenomad@rigor-mortis.nmrc.org avatar

Question for crypto (as in cryptographic) nerds, I am looking for an automated solution for on-prem backups that encrypts said backup. The plan is to take said encrypted backup and store it off sight. Prefer open source, and for further context consider this "home lab" although it does involve multiple servers with public IPs etc. I do not want to have the encryption key easily reachable like in plaintext in a config file.

Right now this is all happening manually, but automated would make this so much easier. It does not have to be a full end-to-end solution, even just the encrypting part being able to be automated would be fine as I could simply script around it. Thoughts and recommendations?

#cryptography #backup #automation #infosec #security

simplenomad, to infosec
@simplenomad@rigor-mortis.nmrc.org avatar

Sounds like a very cool project. The only problem with it is that there is no reference to Kuato (IYKYK).

https://github.com/xaitax/TotalRecall

#infosec #security

GrapheneOS, to privacy
@GrapheneOS@grapheneos.social avatar

GrapheneOS version 2024060400 released:

https://grapheneos.org/releases#2024060400

See the linked release notes for a summary of the improvements over the previous release.

Forum discussion thread:

https://discuss.grapheneos.org/d/13244-grapheneos-version-2024060400-released

#GrapheneOS #privacy #security

Nonilex, to america
@Nonilex@masto.ai avatar

calls ’s democratic values the “grounding wire of our global power” & its “our greatest asset.” …, called for withdrawing American forces in & & has promised… to cut loose even our closest if they don’t do as he tells them. …Trump sees all countries as unreliable, the relations between them . That sentiment has spread throughout a that once championed America’s values abroad…


https://time.com/6984970/joe-biden-2024-interview/

Nonilex,
@Nonilex@masto.ai avatar

#Biden responds to a question about America’s relationship w/ #SaudiArabia by saying that the #US has 2 kinds of #alliances: “There are #values-based, & there are #practical-based.”
…One of his first moves in office was to cut off certain #arms supplies over the kingdom’s #war in #Yemen, which has #displaced 4.5M people & #killed 377k, including 11k children…. Soon after, the de facto Saudi ruler… #MBS, met w/ #China’s FM & proposed greater cooperation on #nuclear energy & #security….

majorlinux, to TikTok
@majorlinux@toot.majorshouse.com avatar

Maybe the hackers forgot they were hacking them.

Malicious code has allegedly compromised TikTok accounts belonging to CNN and Paris Hilton

https://www.engadget.com/malicious-code-has-allegedly-compromised-tiktok-accounts-belonging-to-cnn-and-paris-hilton-174000353.html?src=rss

#TikTok #Security #CNN #SocialMedia #Tech

sjvn, to security
@sjvn@mastodon.social avatar

The NIST Finally Hires a Contractor to Manage CVEs
https://securityboulevard.com/2024/06/the-nist-finally-hires-a-contractor-to-manage-cves/ by @sjvn

After much too long, NIST has finally hired a contractor to deal with the staggering number of unexamined CVE reports.

br00t4c, to security
@br00t4c@mastodon.social avatar

'Did you know that?': Flight attendant shares the real reason they greet you when you board a plane--and it's not to be polite

#security

https://www.dailydot.com/news/flight-attendant-boarding-greeting/

br00t4c, to security
@br00t4c@mastodon.social avatar
helma, to security Dutch
@helma@mastodon.social avatar

De scheurkalender van dinsdag 4 juni gaat over pseudomiseren.

(SURF Security & Privacy Scheurkalender voor het onderwijs)

sjvn, to linux
@sjvn@mastodon.social avatar

Nasty Linux Bug, CVE-2024-1086, is on the loose https://opensourcewatch.beehiiv.com/p/nasty-linux-bug-cve20241086-loose by @sjvn

The patch for this hole came out in January, but in June, the attacks are hitting now. Here's why & what you can do.

ErikJonker, to security
@ErikJonker@mastodon.social avatar

The coming Olympic games in Paris must be a prime target for many terrorists. Many state and non-state actors are motivated to sent a message i think. It must be an incredible difficult job for the people responsible for security. To be prepared for anything and be able to handle different scenarios. In ancient times people stopped fighting during the olympics, those days are gone sadly.
#olympics #paris #security #terrorism

sjvn, to security
@sjvn@mastodon.social avatar

Malicious Package 'Pytoileur' Targets Windows and Leverages Stack Overflow for Distribution https://securityboulevard.com/2024/05/malicious-pypi-package-pytoileur-targets-windows-and-leverages-stack-overflow-for-distribution/ by @sjvn

This latest poisoned Python code used Slack Overflow to advertise itself. Happy, Happy, Joy, Joy!

dethos, to security
@dethos@s.ovalerio.net avatar

"GitHub recommends to pin an Action to a full length commit SHA as it is currently the only way to use an Action as an immutable release.

Still, only 2% of GitHub repositories fully embrace this security best practice!"

https://pin-gh-actions.kammel.dev/

br00t4c, to security
@br00t4c@mastodon.social avatar

'He was ready to judge you': TSA searches passenger's bag after going through security. He can't believe what he finds

https://www.dailydot.com/news/tsa-finds-spam-carry-on/

br00t4c, to security
@br00t4c@mastodon.social avatar
kubikpixel, to rust
@kubikpixel@chaos.social avatar

«Methods Should Be Object Safe»
– by @noracodes

🤔 https://nora.codes/post/methods-should-be-object-safe/


helma, to security
@helma@mastodon.social avatar

Be scanned or be banned (from normal internet use): "Despite a nicer-sounding name, it would still be the mass scanning of the private communications of people who are not suspected of any crime even in E2E encrypted environments. Technology and cybersecurity experts have repeatedly warned that this cannot be done safely and securely – putting at risk the private communications of activists, journalists, young people, businesses and even governments!"

https://edri.org/our-work/be-scanned-or-get-banned/

myfear, to security
@myfear@mastodon.online avatar

Detection Engineering is a tactical function of a cybersecurity defense program that involves the design, implementation, and operation of detective controls with the goal of proactively identifying malicious or unauthorized activity. https://github.com/infosecB/awesome-detection-engineering

SomeGadgetGuy, to tech
@SomeGadgetGuy@techhub.social avatar

Apple is partnering with OpenAI to improve Apple's lagging AI strategy, but we still don't know what the deal looks like.
https://somegadgetguy.com/b/45u

Is Apple paying OpenAI? Is OpenAI paying Apple?

This is a tough partnership for Apple, as the optics on AI in general run counter to the marketing Apple has poured into "privacy".

Shareholders must be REALLY excited though...

br00t4c, to security
@br00t4c@mastodon.social avatar

'Directly threatening': Alito's security parked in front of liberal neighbor's home amid dispute

#security #supreme

https://www.alternet.org/alito-security-neighbor-dispute/

br00t4c, to DaftPunk
@br00t4c@mastodon.social avatar

Snowflake denies miscreants melted its security to steal data from top customers

#house #security

https://go.theregister.com/feed/www.theregister.com/2024/05/31/snowflake_breach_report/

GrapheneOS, to privacy
@GrapheneOS@grapheneos.social avatar

GmsCompatConfig (sandboxed Google Play compatibility layer configuration) version 115 released:

https://github.com/GrapheneOS/platform_packages_apps_GmsCompat/releases/tag/config-115

See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

Forum discussion thread:

https://discuss.grapheneos.org/d/13147-gmscompatconfig-version-115-released

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • ngwrru68w68
  • everett
  • InstantRegret
  • magazineikmin
  • thenastyranch
  • rosin
  • GTA5RPClips
  • Durango
  • Youngstown
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • provamag3
  • tacticalgear
  • osvaldo12
  • tester
  • cubers
  • cisconetworking
  • mdbf
  • ethstaker
  • modclub
  • Leos
  • anitta
  • normalnudes
  • megavids
  • lostlight
  • All magazines