nixCraft, to privacy
@nixCraft@mastodon.social avatar
tim, to random

OMG seriously people WHY ARE YOU DISABLING PASTE ON PASSWORD FIELDS? You are literally making your systems LESS SECURE. GRRRRRR. #Security #NotThatHard #WTF

spaf, to Cybersecurity
@spaf@mstdn.social avatar

Today is the 35th anniversary of the Internet Worm.

"Ancient history," you say? Or perhaps, "What's that?"

Read my blog post about it to get my perspective on why it is important:
https://www.cerias.purdue.edu/site/blog/post/reflecting_on_the_internet_worm_at_35/

nixCraft, to privacy
@nixCraft@mastodon.social avatar

Microsoft says it’s starting to test ads inside the Start menu on Windows 11. The software maker will use the Recommended section of the Start menu, which usually shows file recommendations, to suggest apps from the Microsoft Store. Trillion dollar corporation is so poor. They need more money by selling your data to the highest bidder. wtf? https://www.theverge.com/2024/4/12/24128640/microsoft-windows-11-start-menu-ads-app-recommendations

nixCraft, to linux
@nixCraft@mastodon.social avatar

Microsoft reveals subscription pricing for using Windows 10 beyond 2025, and it's not cheap. Customers will need to pay $61 per device, which will double every year for three years, to remain secure on Windows 10. If you just do shopping or social media you can use alternative os like Ubuntu, Mint, or pop os for your older computer instead of jumping to windows 11. Also regardless of windows 10 or 11 prices you will still get Ads in Windows 😂 Choose wisely

RyunoKi, to python
@RyunoKi@layer8.space avatar

Due to a difficult contract situation I'm currently open to employment offers as #Frontend / #Fullstack #Developer.

(Assuming backend is Node.js or #Python)

I can handle frameworks and libraries like #Angular, #React & #Vue but can also achieve amazing results w/ #JavaScript & #TypeScript.

I'm happy to share my knowledge in #Accessibility, #Security & software architecture

Remote Work pref. I've worked internationally before (Portugal, India) but insist on German jurisdiction.

#GetFediHired

Edent, to webdev
@Edent@mastodon.social avatar

🆕 blog! “I can't use my number pad for 2FA codes”

This has to be the most infuriating bug report I've ever submitted. I went to type in my 2FA code on a website - but no numbers appeared on screen. Obviously, I was an idiot and had forgotten to press the NumLock button. D'oh! I toggled it on and typed again. No numbers appeared. I […]

👀 Read more: https://shkspr.mobi/blog/2024/04/i-cant-use-my-number-pad-for-2fa-codes/

cassidy, to security
@cassidy@blaede.family avatar

People building apps and web services: I feel like we need to talk about two-factor authentication terminology.

Here are some of the things I always think and then realized I've never written down. 🧵

#security #ux #UXCopywriting #copywriting #UXDesign

matt, to random
@matt@isfeeling.social avatar

Google now lets you sign into your account with a #passkey. Go here to set it up on your account today! https://g.co/passkeys

And yes, you can use your iPhone to set up the passkey, which will sync to all your personal Apple devices nicely. #security

haubles, to security
@haubles@fosstodon.org avatar

A few weeks back, my company #Fastly put on a (partially) live conversation between our #Security team and @renchap about protecting @Mastodon from #DDOS attacks.

Thanks so much to everyone who attended live and asked great questions!

If you couldn't make it, here's the recording, and a PDF with the answers to questions we didn't get to live.

(it's... very enterprise marketing. But you do not need to give us any of your information to view!)

https://learn.fastly.com/security-mitigating-ddos-and-traffic-surges-with-mastodon-follow-up.html#contentVideo

orsinium, to security
@orsinium@fosstodon.org avatar

Which one would you choose?

  1. Make sure you correctly handle user input in SQL queries to prevent SQL injection, or

  2. Make a standard banning any punctuation in geographical places and force local authorities to rename streets and reissue all street signs.

https://www.bbc.com/news/uk-england-york-north-yorkshire-68942321

nixCraft, to linux
@nixCraft@mastodon.social avatar

Backdoor in upstream xz/liblzma leading to ssh server compromise https://www.openwall.com/lists/oss-security/2024/03/29/4 #unix #linux #openssh #infosec #security

madargon, to drawing Polish
@madargon@is-a.cat avatar

How I see attempts to force #backdoors in E2E #encryption...

#drawing #comic #geek #government #privacy #security

DamienWise, to ai
@DamienWise@aus.social avatar

Dropbox has started to give your files to OpenAI.

They claim it's only if you use their AI tools, and they claim OpenAI will use your data for only 30 days and then delete it. I think that's a terrible abuse of user rights and a security disaster waiting to happen.

Confusingly, they've rolled-out this malfeature to some users but not all (yet). My partner & me compared the "Settings" page on our Dropbox accounts — the "Third-Party AI" tab is there for one of us but not the other.

The setting is switched on by default. This is a "dark pattern" (also known as a "deceptive design pattern") that ignores user consent. If you don't know about it, you can't opt-out. Worryingly, if you're slow to opt-out then there's a chance they've scraped you data already. It's a harsh reminder of the saying "If you're not paying for the product, you are the product".

How to stop Dropbox from sharing your personal files with OpenAI
https://www.cnbc.com/2023/12/13/how-to-stop-dropbox-from-sharing-your-personal-files-with-openai.html

#Dropbox #AI #OpenAI #Security #Privacy #DarkPattern #DeceptiveDesignPattern

shortridge, to security
@shortridge@hachyderm.io avatar

dear plausibly sentient citizens of the milky way,

I published a cliff notes / cheat sheet / tl;dr guide for you on what the hot topixxx of software #resilience and #security chaos engineering (SCE) mean: https://kellyshortridge.com/blog/posts/security-chaos-engineering-sustaining-software-systems-resilience-cliff-notes/

it’s basically the chapter summaries of my paywalled book repurposed as a public, bite-sized guide for you to devour, absorb, then change-make (or sound smart online, in meetings, at parties, to your cat, etc)

let’s keep trying to modernize #infosec together xx

protonmail, to opensource
@protonmail@mastodon.social avatar

Proton Pass is #opensource and has now passed an independent #security audit: https://proton.me/blog/pass-open-source-security-audit.

All fields and metadata in Pass are secured by #e2e encryption, so you can rest assured that no one, not even Proton, can access your information.

greg, to hacking

I updated my instances terms of service to say "no hacking". It was much easier than upgrading. If that doesn't work I'll block the hashtag "#hacking" and defederate from hackers.town.

#MastoAdmin #Security #Mastodon

smadin, to security
@smadin@better.boston avatar

hey so if you have a #spoutible account you need to immediately scroll to the end of this post, take the four steps listed, and then read the whole post. a vulnerability that was just fixed made it possible for an attacker to take complete control of your account without you getting any kind of notification.

https://www.troyhunt.com/how-spoutibles-leaky-api-spurted-out-a-deluge-of-personal-data/

#security

pluralistic, to security
@pluralistic@mamot.fr avatar

Two decades ago, my life changed forever: hearing explain that "" doesn't exist in the abstract. You can only be secure from some threat. A fire alarm won't protect you from burglaries. A condom won't protect you from mass shootings. It seems obvious, but how often do we hear about "security" without any mention of who is being made secure, and from which threat?

1/

tdp_org, to webdev
@tdp_org@mastodon.social avatar

If you run a publicly available website/service, keep an eye on https://www.cve.org/CVERecord?id=CVE-2023-44487.

It'll be announced at midday UTC today (10th Oct 2023).

If there isn't an update you can deploy quickly for your affected services immediately (there should be for the better known software, they've had advance notice) then you should consider disabling the affected element until there is.

Can't share more right now but it's important so don't forget (& tell your friends!).

ThePSF, to rust
@ThePSF@fosstodon.org avatar

Python is a memory-safe programming language that eliminates an entire class of software vulnerabilities 🐍🛡️ Adoption of memory-safe systems languages like continues to grow in the package ecosystem 🦀

https://pyfound.blogspot.com/2024/02/white-house-recommends-.html

ilumium, to security
@ilumium@eupolicy.social avatar

"The biggest source of conflict was an amendment ... that would prohibit #databrokers from selling consumer data to #lawenforcement and would require a warrant to access Americans’ information... National #security hawks in #Congress and local law enforcement groups joined forces to kill the amendment, with the National Sheriffs’ Association claiming it would “kneecap law enforcement” in a letter to Congress..."

https://www.theverge.com/2024/4/5/24122079/data-brokers-fisa-extension-nsa-section-702-surveillance-lexis-nexis

videograndpa, to IT
@videograndpa@mastodon.social avatar

THE PERIOD ISN'T ACTUALLY ALLOWED IT'S JUST THE END OF THE SENTENCE AAAAAAAAAAAAAAAAAA #IT #infosec #security

fatuus, to random
@fatuus@mstdn.fr avatar

Hello :mastodon:

I am hiring 💸 !

Looking 👀 for a Network Security Engineer 🕸️ for my customer.
Job description 📰 on demand.

Required #skills are:
Cisco,
Palo Alto &
Checkpoint
(Algosec would be a plus)

Position based in #luxembourg 🇱🇺

Feel free to contact me

#joboffer #job #iamhiring #lookingforajob

fatuus,
@fatuus@mstdn.fr avatar

Hello :mastodon:

I am hiring 💸 !

We're looking 👀 for a person with Linux Admin :debian: (RedHat actually) skill.
Strong Security mindset 🛡️

Job description 📰 in PM.

Skills needed :
#Linux / #RedHat,
#Security
#Python
#Ansible
#Apache

🇬🇧 Anglais mandatory

Job can be in 🇱🇺 , 🇫🇷 , 🇧🇪 or 🇵🇱
for Internal
Any country in 🇪🇺 as Contractor

Feel free to contact me for anything.

#IAmHiring #hiring #job #emploi #JeChercheUnJob

:boost_requested: makes your CPU faster

autonomysolidarity, to France German
@autonomysolidarity@todon.eu avatar

CALL FOR AN INTERNATIONAL WEEK OF SOLIDARITY WITH THE ACCUSED OF 8.12.2020
FROM 16 TO 23 SEPTEMBER 2023
"The 7 french comrades arrested on 8 December 2020 will go on trial from 3 to 27 October 2023. They will be judged for «criminal association of terrorist criminals» (art. 450-1) in Paris. No terrorist project has been established after two years of investigation characterized by the use of white torture and a very intrusive surveillance. The criminal classification was not retained but the terrorist and collective dimension remains despite the total absence of evidence or even links between all the seven people. Several of them are also charged with “refusing to surrender a secret decryption convention” (Art. 434-15)."
https://anarchistnews.org/content/call-international-week-solidarity-accused-8122020
#Repression #France #Counterterrorism #Frankreich

autonomysolidarity, (edited )
@autonomysolidarity@todon.eu avatar

Seven people are put on trial in #France for:

  • using encrypted apps like Signal
  • participating in digital security training

“8 December” case: why is encryption on trial?
"On 3 October, the trial of the so-called “8 December” case began. Seven people are prosecuted for being a “terrorist group”.

The intelligence services in charge of the judicial investigation (Direction générale de la Sécurité intérieure, DGSI), the National Antiterrorist Prosecution Office (Parquet National Antiterroriste, PNAT), and the investigating judge based their case on the fact that the defendants were using different tools to protect their privacy and encrypt their communications on a daily basis.

This trial is part of an increased political push by states and law enforcement for surveillance measures and the criminalisation of encryption. That is why the trial is crucial in the battle against the state’s ongoing attempts to criminalise commonplace, secure and healthy digital practices.

EDRi member in France La Quadrature du Net has continuously defended people’s right to privacy and fought for strong protections of everyone’s digital security. Now, once again, they stand up for the last pillar of our digital #security#encryption."
via @edri
@surveillance https://edri.org/our-work/8-december-case-why-is-encryption-on-trial/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • ngwrru68w68
  • everett
  • InstantRegret
  • magazineikmin
  • thenastyranch
  • rosin
  • GTA5RPClips
  • Durango
  • Youngstown
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • provamag3
  • tacticalgear
  • osvaldo12
  • tester
  • cubers
  • cisconetworking
  • mdbf
  • ethstaker
  • modclub
  • Leos
  • anitta
  • normalnudes
  • megavids
  • lostlight
  • All magazines