ecosurrealism, to Signal

Signal

  • is not open source
  • Is centrally controlled
  • doesn’t give you any option to verify their claims"
  • is fairly hostile to any other clients"
  • took money from the US Government"
  • seems to have a lot of strong and emotional advocates"
  • requires a phone number
  • exposes the phone numbers of members in any group chat.

#signal #openSource #infoSec #chat

https://blog.dijit.sh/i-don-t-trust-signal

tinker, to infosec

I suck at CTFs....

Hacking into corporations has made me into a lazy and unskilled hacker.

#hacking #infosec

postmodern, to infosec

Now that Twitter is rate limiting access, and more users who create Twitter's content are leaving, I wonder how this will impact all of those so-called "Threat Intel" companies? I know of at least one which was likely getting most of it's data from Twitter searches. I'm guessing most of these companies will pay for the Blue Checkmark to retain access to Twitter's now Premium API, but what's the point if the users who create the data are leaving? The second option is moving their data-mining operations over to ActivePub, except ActivePub isn't curated by fancy algorithms, it's just a raw fire hose.
#infosec #twitter #business #threatintel

nixCraft, to random
@nixCraft@mastodon.social avatar
rysiek, to random
@rysiek@mstdn.social avatar

Midnight Blizzard Entertainment. :blobcatpopcorn:

vwbusguy, (edited ) to random
@vwbusguy@mastodon.online avatar

Pop quiz for . All things being equal, which of these determines the priority of which zone rules get applied if an IP source overlaps:

rysiek, to infosec
@rysiek@mstdn.social avatar

#Yubico is merging with some other company to go public on a stock exchange
https://www.yubico.com/blog/yubico-is-merging-with-acq-bure/

Get ready for Yubico "maximizing shareholder value" — also known as "enshittification." :blobcat_owo:

Time to look more closely at @nitrokey 😉

#InfoSec

kravietz, to infosec
@kravietz@agora.echelon.pl avatar

Going through this excellent book by Shaun Pinner, much recommended! There’s many lessons to learn from this book but from my #infosec angle there are a few. Firstly, always keep an off-line maps app on your phone (I use OsmAnd). As a test — switch on airplane mode and try to survive for a day. Can you still navigate from point A to point B? Secondly, keep your social media profiles friends-only access. Thirdly, don’t keep any passwords in memory - it’s a bad practice from security point of view anyway, but I never thought about the interrogation angle. A password manager locked with biometrics and PIN and random passwords everywhere will prevent you from finding yourself in situation where you’ll be begging your interrogators to check another password because you might have remembered wrong.

kpwn, to infosec

The average user of https://cvecrowd.com sends about 9 HTTP requests to the web server.

On November 2nd, TWO MILLION requests were sent from three IP addresses in two hours.

The Anatomy of an Attack 🧵
#Pentesting #AppSec #InfoSec #CyberSecurity #BugBounty #Hacking #BlueTeam #CveCrowd

avoidthehack, to infosec

More malicious extensions in Web Store

At least 18 different malicious extensions (as of 30 MAY and this post) identified by @WPalant

Remember extensions have privileged access to the browser (and data in the browser). Choose your extensions wisely... they could be or in disguise.

https://palant.info/2023/05/31/more-malicious-extensions-in-chrome-web-store/

taeluralexis, to infosec

Does anyone encounter issues setting up protonvpn on trace labs or any debian-based distros in general? #infosec

Flipboard, to Cybersecurity
@Flipboard@flipboard.social avatar

Today, we're highlighting journalists who cover :

@briankrebs — independent investigative journalist, author of "Spam Nation"

@bobmcmillan — WSJ tech reporter, host of Hack Me if You Can

@campuscodi — RiskyBizNews creator, former ZDNet cybersecurity reporter

@couts — WIRED security editor

@dangoodin — Ars Technica reporter covering security

@JosephMenn — WaPo cyber reporter

@kevincollier — NBC cyber reporter

@lorenzofb — TechCrunch cyber reporter

Wander, to infosec
@Wander@packmates.org avatar

Quick question about DNS and DoH that I thought about after reading this post:

https://packmates.org/@silvereagle@furry.engineer/111176886781705659

Wouldn't it make sense for Firefox or another third party to bundle and transparently forward all DoH requests to cloudflare so that:

A) Cloudflare doesn't know who made what request due to not knowing the origin

B) Firefox doesn't know who made what request due to TLS


CC: @privacyguides

tdp_org, to webdev
@tdp_org@mastodon.social avatar

If you run a publicly available website/service, keep an eye on https://www.cve.org/CVERecord?id=CVE-2023-44487.

It'll be announced at midday UTC today (10th Oct 2023).

If there isn't an update you can deploy quickly for your affected services immediately (there should be for the better known software, they've had advance notice) then you should consider disabling the affected element until there is.

Can't share more right now but it's important so don't forget (& tell your friends!).

nixCraft, to linux
@nixCraft@mastodon.social avatar

With firefox on X11 (#Linux and #Unix machines), any page can pastejack you anytime https://www.openwall.com/lists/oss-security/2023/10/17/1 #security #infosec

chiefgyk3d, to iPod
@chiefgyk3d@social.chiefgyk3d.com avatar

I’m waiting extremely patiently for this device to replace my classic iPod I’ve repaired and modified to have a 3,000 mAh battery and also use an SD card. This is EXACTLY what I’ve been wanting in a music player. Simple, high quality audio, repairable, and no connectivity more than I need to just play music, no internet necessary.
#ipod #music #opensource #arduino #cybersecurity #infosec
https://www.crowdsupply.com/cool-tech-zone/tangara

DM_Ronin, to Canada
@DM_Ronin@mstdn.social avatar

Canada is banning FlipperZero :woozy_clown: extremelu stupid decision, considering that Flipper is extremely low-powered for actual car thefts (unless you add hardware modules – which isn't the same) https://www.canada.ca/en/public-safety-canada/news/2024/02/federal-action-on-combatting-auto-theft.html

#FlipperZero #Canada #Hardware #InfoSec #Security

_L1vY_, to infosec
@_L1vY_@mstdn.social avatar

Really good point. I was so distracted by the revolting inappropriate boundary issues, I didn't even think of #infosec issues.

Via M&M Enterprises
@sfoguj:

"Mike #Johnson and His Son Monitoring Each Other’s Porn Intake Is Worse Than You Think"

“A US Congressman is allowing a 3rd Party tech company to scan ALL of his electronic devices daily and then uploading reports to his son about what he’s watching or not watching, who else is accessing that data"

#CovenantEyes

https://news.yahoo.com/mike-johnson-son-monitoring-other-154928238.html

mjgardner, to privacy
@mjgardner@social.sdf.org avatar

If I read this right, @signalapp, @torproject, and other well-known -centric communications systems were largely funded by and aligned with Western covert agencies, for the purpose of aiding dissidents of enemy governments while centralizing secret traffic onto networks the intelligence community could subvert.

Only now they’re unhappy that Western citizens use them and so have pulled ’s funding.

https://open.substack.com/pub/kitklarenberg/p/signal-facing-collapse-after-cia

zersiax, to accessibility
@zersiax@cupoftea.social avatar

this year, I am participating in the event. I have deided to make videos of me doing the tasks to document the struggles I run into, as well as how I (fail to) get around them, for awareness, education, and basically because I felt like it. The fruits of my labor can be found here: https://www.youtube.com/playlist?list=PLoI1JGnSzOVKWI2fOpymnWcQtgxPLoW4X

Please note that the videos are still processing and therefore may not have subtitles yet. If the autogenerated ones are really bad, which wouldn't surprise me, I have infrastructure in place to do better, just let me know if it's a blocker for you and we'll sort it out. I really hope the community as a whole can learn from this, and that it paves the way forward for better for these kinds of challenges going forward. I'm not asking for too much here, it's about time this industry moves into the 21st century where this is concerned. Let's make it happen! :)

benjamingeer, to Trains
@benjamingeer@zirk.us avatar

Polish hackers figured out that a train manufacturer had programmed its trains to break down after certain dates, or if they were serviced at another company's workshop.

https://badcyber.com/dieselgate-but-for-trains-some-heavyweight-hardware-hacking/

attn @jon @echo_pbreyer

vwbusguy, to Kubernetes
@vwbusguy@mastodon.online avatar
rysiek, to infosec
@rysiek@mstdn.social avatar

> Russia publishes German army meeting on Ukraine
https://www.bbc.com/news/world-europe-68457087

> Germany has admitted the apparent [compromise] by Russia of a military meeting where officers discussed giving Ukraine long-range missiles - and possible targets.

> According to Der Spiegel magazine, the videoconference was not held on a secret internal army network but on the WebEx platform.

🤡

There's an infosec person somewhere who is really trying hard not to go: "I fucking told you this would happen". 👀

rysiek, to microsoft
@rysiek@mstdn.social avatar

Hey it's totally cool that blocked access to one of the repositories in the very center of the backdoor saga. :blobeyes:

It's not like a bunch of people are scrambling to try and make sense of all this right now, or that specific commits got linked to directly from media and blogposts and the like. :blobcatcoffee:

Cool, cool. :blobcatfingerguns:

chetwisniewski, to infosec
@chetwisniewski@securitycafe.ca avatar

Great! TransUnion, whom I have the pleasure of receiving free credit monitoring from due to the MGM Casino breach in Sept, has a policy of only allowing 15 characters or less. Not like anything important is on the line or anything. Oh, they get bonus points for letting me skip the password with a trivial security question! #InfoSec #NotAFeature @boblord @thorsheim

Security question dialog on account creation. Includes questions like "What was your high school mascot?" and "What city were you born in?"

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • ngwrru68w68
  • modclub
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • megavids
  • GTA5RPClips
  • tacticalgear
  • normalnudes
  • tester
  • osvaldo12
  • everett
  • cubers
  • ethstaker
  • anitta
  • provamag3
  • Leos
  • cisconetworking
  • lostlight
  • All magazines