north, to bluesky
@north@fosstodon.org avatar

Fuck it. #YOLO

#Bluesky continues to be entirely non-responsive to the numerous security vulnerabilities I've reported to them, so I spent the evening writing up a nice README and a framework with exploit modules, and just made it all public.

Have fun.

https://github.com/qwell/bsky-exploits

#infosec #security

ADHDefy, (edited ) to privacy
@ADHDefy@easymode.im avatar

Almost got scammed selling some stuff online. 🤙

Had a person send me their number as an interested buyer and told me to text them. I did (first mistake), and we arranged a meetup time. Then they asked if, for their safety, they could send me a six digit code (some of you already know where this is going) that I could repeat back to them to verify myself.

I said, "absolutely!" And sure enough, I got a Google Voice verification number. lol

If you're not familiar with the scam, shady people will take your phone number and try to create a Google Voice account with it. If you provide them with the 6-digit code that Google sends you, they can "verify" that they are you, and then basically use your phone number to run scams, commit fraud, etc. It's nasty business.

I called them out, blocked them, then reported them to the marketplace website and to the FTC--though, almost certainly, they were using the phone number of another poor soul to carry this out.

I used to work as a social engineer, running phishing campaigns (ethically, with consent lol), against Fortune 1000 companies to assess their level of vulnerability. Luckily for me, I was super familiar with this, but most of the people I told about it have said, "Oh, I probably would have fallen for that...", and even I set myself up for it.

So that is why I'm posting this. Please be aware of sketchy shit like this. If someone is asking you for a verification code over SMS or email, tread with EXTREME caution. Also, it's usually pretty shady if a stranger you're already chatting with wants to move to a new platform. Not always, but if someone emails or messages you on Facebook to ask you to text them, that's a little weird. I'd had legitimate buyers/sellers do that, so it's not unheard of, but it should put you on guard.

If you buy/sell/trade online frequently, it's a good idea to use a dedicated MySudo number, VOIP number, and/or a burner phone for that.

Stay safe out there, kids.

mysk, to infosec

Google has just updated its 2FA Authenticator app and added a much-needed feature: the ability to sync secrets across devices.

TL;DR: Don't turn it on.

The new update allows users to sign in with their Google Account and sync 2FA secrets across their iOS and Android devices.

We analyzed the network traffic when the app syncs the secrets, and it turns out the traffic is not end-to-end encrypted. As shown in the screenshots, this means that Google can see the secrets, likely even while they’re stored on their servers. There is no option to add a passphrase to protect the secrets, to make them accessible only by the user.

Why is this bad?

Every 2FA QR code contains a secret, or a seed, that’s used to generate the one-time codes. If someone else knows the secret, they can generate the same one-time codes and defeat 2FA protections. So, if there’s ever a data breach or if someone obtains access .... 🧵

#Privacy #Cybersecurity #InfoSec #2FA #Google #Security

image/jpeg
image/png
image/png

hiramfromthechi, to privacy
@hiramfromthechi@mastodon.social avatar

Any device that needs to be off because it can't be trusted with your conversations should not exist in the first place.

#privacy #privacymatters #security #infosec #cybersecurity #cybersec #amazon #amazonecho #surveillance

mysk, (edited ) to privacy

The rogue 2FA app that steals scanned secrets is now ranked 18 on the German App Store for the productivity category. No wonder! The app disguises as a Microsoft app. It is the top hit when you search for "Microsoft Authenticator" and the developer has updated the screenshots in the ad card to highlight the word "Microsoft". Surprisingly, the product page of the app shows different screenshots with the word "Microsoft" removed.
The app now has 1.2K reviews, as opposed to 18 when we first addressed the app.

🙏 Boosting this post will help spread the word. Thank you!

kaosailor, to privacy
@kaosailor@mastodon.online avatar

I'm still laughing 😂 yet still very incensed..

#privacy #googlechrome #security #memes

nixCraft, to privacy
@nixCraft@mastodon.social avatar

Garbage aka providing relevant Ads 😂 comic credit https://supercombodeluxe.com/gmen/ #privacy #security uBlock Origin, FTW. This is also a good reminder that I don't have any Ads on my blog and if you find my content useful, I have Patreon https://www.patreon.com/nixcraft

ricci, to security
@ricci@discuss.systems avatar

Hey! Let's talk about #SSH and #security!

If you've ever looked at SSH server logs you know what I'm about to say: Any SSH server connected to the public Internet is getting bombarded by constant attempts to log in. Not just a few of them. A lot of them. Sometimes even dozens per second. And this problem is not going away; it is, in fact, getting worse. And attackers' behavior is changing.

The graph attached to this post shows the number of attempted SSH logins per day to one of @cloudlab s clusters over a four-year period. It peaks at about 3.4 million login attempts per day.

This is part of a study we did on our production system, using logs of more than 640 million login attempts, covering more than 1,500 hosts on our side and observing more than 840 thousand incoming IP addresses.

A paper presenting our analysis and a new, highly effective means to block SSH brute force attacks ("Where The Wild Things Are: Brute-Force SSH Attacks In The Wild And How To Stop Them") will be presented next week at #NSDI24 by @sachindhke . The full paper is at https://www.flux.utah.edu/paper/singh-nsdi24

Let's dive in. 🧵

AgreeableLandscape, to random

Random Website: You need to set up with your phone number!

Me: Why?

Website: In case we get hacked!

Me: I don't really care, no one even knows about this account and it doesn't have my personal information.

Website: You misunderstand, it's so that in case we get hacked, we HAVE your information to leak to the hackers. They worked hard and deserve it! Also we sell your account to ad companies but they're not interested unless they can tie it to a real person.

sos, to infosec
@sos@mastodon.gamedev.place avatar

So, Microsoft is silently installing Copilot onto Windows Server 2022 systems and this is a disaster.

How can you push a tool that siphons data to a third party onto a security-critical system?

What privileges does it have upon install? Who thought this is a good idea? And most importantly, who needs this?

nixCraft, to linux
@nixCraft@mastodon.social avatar
nixCraft, to infosec
@nixCraft@mastodon.social avatar

Password security 😅 #infosec #security #banking #wifi

eb, to security
@eb@social.coop avatar

Unfolding now: https://news.ycombinator.com/item?id=39865810

An incredibly technically complex in xz (potentially also in libarchive and elsewhere) was just discovered. This backdoor has been quietly implemented over years, with the assistance of a wide array of subtly interconnected accounts:

The timeline on this is going to take so long to unravel

nixCraft, to privacy
@nixCraft@mastodon.social avatar

Do you like it when browsers share any function of your browsing history with every random website you visit to target Ads? Well, get ready, Google Chrome pushes ahead with targeted ads based on your browser history https://www.theregister.com/2023/09/06/google_privacy_popup_chrome/

Tutanota, to Bulgaria
@Tutanota@mastodon.social avatar

Say NO to broken browsers! ⛔

The EU is preparing a very dangerous law that would undermine the security of every browser.

Speak up now! 🗣️

@Jeremiah has more on how you can help to protect the web! 💪

https://www.jeremiahlee.com/posts/2023-eu-eidas-feedback/

#EU
#privacy
#security
#webdev
#eIDAS

shortridge, to security
@shortridge@hachyderm.io avatar

went down to the hotel lobby to retrieve my dinner delivery in a yoga outfit + snuggly cardigan + face mask.

some men with #RSAC2024 lanyards exited the elevator as I re-entered; they turned back to look at me and one said (very loudly, very pointedly staring at me) to the other, “I was like, did you hire me a hooker?”

if you are a man attending #rsac, please shut that kind of shit down when your peers do it. let’s not let insecurity rule our #security industry.

fedora, to fedora
@fedora@fosstodon.org avatar

🚨 ⚠️ Emergency PSA: A critical security exploit was discovered in the xz package recently, used for compression and decompression on nearly all Linux distributions.

Rawhide users ARE impacted and should immediately STOP using Rawhide until the package update is fully rolled back. (1/3)

Security Advisory: https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users

#Fedora #Linux #OpenSource #Security #Privacy

archlinux, (edited ) to random
@archlinux@fosstodon.org avatar

Upgrade your systems now!

The xz package has been backdoored

https://archlinux.org/news/the-xz-package-has-been-backdoored/

#ArchLinux #Linux #xz #security

johnpettigrew, to ai
@johnpettigrew@wandering.shop avatar

For those of you who use LLMs to help you code, here's a warning: these tools have been shown to hallucinate packages in a way that allows an attacker to poison your application. https://www.theregister.com/2024/03/28/ai_bots_hallucinate_software_packages/ #ai #gpt #chatgpt #security

dethos, to security
@dethos@s.ovalerio.net avatar

"Firefox 115 can silently remotely disable (any) extension on any site"

https://lapcatsoftware.com/articles/2023/7/1.html

#security #privacy #firefox #wtf

linuxtechmore, to firefox
@linuxtechmore@linuxrocks.online avatar

✍️ Firefox Isn't Just a Browser; It Is a Web Resistance, and It's Now at Version 119

I'm baffled as to why Google Chrome still dominates the browser market when Firefox, a faster and privacy-conscious open-source browser, is readily available!

In the previous update, Firefox introduced a long-awaited feature – an automatic and customizable built-in translation. With this addition, Firefox fills a significant gap that was once held against it.

Now, with the latest update, Firefox 119 not only surpasses Chrome (I'm confident it does) but also competes with PDF editors. With great excitement, let's explore what this latest version has in store.

https://www.linuxtechmore.com/2023/10/what-is-new-in-firefox-119.html

AnthonyCollette, to LEGO

From Polish cybersecurity expert Jakub Płuska, this fun SOC LEGO set concept. Gotta love those facial expressions!

dansup, to Pixelfed
@dansup@mastodon.social avatar

🚨 Pixelfed admins: please update ASAP to v0.11.11

More information will be published on Feb 25 to give admins time to update.

https://github.com/pixelfed/pixelfed/security/advisories/GHSA-gccq-h3xj-jgvf

kitoconnell, to security
@kitoconnell@kolektiva.social avatar

Y'all know not to use #Temu right? Right???

Temu app contains ‘most dangerous’ #spyware in circulation: class action lawsuit | Fashion Dive
https://www.fashiondive.com/news/temu-class-action-lawsuit-data-collection/699328/

#security

Em0nM4stodon, to privacy

Obligated periodic reminder
that I am currently Looking for Work! ✨

Remotely from Canada 🇨🇦
(ideally, but flexible)

At a great organization 💚
(this matters more to me than the position)

Related to one of those fields:
#Privacy #Security #Tech #DigitalRights #HumanRights #Python

Check this post for more details: https://infosec.exchange/@Em0nM4stodon/111054547728861638

#GetFediHired #FediHired #JobSearch #LookingForWork

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • magazineikmin
  • Durango
  • Youngstown
  • ngwrru68w68
  • slotface
  • ethstaker
  • everett
  • khanakhh
  • kavyap
  • DreamBathrooms
  • thenastyranch
  • cisconetworking
  • rosin
  • anitta
  • cubers
  • GTA5RPClips
  • mdbf
  • tacticalgear
  • osvaldo12
  • InstantRegret
  • provamag3
  • normalnudes
  • tester
  • Leos
  • modclub
  • megavids
  • lostlight
  • All magazines