nikahverse, to tech

This is outrageous!

Smartphones with Qualcomm chip secretly send personal data to Qualcomm

https://www.nitrokey.com/news/2023/smartphones-popular-qualcomm-chip-secretly-share-private-information-us-chip-maker

#privacy #security #news #tech

encthenet, to infosec
@encthenet@flyovercountry.social avatar

Just a reminder, if your 2FA codes are stored in your cloud provider along with the passwords, you don't have 2FA anymore.

Do NOT turn on Google Authenticator sync as it significantly decreases your security and apparently gives Google access to them..

If you want to backup your codes, buy a dedicated memory card for your point and shoot camera, and take photos of the QR codes obtained via Transfer accounts -> Export accounts.

#InfoSec #Security #2FA

adingbatponder, to linux
@adingbatponder@fosstodon.org avatar

If you wanted to protect a high availability or similar from , would it be advantageous and possible to use sufficiently different versions for each so that not all nodes have the same . Which Linux versions would be most different & so most unlikely to suffer the same vulnerabilities or yet work together somehow? Would using a node with an node & an node offer any advantages?

kylewritescode, to random
@kylewritescode@allthingstech.social avatar

Seriously thinking about getting a @protonmail account.

Just trying to muster up the boldest to face the wife about another monthly expense.

#ProtonMail #Security

LauraPaxton, to random

No, no, noo, not keeping logs isn't irresponsible, it's part of DLP!

#cyber #DLP #security

cryptomator, to opensource
@cryptomator@mastodon.online avatar

Almost 5 years ago, when Android was still Open Core, a user submitted a request to add it to the store.

Using reproducible builds, Cryptomator is finally in the main F-Droid repo 🥳 🎉

See https://docs.cryptomator.org/en/latest/android/setup/ for a detailed description of all variants.

dansup, to random
@dansup@mastodon.social avatar

Just shipped some improvements to sudo mode, 2fa checkpoint and password resets, besides the redesigned layouts, it now features optional captcha support and implements a random sleep timeout to make brute forcing less useful!

#pixelfed #pixeldev #security

mysk, to infosec

Google has just updated its 2FA Authenticator app and added a much-needed feature: the ability to sync secrets across devices.

TL;DR: Don't turn it on.

The new update allows users to sign in with their Google Account and sync 2FA secrets across their iOS and Android devices.

We analyzed the network traffic when the app syncs the secrets, and it turns out the traffic is not end-to-end encrypted. As shown in the screenshots, this means that Google can see the secrets, likely even while they’re stored on their servers. There is no option to add a passphrase to protect the secrets, to make them accessible only by the user.

Why is this bad?

Every 2FA QR code contains a secret, or a seed, that’s used to generate the one-time codes. If someone else knows the secret, they can generate the same one-time codes and defeat 2FA protections. So, if there’s ever a data breach or if someone obtains access .... 🧵

#Privacy #Cybersecurity #InfoSec #2FA #Google #Security

image/jpeg
image/png
image/png

mysk,

.... if someone obtains access to your Google Account, all of your 2FA secrets would be compromised.

Also, 2FA QR codes typically contain other information such as account name and the name of the service (e.g. Twitter, Amazon, etc). Since Google can see all this data, it knows which online services you use, and could potentially use this information for personalized ads.
Surprisingly, Google data exports do not include the 2FA secrets that are stored in the user's Google Account. We downloaded all the data associated with the Google account we used, and we found no traces of the 2FA secrets.

The bottom line: although syncing 2FA secrets across devices is convenient, it comes at the expense of your privacy. Fortunately, Google Authenticator still offers the option to use the app without signing in or syncing secrets. We recommend using the app without the new syncing feature for now.

#Privacy #Cybersecurity #InfoSec #2FA #Google #Security

germanio, to random
@germanio@mastodon.social avatar

Today I learned about the Web Authentication API (WebAuthn):

https://webauthn.guide/

A way to authenticate to sites with public key cryptography (no passwords sent).

#security #Web #webauthn #TIL

itnewsbot, to tech
@itnewsbot@schleuss.online avatar

Zero trust for Zoom calls: ChromeOS getting universal microphone/camera toggles - Enlarge / Rather than app-by-app permissions that are set once, ChromeO... - https://arstechnica.com/?p=1934169 #chromebooks #webmeetings #microphone #videocalls #chromeos #security #privacy #camera #tech #zoom

hehemrin, to random

Mobile phone data leakage to Qualcomm, and more. I hope I will read a blog post or comment from @e_mydata and any action. I would also like to read a view from @volla in respect to their hw and sw (not a topic in the article). #security #privacy #mobile https://www.nitrokey.com/news/2023/smartphones-popular-qualcomm-chip-secretly-share-private-information-us-chip-maker

paninid, to random
@paninid@mastodon.world avatar

“It’s really frustrating: I want to build cool things on top of LLMs, but a lot of the more ambitious things I want to build—the things that other people are enthusiastically exploring already—become a lot less interesting to me if I can’t protect them against being exploited.” - @simon

https://simonwillison.net/2023/Apr/14/worst-that-can-happen/

#LLMs #promptengineering #promptinjection #exploit #security #productdevelopment

TiffyBelle, to infosec

ESET buys 18 corporate routers, over half contain "a treasure trove of sensitive data... including corporate credentials, VPN details, cryptographic keys, and more."

https://www.pcmag.com/news/yikes-corporate-routers-are-being-resold-before-sensitive-data-is-wiped

Seems a surprising number of organizations don't have robust hardware decommissioning policies in place, or are overlooking network infrastructure equipment.

@infosec #InfoSec #Security #Hardware #Tech #Cybersecurity

debacle, to random
@debacle@framapiaf.org avatar

Wow, this might even affect #MobileLinux, such as #Mobian or #PureOS, doesn't it?

"#Smartphone​s With Popular #Qualcomm Chip Secretly Share Private Information With US Chip-Maker"

https://www.nitrokey.com/news/2023/smartphones-popular-qualcomm-chip-secretly-share-private-information-us-chip-maker

#Nitrokey #privacy #security #LinuxOnMobile

TiffyBelle, to infosec

This is a great series of articles by security researcher Mike Kuketz that documents the data transmission behavior of popular web browsers on their default settings, examining the type of connections they make and what data they "phone home" with:

https://www.kuketz-blog.de/brave-datensendeverhalten-desktop-version-browser-check-teil1/

For privacy, even on so-called privacy-respecting browsers, it's important to take time to tweak their configs properly.

#InfoSec #Security #Privacy #Firefox #Chrome #Brave #CyberSecurity #Tracking #Tech #Browser

kusuriya, to random

Please check your dot files for passwords and other secrets, do it today! If you find any rotate them and remove it from that file. If you ever checked them into source control like git, upload the new copy too.Sectets belong in a keyring, vault, or password manager not some random file on your disk. If you need them in your shell for one reason or another check out what APIs or CLIs your password manager or OS keyring may provide, with a bit of scripting you will get far #Security #passwordhygiene #Shells #dotfiles

Natanox, to random
@Natanox@chaos.social avatar

Smartphones using the Snapdragon 630 chip were found to call home to Qualcomm without the consent of the user, bypassing the whole operating system. Data includes unique hardware ID, current IP, country, your ISP, list of installed apps and other data.

It is send unencrypted and gets combined with data broker profiles.
https://www.nitrokey.com/news/2023/smartphones-popular-qualcomm-chip-secretly-share-private-information-us-chip-maker

As usual, big IT companies don't give a flying fart about any laws, their customers or ethics in general. Who would've guessed. 😔 #privacy #security

Natanox,
@Natanox@chaos.social avatar

Also interesting in context:

In 2016 there already was a very similar (perhaps the same) security flaw found in Qualcomm devices: https://wwws.nightwatchcybersecurity.com/2016/12/05/cve-2016-5341/

However, back then it was the a java process on OS level that requested the data, not the firmware.

Should it be true that Qualcomm, instead of fixing the issue properly, simply moved it to a lower level (as @nitrokey implies) this could be huge. Perhaps @kuketzblog is better at analyzing this than me.
#privacy #security #android #qualcomm

Natanox,
@Natanox@chaos.social avatar

To make anyone of you go ballistic on how bad this currently looks, put it into context to what current-gen Qualcomm smartphones are doing:
https://www.theverge.com/22811740/qualcomm-snapdragon-8-gen-1-always-on-camera-privacy-security-concerns

A phone that calls home on hardware level with always-on mic AND cameras and the ability to analyze that data using the inbuilt NPU (Neural Processing Unit)? Oh boy, do I feel safer now.
🔥 :thisisfine: 🔥 🔥
#privacy #security #android #qualcomm #surveillance #SurveillanceCapitalism

kde, to random
@kde@floss.social avatar

g10 Code becomes a KDE patron🎉! g10 Code are the creators and maintainers of #GnuPG, the vital #encryption engine 🔒 that is one of the fundamental technologies that ensures #privacy 🔑 and #security online.

https://dot.kde.org/2023/04/25/g10-code-becomes-kde-patron

blackvoid, to random
@blackvoid@mastodon.social avatar

The new release candidate has arrived! DSM 7.2 - 64551 brings all the features from the beta with a lot of new patches and updates for the various platforms and frameworks that the system is using.

https://www.blackvoid.club/dsm-7-2-release-candidate-rc-is-live

mitexleo, to opensource

I didn't read @bitwarden 's privacy policy and tos when I started to use their services. Honestly, it was a great Mistake !

Read their TOS : https://tosdr.org/en/service/1348

#privacy #foss #bitwarden #password #pass #security

kuketzblog, to random German
@kuketzblog@social.tchncs.de avatar

LineageOS hinterlässt weder einen datenschutzfreundlichen, noch wirklich sicheren Eindruck. Es unternimmt keine besonderen Anstrengungen, um sich von Google abzunabeln. Fairerweise muss man aber auch erwähnen: Das haben sie nie behauptet. 👇

https://www.kuketz-blog.de/lineageos-weder-sicher-noch-datenschutzfreundlich-custom-roms-teil4/

#android #lineageos #security #privacy #datenschutz #sicherheit #google #customrom

Cloudguy, to random

deleted_by_author

  • Loading...
  • dis,

    @Cloudguy as a fun side effect, it "loses" 100% of the privacy and interaction/accessibility settings. Turns off listen "ding" (request sounds), enables the upload-everything "enhancements" (adaptive listening) etc. Anyone resetting Alexa devices should definitely review ALL of the device settings after.

    "Loses" because it keeps all of the convenience settings, volumes, alarms, audio mixer, wifi, etc.. must be an accident that privacy and accessibility are reset, right?

    #amazon #alexa #security #accessibility #privacy

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • magazineikmin
  • Youngstown
  • khanakhh
  • ngwrru68w68
  • slotface
  • ethstaker
  • mdbf
  • everett
  • kavyap
  • DreamBathrooms
  • thenastyranch
  • cisconetworking
  • rosin
  • JUstTest
  • Durango
  • GTA5RPClips
  • Leos
  • tester
  • tacticalgear
  • InstantRegret
  • normalnudes
  • osvaldo12
  • cubers
  • anitta
  • modclub
  • provamag3
  • lostlight
  • All magazines