simplenomad, to iOS
@simplenomad@rigor-mortis.nmrc.org avatar

Curious. Any fave #iOS apps for #InfoSec and #hackers? Getting a new #iPhone 15 soon and thought I’d refresh my existing apps list.

And yes I’ll take #Android recommendations too, as I have both.

Blog post coming that’s related, but appreciate any interesting ideas/recommendations to help spice things up.

tdp_org, to infosec
@tdp_org@mastodon.social avatar

Very interesting info on modern password cracking using PassGAN (https://arxiv.org/abs/1709.00440).
I can't vouch for this but also have no reason to doubt it.

https://www.homesecurityheroes.com/ai-password-cracking/

#infoSec #security #AI

shellsharks, to infosec

For folks out there, what’s your routine/strategy for “staying current” in the field? I’ve written about my daily reading routine here for anyone interested.

https://shellsharks.com/notes/2023/11/06/keeping-current-in-infosec

catsalad, (edited ) to DEFCON

InfoSec Events by Region

This list only contains accounts for security bsides, events, and conferences found in the fediverse / :mastodon: with some post history. I will regular update this post as more events migrate here. For hacker meet-ups and local DEFCON / 2600 groups, please refer to the link below.

📌⁠Bsides & InfoSec Cons by Region
📌⁠Hacker Meet-ups by Region
📌⁠Hackerspaces by Region

🐈🥗

⸻ Event Info

@cfp_time - Call for Papers ()
@SecurityBSidesGlobal - Security BSides Global

⸻ Online 🌐

@ComfyConAU -
@Digit4lOverdose - D.O. Conference
@pancakescon -

⸻ Canada 🇨🇦

@BSidesVI - , Vancouver Island
@hackfest - , Quebec City
@halifaxbsides - , Nova Scotia
@thelongcon - , Winnipeg
@polar - POLAR Conf, Quebec

⸻ US - Northeast

@bsidesboston - , Boston, MA
@BSidesBuffalo - , Buffalo, NY
@BSidesCambridgeMA - , Cambridge, MA
@BSidesCharm - , Towson, MD
@BSidesNYC - , New York City, NY
@bsidesphilly - , Philadelphia, PA
@bsidespgh - , Pittsburgh, PA
@bsidesroc - , Rochester, NY
@hushcon - , New York City, NY
@ShmooCon - , Washington, DC

⸻ US - Midwest

@BlueTeamCon - , Chicago, IL
@bsides312 - , Chicago, IL
@BSides_BTown - , Bloomington, IN
@bsidesboulder - , Boulder, CO
@bsideschicago - , Chicago, IL
@bsidesdayton - , Dayton, OH
@bsidesdenver - , Denver, CO
@bsideskc - , Kansas City, MO
@bsidesspfd - , Springfield, MO
@CircleCityCon - , Indianapolis, IN
@CypherCon - , Milwaukee, WI
@thotcon - , Chicago, IL
@WWHackinFest - , Deadwood, SD

⸻ US - West

@bsidescv - , Central Valley, CA
@bsidesla - , Los Angeles, CA
@BSidesPDX - , Portland, OR
@BsidesSD - , San Diego, CA
@bsidesseattle - , Seattle, WA
@bsidessf - , San Francisco, CA
@soups - Symposium on Usable Privacy and Security, Anaheim, CA

⸻ US - Southwest

@bsidesaustin - , Austin, TX
@BSidesDFW - , Dallas-Fort Worth, TX
@BSidesLV - , Las Vegas, NV
@BSidesSATX - , San Antonio, TX
@cactuscon - , Mesa, AZ
@defcon - , Las Vegas, NV
@DianaInitiative - , Las Vegas, NV

⸻ US - Southeast

@bsidesatl - , Atlanta, GA
@BSidesAugusta - , Augusta, GA
@BSidesCharleston - , Charleston, SC
@BSidesCLT - , Charlotte, NC
@BSidesCharlotte - , Charlotte, NC
@bsidesknoxville - , Knoxville, TN
@bsidesorlando - , Orlando, FL
@BSidesRDU - , Raleigh/Durham, NC
@bsidesSTL - , St. Louis, MO
@CackalackyCon - Con, Raleigh, NC
@CYBERWARCON - , Arlington, VA
@securityonion - Con, Augusta, GA

⸻ Latin America

@bsidescdmx - , Mexico City, MX 🇲🇽
@bsidesjp - , João Pessoa, BR 🇧🇷

⸻ Europe 🇪🇺

@bsideskbh - , København, DK 🇩🇰
@bsideslisbon - , Lisbon, PT 🇵🇹
@bsidesljubljana - , Ljubljana, SI 🇸🇮
@bsidesoslo - , Oslo, NO 🇳🇴
@bsidesrvk - , Reykjavik, IS 🇮🇸
@BSidesSOF - , Sofia, BG 🇧🇬
@bsidesvienna - , Vienna, AT 🇦🇹
@BSidesZurich - , Zurich, CH 🇨🇭
@deepsec - Con, Vienna, AT 🇦🇹
@hack_lu - , LU 🇱🇺
@passthesaltcon - Pass the SALT Con, Lille, FR 🇫🇷
@securitybsidesitalia - , IT 🇮🇹
@TumpiConIT - , Turin area, IT 🇮🇹

⸻ Germany 🇩🇪

@BSidesMunich - , Munich
@elbsides - , Hamburg
@WEareTROOPERS - TROOPERS Conference, Heidelberg

⸻ United Kingdom 🇬🇧

@44CON - , London 🏴󠁧󠁢󠁥󠁮󠁧󠁿
@BSidesBHAM - , Birmingham 🏴󠁧󠁢󠁥󠁮󠁧󠁿
@BSidesCheltenham - , Cheltenham 🏴󠁧󠁢󠁥󠁮󠁧󠁿
@bsidesleeds - , Leeds 🏴󠁧󠁢󠁥󠁮󠁧󠁿
@VirusBulletin - VirusBulletin, London 🏴󠁧󠁢󠁥󠁮󠁧󠁿

⸻ India 🇮🇳

@BSidesBangalore - , Bangalore
@bsidesodisha - , Odisha

⸻ Australia 🇦🇺

@bsides_bne - , Brisbane
@bsidescbr - , Canberra
@bsidesmelbourne - , Melbourne
@bsidesperth - , Perth
@bsidessydney - , Sydney
@crikeycon - , Brisbane

For other events not in the fediverse try:
➡️⁠https://securitybsides.com
➡️⁠https://github.com/xsa/infosec-events by Xavier Santolaria @0x58

Feel free use, copy, modify, steal, boost, encrypt, or plagiarize this information anyway you want.
:cc_cc:​𝟶 "No Rights Reserved"

rml, to infosec

Are there any interesting #redteam or offensive security reports on cracking #guix or #nixos? I've always been curious what kind of challenges it would present in practice/how much difficulty the immutable store and containerization of packages would really pose, or if there are minor faults throughout the codebase they can easily be tracked down and exploit for professionals. But haven't found any good posts on the matter.

#opsec #infosec #linux

simplenomad, to infosec
@simplenomad@rigor-mortis.nmrc.org avatar

Genuinely curious about this. I have heard from a few people that Summer Camp 2023 wasn't that good. Like, at all. Many people are talking about going next year, skipping the cons, and just having dinner with friends, or skipping Vegas entirely. Do others feel this way? Is this bitterness over a lack of an electronic badge, long lines, and overcrowded events in general? Or is this just old school hackers bitching? Inquiring minds want to know.

#infosec #hacker #summercamp #defcon

mattburgess, to tech

The UK is now building a national system to allow police to access and inspect people's internet history

In 2016, the government passed the Investigatory Powers Act, also known as the Snooper's Charter

The law says telecoms companies can be made to collection people's 'internet connection records' and store them for up to a year

Internet connection records are essentially the websites you visit, but not the individual pages upon them

For the last few months, the UK has been creating a 'national' system that will allow law enforcement to access and 'filter' internet connection records

An initial police trial of the records has found “significant operational benefit”

https://www.wired.com/story/internet-connection-records-uk-surveillance/

#tech #news #privacy #surveillance #infosec

InfoSecSherpa, to infosec

For once, please, can we as an #InfoSec community please NOT be total knobs when it comes to Cybersecurity Awareness Month?

People work hard to produce these programs, tips, and other events.

If our users see security practitioners not taking it seriously and crapping on it, WTF kind of message do you think that sends to end users … AND THEN users get made fun of. 🤦‍♀️

So, this October, be a part of the solution and not the problem.

Don’t make me turn this car around.

rysiek, to webdev
@rysiek@mstdn.social avatar

Hey #WebDev #SysAdmin #InfoSec (yeah, we got the trifecta here!), who remembers CloudFlare's Keyless SSL?
https://www.cloudflare.com/learning/ssl/keyless-ssl/

As much as I loathe CloudFlare itself, this idea is pretty damn neat. I know of two reference implementations, both by CloudFlare, both non-FOSS:
https://github.com/cloudflare/keyless
https://github.com/cloudflare/gokeyless/

So here's my question: does anyone know of an independent, #FLOSS implementation of it? Anyone, perhaps, running it?

Thanks!

:boost_requested:

maxleibman, to infosec
@maxleibman@mastodon.social avatar

Some password advice from an infosec professional:

Good password hygiene means choosing a password that is hard to guess.

One that's hard to type. Hard to remember. Hard to think about. Hard to LOOK at.

A password that makes you feel disoriented, uncomfortable.

In short, your password should be a Cthulhu.

chiefgyk3d, to infosec
@chiefgyk3d@social.chiefgyk3d.com avatar

Just fixed my @Efani dashboard issues, support was great. So now that I have access to my dashboard some notes for #Efani

TOTP Code generation shouldn't just be QR, you should also allow the string of text to be manually input. I had to use zbarimg to convert the QR code to text to input into my @yubico security key and vault for TOTP generation.
You should also add FIDO/WebAuthn support. TOTP has a single seed, so if stolen they have access. #infosec #Cybersecurity #SIMSwap #cellphone

InfoSecSherpa, to infosec

You know you will be asked about #InfoSec topics in the news during your #Thanksgiving observance. Why not have some fun with it? See if you get a bingo talking to family and friends. 🦃🍽️

Get more here:
https://myfreebingocards.com/bingo-card-generator/30-free-cards/gazyvtk

reginagrogan, (edited ) to mastodon
@reginagrogan@mastodon.social avatar

Something happened and i want to ask the about it:

1 hour ago, i wanted to get a chocolate bar and a lemonade, so i went to the fancy grocery store…

As i was standing in the aisle picking a chocolate bar, a man down the way faced me and took several phone pictures of me.

Why did he?
Please answer below or in comments.

Wander, to privacy
@Wander@packmates.org avatar

Federated wireguard network idea
Any feedback welcome.

Let's keep things stupidly simple and simply hash the domain name to get a unique IPv6 ULA prefix.

Then we would need a stupidly simple backend application to automatically fetch pubkeys and endpoints from DNS and make a request to add each others as peers.

Et voilà, you got a worldwide federated wireguard network resolving private ULA addresses. Sort of an internet on top of the internet .

The DNS entries with the public IPv4 / IPv6 addresses could even be delegated to other domains / endpoints which would act as reverse proxy (either routing or nesting tunnels) for further privacy.

Maybe my approach is too naïve and there are flaws I haven't considered, so don't be afraid to comment.

Exact use cases? Idk, but it sounds nifty.

cc: @fediverse

chiefgyk3d, to Twitch
@chiefgyk3d@social.chiefgyk3d.com avatar

#Start9 sent me their Server Pure for a review. They appear to be based on the @purism Librem Mini computers. Intel ME is disabled out of the box. I will have to tinker with this on #twitch tomorrow live but their StartOS seems to be great for those starting to do a #homelab and they are all about data sovereignty and you owning your data. It has options to setup #Mastodon and #Matrix out the box as well as #bitcoin and #monero nodes with #tor as well.

#privacy #infosec #cybersecurity #review

Front of Server Pure with 2 x USB 3 ports and 2 x USB 2 ports, head phone Jack and power
Back I/O of server pure with AC power, Ethernet, 2 x USB 3 ports, HDMI, DisplayPort, and USB Type C

PogoWasRight, (edited ) to Cybersecurity

ICYMI: I interviewed the hacker known as "USDoD" who was responsible for the InfraGard incident last year, as well as the recent Airbus and TransUnion breaches. He tells me he's been busy targeting NATO, Europol, CEPOL, and Interpol. He's an ambitious hacker and is really going after U.S. military intelligence in his own way and for his own endgame purposes.

Why does he tell us his targets? For the challenge -- he wants to beat his targets when they know he's coming.

Read what he told me in “I’m Not Pro-Russia and I’m Not a Terrorist!” —- InfraGard and Airbus Hacker 'USDoD' Unveils His New Campaigns:"

https://www.databreaches.net/im-not-pro-russia-and-im-not-a-terrorist-infragard-and-airbus-hacker-usdod-unveils-his-new-campaigns/

On a positive note, it appears that NATO detected him when he attempted to gain access to an internal area; part of their site has now been "under maintenance" for days.

How serious a threat is he really? I can't judge that -- maybe you can.

#NatSec #cybersecurity #intel #socialengineering #hacker #databreach #defense #USDoD #InfraGard #InfoSec

majorlinux, to apple
@majorlinux@toot.majorshouse.com avatar

I wonder how hard this will hit 2FA usage going forward.

Authy to sunset desktop apps - Desk Chair Analysts

https://dcanalysts.net/authy-to-sunset-desktop-apps/

#2FA #Apple #Authy #Desktop #InfoSec #Microsoft #mobile #PC #Linux #Security #TechNews #DCA

simplenomad, to infosec
@simplenomad@rigor-mortis.nmrc.org avatar

@joshbressers @kurtseifried I just listened to the latest episode of the Open Source Security podcast. Rather entertaining listening to you two go back and forth. I was rather intrigued with the notion that it really isn't "supply chain" in the traditional sense - particularly in this cut-and-paste-from-stackoverflow world. Also interesting since a library or package might be listed as a component but either the vuln part of that component is never called or even never used. Interesting to think about (and we're still just talking about security, skipping the whole privacy elements aka "features" in this altogether).

#infosec #opensource

https://opensourcesecurity.io/2023/10/22/episode-398-is-only-11-of-open-source-mainted/

jkirk, to infosec

Service NSW says starting tomorrow it will scan the "Dark Web" for the email/password combination people use to log in and alert users if it finds that the credentials have leaked. I wonder what service provider it is using for this. #infosec #Australia

Freyja, (edited ) to random French
@Freyja@eldritch.cafe avatar

Vous avez un compte sur LDLC?

Une base de données d'1,5M d'utilisateurs est en vente.

Attention au risque de phishing.

Les données fuitées sont :

  • Civilité
  • Prénom
  • Nom
  • Email
  • Tel portable et fixe
  • Adresse
  • etc.

#infosec #leak #ldlc

EDIT: même s'il n’apparaît pas dans le leak, le conseil de changer le mot de passe reste important.

Crédits: https://twitter.com/

rysiek, to fediverse
@rysiek@mstdn.social avatar

Dear #Fediverse #InfoSec #Privacy folks, if anybody knows of any peer reviewed papers, official reports, etc., on how ad networks are or have been used by malicious actors to target specific people or groups — with malware, but also with targeted surveillance — I would love to hear.

I'm talking beyond "mere" surveillance capitalism. Surveillance capitalism is bad enough, of course, but in this particular case I am looking specifically for stuff that goes beyond "just" targeting ads.

:boost_ok:

jfkimmes, to infosec

Hi fediverse: Can you recommend "hacker type" people, who still actively post here?

Doesn't have to be particularly infosec related, I simply want my timeline to be filled with more technical/interesting/clever/creative hacker mindset stuff.

Please boost for exposure :)

zersiax, to accessibility

Halfway considering doing streams/videos where I go through #tryHackMe #AdventOfCyber 2023 with a #screenReader to illustrate what #accessibility challenges exist and how we #hack our way around them. Honestly not sure if literally anyone would be interested in seeing that though #infoSec #imposterSyndrome #ContentCreator #blind #streamer

WPalant, to infosec

The questions I want answered for any cloud-based password manager:

· Is its encryption approach sane?
· Does the server have access to any plaintext data?
· Can the server manipulate the data?
· Are users being aided in creating safe credentials?
· Do encryption keys or their components ever leave user’s computer?
· Are there encryption backdoors meant to aid account recovery for example?
· Is the client-side software safe from web-based attacks?
· Are there precautions in place to avoid filling in passwords on the wrong websites?
· Are there precautions in place to avoid filling in passwords on compromised websites without user’s knowledge?
· …

The questions media coverage tends to focus on:

· Are there plain text passwords in memory that someone with administrator privileges on user’s machine could read out?

#InfoSec #ApplicationSecurity #PasswordManager

PogoWasRight, to SEC
  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • everett
  • magazineikmin
  • mdbf
  • thenastyranch
  • khanakhh
  • rosin
  • Youngstown
  • ethstaker
  • slotface
  • modclub
  • kavyap
  • DreamBathrooms
  • Durango
  • provamag3
  • ngwrru68w68
  • InstantRegret
  • tacticalgear
  • GTA5RPClips
  • cubers
  • normalnudes
  • osvaldo12
  • tester
  • anitta
  • cisconetworking
  • megavids
  • Leos
  • lostlight
  • All magazines