kuketzblog, to android German
@kuketzblog@social.tchncs.de avatar

Meine Beobachtungen zeigen, dass Certificate-Pinning bei Apps nicht immer als Schutzmechanismus eingesetzt wird, sondern häufig dazu dient, rechtlich fragwürdige Praktiken und (kalkulierte) Datenschutzverstöße zu verschleiern. Auszug aus dem demnächst erscheinenden Artikel »In den Datenstrom eintauchen: Ein Werkzeugkasten für Tester von Android-Apps«.

bagder, to apple
@bagder@mastodon.social avatar

the incident 12604 - or why CA cert verification is unreliable with curl on apple OS

https://daniel.haxx.se/blog/2024/03/08/the-apple-curl-security-incident-12604/

slink, (edited )
@slink@fosstodon.org avatar

@bagder daniel, i respect and admire you for your considerate and respectful behavior, but would it be appropriate to point out the potential of unintended interception more clearly in this case?
i mean, the title could also have been "apple does not want you to notice when you are being wiretapped", or do i miss any other precaution they took for this not to happen?

also, i find it shocking that i don't find this shocking any more… 🤯

slink, to random
@slink@fosstodon.org avatar
scott, to security
@scott@tams.tech avatar

So I think my partner @owen is experiencing a @signalapp attack... I suspect on the part of the phone manufacturer,

How can I...I don't know, prove this? Fix it?

Here's what I did so far to troubleshoot:

  • @owen received a new phone, a Unihertz Atom L, and switched his Signal over to it. As I try to make a habit of, I called him over to verify our "security number". The check failed. The first sign of trouble.

1/3

HonkHase, to random German
@HonkHase@chaos.social avatar

2.0: EU-Regulierung könnte HTTPS- ermöglichen

"Die EU will Browser zur Nutzung möglicherweise unsicherer staatlicher Zertifikate zwingen. Sicherheitsexperten befürchten ."
https://www.golem.de/news/eidas-2-0-eu-regulierung-koennte-staatliche-https-mitm-ermoeglichen-2311-179225.html

Tutanota, to privacy
@Tutanota@mastodon.social avatar

The new tuta.com email domain will be available soon to everyone using one of our new subscription plans!😎

Be quick and create your favorite new address as soon as they go live. Shorter addresses are sure to be gone fast!🏃‍♀️💨

kkarhan,
@kkarhan@mstdn.social avatar

@Tutanota @protonmail The problem is more like "fiddling with the contents" or doing anything in transit.

Cuz I do #E2EE the way it's meant to be done aka. #SelfCustody of #Keys and not some #MITM'ing "Appliance"...

RTP, to news
@RTP@fosstodon.org avatar
madargon, to announcement
@madargon@is-a.cat avatar

It's official :blobcatbolbscream:​

No, I am NOT doing .

I am too busy being a on fedi :blobcatadorablepink:​

jabberati, to random
@jabberati@social.anoxinon.de avatar

Mitigating the Hetzner/Linode XMPP.ru MitM interception incident, part 2: XMPP-specific mitigations

https://www.devever.net/~hl/xmpp-incident-2

xmpp, (edited ) to security
@xmpp@fosstodon.org avatar

Announcement

Recently there was an incident via a so called attack happened to an .

To reduce the risk of such attacks in the future an early stage service called CertWatch has been published by our Community: https://certwatch.xmpp.net/

Many thanks to Stephen P. Weber (@singpolyma)!

Read two related blog posts:
http://blog.jmp.chat/b/certwatch/certwatch

https://snikket.org/blog/on-the-jabber-ru-mitm/

br00t4c, to australia
@br00t4c@mastodon.social avatar

Not one Australian company has been fined despite 1,748 data breaches in 2 years

https://www.crikey.com.au/2023/10/24/data-breach-no-fines-australia-privacy-information-commissioner/

dsfgs,

@br00t4c
Meanwhile the news outlet above is being man-in-the-middled by Cloud(G)lare. We hope that no one thinks the password they use to access that outlet is protected by the padlock they see.

The problem has been documented from as far back as 2017 but the calls by privacy activists have fallen on corrupted ears.

The way Medibank is still 'd by military-contracted 'scam'azon

jabberati, to random
@jabberati@social.anoxinon.de avatar

Machine-in-the-middle Detection and Monitoring for #XMPP Servers

https://certwatch.xmpp.net/

This service allows you to check your XMPP server's #TLS setup, helps you publicly store the hash of the public key in a secure way, and then monitors your server to make sure that connections to it get the same public key that you have configured and sends notifications if anything changes (which may indicate a #mitm attack on your service).

slink, to Amazon German
@slink@fosstodon.org avatar

http://blog.fefe.de/?ts=9bcd85f0 http://blog.fefe.de/?ts=9bcc0e4b http://blog.fefe.de/?ts=9bcc02f4 http://blog.fefe.de/?ts=9bcc63d0 - lesen lohnt sich heute mal wieder besonders. setzt euch lieber auf den boden, damit ihr nicht vom stuhl fallt. oder meinetwegen aufs klo

scy, (edited ) to Germany
@scy@chaos.social avatar

Interesting. Apparently, both 's and 's German datacenters were used to connections to jabber.ru servers hosted there. There's a detailed postmortem here:
https://notes.valdikss.org.ru/jabber.ru-mitm/

I'd take these allegations with a grain of salt. But I must say that MitM'ing with a certificate and then forgetting to renew it, leading to discovery, sounds like the most German law enforcement thing ever.

via https://devco.social/@ripienaar/111268338360338392

scy,
@scy@chaos.social avatar

A very good (but also pretty long) post on how this attack could have possibly been detected and probably been mitigated:
https://www.devever.net/~hl/xmpp-incident

via https://chaos.social/@lasagne/111273031750419721

ge0rg, (edited ) to random
@ge0rg@chaos.social avatar

Detailed and credible looking report of on an server hosted at in Germany: https://notes.valdikss.org.ru/jabber.ru-mitm/

Looks like a transparent bridge was deployed in front of the actual server, obtained dedicated certificates from and MitMed all incoming client connections since July. It was discovered because the LE certificate expired 🤦

BishopFox, to random

FinServ orgs prioritize #cloud vulnerabilities as their top cyber #threat driving #offensivesecurity investments (45%), followed by preventing #DDoS attacks (36%) and #MiTM attacks (28%). Get more insight into #offsec as it pertains to #financialservices in our report with the #PonemonInstitute.

https://bfx.social/46Tzo9G

heiseonline, to news German

KI-Algorithmus kann Cyberattacken auf Militärroboter abwehren

Wissenschaftler haben eine Möglichkeit gefunden, Cyberattacken auf Robotersysteme zu verhindern. Sie nutzen dazu Deep Learning.

https://www.heise.de/news/KI-Algorithmus-kann-Cyberattacken-auf-Militaerroboter-abwehren-9333638.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

marcel,
@marcel@waldvogel.family avatar

@heiseonline Verhinderung von ist ein Problem, was sich exakt lösen kann (Verschlüsselung, Zertifikate, …). Wieso bitte braucht man dazu ? 🤯

leyrer, to random
@leyrer@chaos.social avatar

Irgendjemand aus meiner Bubble auf der "it-sa" in Nürnberg mit einer Einordnung bzw. mit einer Meinung zu dieser "Security" Messe?

kkarhan,
@kkarhan@mstdn.social avatar

@nightlynx @leyrer Auch mein Eindruck basierend auf dem Traffic den die auf macht...

Verzichtbar für alle die kein verkaufen oder kaufen wollen, denn da bieten einem drölfzig Marken denselben von wegen "Installier' unseren Kernelhack in dein --OS um dieses sicher zu machen oder schieb' dir gleich unsere - im 19"-Format ins LAN und |e deinen gesamten -Traffic onsite für umfangreiche Verarsche und Pseudosicherheit!"

ankit_anubhav, to Cybersecurity

Box.com hosting a page which goes to Cloudflare protected /

As usual, the whole trust on corporate URLs is going down big time. I have seen abuses on Microsoft,LinkedIn,Notion,Box and Zoho in a matter of couple of days.

hxxps[://]app[.]box[.]com/s/dzgbby3z63ofzqiunq749m9hfiv5qp3g

ankit_anubhav, to Cybersecurity

phishing hosted on notion. If you have kept notion in some whitelist do reconsider.

hxxps[://]vigorous-harbor-449[.]notion[.]site/CONFIDENTIAL-DOCUMENT-b6e34d5a4532410598073a639f23fec3

cc @da_667 @GossiTheDog

image/png

witchescauldron, to diy

#modteam this instance will be shutting down in a month due to no funding coming in from donations. The has been a year of messaging on this, it's finally time to shut the instance down https://opencollective.com/open-media-network/contribute

Social change is a social thing #DIY is never free, but yes it's low cost.

dsfgs,

HELP! This instance will close down in one month without funds.

WORKING BEE

We're donating 10 SOLID HOURS of VISUAL DESIGN WORK as pro-designers ready to work for a AUD$250+ donation for this great instance. No email pls, DMs only! *some work pictured

Help 'activism' open-worlds to those who need it.

BOOST to help a miracle happen. Maybe such miracles are only reserved for those with () "connections"?

@witchescauldron

image/png
image/png
image/png

changelog, to security
@changelog@changelog.social avatar

A MITM-based HTTP(s) proxy for blocking ads & trackers that's "way more capable than DNS-based blockers"

🔗 https://github.com/Barre/privaxy

lispi314, to random
@lispi314@mastodon.top avatar

Something's going on with exit nodes again. Higher than normal rate of attempts at interfering with my HTTPS connections.

lispi314,
@lispi314@mastodon.top avatar

@RecursiveElegance Not sure where in particular, most of my old resources seem to be gone now.

But generally for users it's an annoyance as its anti-bot measures are very user-hostile.

It also makes mandatory to enable in one's , which in general but especially in conjunction with is a hazard.

Depending on the settings used, it can also act as a general attacker.

strypey, to random

Using CloudFlare and other corporate MitM "services" to protect your server against DDOS attacks? Looking for an ethical replacement? Cory Doctorow is using Deflect for pluralistic.net:

https://deflect.ca/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • kavyap
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • osvaldo12
  • khanakhh
  • Youngstown
  • mdbf
  • slotface
  • rosin
  • everett
  • ngwrru68w68
  • Durango
  • anitta
  • InstantRegret
  • GTA5RPClips
  • cubers
  • ethstaker
  • normalnudes
  • tacticalgear
  • cisconetworking
  • tester
  • Leos
  • modclub
  • megavids
  • provamag3
  • lostlight
  • All magazines