avoidthehack

@avoidthehack@infosec.exchange

An initiative promoting the intersection of internet #privacy and #cybersecurity for all users.

Based in the USA. 🇺🇸

You’re more than just a data point.

Operated by: https://cyberplace.social/@ashwrites

Established in 2020.

#fedi22 #infosec #opsec

This profile is from a federated server and may be incomplete. Browse more on the original instance.

avoidthehack, to privacy

#ExpressVPN User #Data Exposed Due to Bug

Split tunneling feature has been disabled as it was leaking user #DNS requests - which can be used to ascertain browsing activity to whoever captures the leaked requests - since at least 2022.

Not a #VPN I would recommend for other reasons, but yeah - choose your VPN provider carefully.

#privacy #privacymatters #opsec

https://www.securityweek.com/expressvpn-user-data-exposed-due-to-bug/

avoidthehack, to privacy

Private Engine Deploys New Algorithm That Provides Better Results for Users

Go @Mojeek!!

Now Mojeek has introduced semantic matching, aiming for a better user experience. :ablobcatbongokeyboard:

https://reclaimthenet.org/mojeek-deploys-new-algorithm

avoidthehack, to opensource

Skiff Privacy has been acquired, will be shutting down

Skiff has “joined” (read: been acquired) by Notion.

Skiff privacy is (was?) an and friendly product suite, featuring email, pages, drive and calendar.

According to their blog post and an email mirror that blog post, Skiff will be “sunsetting” in the next 6 months. In plainspeak, in about 6 months (no definitive date as of writing this post) Skiff’s services will no longer work. Users will not be automatically migrated to Notion.

Users must migrate/download their data, including migrating skiff domains and redirecting emails. From what I currently understand, email aliases must be handled by hand - so the redirect only works for the primary address.

@alternativeto @BleepingComputer @arstechnica @itsfoss

I will be pulling the recommendation for Skiff on Avoidthehack.com ASAP.

https://skiff.com/data-migration

Twitter/X screenshot “skiff is joining Notion. we’re exciting to accelerate Skiff’s mission by joining Notion…”

avoidthehack,

I’ve pulled recommendations of Skiff from Avoidthehack as Skiff is no longer a viable privacy-friendly option.

A lot of people used for their encrypted service - if you are looking for similar alternatives: https://avoidthehack.com/best-email-services

(Pending adding Posteo as of writing)

avoidthehack, to random

Lately I’ve been seeing a lot of people saying they are using uMatrix.

Last I heard it was discontinued a few years ago and still unmaintained. Is there a fork I missed? Or are people using something that is at least 3+ years not updated or otherwise maintained?

avoidthehack, to random

Hmmm, today I learned many cloud providers block port 25 TCP (SMTP) by default. 🤔

Spammers really have ruined everything.

Mojeek, to random
@Mojeek@mastodon.social avatar

just in case anyone sees this and wonders, we didn't pay for it

we got it "complimentary ... via advertising spend"

our spend was in the tens of pounds over a few years 🤔 very normal

avoidthehack,

@Mojeek think that’s their way of begging you to buy more ads.

avoidthehack, to twitter

Privacy-oriented X front-end is shutting down following changes to guest accounts

Nitter is dead after Twitter/X stops allowing guest accounts. Nitter was a front-end for Twitter that worked without JavaScript… @alternativeto

RIP.

https://alternativeto.net/news/2024/1/privacy-oriented-x-front-end-nitter-is-shutting-down-following-changes-to-guest-accounts/

avoidthehack, to internet

NSA Admits Secretly Buying Your Browsing Data without Warrants

I guess this is why no one cares to barely acknowledge the data broker industry - much less address the shitty gray area they operate in.

https://thehackernews.com/2024/01/nsa-admits-secretly-buying-your.html

avoidthehack, to privacy

I missed the official “Data privacy Day” because I don’t social media on Sundays, but here’s a guide for anyone looking to get started on learning about/improving their #privacy.

All the actionable advice boils down to:

  • using a privacy-oriented #browser
  • using a private/encrypted #email provider
  • using a private search engine

#privacymatters #dataprivacyday

https://avoidthehack.com/getting-started-privacy

avoidthehack, to privacy

23andMe data breach: stole raw genotype data, health reports

Ugh, so after blaming other people for this breach, 23andMe admits that raw genotype data (which, btw is immutable as it gets for data points) was compromised… due to a 5-month long credential stuffing campaign.

https://www.bleepingcomputer.com/news/security/23andme-data-breach-hackers-stole-raw-genotype-data-health-reports/

avoidthehack, to privacy

🚨🎬 Concerns about Apple Push Notifications

Research by @mysk shows that , , and other use push notifications to collect data about your . Likely, this data is used for fingerprinting (and then subsequently tracking) users across different apps.

claims it will implement “tighter restrictions” in spring 2024.

https://m.youtube.com/watch?v=4ZPTjGG9t7s

avoidthehack, to security

HP has effectively blocked the use of third party ink cartridges

@majorlinux

OTA update bricks printers using third party ink cartridges in the name of………… measures. The claim is viruses can be embedded into ink cartridges - but the likelihood is so low. Like really low. Low. Extremely low.

In other words, large company does shady thing and blames it on “

https://dcanalysts.net/hp-has-effectively-blocked-the-use-of-third-party-ink-cartridges/

avoidthehack, to iOS

iOS 17.3 adds multiple features originally planned for #iOS 17

Adds “Stolen Device Protection” + a handful of #security #updates. Update ASAP.

Stolen Device Protection limits passcode fallback for some actions and adds security delay functions to sensitive changes, such as changing the device pin.

#cybersecurity #infosec #apple #iphone

https://arstechnica.com/gadgets/2024/01/ios-17-3-adds-multiple-features-originally-planned-for-ios-17/

avoidthehack, to SEC
avoidthehack, to windows

Hackers Weaponize Flaw to Deploy Crypto-Siphoning Phemedrone Stealer

Note: This vulnerability (CVE-2023-36025) is now patched as of NOV 2023. So hopefully you've updated your Windows device(s) since November 2023 Patch Tuesday.

Also, this campaign is yet another that abuses Discord's CDN by hosting the malware. The executes a control panel file in a way that bypasses SmartScreen. Paves the way for loading information stealer "Phemedrone"

https://thehackernews.com/2024/01/hackers-weaponize-windows-flaw-to.html

shortridge, to Cybersecurity
@shortridge@hachyderm.io avatar

#cybersecurity zealots often shame humans for writing down their passwords, but as someone who just had to excavate the digital remains of a loved one who died suddenly:

please write down your credentials somewhere a trusted human can find them, especially your phone passcode and any primary passwords (like for email accounts, password manager, etc.)

the humans who care about you will need that access for many reasons; a "badass" threat model will only add helplessness to their grief

avoidthehack,

@shortridge first, sorry for your loss.

I’m one of those cybersecurity zealots (?) and this is a use cases where I can agree. I think the real trick is putting in a spot where its accessible but otherwise safely tucked away.

As morbid as this might sound everyone should have a “in case of death” folder/safe/lockbox/thing. Even before cybersecurity or smartphones or the internet were things, I’ve heard stories of so many households falling into disarray without one…

avoidthehack, to passkeys

When the banking app inevitably asks you for your opinion on what they can do better, reply “it’s 2024. Support TOTP, FIDO2, or , thanks.”

jerry, to random

Tuesday coming at us like…

video/mp4

avoidthehack,

@jerry I’m not ready. They deployed something on Friday and while I am not at all plugged into DevSecOps it’s going to somehow become my problem.

avoidthehack, to security

Ever wondered when software you’re using is end of life - or otherwise no longer support or maintained by the developer/vendor with important things like updates?

Enter https://endoflife.date

It doesn’t include every app, piece of software or firmware, but it has quite a few!

avoidthehack, to privacy

Alright, I'm gonna do better about remembering to do in 2024.

Free tools/service providers found in the post at https://avoidthehack.com/free-privacy-tools with a presence on :

@StartpageSearch
@Mojeek
@brave
@mozilla (firefox)
@torproject
@mullvadnet
@safing
@signalapp
@session
@protonmail
@Tutanota
@bitwarden

Lockdownyourlife, to random

deleted_by_author

  • Loading...
  • avoidthehack,
    avoidthehack, to Cybersecurity

    Yesterday (9 JAN 24) was the first Patch Tuesday of 2024.

    For the uninitiated: Patch Tuesday is usually the second Tuesday of each month where vendors such as Microsoft and Oracle (among a few others) drop a big patch of updates.

    These usually include security fixes. Note that only a handful of vendors “observe” patch Tuesday and security updates can be pushed at any time. It’s important to stay up to date with at least the latest security updates for any software or firmware you use.

    JAN 2024 was pretty quiet, but make sure you your stuff.

    https://www.crowdstrike.com/blog/patch-tuesday-analysis-january-2024/

    avoidthehack, to privacy

    Can ISPs data be used to track traffic going through VPNs?

    @ivpn explains how netflow aggregation coupled with other pieces of the puzzle can affect your while using a .

    https://www.ivpn.net/privacy-guides/isp-netflow-surveillance-and-vpn/

    avoidthehack, to privacy

    is shutting down its app

    Authy is a a / authentication app, though one that is not recommended in the space primarily because it does not offer easy export of codes (making it difficult to switch apps) and is closed source.

    However, many people used it because it was one of the only apps not integrated into a password manager that allowed easy syncing across different devices.

    I am urging any Authy users/holdouts to switch to an alternative that allows exporting 2FA secrets.

    https://www.theverge.com/2024/1/8/24030477/authy-desktop-app-shutting-down

  • All
  • Subscribed
  • Moderated
  • Favorites
  • anitta
  • InstantRegret
  • mdbf
  • ngwrru68w68
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • osvaldo12
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • JUstTest
  • tacticalgear
  • ethstaker
  • modclub
  • cisconetworking
  • tester
  • GTA5RPClips
  • cubers
  • everett
  • megavids
  • provamag3
  • normalnudes
  • Leos
  • lostlight
  • All magazines