Search
Items tagged with: infosec
NEW: WhatsApp will soon make it possible to chat with people who use other messaging apps. It's revealed some more details on how that will work.
— Apps will need to sign an agreement with Meta, then connect to its servers.
— Meta wants people to use the Signal Protocol, but also says other encryption protocols can be used if they can meet WhatsApp's standards
— WhatsApp has been testing with Matrix in recent months, although nothing is agreed yet. Swiss app Threema says it won't become interoperable
https://www.wired.com/story/whatsapp-interoperability-messaging/ #tech #whatsapp #dma #infosec #news #technology
WhatsApp Chats Will Soon Work With Other Encrypted Messaging Apps
New EU rules mean WhatsApp and Messenger must be interoperable with other chat apps. Here’s how that will work.Matt Burgess (WIRED)
Fuck it. #YOLO
#Bluesky continues to be entirely non-responsive to the numerous security vulnerabilities I've reported to them, so I spent the evening writing up a nice README and a framework with exploit modules, and just made it all public.
Have fun.
https://github.com/qwell/bsky-exploits
GitHub - qwell/bsky-exploits
Contribute to qwell/bsky-exploits development by creating an account on GitHub.GitHub
🚨 cuidado con las urls de sitios apócrifos
Este caso de suplantación de sitio del #sat 👇
#infosec #cibersecurity #ciberseguridad
🇲🇽 Cuidado, sitio activo suplantando la identidad de #SATMX
El sitio distribuye malware para realizar ataques Man-in-the-Browser, es decir, intercepta y manipula la info/actividades del usuario en el navegador infectado
Archivo descargado: SAT_Complemento_Seguridad.zip
vía hiramcoop en ✖️ antes 🐦
If companies like #Microsoft keep sending out emails with big login buttons in them, how do they expect people to learn not to click buttons and links in #phishing emails. Corporate marketing people need to be fired for sending emails like this. Period. No second chances. Send a link in an email, lose your job. Immediately.
Fun stuff within some of the infosec subreddits:
https://www.reddit.com/r/ModCoord/comments/148ks6u/comment/jo0v7sf/
#reddit #redditBlackout #infosec
#security #infosec
#Intel Deploys Undisclosed #Microcode Security Update For CPUs Going Back To Coffee Lake (2017 launched CPUs)
Intel released CPU microcode updates for processors all the way back to Coffee Lake on Friday afternoon. Unfortunately, the changelog doesn't delve into details other than that the new microcode fixes an undisclosed security issue.
#InfoSec
https://www.tomshardware.com/news/intel-microcode-security-update
Intel Deploys Undisclosed Microcode Security Update For CPUs Going Back To Coffee Lake
The security issue affects a wide range of CPUs spanning from mobile to server lineups.Zhiye Liu (Tom's Hardware)
Today on #Wikipedia
https://en.wikipedia.org/wiki/User_talk:%27;_DROP_TABLE_users;_DROP_DATABASE_PROD;_--
I guess that username qualifies as 'otherwise disruptive'
So Google is now preventing people from removing location data from photos taken with Pixel phones.
Remember when Google's corporate motto was "don't be evil?"
Obviously, accurate location data on photos is more useful to a data mining operation like Google.
From Google: "Important: You can only update or remove estimated locations. If the location of a photo or video was automatically added by your camera, you can't edit or remove the location."
It's enshitification in action.
Source: https://support.google.com/photos/answer/6153599?hl=en&sjid=8103501961576262529-AP
#technology #tech @technology #business #enshitification #Android #Google @pluralistic #infosec
https://letsencrypt.org/
#opensource #TLS #PKI #infosec
Let's Encrypt
Let's Encrypt is a free, automated, and open certificate authority brought to you by the nonprofit Internet Security Research Group (ISRG).letsencrypt.org
Can We Stop Pretending SMS Is Secure Now?
SMS text messages were already the weakest link securing just about anything online, mainly because there are tens of thousands of people (many of them low-paid mobile store employees) who can be tricked or bribed into swapping control over a…krebsonsecurity.com
IMO Telegram should be treated like Facebook: if you're registered there, don't leave any details, configure all chats to self-delete (especially non-private ones), and FFS do not use it for group chats, whether they're open or closed, as they're not encrypted at all.
#Telegram #Privacy #Security #UkraineRussiaWar #InfoSec #Encryption #Messenger
The Kremlin Has Entered the Chat
Russian antiwar activists placed their faith in Telegram, a supposedly secure messaging app. How does Putin’s regime seem to know their every move?Darren Loucaides (WIRED)
There've been quite a few #fedisearch issues recently, but the common thread is that there's usually a gap in reporting - they're often live for weeks before people are made aware.
It's not just people's pet projects either, there are other #scrapers active, quietly consuming posts
So, I built a bot to detect and out them so that fedi admins can block as necessary
https://www.bentasker.co.uk/posts/blog/security/autodetecting-and-outing-mastodon-scrapers-with-scrapersnitchbot.html
#infosec #security
Creating A Log-Analysis System To Autodetect and Announce Mastodon Scr
I decided to build a scraper bot detection system to run against my mastodon instance, it uses behavioural scoring to fimd scrapers and then toots details to help other instance admins protect their uwww.bentasker.co.uk
This legal tactic is used constantly to scare people into not leaving to escape toxic work environments, find better pay or get better benefits (be it flexible hours, remote work, health care, retirement contributions, paid time off, etc.).
I hope they decide to do it.
https://www.wsj.com/articles/ftc-proposes-banning-noncompete-clauses-for-workers-11672900586
FTC Proposes Banning Noncompete Clauses for Workers
Move would allow former employees to take jobs with rival companies or start competing businessesDave Michaels (The Wall Street Journal)
2347: Dependency - explain xkcd
Explain xkcd is a wiki dedicated to explaining the webcomic xkcd. Go figure.www.explainxkcd.com