Skip to main content

Search

Items tagged with: infosec



Anyway, a throwback for anyone wanting a little more.

These guys have been sending bomb threats to the Japanese government impersonating as KuronekoServer developers before the attack went big. #spam#infrastructure#fediblockmeta#cybersec#cybersecurity#infosec#spam#infrastructure#fediblockmeta#cybersec#cybersecurity#infosec


NEW: WhatsApp will soon make it possible to chat with people who use other messaging apps. It's revealed some more details on how that will work.

— Apps will need to sign an agreement with Meta, then connect to its servers.
— Meta wants people to use the Signal Protocol, but also says other encryption protocols can be used if they can meet WhatsApp's standards
— WhatsApp has been testing with Matrix in recent months, although nothing is agreed yet. Swiss app Threema says it won't become interoperable

wired.com/story/whatsapp-inter… #tech #whatsapp #dma #infosec #news #technology


Fuck it. #YOLO

#Bluesky continues to be entirely non-responsive to the numerous security vulnerabilities I've reported to them, so I spent the evening writing up a nice README and a framework with exploit modules, and just made it all public.

Have fun.

github.com/qwell/bsky-exploits

#infosec #security


🚨 cuidado con las urls de sitios apócrifos

Este caso de suplantación de sitio del #sat 👇

#infosec #cibersecurity #ciberseguridad

🇲🇽 Cuidado, sitio activo suplantando la identidad de #SATMX

El sitio distribuye malware para realizar ataques Man-in-the-Browser, es decir, intercepta y manipula la info/actividades del usuario en el navegador infectado
Archivo descargado: SAT_Complemento_Seguridad.zip

vía hiramcoop en ✖️ antes 🐦


If companies like #Microsoft keep sending out emails with big login buttons in them, how do they expect people to learn not to click buttons and links in #phishing emails. Corporate marketing people need to be fired for sending emails like this. Period. No second chances. Send a link in an email, lose your job. Immediately.

#infosec #marketing


I've always questioned how much more secure this is than emailing files, for outbound documents. It limits the opportunity window of an attacker when the first document is sent, rather than the file sitting on various mail servers. But if an attacker can intercept the email, then that attacker can sign in to Nextcloud and access the file. Ideally, you would do some sort of identity proofing or non-email communication of initial credentials before exchanging files.
#security #infosec


So Google is now preventing people from removing location data from photos taken with Pixel phones.

Remember when Google's corporate motto was "don't be evil?"

Obviously, accurate location data on photos is more useful to a data mining operation like Google.

From Google: "Important: You can only update or remove estimated locations. If the location of a photo or video was automatically added by your camera, you can't edit or remove the location."

It's enshitification in action.

Source: support.google.com/photos/answ…

#technology #tech @technology #business #enshitification #Android #Google @pluralistic #infosec


Hey there -- we're Let's Encrypt, the free and open certificate authority serving over 300 million websites worldwide. We're new to Mastodon and are excited to get to know the infosec community in this new space!

letsencrypt.org/

#opensource #TLS #PKI #infosec


TOTP and U2F/WebAuthn keys work for free and are much more secure. Everyone should stop using SMS 2FA. More info in this great article. krebsonsecurity.com/2021/03/ca… #infosec


Excellent story on Wired about Telegram's problems with supposedly being "private" and secure, and how Russia is exploiting it wired.com/story/the-kremlin-ha…

IMO Telegram should be treated like Facebook: if you're registered there, don't leave any details, configure all chats to self-delete (especially non-private ones), and FFS do not use it for group chats, whether they're open or closed, as they're not encrypted at all.

#Telegram #Privacy #Security #UkraineRussiaWar #InfoSec #Encryption #Messenger


Lo, thar be cookies on this site to keep track of your login. By clicking 'okay', you are CONSENTING to this.