Infosec

simplenomad,
@simplenomad@rigor-mortis.nmrc.org avatar

Hey and various old school types out there. Ages ago I read a tale about a print server that was the source of an intrusion into some system that the author of this tale was trying to secure. In other words, the print server (at some ISP in Australia) had been popped and from there the attacker was getting into other systems. If you were around in the last century and involved in tech and security you might have read this in some zine or blog. A pointer to a copy of this tale would be appreciated, and you will be rewarded in a large quantity of Zorkmids. And if you get the Zorkmids reference, surely you might recall this tale. Boosts appreciated.

Kovah,
@Kovah@mastodon.social avatar

Wow, this phishing attempt ALMOST got me.

Stay safe.

image/jpeg

PC_Fluesterer,
@PC_Fluesterer@social.tchncs.de avatar

@Kovah
You suppress the real email address? Bad idea.

Kovah,
@Kovah@mastodon.social avatar

@PC_Fluesterer I changed that after those mails. It was just too close.

FlohEinstein,
@FlohEinstein@chaos.social avatar

Days without DATETIME / TIMESTAMP incident:

BootsChantilly,
@BootsChantilly@mstdn.social avatar

"The bottom line is that when you need to redact text, use black bars covering the whole text. Never use anything else. No pixelization, no blurring, no fuzzing, no swirling. Oh, & be sure to actually edit the text as an image." https://bishopfox.com/blog/unredacter-tool-never-pixelation

jbzfn,
@jbzfn@mastodon.social avatar

🔎 flawz: A Terminal UI for browsing security vulnerabilities (CVEs) | @orhun

"As default it uses the vulnerability database (NVD) from NIST and provides search and listing functionalities in the terminal with different theming options."

https://github.com/orhun/flawz

cigitalgem,
@cigitalgem@sigmoid.social avatar
newmanth,
@newmanth@zirk.us avatar

@cigitalgem Great advertisement for

protonprivacy,
@protonprivacy@mastodon.social avatar

In this month’s we recommend “If It's Smart, It's Vulnerable” by expert Mikko Hypponen.

The book includes:
📚 an overview of how the Internet became what it is
🌏 discussions on the legal and geopolitical aspects of
🛑 a comprehensive overview of the multitudes of threats lurking on the web

And it’s all peppered with real-life stories from Hypponen’s 3-decade-long career: https://www.ifitssmartitsvulnerable.com/

north,
@north@xn--8r9a.com avatar

An unspecified vulnerability was discovered in an unspecified platform from an unspecified vendor. The vulnerability allowed an attacker to do something.

Yeah, fuck that.

I am never working with Synack / ResponsibleDisclosure.com ever again.

It's been beyond my control, for other reasons, but I'll likely be publishing this tomorrow.

maxleibman,
@maxleibman@mastodon.social avatar

One of my computers is 100% secure. Totally unhackable. Beyond your reach, that of any hacker you’ve ever known, even any state actor.

It’s my childhood Commodore VIC-20.

Which has no permanent data storage, is broken, and is buried under 30 years of landfill.

Langhamian,
@Langhamian@mastodon.social avatar

@maxleibman my first computer was a TRS-80. You could barely program it, much less hack it...

kravietz,
@kravietz@agora.echelon.pl avatar

Going through this excellent book by Shaun Pinner, much recommended! There’s many lessons to learn from this book but from my #infosec angle there are a few. Firstly, always keep an off-line maps app on your phone (I use OsmAnd). As a test — switch on airplane mode and try to survive for a day. Can you still navigate from point A to point B? Secondly, keep your social media profiles friends-only access. Thirdly, don’t keep any passwords in memory - it’s a bad practice from security point of view anyway, but I never thought about the interrogation angle. A password manager locked with biometrics and PIN and random passwords everywhere will prevent you from finding yourself in situation where you’ll be begging your interrogators to check another password because you might have remembered wrong.

geonerd,
@geonerd@mapstodon.space avatar

@organicmaps @notsoloud @kravietz If you could add planning routes ahead of time (from –> to boxes) and a button to save them to a list, that would be handy.

organicmaps,
@organicmaps@fosstodon.org avatar

@geonerd @notsoloud @kravietz what do you mean by planning ahead of time? Can’t you do it right now? Saving routes is planned.

tulpa,
@tulpa@fosstodon.org avatar

In people like to talk about "defense in depth". In other kinds of (non-computer) security, I never hear about that philosophy.

simon,
@simon@fosstodon.org avatar

@tulpa mediaeval castle designers would like a word

doctorambient,
@doctorambient@mastodon.social avatar
NaturaArtisMagistra,
@NaturaArtisMagistra@mastodon.world avatar

@doctorambient

I hate that company

thomrstrom,
@thomrstrom@triangletoot.party avatar

👋 My last was in 2022, so here's an update:

  • Head of Security at
  • Keenly interested in and
  • 30 years of experience messing with the Internet & UNIX systems
  • I build my own frames & spend more time tinkering than riding
  • Spend my idle time playing and wandering on 2-wheel EVs
  • Live in NC with my wife & kids
  • Contributed to 250+ projects including 100+ I've created - bincapz is my latest.
kramse, Danish
@kramse@social.kramse.org avatar

So there is a new Cybersecurity by Pearson book Humble Bundle, and this time you SHOULD buy it.

https://www.humblebundle.com/books/cybersecurity-pearson-books

It contains classics like Network Security, 3rd ed from Charlie Kaufman and Radia Perlman

  • updated 2023 and a great resource on cryptography

and new classics like Cybersecurity Myths and Misconceptions bya @spaf Eugene H. Spafford, Leigh Metcalf and Josiah Dykstra - I have that in print and getting the PDF is really nice! Lovely book!

#BookLove #InfoSec

jsrailton,
@jsrailton@mastodon.social avatar

FINALLY: a 🇺🇸US official speaks the truth security researchers keep warning about...

Americans' movements being tracked with well-known weaknesses that US telcos aren't fixing.

It's remarkable how bad the problem with & is.

Must-read story by @josephcox
https://www.404media.co/cyber-official-speaks-out-reveals-mobile-network-attacks-in-u-s/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • infosec
  • ngwrru68w68
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • InstantRegret
  • GTA5RPClips
  • Youngstown
  • everett
  • slotface
  • rosin
  • osvaldo12
  • mdbf
  • kavyap
  • cubers
  • JUstTest
  • modclub
  • normalnudes
  • tester
  • khanakhh
  • Durango
  • ethstaker
  • tacticalgear
  • Leos
  • provamag3
  • anitta
  • cisconetworking
  • megavids
  • lostlight
  • All magazines