neko, to science
@neko@clubcyberia.co avatar
KissAnne, to news
@KissAnne@mastodon.social avatar

Major data could affect up to 120k pupils, guardians and city workers in | Yle | The breach was carried out from outside . The files included information on parents' early childhood education fees and their payment, sensitive data regarding children' s situations at schools — their special support requirements, medical reports in regard to middle school pupils' suspensions, details about educators' and training staff sick leave.
https://yle.fi/a/74-20088448

echo_pbreyer, to random German
@echo_pbreyer@digitalcourage.social avatar

🇬🇧 New on : Privacy-friendly and encrypted messaging services are to be penalised with chat control bulk scanning orders. They want to turn the safest services into the most monitored ones!

Read on: https://www.patrick-breyer.de/en/leak-privacy-friendly-and-encrypted-messaging-services-are-to-be-penalised-with-chat-control-bulk-scanning-orders/

pete,

@echo_pbreyer If they truly pull this off we should all be advocating apps like DeltaChat (f-droid.org/en/packages/com.b4…), an E2E encrypted chat app that utilizes GPG encrypted emails in a user-friendly fashion.
And best of all the whole "walled garden messaging service" deal would be a thing of the past - all a participant ever needs is ANY single email provider and the DeltaChat app.

Wonder how they'll try to ruin a decades old backbone internet service like the MTA protocol?

echo_pbreyer,
@echo_pbreyer@digitalcourage.social avatar

@pete Self-hosted apps will not be affected. However, to contact most people, you won't have the choice to use such software.

echo_pbreyer, to random German
@echo_pbreyer@digitalcourage.social avatar

🚨New on : EU interior ministers want to exempt themselves, police staff etc. from error-prone scanning, while searching our messages indiscriminately - outrageous! Read on:
https://www.patrick-breyer.de/en/leak-eu-interior-ministers-want-to-exempt-themselves-from-chat-control-bulk-scanning-of-private-messages/

34787bf10dc7c564a163a30712a5614b4a01b058babe394439d95949ebf29dce,
@34787bf10dc7c564a163a30712a5614b4a01b058babe394439d95949ebf29dce@mostr.pub avatar

UK / Germany

echo_pbreyer,
@echo_pbreyer@digitalcourage.social avatar

@34787bf10dc7c564a163a30712a561@mostr.pub In Germany, join or support Pirates, Digitalcourage, CCC...

ai6yr, to Cybersecurity
majorlinux, to ads
@majorlinux@toot.majorshouse.com avatar

What would be your dream fighting game stage?

Find out what we think Tekken should do with Waffle House on this week's episode of Tech Talk Thursdays!

Tech Talk Thursdays Episode (04/04/2024) - Desk Chair Analysts

https://dcanalysts.net/tech-talk-thursdays-episode-112-04-04-2024/

PrivacyDigest, to privacy
@PrivacyDigest@mas.to avatar

AT&T says leaked data set affects about 73 million current, former account holders

Telecom company AT&T said on Saturday that a data set released on the "dark web" about two weeks ago has impacted approximately 7.6 million current account holders and 65.4 million former account holders, based on the company's preliminary analysis of the incident.
#att #privacy #security #leak

https://finance.yahoo.com/news/1-t-says-leaked-data-143508014.html

Debby, to internet
@Debby@esperanto.masto.host avatar

A Backdoor in XZ Utils was found!
To know if you are affected rune:
xz -V in your terminal
if like me you have XZ 5.6.0 or XZ 5.6.1 downgrade XZ Utils to an earlier version, such as 5.4.6 (Stable) or disable ssh

Malicious backdoor found in ssh libraries https://www.youtube.com/watch?v=jqjtNDtbDNI

Are You Affected by the Backdoor in XZ Utils?
https://www.darkreading.com/vulnerabilities-threats/are-you-affected-by-the-backdoor-in-xz-utils

https://openwall.com/lists/oss-security/2024/03/29/4

https://archlinux.org/news/the-xz-package-has-been-backdoored/

cccfr, to internet German
@cccfr@chaos.social avatar

xz or not xz , thats the question?
ugly, mode: alles anzünden

"Backdoor found in xz liblzma specifically targets the RSA implementation of OpenSSH. Story still developing."

#leak #backdoor #ssh #Internet #xz #linux #rsa #libzma #openssh #CVE20243094 #sicherheitslücke
https://www.youtube.com/watch?v=jqjtNDtbDNI
https://openwall.com/lists/oss-security/2024/03/29/4
https://archlinux.org/news/the-xz-package-has-been-backdoored/
https://sc.tarnkappe.info/d941c4

cccfr,
@cccfr@chaos.social avatar

"I think a LOT of people are missing the fact that we got LUCKY with this malicious backdoor.".

you could be affected if using Debian sid or kali.
In other cases you probably wont.

we expect more, and good detailed write ups / Videos on that the coming hours and days.

"I gave a talk about state actors attacking FOSS, ten years ago, on : https://www.youtube.com/watch?v=3jQoAYRKqhg "

here 2 threads
https://chaos.social/@tinker@infosec.exchange/112180669379673577
https://chaos.social/@tinker@infosec.exchange/112181161454177547

mcfly,
@mcfly@milliways.social avatar

@cccfr that is for the backdoor that was found - and i would make the argument that that was luck.

minioctt, (edited ) to Amazon Italian

Stasera ho sentito proprio il senso di , dovevo dagli incubi del webdev dopo le mie ore più terribili, e in qualche modo sono finita a per trovare qualche nuovo da acquistare (magari oltre ai manga, perché ogni tanto qualcosa di diverso fa piacere), che qui il fa ancora molta fatica a esaurirsi, e a me rimane appena un mese di tempo… 🌚

E qualcosa ho trovato. Qualcosa ho potuto sbirciarla bene scaricandola dai siti pirata e concludendo che probabilmente si, la comprerò cartacea, qualche altra cosa l’ho trovata solo su YouTube, ma in ogni caso domani passo prima in a vedere se hanno direttamente lì almeno una parte; se il libraio è ben fornito, questa volta Bezos non vincerà. 😊 (Anche perché la sua di merda è sempre peggio… ricordavo benissimo di avere 2 manga nel carrello fino a qualche ora fa, che avevo salvato per non dimenticarmi, ma navigando normalmente mi sa che uno è totalmente sparito completamente da solo: il carrello conta 1 articolo, e io ora non ricordo più cosa fosse quell’altro, non appare nemmeno nei “salvati per dopo”…)

https://octospacc.altervista.org/wp-content/uploads/2024/03/image-16.pngCosa relata: da ieri mi è arrivata la FTTH, quindi nuovo router, quindi tutto di nuovo da configurare. Molta roba già l’ho fatta, ma avevo dimenticato di disattivare l’odiosa funzione “DNS sicuro” di Vodafone, quindi sono stata 1 minuto buono a carcare di capire come mai mi uscisse l’avviso di sull’Archivio di Anna in 4G anche dopo aver attivato la VPN casalinga… beh, per una volta il cervello si è dimostrato utile, avrei potuto sprecare molto più tempo, invece ho capito subito il problema! E altra cosa molto buffa: stasera, lo ha riportato anche TorrentFreak, è apparso su un di parte del codice interno di … cercate “fuckpiracyshield” lì sopra, you’re welcome 👀https://octospacc.altervista.org/2024/03/27/libramento-con-pazienza/

tagesschau, to random German
@tagesschau@ard.social avatar

Generalbundesanwalt ermittelt zum "Taurus Leak"

Verteidigungsminister Pistorius hat für das geleakte "Taurus"-Telefonat von Bundeswehroffizieren schnell eine Erklärung geliefert. Dabei ist unklar, wie es abgehört wurde. Nun liegt der Fall nach WDR-Informationen beim Generalbundesanwalt.

➡️ https://www.tagesschau.de/investigativ/ndr-wdr/taurus-leak-bundeswehr-offiziere-gba-ermittlungen-100.html?at_medium=mastodon&at_campaign=tagesschau.de

kubikpixel, to ai
@kubikpixel@chaos.social avatar

's can read private assistant chats even though they’re .
All non-Google chat 's affected by side channel that 's responses sent to 's.

🗣️ https://arstechnica.com/security/2024/03/hackers-can-read-private-ai-assistant-chats-even-though-theyre-encrypted/

fairkom, to Bulgaria German
@fairkom@chaos.social avatar

Mit fairmeeting wäre kein solcher möglich - denn da gibt es die Option der vollen Ende-zu-Ende Verschlüsselung und Passwortschutz. Telefoneinwahl haben wir 2023 deaktiviert, genau aus dem Grund dass unerwünschte Gäste sich verstecken könnten. Im Vergleich zu Jitsi und ist fairmeeting.net DSGVO konform, da in der gehosted und von einem EU Unternehmen betrieben. Wann dürfen wir an der nächsten Ausschreibung der teilnehmen @bmi ?
@fbausch

NewsDesk, to random
@NewsDesk@flipboard.social avatar

U.S. Air National Guardsman Jack Teixeira, who is accused of posting classified documents online, is expected to plead guilty next week, multiple outlets say. The details of the agreement with prosecutors over changing his plea are not immediately known, but Teixeira faces decades in prison if convicted. Read more from CNN.

https://flip.it/LXYa0n

Freyja, (edited ) to random French
@Freyja@eldritch.cafe avatar

Vous avez un compte sur LDLC?

Une base de données d'1,5M d'utilisateurs est en vente.

Attention au risque de phishing.

Les données fuitées sont :

  • Civilité
  • Prénom
  • Nom
  • Email
  • Tel portable et fixe
  • Adresse
  • etc.

EDIT: même s'il n’apparaît pas dans le leak, le conseil de changer le mot de passe reste important.

Crédits: https://twitter.com/

fvsch,
@fvsch@hachyderm.io avatar

@Freyja Je voulais changer mon mot de passe, mais finalement j’ai supprimé mon compte car ils ne me permettent pas de changer mon prénom🤷‍♀️

Freyja,
@Freyja@eldritch.cafe avatar

@fvsch c'est une bonne raison

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • cubers
  • DreamBathrooms
  • InstantRegret
  • tacticalgear
  • magazineikmin
  • Youngstown
  • thenastyranch
  • mdbf
  • slotface
  • rosin
  • modclub
  • kavyap
  • ethstaker
  • provamag3
  • osvaldo12
  • khanakhh
  • cisconetworking
  • Durango
  • everett
  • ngwrru68w68
  • Leos
  • normalnudes
  • GTA5RPClips
  • tester
  • megavids
  • anitta
  • lostlight
  • All magazines