Infosec

Steve12L, French
@Steve12L@mamot.fr avatar

Bientôt en France...

Les constructeurs automobiles communiquent les données de localisation des conducteurs à la police sans mandat ni ordonnance judiciaire
Alors qu'ils s'étaient publiquement engagés à ne pas le faire

https://droit.developpez.com/actu/357254/Les-constructeurs-automobiles-communiquent-les-donnees-de-localisation-des-conducteurs-a-la-police-sans-mandat-ni-ordonnance-judiciaire-alors-qu-ils-s-etaient-publiquement-engages-a-ne-pas-le-faire/

neurovagrant,
@neurovagrant@masto.deoan.org avatar

Hearing @NotTheLinux and our CEO talk to Dimitiri Alperovitch on @BreakingBadness is a special thrill for me. I love working with Kali and Tim both, and I've followed Alperovitch for years thanks to his deep knowledge and deliberate thinking, as well as solidarity with a long-obvious fellow news junkie. I've been looking forward to "World On The Brink" since I saw it on pre-order and now it's sitting on my Kindle, just tempting me!

1/n

Listen here: https://www.domaintools.com/resources/podcasts/breaking-badness-book-club-with-dimitri-alperovitch/

neurovagrant,
@neurovagrant@masto.deoan.org avatar

More than anything, the focus Dimitri Alperovitch puts on understanding adversaries, their motivations, and their capabilities speaks to me as someone who believes in the deep importance of human elements in cybersecurity, and I often find it glossed over elsewhere. And his emphasis on the need to point out things that other folks don't want to speak about in public is important, as well as close to my heart.

neurovagrant,
@neurovagrant@masto.deoan.org avatar

3/3

(Please excuse the lighting in the picture, but this is legitimately taken down in my basement workshop while I work on parallelizing pDNS data transfer flows to a storage device for a customer! The book will have to wait until tonight...)

jeff,
@jeff@soapbox.hackdefendr.com avatar

Yo , , and anyone else:

Have you heard of the Fediverse Effect DDoS?

https://news.itsfoss.com/mastodon-link-problem/

slink,
@slink@fosstodon.org avatar
mcfly, German
@mcfly@milliways.social avatar

If i want to give a security challenge / CTF site to our juniors - what would you recommend?

Thanks a lot

fd0,
vegard,
@vegard@mastodon.social avatar

Good comment describing how various CAP_* are de facto equivalent to root: https://lwn.net/Articles/971891/

This is not news, of course, but it's interesting to see it spelled out. Are there other pages/lists like this? Maybe even a cap-to-root script/program..?

johnleonard,
@johnleonard@mastodon.social avatar

Experimental Morris II worm can exploit popular AI services to steal data and spread malware

Cornell researchers created worm 'to serve as a whistleblower'

https://www.computing.co.uk/news/4203370/experimental-morris-ii-worm-exploit-popular-ai-services-steal-spread-malware

phillmv,
@phillmv@hachyderm.io avatar

Do you work in ? Do you want to work on offensive security at GitHub? Come join our Red Team!

🇺🇸https://githubinc.jibeapply.com/jobs/2933

🇬🇧 https://githubinc.jibeapply.com/jobs/2934

jomo,
@jomo@mstdn.io avatar

Once again researchers (@epicenter_works) were sued for responsibly disclosing a vulnerability. This time by the Austrian government. The charges were eventually dropped, but not before they had 15k€ of legal fees. Others would have paid them a 100k bounty instead.

You really want us to to anonymously drop vulns on the internet, right? I'm so sick of this bullshit.

de-AT: https://orf.at/stories/3355943/

jomo,
@jomo@mstdn.io avatar

Edit: If I read correctly, the @web journalists were not sued, they only published the vuln after it was fixed.

@epicenter_works

chiefgyk3d,
@chiefgyk3d@social.chiefgyk3d.com avatar

I had an unsettling discovery about some family history on Monday that threw me through a loop and prevented me from being in the right mind to start streaming and making content again.

Tonight I am breaking Passover with family, so I am hoping tomorrow I can finally get back on the wagon to make content and get back to streaming my tinkering and Gaming on Linux stuff. But the first stream will be a "what happened in the past two months" hangout

chiefgyk3d,
@chiefgyk3d@social.chiefgyk3d.com avatar

This is awesome I stumbled across @EU_Commission and it looks like it's an actual official government thing.

I really hope this is the start of seeing more official Government communications globally on open source as to opposed Twitter and that craptastic platform.

USAspressoFit,
markstos,
@markstos@urbanists.social avatar

This weekend a chain of vulnerabilities was exploited against my family that resulted in permanent access to our house by Orion. I’ll share what happened so you can avoid the same fate:

  1. Like a lot exploits, this one started by looking browsing a dangerous website with local cat photos. It is safest to avoid these.

( 🧵continues )

Edent,
@Edent@mastodon.social avatar

What does this even mean?

I suppose a SIM might contain SMS or contact details - but those are far more likely to be on the phone these days.
Call records aren't stored on there.
So what was "downloaded"?

https://www.theguardian.com/uk-news/2023/jun/27/met-police-admit-downloading-sim-radical-french-publisher-lawyer-claims

LonM,
@LonM@vivaldi.net avatar

@Edent maybe they meant that they have so far downloaded an esim, but haven't actually reviewed it yet

Edent,
@Edent@mastodon.social avatar

@LonM What would be on an eSIM which would be useful?

deepthaw,
@deepthaw@social.sdf.org avatar

So my work now supports a physical security key for 2FA (I assume in lieu of an Authenticator app.) Anything I should know or look for if I buy one? Can I leverage it for my non-work accounts in any way?

endareth,
@endareth@disobey.net avatar

@deepthaw YubiKey by @yubico still tops the field. Definitely get two, and make sure to always add both to any account that supports WebAuthn.

grumpybozo,
@grumpybozo@toad.social avatar

I boosted my own reply toot because the 2nd paragraph is relevant to all. Neither Apple nor any other mega-corp with literally billions of end-users can do proactive support for all of them on an individual basis. If someone calls you claiming to be from the security staff of $BIGCORP about your account being cracked, they are lying.
There are not enough skilled humans to handle that sort of operation.

neurovagrant,
@neurovagrant@masto.deoan.org avatar

For those that enjoy stickers as much as I do, it's worth noting that I shared a bunch of stickers with friends this weekend and almost invariably the ones snatched first were from @unknownbinaries shop.

The Eicar "Trust Me" got the most laughs, but the sparkly 3 possums in a hacker hoodie sticker got by far the most "It Me!!" responses.

(gonna be feisty and tag it mostly because I know y'all enjoy these)

https://unknownbinaries.storenvy.com

Sticker with "Celestial Contaminant" and an angel-related special character that is just a bunch of eyes
Sticker with an occult symbol in a magic circle with "502 bad gateway"
Sparkly sticker of three possums in a hacker hoodie joyously and chaotically typing on a laptop.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • infosec
  • rosin
  • thenastyranch
  • ethstaker
  • osvaldo12
  • mdbf
  • DreamBathrooms
  • InstantRegret
  • magazineikmin
  • Youngstown
  • ngwrru68w68
  • slotface
  • GTA5RPClips
  • kavyap
  • cubers
  • JUstTest
  • everett
  • cisconetworking
  • tacticalgear
  • anitta
  • khanakhh
  • normalnudes
  • Durango
  • modclub
  • tester
  • provamag3
  • Leos
  • megavids
  • lostlight
  • All magazines