governa, to bitwarden
@governa@fosstodon.org avatar
adingbatponder,
@adingbatponder@fosstodon.org avatar

@governa looks like this

informapirata, to informatica Italian
@informapirata@mastodon.uno avatar

Dropbox sarebbe stato violato. Rubati i dati dei clienti e i token di autenticazione

Dropbox ha affermato che gli sono penetrati nei di della piattaforma di firma elettronica . Hanno ottenuto l’accesso a di , di autenticazione a più fattori (), con hash e sui clienti.

@informatica

Notizia segnalata su @redhotcyber

https://www.sec.gov/Archives/edgar/data/1467623/000146762324000024/may2024exhibit991.htm

paolabonacini,
@paolabonacini@mastodon.uno avatar

@informapirata @informatica @redhotcyber
tutto in pratica 😱

factcheck,
@factcheck@mastodon.uno avatar

@gmarcosanti @informapirata Se tu hai una bicicletta, ed io non te la porto via ma ho duplicato ogni singola chiave di ogni singolo lucchetto, tu quella bici non potrai più parcheggiarla senza cambiare tutto

E se dentro il borsello avevi le chiavi di casa, tra una settimana sarai vittima di un furto

rebekka_m, to random German
@rebekka_m@fnordon.de avatar

Ein Bekannter ist zur Zeit in Ausbildung zum und sucht einen als oder in oder bei . Falls du etwas weißt/eine Stelle anzubieten hast oder du wen kennst, der oder die etwas wissen könnte, schreib mir einfach. :) Danke <3!

... und ansonsten gilt wie immer: Boost tut gut!

majorlinux, to infosec
@majorlinux@toot.majorshouse.com avatar

Time to mix up those passwords!

Roku hit by credential stuffing attack - Desk Chair Analysts

https://dcanalysts.net/roku-hit-by-credential-stuffing-attack/

mattotcha, to Cybersecurity
@mattotcha@mastodon.social avatar

Cisco: Hacker breached multifactor authentication message provider on April 1
https://therecord.media/cisco-duo-data-breach-mfa-telephony-provider #cybersecurity #hacker #Cisco #MFA #Duo

KathyReid, to random
@KathyReid@aus.social avatar

My Google Pixel 4a 5G died this afternoon and it won't turn on - I am trying all the rebooting / forced restarting options, but nothing is working so far.

The key lesson I am learning is how dependent I am on everything on my phone - my music is on my phone, audio books are on my phone, is on my phone, entertainment in the form of games are on my phone.

I knew I was dependent, but not just how dependent I was.

KathyReid,
@KathyReid@aus.social avatar

@ed I'm sorry you had this experience too

KathyReid,
@KathyReid@aus.social avatar

@decryption agreed

Olly42, to apple
@Olly42@nerdculture.de avatar

iPhone Users under ‘Reset Password’ Attack.

Beware support calls offering a fix.

Cybersecurity researchers have figured out a way to exploit what seems to be a bug in Apple’s password reset feature in a new scam that can lock you out of your iPhone if you’re not careful.

https://krebsonsecurity.com/2024/03/recent-mfa-bombing-attacks-targeting-apple-users/

image/png

ErikJonker, to Cybersecurity
@ErikJonker@mastodon.social avatar

Good blog about how criminals attack, in this case, iPhone users and illustrates the weakness of having to use one unchangeable phonenumber everywhere.
https://krebsonsecurity.com/2024/03/recent-mfa-bombing-attacks-targeting-apple-users/

trendless, to security
@trendless@zeroes.ca avatar

Sanity check:

2FA via SMS was already risky and unsafe, but hey let's make it even worse by adding the ability to have the code sent to a friend?!

:mastomindblown:

Is it really that hard to setup an authenticator app like Aegis or use the one built into keychain?

#2FA #MFA #Security #Telegram #Authentication

maleve,
@maleve@zeroes.ca avatar

@trendless

Case in point.

https://globalnews.ca/news/10376032/toronto-couple-sim-swap-scam/

I really wish there was more detail here about how passwords got reset.

I just wish more places would accommodate FIDO keys for those who wish to use them.

I’d even prefer a mail based code given my mail is yubikey protected.

maleve,
@maleve@zeroes.ca avatar

@trendless i mean 2016…

sehe, to random
@sehe@fosstodon.org avatar

Byebye !

I remember the day I switched to Authy because it would not vendor-lockin me for codes. Alas, today is the day where I ditched it because Authy - without warning - stopped supporting the desktop app, even hurrying the deadline by 5 months! That was 70% of the total notification window as far as I could tell.

Requiring a mobile device for is not quite the same for me, and it can get lost (or stolen) way too easily for my taste.

Edent, (edited ) to foss
@Edent@mastodon.social avatar

Which open-source TOTP code generator do you use on Android?

Brahn,
@Brahn@hachyderm.io avatar

@Edent 1password

no one else in this thread?

Edent,
@Edent@mastodon.social avatar

@Brahn
I didn't think it was Open Source?

sphcow, to Cybersecurity
@sphcow@mas.to avatar

Passwordless is great, but perhaps you need to consider basic MFA to start? If that's you, it's time for a refresher. Spoiler: it's not heavy key fobs any more.

#

https://sphericalcowconsulting.com/2024/03/03/mfa-beyond-sms-and-email/

Edent, to linux
@Edent@mastodon.social avatar

🆕 blog! “Review: An NFC reader/writer with USB-C - ACR1252U-MF”
★★★★⯪

I needed to read and write NFC cards on Linux. I only buy USB-C peripherals now, so I found the brilliantly named "ACR1252U-MF" which appears to be the only USB-C reader on the market. Total cost was about £35 on eBay. It's a cheap and light plastic box with a short USB …

👀 Read more: https://shkspr.mobi/blog/2024/02/review-an-nfc-reader-writer-with-usb-c-acr1252u-mf/

-c

blog, to linux
@blog@shkspr.mobi avatar

Review: An NFC reader/writer with USB-C - ACR1252U-MF
https://shkspr.mobi/blog/2024/02/review-an-nfc-reader-writer-with-usb-c-acr1252u-mf/

I needed to read and write NFC cards on Linux. I only buy USB-C peripherals now, so I found the brilliantly named "ACR1252U-MF" which appears to be the only USB-C reader on the market. Total cost was about £35 on eBay.

It's a cheap and light plastic box with a short USB cord. When you plug it in, there's a flashing light which can't be disabled. When it is powered up, or it detects and NFC chip, it makes this weird and scratchy beep:

🔊💾 Download this audio file.

On Linux, it shows up as: 072f:223b Advanced Card Systems, Ltd ACR1252 Dual Reader

To get it working, install PCSC Tools and the PCSC Daemon:

sudo apt install pcsc-tools pcscd

To start the daemon:

service pcscd start

Running pcsc_scan detected the reader as two readers - PICC and SAM

Using reader plug'n play mechanismScanning present readers...0: ACS ACR1252 1S CL Reader [ACR1252 Dual Reader PICC] 00 001: ACS ACR1252 1S CL Reader [ACR1252 Dual Reader SAM] 01 00

Putting tokens on and off the reader showed them being detected and removed.

Despite my best efforts, I was unable to get this working with .

nfc-list uses libnfc 1.8.0No NFC device found.

For reading and writing basic NDEF tags, I used Wakdev's NFC tools, I was also able to use various Python scripts like PCSC NDEF

It also worked with a FIDO2 / HID Bridge so I could use an MFA token.

There's lots of documentation about the reader and its API as well as some official ACS Linux tools. In theory it supports firmware update - although none have been released.

It's a cheap and cheerful device. It would be nice if there were a way to stop the flashing LED and crappy buzzer.

https://shkspr.mobi/blog/2024/02/review-an-nfc-reader-writer-with-usb-c-acr1252u-mf/

Edent, to random
@Edent@mastodon.social avatar

🆕 blog! “Giving the finger to MFA - a review of the Z1 Encrypter Ring from Cybernetic”
★★★★☆

I have mixed feelings about Multi-Factor Authentication. I get why it is necessary to rely on something which isn't a password but - let's be honest here - it is a pain juggling between SMS, TOTP apps, proprietary apps, and mag…

👀 Read more: https://shkspr.mobi/blog/2024/02/giving-the-finger-to-mfa-a-review-of-the-z1-encrypter-ring-from-cybernetic/

NHBoehm,
@NHBoehm@ioc.exchange avatar

@Edent Thank you for your review.

I seriously considered purchasing a ring.

But, it turns out that the shop does not process purchase requests, resulting in an incomplete page with nothing to click on.
And the support email bounces as nonexistent.

I hope that you would incorporate that information in your review and/or boost this as a real world experience.

Edent,
@Edent@mastodon.social avatar

@NHBoehm leave it as a comment on the post and I'll publish it.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • cisconetworking
  • thenastyranch
  • GTA5RPClips
  • everett
  • Durango
  • rosin
  • InstantRegret
  • DreamBathrooms
  • magazineikmin
  • Youngstown
  • mdbf
  • slotface
  • ethstaker
  • megavids
  • kavyap
  • normalnudes
  • modclub
  • cubers
  • ngwrru68w68
  • khanakhh
  • tacticalgear
  • tester
  • provamag3
  • Leos
  • osvaldo12
  • anitta
  • lostlight
  • All magazines