scy, to opsec
@scy@chaos.social avatar

Huh. Anyone ordered a lately? Did yours also come with an obvious fingerprint smudge on its contact surface?

The packaging is apparently undamaged.

I've contacted Yubico support about whether that's normal or a possible sign of tampering. Let's see what they say.

kravietz, to Russia
@kravietz@agora.echelon.pl avatar

published alleged intercept of Bundeswehr officers discussing the use of Taurus long-range missiles in . The intercept may be a deep fake, but so far it has been not denied by German government.

In the first place, it’s an obvious screw up on the side of German officers, one of whom was reportedly in Singapore when the call was wiretapped (do you remember 2014 Nuland and Pyatt stupidly talking over unprotected phones in Euromaidan and being picked by Russian-controlled SBU?).

But apart from that I don’t see anything in the call that would be in any way a shame for Germany, quite the opposite: they are actively supporting Ukraine with weapons and discuss their technical details. That’s great and we should have more of these, not necessarily in public and not leaked by Russians.

Some people are concerned about “escalation”, but just like with NATO personnel in Ukraine, “escalation” for whom? Because Russian media are telling their audience “Russia is at war with NATO” already since 2023. They hyped the legendary NATO presence so high that their military is already laughing at it, because they best of all know they’re fighting regular Ukrainian army with some NATO weapons and some NATO ammunition shortages.

So I believe the group the most impacted by Russian leak is those EU and US politicians who would like to prefer their position cloaked in a safe “not our war” zone.

ianonymous3000, to privacy
@ianonymous3000@mastodon.social avatar

🚨 Important update from @signalapp 🚨
The latest update (v7 on Desktop):
✅ Keep your phone number hidden
✅ Choose to share a username instead
✅ Take control with new privacy settings - You decide who finds you by phone number.

cappy, to OSINT
@cappy@fedi.fyralabs.com avatar

I'm doing some funny OSINT stuff and... I have found some funny stuff.

I looked him up on Google, Found a Discord report about him with his real email attached.

Looked up his email, and found a post on the ctkpaarr forums (the one he's advertising the discord) of him being currently flamed for this current ongoing incident.

The best part? He bought the script using a PayPal account. With his real name and identity.

He is a real skid. He just bought an off-the-shelf script and decided to piss off a lot of people, even the dude he bought it from with his antics. Bro snitched on himself and his entire community LMEOW

For the sake of my own job, my rep and legal security I'm not gonna tell where exactly I found this, but you guys can find it yourself. Figure it out.

This guy is making me dying out of laughter 💀 Our team @hq is hysterical right now at this horrible opsec.

Don't be a skid, kids.

RE: https://fedi.fyralabs.com/notes/9pr6thyvz5

avoidthehack, to privacy

User Exposed Due to Bug

Split tunneling feature has been disabled as it was leaking user requests - which can be used to ascertain browsing activity to whoever captures the leaked requests - since at least 2022.

Not a I would recommend for other reasons, but yeah - choose your VPN provider carefully.

https://www.securityweek.com/expressvpn-user-data-exposed-due-to-bug/

xyhhx, to opsec
@xyhhx@438punk.house avatar

idk who needs to hear this, but your threat model / opsec precautions shouldn't just be based on your current situation. you need to consider anything and everything that could happen in the foreseeable future

that includes a change of political climate, a change of your own skill sets and undertakings, etc

please boost this shit

blendingbits, to IT

Know someone who runs a ?

Make sure you let them know to do some input sanitation. Apparently and creators are now signing up their targets for newsletters and put links to their stuff in the name field or other fields, that way the recipient might be shown a functioning link.

sergiopantalone, to opsec
@sergiopantalone@corteximplant.com avatar

I work in engineering at a small design firm where our IT department consists of one person, who is also the building manager and director of operations. We engineers are currently fighting for local admin privileges rather than wait hours to get critical software installed, but were told people "good with computers" are actually a bigger security risk because of "hubris and experimentation." Is this true? Does anyone have any evidence (esp literature) to the contrary? Boosts appreciated, and thanks!

Tutanota, (edited ) to privacy
@Tutanota@mastodon.social avatar

Getting security online right seems like a daunting task. But one thing is certain: Password managers help! 💪

🔥Here are our top three: https://tuta.com/blog/best-password-manager 🔥

What are your favorite

madargon, to escribiendo
@madargon@is-a.cat avatar

Some random anxious thoughts...

I currently read some crime again. Fiction literature. And there are many encounters with police gaining access to someone's (either criminal or victim) content, private messages on , text messages on etc. I wonder if it could be really possible in real world.

Or what would happen if someone use hard disk encryption? Do they have these from service providers? Could using encrypted email service like or prevent this? If I understand correctly, emails content is encrypted in rest.

Are regular data deletion, history cleaning and/or disappearing messages (like features) effective for this?

If someone avoid big mainstream services, only niche/encrypted/self-hosted ones are they safe?

Is it possible to become immune to this both via software/service choices and online habits? How to achieve this if so?

I don't want to commit crimes, only become "invincible" :blobcatjoy:​

datacyclist, to opsec German
@datacyclist@swiss.social avatar

Wenn ihr beim SRF im Video den Panzertransport filmt und dabei noch den Bahnhaltepunkt Bronschhofen AMP mit drauf habt, ist das nicht weit her mit "militärischer Geheimhaltung", die im Text erwähnt wird. https://www.srf.ch/news/schweiz/indirekte-ruestungshilfe-schweizer-leopard-2-panzer-auf-dem-weg-nach-deutschland

monkeyflower, to journalism

Well this is terrifying. As usual big thanks to @josephcox for this important journalism.

"A wide-spanning investigation by 404 Media reveals more details about a secretive spy tool that can tracks billions of phone profiles through the advertising industry called Patternz. Google has taken action in response to 404 Media's inquiries."

@404mediaco https://mastodon.social/@404mediaco/111812269281519818

Kels_316, to random
@Kels_316@aus.social avatar

lets find out if this "contractor management portal" does anything useful or if I can upload a word document consisting of a single full stop as my health and safety policy

neoluddite,
@neoluddite@aus.social avatar

@jpm @Kels_316 just as long as you don't have any easily identifiable moles

FlockOfCats, to opsec
@FlockOfCats@famichiki.jp avatar

“opsec” stands for “oppai security”

tinker, to infosec

If your first instinct is to try and find blame when a security vulnerability is pointed out...

...you have already created an environment where everyone will hide issues from you.

You currently live in a fake reality where you think everything is fine and you have no idea the rot that is underneath you.

If you fire or punish a person every time a vulnerability is found, you will have no one left. Hell, fire yourself first to save us all the trouble.

Vulnerabilities exist. The world changes. Software changes. Attacks change. Business needs change.

Life is fucking impermanence.

So create an environment where folks come to you quickly and tell you what needs to be fixed as they find it.

How do you do that?! Reward vulnerability discovery. Reward mitigations. Reward patch management. Reward security improvement. Reward safety improvement.

#informationsecurity #infosec #operationalsecurity #opsec #ics #ot

deweyritten, to opsec

has anyone ever tried incogni?

monkeyflower, to infosec

US nuke reactor lab hit by 'gay furry hackers' demanding cat-human mutants

https://www.theregister.com/2023/11/22/nuclear_lab_hacked/

"The self-styled furry hackers meanwhile have offered to remove the staff records if the lab performs experiments that at best could be described as highly irregular.

"We're willing to make a deal with INL. If they research creating IRL catgirls we will take down this post," the group said. The creation of real cat-human female hybrids is a frequently posted meme in certain corners of the internet, but it's not the laboratory's specialty.

According to the hacktivists, the invaders gained access to "hundreds of thousands of user, employee and citizen data," among it full names, dates of birth, email addresses, social security numbers, employment info and "lots lots more!"

INL employs more than 6,100 people in and around Idaho Falls at its massive 890-square mile site, which houses the densest concentration of nuclear reactors in the world. The 70-year-old facility has been instrumental in the development of nuclear power, was the home of the first nuclear generator to provide a usable amount of electricity, and developed the first nuclear propulsion system for US Navy submarines.

It's unclear what motivated SiegedSec's attack on INL. In its previous network penetration of NATO the group attributed its actions to the military org's "attacks on human rights," adding that it's also "fun to leak documents." ®"

btp, to random
@btp@fosstodon.org avatar

What are your favorite hashtags to follow on Mastodon?

adamsdesk,
@adamsdesk@fosstodon.org avatar

@btp I would say all of the hashtags I follow are my favourite.

ianonymous3000, to privacy
@ianonymous3000@mastodon.social avatar

Do you want to help your friends practice better cyber hygiene? Try standing behind them while they use their devices, and when they inevitably give you a 'personal space' glare, tell them that you're just their friendly neighborhood watch. Smile, you're on camera!

D_70WN, to random German
@D_70WN@chaos.social avatar

Gibt es ausser Posteo.de und Mailbox.org noch vertrauenswürdige E-Mail Anbieter aus Deutschland?

Tuta(nota) und reine IMAP Anbieter scheiden komplett aus, wie alle Freemailer.

kkarhan,
@kkarhan@mstdn.social avatar

@D_70WN @vegos_f06 @albigdd Glaubst doch wohl nicht, dass davor schützt?

Das wird eh alles arxhiviert wenn nicht sogar auf vorrat gespeichert...

Ob legal oder Illegal ist den Behörden shiceeegal...

Das einzig effektive was hilft, sind , , & :

D.h. wer konsequent /MIME nutzt und sauber Identitäten trennt dem kann ne Durchsuchung shiceegal sein!

https://mstdn.social/@kkarhan/111631190348553830

vfrmedia, to security
@vfrmedia@social.tchncs.de avatar

I got a cheap USB #microscope to look at car paintwork, small electronics and the ratings label of some power supply units like mobile phone chargers, which are increasingly often way too small to read with bare eyes.

I also happen to have a 365nm UV torch in my kit bag, so I thought I would look at some printouts from the office printer - here you can see the unique machine identifier code added to the printouts (these are very faint yellow dots) #security #privacy #opsec

CCC, to random German
@CCC@social.bau-ha.us avatar

Hessen: CDU und SPD wollen digitale Wohnzimmer-Wanzen, die heimliche „Online-Durchsuchung“ mit und mehr Videoüberwachung https://www.heise.de/news/Polizeibefugnis-CDU-und-SPD-in-Hessen-wollen-digitale-Wanzen-im-Wohnzimmer-9577621.html

kkarhan,
@kkarhan@mstdn.social avatar

@CCC ROFLMAO!

Das einzige was diese macht ist gesetzestreue Ottonormalbürger*innen entrechten während OK-Elemente natürlich , , & umsetzen sodass dies komplett ins leere greift...

LoganFive, to random
@LoganFive@beige.party avatar

Just curious: what do you all make sure you DON'T post when you're posting (e.g., photos of yourself, any indication of location, any mention of a last name, any mention of how many bodies are in your basement)?

And do you set your posts to expire after a certain amount of time?

I'm just curious how cautious people are when sharing on Mastodon/the Fediverse.

maxleibman,
@maxleibman@mastodon.social avatar

@LoganFive My number-one rule is when you post your social security number, only @-mention people you really trust.

samanthagroves, to opsec

A post with some basic links:

On how Google and Apple have been spying on you via push notifications (for years): https://www.reuters.com/technology/cybersecurity/governments-spying-apple-google-users-through-push-notifications-us-senator-2023-12-06/

Signal statement on the subject by their CEO (they say that no sensitive data is included in their push notifications): https://mastodon.world/

Why should you still care?

  • Do a quick search for 'Michael Hayden" + “We Kill People Based on Metadata” (obviously use anything but google)

The Electric Frontier Foundation @eff is a good place to check for updates and an account to follow to choose the tools that are right for you.

, a cross platform chat program relying on the IMAP/SMTP protocol (email) with easy to set up encryption via autocrypt: https://delta.chat/en/help#encryption-and-security

Deltachat relies on IMAP/SMTP (emailK so make sure that you set up a new address with a provider you trust and use an username that can't be linked back to your usual nicknames or worse: your government name.

is an IM client with mesh support (aka peer to peer) you can restrict communication to your local network to Bluetooth, and redirect internet traffic via tor: https://briarproject.org/manual/
Do note that any blog you posted can't ever be deleted and that you will systematically be sharing your Bluetooth address (you can nuke your account at any time)

is a portable OS which allows you to "temporarily turn your own computer into a secure machine. You can also stay safe while using the computer of somebody else": https://tails.net/about/index.en.html

Obviously you should be aware of : https://www.torproject.org/ and check your fedi account for common mistakes: https://distro.f-91w.club/masto-opsec

Last but not least, for IRL shit this is as good a place to start as any: https://opsec.riotmedicine.net/ (by @hakan_geijer)

Stay safe, wear a mask, be they, do crimes and ffs, don't ever talk about the later!

And if you do have a criticism towards the one or other mentioned app, please do share it!

ianonymous3000, to privacy
@ianonymous3000@mastodon.social avatar

If I have to recommend one tool that will drastically improve your privacy on Windows, it's @safing Portmaster!
✨ Monitor all app connections
🚫 Auto-block trackers & malware
🔒 Secure DNS by default
✅ Reduce telemetry
🔧 Customizable rules & settings

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • tacticalgear
  • thenastyranch
  • ngwrru68w68
  • magazineikmin
  • khanakhh
  • rosin
  • mdbf
  • Youngstown
  • slotface
  • everett
  • cisconetworking
  • kavyap
  • DreamBathrooms
  • anitta
  • InstantRegret
  • Durango
  • osvaldo12
  • ethstaker
  • modclub
  • GTA5RPClips
  • Leos
  • cubers
  • tester
  • normalnudes
  • megavids
  • provamag3
  • lostlight
  • All magazines