ths, to opsec German

wird bei unseren Behörden groß geschrieben:

„Für Aufregung in Sicherheitskreisen sorgte am Nachmittag eine vorzeitige Meldung von Bundesjustizminister Marco Buschmann. Seine Pressestelle verbreitete ein Statement zu den Festnahmen bereits zu einem Zeitpunkt, als die GSG9 noch nicht alle Beschuldigten überwältigt hatte und der Polizeieinsatz noch nicht abgeschlossen war.“

https://www.tagesschau.de/inland/gesellschaft/hamas-generalbundesanwalt-100.html

avoidthehack, to Cybersecurity

Annual Reminder: Is a Dangerous Christmas Gift That Could Have Unforeseen Impacts on Your Entire Family, Your Children, Etc.

From @404mediaco

PS: The 23andMe hack keeps getting worse. Can't really change your (unless you know something I don't), so you should avoid giving it away...

https://www.404media.co/23andme-hack-christmas-gift/

lexd0g, to random
@lexd0g@wetdry.world avatar

holy fucking shit bitwarden finally got passkeys

kkarhan,
@kkarhan@mstdn.social avatar

@ljrk @lexd0g It's worse because brick a lot of workflows and systems as an addon-layer instead of fixing the core problem.
And the core problem is that , , and are just "Afterthoughts" at best for all but the most .

Using i.e. encryption and login on everything [and not as a "password replacement"] would be a way better fix.
Just like @torproject does a self-signing namespace on .

Again, not perfect but better than !

germannr4, to NixOS

Any good guides on how to turn NixOS into an os that mirrors TailsOS as closely as possible in function?

ianonymous3000, to privacy
@ianonymous3000@mastodon.social avatar

Even with Advanced Data Protection activated on ,
Apple can still access your iCloud Mail, Contacts, and Calendar. The encryption applies in transit and on their servers, but it's not end-to-end. Apple holds the keys.

https://support.apple.com/en-us/102651

monkeyflower, to infosec

Spyware being used by 13 federal departments, documents show | CBC News

WTF Canada!?! 🇨🇦😬

https://www.cbc.ca/news/canada/ottawa/spyware-federal-canada-government-department-privacy-1.7041255

The tools in question can be used to recover and analyze data found on computers, tablets and mobile phones, including information that has been encrypted and password-protected ...

osintambition, to OSINT
monkeyflower, to infosec

This may be the most poetic/ ironic screenshot of all time. 🙃

kkarhan, (edited ) to random
@kkarhan@mstdn.social avatar

Dass nen war sollte angesichts des aggressiven und der unseriös hohen Renditen doch einleuchten...

Aber und Leute sind allzuoft !
https://www.youtube.com/watch?v=cFbD6QKNj4s

kkarhan,
@kkarhan@mstdn.social avatar
Tutanota, to privacy
@Tutanota@mastodon.social avatar

The new tuta.com email domain will be available soon to everyone using one of our new subscription plans!😎

Be quick and create your favorite new address as soon as they go live. Shorter addresses are sure to be gone fast!🏃‍♀️💨

kkarhan,
@kkarhan@mstdn.social avatar

@nebula @Tutanota @protonmail If people didn't trust in nebulous bogus claims, than neither nor nor would've been the desasters they are...

Because proper , , and are critical for everyone.

monkeyflower, to opsec
gianmarcogg03, to Bulgaria
@gianmarcogg03@mastodon.uno avatar

I did another one of those fucked up EU law notices, this time about Article 45. Like with the Chat Control one, feel free to copy and paste this onto your website, just credit me for the text.

avoidthehack, to opsec

Encrypted Messaging and Why You Need It

From @Lockdownyourlife

Encrypted messengers for all!

My favorite encrypted messenger is SimpleX Chat @simplex. I'm also a fan of Signal @signalapp and Session @session.

What's yours?

https://www.lockdownyourlife.com/encrypted-messaging/

steampixel, to opsec German
@steampixel@social.tchncs.de avatar

Smartphone Halt's Maul: Diese Checkliste soll dir helfen spielerisch deine Smartphone-Sicherheit zu überprüfen, damit du ein Gefühl für die Thematik entwickeln kannst. Die Liste enthält konkrete Vorschläge zur Verbesserung deiner Sicherheit. Punkte und Level sollen dich ermutigen so viel wie möglich abzuhaken.

https://smartphone-halts-maul.de/

avoidthehack, to privacy

Passkeys and

I'm pretty hyped for adoption, not gonna lie. I know passkeys have drawbacks (especially when synced to the cloud, and if not, issues when a device is lost/stolen). These passwords have gotta go.

https://www.eff.org/deeplinks/2023/10/passkeys-and-privacy

syntaxseed, to security
@syntaxseed@phpc.social avatar

What's the current state of the art in terms of identity verification?

With Twitter blue checks pointless now, we don't have much awareness of what is useful for average individuals to publish their own identity or verify that of others. And with LLMs flooding the web with fake info, I think this is going to become more & more important.

I'd like to look into ensuring my own online identity is as authenticated as possible.

bashinho, to opsec German
@bashinho@social.tchncs.de avatar

Ein sehr interessantes Whitepaper zu hat das Fazit: "Of the 16 VPNs we analyzed, Mullvad, PIA, IVPN, and Mozilla VPN (which runs on Mullvad’s servers)—in that order—were among the highest ranked in both privacy and security. However, PIA has never had a public third-party security audit. 1/x
https://innovation.consumerreports.org/wp-content/uploads/2021/12/VPN-White-Paper.pdf

ianonymous3000, to Cybersecurity
@ianonymous3000@mastodon.social avatar

With QR codes everywhere, there's a rising concern about their misuse. 🚨 How do you protect yourself from malicious QR codes? What are your go-to security measures before scanning? Please share your best practices & tips!

SirTapTap, (edited ) to aitools
@SirTapTap@mastodon.social avatar

New feature just hit 14 looks like

Search for "ad" in settings to find it. Most private option is "off" for all options. Only reason to leave them "on" is "better ads" which I don't particularly believe in

Edit: All of the options claim to auto-delete data periodically, a change I do like. Difficult to confirm, and really I think the consumer/advertiser trust is just too low. We needed that 15 years ago not now.

emory, to tv
@emory@soc.kvet.ch avatar

one of my hobbies is making and restoring for Apple devices.

make: some themes, samples like Schitt's Creek, Flight Attendant; some games: , Mass Effect.

“restore?" you ask? classic System 7 and OG alerts and effects, and just wait until you see the Nokia folder: https://www.dropbox.com/sh/rzgrhydodxzd92n/AAB2mkgU7OIpK7pcoVerhOBAa?dl=0

also available as share for the first 20 people at least, just to throttle: https://link.resilio.com/#f=Tones&sz=14E7&t=2&s=OTEVUE7PGKFMZXWOZ2AO646MPLRU5C7NAEOFFEEM2R5KVUZ5IEZA&i=C43SQZUZQYGJPFU7OWJ4SCZHBZAZTXUIG&v=2.7&a=2

there's always at least 3 peers around for this share.

emory,
@emory@soc.kvet.ch avatar

to promote security awareness and encourage people caring about privacy, i am considering referring to rando open ports in the wild (like these at C9), as "Glory Holes".

don't stick your phone or anything else you like in there, because sometimes you get something untreatable.

avoidthehack, to windows

Brave Browser's latest update installs services without user consent on

From @alternativeto

sigh another transparency issue from Brave.

The argument from Brave is that it is “set to manual” (so not automatically enabled) but you absolutely should prompt users first.

If I download a browser, I expect a browser - not for it to add to my VPN configuration settings without prompting first.

https://alternativeto.net/news/2023/10/brave-browser-s-latest-update-installs-vpn-services-without-user-consent-on-windows/

webbreacher, to privacy

OK. Real question here about and I guess .

Most of us know that the use of apps to do MFA (multifactor authentication) is a useful thing to protect someone from guessing/using our passwords on sites.

Many of the password managers now include a helpful MFA feature where you can store your password AND do MFA in their app.

My question is, doesn't this defeat the purpose of MFA if they are stored in the same app/location?

gianmarcogg03, to Bulgaria
@gianmarcogg03@mastodon.uno avatar

I had a little idea: I added a banner on my homepage to inform people about and to encourage them to do something about it.

Mer__edith, to random
@Mer__edith@mastodon.world avatar

Where I speak some advantages Signal has over the bigger richer rest of tech:

“We don’t have to be full of shit. We’re not a surveillance company. I’m not trying to pretend Facebook is good. I don’t have to toe a party line that is divorced from reality”

https://restofworld.org/2023/signal-president-meredith-whittaker-messaing-privacy/

kkarhan,
@kkarhan@mstdn.social avatar

@anarchopunk_girl @fla @Mer__edith @signalapp

also doesn't provide value to me beyond what + & + /MIME can offer for decades now.

Instead it creates shitty dependencies to - that have no legitimate reason to exist and their unwillingness to allow makes it worse than a default installation in terms of , , & .
https://zulip.com/why-zulip/

kkarhan,
@kkarhan@mstdn.social avatar

@anarchopunk_girl @fla @Mer__edith

After all, @signalapp does in fact comply with demands of the U.S. government and restricts 's functionality based of "striclty unnecessary" data like !

Whereas @torproject is specifically designed to be incapable of doing so, even if all their maintainers were simultaneously held at gunpoint.

Cuz that's basic to the point that every small / in Germany has to get that in place!

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • everett
  • InstantRegret
  • thenastyranch
  • magazineikmin
  • khanakhh
  • rosin
  • Youngstown
  • slotface
  • mdbf
  • cisconetworking
  • kavyap
  • cubers
  • DreamBathrooms
  • megavids
  • ngwrru68w68
  • Durango
  • osvaldo12
  • tacticalgear
  • modclub
  • normalnudes
  • Leos
  • ethstaker
  • GTA5RPClips
  • tester
  • anitta
  • provamag3
  • lostlight
  • All magazines