scottjenson, to UX
@scottjenson@social.coop avatar

Oh come on! This is getting silly

argv_minus_one, to Cybersecurity
@argv_minus_one@mstdn.party avatar

xz: backdoored

xz maintainer: fell victim to social engineering, reportedly due to ill health

xz co-maintainers responsible for code review: don't exist; nobody's getting paid to do that

Corporate security impresarios in the near future, probably: “Three-factor authentication is now mandatory. This will solve everything for sure this time.”

EU government: “Open source is now illegal. Use proprietary software instead; it never contains malware.”

btaroli, to ADHD
@btaroli@federate.social avatar

🧵1/2 Someone has a really rotten sense of humor today. I make a simple request of IT, and have to do it in a channel that’s truly horrible about doing things properly. Fine.

But then hours and hours go by. So I finally decide to run an errand for my son after lunch. I’m about five minutes from home, driving, when several people pop into my slack asking to help.

btaroli,
@btaroli@federate.social avatar

🧵 2/2 Uh ok. Can you wait five minutes until I’m home and won’t cause a wreck? No, as it turns out. By the time I reply again from my workstation they are all gone.

I can’t even describe how triggering this. Took a very simple task and turned into some horrible and painful in the name of security theater. So angry right now.

viq, to infosec
@viq@hackerspace.pl avatar

Ah, yes, gotta love sites with security requirements, "lower case, upper case, digits and symbols, at least 6 characters", and happily accept a long random generated password... Which turns out to be too long to later log in with.

ge0rg, to random German
@ge0rg@chaos.social avatar

hat ihr Security Theater optimiert! Bei der manuellen Nachkontrolle des Self Service Checkouts wird nicht mehr der gesamte Warenkorb kontrolliert, sondern nur noch eine Teilmenge der von mir gescannten Artikel. What could possibly go wrong?

Und ich musste nur fünf Minuten auf die gestresste Mitarbeiterin warten.

pludikovsky, to random
@pludikovsky@chaos.social avatar

Enterprise Security™: as Infra/Network admins we get Homebrew installed, but we're not allowed to use the App Store for "Security Reasons".

teresabuecker, to random German
@teresabuecker@social.dev-wiki.de avatar

Ich fliege heute statt Zug zu fahren, damit die Lesung nicht verschoben werden muss - und dennoch ist es so ein Quatsch. Die Reise ist zerstückelt, man steht herum, kann die Zeit für nichts wirklich nutzen, der Arbeitstag ist hin, anders als im Zug. Verstehe nicht, wer freiwillig im Inland fliegt.

kkarhan,
@kkarhan@mstdn.social avatar

@teresabuecker Ich schon.
ist , , und trotz postfaktischem deutlich stressig und das Personal unfreundlicher als der billigste Billigflieger in dem ich je saß!

Außerdem hat kaum mensch Zeit und Lust sich stundenlang in überfüllte Züge und Bahnhöfe zu quälen!

Gibt nur sehr wenige Ausnahmen die bequemer sind - bspw. Köln-Frankfurt, aber warum soll Mensch >€400 p.P. & Richtung für CGN<->TXL zahlen wenn der Flug €190 hin & zurück & schneller ist?

dimi, to security
@dimi@techforgood.social avatar

I have published a new article on security theater and tickbox security, two pitfalls that can harm security strategy. They can cause resource waste, false security, and vulnerability. I have been interested in this topic for a long time, and I have updated the article with the latest insights and examples. You can read it here: https://blog.palo-it.com/en/security-theater-tickbox-security . Please share your feedback and comments.

salixlucida, to pdx
@salixlucida@mastodon.sdf.org avatar

So is utterly useless, as I've long suspected. Someone at will hopefully be fired over this. It's time to do away with this that fails to keep a gun out of a carry-on.

https://www.seattletimes.com/seattle-news/politics/wa-state-senator-arrested-in-hong-kong

jmw, to security

Look. I get it. More is better.

But at what cost?

My gripe today is every website I use suddenly requiring 2FA when there would be little/if any info that could be gained from them.

Does my boardgame collection management site REALLY need to email me a code "JUST TO MAKE SURE IT'S ME"? I am pretty sure they cannot transfer a game from my collection to someone else's with the click of a button.

This becomes even more irksome when it's some random website that I signed up for with a user/pass and NOW it wants to send me emails to confirm it's me. Maybe I'm the only one on the planet however I'm not staring at my inbox 24/7 just waiting for a code. Let me opt out of this junk.

I am NOT against security. all the things for financial, healthcare, identity and other high risk targets (or their tangential sites) but at some point it's just a pain in the ass going back and forth between sites, (which is bad -anyway-), Email, the authenticator app, etc.

That's not even address the fact that these 2FA solutions often seem like security theater, which means it's making my chore longer for zero actual benefit.

jmw,

@dreadpir8robots I totally agree. I was trying to make it clear that I'm not being a stick in the mud sysadmin screaming "KILL ALL 2FA!". I just despise the of putting 2FA everywhere, just because.

I also know that these methods stop the 'honest thief' but anyone with any real dedication to doing harm can buy 0days, steal cookies, spearphish, gain access to email, sms, etc.

Those looking to do real harm likely aren't going attack services using my creds.

huey, to random

I wonder why the CSA is now recommending people install antivirus apps on their smartphones since it's not clear that antivirus apps improve cybersecurity on mobile devices and in fact may provide another vector for infection

https://www.straitstimes.com/singapore/download-these-antivirus-apps-csa-urges-in-latest-drive-against-cybercrooks

MadiqIzichi,
@MadiqIzichi@kopiti.am avatar

@huey the recommendation is so that they covered their own ass. In the future event of someone falling victim, they can deny responsibility by saying, ”we already told you to install antivirus"

modacitylife, to random
mfeilner,
@mfeilner@mastodon.cloud avatar

@modacitylife But over here, in Germany, we are still more stuck in the culture of victimizing the not-car-drivers.

peterdutoit, to climate
@peterdutoit@mastodon.green avatar

deleted_by_author

  • Loading...
  • kkarhan,
    @kkarhan@mstdn.social avatar

    @peterdutoit Ask those flying why they "choose" a plane...

    Usually it's lack if high speed rail espechallythe [ has no excuse for that!] or the lack of cheaper, more convenient in spite of the [] of efficient options.

    BTW: are even worse polluters both per passenger kilometer and efficiency!
    https://www.youtube.com/watch?v=aVAWYBLymYw&t=230s

    pludikovsky, to random
    @pludikovsky@chaos.social avatar
    socialhack, to random

    Weil ich gefragt wurde: whatsappsim.de ist keine |s Verletzung. @telefonica_de tut nur so als würde bevorzugt. Nach aufgebrauchtem Datenvolumen ist das gesamte Netz weiterhin mit 32 kBit/s abrufbar. Nennt man application-agnostic zero-rating 👍

    kkarhan,
    @kkarhan@mstdn.social avatar

    @socialhack technisch gesehen ist es dann ein Verstoß gegen wenn entdrosselt wird aber z.B. , oder nicht.

    aber ich würd's wegen dem postfaktischen eh nicht kaufen...

    miss IMHO verfügbar bleiben!

    raymondpert, to Florida
    @raymondpert@mstdn.social avatar

    is 26th state to allow permitless carry despite risks to public safety, growing opposition

    >No permit, safety training, or background check: That's what's needed to carry a loaded in over half the country. Nothing! is the 26th state to let adults carry without a permit or license. Meanwhile, states that allow permitless carry, which is also called "constitutional carry," continually see increased violence and death.
    https://www.dailykos.com/stories/2023/7/20/2182214/-Florida-is-26th-state-to-allow-permitless-carry-despite-risks-to-public-safety-growing-opposition

    kkarhan,
    @kkarhan@mstdn.social avatar

    @AT1ST @raymondpert would you retract that moot point if the most successful attacker was with an axe in Germany and not the person with a Glock and 300+ rounds?

    Not to mention that in the post- & post- era any gun orohibition is not effectively enforceable, thus only resulting aka. false sense of security...

    jonny, (edited ) to random
    @jonny@neuromatch.social avatar

    ok im joining late because i can't stand ads. temporary magnet link in reply if you feel similarly

    (edit: you can also mute this thread if monsterdon is annoying u)

    jonny,
    @jonny@neuromatch.social avatar

    see the whole making sure you have one person standing guard thing doesn't work when both of them are clearly space vampires

    xgranade, to random
    @xgranade@wandering.shop avatar

    It's already the case that flying generally involves the threat or actuality of groping, invasive searches, denial of accessibility accommodations, and other violations of bodily autonomy. Now it gets worse with consent violation formalized at a technical level.

    There is an irony to that borders are where boundaries do not exist, and that we have made the entire US into a network of borders.

    https://www.washingtonpost.com/technology/2023/07/11/tsa-airport-security-facial-recognition/

    via https://mastodon.online/@evangreer/110696961117374420

    kkarhan,
    @kkarhan@mstdn.social avatar

    @xgranade nodds in agreement

    I think this whole , and shit needs to stop!
    https://www.youtube.com/watch?v=-LDzOi1dyAA

    StillIRise1963, to random
    @StillIRise1963@mastodon.world avatar

    Hair salon owner tells nonbinary patrons to 'seek the services of a pet groomer'

    Here we go. 🤬 Many more will follow.

    https://www.rawstory.com/scotus-website/

    kkarhan,
    @kkarhan@mstdn.social avatar

    @DelilahTech @KrissyKat @matty I mean, the shitty at airports - espechally in the USA - is just nerve-wrecking...

    DelilahTech,

    @kkarhan
    Truth. The airlines rely on us mechs and techs to keep the planes in the air, but heaven forbid we bring a tool into the cabin...
    @KrissyKat @matty

    AufstandLastGen, to random German

    🏎️ Boxenstopp für die Bundesregierung!

    „Wir lassen uns den Spaß alle nicht vermiesen.“ sagte Thomas Voss (Leiter ADAC Motorsport).

    👉🏽 Wir fragen uns: Wie lange wollen wir die Klimakatastrophe noch verdrängen?

    1/3

    video/mp4

    kkarhan,
    @kkarhan@mstdn.social avatar

    @atarifrosch @AufstandLastGen

    Also ich weiß ja nicht ob's das denen wert ist aber ist denen Entscheidung...
    https://climatejustice.social/@AufstandLastGen/110691090761132968

    Ich bin ja der Ansicht wenn mensch schon was riskiert dann doch bitte für etwas was wirklich direkten und nachhaltigen Einfluss hat...

    Ich sehe nur dass es hier am Ende nur mehr geben wird und man dies als Vorwand für mehr nutzen wird, was anderen Protesten nachhaltig schaden würde...

    futurebird, (edited ) to random
    @futurebird@sauropods.win avatar

    How long will USB-C be the most common & standard connector for consumer electronics? (there can be updates to voltage and protocols, but it must be backwards compatible to what we have now)

    kkarhan,
    @kkarhan@mstdn.social avatar

    @DrewNaylor
    I mean and the subsequent german copy () really are fast and only beaten by and it's relative, .

    At 3h 15min from to , it's faster than flying considering the and the need to catch connecting trains of we compare Statio-to-Station.

    In fact, even if I were able to race at 250+ km/h up until the french border if not straight to Paris, it would not be possible to even keep up.

    Reborn_Cat_Mom, to random
    @Reborn_Cat_Mom@chaosfem.tw avatar

    It is a twisted sense of amusement when I explain to CIS people why I plan extra time to go through airport security.

    That said, so far I’ve been lucky and only had some extra groping during my first flight after transition 🤢. Last few flights I breezed through. But with everything going on, I plan for the worst and hope for the best.

    That means getting there early, having extra documentation even a domestic trip, and everything as close to perfect as possible for security checkpoints.

    kkarhan,
    @kkarhan@mstdn.social avatar

    @NicolaElle @Reborn_Cat_Mom I hate this because it's not actually increasing safety at all!
    https://www.youtube.com/watch?v=-LDzOi1dyAA

    astrid, to random
    @astrid@fedi.astrid.tech avatar

    yippee I got the full crotch patdown by TSA today because I forgot to take my belt off

    kkarhan,
    @kkarhan@mstdn.social avatar

    @astrid the facist at - espechally in the - is one of the reasons I won't enter the ...

    https://www.youtube.com/watch?v=-LDzOi1dyAA

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • tester
  • magazineikmin
  • thenastyranch
  • InstantRegret
  • mdbf
  • Youngstown
  • GTA5RPClips
  • slotface
  • everett
  • rosin
  • cubers
  • kavyap
  • DreamBathrooms
  • modclub
  • khanakhh
  • osvaldo12
  • ngwrru68w68
  • vwfavf
  • cisconetworking
  • Durango
  • anitta
  • normalnudes
  • ethstaker
  • tacticalgear
  • Leos
  • provamag3
  • JUstTest
  • All magazines