@cy@chaos.social
@cy@chaos.social avatar

cy

@cy@chaos.social

software, security, devoops, DevOps Meetup Karlsruhe, CCC, milliways

This profile is from a federated server and may be incomplete. Browse more on the original instance.

cy, to random
@cy@chaos.social avatar

@psy finde den thread zu externem Monitor nicht mehr, aber im Zweifelsfsall ist sowas beim großen A grade "billig" zum Ausprobieren:

https://www.amazon.de/dp/B092KKLH93/ (coupon checkbox klicken, 100eu neuer preis)

arstechnica, to random
@arstechnica@mastodon.social avatar

Flipper Zero gadget that DoSes iPhones takes once-esoteric attacks mainstream

No cure yet for a popular iPhone attack, except for turning off Bluetooth.

https://arstechnica.com/security/2023/11/flipper-zero-gadget-that-doses-iphones-takes-once-esoteric-attacks-mainstream/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

cy,
@cy@chaos.social avatar
mcfly, to tv German
@mcfly@milliways.social avatar

A first for me today:

A manager refuses to believe something security says because "I have seen in CSI:Cyber that this works without problems...."

cy,
@cy@chaos.social avatar

@mcfly oh boy

cy,
@cy@chaos.social avatar

@mcfly well, at least get him to document this in writing

RichiH, to random
@RichiH@chaos.social avatar

By sheer accident, I just noticed that I'm at 999 followers. Let's see who the lucky(?) 1000th will be be.

cy,
@cy@chaos.social avatar

@RichiH let me quickly unfollow until someone else clicks, so i can be 1000 :D

tychotithonus, (edited ) to random

Only the YubiKey 5 series supports creating and storing passkeys ("resident WebAuthn credentials"), and you can only store 25 of them.

Also, non-passkey use of YubiKeys appears to no longer be [reliably*] supported by Google's Advanced Protection Program. You have to create a reliable passkey, then delete and re-add all of your existing keys (listed under "2-step verification only security keys"). Some of my keys are ... extremely offsite, so it will take time to restore my previous levels of redundancy.

I think I'm starting to understand how we got here, but I'm still unhappy that the benefits of the previous model - in which unlimited sites could be used with each security key, and U2F keys were backward compatible - are gone.

I also feel as though Google, Yubico, and others could have done a better job of communicating the consequences for advanced users ... in advance. Instead, Google searches for "2-step verification only security keys" currently only produce 5 results, which are Reddit threads full of commiserators and Google support threads like this one that are locked without response:

https://support.google.com/accounts/thread/213974810/how-can-i-migrate-a-device-from-2-step-verification-to-full-passkey

* Once any passkeys use is enabled, some APP users (including me) can sometimes do a fresh Google login from scratch on a new device with only a security key .. but other times, any "2-step verification only" key you try is rejected as unrecognized. I do not know what the variability is - and the forums are full of people with similar complaints.

UPDATE: On further testing, and based on reports from others on the side, it may be that the symptoms I (and the folks in the forums) experienced were a problem for the first few months at launch, but may have been fixed. It last failed for me about a month ago, but I'm unable to recreate from Incognito. But since Google uses many signals to determine how to prompt for what kind of MFA, I am not at all confident that I will be able to use non-passkey security keys from a fresh computer in a new geographic location away from my phone. If Google fixed something , I do wish they'd say something about it somewhere, so that I can key with confidence!

Update 2: a friendly, authoritative reply that we don't think anything has changed, so the symptoms are still mysterious (and maybe more common if a PIN is set on the key?):
https://infosec.exchange/@skarra/111309708728390341

Update 3: And to head off some side questions - this doesn't diminish my YubiKey fanboy-ness. :D I do see the trade-offs, and the middle ground for me will probably look something like storing my "top 20" critical passkeys on YubiKeys, and keeping all the others in a password-management layer.

cy,
@cy@chaos.social avatar

@tychotithonus Resident keys are only needed in 1 scenario which is "login without username". For everything else, non -resident keys should be ok, and not less secure.

cy,
@cy@chaos.social avatar

@tychotithonus yes.
The non-residential key is generated from a server-based nonce every time you log in. Using the master key. Sadly resident keys became somewhat default. default .
I explained here more in-depth https://media.ccc.de/v/camp2023-57174-fido2#t=1520
(the slide is misleading though, "discouraged" means "non-discoverable" or "non-residential" key. i copy-pasted the "discouraged" from the setting before that timestamp

genkin, to random

For those wondering if Apple’s iOS/iPadOS 17.1 and macOS 14.1 released yesterday protect against https://ileakage.com/? We took a look for you, the answer is no. Devices are still vulnerable.

cy,
@cy@chaos.social avatar

@dangoodin @genkin well what is another couple of days on top of the >400days apple had known about the vulnerability though ¯⁠\⁠⁠(⁠ツ⁠)⁠⁠/⁠¯

kuketzblog, to ads German
@kuketzblog@social.tchncs.de avatar

Wer grob testen möchte, wie gut seine Adblocker (uBlock Origin, Pi-hole, AdGuard etc.) funktionieren, kann diese Testseite besuchen. 👇

Meine Blockrate: 99%

https://d3ward.github.io/toolz/adblock.html

cy,
@cy@chaos.social avatar

@kuketzblog spannend.
Brave auf Android: 96%
Firefox Klar: 52%
Beides recht Default eingestellt

jpmens, to random
@jpmens@mastodon.social avatar

deleted_by_author

  • Loading...
  • cy,
    @cy@chaos.social avatar

    @jpmens after slaughtering the cow themselves

    keepassxc, to random
    @keepassxc@fosstodon.org avatar

    Help us test PassKeys! We just merged our PassKey support to our next release branch. You can grab a snapshot build and test it out now. We already released support in our browser extension.

    Test now: https://snapshot.keepassxc.org/latest/

    Development work: https://github.com/keepassxreboot/keepassxc/pull/8825

    cy,
    @cy@chaos.social avatar

    @joel @keepassxc https://media.ccc.de/v/camp2023-57174-fido2 if you got an hour to listen to a sweaty hungover dude during summercamp :D

    cy,
    @cy@chaos.social avatar

    @keepassxc how do you tackle the attestation requirement? do you map the keypass container to the hardware? could there be some passkey services you will not be able to use keepassxc for? (and will keepassxc be FIDO certified?)

    cy,
    @cy@chaos.social avatar

    @keepassxc aight, that's what I expected. thx for clearing up

    simon_brooke, to climate
    @simon_brooke@mastodon.scot avatar

    5.3 metres – the degree of sea level rise now unavoidable from West Antarctic Ice Sheet melting ALONE – is sufficient to entirely submerge most of urban Abu Dhabi, Bahrain, Dubai, and an enormous area of southern Iraq (Qatar gets off surprisingly lightly).

    Are they sure they want to pump YET MORE oil?

    https://coastal.climatecentral.org/map/6/50.1713/28.1743/?theme=water_level&map_type=water_level_above_mhhw&basemap=roadmap&contiguous=true&elevation_model=best_available&refresh=true&water_level=5.3&water_unit=m

    cy,
    @cy@chaos.social avatar

    @simon_brooke where do you get the 5.3m from?

    cy,
    @cy@chaos.social avatar

    @simon_brooke in what timeframe? :D

    cy,
    @cy@chaos.social avatar

    @Brendanjones @simon_brooke well since we are in the migration from the "fuck around" into the "find out" phase, i guess "we'll see" 😮

    nixCraft, to random
    @nixCraft@mastodon.social avatar
    cy,
    @cy@chaos.social avatar

    @nixCraft if only xenia had become the mascot, we'd all be running Linux by now

    GossiTheDog, to random
    @GossiTheDog@cyberplace.social avatar

    deleted_by_author

  • Loading...
  • cy,
    @cy@chaos.social avatar

    @GossiTheDog my guess: it works like the keychain in general is synced. like you used to sync passwords back and forth between devices before passkeys (where the synced part is basically a private key, as syncable as a very long password)

    padeluun, to random German
    @padeluun@digitalcourage.social avatar

    Carl Waßmuth: „Als wir vor 30 Jahren die Bahnreform bekommen haben, gab es 6.000 sogenannte Bahndirektoren, was als verschwenderisch angeprangert wurde. Heute leistet sich die Bahn 20.000 Manager.

    Wenn jeder von ihnen 100.000 Euro Jahresgehalt bekommt, sind das bereits zwei Milliarden jährlich! Gleichzeitig wurden 190.000 Stellen eingespart.“

    https://www.telepolis.de/features/Deutsche-Bahn-Mit-20-000-Managern-auf-dem-Weg-zur-Privatisierung-9336094.html

    cy,
    @cy@chaos.social avatar

    @Andrew_K @padeluun @HolgerPieta vielleicht muss man da aufpassen was in einem Laden ein "manager" ist.
    Facility Manager leert auch (dankenswerterweise) die Mülleimer.
    gibt auch Firmen die nennen den Teamleiter "Teammanager"

    masek, to random

    Charging devices via USB C is driving me crazy

    During the last vacation my wife forgot her cable to charge her iPad. So I bought locally a cheap USB A to USB C charging cable.

    Unluckily that cable would not charge anything:, not her iPad, not my iPad, not my Steam deck, not my MacBook and not my Kindle. All those devices could be charged by the single, then most heavily used cable I brought with me.

    The locally bought cable only worked for the Android mobile phone of the vendor (which she demonstrated happily).

    Today I wanted to charge my Abus SmartLock BORDO One 6500A. It also uses USB C. None of my standard cabled worked. I tried dozens of them.

    Then I tried the shitty cable from the vacation and connected it to a powerbank. Suprise: now the lock is charging. What devilish mechanism is this?

    cy,
    @cy@chaos.social avatar

    @masek same with data cables.
    i have multiple usb-c cables that work fine with most devices, but NOT on my idabao id80 keyboard (however works on my keychron v1).
    a cheap-end cable that came with another device works on the id80, and my phone, but not on the keychronv1 :D

    CCC, to random German
    @CCC@social.bau-ha.us avatar

    Thorn als Geldmaschine: Debatte über die massiv beeinflusst, vor allem eigene Software angepriesen https://www.heise.de/news/Chatkontrolle-Verfechter-Thorn-Geldmaschine-statt-Wohltaetigkeitsorganisation-9327679.html

    cy,
    @cy@chaos.social avatar

    @CCC ich bin überrascht!!!11

    nixCraft, to random
    @nixCraft@mastodon.social avatar

    What type of information are they going to collect in the room? What could possibly go wrong?

    cy,
    @cy@chaos.social avatar

    @nixCraft Alexa, does my snoring sound like i'm dying?

    thopan, (edited ) to random German
    @thopan@norden.social avatar

    Frage an die Leute, die ihre Geräte wie Laptops mit Sicherheits-Token wie YubiKey oder Nitrokey, … und so absichern: Welche USB-/NFC-Tokens nutzt/empfehlt ihr?

    Ich würde meinen Laptop (Linux-/Win-Dualboot) und mein Smartfon damit beglücken wollen. Lese mch gerade ins Thema ein.

    :boost_ok:

    cy,
    @cy@chaos.social avatar

    @thopan imho geben sich die Hersteller nicht viel. ich würd tatsächlich mal die feature-listen nebeneinander legen.
    Mein Tip: überleg dir welchen Formfaktor bzw. welchen Anschluss du willst. wenn du laptop und phone mit usb-c hast, brauchst bei usb-a stick immer nen adapter, nicht unterschätzen :D
    das was du machen willst sollten alle hersteller können, evtl willst du auch FIDO2 support, um passkeys mit dem Stick zu machen, können auch die meisten. Nitrokey ist ne deutsche Firma, "regional"! :D

    jerry, to random

    Happy Friday! Don’t forget to git push to prod on your way out this afternoon

    cy,
    @cy@chaos.social avatar

    @jerry why would you push to prod yourself?
    dont you have automation to do this couple times during any day?

    davidrevoy, to random
    @davidrevoy@framapiaf.org avatar

    In the Press right now:

    "All Those NFTs Are Officially Worthless" → https://kotaku.com/nft-meaning-scam-crypto-marketplace-price-bored-ape-1850860661

    "Your NFTs Are Actually — Finally — Totally Worthless" → https://www.rollingstone.com/culture/culture-news/nfts-worthless-researchers-find-1234828767/

    Me:

    cy,
    @cy@chaos.social avatar

    @davidrevoy next step "your Bitcoin is worthless"

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • ngwrru68w68
  • ethstaker
  • tacticalgear
  • osvaldo12
  • mdbf
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • Youngstown
  • everett
  • InstantRegret
  • slotface
  • rosin
  • provamag3
  • kavyap
  • GTA5RPClips
  • Leos
  • modclub
  • cisconetworking
  • Durango
  • khanakhh
  • cubers
  • normalnudes
  • anitta
  • tester
  • megavids
  • lostlight
  • All magazines