@GossiTheDog@cyberplace.social
@GossiTheDog@cyberplace.social avatar

GossiTheDog

@GossiTheDog@cyberplace.social

Cybersecurity weather person and award winning shitposter. Shitposting is an anagram of Top Insights. You may be surprised to know I am not representing my employer here and these are not their opinions.

I have Direct Messages disabled - you can send them, but I will never receive them.

This profile is from a federated server and may be incomplete. Browse more on the original instance.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

If you want to explain to yourself why companies keep launching all these dumbass AI products and hurting their sentiments and bottom line, keep this @Quinnypig banger in mind.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Microsoft India’s $10k gold tick Twitter account has been flogging cryptocurrency phishing for the last few hours, still going. https://x.com/microsoftindia/status/1797743970010968398

GossiTheDog,
@GossiTheDog@cyberplace.social avatar
GossiTheDog,
@GossiTheDog@cyberplace.social avatar

@sepi1enfwb those aren’t AI 🤣

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

361 million credentials for websites stolen via infostealers have been added to Have I Been Pwned.

Soon we will also have key and screen logs via Recall also being stolen, eg financial account details.

https://troyhunt.com/telegram-combolists-and-361m-email-addresses

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

Very big cyber incident playing out at Snowflake, who describe themselves as “AI Data Cloud”. They have a free trial where anybody can sign up and upload data… and they have.

Threat actors have been scraping customer data using a tool called rapeflake, for about a month.

GossiTheDog, (edited )
@GossiTheDog@cyberplace.social avatar

The deleted Hudson Rock post on Snowflake breach: https://web.archive.org/web/20240531140540/https://hudsonrock.com/blog/snowflake-massive-breach-access-through-infostealer-infection

For the record I don't think all the content is accurate - however Snowflake did have a security incident via their former employee, they have full IR stood up. They didn't follow their own best practices.

I also know multiple orgs who've had their full databases take from Snowflake.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

I wrote a blog on everything I know about the Snowflake situation https://doublepulsar.com/snowflake-at-central-of-worlds-largest-data-breach-939fc400912e

GossiTheDog, (edited )
@GossiTheDog@cyberplace.social avatar

The Snowflake authentication setup is terrible.

MFA can’t be enabled org wide, each user has to manually log in and enable it. There’s no policy to block users without MFA. And it uses Duo MFA rather than your orgs MFA. (You can bring your own MFA with SAML).

Also all users log in via a Snowflake domain, so you can just pull creds from info stealer marketplaces or logs.

That’s why they’re being targeted as a platform.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

@SamJSharpe huh.. I wonder if it’s a licensing thing. Are you an admin on them? I’m pondering how your org set that up.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Hudson Rock have put out a statement saying a legal threat from Snowflake caused them to remove their blog. https://www.linkedin.com/posts/hudson-rock_activity-7203433945919578113-RH05 HT @mattburgess

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

For those who aren’t aware, Microsoft have decided to bake essentially an infostealer into base Windows OS and enable by default.

From the Microsoft FAQ: “Note that Recall does not perform content moderation. It will not hide information such as passwords or financial account numbers."

Info is stored locally - but rather than something like Redline stealing your local browser password vault, now they can just steal the last 3 months of everything you’ve typed and viewed in one database.

video/mp4

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Nvidia just announced that Copilot+ and Recall are coming to AMD systems. https://www.theverge.com/2024/6/2/24169568/microsoft-copilot-plus-gaming-pc-nvidia-amd

GossiTheDog, (edited )
@GossiTheDog@cyberplace.social avatar

Somebody made a tool called Total Recall to dump Recall database and screenshots. https://x.com/xaitax/status/1797349055917416457?s=46

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Recent DHS published report handed to the US President which said it had "identified a series of Microsoft operational and strategic decisions that collectively pointed to a corporate culture that deprioritized enterprise security investments and rigorous risk management"

Microsoft: let’s use AI to screenshot everything users do every 5 seconds, OCR the screenshots, make it searchable and store it in AppData!

Tkn GIF by ROSALÍA

GossiTheDog, (edited )
@GossiTheDog@cyberplace.social avatar

Searching Recall database for passwords with @awakecoding

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

🫡

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

If anybody is wondering if you can enable Recall on a machine remotely without Copilot+ hardware support - yep.

I’ve also found a way to disable the tray icon.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

I went and looked at YouTube for Recall to get out of the echo chamber and I can only find one positive video. Even the people at the event are slating it, including people with media provided Copilot+ PCs.

There’s some content creators who’ve realised it records their credit cards, so they’re making videos of their cards going walkies.

image/jpeg
image/jpeg
image/jpeg

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

@acquirer a Windows fan site

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

It’s going to be interesting to see how Microsoft get out of this one. They may have contractual commitments to ship Recall with external parties.

I thought they were risking crashing the Copilot brand with this one, but I was wrong looking at the videos and comments on them - I think they’re crashing the Windows consumer brand.

The reaction to photographic memory of what people do at home has - you’ll be surprised to know - not been seen as a reason to buy a device, but a reason why not to.

GossiTheDog, (edited )
@GossiTheDog@cyberplace.social avatar

@forgifuzzbutt yep. And there’s loads of tangible security benefits from the rest of the work going on in Windows 11 in terms of security.

They just shit their own bed on this one by not understanding their customers, Apple must be so happy.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

@never_released oh I agree they will be shipping. Commercially it looks like they’ve made New Coke. There’s gonna be victims in terms of fraud from Recall, which is just going to pile on the problems.

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

@Npars01 I don’t think it’s anything like that at all, they’ve probably just signed deals with AMD, Dell etc for laptops with Copilot+

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

@Npars01 that has nothing to do with Recall

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Windows Central, about the only outlet giving Recall positive coverage and having articles tweeted by Microsoft staff - have updated their take after being hands on with a device. https://www.windowscentral.com/software-apps/windows-11/microsoft-should-recall-windows-recall-security-researcher-finds-microsofts-new-ai-tool-woefully-insecure

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

@jt_rebelo yeah, they’re wrong about that. They’re talking to Microsoft people about it and unfortunately Microsoft people don’t seem to understand what happens outside their world.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • thenastyranch
  • magazineikmin
  • mdbf
  • GTA5RPClips
  • everett
  • rosin
  • Youngstown
  • tacticalgear
  • slotface
  • ngwrru68w68
  • kavyap
  • DreamBathrooms
  • khanakhh
  • megavids
  • tester
  • ethstaker
  • cubers
  • osvaldo12
  • cisconetworking
  • Durango
  • InstantRegret
  • normalnudes
  • Leos
  • modclub
  • anitta
  • provamag3
  • lostlight
  • All magazines