Notices tagged with infosec

  1. Conversations with kids, about #, #, and #:

    "Why are they looking at me?"
    "Because they heard you fart."
    "Whhhhat do you mean?!?!"
    "Hearing people can hear farts."

    https://www.jwz.org/blog/2018/11/tell-them-to-stop-listening-to-my-farts/
    !education !parenting # !security

    Wednesday, 21-Nov-18 18:55:42 UTC from status.hackerposse.com in context
  2. actual article  https://mangoposter.club/attachment/2509489 # # # #

    Monday, 15-Oct-18 14:36:58 UTC from shitposter.club in context
  3. @hoergen allerdings: auch sofern ein Ausschaltknopf da ist weiß man trotzdem nicht, ob das Gerät (z. B. iPhone) wirklich aus ist. Zum Beispiel könnte ein Mobiltelefon 1x täglich (unauffällig, ohne Display) hochfahren und schauen, ob es Anweisungen des Herstellers herunterzuladen gibt und sich wieder ausschalten.
    Es werden ja schon lange keine die-Stromversorgung-physisch-trennenden Schalter mehr verwendet. !infosec

    Sunday, 10-Jun-18 10:28:35 UTC from quitter.no
  4. With all my gripes with# Signal (centralized, non-federated, server-based, Electron-based desktop app), the fact that in my circle of contacts it's not longer the "pretty good solution we should be using" but the "pretty good solution we are using but looking for something better" is such a win.

    I just wanted to stop for a second and appreciate that.

    If we're talking about the need to move to something better than Signal, we are in a pretty decent place.

    Wednesday, 23-May-18 17:33:38 UTC from mastodon.social Repeated by mmn
  5. With all my gripes with# Signal (centralized, non-federated, server-based, Electron-based desktop app), the fact that in my circle of contacts it's not longer the "pretty good solution we should be using" but the "pretty good solution we are using but looking for something better" is such a win.

    I just wanted to stop for a second and appreciate that.

    If we're talking about the need to move to something better than Signal, we are in a pretty decent place.

    Wednesday, 23-May-18 17:33:38 UTC from mastodon.social
  6. Oh boy. github.com/signalapp/Signal-De

    tl;dr Signal Desktop is based on Electron, which in turn is based on Chromium 58-59, and it seems to be affected by bugs that have been fixed in Chrome/Chromium 60-62.

    Gotta love . As somebody said "now everyone is running 5 different instances of old insecure versions of the most scrutinized and attacked application on Earth."

    Saturday, 12-May-18 12:56:59 UTC from mastodon.social Repeated by mmn
  7. Oh boy. github.com/signalapp/Signal-De

    tl;dr Signal Desktop is based on Electron, which in turn is based on Chromium 58-59, and it seems to be affected by bugs that have been fixed in Chrome/Chromium 60-62.

    Gotta love . As somebody said "now everyone is running 5 different instances of old insecure versions of the most scrutinized and attacked application on Earth."

    Saturday, 12-May-18 12:56:59 UTC from mastodon.social
  8. The office has hundreds of thousands of dollars in computer equipment sitting in open cubes but the extra paper towels and tissue boxes are locked up.

    Monday, 07-May-18 16:45:59 UTC from mastodon.xyz Repeated by moonman
  9. The office has hundreds of thousands of dollars in computer equipment sitting in open cubes but the extra paper towels and tissue boxes are locked up.

    Monday, 07-May-18 16:45:59 UTC from mastodon.xyz
  10. Comodo revoked TLS certificates for some Sci-Hub domains:

    torrentfreak.com/sci-hub-pirat

    #science #infosec

    Thursday, 03-May-18 21:57:48 UTC from boringpeople.org Repeated by akionux
  11. Comodo revoked TLS certificates for some Sci-Hub domains:

    torrentfreak.com/sci-hub-pirat

    #science #infosec

    Thursday, 03-May-18 21:57:48 UTC from boringpeople.org Repeated by moonman
  12. Comodo revoked TLS certificates for some Sci-Hub domains:

    torrentfreak.com/sci-hub-pirat

    #science #infosec

    Thursday, 03-May-18 21:57:48 UTC from boringpeople.org
  13. Defensive Security Podcast Episode 216
    defensivesecurity.org/defensiv

    Saturday, 21-Apr-18 19:42:24 UTC from infosec.exchange Repeated by therubackup
  14. Defensive Security Podcast Episode 216
    defensivesecurity.org/defensiv

    Saturday, 21-Apr-18 19:42:24 UTC from infosec.exchange
  15. Long story short:

    Sunday, 01-Apr-18 12:59:35 UTC from mastodon.social in context Repeated by moonman
  16. Long story short:

    Sunday, 01-Apr-18 12:59:35 UTC from mastodon.social in context
  17. Defensive Security Podcast Episode 214
    defensivesecurity.org/defensiv

    Thursday, 29-Mar-18 01:13:28 UTC from infosec.exchange Repeated by therubackup
  18. Defensive Security Podcast Episode 214
    defensivesecurity.org/defensiv

    Thursday, 29-Mar-18 01:13:28 UTC from infosec.exchange
  19. Oh... wow:
    arstechnica.com/gaming/2018/02

    Flight-sim devs say hidden password-dump tool was used to fight pirates
    Installer ran a "Chrome Password Dump" tool on copies suspected of piracy.

    Monday, 19-Feb-18 16:55:15 UTC from mastodon.social Repeated by mcscx
  20. Oh... wow:
    arstechnica.com/gaming/2018/02

    Flight-sim devs say hidden password-dump tool was used to fight pirates
    Installer ran a "Chrome Password Dump" tool on copies suspected of piracy.

    Monday, 19-Feb-18 16:55:15 UTC from mastodon.social
  21. this seems neat https://jerrygamblin.com/2017/06/12/quickly-building-a-cloud-virtual-lab/ #

    Sunday, 18-Feb-18 16:00:33 UTC from theru.xyz
  22. Can't find an english language news source for this, but it seems that Defender is flagging files that contain short strings (like "Squeamish Ossifrage" or "malicious_x = %p") from the PoC as malware: m.heise.de/security/meldung/Mi

    This is obviously useless for actual threat detection, so are they trying to find people who are playing with the PoC code?

    Saturday, 03-Feb-18 11:55:51 UTC from mastodon.infra.de Repeated by mcscx
  23. Can't find an english language news source for this, but it seems that Defender is flagging files that contain short strings (like "Squeamish Ossifrage" or "malicious_x = %p") from the PoC as malware: m.heise.de/security/meldung/Mi

    This is obviously useless for actual threat detection, so are they trying to find people who are playing with the PoC code?

    Saturday, 03-Feb-18 11:55:51 UTC from mastodon.infra.de
  24. breaks the embargo on : googleprojectzero.blogspot.pt/
    security.googleblog.com/2018/0

    Meet and :
    spectreattack.com/spectre.pdf
    meltdownattack.com/meltdown.pd

    Wednesday, 03-Jan-18 23:39:00 UTC from mastodon.social Repeated by hfaust
  25. breaks the embargo on : googleprojectzero.blogspot.pt/
    security.googleblog.com/2018/0

    Meet and :
    spectreattack.com/spectre.pdf
    meltdownattack.com/meltdown.pd

    Wednesday, 03-Jan-18 23:39:00 UTC from mastodon.social Repeated by moonman
  26. breaks the embargo on : googleprojectzero.blogspot.pt/
    security.googleblog.com/2018/0

    Meet and :
    spectreattack.com/spectre.pdf
    meltdownattack.com/meltdown.pd

    Wednesday, 03-Jan-18 23:39:00 UTC from mastodon.social
  27. Yo #infosec - new malware, "Petya"

    It's wcry again, but with the killswitch taken out and some phishing initial delivery.

    And by "it's wcry again" I mean it. Same exploit. Same traffic. Same everything. If your org bothered patching or mitigating, then this won't affect you.

    Tuesday, 27-Jun-17 16:03:15 UTC from mastodon.hasameli.com Repeated by archaeme
  28. Yo #infosec - new malware, "Petya"

    It's wcry again, but with the killswitch taken out and some phishing initial delivery.

    And by "it's wcry again" I mean it. Same exploit. Same traffic. Same everything. If your org bothered patching or mitigating, then this won't affect you.

    Tuesday, 27-Jun-17 16:03:15 UTC from mastodon.hasameli.com
  29. Apart from ideological arguments (with which I largely agree), are there any concrete reasons/arguments to use #VeraCrypt full disk encryption for #Windows, rather than the integrated #BitLocker?

    #InfoSec

    Monday, 15-May-17 09:57:37 UTC from mastodon.social in context Repeated by mcscx
  30. Apart from ideological arguments (with which I largely agree), are there any concrete reasons/arguments to use #VeraCrypt full disk encryption for #Windows, rather than the integrated #BitLocker?

    #InfoSec

    Monday, 15-May-17 09:57:37 UTC from mastodon.social in context