Zum Inhalt der Seite gehen

Suche

Beiträge, die mit infosec getaggt sind


Download this pdf now before it is taken down by Trump/Musk:

Mobile communications best practices guide from the Federal Cybersecurity and Infrastructure Security Agency. (2/x)

#Resistance #Infosec

https://www.cisa.gov/sites/default/files/2024-12/guidance-mobile-communications-best-practices.pdf


(Rebooting this chain from last month - with updates.)

Recommendation #1: This is a priority: Practice security culture.

The Electronic Frontier Foundation has a fabulous on-line guide to Surveillance Self-Defense. (1/x)

#Resistance #Infosec

ssd.eff.org


This has to be actionable.

#Musk aides lock #GovernmentWorkers out of computer systems at #US #FederalAgency

Aides to #ElonMusk charged have locked career #CivilServants at #OPM out of computer systems that contain the #personal #data of millions of federal #employees

Since taking office, #Trump has embarked on a massive govt makeover, firing & sidelining hundreds of civil servants & installing more loyalists.

#law #cybersecurity #oversight #NationalSecurity #InfoSec
https://www.reuters.com/world/us/musk-aides-lock-government-workers-out-computer-systems-us-agency-sources-say-2025-01-31/


#ElonMusk staff Have #Infiltrated Another #Government Agency - Elon Musk’s former employees are trying to use #WhiteHouse #credentials to access General Services Administration #GSA tech, giving them the potential to remote into #laptops, read #emails, and more, sources say. mass #cybercrime attack against the federal government #infosec this #cybersecurity breach by non government agents is a crime. the damage will be irreparable. https://www.wired.com/story/elon-musk-lackeys-general-services-administration/


#WhatsApp confirms that nearly 100 journalists and "other #civilsociety members" have been targeted and possibly compromised on a zero-click attack (meaning they didn't do anything on their own to let the malware in).

If Meta's boss new political leanings were not enough to convince folks that none of its platforms are trustworthy enough as to manage sensitive information and conversations in them, maybe this is your #Signal

#journalism #infosec

https://www.theguardian.com/technology/2025/jan/31/whatsapp-israel-spyware


Data Deletion: How to Stay Safe & Clean-Up Your Online Presence
Who is this for?
This is for you if:
- You have someone to protect
- You have something to protect
- You're being harassed/stalked/DV
- You're a journalist, activist, advocate
- You're concerned about your digital footprint
https://lockdownyourlife.as.me/data-deletion

#security #privacy #community #training #safety #tech #infosec #journalist #education


Guten Morgen liebe*r Fediversebwohner*in,

Werbung ist nicht nur nervig. Sie verbraucht auch eine Menge Daten und verlangsamt damit Webseiten und Apps. Werbeplätze werden in automatischen Auktionen an die Meistbietenden verkauft. Dazu werden verschiedenste Daten über dich gesammelt und verkauft. Außerdem gibt es immer wieder Fälle, in denen Werbung für eine Anwendung gar nicht vom Anbieter stammt sondern von Angreifer*innen, die dich zu Seiten mit Trojanern locken. Oder es wird sogar in der Werbung selbst Schadcode auf seriösen Seiten ausgeliefert.
Es gibt daher gute Gründe, warum du einen Werbeblocker nutzen solltest. Besonders gut ist zum Beispiel uBlock Origin https://addons.mozilla.org/en-US/firefox/addon/ublock-origin/ Neben Werbung unterbindet uBlock Origin auch Tracker, die deine Daten sammeln, oder bekannte Seiten mit Schadcode.
Webseiten werden schneller geladen und sind ohne die ganze Werbung viel besser zu lesen. Ich bekomme jedes mal einen kleinen Schock, wenn ich Webseiten mal ohne Werbeblocker sehe.
Da Google in Chrome die Schnittstelle für Erweiterungen so geändert hat, das Werbeblocker nicht mehr richtig arbeiten, solltest du Firefox eine Chance geben. Hier funktionieren die Erweiterungen wie sie sollen.
Sowohl Firefox als auch uBlock Origin sind OpenSource. Du kannst sie also kostenlos nutzen und bei Problemen auf eine breite Community zurückgreifen.
Wenn du einer Webseite Geld zukommen lassen möchtest, weil du jetzt keine Werbung mehr siehst und damit deren Einnahmequelle wegfällt, gibt es meistens auch andere Wege. Z.B. Abos, Spenden, Mitgliedschaften oder Dienste wie Patreon. Gerade in Zeiten von Fakenews und KI, die alles frisst was erreichbar ist, ist eine unabhängige Finanzierung guter Angebote von Qualität notwendig.
Nimm den heutigen Tag als Anlass und probiere Firefox mit uBlock Origin.

Habt einen wundervollen Tag

#infosec #itsecurity #goodmorning #shakeupitsecurity #wisdomoftheday
Eine Postkarte mit dem Logo von seism0saurus auf der linken Seite. Ein gezeichneter Seismosaurus im Comicstil. Neben seinem langen Hals steht nicht ganz ernst gemeint "Shake up it-security" und seine Homepage seism0saurus.de
  
Rechts daneben der Spruch des Tages: "Schon das Werbefreie Internet getestet? Nutze Firefox und uBlock Origin."


So using a non-google maps app is possible & probably a good idea. Giving your location to google is not safe going forward.

Been using & experimenting with some & I think you might want to find some too.

Apps: https://european-alternatives.eu/category/navigation-apps

https://www.cnbc.com/amp/2025/01/27/google-maps-to-show-gulf-of-america-after-government-updates.html

cc @european_alternatives

#maps #navigation #google #infosec #USpol #location #DataEthics


Could any #privacy , #infosec people weigh in on whether the you tube guy Rob Braxman is legit. The usual searches don't lead to much.
https://www.youtube.com/@robbraxmantech


Guten Morgen liebe*r Leser*in,

Gerade bei mobilen IT-Geräten wie Laptops, Smartphones oder Tablets werden viele persönliche Daten durch die Gegend getragen. Um diese zu schützen, solltest du die Geräte verschlüsseln. Zum Glück musst du dafür heute nicht mehr manuell mit kryptografischen Befehlen hantieren. Android und iOS verschlüsseln Smartphones und Tablets automatisch. Selbst Laptops sind inzwischen meistens mit Windows BitLocker oder Apples FileVault verschlüsselt. Falls deine Version von Windows kein BitLocker unterstützt oder du ein externes Laufwerk so verschlüsseln möchtest, dass du es auch unter MacOS oder Linux entschlüsseln kannst, kannst du VeraCrypt einsetzen. VeraCrypt ist ein OpenSource Tool, dass sich auf die Verschlüsselung von Partitionen konzentriert.
Nimm den heutigen Tag als Anlass und verschlüssele deine Daten.

Habt einen guten Tag!

#infosec #itsecurity #goodmorning #shakeupitsecurity #wisdomoftheday
Eine Postkarte mit dem Logo von seism0saurus auf der linken Seite. Ein gezeichneter Seismosaurus im Comicstil. Neben seinem langen Hals steht nicht ganz ernst gemeint "Shake up it-security" und seine Homepage seism0saurus.de
  
Rechts daneben der Spruch des Tages: "Hast du deine Festplatte verschlüsselt? Schütze deine Daten vor unbefugtem Zugriff."


Conduent Confirms Cyberattack After Government Agencies Report Outages - https://mwyr.es/jCKF1Puc #securityweek #infosec


Browser (Firefox): Bitwarden, CanvasBlocker, Decentraleyes, D̶i̶s̶a̶b̶l̶e̶ ̶J̶a̶v̶a̶S̶c̶r̶i̶p̶t̶,̶ ̶D̶o̶n̶'̶t̶ ̶T̶r̶a̶c̶k̶ ̶M̶e̶ ̶G̶o̶o̶g̶l̶e̶,̶, Containers, P̶r̶i̶v̶a̶c̶y̶ ̶B̶a̶d̶g̶e̶r̶, uBlock Origin, S̶e̶a̶r̶c̶h̶ ̶b̶y̶ ̶I̶m̶a̶g̶e̶.

Self-hosted: SearXNG, Redlib, NextCloud, Immich.

Network: Pi-hole + Unbound DNS, VPN, DNS leak tests.

Email: ProtonMail, alias sign-ups.

What am I missing? Any tips?
Just go Tor 24/7 at this point?

Edit:
added strike-through

#Privacy #Anonymity #Infosec #CyberSecurity


Hey, what about I start spinning off some threads 🧵 with quick and easy tips for #journalist and #activist to improve their workflow ( #opsec & #infosec focus ). You know that you can click an hashtag and choose "See #tips posts by user" to see all my posts with that specific hashtag. (bsky only)


7-Zip-Entwickler Igor Pavlov behebt Sicherheitsproblem: Neue Version 24.09 schließt Lücke, die Windows "Mark-of-the-Web"-Schutz umgeht. #InfoSec https://winfuture.de/news,148320.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia


There's a "Signal deanonymized" thing going around:
https://gist.github.com/hackermondev/45a3cdfa52246f1d1201c1e8cdef6117

Stay calm. Deep breaths.

👉 while this is a real consideration, the only thing the attacker gets from this is a very rough (kilometers or tens of kilometers radius) location

👉 other communication platforms that use any kind of caching CDN to deliver attachments are just as affected

👉 you almost certainly should continue to use Signal, unless you specifically know that this is a big problem for you.

#Signal #InfoSec


Hello fellow fediverse denziens. I just deleted my #Facebook account and moved here. I didn't use #Twitter or #Instagram, so if I do weird things here that's probably why. I will, for example, use full sentences and the Oxford comma.

I live in #Portland, #Oregon with my wife and cat. I am currently trying to escape the corporate world, where I work as an #infosec professional. I am an #OSU Apprentice #Beekeeper and have two hives of #bees. And they're still alive!

#introduction


Update:
Proton removed their response (link below) from Mastodon, seems they realized it exploded into their face.

Original toot:
After I had given #Protonmail the benefit of the doubt for one board member making inconsiderate and alarming statements on #MAGA #Trump, they have doubled down officially:
https://mastodon.social/@protonprivacy/113833073219145503

I therefore consider this official opinion of Proton. Focussing on one aspect and completely ignoring the bigger picture of a luming fascist period in the most militarized economy of the world is just inacceptable. Proton just could have kept their mouth shut, but they decided not to.
Thanks for revealing yourselves and happy to end my subscription, I won't support a company like you until you do better @protonprivacy

Please boost to spread this news if you find this important.

@kuketzblog @chpietsch @aral
@linuzifer

#ProtonExodus #Proton #E2E #Email #Privacy #Infosec


The rsync utility in Linux, *BSD, and Unix-like systems are vulnerable to multiple security issues, including arbitrary code execution, arbitrary file upload, information disclosure, and privilege escalation. Hence, you must patch the system ASAP https://www.cyberciti.biz/linux-news/cve-2024-12084-rsyn-security-urgent-update-needed-on-unix-bsd-systems/

#infosec #security #linux #unix
A critical vulnerability (CVE-2024-12084 and five others) requires immediate patching on Linux, *BSD, macOS, and Unix-like systems to protect your systems from attacks. Update Rsync now!


Nutzer-Standorte aus Zehntausenden Apps stehen zum Verkauf

https://www.tagesschau.de/investigativ/br-recherche/standortdaten-apps-datenhandel-100.html

>> Millionen von #Standortdaten aus Apps fließen an #Datenhändler ab - das zeigen Recherchen des BR mit internationalen Partnermedien.[...] Experten sprechen von "Kontrollverlust".

>> [...] Wetter Online, Flightradar24, Kleinanzeigen oder Focus Online.

#InfoSec


#osint - Open-source intelligence is the foundation on which we'll rebuild non-billionaire real news, because we now have to.

Interested folks can learn valuable research skills for free, online. Bellingcat is the best place to start.

#journalism #infosec #research #librarian #internship #datamining #factchecking https://mstdn.social/@Bellingcat/113753859276481024


#GrapheneOS appears to be standing up to UK forensics, in this painful and "unprecedented" case which could see a UK journalist go to jail for not relinquishing the passphrase to his devices. Not only is withholding his basic human right, but he does it to protect his sources, and as ratified in the European Court of Human Rights.

https://www.ilfattoquotidiano.it/in-edicola/articoli/2025/01/02/british-journalist-could-face-years-in-prison-for-refusing-to-hand-over-his-passwords-to-the-police/7822432/

#humanrights #infosec #privacy


Beware of sympathy scams. Every conflict brings scammers tugging at heartstrings to get donations. This has been happening for years. Always research campaigns asking for money—sadly, your generosity might not be helping the actual victims. Stay vigilant. #Cybersecurity #InfoSec #Scam #Ukraine #Gaza


LockBit Ransomware Developer Arrested in Israel

#Israel #infosec
https://www.darkreading.com/cyberattacks-data-breaches/lockbit-ransomware-developer-arrested-israel


Un cybercriminel membre du célèbre gang de hackers Lockbit se cachait en Israël
https://www.numerama.com/cyberguerre/1869958-un-cybercriminel-membre-du-celebre-gang-de-hackers-lockbit-se-cachait-en-israel.html

#Infosec #Security #Cybersecurity #CeptBiro #Cybercriminel #Lockbit #Israel


Cellebrite Unlocked This Journalist’s Phone. Cops Then Infected it With Malware Just another day in dystopian paradise. www.404media.co/cellebrite-u...#infosec #malware #spyware #opsec #ethics #journalism

Cellebrite Unlocked This Journ...


Want To Make The Most Of Tails Amnesiac Linux OS "Pull Out" Feature?

💡 Try My Idea: USBSTICK "Pull The Plug" Bracelet (ideal for Tails)

This idea allows you to attach yourself to the inserted Tails disk, by bracelet (on demand)

If your arm ever gets too far from the computer: *POOF* there goes forensics! 😁

#HumanRights #Journalism #Tails #Linux #privacy #forensics #ideas #tech #GNU #fun #bracelet #jewelry #RAM #coldbootattack #infosec #cybersecurity #TorProject

https://tube.tchncs.de/w/q2Vdv11aTrmgAjKrrAULw2


I'm not sure what it says about me that the first thought I had when I heard about the "david meyer" chatgpt kerfuffle, was "woah, that would be so easy to weaponize!" And it is! Because OpenAI chose to go with the cheapest option: blocking the offending term through an asynchronous, case insensitive exact match against a deny list, and doing it asynchronously to ensure it doesn’t impact latency.

#openai #chatgpt #Enshittification #infosec

https://centreforaileadership.org/resources/analysis_the_curious_case_of_one_david_mayer/


Hacker In Snowflake Extortions May Be A US Soldier - https://mwyr.es/aLTNK6i2 #infosec


I'm looking for a new job doing security assessments / research.

I spent the last 6 years building advanced security assessment capabilities around hardware/IoT, industrial, marine OT, and x86 platforms. Before that I spent 5 years as a pentester. I excel at weird and novel stuff with no template.

I'm in the UK and I'm looking for a full-time remote role.

CV: https://poly.nomial.co.uk/graham_sutherland.pdf

Please get in touch if you know of any available roles! :)

#getfedihired #fedihire #fedihired #infosec


The fact that media outlets are falling for impersonator accounts on Bluesky highlights how much the media’s ability to fact-check and verify information has declined. This issue isn’t just about Bluesky’s verification system—it’s also about journalistic responsibility.
#journalism #infosec
1/5