Skip to main content

Search

Items tagged with: security


New Privacy Guides video πŸ“Ίβœ¨
by @jw

If you've wondered about
the difference between:

Privacy,
Security,
and Anonymity :neocat_foxmask:

And why some privacy-focused
services are worth using even when they don't provide perfect anonymity, watch this!

It's truly an amazing short video!
Everyone should watch it πŸ‘‡

https://www.privacyguides.org/videos/2025/03/14/stop-confusing-privacy-anonymity-and-security/

#PrivacyGuides #Privacy #Security #Anonymity


FreeTube ─ Watch YouTube without ads, without login, and with private playlists.

https://freetubeapp.io

#google #YouTube #privacy #ad #safety #security #InfoSec #data #advertisement #tech #technology #BigTech #app #apps #tip #tips


#Research finds 12,000 β€˜Live’ #API Keys and ßPasswords in #DeepSeek's #Training Data


Source: https://trufflesecurity.com/blog/research-finds-12-000-live-api-keys-and-passwords-in-deepseek-s-training-data

#ai #technology #security #privacy #fail #password #Problem #cybersecurity #news #Software


UK government demands access to Apple users' encrypted data https://www.bbc.com/news/articles/c20g288yldko

This is an absolutely stupid idea

#gdpr #security


#Google begins requiring #JavaScript for Google #Search


search: https://techcrunch.com/2025/01/17/google-begins-requiring-javascript-for-google-search/

β€œEnabling JavaScript allows us to better protect our services and users from bots and evolving forms of abuse and spam,” the spokesperson told TechCrunch, β€œand to provide the most relevant and up-to-date information.”


In other words it is for better tracking and surveillance ... πŸ™

#web #www #security #news #internet #browser #tracking #cybersecurity


Millions of Accounts Vulnerable due to sGoogle’s #OAuth Flaw

Source: https://trufflesecurity.com/blog/millions-at-risk-due-to-google-s-oauth-flaw

#cybersecurity #security #identity #login #fail #Software #Problem #internet #news #identification #configuration


πŸ”΄ Agenda na #JesienLinuksowa juΕΌ dostΔ™pna! πŸ”΄

W programie: #DevOps, #security, #gaming, #prywatnoΕ›Δ‡ i wiΔ™cej!

GoΕ›cie specjalni: Kuba Mrugalski (@uwteam), Tomasz ZieliΕ„ski (@infzakladowy)
Dodatkowo: πŸ’¬ Unconference ⚑ Lightning Talks πŸŽ‰ Fedora release party!
Do zobaczenia! πŸ₯³


Do you want to help make software safer? Find the bugs in our ntpd-rs!

The ntpd-rs Bug Bounty Program offers a reward to anyone who finds a qualifying vulnerability.

Read the details here: https://yeswehack.com/programs/pendulum-bug-bounty-program

This Bug Bounty Program is organized and funded by @sovtechfund . Read more about this initiative here: https://www.sovereigntechfund.de/programs/bug-resilience/

#foss #opensource #security


With regard to xz backdoor, did anyone actually have any idea this was going on? With all these vendors doing source code scanning, was there any indication of maliciousness?

#OSS #Security #SBOM #xz


So now that we all understand that thanklessly relying on free work of overworked maintainers is a problem, how about we put our money where our mouth is?

I think @AndresFreundTec needs a fat bonus check for saving our asses.

And Lasse Collin needs a lot of support, and probably a nice vacation.

I pledge $100, for starters.

Now how can we make sure to send the funds to the correct people?

Or is there already any fundraiser that I missed?

#liblzma #xz #ssh #security #oss #floss


β€žGitHub Disables The XZ Repository Following Today's Malicious Disclosureβ€œ

#xz #GitHub #security

https://www.phoronix.com/news/GitHub-Disables-XZ-Repo


Millions Of #google #whatsapp #Facebook #2FA #Security Codes #Leak Online

Security experts advise against using SMS messages for two-factor authentication codes due to their vulnerability to interception or compromise. Recently, a security researcher discovered an unsecured database on the internet containing millions of such codes, which could be easily accessed by anyone.

#news #tech #technews #technology #privacy

https://www.forbes.com/sites/daveywinder/2024/03/06/millions-of-google-whatsapp-facebook-2fa-security-codes-leak-online/


Y'all know not to use #Temu right? Right???

Temu app contains β€˜most dangerous’ #spyware in circulation: class action lawsuit | Fashion Dive
https://www.fashiondive.com/news/temu-class-action-lawsuit-data-collection/699328/

#security


But to be fair ...

Is it the implementation language being the main issue? Or is it the flexibility of extending it with plugins and that it is effectively a setuid tool, granting root access immediately when an unprivileged user starts the program (the privileges are reduced first when it has parsed the sudo config).

Sudo is a nice tool from the user's side. But security wise it's a disastrous approach. Privileges should first be elevated *after* the config has been parsed and the expected privilege level has been established. Then the tool should ideally jump to that privilege level directly.

This post introduces some new ideas ... https://tim.siosm.fr/blog/2023/12/19/ssh-over-unix-socket/

It's not a perfect approach in all cases. But it gets rid of the setuid issue.

#linux #sudo #security



Seriously, WTF @protonmail ?

#YouHadOneJob as #eMail #Provider and that is to get shit reliably sent and recieved.

If that's too hard then how should anyone trust them re: #security and #privacy?
Spoiler: Noine should!
https://www.youtube.com/watch?v=QCx_G_R0UmQ



#BraveBrowser is installing VPNs without users' consent, even if you didn't willingly enable their #VPN service. Just stop using #Brave, it's garbage.

Edit: the services are disabled by default, but they were still installed with very little to no transparency about them towards the user, alongside all the other stuff that's often unwanted from Brave users (Pocket on Firefox is to blame too, lol.)

https://www.ghacks.net/2023/10/18/brave-is-installing-vpn-services-without-user-consent/

#Browser #Security #Privacy #OpenSource #FreeSoftware #LibreSoftware

Screenshot of the Windows Services console taken from the ghacks.net article where two services are highlighted: "Brave Vpn Service" and "Brave Vpn Wireguard Service."


Fellow Masto Admins,
Kindly upgrade to the latest release of Mastodon as soon as possible.

#mastodon #mastodev #mastoadmin #security #fediverse #cve


Concerned about the safety of your Google Docs when it comes to AI training? Check out this informative article on #ZDNet that explores the potential risks and safeguards. Stay informed and protect your data! https://www.zdnet.com/article/are-your-google-docs-safe-from-ai-training/#AI #DataPrivacy #Security


< ORIGINAL STATEMENT >
Smartphones using the Snapdragon 630 chip were found to call home to Qualcomm without the consent of the user, bypassing the whole operating system. […]
< SEE ATTACHMENT >

EDIT / UPDATE:
Martijn Braam took a look and provides a valuable counterstatement. Thx @bart
https://blog.brixit.nl/nitrokey-dissapoints-me/
Still without the actual data that gets transmitted though. Unless someone does it first I'll replicate the test setup myself tomorrow and post my findings here.
#privacy #security
Screenshot of original toot:

Smartphones using the Snapdragon 630 chip were found to call home to Qualcomm without the consent of the user, bypassing the whole operating system. Data includes unique hardware ID, current IP, country, your ISP, list of installed apps and other data.

It is send unencrypted and gets combined with data broker profiles.
https://www.nitrokey.com/news/2023/smartphones-popular-qualcomm-chip-secretly-share-private-information-us-chip-maker

As usual, big IT companies don't give a flying fart about any laws, their customers or ethics in general. Who would've guessed. πŸ˜” #privacy #security


☣️ This is why you should never trust your important information (like passwords!) to proprietary software like @1password.

#OpenSource #FreeSoftware #privacy #security #infosec

🀑 #1Password becomes #spyware:

https://blog.1password.com/privacy-preserving-app-telemetry/


U.S. sues Google for abusing dominance over online ad market

https://www.bleepingcomputer.com/news/security/us-sues-google-for-abusing-dominance-over-online-ad-market/

#Security


LastPass Sibling Company GoTo Loses Encrypted Backups to Hackers

The hacker also stole an encryption key for a portion of the encrypted backups by accessing a cloud storage database shared by both LastPass and GoTo.

#news #tech #technology #security #privacy #Lastpass #breach #hacking

https://www.pcmag.com/news/lastpass-sibling-company-goto-loses-encrypted-backups-to-hackers


Just a #reminder, the #LastPass data #leak happened despite all the military grade and government verified as well as standardized encryption πŸ”

#Encryption alone is not #security, but its implementation, and some do it better and others just badly. If the single point of #failure is vulnerable, the rest is usually useless πŸ˜‰

Please do not fall for #buzzwords and the associated #advertising promises πŸ™


TikTok pushes potentially harmful content to users as often as every 39 seconds, study says

#TikTok recommends self-harm and eating disorder content to some users within minutes of joining the platform, according to a new report published Wednesday by the Center for Countering Digital Hate ( #CCDH ).

#news #technology #tech #security #china

https://www.cbsnews.com/news/tiktok-pushes-potentially-harmful-content-to-users-as-often-as-every-39-seconds-study/


Wait, what?… you don’t mean that your all-important secret for your Small Web site is going to be… A STRING OF EMOJI?!*

(Why yes, yes it is…) :awesome:

* Or, if you want to take all the fun out of it, a base256 encoding of your ed25519 private key that is purposefully impractical to write down somewhere or type in so you’ll be forced to practice good security hygiene and store it in your password manager.

#design #security #privacy #cryptography #kitten #SmallWeb #SmallTech
Screenshot of Kitten running an app at ~/sandbox/kitten-auth-test-1 (git main branch, 62 changes). Alongside the normal output there is a highlighted box labelled IMPORTANT! that reads: β€œThis line of emoji is your secret <line of emoji follows> It will not be shown again. Please save your secret in your password manager.”


This week on the #osspodcast @joshbressers and @kurtseifried discuss #factorio and then #usability vs #security https://opensourcesecurity.io/2022/11/27/episode-351-is-security-or-usability-a-law-of-the-universe/ TL;DR: THE ADMINS CAN READ THESE TOOTS!!!! EVEN THE PRIVATE TOOTS!!!!

Also, we managed to avoid discussing CISA, Twitter, and all the other things on fire.


#geek #security
Getting an #SSL #certificate from #LetsEncrypt (or possibly anywhere) results _immediate_ #attack's on the host. It seems bots constantly monitoring new certs.
Keep in mind when pulling up new services.

⇧