Search
Items tagged with: security
Remember Microsoft's Recall? The first implementation was never released and was met with strong criticism from privacy advocates and the infosec/security community. Guess what? Microsoft has doubled down, and its controversial Recall scraper is finally entering the public preview stage. If you care about privacy, please think twice before using this on your AI-enabled PCs (Snapdragon-powered Copilot+ PCs) blogs.windows.com/windows-insi…
#privacy #infosec #security #windows11 #DoNotWant
Previewing Recall with Click to Do on Copilot+ PCs with Windows Insiders in the Dev Channel
Hello Windows Insiders, today we are releasing Windows 11 Insider Preview Build 26120.2415 (KB5046723) to the Dev Channel. With this update, we welcome Windows Insiders with Snapdragon-poweredWindows Insider Blog
#Android will soon instantly log you in to your apps on new devices
#security
arstechnica.com/gadgets/2024/1…
Android will soon instantly log you in to your apps on new devices
New phone day for Android users should get a whole bunch easier.Kevin Purdy (Ars Technica)
And Signal app is FREE 😁
#security #encrypted #message
lifehacker.com/tech/signal-is-…
Signal Is Now a Great Encrypted Alternative to Zoom and Google Meet
You can make free and encrypted group video calls with up to 50 participants.Pranay Parab (Lifehacker)
Have you heard about the latest losers? theregister.com/2024/11/20/dli…
#dlink #cybersecurity #Router #vpn #internet #Software #Firmware #fail #bug #economy #Problem #security #news
D-Link tells users to trash old VPN routers over bug too dangerous to identify
Vendor offers 20% discount on new model, but not patchesConnor Jones (The Register)
Urgent Warning for Fedi Admins
We've discovered an ongoing Denial-of-Service attack against Misskey-based instances. The attacks exploit a zero-day vulnerability impacting Misskey, Sharkey, IceShrimp, and other related software. Patches are in progress and will be released ASAP. We encourage all admins to update immediately!
Note: this is a different vulnerability from the ones that were recently announced! You should update today and again tomorrow at the scheduled time.
Let's Encrypt is 10 years old today!
Let's Encrypt is a free, automated, and open certificate authority brought to you by the nonprofit Internet Security Research Group (ISRG). Huge thanks to everyone involved in making HTTPS available to everyone for free
#tech #technology #security #privacy #encryption #https #letsencrypt #ISRG
Let's Encrypt
Let's Encrypt is a free, automated, and open certificate authority brought to you by the nonprofit Internet Security Research Group (ISRG). Read all about our nonprofit work this year in our 2023 Annual Report.letsencrypt.org
📣 EMERGENCY UPDATES 📣
Apple pushed updates for 2 new zero-days that may have been actively exploited.
🐛 CVE-2024-44308 (JavaScriptCore),
🐛 CVE-2024-44309 (WebKit):
- iOS and iPadOS 17.7.2
- iOS and iPadOS 18.1.1
- macOS Sequoia 15.1.1
#apple #cybersecurity #infosec #security #ios
tools like @torproject, @securedrop (by @freedomofpress) and @signalapp are going to be so important for protecting people in the coming years. please support them
Sometime ago somebody shared a screenshot of a service with a cookie message along the lines of:
"We take your privacy seriously" while there also was a list of 600+ vendors with whom data would be shared. Does anyone have this screenshot & the source? I think this was by Microsoft MS365?
#Privacy #Cookies #Tech #TechPolicy #OpenSource #Data #GDPR #bigtech #Security #CyberSecurity
#Ad blockers are #security tools. What would be the implications of offering up a pi-hole ad blocker open to the public? I could do it easily enough. At least then people could have some ad blocking without having to install the pi-hole. Is it worthwhile? Does it make sense? Maybe a few of us can work together and provide a resilient bunch of pi-holes?
(I wouldn’t literally use a pi, but the software is good)
A great guide for anyone interested in improving their #privacy posture.
(TL;DR in the comments.)
"Whatever platforms you're on, whatever devices you have, you need to have a sense of what kind of data you're generating and then use the controls available to limit who can see what you're doing."
GitHub - FiloSottile/age: A simple, modern and secure encryption tool (and Go library) with small explicit keys, no config options, and UNIX-style composability.
A simple, modern and secure encryption tool (and Go library) with small explicit keys, no config options, and UNIX-style composability. - FiloSottile/ageGitHub
China's cyber spies intercept phone data and calls from US network operators
Chinese cyber spies infiltrated US network operators. Conversations and data from government and politicians were intercepted, as were police wiretaps.
heise.de/en/news/China-s-cyber…
#ATT #Cybersecurity #Cyberspionage #DonaldTrump #FBI #Provider #Security #Spionage #Verizon #news
Pregnancy Tracking #App ‘What to Expect’ Refuses to Fix Issue that Allows Full Account Takeover
What to Expect is a popular pregnancy tracking app available for #ios and #android.
An exposed API endpoint handling password reset requests for the app does not require authentication or enforce rate limits and is vulnerable to brute force attacks.
#privacy #security #cybersecurity
404media.co/pregnancy-tracking…
Pregnancy Tracking App ‘What to Expect’ Refuses to Fix Issue that Allows Full Account Takeover
Vulnerabilities in the popular What to Expect app include one that allows a full account take over, and another that exposes that email address of forum admins.Joseph Cox (404 Media)
Western inaction on Ukraine’s security guarantees opens door to global nuclear proliferation
Western indecision in Ukraine’s pursuit of #security #guarantees risks triggering a global chain reaction, with nations turning to #nuclear #weapons as a deterrent in the absence of reliable security commitments.
#Ukraine's security commitment - the #Budapest #Memorandum of 1994 - is currently and has been repeatably violated
kyivindependent.com/opinion-we…
#RussianAggression #RussiaInvadedUkraine
Opinion: Western inaction on Ukraine’s security guarantees opens door to global nuclear proliferation
Russia’s invasion of Ukraine is approaching its 11th year, with three years of full-scale war. In search of security guarantees like NATO membership, Ukraine has been left in limbo due to Russian-occupied territories and Western bureaucracy.Julian McBride (The Kyiv Independent)
If you’re looking for an EU-based alternative to AzireVPN since they’ve now sold to a US company (why, hello, Trump presidency, how goes?), see Mullvad VPN (@mullvadnet).
#privacy #security #VPN #AzireVPN #MullvadVPN
Mullvad VPN - Free the internet
Free the internet from mass surveillance and censorship. Fight for privacy with Mullvad VPN and Mullvad Browser.Mullvad
#Amazon confirms #employee data stolen after #hacker claims #MOVEit #breach
source: techcrunch.com/2024/11/11/amaz…
“Amazon and AWS systems remain secure, and we have not experienced a #security event. We were notified about a security event at one of our property management vendors that impacted several of its customers including Amazon. The only Amazon information involved was employee work contact information, for example work email addresses, desk phone numbers, and building locations,” Montgomery said.
If not even a company like Amazon can store its data securely, is there any security at all? Amazon doesn't lack money or experts, but it does seem to lack secure software.
#fail #cybersecurity #problem #software #internet #news #economy #hack #cloud
Amazon confirms employee data stolen after hacker claims MOVEit breach | TechCrunch
Amazon has confirmed that employee data was compromised after a “security event” at a third-party vendor. In a statement given to TechCrunch on Monday,Carly Page (TechCrunch)
Law enforcement operation takes down 22,000 malicious IP addresses worldwide
Operation Synergia II took aim at phishing, ransomware, and information stealing.Dan Goodin (Ars Technica)
Seeing how the Trumpists are about to take charge of the government (including our intelligence agencies), it's probably best to start familiarizing yourself with things like the 5/9/14 Eyes agreements and adjust your online behavior accordingly.
protonvpn.com/blog/5-eyes-glob…
What countries are in the 5 Eyes, 9 Eyes, and 14 Eyes agreements?
A list of the Five Eyes countries of the UKUSA and other intelligence-sharing agreements, including the Nine Eyes and Fourteen Eyes.Richie Koch (Proton VPN)
Don’t panic, we have the tools we need.
scidsg.medium.com/dont-worry-u…
#news #election #security #journalism
Don’t Worry, Usable Security and Privacy are Here - Science & Design - Medium
For those concerned about digital privacy in today’s political climate, brace yourself for a wave of FUD (fear, uncertainty, and doubt) from companies aiming to scare you into compliance. But you…Science & Design (Medium)
Why is my air fryer spying on me? Which? reveals the #smart devices gathering your data - and where they send it
Source: which.co.uk/policy-and-insight…
The Aigostar air fryer wanted to know gender and date of birth when setting up an owner account, again for no clear reason, but this was optional. The Aigostar and #Xiaomi fryers both sent people’s personal data to servers in #China, although this was flagged in the #privacy notice.
Why must smart technology be in the #cloud - is the advantage of this only surveillance? 🤔
#news #technology #Software #economy #fail #spy #bigdata #bigbrother #orwell #Problem #security
Why is my air fryer spying on me? Which? reveals the smart devices gathering your data - and where they send it - Which? Policy and insight
Which? research has found evidence of excessive smart device surveillance - from air fryers demanding permission to listen in on conversations and sharing data with TikTok, to TVs wanting to know users’ exact locations at all timesWhich?
That's why we publish all our apps on @fdroidorg ❤️
🔒 Get the new calendar app now! 🔒
👉 tuta.com/blog/tuta-calendar-fd…
#FOSS #OpenSource #Encryption #Security #Calendar
New Tuta Calendar app is now on F-Droid! | Tuta
Encrypted, open source, zero strings to Google – introducing the Tuta Calendar.Tuta
Hey everyone! A couple good things to remember:
Signal is your friend! signal.org/Be careful about what you post on corporate and federated social media. You don't need to self censor but you should take extra spicy discussions to something like Signal!
(people: please feel free to add hot tips for helping people keep things private!)
#security #secureCommunications
Signal Messenger: Speak Freely
Say "hello" to a different messaging experience. An unexpected focus on privacy, combined with all of the features you expect.Signal Messenger
Hundreds of #code #libraries posted to #NPM try to #install #malware on dev machines
source: arstechnica.com/security/2024/…
The malicious packages have names that are similar to legitimate ones for the Puppeteer and Bignum.js code libraries and for various libraries for working with #cryptocurrency.
Dependency hell 👎👿
#software #problem #development #library #dependency #security #cybersecurity #news #cybercrime #attack
Hundreds of code libraries posted to NPM try to install malware on dev machines
These are not the the developer tools you think they are.Dan Goodin (Ars Technica)
"But new data reveal that #Trump was the one whose #immigration policies damaged the country’s #security. In fact, he released more convicted criminals into the #UnitedStates than his successor....
when it comes to the small percentage of noncitizens who do commit crimes, Trump did not prioritize removing them during his term in office. In fact, he explicitly deprioritized them."
washingtonpost.com/opinions/20…
#Immigration #Politics #GOP #NationalSecurity #Crime #News #USNews #USA
Never ending story about the #security of fitness app...
Source: thehindu.com/sci-tech/technolo…
#news #stava #cybersecurity #sports #Problem #Software #privacy #politics #fail #online #cloude #surveillance #bigdata #economy
Fitness app Strava gives away location of Biden, Trump and other leaders, French newspaper says
Le Monde reported that movements of some of the world’s most powerful leaders could be tracked online through a fitness app used by their bodyguards.The Hindu
🔐 Sending a password-protected email to anyone is easy with Tuta Mail! 🔐
Check out our latest guide on how to send encrypted, password-protected emails here 👇👇👇
tuta.com/blog/how-to-password-…
#encryption #security #privacy #email
The easiest way to send password-protected emails | Tuta
Unsure of how to send a password-protected email? Find out how easy it is in this quick guide.Tuta
UN #Security Council to meet Monday over #Israel's strike on #Iran
Source: uk.news.yahoo.com/un-security-…
“The Islamic Republic of Iran, in alignment with the principles enshrined in the Charter of the United Nations and under international law, reserves its inherent right to legal and legitimate response to these criminal attacks at the appropriate time,”...
I always ask myself whether these people are still capable of logical thinking? If this Israeli airstrike was criminal, what was the Iranian one? If the Iranian one was a justified retaliation in his way of thinking, why is the retaliation of the retaliation criminal? Why are such people tolerated in the #government?
#uno #war #diplomacy #argument #politics #military #fail #news #MiddleEast #crime
@Tutanota I just realised that all the comments I have added to my contacts over the years, including family-related and medical important information, are gone...
github.com/tutao/tutanota/issu…
Bugs are becoming more common recently, and this one made me lose data. I'm quite disappointed.
#Email #OpenSource #FOSS #Security #Privacy
Lost all my contact comments on Android · Issue #7818 · tutao/tutanota
This is not a feature request (existing functionality does not work, not missing functionality). I will request features on forum or via support. I've searched and did not find a similar issue. Bug...GitHub
#Cisco reports more than 35 #vulnerabilities in #firewall products
Source: heise.de/en/news/Cisco-reports…
Don't forget that you use firewalls to increase #security.
#news #Software #vulnerability #bug #fail #cybersecurity #Problem #fail #qa #economy
Cisco reports more than 35 vulnerabilities in firewall products
Cisco's ASA, Firepower and Secure Firewall Management Center have security vulnerabilities, some of which are critical. More than 35 updates are now available.Dirk Knop (heise online)
The #EU is now trying to find means of its own to bolster enforcement & reinforce its curbs on #Russia.
Tom Keatinge, of think tank the Royal United Services Institute, said European policy makers had been preparing "autonomous European #sanctions considering the possibility of a #Trump presidency" but would have to bolster enforcement.
#geopolitics #Authoritarianism #StrongMen #dictatorship #totalitarianism
#ForeignPolicy #Security #democracy #VoteBlue #HarrisWalz2024
"Should a #Trump presidency reverse #US sanctions on #Russia, Europeans will need to be much more muscular in ... enforcement action & will no longer be able to hide behind Uncle Sam," he said.
…European countries were wrongfooted during Trump's last presidency, when the #UnitedStates reversed an international deal w/ #Iran over its #nuclear program & unilaterally reinstated #sanctions, leaving #Europe out on a limb.
#geopolitics #Security #ForeignPolicy #democracy #VoteBlue #HarrisWalz2024
#PeterTodd has gone underground after an #HBO #documentary named him as the creator of #Bitcoin, #SatoshiNakamoto, whose real #identity has long remained a #mystery.
Source: wired.com/story/peter-todd-was…
#problem #wealth #crime #news #journalism #press #security #crypto
TLS-Zertifikate: Apple schlägt maximale Laufzeit von 10 Tagen vor
Nachdem Google mit einem ähnlichen Ansinnen gescheitert war, probiert Apple es erneut und legt einen konkreten Zeitplan vor. Die Resonanz ist gemischt.
heise.de/news/TLS-Zertifikate-…
#Apple #Google #https #Security #news
TLS-Zertifikate: Apple schlägt maximale Laufzeit von 45 Tagen vor
Nachdem Google mit einem ähnlichen Ansinnen gescheitert ist, probiert Apple es erneut und legt einen konkreten Zeitplan vor. Die Resonanz ist gemischt.Dr. Christopher Kunz (heise online)