Skip to main content

Search

Items tagged with: security


###
#Microsoft employees exposed internal passwords in #security lapse

source: https://techcrunch.com/2024/04/09/microsoft-employees-exposed-internal-passwords-security-lapse/

Security researchers Can Yoleri, Murat Özfidan and Egemen Koçhisarlı with #SOCRadar, a #cybersecurity company that helps organizations find security weaknesses, discovered an open and public storage server hosted on Microsoft’s #Azure #cloud service that was storing internal information relating to Microsoft’s #Bing search engine.


#fail #password #leak #problem #news


#Twitter’s Clumsy Pivot to X.com Is a Gift to Phishers


source: https://krebsonsecurity.com/2024/04/twitters-clumsy-pivot-to-x-com-is-a-gift-to-phishers/

Those include carfatwitter.com, which Twitter/X truncated to carfax.com when the domain appeared in user messages or tweets. Visiting this domain currently displays a message that begins, “Are you serious, X Corp?”


#internet #fail #security #phishing #cybersecurity #twitter #news



So this is what Microsoft is up to now? Sad. It is a pathetic company. Maybe the EU and FTC need to look into this kind of stuff. Trust and Microsoft have no relationship. If you care about your privacy, never use anything built by MS. Use Firefox or other browsers. I don’t use edge or windows but it was posted https://nitter.privacytools.io/ianzelbo/status/1777450065214271750?s=46 here. I am amused by how they are abusing their power. #privacy #security

(Nitter addon enabled: Twitter links via https://nitter.privacytools.io)


For the strong believers in consent #fedi instead of harassment, threats and outrage and attempting to bully devs why not use a platform that actually provides #privacy #permissions #security ? You want to use #Mastodon and create these social pressures as opposed to truly protecting yourself. There’s a way to do it without helping feed the negative reputation of Mastodon and making this place appear hostile. Make the switch and talk to #admins to make the move to #Hubzilla #Streams https://hubzilla.org/page/info/user_guide #fediverse


I find this argument a bit problematic. Just because software like @Team KeePassXC gives users control and choice over their passkeys, which Apple / Google / ... currently don't, doesn't mean they are irresponsible. From what I can tell KeePassXC devs were not involved in the discussions around transfer of passkeys.

Big tech wanted to get passkeys into user hands, which is a great thing, as are passkeys in general. But the statement that it is somewhat of a lock-in situation currently is not false.

And finger-pointing at software that does give users the option to transfer passkeys at their desire is not helping I think. Especially when that aspect has not yet been standardized.

If transfer can happen in encrypted form, that is clearly preferable. You filed https://github.com/keepassxreboot/keepassxc/issues/10407 which is a good thing. The discussion shows however, that the way the debate was going on so far was not ideal.

#passkeys #security #passwordless


#ThreatWire these days is presented by @endingwithali :blobcathearts:

Bringing us the latest on our #security, #privacy & #InternetFreedom

Give her a follow :cat_hug_triangle: :fediverse:

https://www.youtube.com/@hak5


When #security matters: working with #Qubes OS at the #Guardian


Source: https://www.theguardian.com/info/2024/apr/04/when-security-matters-working-with-qubes-os-at-the-guardian

Configuring a Qubes workstation was a new challenge for the team as we abandoned years of experience writing Infrastructure as Code for the cloud and started learning how to write #Salt #configuration. Salt (also know as SaltStack) is a management engine available by default in Qubes.


#cybersecurity #news #journalism #linux #technology #software #securedrop


Exclusive: #YossiSariel unmasked as head of #Unit8200 and architect of #AI #strategy after book written under pen name reveals his #Google account


Source: https://www.theguardian.com/world/2024/apr/05/top-israeli-spy-chief-exposes-his-true-identity-in-online-security-lapse

The embarrassing #security lapse is linked to a book he published on #Amazon, which left a digital trail to a private Google account created in his name, along with his unique ID and links to the #account’s maps and calendar profiles.


#Israel #internet #Anonymity #privacy #spy #military #CyberSecurity #news #online #leak #identity


What #encryption do you use for your everyday #communication?


I'm not talking about your nerd friends, who can be counted on one hand and who know a thing or two about the subject. I'm talking about your normal friends, business partners and colleagues with whom you communicate both professionally and privately.

I was recently called by my support via Microsoft Teams because I had to enter some passwords. The support team proudly said that they were contacting me via Teams because it was more secure than the normal phone. He was then very surprised when I told him that Teams is unencrypted and can be intercepted much more easily.

encryption

#messenger #email #question #security #cybersecurity #internet #spy #surveillance #privacy #nsa #snowden #5eyes


#XZ #Backdoor: Times, damned times, and scams


However, I believe that he is actually from somewhere in the UTC+02 (winter)/UTC+03 (DST) timezone, which includes Eastern Europe (EET), but also Israel (IST), and some others. Forging time zones would be easy — no need to do any math or delay any commits. He likely just changed his system time to Chinese time every time he committed.


source: https://rheaeve.substack.com/p/xz-backdoor-times-damned-times-and

#security #software #time #news #hack #linux #timezone