gcluley , to Cybersecurity
@gcluley@mastodon.green avatar

Prison for cybersecurity expert selling private videos from inside 400,000 homes.

Months before, the guy had given an interview demonstrating how simple it was to hack into wallpads - describing them as something that "middle schoolers with basic knowledge of computers can easily hack."

He later argued in court (unsuccessfully) that the data leak was to publicise the security vulnerabilities... 🙄

https://www.bitdefender.com/blog/hotforsecurity/prison-for-cybersecurity-expert-selling-private-videos-from-inside-400-000-homes/

Tutanota , to Android
@Tutanota@mastodon.social avatar

Psst 👋 Email Preview for push notifications is coming soon!

Now you can know who is sending you an email before opening your mailbox! 🎉

Here's a sneak peek 🤫

kuketzblog , to Privacy German
@kuketzblog@social.tchncs.de avatar

Ich möchte mich ganz herzlich für die anhaltende Unterstützung und das Vertrauen in meine Arbeit bedanken. Eure Spenden ermöglichen es mir, mich weiterhin auf die Qualität und Entwicklung des Blogs zu konzentrieren und unabhängig und frei von kommerziellen Interessen zu bleiben. Ohne eure Großzügigkeit und Unterstützung wäre dies nicht möglich. Vielen Dank! ❤️

https://www.kuketz-blog.de/kuketz-blog-aktuelle-spendeninfos-monat-mai-2024/

alng , to Random stuff
@alng@journa.host avatar

New: The TSA fought senators' proposal to make its policy to allow opt-outs for facial recognition scans at airports into a law as it plans to mandate biometric scans in the future https://subscriber.politicopro.com/article/2024/05/tsa-fought-against-proposal-to-require-facial-recognition-opt-outs-at-airports-00157411

ALT
  • Reply
  • Expand (1)
  • Collapse (1)
  • Loading...
  • alng OP ,
    @alng@journa.host avatar

    Updated with a statement from Sen. Merkley, who proposed the amendment and was a part of the negotiation: "As I worked with other Senate negotiators to develop a compromise proposal governing TSA’s use of facial recognition, it became abundantly clear that the end goal for TSA is to make facial recognition mandatory for all American air travelers and that the current opt-out system will end."

    https://subscriber.politicopro.com/article/2024/05/tsa-fought-against-proposal-to-require-facial-recognition-opt-outs-at-airports-00157411/

    ninjaowl Bot , to Cybersecurity
    @ninjaowl@mastodon.social avatar

    Chrome Zero-Day Alert — Update Your Browser to Patch New Vulnerability https://thehackernews.com/2024/05/chrome-zero-day-alert-update-your.html

    dangillmor , (edited ) to Random stuff
    @dangillmor@mastodon.social avatar

    Does anyone know of a way to buy an EV that doesn't relentlessly spy on the driver/passengers and send the data to whoever the carmaker feels like selling it to?

    Related: Does anyone know of a service in the Bay Area that will disable all the surveillance that was, without my knowledge or permission, built into a 2008 Prius?

    waltwooton ,
    @waltwooton@spartanburg.social avatar

    @dangillmor I recently received a notice from Subaru that the 3G cellphone embedded in my 2016 Outback could be draining my battery because it can no longer phone home. They would like to replace it for me. Fat chance.

    It would seem that ripping out the embedded phone would fix the problem at the source. The loss functionality seems to me to be of dubious utility.

    reillypascal , to Privacy
    @reillypascal@hachyderm.io avatar

    "US Rep. Zoe Lofgren (D-Calif.) had a different interpretation of the email, telling Wired that it 'seems to show that the FBI is actively pushing for more surveillance of Americans, not out of necessity but as a default.'"

    https://arstechnica.com/tech-policy/2024/05/fbi-urges-employees-to-look-for-ways-to-collect-americans-messages/

    jsrailton , to Privacy
    @jsrailton@mastodon.social avatar

    I can confidently diagnose as sociopaths.

    Promised therapy customers privacy...then gave their mental health info to advertisers.

    Victims get less than ten bucks each.

    Company made billion+ in revenue last year alone.

    In a just society with good privacy laws, they'd face existential civil & criminal consequences.

    https://www.wcnc.com/article/news/nation-world/betterhelp-therapy-class-action-settlement-refund/507-b4ef5e0f-c722-4562-95e9-c3cdd7738d1a

    image/png
    image/png
    image/png

    scottwilson , to Cybersecurity
    @scottwilson@infosec.exchange avatar

    STATEMENT:

    “We take the privacy and confidentiality of your information seriously.”

    TRANSLATION:

    “Every time we have a data breach we’ll let you know about it! Mainly ‘cuz we are required to in order to minimize our legal liability… and of course after we’ve consulted with our legal firm and our new 3rd party incident response vendor.”

    FediVideo , to Linux
    @FediVideo@social.growyourown.services avatar

    Niccolò Ve is a KDE developer who posts videos about Linux, technology, the internet, online privacy and related topics. You can follow at:

    ➡️ @veggero

    If the videos haven't federated to your server yet, you can browse them all at https://tube.kockatoo.org/a/veggero/videos

    gcluley , to Cybersecurity
    @gcluley@mastodon.green avatar

    Cancer patients' sensitive information accessed by "unidentified parties" after being left exposed by screening lab for years.

    Read more in my article on the Bitdefender blog: https://www.bitdefender.com/blog/hotforsecurity/cancer-patients-sensitive-information-accessed-by-unidentified-parties-after-being-left-exposed-by-screening-lab-for-years/

    ianonymous3000 , to Cybersecurity
    @ianonymous3000@mastodon.social avatar

    📚 Just completed the 'Basics of Personal Threat Modeling' course by @privacyguides 🛡️

    Threat modeling is crucial because it helps identify and prioritize the most probable security and privacy risks. It enables focused resource allocation, tailored defenses, and heightened awareness.

    Check it out: https://learn.privacyguides.org

    image/png

    tallship , to Privacy

    is a goal, not a promise. As far back as I can remember, forums like those supporting and were staffed with volunteers from the privacy community who repeatedly insisted on answering questions, like, "Is <this> (whatever this might be) totally secure?" with stock questions like, "What is it that you consider 'totally secure?" or answers such as, "Secure is a relative term, nothing is completely secure, how secure do you need your mission's communications to be?"

    Phrases such as, reasonably secure should be indicators of how ridiculous it is to assume that any secure platform is EVER completely, and totally secure.

    That begs the question, "Exactly how secure do you require your communications to be?" The answer is always, ... relative.

    Which means that you should always believe Ellen Ripley when she says, "Be afraid. Be very afraid!"

    https://www.city-journal.org/article/signals-katherine-maher-problem

    .

    tokyo_0 , to News from fediverse
    @tokyo_0@mas.to avatar

    Coincidentally, this seems to expose a gap in security—since right now there's no way for me to continue posting to a hashtag I use frequently and avoid this user, who openly admits that they use .social to browse hashtags and then quote posts.

    https://makai.chaotic.ninja/notes/9szvrst4m6

    The only way I can use a hashtag on this federated network is to make my post publicly visible. Doesn't that make all hashtag-based communities here vulnerable to surveillance and potential abuse?

    tokyo_0 OP ,
    @tokyo_0@mas.to avatar

    @adnan Maybe the would benefit from some kind of "listed and fediverse-public but not external-public" level of post visibility that would allow people to have their posts on hashtags propagated across the fediverse and visible internally within the federated timeline but not visible via pages like the non-authenticated external search on most instances to people who are not logged in 🤔

    alshafei , to Privacy
    @alshafei@mastodon.social avatar
    avoidthehack , to Android
    @avoidthehack@infosec.exchange avatar

    DNS traffic can leak outside the VPN tunnel on

    Android can leak traffic when:

    • A VPN is on but no server is configured
    • A window where the app is re-configuring the tunnel or stopped/crashes

    @mullvadnet @ivpn @protonprivacy

    https://mullvad.net/en/blog/2024/5/3/dns-traffic-can-leak-outside-the-vpn-tunnel-on-android

    patrick , to Privacy
    @patrick@retro.social avatar

    Been talking about telemetry in software recently, and how people seem to be opposed to it in principle, while there are use cases that truly benefit from such data collection, like figuring out how to optimize the UI of such software.

    It's still a work in progress, but I'm wondering if https://patrick.georgi.family/2024/05/04/user-behavior-analysis-in-open-source/ is a concept that could be acceptable and workable for concious open source folks (who want to know what's going on with their data) and researchers (who'd like to have such data) alike.

    Comments welcome!

    alshafei , to Privacy
    @alshafei@mastodon.social avatar

    Disappointed to see The Markup share advice for people to use WhatsApp in its post about preparing your phone for a protest, and that it's coming from "digital security trainers."

    Metadata literally kills, and WhatsApp is swimming in it. The metadata they collect includes:

    Groups you're a member of, location, personal info (email, phone number, user IDs), contacts and their phone numbers, in-app search history, when you use the app & how often you use it. E2EE alone doesn't guarantee

    linuxmagazine , to Privacy
    @linuxmagazine@fosstodon.org avatar

    From this week's Linux Update: Matthias Wübbeling shows you how to protect your data and operating system from prying eyes with @veracrypt https://www.linux-magazine.com/Issues/2024/279/VeraCrypt

    oligneisti , to Privacy
    @oligneisti@social.linux.pizza avatar

    What is the best non-invasive and respecting service?

    Em0nM4stodon , to Privacy
    @Em0nM4stodon@infosec.exchange avatar

    If you heard about Password Managers but aren't using one yet and would like to start soon:

    I wrote this article-tip to help you get started with using a password manager for the first time.

    Setting up a password manager can be a little intimidating at first, but it is one of the best thing you can do to improve your security and privacy online. It will allow you to easily use a unique, long, and complex password for each of your many accounts without having to remember any of them!

    I hope this article can encourage you to make the jump towards better security! 🔑✨

    https://controlaltdelete.technology/articles/easy-practical-privacy-tips-for-everyone.html#tip-password

    Em0nM4stodon , to Privacy
    @Em0nM4stodon@infosec.exchange avatar

    If you are the tech-savvy person within your family or friends group :blobcatcool: :

    Never ever shame someone for coming to you for advice after being the victim of a scam, malware, or for using an unsecure product.

    If you do this,
    they might never come back to you later. They might just feel so ashamed they will just stay alone with their tech problems.

    Instead, always tell them:

    1. It was a good idea to come to you with this. Be empathetic with them 💚

    2. Give them advice on how to minimize the damage now. Actionable advice 🚑

    3. Help them harden their security for now and for the future. Recommend better products to them. But be careful not to overwhelm them with advice. One step at the time 🔒

    4. Talk to them with respect and empathy. Tell them how the people who abused their trust are horrible and anyone can fall for the right scam. Remind them there are things to do to reduce the risks of being victimized again in the future, and help them slowly implementing these 💪

    5. Be thankful they trusted you with this. It means they think highly of you 🥰

    Em0nM4stodon , to Privacy
    @Em0nM4stodon@infosec.exchange avatar

    For today's World Password Day 🔑✨:

    What is your favorite password manager service, and why? 👀

    Tutanota , to Privacy
    @Tutanota@mastodon.social avatar

    We ❤️ Free Software

    It's been a pleasure when the Linux Professional Institute asked us for an interview. 😍

    Read Hanna's insights on , - and how to best apply for a at Tuta!

    ➡️ https://www.lpi.org/blog/2024/04/24/foss-privacy-and-innovation-meet-tuta-mail/

    EU_Commission , to Random stuff
    @EU_Commission@social.network.europa.eu avatar

    We have opened formal proceedings against Meta to assess whether Facebook and Instagram may have breached the Digital Services Act in areas linked to:

    ▪️ Disinformation
    ▪️ Visibility of political content
    ▪️ Non-availability of election-monitoring tools
    ▪️ Mechanisms to flag illegal content

    More info: https://europa.eu/!h4Tjfy

    nf3xn ,
    @nf3xn@mastodon.social avatar

    @EU_Commission Budget shortfall 2028 volunteer just dropped.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • Mordhau
  • WatchParties
  • Rutgers
  • loren
  • Lexington
  • cragsand
  • mead
  • RetroGamingNetwork
  • mauerstrassenwetten
  • MidnightClan
  • xyz
  • PowerRangers
  • AnarchoCapitalism
  • kamenrider
  • supersentai
  • itdept
  • neondivide
  • AgeRegression
  • Teensy
  • WarhammerFantasy
  • space_engine
  • learnviet
  • bjj
  • electropalaeography
  • steinbach
  • khanate
  • jeremy
  • fandic
  • All magazines