Skip to main content

Search

Items tagged with: security


Jun 2
New Hampshire 2600 Monthly Meeting for June 2023
Fri 10:30 PM - Sat 12:30 AM
2600 New Hampshire

Welcome to the New Hampshire 2600 Monthly Meeting! ^_^

2600 meetings are monthly meetings which happen all over the world on the first Friday of each month. Here hackers, technologists, and lovers of free culture come together to hang out, discuss, share ideas, share projects, and enjoy conversation on all aspects of technology.

This meeting is welcome to everyone, including those people who are curious & want to learn more about what "hacker culture" is. This meeting is 100% affiliated with 2600 and the US 2600 magazine. For more information, visit https://2600.com, hop into #nh2600 on the 2600 IRC network, or join us on Matrix at #nh2600:hispagatos.org.

**** The meeting time is 6:30PM to 8:30PM EST. Mobilizon is having trouble adding the venue, so this meeting will be at Grill 603, 168 Elm Street, Milford, New Hampshire. - https://www.grill603.com/ ****


INTERNET ENGINEERING TASK-FORCE: Reflections 10 Years Since Snowden Revelations

#News #privacy #Snowden #surveillance #spying #HumanRights #IETF #engineering #internet #security #infosec #cybersecurity #tech

https://www.ietf.org/archive/id/draft-farrell-tenyearsafter-00.html


"With #AI, they could be used for all sorts of malicious tasks, including leaking people’s private information and helping criminals phish, spam, and scam people. Experts warn we are heading toward a #security and #privacy disaster.”

https://www.technologyreview.com/2023/04/03/1070893/three-ways-ai-chatbots-are-a-security-disaster/


🧬 SR134 is finally here with nearly an hour of #privacy & #security news!

- Your DNA is everywhere
- A free smart TV that's too good to be true
- A KeePass vulnerability
- More!

Tune in now: https://surveillancereport.tech
YouTube: https://youtu.be/ddMP9nI-E48


Earlier this year we got into a surprising and somewhat annoying struggle with Web browser sandboxing failures related to our "web apps shared in a chat" feature. After much background work we released the hardened Delta Chat 1.36 series, also addressing a dedicated fourth independent security audit, and can finally share more of what was going on behind the scenes https://delta.chat/en/2023-05-22-webxdc-security

#chromium #deltachat #security #webxdc


SimpleX Chat v5.1-beta.1 is released!

New in v5.1-beta.1:
- message reactions - finally! - only 6 for now: 👍👎😀😢❤️🚀
- self-destruct passcode.
- voice messages up to 5 minutes, with 2x quality and playback slider.
- custom time to disappear - can be set just for one message.
- message editing history.
- a setting to disable audio/video calls per contact.
- group welcome message visible in group profile.

Install the apps via the links here: https://github.com/simplex-chat/simplex-chat#install-the-app

#privacy #security #messenger


Use FIDO U2F security keys with Fedora Linux 🔑
https://fedoramagazine.org/use-fido-u2f-security-keys-with-fedora-linux/

Hardware security keys are a form of multi-factor authentication for logging into important accounts. If you were thinking about getting a one, it's good to know Fedora supports them.

But remember to get two so you can make a backup!
#Fedora #FIDO #security #privacy


Our new Contact Scopes feature is now available in the Alpha channel. It provides a way to avoid granting the Contacts permission for apps requiring it. It's similar to our Storage Scopes feature replacing needing any of the media/storage permissions.

https://grapheneos.social/@GrapheneOS/110382121185752120

#ContactScopes #StorageScopes #permissions #sandbox #android #GrapheneOS #privacy #security


Random Website: You need to set up #2FA with your phone number!

Me: Why?

Website: In case we get hacked!

Me: I don't really care, no one even knows about this account and it doesn't have my personal information.

Website: You misunderstand, it's so that in case we get hacked, we HAVE your information to leak to the hackers. They worked hard and deserve it! Also we sell your account to ad companies but they're not interested unless they can tie it to a real person.

#security #privacy #web


#YouTube blocking my #adblocker? Maybe reduce the frequency of #advertising interruptions and I’ll consider turning mine off. https://apple.news/AUR1RileFSuyKNE6wLNuKyw

Anyone notice this is happening at the same time #Google is working on the final stages of removing support for #Chrome #browser extensions that dynamically examine and modify web requests, e.g., strong #adblockers like #uBlockOrigin, in favor of their more restrictive #ManifestV3 spec? https://www.eff.org/deeplinks/2021/12/chrome-users-beware-manifest-v3-deceitful-and-threatening

#privacy #security #infosec


Auditor app version 70 released: https://github.com/GrapheneOS/Auditor/releases/tag/70.

See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

Forum discussion thread:

https://discuss.grapheneos.org/d/4972-auditor-app-version-70-released

See https://attestation.app/about and https://attestation.app/tutorial for info about the app and optional monitoring service.

#GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement #auditor


First experimental release of GrapheneOS for Pixel 7a is available. Can be installed via our staging site web installer or downloaded from the releases page for CLI install.

https://staging.grapheneos.org/install/web
https://staging.grapheneos.org/releases

We don't have a Pixel 7a yet so it's entirely untested.

#grapheneos #privacy #security #experimental #pixel7a #7a


We'll be heavily prioritizing adding support for the Pixel 7a, Pixel Tablet and Pixel Fold. It has been years since we supported a tablet (Nexus 9) and there will likely be additional work to support the form factor properly. Pixel Fold is a new form factor and may be difficult.

#grapheneos #privacy #security #pixel #pixel7a #pixeltablet #pixelfold


LEAVE GOOGLE NOW: (or yesterday)

"All you will have to do is verify your identity on the device using a PIN unlock code, biometrics such as a fingerprint or face scan, or a more sophisticated physical security dongle."

#passkey
#monopoly
#security
#privacy
#humanrights

https://www.aljazeera.com/news/2023/5/4/google-to-abolish-passwords-for-passkeys-heres-what-to-know


I'm excited to announce that I have successfully put together a #Signet #hardware #password manager, without any jumpers or hackery.

This means I will be making more of these so people who want to up their #security game will be able to just buy them.

I'll be honest: this one cost me over $300 in parts and many hours of labor. My goal is to get them down to about $45 each. That should allow me to break even (assuming I can produce them faster and my time is worth minimum wage). #infosec #foss

A small USB device with Signet v1.3 printed on the purple printed circuit board.


Google has just updated its 2FA Authenticator app and added a much-needed feature: the ability to sync secrets across devices.

TL;DR: Don't turn it on.

The new update allows users to sign in with their Google Account and sync 2FA secrets across their iOS and Android devices.

We analyzed the network traffic when the app syncs the secrets, and it turns out the traffic is not end-to-end encrypted. As shown in the screenshots, this means that Google can see the secrets, likely even while they’re stored on their servers. There is no option to add a passphrase to protect the secrets, to make them accessible only by the user.

Why is this bad?

Every 2FA QR code contains a secret, or a seed, that’s used to generate the one-time codes. If someone else knows the secret, they can generate the same one-time codes and defeat 2FA protections. So, if there’s ever a data breach or if someone obtains access .... 🧵

#Privacy #Cybersecurity #InfoSec #2FA #Google #Security


New study shows how scary fast today's AI is at cracking passwords

51% of common passwords can be cracked in less than a minute, 65% in less than an hour, 71% in less than a day, and 81% in less than a month.

Additionally, the group provided its findings in a table. As you can see in the image below, almost every password with six or fewer characters was instantly cracked.

#password #passwords #artificialintelligence #ai #security #cybersecurity #infosec #hacking

https://www.androidauthority.com/ai-password-cracking-3310709/


May 5
New Hampshire 2600 Monthly Meeting for May 2023
Fri 10:30 PM - Sat 12:30 AM
2600 New Hampshire

Welcome to the New Hampshire 2600 Monthly Meeting! ^_^

2600 meetings are monthly meetings which happen all over the world on the first Friday of each month. Here hackers, technologists, and lovers of free culture come together to hang out, discuss, share ideas, share projects, and enjoy conversation on all aspects of technology.

This meeting is welcome to everyone, including those people who are curious & want to learn more about what "hacker culture" is. This meeting is 100% affiliated with 2600 and the US 2600 magazine. For more information, visit https://2600.com, hop into #nh2600 on the 2600 IRC network, or join us on Matrix at #nh2600:hispagatos.org.

**** The meeting time is 6:30PM to 8:30PM EST. Mobilizon is having trouble adding the venue, so this meeting will be at Grill 603, 168 Elm Street, Milford, New Hampshire. - https://www.grill603.com/ ****


Learn to Hack Web Apps - Live | #APIs #BOPLA #CTF https://cyberfeed.io/article/78e8b3c8f1c274e0b4ce01500b10df5f #cybersec #security #infosec #cybersecurity


First #RaspberryPi earned a shitstorm by hiring a cop formerly specialized in hidden surveillance.

Now they accept an investment by Sony for their proprietary AI engine to be included in the next Pi. Which "only sends metadata to the cloud".

Here's a fine list of alternatives to that now-garbage company:

- https://pine64.com/
- https://beagleboard.org/
- http://www.orangepi.org/
- https://www.banana-pi.org/
- https://www.hardkernel.com/
- https://www.friendlyelec.com/

#Privacy #Security #SBC


📱 SR130 has landed with the latest #privacy & #security news!

* New Linux tablets!
* Android 14 in public beta
* Malicious calendar invites
* More!

Tune in now: https://surveillancereport.tech
YouTube: https://youtu.be/VehvQ3e2x8w


Whole Foods, owned by Amazon, now has biometric handprint scanning to pay for your groceries.

When I expressed my concern, the feller behind the counter said, “It’s just like the biometric scanner on your phone…”

“Um, no, it’s not,” I replied. “Because THAT biometric data is on MY device, not yours.”

He shrugged in response.

I don’t advise you to go this route, friends. Not until there are more legal standards and protections in place to protect consumers.

#privacy #security
photo of Whole Foods new biometric hand scanner, to allow customers to quickly pay for food... in exchange for their handprint data.


Cybersecurity Labs (FOR FREE) - Linux Backdoor Analysis https://cyberfeed.io/article/81d7b9fb39268fe5fe9238d9013fd131 #cybersec #security #infosec #cybersecurity


I often meet #Python developers who thing #Django is too heavyweight and they prefer Flask*.

The problem is that developers underestimate the complexity of even simple web applications - take password #security, for example - https://docs.djangoproject.com/en/4.2/topics/auth/passwords/#password-upgrading

It's these kind of background features that you get for free with Django, but have to think about with any other framework.

*Nothing wrong with Flask BTW, but you need to know what you're missing out on.


Politicians dream about the idea of #encryption backdoors and the ability to read any message in the world. But what they don't realize is that they won't be the only ones using it. A #backdoor endangers us all: it is a sure road towards abuse of power and unintended exploitation that essentially voids any expectation of #security or #privacy.

Confusing? Perhaps this is more clear with a quick #comic.

Don't let the #surveillance machine run loose, friends.
Cartoon titled "Why backdooring encryption doesn't work"

A man dressed in a suit labelled "GOV" holds a sharp pin labelled "BACKDOOR" pointing menacingly towards a fully inflated balloon labelled "ENCRYPTION." The balloon is kept inflated by a machine pumping in "ALL THE WORLD'S SECRETS" into it.

The man looks at the reader and says: "I'm uncomfortable with the idea of you knowing something I don't. I'll make a small hole here, so my friends and I can access it when we think we need to. Don't worry: it's only a small hole."

The man continues in a second speech bubble: "What? C'mon, it's only a little hole! How bad can it be?"

This cartoon is authored by kzimmermann <https://kzimmermann.0x.no> and licensed under CC-BY-SA 4.0


"Security considerations play a day-to-day role. However, the “most secure protocol” is useless if few are able to understand or use it. “Usable security” itself remains an evasive concept if we can’t facilitate its implementation in real-life apps. Between usability, security, and implementation considerations there is no natural hierarchy: each constrains and influences the others."

https://delta.chat/en/2022-12-15-uidevjob

Well put.

#DeltaChat #security #UX #encryption


HackTheBox: alone, it's a pain. Two? Then I'm game! - https://m4iler.cloud/2023/04/06/hackthebox-learning/ #hackthebox #motivation #security #training #CTF


If the thought of somebody seeing your source code makes you afraid of attack, then you need to fix your source code. Transparency should not be a security concern.

#security #cybersecurity #twitter #elonmusk

https://www.neowin.net/news/parts-of-twitters-source-code-were-leaked-and-posted-on-github/


We hardly talked about #security audits but there is nothing to hide!

#DeltaChat received three security audits in total, covering core networking #encryption as well as SMTP/IMAP protocol and end-to-end encryption, and also including an audit on our recent secure server setup guide: https://delta.chat/en/2023-03-27-third-independent-security-audit


Israel Crisis

"Hundreds of thousands join nationwide protests, with key overhaul law about to pass. 200,000 rally in Tel Aviv ahead of planned ‘week of paralysis,’ with coalition set to pass law to take control of judicial appointments; 44 held, water cannon used to clear highway"

https://www.timesofisrael.com/over-200000-protest-across-israel-against-judicial-overhaul-as-gallant-urges-pause/

#Israel #Likud #CivilUnrest #Fascism #Nato #US #Iran #Security #IDF #Netanyahu


Robots are replacing security guards. Should we give them guns?

https://www.foxnews.com/tech/robots-replacing-security-guards-give-guns

#robot #security #ai #technology


A subsidiary of India's largest private bank, #HDFC, is the latest to suffer a massive data breach by the same hacker who was behind the #Acer breach a couple of days ago.

https://hackread.com/hackers-india-hdfc-bank-data-leak/

#Security #India #Breach #CyberAttack #Leaks #OpIndia


New MortalKombat ransomware decryptor recovers your files for free - Cybersecurity company Bitdefender has released a free MortalKombat ransomware decryptor t... https://www.bleepingcomputer.com/news/security/new-mortalkombat-ransomware-decryptor-recovers-your-files-for-free/ #security #software

Este sitio web utiliza cookies. Si continúa navegando por este sitio web, usted acepta el uso de las cookies.