Search
Items tagged with: security
Welcome to the New Hampshire 2600 Monthly Meeting! ^_^
2600 meetings are monthly meetings which happen all over the world on the first Friday of each month. Here hackers, technologists, and lovers of free culture come together to hang out, discuss, share ideas, share projects, and enjoy conversation on all aspects of technology.
This meeting is welcome to everyone, including those people who are curious & want to learn more about what "hacker culture" is. This meeting is 100% affiliated with 2600 and the US 2600 magazine. For more information, visit https://2600.com, hop into #nh2600 on the 2600 IRC network, or join us on Matrix at #nh2600:hispagatos.org.
**** The meeting time is 6:30PM to 8:30PM EST. Mobilizon is having trouble adding the venue, so this meeting will be at Grill 603, 168 Elm Street, Milford, New Hampshire. - https://www.grill603.com/ ****
INTERNET ENGINEERING TASK-FORCE: Reflections 10 Years Since Snowden Revelations
#News #privacy #Snowden #surveillance #spying #HumanRights #IETF #engineering #internet #security #infosec #cybersecurity #tech
https://www.ietf.org/archive/id/draft-farrell-tenyearsafter-00.html
Reflections on Ten Years Past The Snowden Revelations
This memo contains the thoughts and recountings of events that transpired during and after the release of information about the NSA by Edward Snowden.www.ietf.org
"With #AI, they could be used for all sorts of malicious tasks, including leaking people’s private information and helping criminals phish, spam, and scam people. Experts warn we are heading toward a #security and #privacy disaster.”
https://www.technologyreview.com/2023/04/03/1070893/three-ways-ai-chatbots-are-a-security-disaster/
Three ways AI chatbots are a security disaster
Large language models are full of security vulnerabilities, yet they’re being embedded into tech products on a vast scale.Melissa Heikkilä (MIT Technology Review)
🧬 SR134 is finally here with nearly an hour of #privacy & #security news!
- Your DNA is everywhere
- A free smart TV that's too good to be true
- A KeePass vulnerability
- More!
Tune in now: https://surveillancereport.tech
YouTube: https://youtu.be/ddMP9nI-E48
It Turns Out Your DNA is EVERYWHERE - SR134
Human DNA can be found literally everywhere, a free smart TV that’s too good to be true, a serious KeePass vulnerability, and more!Welcome to the Surveillanc...YouTube
Earlier this year we got into a surprising and somewhat annoying struggle with Web browser sandboxing failures related to our "web apps shared in a chat" feature. After much background work we released the hardened Delta Chat 1.36 series, also addressing a dedicated fourth independent security audit, and can finally share more of what was going on behind the scenes https://delta.chat/en/2023-05-22-webxdc-security
#chromium #deltachat #security #webxdc
Delta Chat: Bringing E2E privacy to the Web: 4th security audit 😅
Delta Chat’s “web apps shared in a chat” come with a unique privacy promise but in January it was shown to be compromised. We got into a surprising struggle with Web browser sandboxing issues that ...delta.chat
So far, the 5 biggest debates in the 21st century are #HumanCognition vs #ArtificialIntelligence, #RenewableEnergy vs #NonRenewableEnergy, #Veganism vs #Carnism, #Freedom vs #Security, and…
#JavaScript vs #Everything.
#WebDev #Programming #Python #Life #History
SimpleX Chat v5.1-beta.1 is released!
New in v5.1-beta.1:
- message reactions - finally! - only 6 for now: 👍👎😀😢❤️🚀
- self-destruct passcode.
- voice messages up to 5 minutes, with 2x quality and playback slider.
- custom time to disappear - can be set just for one message.
- message editing history.
- a setting to disable audio/video calls per contact.
- group welcome message visible in group profile.
Install the apps via the links here: https://github.com/simplex-chat/simplex-chat#install-the-app
GitHub - simplex-chat/simplex-chat: SimpleX - the first messaging platform operating without user identifiers of any kind - 100% private by design! iOS and Android apps are released 📱!
SimpleX - the first messaging platform operating without user identifiers of any kind - 100% private by design! iOS and Android apps are released 📱! - GitHub - simplex-chat/simplex-chat: SimpleX - ...GitHub
Use FIDO U2F security keys with Fedora Linux 🔑
https://fedoramagazine.org/use-fido-u2f-security-keys-with-fedora-linux/
Hardware security keys are a form of multi-factor authentication for logging into important accounts. If you were thinking about getting a one, it's good to know Fedora supports them.
But remember to get two so you can make a backup!
#Fedora #FIDO #security #privacy
Use FIDO U2F security keys with Fedora Linux - Fedora Magazine
A FIDO U2F security key is a small USB and/or NFC based device. It is a hardware security token with modules for many security related use-cases. There are several brands of FIDO compliant keys, including NitroKey, SoloKey v2, and YubiKey.Alexander Wellbrock (Fedora Project)
Our new Contact Scopes feature is now available in the Alpha channel. It provides a way to avoid granting the Contacts permission for apps requiring it. It's similar to our Storage Scopes feature replacing needing any of the media/storage permissions.
https://grapheneos.social/@GrapheneOS/110382121185752120
#ContactScopes #StorageScopes #permissions #sandbox #android #GrapheneOS #privacy #security
Random Website: You need to set up #2FA with your phone number!
Me: Why?
Website: In case we get hacked!
Me: I don't really care, no one even knows about this account and it doesn't have my personal information.
Website: You misunderstand, it's so that in case we get hacked, we HAVE your information to leak to the hackers. They worked hard and deserve it! Also we sell your account to ad companies but they're not interested unless they can tie it to a real person.
#YouTube blocking my #adblocker? Maybe reduce the frequency of #advertising interruptions and I’ll consider turning mine off. https://apple.news/AUR1RileFSuyKNE6wLNuKyw
Anyone notice this is happening at the same time #Google is working on the final stages of removing support for #Chrome #browser extensions that dynamically examine and modify web requests, e.g., strong #adblockers like #uBlockOrigin, in favor of their more restrictive #ManifestV3 spec? https://www.eff.org/deeplinks/2021/12/chrome-users-beware-manifest-v3-deceitful-and-threatening
YouTube is going to stop you from using ad blockers — here’s how — Tom's Guide
YouTube is testing out a new feature that prevents the use of ad-blocking software — and this could make a YouTube Premium subscription practically essential.apple.news
Auditor app version 70 released: https://github.com/GrapheneOS/Auditor/releases/tag/70.
See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.
Forum discussion thread:
https://discuss.grapheneos.org/d/4972-auditor-app-version-70-released
See https://attestation.app/about and https://attestation.app/tutorial for info about the app and optional monitoring service.
#GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement #auditor
Release 70 · GrapheneOS/Auditor
Notable changes in version 70: add Pixel 7a support disable attest key downgrade support which was used to work around a bug discovered/reported by GrapheneOS causing attest keys becoming unusable...GitHub
First experimental release of GrapheneOS for Pixel 7a is available. Can be installed via our staging site web installer or downloaded from the releases page for CLI install.
https://staging.grapheneos.org/install/web
https://staging.grapheneos.org/releases
We don't have a Pixel 7a yet so it's entirely untested.
#grapheneos #privacy #security #experimental #pixel7a #7a
GrapheneOS web installer
Web-based installer for GrapheneOS, a security and privacy focused mobile OS with Android app compatibility.GrapheneOS
We'll be heavily prioritizing adding support for the Pixel 7a, Pixel Tablet and Pixel Fold. It has been years since we supported a tablet (Nexus 9) and there will likely be additional work to support the form factor properly. Pixel Fold is a new form factor and may be difficult.
#grapheneos #privacy #security #pixel #pixel7a #pixeltablet #pixelfold
LEAVE GOOGLE NOW: (or yesterday)
"All you will have to do is verify your identity on the device using a PIN unlock code, biometrics such as a fingerprint or face scan, or a more sophisticated physical security dongle."
#passkey
#monopoly
#security
#privacy
#humanrights
https://www.aljazeera.com/news/2023/5/4/google-to-abolish-passwords-for-passkeys-heres-what-to-know
Google to abolish passwords for ‘passkeys’: Here’s what to know
Tech giant will now verify a person’s identity on a device using a PIN unlock code or biometrics such as a fingerprint.Al Jazeera
I'm excited to announce that I have successfully put together a #Signet #hardware #password manager, without any jumpers or hackery.
This means I will be making more of these so people who want to up their #security game will be able to just buy them.
I'll be honest: this one cost me over $300 in parts and many hours of labor. My goal is to get them down to about $45 each. That should allow me to break even (assuming I can produce them faster and my time is worth minimum wage). #infosec #foss
Google has just updated its 2FA Authenticator app and added a much-needed feature: the ability to sync secrets across devices.
TL;DR: Don't turn it on.
The new update allows users to sign in with their Google Account and sync 2FA secrets across their iOS and Android devices.
We analyzed the network traffic when the app syncs the secrets, and it turns out the traffic is not end-to-end encrypted. As shown in the screenshots, this means that Google can see the secrets, likely even while they’re stored on their servers. There is no option to add a passphrase to protect the secrets, to make them accessible only by the user.
Why is this bad?
Every 2FA QR code contains a secret, or a seed, that’s used to generate the one-time codes. If someone else knows the secret, they can generate the same one-time codes and defeat 2FA protections. So, if there’s ever a data breach or if someone obtains access .... 🧵
51% of common passwords can be cracked in less than a minute, 65% in less than an hour, 71% in less than a day, and 81% in less than a month.
Additionally, the group provided its findings in a table. As you can see in the image below, almost every password with six or fewer characters was instantly cracked.
#password #passwords #artificialintelligence #ai #security #cybersecurity #infosec #hacking
https://www.androidauthority.com/ai-password-cracking-3310709/
New study shows how scary fast today’s AI is at cracking passwords
Researchers looked into a new AI-powered password-cracking tool called PassGAN to see just how fast it could compromise passwords.Ryan McNeal (Android Authority)
Welcome to the New Hampshire 2600 Monthly Meeting! ^_^
2600 meetings are monthly meetings which happen all over the world on the first Friday of each month. Here hackers, technologists, and lovers of free culture come together to hang out, discuss, share ideas, share projects, and enjoy conversation on all aspects of technology.
This meeting is welcome to everyone, including those people who are curious & want to learn more about what "hacker culture" is. This meeting is 100% affiliated with 2600 and the US 2600 magazine. For more information, visit https://2600.com, hop into #nh2600 on the 2600 IRC network, or join us on Matrix at #nh2600:hispagatos.org.
**** The meeting time is 6:30PM to 8:30PM EST. Mobilizon is having trouble adding the venue, so this meeting will be at Grill 603, 168 Elm Street, Milford, New Hampshire. - https://www.grill603.com/ ****
Learn to Hack Web Apps - Live | #APIs #BOPLA #CTF | Cyberfeed.io
A live session called "Learn to Hack Web Apps" is being held, covering topics such as APIs, CTF, pentesting, appSec and an AMA. #BOPLA is also included in the hashtag.cyberfeed.io
Now they accept an investment by Sony for their proprietary AI engine to be included in the next Pi. Which "only sends metadata to the cloud".
Here's a fine list of alternatives to that now-garbage company:
- https://pine64.com/
- https://beagleboard.org/
- http://www.orangepi.org/
- https://www.banana-pi.org/
- https://www.hardkernel.com/
- https://www.friendlyelec.com/
#Privacy #Security #SBC
PINE64 Store - Main Page
The main purpose of Pine Store creation is servicing PINE64 community.PINE Store
* New Linux tablets!
* Android 14 in public beta
* Malicious calendar invites
* More!
Tune in now: https://surveillancereport.tech
YouTube: https://youtu.be/VehvQ3e2x8w
Surveillance Report
Weekly security and privacy news - Presented by Techlore & The New Oilsurveillancereport.tech
When I expressed my concern, the feller behind the counter said, “It’s just like the biometric scanner on your phone…”
“Um, no, it’s not,” I replied. “Because THAT biometric data is on MY device, not yours.”
He shrugged in response.
I don’t advise you to go this route, friends. Not until there are more legal standards and protections in place to protect consumers.
#privacy #security
Cybersecurity Labs (FOR FREE) - Linux Backdoor Analysis | Cyberfeed.io
Jump into cybersecurity training with Pay What You Can courses offered by John Strand. Learn Linux Backdoor Analysis and access training materials for free or make a donation that suits your budget.cyberfeed.io
The problem is that developers underestimate the complexity of even simple web applications - take password #security, for example - https://docs.djangoproject.com/en/4.2/topics/auth/passwords/#password-upgrading
It's these kind of background features that you get for free with Django, but have to think about with any other framework.
*Nothing wrong with Flask BTW, but you need to know what you're missing out on.
Confusing? Perhaps this is more clear with a quick #comic.
Don't let the #surveillance machine run loose, friends.
https://delta.chat/en/2022-12-15-uidevjob
Well put.
#DeltaChat #security #UX #encryption
Delta Chat: Decentralization Unchained (Psst ... want a UI/UX dev job?)
What do indigenous communities in the Amazon rainforest, friends in Cuba, families in Iran, activists from Russia, a monastery in Cambodia, and many folks in the Fediverse have in common? You guess...delta.chat
HackTheBox: alone, it's a pain. Two? Then I'm game!
I have had my HackTheBox account for a long time now. Getting close to a decade. For those of you who don’t know, HackTheBox is a training/CTF platform, similar to TryHackMe. It is also a little diffem4iler
#security #cybersecurity #twitter #elonmusk
https://www.neowin.net/news/parts-of-twitters-source-code-were-leaked-and-posted-on-github/
Parts of Twitter's source code were leaked and posted on GitHub
Twitter revealed the source code leak in a court filing on Friday, but there's no word on who posted the code on GitHub, nor how long it was available on the Microsoft-owned software development site.John Callaham (Neowin)
#DeltaChat received three security audits in total, covering core networking #encryption as well as SMTP/IMAP protocol and end-to-end encryption, and also including an audit on our recent secure server setup guide: https://delta.chat/en/2023-03-27-third-independent-security-audit
Delta Chat: Good news from security audits, past and present
In case you wonder how safe Delta Chat’s core messaging implementation and server guides is, you may be interested in the summary statement from the recent independent security audit by Cure53: &qu...delta.chat
"Hundreds of thousands join nationwide protests, with key overhaul law about to pass. 200,000 rally in Tel Aviv ahead of planned ‘week of paralysis,’ with coalition set to pass law to take control of judicial appointments; 44 held, water cannon used to clear highway"
https://www.timesofisrael.com/over-200000-protest-across-israel-against-judicial-overhaul-as-gallant-urges-pause/
#Israel #Likud #CivilUnrest #Fascism #Nato #US #Iran #Security #IDF #Netanyahu
Hundreds of thousands join nationwide protests, with key overhaul law about to pass | The Times of Israel
200,000 rally in Tel Aviv ahead of planned 'week of paralysis,' with coalition set to pass law to take control of judicial appointments; 44 held, water cannon used to clear highwayToI Staff (Times of Israel)
#infosec #OpenSource
Ubuntu 22.10 Users Get New Linux Kernel Security Update, 9 Vulnerabilities Patched - 9to5Linux
Canonical released a new Linux kernel security update for Ubuntu 22.10 (Kinetic Kudu) users to address nine security vulnerabilities.Marius Nestor (9to5Linux)
#Infosec #News #Cybersecurity #Google #ProjectZero #vulnerability #exploit #modem #Exynos #privacy #security #smartphone #android
https://arstechnica.com/information-technology/2023/03/critical-vulnerabilities-allow-some-android-phones-to-be-hacked/
Google tells users of some Android phones: Nuke voice calling to avoid infection
If your device runs Exynos chips, be very, very concerned.Ars Technica
https://www.foxnews.com/tech/robots-replacing-security-guards-give-guns
#robot #security #ai #technology
Robots are replacing security guards. Should we give them guns?
Cobalt Robotics is creating robot security guards that can keep businesses safe. Kurt "CyberGuy' Knutsson explains the pros and cons of this new tech.Kurt Knutsson, CyberGuy Report (Fox News)
https://hackread.com/hackers-india-hdfc-bank-data-leak/
#Security #India #Breach #CyberAttack #Leaks #OpIndia
Hacker Leaks 73M Records from Indian HDFC Bank Subsidiary
A hacker known as Kernelware has leaked user data belonging to HDB Financial Services, a subsidiary of India's largest private bank, HDFC Bank.Waqas (Hack Read)
New MortalKombat ransomware decryptor recovers your files for free
Cybersecurity company Bitdefender has released a free MortalKombat ransomware decryptor that victims can use to restore their files without paying a ransom.Bill Toulas (BleepingComputer)