@rysiek Yeah, embargo has just been broken: https://efail.de/
HTML parsing in email clients is to blame, no problems when working in plain-text mode.
#infosec #gpg #pgp
Notices tagged with infosec, page 8
-
Alexander Bochmann (galaxis@mastodon.infra.de)'s status on Monday, 14-May-2018 10:21:33 UTC Alexander Bochmann -
Rysiekúr Memesson (rysiek@mastodon.social)'s status on Monday, 14-May-2018 07:57:53 UTC Rysiekúr Memesson What the actual fuck:
https://www.eff.org/deeplinks/2018/05/attention-pgp-users-new-vulnerabilities-require-you-take-action-now"A group of European security researchers have released a warning about a set of vulnerabilities affecting users of PGP and S/MIME. EFF has been in communication with the research team, and can confirm that these vulnerabilities pose an immediate risk to those using these tools for email communication, including the potential exposure of the contents of past messages."
-
Rysiekúr Memesson (rysiek@mastodon.social)'s status on Saturday, 12-May-2018 12:56:59 UTC Rysiekúr Memesson Oh boy. https://github.com/signalapp/Signal-Desktop/issues/1635
tl;dr Signal Desktop is based on Electron, which in turn is based on Chromium 58-59, and it seems to be affected by bugs that have been fixed in Chrome/Chromium 60-62.
Gotta love #Electron. As somebody said "now everyone is running 5 different instances of old insecure versions of the most scrutinized and attacked application on Earth."
-
Rysiekúr Memesson (rysiek@mastodon.social)'s status on Friday, 04-May-2018 12:25:55 UTC Rysiekúr Memesson I do not want to live on this planet anymore:
https://arstechnica.com/information-technology/2018/05/drive-by-rowhammer-attack-uses-gpu-to-compromise-an-android-phone/"[T]he exploit is the first to show that GPUs can flip individual bits stored in dynamic random-access memory. (...) It's also the first Rowhammer attack that uses standard JavaScript to compromise a smartphone, meaning it can be executed when users do nothing more than visit a malicious website. Another key innovation: on average, GLitch takes less than two minutes to compromise a device"
-
Tarik (crowd42@infosec.exchange)'s status on Saturday, 28-Apr-2018 11:40:11 UTC Tarik 48 million people put at risk after firm that scraped social networks left data exposed for anyone to download https://hotforsecurity.bitdefender.com/blog/48-million-people-put-at-risk-after-firm-that-scraped-info-from-social-networks-left-it-exposed-for-anyone-to-download-19784.html#new_tab #infosec
-
Rysiekúr Memesson (rysiek@mastodon.social)'s status on Friday, 20-Apr-2018 16:03:04 UTC Rysiekúr Memesson Wait, what. Windows 10 sends info on USB devices plugged in directly to Microsoft?
And it does that using pure HTTP?
https://pastebin.com/ttYp5rLgYou gotta be kidding me.
-
The GME™🙈🙉🙊 (gme@toot.zone)'s status on Saturday, 14-Apr-2018 14:16:01 UTC The GME™🙈🙉🙊 RT @Fisher85M@twitter.com: Classic. {Comic}
#Cybersecurity #IoT @fisher85m@twitter.com #IoTSecurity #infosec #security
https://twitter.com/Fisher85M/status/985157005680742400 -
Râu Cao ⚡ (raucao@kosmos.social)'s status on Friday, 06-Apr-2018 22:52:10 UTC Râu Cao ⚡ T-Mobile Austria started a big old #infosec dumpster fire on birdsite: https://twitter.com/tmobileat/status/982190220798967809 /ht @bkero
-
9sd9dffa7s8d99f0a7s8d (vagnes@infosec.exchange)'s status on Friday, 30-Mar-2018 08:18:43 UTC 9sd9dffa7s8d99f0a7s8d MyFitnetssPal got hacked.
https://www.digitaltrends.com/computing/under-armour-myfitnesspal-accounts-hacked/
-
Tinker ☀️ (tinker@infosec.exchange)'s status on Friday, 23-Mar-2018 01:41:43 UTC Tinker ☀️ Anyone who just recently joined Mastodon, post up an introduction about who you are, what you do, and what you like to talk about!
Hashtag it #Introductions or #Introduction ! We use hashtags a lot to follow ideas across multiple instances!
Check those Introduction hashtags to meet more new folks.
Here are two of my favorite hashtags:
- #Infosec
- #MastoArtOther folks might have other suggestions!
-
absorto (absor70@freeradical.zone)'s status on Wednesday, 21-Mar-2018 13:28:34 UTC absorto Help the 5th edition of the biggest infoSec, cryptography and hacking convention in Latin America exist. Have some spare money? Donate so the 5th Crypto Rave can happen! There is only a few days left 😱😱 https://cryptorave.org/en/
You can also submit a proposal for an activity! There'll be tons of lectures, talks, workshops, installfest and partying 😃
Retoots are more than welcome :)
#crypto #infoSec #cryptorave #crowdfunding -
aeTIos (aetios@i.write.codethat.sucks)'s status on Wednesday, 21-Mar-2018 11:16:29 UTC aeTIos Hello! Made an account here some time ago because the instance name resonated with me, then decided to actually do something with it because @bb010g shilled mastodon so here I am I guess. I'm looking for some people to follow so taking suggestions. My bio describes my interests quite accurately but here are some of them as tags #music #guitar #warhammer #gaming #linux #programming #security #infosec
Have a great day and see you around :D #introduction
-
piks3l (piks3l@pouet.it)'s status on Friday, 09-Mar-2018 15:37:51 UTC piks3l Sandvine’s PacketLogic Devices Used to Deploy Government Spyware in Turkey and Redirect Egyptian Users to Affiliate Ads?
-
piks3l (piks3l@pouet.it)'s status on Tuesday, 27-Feb-2018 09:14:39 UTC piks3l When you are #infosec but also #medieval https://pouet.it/media/ljM9QuJdx8cu0wwvU_k
-
Seize the means of computation (brandon@fosstodon.org)'s status on Monday, 15-Jan-2018 14:28:53 UTC Seize the means of computation Cisco can now sniff out malware inside encrypted traffic - https://www.theregister.co.uk/2018/01/11/cisco_sniff_malware_inside_encrypted_traffic/
Yeah but you have to send traffic from their kit flow to a cloud-based analytics service. That's not gonna form YET another surface of attack. Naaah
-
Alexander Bochmann (galaxis@mastodon.infra.de)'s status on Monday, 25-Dec-2017 11:33:30 UTC Alexander Bochmann #infosec christmas present: Privilege escalation through bugs in the eBPF verifier in Linux 4.4 and newer.
https://www.decadent.org.uk/ben/blog/bpf-security-issues-in-debian.html
https://marc.info/?l=oss-security&m=151388232503996&w=2 -
Tinker ☀️ (tinker@infosec.exchange)'s status on Wednesday, 20-Dec-2017 21:51:54 UTC Tinker ☀️ Bad idea! #Keeper , a password manager bundled with Windows has a security flaw. Security journalists reported on it. What did Keeper do? Sued the journalists.
Fuck Keeper.
-
Boing Boing (boingboingbot@botsin.space)'s status on Friday, 17-Nov-2017 18:20:08 UTC Boing Boing EFF's Security Education Companion: essential materials for people helping their communities practice good information security https://boingboing.net/2017/11/17/enabling-teachers-with-securit.html #securityeducationcompanion #trainertraining #pedagogy #security #infosec #opsec #Post #eff
-
தோட்டக்காரன்(gardener) (solariiknight@social.systemreboot.net)'s status on Thursday, 19-Oct-2017 18:36:20 UTC தோட்டக்காரன்(gardener) Information, once stored centrally will be breached someday.
- Murphy's law for Databases.
https://social.systemreboot.net/url/67598
#infosec #DestroyTheAadhaar #Aadhaar -
தோட்டக்காரன்(gardener) (solariiknight@social.systemreboot.net)'s status on Wednesday, 18-Oct-2017 11:37:41 UTC தோட்டக்காரன்(gardener) 2048 bit keys generated by Infineon's RSA Library version v1.02.013, is vulnerable to factorisation.
This library was used to generate keys using smartcards instead of PCs. However, the method used generates keys that are vulnerable to factorisation.
https://social.systemreboot.net/url/67545
#infosec #RSA #publickeycryptography
Encryption is truly an arms race! Its not matter of if, but when it will be broken.