Bobinas P4G
  • Login
  • Public

    • Public
    • Groups
    • Popular
    • People

Notices by infosec-handbook.eu (infosechandbook@mastodon.at)

  1. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Tuesday, 20-Aug-2019 16:01:12 UTC infosec-handbook.eu infosec-handbook.eu

    VLC media player 3.0.8 released, fixes security vulnerabilities:

    https://www.videolan.org/security/sb-vlc308.html

    – 12 security vulnerabilities were fixed
    – all versions prior to 3.0.8 are vulnerable to most of these vulnerabilities

    #vlc #videolan #mediaplayer #update #infosec #security #cybersecurity

    In conversation Tuesday, 20-Aug-2019 16:01:12 UTC from mastodon.at permalink
  2. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Friday, 12-Jul-2019 17:20:19 UTC infosec-handbook.eu infosec-handbook.eu

    Physical (de)centralization of Mastodon servers – after our XMPP scan, we took 1000+ random Mastodon servers and looked at their hosters:

    https://gist.github.com/infosec-handbook/0cdb8da86cfe63be657fcf44bde291d1

    – about 50% of these servers are hosted by only 5 companies in 4 countries
    – 26% of servers are hosted in Japan, followed by the USA (24%) and France (23%)

    #mastodon #decentralization #centralization #statistics

    In conversation Friday, 12-Jul-2019 17:20:19 UTC from mastodon.at permalink
  3. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Sunday, 07-Jul-2019 12:59:46 UTC infosec-handbook.eu infosec-handbook.eu

    Notes on privacy and data collection of Matrix.org:

    https://gist.github.com/maxidorius/5736fd09c9194b7a6dc03b6b8d7220d0

    "matrix.org and vector.im receive a lot of private, personal and identifiable data on a regular basis, or metadata that can be used to precisely identify and/or track users/server, their social graph, usage pattern and potential location. This is possible both by the default configuration values in synapse/Riot […]"

    #matrix #messaging #riot #security #privacy

    In conversation Sunday, 07-Jul-2019 12:59:46 UTC from mastodon.at permalink
  4. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Wednesday, 26-Jun-2019 17:26:20 UTC infosec-handbook.eu infosec-handbook.eu

    Tor-focussed :tor: operating system Tails 3.14.2 released:

    https://tails.boum.org/news/version_3.14.2/index.en.html

    – update for Tor Browser (8.5.3)
    – ⚠ the Tails OS developers strongly advice against using Tails OS 3.14.1 or earlier: https://tails.boum.org/security/sandbox_escape_in_tor_browser/index.de.html

    #tails #tor #torbrowser #privacy #anonymity

    In conversation Wednesday, 26-Jun-2019 17:26:20 UTC from mastodon.at permalink

    Attachments


  5. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Tuesday, 21-May-2019 18:02:42 UTC infosec-handbook.eu infosec-handbook.eu

    Tor Browser :tor: 8.5 released, comes with first stable version for Android:

    https://blog.torproject.org/new-release-tor-browser-85

    – based on FF 60.7.0esr
    – updates for Torbutton, HTTPS Everywhere, OpenSSL, Tor Launcher
    – fixes dozens of bugs

    #tor #torbrowser #webbrowser #anonymity #privacy #android #torbrowser85

    In conversation Tuesday, 21-May-2019 18:02:42 UTC from mastodon.at permalink
  6. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Tuesday, 14-May-2019 06:48:48 UTC infosec-handbook.eu infosec-handbook.eu

    After major security vulnerabilities or data breaches, "security people" show up and tell you to delete your account immediately. "Oh, time to delete your account! Switch to service/product … instead!"

    Such statements totally ignore that security vulnerabilities are widespread and the vast majority of data breaches won't become publicly-known. Full control over your data and devices requires 100% isolation from the internet, not just arbitrarily switching services or products.

    #infosec

    In conversation Tuesday, 14-May-2019 06:48:48 UTC from mastodon.at permalink
  7. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Tuesday, 07-May-2019 03:59:14 UTC infosec-handbook.eu infosec-handbook.eu

    Tor-focussed :tor: operating system Tails 3.13.2 released:

    https://tails.boum.org/news/version_3.13.2/index.en.html

    – update for Tor Browser to fix disabled extensions
    – updates for Debian (9.9), and Thunderbird 60.6.1
    – bug fixes and minor changes

    #tails #tor #torbrowser #privacy #anonymity

    In conversation Tuesday, 07-May-2019 03:59:14 UTC from mastodon.at permalink
  8. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Tuesday, 07-May-2019 03:55:49 UTC infosec-handbook.eu infosec-handbook.eu

    Tor Browser :tor: 8.0.9 released, fixes disabled extensions:

    https://blog.torproject.org/new-release-tor-browser-809

    – re-enable xpinstall.signatures.required if you disabled this
    – updates for NoScript, and Torbutton

    #tor #torbrowser #webbrowser #anonymity #privacy

    In conversation Tuesday, 07-May-2019 03:55:49 UTC from mastodon.at permalink
  9. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Saturday, 27-Apr-2019 06:43:52 UTC infosec-handbook.eu infosec-handbook.eu

    2+ million IoT devices vulnerable to man-in-the-middle attacks, allowing attackers to steal passwords:

    https://hacked.camera/

    – the website contains a list, so you can check if your devices are vulnerable
    – CVE-2019-11219, CVE-2019-11220
    – mitigation: dispose your vulnerable devices, or block OUTBOUND traffic to 32100/udp

    #iot #vulnerability #cve201911219 cve201911220 #infosec #mitm #cybersecurity #security

    In conversation Saturday, 27-Apr-2019 06:43:52 UTC from mastodon.at permalink
  10. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Saturday, 20-Apr-2019 04:27:36 UTC infosec-handbook.eu infosec-handbook.eu

    OpenSSH 8.0 available:

    https://www.openssh.com/txt/release-8.0

    – contains mitigations for an scp vulnerability (CVE-2019-6111)
    – adds experimental post-quantum key exchange method, based on a combination of Streamlined NTRU Prime 4591^761 and X25519
    – increases the default RSA key size to 3072 bits
    – includes several bug fixes

    #openssh #ssh #infosec #security #cybersecurity #postquantum #crypto #x25519 #rsa

    In conversation Saturday, 20-Apr-2019 04:27:36 UTC from mastodon.at permalink
  11. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Friday, 19-Apr-2019 05:53:35 UTC infosec-handbook.eu infosec-handbook.eu

    Facebook :facebook: always in the news. This time: Millions of passwords of Instagram users stored in plaintext:

    https://thehackernews.com/2019/04/instagram-password-plaintext.html

    – millions of plaintext passwords of Instagram and Facebook users were accessible to Facebook
    – besides, Facebook stored 1.5 million records of users without their consent or knowledge

    #facebook #instagram #privacy #password #infosec #cybersecurity #security

    In conversation Friday, 19-Apr-2019 05:53:35 UTC from mastodon.at permalink
  12. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Thursday, 11-Apr-2019 04:03:45 UTC infosec-handbook.eu infosec-handbook.eu

    Dragonblood–vulnerabilities in WPA3 standard:

    https://papers.mathyvanhoef.com/dragonblood.pdf (PDF file)

    – the paper describes 5 different vulnerabilities (DoS, downgrade, side-channel attacks)
    – researches believe that WPA3 "does not meet the standards of a modern security protocol"
    – the Wi-Fi Alliance published a security update for the standard: https://www.wi-fi.org/security-update-april-2019

    #wpa3 #wifi #wlan #infosec #security #cybersecurity #dragonblood #dragonfly #kex

    In conversation Thursday, 11-Apr-2019 04:03:45 UTC from mastodon.at permalink

    Attachments


  13. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Saturday, 06-Apr-2019 04:54:19 UTC infosec-handbook.eu infosec-handbook.eu

    Git–learn to contribute to e-mail-driven Git projects:

    https://git-send-email.io/

    #git #development #email

    In conversation Saturday, 06-Apr-2019 04:54:19 UTC from mastodon.at permalink
  14. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Thursday, 04-Apr-2019 03:53:06 UTC infosec-handbook.eu infosec-handbook.eu

    Facebook–security team spots 146GB dataset containing 540 million records of Facebook users:

    https://www.upguard.com/breaches/facebook-user-data-leak

    – dataset includes comments, likes, reactions, account names, Facebook IDs, and more
    – origin of the leak is the Mexico-based media company Cultura Colectiva that develops third-party apps
    – a second dataset contains 22,000 cleartext passwords from 2014

    #facebook #leak #culturacolectiva #privacy #infosec #cybersecurity #security

    In conversation Thursday, 04-Apr-2019 03:53:06 UTC from mastodon.at permalink
  15. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Saturday, 23-Mar-2019 06:39:39 UTC infosec-handbook.eu infosec-handbook.eu

    Mozilla releases updates for two critical security vulnerabilities in Firefox:

    https://www.mozilla.org/en-US/firefox/66.0.1/releasenotes/

    https://www.mozilla.org/en-US/firefox/60.6.1/releasenotes/

    Fixed versions are:

    – Firefox 66.0.1
    – Firefox for Android 66.0.1
    – Firefox ESR 60.6.1
    – Tor Browser 8.0.8

    #firefox #mozilla #update #vulnerability #security #infosec #cybersecurity #pwn2own

    In conversation Saturday, 23-Mar-2019 06:39:39 UTC from mastodon.at permalink
  16. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Friday, 15-Mar-2019 13:56:25 UTC infosec-handbook.eu infosec-handbook.eu

    As announced in January, we looked at the /e/ Android ROM, provided by the /e/ Foundation:

    https://infosec-handbook.eu/blog/e-foundation-first-look/

    – it isn't completely "ungoogled" as promised
    – some traffic of preinstalled apps is unencrypted and contains personal data
    – the security of their website is in great need of improvement

    #efoundation #android #googlefree #privacy #signal #magicearth #microg #k9mail #fdroid

    In conversation Friday, 15-Mar-2019 13:56:25 UTC from mastodon.at permalink
  17. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Wednesday, 13-Mar-2019 16:39:28 UTC infosec-handbook.eu infosec-handbook.eu

    Google Play–more than 200 apps contain "SimBad" adware, downloaded more than 150 million times:

    https://techcrunch.com/2019/03/13/new-android-adware-google-play/

    – the malware masquerades as an ad-serving platform
    – SimBad is mostly contained in free games
    – list of infected apps: https://assets.documentcloud.org/documents/5766854/SimBad-AppList-Package.txt

    #simbad #malware #adware #android #google #googleplay #infosec #cybersecurity #security

    In conversation Wednesday, 13-Mar-2019 16:39:28 UTC from mastodon.at permalink

    Attachments


    1. Invalid filename.
  18. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Wednesday, 13-Mar-2019 16:34:12 UTC infosec-handbook.eu infosec-handbook.eu

    WordPress 5.1–critical exploit chain that enables an unauthenticated attacker to gain remote code execution on any WordPress installation:

    https://blog.ripstech.com/2019/wordpress-csrf-to-rce/

    – exploit is possible due to a CSRF vulnerability in comment forms
    – fixed in WordPress 5.1.1

    #wordpress #rce #csrf #wordpress5 #infosec #cybersecurity #security

    In conversation Wednesday, 13-Mar-2019 16:34:12 UTC from mastodon.at permalink
  19. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Tuesday, 29-Jan-2019 15:31:49 UTC infosec-handbook.eu infosec-handbook.eu

    French /e/ foundation develops Google-free Android :android: ROM (in development):

    https://e.foundation/

    – we are testing it on Moto G4 (Android 7.1.2, Patch Level Dec 2018)
    – ROM comes with Signal, Magic Earth, K-9 Mail (fork), microG and more
    – you can use F-Droid as an app store
    – we will likely publish an article about it in the near future

    #efoundation #android #googlefree #privacy #signal #magicearth #microg #k9mail #fdroid

    In conversation Tuesday, 29-Jan-2019 15:31:49 UTC from mastodon.at permalink

    Attachments


    1. https://todon.nl/system/media_attachments/files/001/999/338/original/471038f13412e6f7.png
  20. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Tuesday, 22-Jan-2019 04:42:51 UTC infosec-handbook.eu infosec-handbook.eu

    Parrot OS 4.5 released:

    https://www.parrotsec.org/blog/parrot-4-5-release-notes/

    – Parrot is 64bit only now
    – new Docker templates introduced
    – based on Linux 4.19
    – contains Metasploit 5.0

    #parrot #os #pentesting #security #infosec #cybersecurity #metasploit

    In conversation Tuesday, 22-Jan-2019 04:42:51 UTC from mastodon.at permalink
  • Before

User actions

    infosec-handbook.eu

    infosec-handbook.eu

    A European non-profit information security blog that appreciates your privacy.#blog #nobot #infosec #security #privacy #infosechandbook

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          9228
          Member since
          30 Apr 2018
          Notices
          27
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • Privacy
          • Source
          • Version
          • Contact

          Bobinas P4G is a social network. It runs on GNU social, version 2.0.1-beta0, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All Bobinas P4G content and data are available under the Creative Commons Attribution 3.0 license.