Search
Items tagged with: security
puri.sm/posts/the-evolution-of…
#UserPrivacy #Purism #PureOS #Security
The Evolution of Smartphone Security – Purism
Purism makes premium phones, laptops, mini PCs and servers running free software on PureOS. Purism products respect people's privacy and freedom while protecting their security.Purism SPC
Accrescent 0.23.0 is out! This release makes multilingual support a little bit better, prevents you from accidentally using your metered data by default, and improves the security of its dependencies.
See the release notes below 👇
github.com/accrescent/accresce…
#accrescent #privacy #security #appstore #android
Release 0.23.0 · accrescent/accrescent
This release makes Accrescent a little more friendly for multilingual users, helps prevent you from accidentally using your metered data by default, and improves security by removing an unmaintaine...GitHub
Why did you choose Tuta Mail? 😀
#Tuta #Germany #privacy #bestemail #encryption #security #PrivacyMatters #FREE #SecureEmail #privacyfirst #encrypted #protect
We sat down with Troy Hunt from Have I Been Pwned to discuss how to maintain privacy and security despite the constant wave of data breaches. 🧑💻
Check it out here 👉 youtu.be/94WJbheo_T0
#privacy #security #databreach #passwords #encryption
Passwords, Data Breaches & Security with Troy Hunt from Have I Been Pwned | Tuta Talks #password
We sat down with Troy Hunt from Have I Been Pwned to discuss #passwords, data breaches, and what you can do to keep your personal information safe online.Wit...YouTube
I learned about secure software development on the job, but like ethical computing (which I've talked about before), this should also be included in formal education. Because of the current threat models, topics like security by design and zero-trust frameworks are critical when developing Internet systems. linuxfoundation.org/press/linu…
#securitybydesign #security #softwaredevelopment #zerotrust #infosec #cybersecurity #education
The Linux Foundation and OpenSSF Release Report on the State of Education in Secure Software Development
Findings show nearly one-third of industry professionals are not familiar with secure software development practicesThe Linux Foundation
#WhatsApp for #Windows lets Python, PHP scripts execute with no warning
Granted, Python needs to be installed on the system prior.
Meta says they will not bother to fix this, despite maintaining a built-in list of potentially dangerous file types (ex: .exe)
Being #OpenSource has many advantages. For #NVDA has opened the way for community contributions, and has enabled #transparency, #security and #innovation beyond what might have been possible in closed software. Increasingly, governments are also mandating the use of open source. Here is an article on such a step forward in Switzerland:
"Switzerland Makes Open Source Software Mandatory For Public Sector"
news.itsfoss.com/switzerland-o…
#FOSS #NVDA #NVDAsr #Accessibility #Software #News
Switzerland Makes Open Source Software Mandatory For Public Sector
A big boost to the open-source community and an inspiration to other public sectors!Sourav Rudra (It's FOSS News)
puri.sm/posts/private-cellular…
Private Cellular Networking and Secure Client Devices – Purism
Purism makes premium phones, laptops, mini PCs and servers running free software on PureOS. Purism products respect people's privacy and freedom while protecting their security.Purism SPC
We all have an email alter ego - who is yours? 🥸
Let us know in the comments!
#email #privacy #officehumor #security #encryption
In case you missed it: Accrescent is now mirrored in the GrapheneOS App Store! This helps GrapheneOS users securely and easily obtain Accrescent from a trusted source.
GrapheneOS highly values privacy and security as we do, so we're excited about this collaboration.
grapheneos.social/@GrapheneOS/…
#privacy #security #accrescent #appstore #android
GrapheneOS (@GrapheneOS@grapheneos.social)
GrapheneOS App Store now includes a mirror of Accrescent, which is a privacy and security focused alternative to the Play Store distributing developer builds of apps: https://accrescent.GrapheneOS Mastodon
What's the main difference between Tuta Mail and Gmail? 😎 PRIVACY 🔐
Get your #FREE Tuta Mail account now: app.tuta.com/signup
#Tuta #Germany #privacy #freedom #bestemail #encryption #security #PrivacyMatters #FREE #SecureEmail #privacyfirst #encrypted
Secure Emails Become a Breeze
Tuta Mail is the secure email service, built in Germany. Use encrypted emails on all devices with our open source email client, mobile apps & desktop clients.Tuta Mail
APPLE OR ANDROID? 🧐
Either way, we've got you covered ✌️
Read our #tips for protecting your #privacy on iPhone and Android here👇
✅Android users: tuta.com/blog/android-settings…
✅iPhone users: tuta.com/blog/iphone-security-…
#apple #android #security #tips #privacytips #securitytips #Tuta #encrypted #Eu
Increase your privacy with these Android security settings.
Don’t share all your data with Google! Improving your privacy settings on Android is quick and easy with this guide.Tutanota
STAGGERING: Nearly all #ATT customers' text & call records breached.
An unnamed entity now has an NSA-level view into Americans' lives.
Damage isn't limited to AT&T customers.
But everyone they interacted with.
Also a huge national security incident given government customers on the network.
And of course, third party #Snowflake makes an appearance.
cnn.com/2024/07/12/business/at…
#infosec #cybersecurity #telco #cellular #privacy #security #breach
Computer hardware maker #Zotac exposed customers' RMA info on Google Search
Misconfiguration of permissions folders holding customer info related to RMAs have been indexed by search engines like #Google. As a result, it has shown up on SERPs.
Information leaked includes invoices, addresses, and contact information.
Fun fact: Security Misconfiguration is number 6 on the OWASP Top 10 Web app Security Risks.
Do you want to help secure GNOME and get a reward? 🏅
We are testing a new program in which people get a payment for reporting and/or solving vulnerabilities.
yeswehack.com/programs/gnome-b…
From €500 to €10,000 depending on criticality 💶
For now only GLib is in scope but we will expand the list of modules and advertise as the program grows.
In partnership with @yeswehack and @sovtechfund
#GNOME #infosec #FreeSoftware #security #bugBounty #OpenSource #cybersecurity
GNOME Bug Bounty Program bug bounty program - YesWeHack
GNOME Bug Bounty Program bug bounty program detailsYesWeHack #1 Bug Bounty Platform in Europe
This is a bit of a concern @signalapp hopefully this is addressed sooner
@Mer__edith
#Signal #Bug #security
Another one back-to-back! Accrescent 0.22.0 is released to ensure Accrescent can always update itself, add a theme option to settings, and fix a bug related to preferred languages: github.com/accrescent/accresce…
#security #android #appstore #privacy #accrescent
Release 0.22.0 · accrescent/accrescent
This release ensures Accrescent can always update itself, adds a setting to manually change the app theme (light, dark, or system), and fixes an issue where app's wouldn't be installed in the user'...GitHub
Blind writer tries the Gandalf | Lakera prompt injection game for the first time.
Upon recommendations, I tried this AI prompt injection game for the first time. I made it to level 7 with no help from the internet!
If you want to donate to me, donate to me on this page.
My website is here where I usually blog. I'm not much of a video person, so I blog and write more than I do video!
Gandalf | Lakera – Test your prompting skills to make Gandalf reveal secret information.
Trick Gandalf into revealing information and experience the limitations of large language models firsthand.gandalf.lakera.ai
Accrescent 0.21.0 is out with minor accessibility improvements, settings changes, and networking improvements.
Check it out and read the release notes below!
github.com/accrescent/accresce…
#android #security #privacy #appstore #accrescent
Release 0.21.0 · accrescent/accrescent
This release includes some minor accessibility improvements, settings changes, and network improvements. Changes A11y: Announce app list refreshing state (@PatrykMis) Add donation link to settings...GitHub
3/3 For those interested in learning more about the code signing process, and this warning, please see: answers.microsoft.com/en-us/wi…"
and if you would like to test out Alpha builds of NVDA, head to: Please feel encouraged to run the latest snapshot from nvaccess.org/files/nvda/snapsh….
If you do have any questions or concerns, please reach out to us at info@nvaccess.org.
#NVDA #FOSS #Alpha #testing #Prerelease #Certificate #Security
2/3 When the warning appears, press tab to "More info", then press enter. Reading through the dialog, note that the publisher is listed as:
"AU, Queensland, Camp Mountain, NV Access Limited, NV Access Limited"
To allow NVDA to run, press tab to "Run anyway", and press enter to run the snapshot. This will help us get through this period until Windows considers our certificate "trusted":
#NVDA #FOSS #Alpha #testing #Prerelease #Certificate #Security
ID Verification Service for #TikTok, #Uber, X Exposed Driver Licenses
In this case, the ID verification vendor leaked admin credentials and exposed people’s information (sensitive documents and status of verification) for over a year.
All for “age verification” we introduce another EZ mode way for people’s real life identities to be compromised. Companies want you to provide sensitive documents to prove you’re real/your age but can’t be bothered to invest money/time/effort in basic #security to secure what you give them.
404media.co/id-verification-se…
ID Verification Service for TikTok, Uber, X Exposed Driver Licenses
As social networks and porn sites move towards a verified identity model, the actions of one cybersecurity researcher show that ID verification services themselves could get hacked too.Joseph Cox (404 Media)
#Windows 11 is now automatically enabling #OneDrive folder backup without asking permission
"Quietly and without any announcement, the company [#Microsoft] changed Windows 11's initial setup so that it could turn on the automatic folder backup without asking for it."
Imagine your operating system forcing all your desktop files to sync to the cloud, without letting you know it would do that. Users should be aware of when their files are synced to any cloud.
Oh wait, I forgot... Microsoft has zero regard for user choice, #privacy, and #security.
neowin.net/news/windows-11-is-…
Windows 11 is now automatically enabling OneDrive folder backup without asking permission
Microsoft quietly changed how folder backup works in the OneDrive app on Windows 11. Now, the OS enables it by default during the initial setup without asking the user for permission.Taras Buria (Neowin)
"for the first time, Commissioner Jourova publicly admitted at yesterday's EDPS summit that encryption would need to be broken for Chat Control to become effective."
— tuta.com/blog/interview-patric…
#ChatControl #EuropeanCommission #Surveillance #EU #Privacy #HumanRights #Encryption #Security
Europe and Australia will both not break encryption! We’ve interviewed Patrick Breyer – the guy who coined the term Chat Control.
Action taken by privacy activists and citizens stops the push for mass surveillance.Tutanota
Patrick Breyer fordert zum Widerstand gegen die Chatkontrolle auf und gibt Tipps, wie sich jeder Einzelne aktiv beteiligen kann. Werdet JETZT aktiv, sonst kann es sein, dass die Unvernunft siegt. 👇
patrick-breyer.de/rat-soll-cha…
#chatkontrolle #ChatkontrolleStoppen #sicherheit #security #datenschutz #privacy
Rat soll Chatkontrolle durchwinken - Werde jetzt aktiv!
Der belgische Vorsitz im Rat der EU will die Chatkontrolle am Mittwoch den 19. Juni abstimmen lassen. Damit bestätigen sich die Befürchtungen: die Verfechter der Chatkontrolle wollen ausnutzen, dass es nach den Wahlen weniger öffentliche Aufmerksamke…Patrick Breyer
potaroo.net/ispcol/2024-05/dns…
My own domains are DNSSEC-signed. The necessary Bind 9 configuration is simpler nowadays than it used to be, as much of the process has been automated - a welcome change.
#Internet #DNS #DNSSEC #security
securitycryptographywhatever.c…
#Security #CryptographicProtocols
ekr
iykyk Links: https://hovav.net/ucsd/dist/draft-shacham-tls-fasttrack-00.txt https://crypto.stanford.edu/~dabo/pubs/papers/fasttrack.pdf https://datat...securitycryptographywhatever.com
New Windows AI feature records everything you’ve done on your PC
Recall uses AI features "to take images of your active screen every few seconds."Ars Technica
We love #DNS! ❤️
Tuta uses DMARC, DKIM & SPF to protect your domains from spoofing. Unlimited custom domain aliases & strong #security are a perfect match. 🔒
Not sure what these acronyms mean? No worries, we've got you covered.
👉 tuta.com/blog/dkim-custom-emai…
Tuta Mail supports SPF, DMARC and DKIM for best security when using your custom domain.
Secure your custom domain emails with Tuta - the email service with built-in encryption.Tutanota
#Android is getting an AI-powered #scam call detection feature
Will be powered by Gemini Nano, which #Google says can be run locally and offline to process "fraudulent language and other conversation patterns typically associated with scams" and push real-time alerts during calls where detected red flags are present.
It will be opt-in, but Gemini Nano is currently only supported on Google Pixel 8 Pro and Samsung S24 series devices.
theverge.com/2024/5/14/2415621…
Android is getting an AI-powered scam call detection feature
Google is testing a new call monitoring feature that warns users if the person they’re talking to is likely attempting to scam them and encourages them to end such calls.Jess Weatherbed (The Verge)
Der Messenger #Telegram ist für eine sichere Kommunikation nicht geeignet - standardmäßig sind die Nachrichten nicht einmal Ende-zu-Ende verschlüsselt. Besser geeignet sind #Signal oder #Threema. Übrigens: Elon Musk ist das Paradebeispiel eines Trolls. Einfach ignorieren. 😉
Wer eine Entscheidungshilfe für einen Messenger sucht: messenger-matrix.de/messenger-…
#sicherheit #security #schwachstelle #e2ee #vulnerabilty #musk #durow
Messenger-Matrix • Kuketz IT-Security Blog
Gegenüberstellung sicherheits- und datenschutzrelevanter Eigenschaften von Messengernwww.messenger-matrix.de
TPM2-measured boot with bus protection is pretty nice actually for Linux installations where secure boot is not enabled, like the default Arch Linux installation for instance.
For the sake of "defence in depth", I'd enable both if it is out-of-the-box feature but would not probably bother with secure boot if it requires extra work.
So, the takeaway from this is that it would make a lot of sense to make measured boot happen in arch-install installation as opt-in feature. No Microsoft key required.
Still so far the most informative overview for the shenanigans is microos.opensuse.org/blog/2023… but I'd also look for more recent references.
Policy hash calculation per kernel package update for LUKS2 is what needs to happen over time whenever a new kernel package is installed with hooks/scripts.
So the thing that was hyped to DRM the world into a locked down hellhole rendered out the Microsoft key hard binding instead 🤷
#tpm #linux #archlinux #opensuse #secureboot #security
Systemd-boot and Full Disk Encryption with TPM and FIDO2
Systemd-boot and Full Disk Encryption in Tumbleweed and MicroOSopenSUSE MicroOS
Those changes are currently only applied to the master branch and didn't yet go to any release or distribution packages. They were supposed to fix a #security issue, but not to break some binary repos, which is what the applied patches might do. Find the originally proposed and recommended patches at github.com/obfusk/fdroid-fakes… – and also see e.g. tech.lgbt/@obfusk/112306314357… for some additional background.
Who controls the tech stack❓
When choosing a secure solution for your data, this one of the most important questions❗
Here's why: ➡️ tuta.com/blog/what-is-a-tech-s…
#security #technology #opensource #foss
What is a tech stack and how Tuta makes sure it's secure
Open Source audited technologies and self-built solutions give the Tuta team full control over their tech stack - an important factor when it comes to security.Tutanota
Important security update for GLib and D-Bus, thanks to @pwithnall
discourse.gnome.org/t/security…
If you are a downstream distributor of GLib, GTK, or GNOME-related projects, remember to follow the distributor tag on Discourse.
Security fixes for signal handling in GDBus in GLib
A series of related security fixes for how signal subscriptions are handled in GDBus have just landed in GLib.GNOME Discourse