Search
Items tagged with: Security
Important security update for GLib and D-Bus, thanks to @pwithnall
discourse.gnome.org/t/security…
If you are a downstream distributor of GLib, GTK, or GNOME-related projects, remember to follow the distributor tag on Discourse.
Security fixes for signal handling in GDBus in GLib
A series of related security fixes for how signal subscriptions are handled in GDBus have just landed in GLib.GNOME Discourse
This #Debian wiki page was what I found that helped me get fingerprint authentication set up on my laptop.
So I contributed something back. I added the "Caveats" section at the bottom. Hopefully this helps somebody else, 🙂
Veilig communiceren met én binnen de overheid. Hoe werkt dat? Dit kan alleen wanneer er volledige zekerheid is over de afzender, de inhoud en de vertrouwelijkheid van het bericht. PKIoverheid zorgt daarvoor. Check de video! 👇
#DigitaleOverheid #DigitaleInclusie #Toegankelijkheid #Security
New bookmark: ActivityPub on a (mostly) static website.
There have been other attempts to document the process of bringing ActivityPub to a (mostly) static site, but this is my favorite so far. I wonder if I should give it a go, if POSSE ever stops serving my needs.
Originally posted on seirdy.one
: See Original (POSSE). #IndieWeb #Security #Web
Accrescent 0.20.0 is out with support for respecting other app stores, UI improvements, bug fixes and more!
Download Accrescent or view the changelog below for details.
github.com/accrescent/accresce…
#accrescent #android #security #privacy #appstore
Release 0.20.0 · accrescent/accrescent
A more substantial release this time around! Accrescent now respects other app stores and manual APK installations, no longer attempting to take over updates for apps you installed outside of Accre...GitHub
Should you have noticed a short "absence" of the #IzzyOnDroid primary web server, that was probably the reboot…
A CVE was published to oss-sec 5 days ago and got its fixes available today (security-tracker.debian.org/tr…), so it was applied immediately as the vuln would have affected some components here.
My thanks here once more goes to @obfusk for bringing it to my attention – and to my service provider who swiftly applied the updates within just minutes 🤩
techradar.com/pro/the-united-n…
#security #encryption #element #matrix #UN #IT #decentralized #federated
The United Nations ditches Big Tech in a bid for security
UNICC has chosen Element to secure its communicationsChiara Castro (TechRadar pro)
Another #security patch has been applied at the #IzzyOnDroid #IzzySoftRepo to protect against what is described at openwall.com/lists/oss-securit…
Though a full scan of the repo hasn't brought up a single affected APK, that doesn't mean any such cannot show up later – so better safe than sorry, right?
If you use brew’s curl on macOS, are you really using it? I installed and had curl setup a couple of years ago. Today it appears that curl was now pointing to Apple’s version, which has this issue (daniel.haxx.se/blog/2024/03/08…). Looks like brew doesn’t add a symlink for curl to /opt/homebrew/bin. Running `ln -s /opt/homebrew/opt/curl/bin/curl /opt/homebrew/bin` resolved the issue.
T-Mobile Employees Across The Country Receive Cash Offers To Illegally Swap SIMs
I still stand by this: if #sms #mfa wasn’t still massively used (especially by the financial sector), sim swaps would be less attractive to sim swappers.
It’s also crazy so much trust is placed in telecoms guarding your phone number and MFA factor for your bank. 🫨
#security #cybersecurity #simswap
tmo.report/2024/04/t-mobile-em…
T-Mobile Employees Across The Country Receive Cash Offers To Illegally Swap SIMs
T-Mobile employees, both third-party and corporate, are receiving cash offers via text to complete SIM swaps for criminals.Jman100 (The Mobile Report)
#curl sometimes fails to access some servers. In most situations the problem is not in curl itself but on the server side. Example:
1. Fails: curl radissonhotels.com
2. Works: curl -A 'Mozilla/5.0 xx Chrome/119' radissonhotels.com
3. Fails: curl -A 'Mozilla/5.0 xx Chrome/118' radissonhotels.com
4. Fails, too: curl -A 'Mozilla/5.0 xx Chrome/1189' radissonhotels.com
Perhaps they perform #filtering to obtain improved #security? It's hard to tell, but any serious attacker surely knows how to spoof the user agent string and bypass such simple #regex
Security Bits by @bart — 14 April 2024 podfeet.com/blog/2024/04/sb-20…
Security Bits — 14 April 2024 - Podfeet Podcasts
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time.Bart Busschots (Podfeet Podcasts)
Time for another release... Accrescent 0.19.0 is out! While not much has changed on the surface, Accrescent now uses our new server infrastructure which brings faster downloads to everyone!
Read the release notes or download below 👇
github.com/accrescent/accresce…
#accrescent #security #privacy #appstore #android
Release 0.19.0 · accrescent/accrescent
This release marks the migration of Accrescent's servers to a more scalable setup. From this version on, Accrescent will connect to the new servers. Earlier versions of Accrescent will automaticall...GitHub
Hey! Let's talk about #SSH and #security!
If you've ever looked at SSH server logs you know what I'm about to say: Any SSH server connected to the public Internet is getting bombarded by constant attempts to log in. Not just a few of them. A *lot* of them. Sometimes even dozens per second. And this problem is not going away; it is, in fact, getting worse. And attackers' behavior is changing.
The graph attached to this post shows the number of attempted SSH logins per day to one of @cloudlab s clusters over a four-year period. It peaks at about 3.4 million login attempts per day.
This is part of a study we did on our production system, using logs of more than 640 million login attempts, covering more than 1,500 hosts on our side and observing more than 840 thousand incoming IP addresses.
A paper presenting our analysis and a new, highly effective means to block SSH brute force attacks ("Where The Wild Things Are: Brute-Force SSH Attacks In The Wild And How To Stop Them") will be presented next week at #NSDI24 by @sachindhke . The full paper is at flux.utah.edu/paper/singh-nsdi…
Let's dive in. 🧵
2 days ago I reported about a #security patch having been applied to the IzzyOnDroid F-Droid repo aka #IzzySoftRepo – but I didn't give much details. After it was tested now at the IoD test & staging area, and running smoothly for two days for the public one, I reported back to its author @obfusk that all seems smooth, and she decided to make POC & patch public. You can find the full details at github.com/obfusk/fdroid-fakes… & openwall.com/lists/oss-securit… now. @fdroidorg @eighthave be welcome using it!
1/2
GitHub - obfusk/fdroid-fakesigner-poc: F-Droid Fake Signer PoC
F-Droid Fake Signer PoC. Contribute to obfusk/fdroid-fakesigner-poc development by creating an account on GitHub.GitHub
FreeBSD Foundation and Digital Security by Design (DSbD)
<globenewswire.com/news-release…>
❝… CHERI and CheriBSD, developed to revolutionize hardware-based protection against memory safety vulnerabilities, were developed by a collaboration from researchers from the University of Cambridge, alongside corporate partners such as Google, Microsoft, Arm, and SRI International, and with support from the UK government. …❞
FreeBSD Foundation and Digital Security by Design (DSbD) Announce Beacon Award Winners for Innovations and Improvements to CheriBSD
Winning Projects Highlight CheriBSD's Role in Advancing Digital Security...FreeBSD Foundation
I am getting tired of reading about the #xz #security issue as if it is all about issues within #opensource. It is much bigger than that, and those takes conflate the problem with the solution.
So I wrote "The xz issue isn't about Open Source" here: changelog.complete.org/archive…
The xz Issue Isn’t About Open Source
You’ve probably heard of the recent backdoor in xz. There have been a lot of takes on this, most of them boiling down to some version of: The problem here is with Open Source Software. I want…The Changelog
theregister.com/2024/03/28/ai_…
#security #AI #MachineLearning
AI hallucinates software packages and devs download them – even if potentially poisoned with malware
Simply look out for libraries imagined by ML and make them real, with actual malicious code. No wait, don't do thatThomas Claburn (The Register)
boehs.org/node/everything-i-kn…
I have begun a post explaining this situation in a more detailed writeup. This is updating in realtime, and there is a lot still missing.
Everything I know about the XZ backdoor
Please note: This is being updated in real time. The intent is to make sense of lots of simultaneous discoveriesboehs.org
Unfolding now: news.ycombinator.com/item?id=3…
- openwall.com/lists/oss-securit…
- github.com/tukaani-project/xz/…
An incredibly technically complex #backdoor in xz (potentially also in libarchive and elsewhere) was just discovered. This backdoor has been quietly implemented over years, with the assistance of a wide array of subtly interconnected accounts:
- github.com/tukaani-project/xz/…
- bugs.debian.org/cgi-bin/bugrep…
- github.com/jamespfennell/xz/pu…
The timeline on this is going to take so long to unravel
feat: update vendored xz to 5.6.1 by jaredallard · Pull Request #2 · jamespfennell/xz
Updates the vendored version of xz to be 5.6.1. Also updates the vendor script to support the addition of SPDX-License-Identifier headers into some files.GitHub
🚨 ⚠️ Emergency PSA: A critical security exploit was discovered in the xz package recently, used for compression and decompression on nearly all Linux distributions.
Rawhide users ARE impacted and should immediately STOP using Rawhide until the package update is fully rolled back. (1/3)
Security Advisory: redhat.com/en/blog/urgent-secu…
#Fedora #Linux #OpenSource #Security #Privacy
Urgent security alert for Fedora Linux 40 and Fedora Rawhide users
Red Hat Information Risk and Security and Red Hat Product Security learned that the latest versions of the “xz” tools and libraries contain malicious code that appears to be intended to allow unauthorized access., (Red Hat)
New bookmark: Firefox bug 1886557: Make JIT Spraying implausible.
This could be the biggest leap forward in years when it comes to SpiderMonkey catching up to V8 and JSC’s JIT hardening. So far, I’ve been telling security-conscious Firefox users to disable the JIT compiler, and to use Chromium when JIT is necessary; maybe I won’t have to in a few years’ time.
Originally posted on seirdy.one
: See Original (POSSE). #browsers #firefox #security
🇩🇪 Ich habe ja schon erwähnt, dass im Januar für das #IzzySoftRepo zusätzliche APK-Checks implementiert wurden. Jetzt habe ich es endlich geschafft, auch den zugehörigen Blog-Artikel fertig zu stellen.
Vielleicht interessiert es Euch ja, einen Blick auf Details und Hintergründe zu werfen? Ihr finden den Artikel "Zusätzliche APK-Checks im IzzyOnDroid Repo" hier:
android.izzysoft.de/articles/n…
Zusätzliche APK-Checks im IzzyOnDroid Repo
Nachdem der Library-Scanner nun seit mehreren Jahren im IzzyOnDroid Repo im Einsatz ist war es an der Zeit, einige zusätzliche APK-Prüfungen zu etablieren.IzzyOnDroid
🇺🇸 I've told you about additional APK checks having been implemented at the #IzzySoftRepo in January. Now finally I found the time to complete the article explaining the details, so you might wish to take a look at "Ramping up security: additional APK checks are in place with the IzzyOnDroid repo":
android.izzysoft.de/articles/n…
Edit: Tags:
Ramping up security: additional APK checks are in place with the IzzyOnDroid repo
With the library scanner in place for multiple years, it was about time to establish some additional APK checks with the IzzyOnDroid F-Droid repository.IzzyOnDroid
Все страницы сайта Habr.ru (локальная копия)
по следующим темам:
[VPN]
[Proxy][proxy-server]
[Mesh]
[i2p]
[i2pd]
[cloak]
[P2P]
[TOR]
[OpenVPN]
[XraY]
[V2rayNG]
[I2raY]
[V2rayXS]
[V2rayN]
[Yggdrasil]
[ValdikSS]Возможно, вам это будет интересно.
Я нашел эти ссылки в интернете.
В связи с намерениями правительства удалить всю информацию по обходу блокировок из российского сегмента интернета, кто-то, решил принять меры. 🙂
ОН, судя по всему считает, что статьи это важная часть культуры и нашего прошлого.
Особенно, комментарии больших групп образованных людей на habrahabr.ru.
Этот человек, скорее всего считает важным сохранять и распространять полезную информацию.
А так же, делиться мнениями других людей, т.к. это развивает и помогает обществу рости в лучшую сторону.
Не смотря на мои предположения, для меня остается загадкой мотивация этой неизвестной личности.
Но я разделяю некоторые идеи, в плане того, что знаниями нужно делиться.
Мне всегда становится грустно, когда я обнаруживаю умерший сайт,
или удаленную страницу и потерянную информацию.
Поэтому, делюсь этими ссылками с вами.
А вы, можете поделиться с другими.
(будет что почитать, если интернет совсем кончится)
К тому же, 14 марта на хабре вышла статья
"Надежный обход блокировок в 2024 протоколы,
клиенты и настройка сервера от простого к сложному"
под которой один человек предложил сохранить статьи по обходу блокировок.
(эта статья сохранена в этом сборнике)
UPD1: "Статья уже была удалена. Но доступна если искать из другой страны."
UPD2: Сейчас, автор статей по "актуальному обходу блокировок MiraclePtr" - удален((
Учитывая времена, думаю стоит сохранить все локально, потому что не известно,
какие именно категории данных будут удаляться в будущем.
И нет надежды, что веб архив не будет заблокирован.
Да и не понятно, как сильно все изменится со временем.
Страниц в папках всего: 2223 или 11.5Gb
1) Видео о содержимом 13Mb можно по этой ссылке:
mega.nz/file/cLMUHSAT#PHjc7WfT…
2) Скачать архивом .7z - 3.3Gb (сжат):
mega.nz/file/hf8xSbiI#3DrGc3P2…
3) Скачать отдельные папки 11.5Gb:
mega.nz/folder/9TVGgZjL#pGAidX…
4) Копия архива .7z - 3.3Gb:
fileconvoy.com/dfl.php?id=gee7…
5) Ссылка на репозиторий, если кому-то удобней скачивать так:
codeberg.org/hrabr/Habr.git
О содержимом.
Судя по ссылкам в страницах, они были сохранены с середины марта 2024.
Информация собрана по темам (список вверху) и все рассортировано по папкам.
Сохранены практически все страницы (за исключением откровенно рекламных статей).
Возможно вы встретите небольшое количество дублей, т.к. темы пересекаются.
(так же, встречаются одинаковые статьи опубликованные в разное время, но имеющие разные комментарии)
Возможна какая-то информация вам будет не интересна.
Есть страницы с устаревшей информацией (с 2008 года).
Они и комментарии из этих статей сохранены для истории.
В архиве есть index.html, через который можно искать статьи по ключевым словам через Ctrl+F.
Так же, под этим сообщением есть скриншеты и видео о структуре.
Если у вас в закладках, есть страницы с инструкциями для построения защищенных сетей,
или что-то, что вы считает полезными и это может быть потеряно,
добавляйте ссылки под этим постом, с описанием.
Может быть, ваша информация будет кому-то полезна.
Страницы были сохранены через невероятное дополнение: SingleFile
Если кто-то захочет оформить раздачу на rutracker,
то этот человек очень поможет нашему большому обществу,
когда страницы будут удалены с хабра (я считаю, это вопрос времени).
Как это уже произошло со страницами сайта 4pda.to.
Хочу сказать спасибо MiraclePtr за чудесные статьи и отдельное спасибо UranusExplorer за простые инструкции.
А так же, всему Хабр-сообществу, которое десятилетиями писало статьи и делилось своим мнением в комментариях.
#хабр #обходблокировок
#habr #pages #backup #cloak #i2p
#xray #nekobox #v2ray #v2rayn
#v2rayxs #v2rayng #i2ray #git
#amnezia #outline #shadowsocks
#vpn #proxy #server #mesh #p2p
#roskomnadzor #valdikss #network
#internet #dns #ssl #wireguard
#ikev2 #ipsec #l2tp #mikrotik
#linux #unix #mozilla #softether
#softethervpn #openvpn #peervpn
#pptp #security #ssh #openbsd
#ubuntu #debian #router #firewall
#private #http #https #openxray
#tor #info #articles #p2panda
#yggdrasil #habr #habrahabr #i2pd
#telegram #mega #rutracker #4pda
#блокировки
@Revertron - тут куча твоих комментов и статьи есть, поэтому решил упомянуть тебя.
Пожалуйста, поделитесь этой информацией с друзьями. 💗
Если у вас есть идея куда еще можно залить эти статьи, предлагайте.
Habr
A copy of articles and comments from https://habr.ru, for the sake of history. Please share this information with your friends. Peace and love.Codeberg.org
nitrokey.com/products/nethsm
#HSM #OpenSource #OpenHardware #Security
At long last, a blog update... on updates? Check out this article on Accrescent's progress toward delta updates with conceptual explanations, benchmarks, and lots of pretty graphs!
lberrymage.dev/posts/ina-part-…
#android #accrescent #security
Ina, Part 1: Smaller, faster, and safer software updates for Accrescent
Introduction Well! It’s been a long time since I’ve shared an Accrescent update here (most development discussion takes place in our Matrix rooms), but today I have a big one: we’ve made significant progress in developing delta updates! “That sounds …Logan Magee (Logan's Blog)
Accrescent 0.18.0 released! This is a minor one with removed privileged installer support and maintenance updates. Changelog below.
github.com/accrescent/accresce…
#accrescent #privacy #security #android #appstore
Release 0.18.0 · accrescent/accrescent
This release removes privileged installer support, as it is not currently necessary for any functionality. Removals Remove privileged installer support Updates Bump AGP to 8.3.1 Bump Coli to 2.6...GitHub
It's 2024 and #Google is now requiring bulk #email senders to use DMARC, SPF, & DKIM when emailing #Gmail users. 👍
👉 tuta.com/blog/google-introduci…
This is a great step, BUT why did they allow bulk senders to send #spam emails without proper #security standards until now? 🤔
Google introduces new security requirements for bulk email senders - but should have done so years ago.
Google and Yahoo! will require the use of DMARC, SPF, and DKIM in an attempt to crackdown on spam and phishing. It is surprising that these features were not already a requirement.Tutanota
Privacy can be powerful. The Librem 14 is the first ultra-portable laptop for the security-conscious- designed chip-by-chip, line-by-line, to respect your rights to privacy, security, and freedom.
Order yours now! https://puri.sm/products/librem-14/… #security #privacy #laptops
Today we are proud to announce the launch of the world's first #postquantum secure email platform! 🥳🎉
With TutaCrypt your data is safe against quantum computer attacks at rest & in transit. ⚛️ 🔒
Learn more about this quantum leap in #security here: tuta.com/blog/post-quantum-cry…
Post Quantum Cryptography: Why We Need Resistant Encryption NOW.
Quantum-resistant or post-quantum cryptography is our best bet against attacks from upcoming quantum computers to increase security and privacy.Tutanota
the #Apple #curl #security incident 12604 - or why CA cert verification is unreliable with curl on apple OS
daniel.haxx.se/blog/2024/03/08…
LLVM CFI and Cross-Language LLVM CFI Support for Rust, bughunters.google.com/blog/480….
> add LLVM CFI and cross-language LLVM CFI (and LLVM KCFI and cross-language LLVM KCFI) to the Rust compiler as part of our work in the Rust Exploit Mitigations Project Group. This is the first cross-language, fine-grained, forward-edge control flow protection implementation for mixed-language binaries that we know of.
Really interesting project.
#RustLang #llvm #security #safety #ffi
Blog: LLVM CFI and Cross-Language LLVM CFI Support for Rust
We’re pleased to share that we’ve worked with the Rust community to add LLVM CFI and cross-language LLVM CFI (and LLVM KCFI and cross-language LLVM KCFI) to the Rust compiler as part of our work in the Rust Exploit Mitigations Project Group.bughunters.google.com
Sometimes finding perfect #search results can be a pain and Google buying dominance doesn't help. 🔎
👉 tuta.com/blog/google-search-mo…
Not all search engines offer the same performance, #security, and #privacy! 🤔
Which search engine is your favorite? Let us know in the comments!
Google Pays 1150 Times More for Its Search Monopoly Than for Lobbying in the EU & US
Break the Google Search monopoly! Your data is worth billions, take back control!Tutanota
- DuckDuckGo (64%, 265 votes)
- Ecosia (7%, 30 votes)
- StartPage (21%, 90 votes)
- Qwant (6%, 27 votes)
Just a bit of a ramble on #android and #apple and #privacy and #security inspired by a recent post by @beardedtechguy.
It's a bit of a ranty post, but not trying to be mean
This is day 19 of #100DaysToOffload
joelchrono.xyz/blog/apple-andr…
Apple vs Android on Security and Features
This post by Kyle triggered me a little bit, so I wrote a response with my opinion on the matterjoelchrono.xyz
Protecting your #privacy starts with threat modeling.
By accurately accessing your online #security threats & potential weaknesses, you can better protect your #digital life.
You are one of kind & so is your threat model. You can learn more here: tuta.com/blog/threat-modeling-…
Threat Modeling In 2024: Your Guide For Better Security
Threat model best practices to evaluate your personal cybersecurity and privacy threat landscape.Tutanota
#Nevada aims to stop minors from using end-to-end #encryption to protect their data. 🚫
Stand up for encryption & #privacy! ✊
This isn't protecting the youth, it's #victimblaming at its finest.
We must stop NV Attorney General Aaron Ford from undermining basic #security practices!
👉 tuta.com/blog/nevada-blocks-en…
Nevada Courts Want To Prevent Teens From Using End-to-End Encryption
Stripping teens of their right to strong encryption will not leave them safer or better protected from harm.Tutanota