Search

Items tagged with: security


european-pirateparty.eu/historโ€ฆ while I always believed that "Chat Control" as it was proposed would be dead on arrival, and unenforceable, it's always great to see common sense prevail. Some win for #privacy and #security of communications. The fight is far from over though.


#XSF Announcement

Recently there was an incident via a so called #man_in_the_middle attack happened to an #XMPP #server.

To reduce the risk of such attacks in the future an early stage service called CertWatch has been published by our Community: certwatch.xmpp.net/

Many thanks to Stephen P. Weber (@singpolyma)!

Read two related blog posts:
blog.jmp.chat/b/certwatch/certโ€ฆ

snikket.org/blog/on-the-jabberโ€ฆ

#Jabber #mitm #security #vulnerability #machine_in_the_middle #chat



@shawnhooper People believe they are the hero of their own story. So they believe they can solve problems, if only they had access to the data. However, this kind of power is easy to abuse. Instead people need to consider โ€œwhat if my enemy had this power over me?โ€ Would they still believe itโ€™s a good idea? i think not. This applies equally well to software as well as the law. The best thing we could do to protect everyone is build strong encryption into everything
#security #Software



New-ish Asus routers seem to enable "Yandex.DNS" by default. This forwards all of your DNS lookups to Yandex, a large Russian search engine. I discovered this on my dad's router when he had troubles accessing his bank from his broadband but not on his phone. (Presumably, the bank geoblocked Russian IPs as a protest to the invasion of Ukraine.)

I get that you need to trust someone with your DNS lookups (your ISP, Google, Cloudfare, etc), but I didn't expect the non-ISP option to be the default...

Check your router!

#security #privacy


Some exciting news: Over the past few months I have been working on founding a new organization: Blodeuwedd Labs (@blodeuweddlabs)

We are now in a position to offer subsidized security assessments (and other services) for open source projects.

(In addition to a whole array of analysis, development, and custom research offerings for everyone else)

Announcement (and more info): blodeuweddlabs.com/news/open-sโ€ฆ

#infosec #security #appsec #canada #opensource




We're happy that #Apple has now joined the fight for encryption! ๐Ÿ”’

There is no magic key that allows the police to scan all chat messages, emails, and more for harmful content while not risking the security and privacy of everyone. This is technically not possible.

The more agree to this fact, the higher the chances that legislation is altered to protect everybody's privacy.

bbc.com/news/technology-660287โ€ฆ

#privacy #security #onlinesafetybill #chatkontrolle


Mozilla: "In a well-intentioned yet dangerous move to fight online fraud, France is on the verge of forcing browsers to create a dystopian technical capability. It would force browser providers to create the means to mandatorily block websites present on a government provided list. Such a move will overturn decades of established content moderation norms and provide a playbook for authoritarian governments"

blog.mozilla.org/netpolicy/202โ€ฆ
#france #browser #cybersecurity #mozilla #security #surveillance


If you're using #bitwarden, make sure to change the KDF algorithm to Argon2id[^1] which is much more robust against GPU-powered attacks compared to its counterpart.

You can play around with this little calculator to see the impact of each algorithm on cracking cost estimation: passwordbits.com/passphrase-crโ€ฆ

[^1]: bitwarden.com/help/what-encrypโ€ฆ

#security #infosec #password



Interesting: ProtonMail finally admits that Germany "is a good choice given Germanyโ€™s strong privacy laws and culture that make it almost as strong as Switzerland."

For once, we couldn't agree more. ๐Ÿ˜€

We'd even argue Germany is much better as we do not have data retention laws (which would be against the German constitution) - while in Switzerland large tech companies are forced by law to retain data: tutanota.com/blog/posts/data-rโ€ฆ

#germany #privacy #security


โœ… Staff able to watch customers in the bathroom?
โœ… Obviously shabby infosec?
โœ… Training AI as an excuse for data retention?

๐Ÿ•ต๐Ÿฝ No surprise here: "#Amazon Ring, Alexa accused of every nightmare #IoT #security fail you can imagine" #privacy

theregister.com/2023/06/01/ftcโ€ฆ


Earlier this year we got into a surprising and somewhat annoying struggle with Web browser sandboxing failures related to our "web apps shared in a chat" feature. After much background work we released the hardened Delta Chat 1.36 series, also addressing a dedicated fourth independent security audit, and can finally share more of what was going on behind the scenes delta.chat/en/2023-05-22-webxdโ€ฆ

#chromium #deltachat #security #webxdc


Journalists, whistleblowers, activists - they all risk their lives to make the truth public.

Let's fight for the right to #privacy and #pressfreedom.

Together with #Threema, #Tor #FightfortheFuture and others we call on policymakers to not undermine #encryption.

We ALL depend on encryption for #security and #privacy! ๐Ÿ’ช๐Ÿ”’

Read more: tutanota.com/blog/posts/press-โ€ฆ




Google has just updated its 2FA Authenticator app and added a much-needed feature: the ability to sync secrets across devices.

TL;DR: Don't turn it on.

The new update allows users to sign in with their Google Account and sync 2FA secrets across their iOS and Android devices.

We analyzed the network traffic when the app syncs the secrets, and it turns out the traffic is not end-to-end encrypted. As shown in the screenshots, this means that Google can see the secrets, likely even while theyโ€™re stored on their servers. There is no option to add a passphrase to protect the secrets, to make them accessible only by the user.

Why is this bad?

Every 2FA QR code contains a secret, or a seed, thatโ€™s used to generate the one-time codes. If someone else knows the secret, they can generate the same one-time codes and defeat 2FA protections. So, if thereโ€™s ever a data breach or if someone obtains access .... ๐Ÿงต

#Privacy #Cybersecurity #InfoSec #2FA #Google #Security




The "Report link destination" command in NVDA 2023.1 is very popular. Press NVDA+k to report exactly where a link goes. This is an important #security feature for users. Do you use it? Read more in our In-Process blog: nvaccess.org/post/in-process-6โ€ฆ #a11y #ScreenReader #NVDA


Security is the major reason why software updates are important. The LastPass breach demonstrates this dramatically.

If you search the web for why software updates are important, you will get loads of results that say there are "3 or 5 reasons why software updates are important". While this may be correct, there is only one major reason why you must keep your software up to date: Security.

Stay secure, update your systems! ๐Ÿ˜Ž๐Ÿ’ช๐Ÿ”’

tutanota.com/blog/posts/why-upโ€ฆ

#LastPass #Security




Microsoft Authenticator prompts the user to accept sharing analytics during the first launch. The prompt only dismisses when the user taps on "Accept." In fact, the app starts sending analytics even before accepting the privacy statement.๐Ÿคฆโ€โ™‚๏ธ

In this video, we downloaded the authenticator app from the App Store and we opened it as we monitored the iPhone network traffic. While the app was showing the permission prompt, we captured at least 3 calls made by the app sending diagnostics to Microsoft. The app sent 14 KB of analytics even before accepting the prompt.

The message on the prompt actually says that Microsoft needs to collect diagnostic data in order to keep Authenticator secure and up to date. ๐Ÿ˜ตโ€๐Ÿ’ซ

#Privacy #Cybersecurity #2FA #InfoSec #Security #Microsoft

youtu.be/r5456XXG6v0


Today I learned that when you "edit" or "correct" a message in #XMPP, the original message is still technically stored on the server or device. It's the client side that understands that the new message is an edit of the previous message, and "displays" it as such. But, if you send a password or something sensitive, "editing" the message after it has been sent might not remove the actual contents of the original version of the message, so make sure you use #encryption too.

#privacy #security


Portmaster, eine Art Firewall zur Kontrolle des ausgehenden Datenverkehrs, ist nicht mehr Alpha, sondern in der Version 1.0.7 fรผr Windows, Debian/Ubuntu und Fedora verfรผgbar. Gerade fรผr Windows-Nutzer interessant, die Microsofts Schnรผffelei eindรคmmen wollen.

safing.io/

#security #privacy #firewall #sicherheit #datenschutz #windows




Have you heard about #ReproducibleBuilds? This is one of the biggest #security benefits of #FOSS. On #Android, this technique ensures that the #FDroid version of an app exactly matches the developer's version.

Read our article below for more details and to see how easy it is for developers to get set up:
f-droid.org/en/2023/01/15/towaโ€ฆ


I've asked it in a poll in 8/2021 at Mastodon.technology, now it's time for a refresher: To improve #security I finally consider to really drop support for #TLS 1.0/1.1 (see blog.qualys.com/product-tech/2โ€ฆ and e.g. ssllabs.com/ssltest/analyze.htโ€ฆ). This basically would affect devices running Android < 4.4. As I do not want to lock anybody out, I'd like to see how many of you would this effect.

๐Ÿ‡ฉ๐Ÿ‡ช Noch wer mit Android < 4.4 unterwegs und somit auf TLS 1.0/1.1 angewiesen (1. ja, 2. macht nix, 3. nein)?

So:

  • I still use such a device and need compatibility (1%, 4 votes)
  • I still use such a device but wouldn't mind (6%, 21 votes)
  • I don't care (92%, 320 votes)
345 voters. Poll end: 3 years ago


Do you like security? Do you like privacy? Cryptography? Do you like working for a public benefit non-profit instead of an investor-beholden corporation?

Let's Encrypt is hiring for someone to join our SRE team and help run the largest Certificate Authority in the world! Come work with me and some of the most wonderful folks in tech, to make the web a better place.

abetterinternet.org/careers/leโ€ฆ

#jobs #sre #webPKI #security #privacy #cryptography


What do you value the most in your devices?
Privacy, Security and/or Freedom?

At #CES2023, the biggest #tech event, we are asking people their thoughts about where they stand when it comes to #privacy, #security and #freedom when it comes to their #laptops, #phones, IoT devices

#ces

โ‡ง