Skip to main content

Search

Items tagged with: Security


New article: "Overview of Flatpak's Permission Models"

https://theevilskeleton.gitlab.io/2023/05/11/overview-of-flatpaks-permission-models.html

I noticed that many people criticize Flatpak's security for lacking an #Android-style permission model. This article addresses this (false) information with real-world examples.

I explain the differences between the two permission models in a manner that less technical people can understand.

Huge thanks to @orowith2os for proofreading the article :)

#Flatpak #Linux #GNU #Security #FOSS #OpenSource


Google has just updated its 2FA Authenticator app and added a much-needed feature: the ability to sync secrets across devices.

TL;DR: Don't turn it on.

The new update allows users to sign in with their Google Account and sync 2FA secrets across their iOS and Android devices.

We analyzed the network traffic when the app syncs the secrets, and it turns out the traffic is not end-to-end encrypted. As shown in the screenshots, this means that Google can see the secrets, likely even while they’re stored on their servers. There is no option to add a passphrase to protect the secrets, to make them accessible only by the user.

Why is this bad?

Every 2FA QR code contains a secret, or a seed, that’s used to generate the one-time codes. If someone else knows the secret, they can generate the same one-time codes and defeat 2FA protections. So, if there’s ever a data breach or if someone obtains access .... 🧵

#Privacy #Cybersecurity #InfoSec #2FA #Google #Security


☣️ This is why you should never trust your important information (like passwords!) to proprietary software.

#OpenSource #FreeSoftware #privacy #security #infosec

🤡 #1Password becomes #spyware:

https://blog.1password.com/privacy-preserving-app-telemetry/


In today's video, I decided to take a look at some tools and applications you can use to improve your #privacy and #security on #linux

From internet connection monitoring tools, system wide ad and tracker blockers, sandboxing tools, or permission control apps, to file shredders, and encryption, I think it should help expand your Linux toolbox, with #OpenSource tools to keep control on what your system and apps can do!

https://youtu.be/0LxUF5bcRXI


Inaudible ultrasound attack can stealthily control your phone, smart speaker


Content warning: https://gadgeteer.co.za/wp-content/uploads/2023/03/NUIT-2-400x221.jpg The team of researchers consists of professor Guenevere Chen of the University of Texas in San Antonio (UTSA), her doctoral student Qi Xia, and professor Shouhuai Xu of the University o


Send Files Securely Over The Local Network With Open Source Cross-Platform LocalSend App As An Alternative to AirDrop


Content warning: https://gadgeteer.co.za/wp-content/uploads/2023/03/localsend-receive-400x295.jpg LocalSend is a free and open source, cross-platform alternative to AirDrop for sending files securely over the local network. The Flutter app runs on Linux, Microsoft Windows


#Apple launched https://security.apple.com/ - I'd say at least two decades too late. Tells you about the importance of #security for that mega-corp.

Better very late than never.

Noticed? The page is useless until you enable full #JavaScript in your browser. Is this a security test? 🤔

#fail #Bounty

This website uses cookies to recognize revisiting and logged in users. You accept the usage of these cookies by continue browsing this website.