Search
Items tagged with: Security
Tons of Gigabyte motherboards come with a hidden firmware backdoor https://www.pcworld.com/article/1937046/gigabyte-shipped-hundreds-of-motherboard-models-with-a-firmware-backdoor.html
#Gigabyte #Motherboards #Hardware #PC #Firmware #Backdoor #Security #InfoSec #TechNews
Tons of Gigabyte motherboards come with a hidden firmware backdoor
Gigabyte's motherboard backdoor installs software updates from unsecured web servers.Michael Crider (PCWorld)
https://theevilskeleton.gitlab.io/2023/05/11/overview-of-flatpaks-permission-models.html
I noticed that many people criticize Flatpak's security for lacking an #Android-style permission model. This article addresses this (false) information with real-world examples.
I explain the differences between the two permission models in a manner that less technical people can understand.
Huge thanks to @orowith2os for proofreading the article :)
#Flatpak #Linux #GNU #Security #FOSS #OpenSource
Overview of Flatpak’s Permission Models
Flatpak’s permissions can be confusing. Some are technical and need knowledge on how they work, and others are self-explanatory.TheEvilSkeleton
TL;DR: Don't turn it on.
The new update allows users to sign in with their Google Account and sync 2FA secrets across their iOS and Android devices.
We analyzed the network traffic when the app syncs the secrets, and it turns out the traffic is not end-to-end encrypted. As shown in the screenshots, this means that Google can see the secrets, likely even while they’re stored on their servers. There is no option to add a passphrase to protect the secrets, to make them accessible only by the user.
Why is this bad?
Every 2FA QR code contains a secret, or a seed, that’s used to generate the one-time codes. If someone else knows the secret, they can generate the same one-time codes and defeat 2FA protections. So, if there’s ever a data breach or if someone obtains access .... 🧵
#Privacy #Cybersecurity #InfoSec #2FA #Google #Security
#OpenSource #FreeSoftware #privacy #security #infosec
🤡 #1Password becomes #spyware:
https://blog.1password.com/privacy-preserving-app-telemetry/
We're changing how we discover and prioritize improvements | 1Password
Learn about a new, privacy-preserving in-app telemetry system that 1Password is trialing with its employees.1Password
From internet connection monitoring tools, system wide ad and tracker blockers, sandboxing tools, or permission control apps, to file shredders, and encryption, I think it should help expand your Linux toolbox, with #OpenSource tools to keep control on what your system and apps can do!
https://youtu.be/0LxUF5bcRXI
APPS & TOOLS to improve LINUX PRIVACY & SECURITY
Get 100$ credit for your own Linux and gaming server: https://www.linode.com/linuxexperiment Grab a brand new laptop or desktop running Linux: https://www.tu...YouTube
NVIDIA release details of security issues and release new drivers
NVIDIA issued a new Security Bulletin, to advise you to update your GPU drivers due to multiple security issues discovered.Liam Dawe (GamingOnLinux)
Inaudible ultrasound attack can stealthily control your phone, smart speaker
Content warning: https://gadgeteer.co.za/wp-content/uploads/2023/03/NUIT-2-400x221.jpg The team of researchers consists of professor Guenevere Chen of the University of Texas in San Antonio (UTSA), her doctoral student Qi Xia, and professor Shouhuai Xu of the University o
Send Files Securely Over The Local Network With Open Source Cross-Platform LocalSend App As An Alternative to AirDrop
Content warning: https://gadgeteer.co.za/wp-content/uploads/2023/03/localsend-receive-400x295.jpg LocalSend is a free and open source, cross-platform alternative to AirDrop for sending files securely over the local network. The Flutter app runs on Linux, Microsoft Windows
#dictatorship #apple can't be trusted, apple is member of the #GAFAM #data #surveillance super #spy club.
The ultimate tool for #protests, #demonstrations, #advocacy, #democracy, #unions, #HumanRights workers, #journalists, or anyone looking for #privacy, #security, #anonymity is #Session #Messenger from https://getsession.org.
It's #decentralised (difficult to shut down or block), onion routed random #servers in random #countries (3-hops, IP #obfuscated), end2end #encrypted (#e2ee), #OpenSource, #anonymous (no personal info to register, no #phone, no #email), #disposalable IDs, blinded (#alias IDs), self deleting msgs, #community groups, #private groups, soon 3-hop encrypted #audio #video. Practically zero #metadata.
https://getsession.org
#getsession #foss #tech #news #IM #whatsapp #facebook #telegram #imessage #iphone #iOS #android #Linux #windows #mobile #macOS
Better very late than never.
Noticed? The page is useless until you enable full #JavaScript in your browser. Is this a security test? 🤔
#fail #Bounty