Skip to main content

Search

Items tagged with: security


Couldn't be me, though

Ransomware attack leaks nearly every Maine resident's data - Desk Chair Analysts

https://dcanalysts.net/ransomware-attack-leaks-nearly-every-maine-residents-data/

#InfoSec #Maine #MOVEit #Ransomware #Security #TechNews


Security researcher Gergely Kalman has published a technical write-up on BatSignal (CVE-2022-26704), an unprivileged user to root elevation of privilege vulnerability in macOS.

https://gergelykalman.com/no-CVE-batsignal-a-macos-lpe.html #infosec #cybersecurity #security #apple #macos #vulnerability


On my desktop #Firefox, 99% of those malicious requests are blocked. On my mobile Firefox 97%.

Does your browser protect you and your data? Test yourself:
https://d3ward.github.io/toolz/adblock.html

#privacy #security #adblocker #malware


On the #CyberResilienceAct #CRA the @fsfe has already proposed a solution that will lead to more #security while safeguarding #FreeSoftware (#OpenSource):

* Liability should be shifted to those *deploying* Free Software instead of those *developing* Free Software and

* Those who significantly financially benefit from this deployment should make sure the software becomes CE-compliant

https://fsfe.org/news/2023/news-20230719-01.en.html


Get ready; Google Adsense, which is used by the majority of websites out there, is introducing a beta feature called Offerwall (Ad gate). https://support.google.com/adsense/answer/11913007 Once the threshold of 4 page views has been reached for any given user, the ad gate will appear everywhere. How generous of them and the website operators? Currently, this is optional, but it may become a permanent feature unless you turn off the ad blocker. #privacy #security


New article: "Overview of Flatpak's Permission Models"

https://theevilskeleton.gitlab.io/2023/05/11/overview-of-flatpaks-permission-models.html

I noticed that many people criticize Flatpak's security for lacking an #Android-style permission model. This article addresses this (false) information with real-world examples.

I explain the differences between the two permission models in a manner that less technical people can understand.

Huge thanks to @orowith2os for proofreading the article :)

#Flatpak #Linux #GNU #Security #FOSS #OpenSource


Google has just updated its 2FA Authenticator app and added a much-needed feature: the ability to sync secrets across devices.

TL;DR: Don't turn it on.

The new update allows users to sign in with their Google Account and sync 2FA secrets across their iOS and Android devices.

We analyzed the network traffic when the app syncs the secrets, and it turns out the traffic is not end-to-end encrypted. As shown in the screenshots, this means that Google can see the secrets, likely even while they’re stored on their servers. There is no option to add a passphrase to protect the secrets, to make them accessible only by the user.

Why is this bad?

Every 2FA QR code contains a secret, or a seed, that’s used to generate the one-time codes. If someone else knows the secret, they can generate the same one-time codes and defeat 2FA protections. So, if there’s ever a data breach or if someone obtains access .... 🧵

#Privacy #Cybersecurity #InfoSec #2FA #Google #Security

This website uses cookies to recognize revisiting and logged in users. You accept the usage of these cookies by continue browsing this website.