Ooof.
SAT company caught not understanding tracking pixels, and the privacy ramifications thereof.
https://gizmodo.com/sat-college-board-tells-facebook-tiktok-your-scores-gpa-1850768077
This is too much for me to read right now, but looks interesting.
NIST's take on AI and how to secure it.
#Lastpass Hack mitigation:
If you're a Lastpass user, even if you're planning on leaving, it'll take some time to do so.
1. Enable MFA, preferably a good one like hardware keys or authenticator apps.
2. Lock down LastPass access to only the countries you expect to be in in the near term. You can do this through the web advanced settings tab.
3. Prohibit access from tor networks unless you're typically using them.
4. Increase your 'password iterations' value to something OVER 600,000.
#cososec
This is bad.... Not the end of the world bad, but still bad. The attacker still needs to figure out individual master passwords to get your encrypted site passwords, but they have everything else.
Now to convince my wife to change /everything/ to onePassword.
I've been noticing several attempted charges of 88¢ against my privacy.com cards.
I'm glad it exists for any site that seems sketchy or any time I have to verbally give a CC number.
But stay vigilant. A small charge could be a probe charge or it could be there just to drain a little money from lots of people, hoping that small charges would go undetected.
It's cybersecurity awareness month.
I don't have much to pay right now, but go through the #cososec and #securityhygiene tags.
Remember: Cyber Safely 😜
The intersection of #cososec, #cosoparents, and #education
The seesaw app was hacked via credential stuffing and was used to send explicit images to other users.
Don't.
Reuse.
Passwords!
OWASP Global App Sec will be in San Fran this year.
If you code, test, or hack anything web-based, it's a good place to learn and meet others.
https://www.bbc.com/news/world-asia-61921222
So much wrong here.
Let's dissect it.
a) a culture where taking work home is acceptable
b) taking other people's data home
c) stopping at a someplace other than home while in the possession of other people's data
d) getting pass-out drunk while in the possession of other people's data
Don't be this person.
"We take your security and privacy very seriously." = "We don't snicker when we're caught mishandling your financial information."