Show more

ProTip: when upgrading your yubikey or similar device, make sure you go through *every* account.

I was locked out of my work password manager for 2 days because I forgot that account.


Capital One breach response.

THERE WERE NO SSN'S IN THE BREACH
except about 200,000

BUT THERE WERE NO BANK ACCOUNT NUMBERS IN THE BREACH
except around 100,000

BUT IT WAS ALL ENCRYPTED
except some of it


How not to do breach response

members:

OWASP just announced their conference line up.

It'll be in DC in September

dc.globalappsec.org/program/sc

FFS. He doesn't get it does he. Once an encryption backdoor is opened, it cannot be closed. A bad actor will just walk right through that very same day.

I get it. Encryption can help the bad guys. But there are mitigation techniques, albeit difficult, manpower-expensive ones, around that. Once encryption is broken, it leaves *every* *single* *person* in the world open to attack. What's that saying ... "good ... bad ... ratio ... and act accordingly"

techcrunch.com/2019/07/23/will

This may not be all that understandable to the average netizen... but this is kinda disturbing to me.

If Googlebot is susceptible to XSS which could allow SEO stuffing, then Google results can't always be trusted. (seriously, no snark here... google *is* the top SE after all.)

tomanthony.co.uk/blog/xss-atta

Ever try to get around a paywall in incognito mode only to see "Sorry, you can't view this in private mode."?

Chrome is about to close that loophole.

gizmodo.com/google-chrome-upda

With all the ransomware out there, remember: your second (and perhaps final) line of defence is to
do backups to _non-connected_ media.

Well, this is disturbing.

4 watts of power, 4 fake LTE "towers" some special software, a densely crowded area, and a well crafted fake "Presidential Emergency Message" and you now have a recipe for localized chaos.

hackread.com/researchers-explo

"The fact that American corporations are mimicking the actions of an authoritarian government to score and treat consumers differently is disturbing"

gizmodo.com/the-surveillance-s

Still think if you don't do anything wrong you have nothing to hide?

I think most people here know better, but remind those less technical. Don't click on ads claiming to speed up, clean, or otherwise "fix" your computer.

infosecurity-magazine.com/news

/

Show more

<invalid character>

CounterSocial is the first Social Network Platform to take a zero-tolerance stance to hostile nations, bot accounts and trolls who are weaponizing OUR social media platforms and freedoms to engage in influence operations against us. And we're here to counter it.