Show more

Another 0 day presents another opportunity to remind everybody:

*don't trust WiFi you don't control*

Whitehats have been able to grab "deleted" photos off an iPhone which connected to a WiFi point under their control. Other pieces of info are on the table to, but photos were the first things they could get to.

engadget.com/2018/11/15/iphone

sorry if this has already been posted.

🇺🇸 US 'nauts - Sign up for the USPS informed delivery before crooks do it for you.

ID thieves are signing up for this service on your behalf to sign up for credit cards in your name and then using it to find out when to grab the new card out of your mailbox.

csoonline.com/article/3319640/

I know @White_Rabbit and i differed on opinions on this subject. Personally I thought the repudiation was a difficult hurdle, and a potential attachment vector itself, he thought that it was rapidly becoming the only deterrent. (He's not wrong there)

theatlantic.com/business/archi

Healthcare.gov breach

Data exposed may have included Social Security numbers and a variety of other personal information, such as income, tax filing status, family relationships, and immigration status.

gizmodo.com/healthcare-gov-bre

Make sure you only enable browser extensions you fully trust.

At least 81k users private messages were stolen using a malicious plugin, and then sold for 10¢ a piece.

gizmodo.com/a-browser-extensio

🇪🇺 🇭🇺 🇬🇷 🇱🇻
"Hey, guys, I got an idea. This whole AI thing is taking off. Lets see if we can use it to see if people are lying when they're crossing the boarder!"

"Hmm, I see no problems with this"

gizmodo.com/an-ai-lie-detector

Mac forums data breach.

326k records records breached in 2016 that included usernames, IP and email addresses, dates of birth and passwords stored as salted MD5s.

twitter.com/haveibeenpwned/sta

This article starts off one way (warning conservatives about scam PACs), but reading into it, I found something I never knew before.

Apparently to become a PAC, you just have to register, and then give *some* money to a candidate, doesn't matter how much, or what percent.

Scam PACs are a thing, they take donations and then put 99.99% of those donations into "operating costs" or "administration salaries"

workplacetablet.com/2018/10/29

This is an example of "in the wild" phishing based on people's need to help others. The info-graphic at the bottom is a good refresher for those not living and breathing this stuff every day.

go.newsfusion.com//cloud-compu

This looks to be an interesting product. Over-all it's fairly expensive for an email server, but for the less-technical, but still privacy minded folk, it may be a solution.

theverge.com/circuitbreaker/20

This is still unconfirmed but Brian Krebs is reporting that some people are gaining access Experian's credit freeze PINs without authorization.

twitter.com/briankrebs/status/

(screenshot because link eventually goes to FB)

Good news, guys! California just fixed the Russian bot problem for us!

They now have to tell us they are bots before they attempt to influence.

nbcnews.com/tech/tech-news/can

Facebook security tokens abused.

Facebook really doesn't care about your privacy that much, so they are downplaying it by saying *only* 50 million people impacted.

threatbrief.com/facebook-50-mi

well then.

Chrome won't delete google cookies when you ask to "delete all"

TBH, I haven't tested this (I don't do "nuke all" with my cookies) But if it's true, it's pretty damning.

news.ycombinator.com/item?id=1

Newegg was exposing Credit Card info for a month.

Some persistent XSS was detected on the checkout page skimming credit card info and sending it to a third party server.

theverge.com/2018/9/19/1787963

In the coming hours you may hear about a new attack on your computer called ColdBoot.

en.wikipedia.org/wiki/Cold_boo

While it's a pretty bad vulnerability - it's not the worst thing ever. Don't get caught up in the hype. The attacker needs extended access to your machine (e.g. it needs to be stolen) while it's on or very shortly after it's been turned off.

theverge.com/2018/9/13/1785507

I don't have the attention span to digest this right now. but it seems to me like a bad idea.

Any pros want to comment on this?

Just a reminder - in the coming days, you'll be inundated with reminders/requests/hints to help the victims of Florence monetarily.

Be careful: while most are legit, many will be scams. Do your homework if you choose to donate your hard earned money.

Additionally, they may not even ask for donations, they may pull on your heartstrings to trick you into giving up pieces of your identity.

Give, but be smart in giving.

Show more

<invalid character>

CounterSocial is the first Social Network Platform to take a zero-tolerance stance to hostile nations, bot accounts and trolls who are weaponizing OUR social media platforms and freedoms to engage in influence operations against us. And we're here to counter it.