Show more

Biggest takeaway - if you get a SMS message purporting to be from a bank or company you do business with, go to the business's homepage directly, and not through the link in the text message.

arstechnica.com/information-te


Facebook: We're discontinuing use of the highly controversial and privacy destroying facial recognition AI.

World: CHEERS!

Facebook: We're also changing our name to Meta.

World: umm.. ok, kinda weird, but whatevs.

Meta: No, no no... FACEBOOK discontinued facial recognition, Meta never did!

appleinsider.com/articles/21/1


If you needed another reason to dump FB ... new stalking tool just released as an "OSINT" tool.

"You give it a name and at least one photo. It then searches Facebook for this name and does Facial Recognition to determine the right Facebook Profile. After that it does a Google and ImageRaider Reverse Image Search to find other Social Media Profiles."

OH DEAR. THIS POST WAS SET TO SELF-DETONATE 💣 💥 🔥

Ą̷͇̀l̵̩̓̕l̸̩͘ ̸̭̪̈́ť̷̝̍̆h̶̡̛̰̯̏͌a̷͕̞͋̂t̵̩͙͑̈́͝'̵̛̍́ͅͅş̴̬̱͝ ̷̗̊͠l̵͚̕͠ē̸̻͓̐͝f̷̧͙̀̑͝t̶͓̓͊̚ ̶̜̱̓͌́a̴͉͊r̶̡̩͛̀é̵̦̞͕ ̶̮̾ṫ̷̡͈̍ḧ̸̛͍́̊e̴̫̅ş̶̥̰̓e̴̟̪͌͂̇ ̷̞̅͊̚h̷̰͕͈͂e̶̡̹̜̚ŗ̸̗͈̾̇e̴̩̍͐ ̷̪͉̩̀a̵̡̱̐͑͝s̴͎͖̈́h̸͈͌́͜e̴͕̝̐̌ś̶͓̆ͅ.̵̩̉ ̵̱͊͑̀

so, uh... anybody travel Air India?

you may want to cycle your credit cards.

and passport #

and everything else.

I know I've posted my "Don't use link shorteners" spiel in both and

But don't just take my work for it: gcs.civilservice.gov.uk/blog/l

The one exception is when you need an easy-to-remember link you're displaying in a physical space somewhere.

Conversely don't click on shortened links - don't trust them, ask the original sender to send you the actual link. (This goes for apple news too since many of us don't use iphones/macs)

Breaking: DOJ announced they seized the Colonial Pipeline ransom bitcoin wallet.

Just had a minor panic attack.

When I set up my work password manager's 2fa, I used my old yubikey (no NFC)

I've since gotten a new one with NFC.

I needed to authenticate just now, forgetting that I never setup my new yubikey.

I couldn't find my old one.

The moral of the story:

If you use 1 yubikey, use 2.

And make sure you have all 2fa's setup with /both/ of them.

A man was arrested recently using a hack at an ATM - apparently if you backspace at the right time, a bug in the software remembered your original entry for the deduction amount, but used your second entry for the dispensing amount. (not exactly, but the results are the same)

Great hack from a pen-test perspective... but he was arrested because he spent several hours at the same ATM with multiple stolen credit cards.... so awful execution.

(Not linking to avoid details)

Dammit - now I'm gonna have to start blocking favicon.ico.

... and my vast array of open tabs will be unmaintainable.

gizmodo.com/favicons-could-be-

Apparently it's Safer Internet Day.

So, here's my list for the average user:

1. Use a
2. Use an ad-blocker whenever possible. (lots of malware comes from ads)
3. Turn on 2 Factor Authentication (a.k.a. 2FA, MFA) whenever possible.
4. If you see something outrageous, really think about that link, the source, the probable outcome and if you really need to expose your computer or mental health to that.
5. Backup your devices to non-connected media.


Careful out there... perl[.]com was taken over by domain squatters.

Ok,
Since it keeps coming up, lets tell us your favorite and more importantly - Why it is.

We all know people should be using it, but many out there don't always how to evaluate which one would work best for them. So the why is important.

Use a password manager
I'm sorry if I sound like a broken record. But then, so do the security headlines

Spotify succumbed to a credential stuffy attack.

hotforsecurity.bitdefender.com

Show more

<invalid character>

CounterSocial is the first Social Network Platform to take a zero-tolerance stance to hostile nations, bot accounts and trolls who are weaponizing OUR social media platforms and freedoms to engage in influence operations against us. And we're here to counter it.