Well, my confidence in Firefox has just dropped a bit. #CoSoSec
https://twitter.com/MichalPurzynski/status/1293220570885062657
This sounds pretty awesome. Or terrifying. #CoSoSec
//
Ciphey is an automated decryption tool. Input encrypted text, get the decrypted text back.
"What type of encryption?"
That's the point. You don't know, you just know it's possibly encrypted. Ciphey will figure it out for you.
Ciphey can solve most things in 3 seconds or less.
The U.S. National Security Agency (NSA) today has published guidance on how to expose as little location information as possible while using mobile and IoT devices, social media, and mobile apps.
This has been a problem with Tor for a while now, and it appears to be getting worse. It is the main reason I don't feel any safer using it.
#CoSoSec
//
How Malicious Tor Relays are Exploiting Users in 2020 (Part I)
>23% of the Tor network’s exit capacity has been attacking Tor users
https://medium.com/@nusenu/how-malicious-tor-relays-are-exploiting-users-in-2020-part-i-1097575c0cac
It's 11 PM. Do you know where your removable keyboard cables are?
#CoSoSec
Here is a thorough analysis of what user data TikTok is sending back. It's less than you might think. #CoSoSec
//
TikTok: Logs, Logs, Logs. We are in 2020 and the US president is… | by Elliot Alderson | Aug, 2020 | Medium
https://medium.com/@fs0c131y/tiktok-logs-logs-logs-e93e8162647a
I use Bitwarden, and I am not very enthused by this news. Biometrics are not as secure as a strong password with 2FA, especially face ID. A password vault should have the strongest protection you have available.
I suppose it's better than someone using a weak password or PIN, but there's no way I'd use this feature.
//
Say Hello to Windows Hello and Touch ID in the Bitwarden Desktop App | Bitwarden Blog
https://bitwarden.com/blog/post/introducing-desktop-biometrics/
Firefox is launching their own email masking / forwarding service.
Summary of hypotheses on Twitter hack.
🔥 #CoSoSec 🔥
Keep your eyes open for this one. No modified hardware required.
//
BadPower attack corrupts fast chargers to melt or set your device on fire
Attackers can alter the firmware of fast charger devices to deliver extra voltage and damage connected equipment.
I won't link it here, but Brian Krebs is once again doxxing individuals who he believes are responsible for the recent Twitter compromise.
Way to make it harder for law enforcement to do their jobs, and to potentially ruin people's lives if you're wrong (or their families' lives even if you're right).
This is why I no longer respect Brian Krebs.
It doesn't matter how good your password and MFA game is, if you are careless with what you post on social media.
#CoSoSec
🚨 #CoSoSec 🚨
Hackers Are Breaking Directly Into Telecom Companies to Take Over Customer Phone Numbers
SIM swappers have escalated from bribing employees to using remote desktop software to get direct access to internal T-Mobile, AT&T, and Sprint tools.
"Hackers used social engineering to target some of Twitter’s employees and then gained access to the high-profile accounts."
AP News: Experts say Twitter breach troubling, undermines trust
Twitter Is Removing Images of Internal Tool Sources Say Enables Account Takeover
Multiple screenshots obtained by Motherboard show an internal panel that are being shared in the underground after a wave of account takeovers.
Rachel Tobac with some thoughts on the Twitter incident. #CoSoSec
What does #CoSoSec think about how big a deal this is or is not?
A few thoughts about Signal’s Secure Value Recovery
Musician | Teacher | Nerd
𝘐 𝘢𝘮 𝘩𝘪𝘵𝘵𝘪𝘯𝘨 𝘮𝘺 𝘩𝘦𝘢𝘥 𝘢𝘨𝘢𝘪𝘯𝘴𝘵 𝘵𝘩𝘦 𝘸𝘢𝘭𝘭𝘴, 𝘣𝘶𝘵 𝘵𝘩𝘦 𝘸𝘢𝘭𝘭𝘴 𝘢𝘳𝘦 𝘨𝘪𝘷𝘪𝘯𝘨 𝘸𝘢𝘺.
- 𝘎𝘶𝘴𝘵𝘢𝘷 𝘔𝘢𝘩𝘭𝘦𝘳