You Should Probably Stop Using ExpressVPN
https://gizmodo.com/you-should-probably-stop-using-expressvpn-1847739547
When the Director of Cybersecurity for the NSA recommends implementing network-wide ad blocking, you should listen. #cososec
//
"NSA cybersecurity best practices do indeed recommend utilizing ad blocking. Read more from NSA on blocking unnecessary advertising here:"
https://twitter.com/NSA_CSDirector/status/1441035682760249344
Successful update to the latest pi-hole just now. I was holding off because of a few reported issues, all went smoothly by following this poster's advice:
https://discourse.pi-hole.net/t/apt-get-error-on-update/49569/5
iOS 15 users: Does enabling this setting effectively mean your are proxying all your traffic through Apple servers? I don't understand how it would do what it says otherwise. #cososec
Two ransomware questions for #cososec:
1. Is the spread of cryptocurrencies directly related to the spread of ransomware?
I just finished 'Clickbait' on Netflix. It was great, but it also implies some serious #cososec points:
1. Secure all personal devices with password / pin locks.
2. Do not connect personal devices to work networks or devices.
3. Do not do personal things on work devices.
4. Turn off location tagging in all apps.
5. Use strong, unique passwords and MFA for all accounts.
6. Do not post anything about your personal life on public sites.
7. Trust your gut when it tells you something is off.
We've gone from Print Nightmare to Print Nowhere. #cososec
New Windows security updates break network printing
https://www.bleepingcomputer.com/news/security/new-windows-security-updates-break-network-printing/
How Apple's locked down security gives extra protection to the best hackers
https://www.technologyreview.com/2021/03/01/1020089/apple-walled-garden-hackers-protected/
The new warrant: how US police mine Google for your location and search history | US policing | The Guardian
https://www.theguardian.com/us-news/2021/sep/16/geofence-warrants-reverse-search-warrants-police-google
Hold on to your butts, #cososec. DoS attacks are about to get much worse.
This study found censorship middleboxes which are not standards-compliant may allow theoretically INFINITE packet amplification.
censorship.ai | Weaponizing Middleboxes for TCP Reflected Amplification
https://geneva.cs.umd.edu/posts/usenix21-weaponizing-censors/
^ Hashtag got caught in the sanitizer.
#cososec
Apple is patching a delivery vector for Pegasus spyware, which is used against people who say things governments or other powerful organisations don't like.
Pi-hole update just dropped.
#cososec
Pi-hole FTL v5.9, Web v5.6 and Core v5.4 released – Pi-hole
https://pi-hole.net/2021/09/11/pi-hole-ftl-v5-9-web-v5-6-and-core-v5-4-released/
It turns out that wireless charging leaks private data. It leaks information about websites visited by the user. " allows accurate website fingerprinting on a charging smartphone". Information leaked depends on the battery level. Cool work! #GDPR #ePrivacy https://t.co/CgclD0kzeB https://t.co/zkpy0zcB82
If you use a VPN...
When was the last time you changed your password?
Is it long, complex, and random?
Have you enabled MFA?
Does your provider support MFA? (If not, consider a different provider.)
Has your VPN undergone a third-party security audit? (If not, consider a different provider.)
Hackers leak passwords for 500,000 Fortinet VPN accounts
A threat actor has leaked a list of almost 500,000 Fortinet VPN login names and passwords that were allegedly scraped from exploitable devices last summer.
While the threat actor states that the exploited Fortinet vulnerability has since been patched, they claim that many VPN credentials are still valid.
German police secretly bought Pegasus spyware
Sources have confirmed media reports that federal criminal police purchased and used the controversial Israeli surveillance spyware despite lawyers' objections.
https://www.dw.com/en/german-police-secretly-bought-nso-pegasus-spyware/a-59113197
Heads up, ProtonMail users: Some of their claims about privacy may be more marketing than truth.
Climate activist arrested after ProtonMail provided his IP address
https://news.ycombinator.com/item?id=28427259
Proton's response, and criticism thereof:
https://protonmail.com/blog/climate-activist-arrest/
https://news.ycombinator.com/item?id=28433601
#cososec
nosanitize
Thread: TikTok, has become a hotbed for Russian disinformation and historical revisionism in regards to Syria. This disturbing trend should concern us all since the majority of TikTok’s users are teenagers and young adults. For example this video got 20k impressions. https://t.co/CCDsJFfsxp
Musician | Teacher | Nerd
𝘐 𝘢𝘮 𝘩𝘪𝘵𝘵𝘪𝘯𝘨 𝘮𝘺 𝘩𝘦𝘢𝘥 𝘢𝘨𝘢𝘪𝘯𝘴𝘵 𝘵𝘩𝘦 𝘸𝘢𝘭𝘭𝘴, 𝘣𝘶𝘵 𝘵𝘩𝘦 𝘸𝘢𝘭𝘭𝘴 𝘢𝘳𝘦 𝘨𝘪𝘷𝘪𝘯𝘨 𝘸𝘢𝘺.
- 𝘎𝘶𝘴𝘵𝘢𝘷 𝘔𝘢𝘩𝘭𝘦𝘳