Show more

I don't buy LastPass' statement that this breach of master passwords was due to credential stuffing. If that were the case, then LastPass users who feel victim would have been using their master passwords for something else. The victims who posted in the HN thread specifically said they did not do that.

LastPass Says It Didn’t Leak Your Master Password
howtogeek.com/776450/lastpass-

Just received a "suspicious activity" password reset prompt email from PayPal.

I went to PP manually rather than clicking the link the email (on phishing suspicion). Email was legit; it prompted me to change password immediately.

So, I fired up Bitwarden to generate a new password with my default settings.

Nope. Needed to adjust down, because PayPal STILL has a 20-character limit on passwords! 🤬

SERIOUSLY, PayPal?!?!

At least they support 2FA, but get with the program, people.

🚨 Heads up, TP-Link router owners:

You might have a mesh network automatically enabled that you didn't know existed.

Hidden Networks in TP-Link Routers | Jahed Ahmed
jahed.dev/2021/12/19/hidden-ne

Here is some really neat AirTag analysis on what / when it is broadcasting.

A great undergrad I work with, @wentian23731747 (who is applying for PhD programs this year) made a quick writeup of AirTag BLE activity t.co/ZG0JEVPRs9
AirTags are kinda complex, but the short story is a *lost* tag's MAC rotates 10-30min, but public key doesn't

twitter.com/skateprofessor/sta

I never would have thought about someone doing this, but I sure as hell aren't going to forget it.

🚨 Heads up, Tor users! 🚨

A mysterious threat actor is running hundreds of malicious Tor relays - The Record by Recorded Future
therecord.media/a-mysterious-t

👋Welcome, new CoSoNauts!

Time to crack those eggs. Upload a profile pic, and say hello. Check out the user guide:
counter.social/userguide.pdf

Some tags to follow:

Infosec discussion: .

Music lovers and musicians: check out , , and .

If you love good drinks, follow and .

Animal lovers: , , .

We're glad you made it here. Enjoy the realness!

A "deep scrub"? Do tweets embed origin IPs in metadata? I would expect IPs to be logged, but not in a way that is accessible to third-parties.

Divide & conquer: A sample of 32,315 pro-Rittenhouse hashtag tweets, Nov 19-20, showed 29,609 with disabled geolocation. Of those, 17,701 were listed as "foreign", but a deep scrub revealed most of those were in Russia, China, and the EU.

twitter.com/FrankFigliuzzi1/st

It's backup day. Running BD-R, DVD-R DL, and even a couple CDs (rescue and repair discs).

When have YOU last backed up?

As an XMPP fan, I support this:

"What if we could make a Signal that was a little more open? And an XMPP that was a little bit less diverse? Accept that we would trade some of the agility for robustness, and some of our diversity in favour of consistent usability.

Can we move beyond Signal’s flaws to build something that is open, interoperable, user-friendly, consistent and decentralized? I believe so, and as they say, there’s only one way to find out."

snikket.org/blog/products-vs-p

Calling on hive mind:

I am looking for an Android solution for creating encrypted local containers that can later be mounted by VeraCrypt or similar apps after copying to desktop.

So far I am only seeing one option. Anyone know of any others?

play.google.com/store/apps/det

nosanitize

Show more

ᏤⵁŁ₮ƦⵁИł€

CounterSocial is the first Social Network Platform to take a zero-tolerance stance to hostile nations, bot accounts and trolls who are weaponizing OUR social media platforms and freedoms to engage in influence operations against us. And we're here to counter it.