Show more

Stop using Facebook and Instagram.

Facebook’s In-app Browser on iOS Tracks ‘Anything You Do on Any Website’ | Threatpost
threatpost.com/facebook-ios-tr

I gotta say, Wireguard wipes the floor with OpenVPN. So glad I switched.

This post addresses the "eggs in one basket" argument people make against using password managers.

About eggs and baskets - password managers
johnopdenakker.com/about-eggs-

Someone on my street made their exact street address their SSID. :facepalm:

Also, a lot of nearby Bluetooth Low Energy devices aren't nearly "low energy" enough.

The sent/received metadata but with the actual messages missing on the USSS agents' phones could have two possible explanations:

1. They were using a messaging app with the disappearing / exploding messages feature turned on. Most of the popular encrypted messaging apps have this option.

2. If not option 1 - whether they used an encrypted messenger or regular SMS, the messages were specifically and intentionally deleted.

New documents reveal ‘huge’ scale of US government’s cell phone location data tracking | TechCrunch
techcrunch.com/2022/07/18/home

To anyone out there still using face unlock, STOP.

The FBI Forced A Suspect To Unlock Amazon’s Encrypted App Wickr With Their Face
forbes.com/sites/thomasbrewste

Paging COSO Hive Mind:

I am interested in installing a WiFi thermostat for remote control, scheduling, multiple users, and potential energy savings.

Google Nest Thermostat ticks all the boxes, and for a good price. Are there any serious security concerns with current models beyond the usual Google stuff? The exploits I'm reading about are all from 2014-2016.

It would be on an isolated VLAN, and my pi-hole would minimize the data sent to the Googleship.

Thoughts? Better options?

OK, infosec pros: Is this the panacea so many are making it out to be? I understand the benefits, but I am concerned with the greater reliance on biometrics. Unless they bring back iris scanning on phones [pouring one out for my GS8].

//

Tech giants want to kill off passwords. Here's why they think passkeys will change the world, and what that means for you - ABC News
abc.net.au/news/2022-07-14/tec

This is a comprehensive data security audit of iOS and Android devices.

Data Security on Mobile Devices
securephones.io/

It bears repeating: If you care about your privacy, STOP USING CHROME.

Google 'private browsing' mode not really private, Texas lawsuit says | Reuters
reuters.com/legal/litigation/g

U.S. Healthcare Orgs Targeted with Maui Ransomware | Threatpost

State-sponsored actors are deploying the unique malware–which targets specific files and leaves no ransomware note–in ongoing attacks.

threatpost.com/healthcare-maui

An unusually advanced hacking group has spent almost two years infecting a wide range of routers in North America and Europe with malware that takes full control of connected devices running Windows, macOS, and Linux, researchers reported on Tuesday.

arstechnica.com/information-te

I'm doing a required phishing awareness training from my school district this morning. Should be fun.

If your car gets broken into with no sign of forced entry, this may be how it was done.

RollBack - A New Time-Agnostic Replay Attack Against the Automotive Remote Keyless Entry Systems - Black Hat USA 2022 | Briefings Schedule
blackhat.com/us-22/briefings/s

Twitter insists you add an email to your account in order to enable 2FA. Nope. I'm not giving them my phone number or email.

The workaround is to use an email forwarding service. I've been using simplelogin.io/ which is dead simple to use, and the free tier gives you quite a lot to work with.

Boom. 2FA enabled, and without Twitter ever knowing my real email address.

Show more

ᏤⵁŁ₮ƦⵁИł€

CounterSocial is the first Social Network Platform to take a zero-tolerance stance to hostile nations, bot accounts and trolls who are weaponizing OUR social media platforms and freedoms to engage in influence operations against us. And we're here to counter it.