Show more

Here’s a reminder to make your Venmo transactions private, courtesy of Clarence Thomas / Lawyers appearing before the Supreme Court sent money to a Clarence Thomas aide via Venmo, according to the aide’s profile. Don’t be like him.

theverge.com/2023/7/12/2379292

Mastodon fixes critical “TootRoot” vulnerability allowing node hijacking

Most critical of the bugs allowed attackers to root federated instances.

arstechnica.com/security/2023/

Watching a bunch of notable infosec accounts jumping on board the bandwagon makes me want to scream.

If you would expect anyone to carefully read privacy policies and app permissions, you'd think it would be these people.

They did the same thing with and I lost respect for those people when that happened. This one is even worse.

I made a reference sheet that links to privacy policies for various social networks. The next time someone asks if their privacy is being protected by a certain network or app, you can point them here.

rentry.co/socialnetworkprivacy


has a very long list of requested app permissions. Screenshot below from Play store.

If you install this, you're opening yourself up to a lot of invasive data mining. Still think it's a good idea?

For those who may be averse to cloud-based password vaults, here is a cake-and-eat-it-too solution.

ALWAYS change the default login credentials for any device. Lists like this exist and you will get instantly popped.

github.com/ihebski/DefaultCred

Private Spies Hired by the FBI and Corporate Firms Infiltrate Discord, Reddit, WhatsApp

Leading “threat intelligence” firms are creating fake online personas to gain access to every corner of the web.

leefang.com/p/private-spies-hi

Next to the phone number requirement, the metadata retention is one of the biggest reasons I don't use Signal.

twitter.com/matthew_d_green/st

Ars write-up on Google Passkeys. I'm surprised to see this kind of pollyana article from them with no cautions stated whatsoever.

My concerns about passkeys (as implemented by Google) linked below.

arstechnica.com/information-te

counter.social/@voltronic/1103

This Passkey idea sounds good in theory, but I have some serious concerns with what is described in this post.

security.googleblog.com/2023/0

Show more

ᏤⵁŁ₮ƦⵁИł€

CounterSocial is the first Social Network Platform to take a zero-tolerance stance to hostile nations, bot accounts and trolls who are weaponizing OUR social media platforms and freedoms to engage in influence operations against us. And we're here to counter it.