Here’s a reminder to make your Venmo transactions private, courtesy of Clarence Thomas / Lawyers appearing before the Supreme Court sent money to a Clarence Thomas aide via Venmo, according to the aide’s profile. Don’t be like him.
Who's down with WPA3?
Yeah, you know, me.
Mastodon fixes critical “TootRoot” vulnerability allowing node hijacking
Most critical of the bugs allowed attackers to root federated instances.
Watching a bunch of notable infosec accounts jumping on board the #Threads bandwagon makes me want to scream.
If you would expect anyone to carefully read privacy policies and app permissions, you'd think it would be these people.
They did the same thing with #Bluesky and I lost respect for those people when that happened. This one is even worse.
I made a reference sheet that links to privacy policies for various social networks. The next time someone asks if their privacy is being protected by a certain network or app, you can point them here.
For the new people, here are my top 5 hashtags, submitted for approval:
#cosomusic
#cosoclassical
#cosoteachers
#musictheory
#cososec
For those who may be averse to cloud-based password vaults, here is a cake-and-eat-it-too solution.
#cososec
ALWAYS change the default login credentials for any device. Lists like this exist and you will get instantly popped.
Here's yet another reason why Signal should NOT be held up as the standard for secure and/or private comms.
How to Disable Ad ID Tracking on iOS and Android, and Why You Should Do It Now
https://www.eff.org/deeplinks/2022/05/how-disable-ad-id-tracking-ios-and-android-and-why-you-should-do-it-now
Private Spies Hired by the FBI and Corporate Firms Infiltrate Discord, Reddit, WhatsApp
Leading “threat intelligence” firms are creating fake online personas to gain access to every corner of the web.
https://www.leefang.com/p/private-spies-hired-by-the-fbi-and
Next to the phone number requirement, the metadata retention is one of the biggest reasons I don't use Signal.
#cososec
https://twitter.com/matthew_d_green/status/1660617576005660672
How well does your web browser protect your privacy? Find out here:
To anyone interested in connecting on SimpleX Chat, the old room was getting cranky (technically). New room is here:
Ars write-up on Google Passkeys. I'm surprised to see this kind of pollyana article from them with no cautions stated whatsoever.
My concerns about passkeys (as implemented by Google) linked below. #cososec
This Passkey idea sounds good in theory, but I have some serious concerns with what is described in this post.
#cososec
https://security.googleblog.com/2023/05/so-long-passwords-thanks-for-all-phish.html
Musician | Teacher | Nerd
𝘐 𝘢𝘮 𝘩𝘪𝘵𝘵𝘪𝘯𝘨 𝘮𝘺 𝘩𝘦𝘢𝘥 𝘢𝘨𝘢𝘪𝘯𝘴𝘵 𝘵𝘩𝘦 𝘸𝘢𝘭𝘭𝘴, 𝘣𝘶𝘵 𝘵𝘩𝘦 𝘸𝘢𝘭𝘭𝘴 𝘢𝘳𝘦 𝘨𝘪𝘷𝘪𝘯𝘨 𝘸𝘢𝘺.
- 𝘎𝘶𝘴𝘵𝘢𝘷 𝘔𝘢𝘩𝘭𝘦𝘳