social.tchncs.de is one of the many independent Mastodon servers you can use to participate in the fediverse.
A friendly server from Germany – which tends to attract techy people, but welcomes everybody. This is one of the oldest Mastodon instances.

Administered by:

Server stats:

3.8K
active users

#itsec

5 posts4 participants0 posts today
PositivDenken 🤯<p>The chiropractors of IT <a href="https://mastodon.social/tags/itsecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itsecurity</span></a> <a href="https://mastodon.social/tags/opsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>opsec</span></a> <a href="https://mastodon.social/tags/itsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itsec</span></a></p>
PositivDenken 🤯<p>Questioning some of those self proclaimed itsec experts seems to be a hobby on its own. </p><p><a href="https://mastodon.social/tags/itsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itsec</span></a> <a href="https://mastodon.social/tags/opsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>opsec</span></a> <a href="https://mastodon.social/tags/whateversec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>whateversec</span></a></p>
Heals :heart_nb:<p>Can websites please stop to default to send me a one-time code via email?</p><p>I’m not sure who thought it’s a nice feature but it’s way less secure than my login with email + password + 2FA token would be simply because all you need to do now is somehow get my email login.. </p><p><a href="https://indiepocalypse.social/tags/2fa" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>2fa</span></a> <a href="https://indiepocalypse.social/tags/login" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>login</span></a> <a href="https://indiepocalypse.social/tags/authentication" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>authentication</span></a> <a href="https://indiepocalypse.social/tags/ITSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ITSecurity</span></a> <a href="https://indiepocalypse.social/tags/itSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itSec</span></a> <a href="https://indiepocalypse.social/tags/healsRants" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>healsRants</span></a></p>
Benjamin Carr, Ph.D. 👨🏻‍💻🧬<p><a href="https://hachyderm.io/tags/Microsoft" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Microsoft</span></a> used its <a href="https://hachyderm.io/tags/AI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AI</span></a>-powered <a href="https://hachyderm.io/tags/SecurityCopilot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SecurityCopilot</span></a> to discover 20 previously unknown vulnerabilities in the <a href="https://hachyderm.io/tags/GRUB2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GRUB2</span></a>, <a href="https://hachyderm.io/tags/UBoot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>UBoot</span></a>, and <a href="https://hachyderm.io/tags/Barebox" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Barebox</span></a> <a href="https://hachyderm.io/tags/opensource" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>opensource</span></a> <a href="https://hachyderm.io/tags/bootloaders" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>bootloaders</span></a>.<br>GRUB2 (GRand Unified Bootloader) is the default boot loader for most <a href="https://hachyderm.io/tags/Linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Linux</span></a> distributions, including Ubuntu, while U-Boot and Barebox are commonly used in embedded and <a href="https://hachyderm.io/tags/IoT" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IoT</span></a> devices. <br><a href="https://www.bleepingcomputer.com/news/security/microsoft-uses-ai-to-find-flaws-in-grub2-u-boot-barebox-bootloaders/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/microsoft-uses-ai-to-find-flaws-in-grub2-u-boot-barebox-bootloaders/</span></a> <a href="https://hachyderm.io/tags/ITSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ITSec</span></a></p>
Felix Eckhardt<p><span class="h-card" translate="no"><a href="https://social.heise.de/@heisec" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>heisec</span></a></span> Die NVD Website hat immer noch Probleme: <a href="https://www.nist.gov/itl/nvd" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">nist.gov/itl/nvd</span><span class="invisible"></span></a></p><p>Die API ist davon aber nicht betroffen!</p><p><a href="https://det.social/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://det.social/tags/itsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itsec</span></a> <a href="https://det.social/tags/itsecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itsecurity</span></a> <a href="https://det.social/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a></p>
Cara<p><a class="hashtag" href="https://bsky.app/search?q=%23itsec" rel="nofollow noopener noreferrer" target="_blank">#itsec</a> Trump-Berater <a class="hashtag" href="https://bsky.app/search?q=%23Waltz" rel="nofollow noopener noreferrer" target="_blank">#Waltz</a> verschickte militärische Geheimnisse auch über private Gmail-Adresse Nach dem <a class="hashtag" href="https://bsky.app/search?q=%23Signal-Gate" rel="nofollow noopener noreferrer" target="_blank">#Signal-Gate</a> folgt der nächste problematische Umgang mit sensiblen Informationen.Das Umfeld von Mike Waltz dementiert,die "Washington Post" hat Belege <a href="https://www.derstandard.at/story/3000000263974/trump-berater-waltz-verschickte-militaerische-geheimnisse-auch-ueber-private-gmail-adresse?ref=article" rel="nofollow noopener noreferrer" target="_blank">www.derstandard.at/story/300000...</a><br><br><a href="https://www.derstandard.at/story/3000000263974/trump-berater-waltz-verschickte-militaerische-geheimnisse-auch-ueber-private-gmail-adresse?ref=article" rel="nofollow noopener noreferrer" target="_blank">Trump-Berater Waltz verschickt...</a></p>
𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕<p>»Gmail Gets End-To-End Encryption From Google As 21'st Birthday Present:<br>[…] Google Claims To Have Invented An Entirely New Type Of Encryption For Gmail Users […]«</p><p>This is not an April joke and yes Google offers OpenPGP for Gmail Accounts. This is not difficult to set up but too many people are too lazy in my opinion.</p><p>📧 <a href="https://www.forbes.com/sites/daveywinder/2025/04/01/gmail-gets-end-to-end-encryption-from-google-as-21st-birthday-present/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">forbes.com/sites/daveywinder/2</span><span class="invisible">025/04/01/gmail-gets-end-to-end-encryption-from-google-as-21st-birthday-present/</span></a></p><p><a href="https://chaos.social/tags/e2ee" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>e2ee</span></a> <a href="https://chaos.social/tags/openpgp" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>openpgp</span></a> <a href="https://chaos.social/tags/email" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>email</span></a> <a href="https://chaos.social/tags/gmail" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>gmail</span></a> <a href="https://chaos.social/tags/mail" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>mail</span></a> <a href="https://chaos.social/tags/itsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itsec</span></a> <a href="https://chaos.social/tags/encryption" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>encryption</span></a> <a href="https://chaos.social/tags/google" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>google</span></a> <a href="https://chaos.social/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://chaos.social/tags/april" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>april</span></a> <a href="https://chaos.social/tags/endtoendencryption" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>endtoendencryption</span></a> <a href="https://chaos.social/tags/pgp" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>pgp</span></a> <a href="https://chaos.social/tags/joke" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>joke</span></a> <a href="https://chaos.social/tags/birthday" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>birthday</span></a> <a href="https://chaos.social/tags/nojoke" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>nojoke</span></a> <a href="https://chaos.social/tags/april" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>april</span></a> <a href="https://chaos.social/tags/ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ransomware</span></a></p>
Felix Eckhardt<p><span class="h-card" translate="no"><a href="https://social.heise.de/@heisec" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>heisec</span></a></span> Wisst Ihr, was da bei NIST los ist? nvd.nist.gov ist seit min. heute Mittag immer wieder nicht erreichbar (503).</p><p><a href="https://det.social/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://det.social/tags/itsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itsec</span></a> <a href="https://det.social/tags/itsecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itsecurity</span></a> <a href="https://det.social/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a></p>
Felix Eckhardt<p>nvd.nist.gov seems to be down? DOGE@work?</p><p><a href="https://det.social/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://det.social/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://det.social/tags/itsecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itsecurity</span></a> <a href="https://det.social/tags/itsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itsec</span></a> <a href="https://det.social/tags/doge" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>doge</span></a> <a href="https://det.social/tags/musk" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>musk</span></a></p>
Griesgram in spe :linux:<p>Interessant: Wenn ich der Home Assistant App (iOS) die Berechtigung sich im LAN umzuschauen, entziehe, dann funktioniert die Verbindung zum Server nicht mehr. Eigentlich sollte der Server-URL ausreichen. Finde ich verdächtig. </p><p><a href="https://norden.social/tags/homeassistant" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>homeassistant</span></a> <a href="https://norden.social/tags/itsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itsec</span></a> <a href="https://norden.social/tags/opensourceistnichtimmersicher" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>opensourceistnichtimmersicher</span></a></p>
CyberEthical.Me<p>💣 Full write-up for "Tales for the Brave" - this year's Hard forensics challenge from Hack The Box Cyber Apocalypse CTF - Tales From Eldoria.</p><p>🔸 Code <a href="https://infosec.exchange/tags/deobfuscation" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>deobfuscation</span></a><br>🔸 hashtag#Telegram data exfiltration<br>🔸 Malware behavioral analysis</p><p>🔗 <a href="https://blog.cyberethical.me/htb-ctf-2025-forensics-tales-for-the-brave" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">blog.cyberethical.me/htb-ctf-2</span><span class="invisible">025-forensics-tales-for-the-brave</span></a> </p><p><a href="https://infosec.exchange/tags/CyberEthical" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberEthical</span></a> <a href="https://infosec.exchange/tags/CyberApocalypse25" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberApocalypse25</span></a> <a href="https://infosec.exchange/tags/HackTheBox" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HackTheBox</span></a> <a href="https://infosec.exchange/tags/forensics" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>forensics</span></a> <a href="https://infosec.exchange/tags/EthicalHacking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EthicalHacking</span></a> <a href="https://infosec.exchange/tags/blueteaming" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>blueteaming</span></a> <a href="https://infosec.exchange/tags/itsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itsec</span></a> <a href="https://infosec.exchange/tags/dataexfiltration" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dataexfiltration</span></a> <a href="https://infosec.exchange/tags/malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>malware</span></a></p>
𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕<p>»Unsicherheit – US-Kürzungsrausch gefährdet für das Internet wichtige Open-Source-Projekte:<br>Die neue US-Regierung entzieht dem Open Technology Fund (OTF) die Mittel. Von diesem sind unter anderem <span class="h-card" translate="no"><a href="https://infosec.exchange/@letsencrypt" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>letsencrypt</span></a></span>, <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>torproject</span></a></span> und <span class="h-card" translate="no"><a href="https://floss.social/@fdroidorg" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>fdroidorg</span></a></span> finanziell abhängig. Der OTF hat Klage eingereicht«</p><p>Sehr heikel und es petrifft, wenn auch "nur" indirekt, alle Menschen auf der Erde. Der Egoismus eines Irren kann uns alle betreffen!</p><p>👉 <a href="https://www.derstandard.at/story/3000000263520/lets-encrypt-tor-trump-kuerzungen-gefaehrden-fuer-das-internet-wichtige-open-source-projekte" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">derstandard.at/story/300000026</span><span class="invisible">3520/lets-encrypt-tor-trump-kuerzungen-gefaehrden-fuer-das-internet-wichtige-open-source-projekte</span></a></p><p><a href="https://chaos.social/tags/trump" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>trump</span></a> <a href="https://chaos.social/tags/uspol" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>uspol</span></a> <a href="https://chaos.social/tags/tor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tor</span></a> <a href="https://chaos.social/tags/fdroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fdroid</span></a> <a href="https://chaos.social/tags/letsencrypt" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>letsencrypt</span></a> <a href="https://chaos.social/tags/itsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itsec</span></a></p>
𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕<p>»Cyberkriminalität - Swisspass-Konto gehackt: freie Fahrt für die Betrüger:<br>Hacker ändern das Login und bestellen auf Kosten eines Studenten Zugtickets von fast 900 Franken. Das ist kein Einzelfall.«</p><p>Ich bin froh, dass ich öfters noch analoge Dinge nutze und dies bewusst. Was mich mehr aufregt, ist dass viele digitale so wie online Dienste sich nicht wirklich um die Sicherheit ihrer Kunden kümmern.</p><p>🔊 [CH-DE] <a href="https://www.srf.ch/sendungen/kassensturz-espresso/espresso/cyberkriminalitaet-swisspass-konto-gehackt-freie-fahrt-fuer-die-betrueger" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">srf.ch/sendungen/kassensturz-e</span><span class="invisible">spresso/espresso/cyberkriminalitaet-swisspass-konto-gehackt-freie-fahrt-fuer-die-betrueger</span></a></p><p><a href="https://chaos.social/tags/sbb" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sbb</span></a> <a href="https://chaos.social/tags/bahn" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>bahn</span></a> <a href="https://chaos.social/tags/ticket" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ticket</span></a> <a href="https://chaos.social/tags/mobile" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>mobile</span></a> <a href="https://chaos.social/tags/digital" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>digital</span></a> <a href="https://chaos.social/tags/hacking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hacking</span></a> <a href="https://chaos.social/tags/schweiz" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>schweiz</span></a> <a href="https://chaos.social/tags/itsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itsec</span></a></p>
𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕<p>Apple ID Hack — New Warning For 2 Billion Users</p><p>Apple has long since had an air of invulnerability about it as far as users have been concerned; be they iPhone, iPad or Mac fans, the ecosystem has been thought of as pretty darn secure. Like most security assumptions, however, it is wrong. […]</p><p>🍎 <a href="https://www.forbes.com/sites/daveywinder/2025/03/30/apple-id-hack-new-warning-for-2-billion-users/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">forbes.com/sites/daveywinder/2</span><span class="invisible">025/03/30/apple-id-hack-new-warning-for-2-billion-users/</span></a></p><p><a href="https://chaos.social/tags/apple" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>apple</span></a> <a href="https://chaos.social/tags/itsecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itsecurity</span></a> <a href="https://chaos.social/tags/hacking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hacking</span></a> <a href="https://chaos.social/tags/users" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>users</span></a> <a href="https://chaos.social/tags/itsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itsec</span></a> <a href="https://chaos.social/tags/iphone" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>iphone</span></a> <a href="https://chaos.social/tags/ipad" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ipad</span></a> <a href="https://chaos.social/tags/mac" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>mac</span></a> <a href="https://chaos.social/tags/itsecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itsecurity</span></a> <a href="https://chaos.social/tags/idhack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>idhack</span></a> <a href="https://chaos.social/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://chaos.social/tags/appleidhack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>appleidhack</span></a> <a href="https://chaos.social/tags/appleid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>appleid</span></a> <a href="https://chaos.social/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a></p>
𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕<p>User vs IT security 😼💻</p><p><a href="https://chaos.social/tags/itsecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itsecurity</span></a> <a href="https://chaos.social/tags/user" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>user</span></a> <a href="https://chaos.social/tags/online" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>online</span></a> <a href="https://chaos.social/tags/password" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>password</span></a> <a href="https://chaos.social/tags/it" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>it</span></a> <a href="https://chaos.social/tags/web" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>web</span></a> <a href="https://chaos.social/tags/itsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itsec</span></a> <a href="https://chaos.social/tags/passwords" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>passwords</span></a> <a href="https://chaos.social/tags/joke" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>joke</span></a> <a href="https://chaos.social/tags/ITJokes" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ITJokes</span></a> <a href="https://chaos.social/tags/video" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>video</span></a> <a href="https://chaos.social/tags/humor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>humor</span></a> <a href="https://chaos.social/tags/login" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>login</span></a> <a href="https://chaos.social/tags/jokes" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>jokes</span></a> <a href="https://chaos.social/tags/cats" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cats</span></a> <a href="https://chaos.social/tags/cat" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cat</span></a></p>
Franz<p>Cursed idea: An die E-Mail-Adresse im Impressum einen Alias mit Timestamp-basierten Hash anhängen und Spam automatisiert mit IP-Adresse aus dem Log an die Justiz übergeben</p><p><a href="https://chaos.social/tags/spam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>spam</span></a> <a href="https://chaos.social/tags/itsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itsec</span></a> <a href="https://chaos.social/tags/itsecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itsecurity</span></a></p>
defnull<p>Yearly reminder that <a href="https://chaos.social/tags/malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>malware</span></a> on <a href="https://chaos.social/tags/linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>linux</span></a> can just shutdown <a href="https://chaos.social/tags/ClamAV" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ClamAV</span></a> before downloading payload to avoid real-time detection, and <a href="https://chaos.social/tags/cisco" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cisco</span></a> does not think this is a problem.</p><p><a href="https://github.com/Cisco-Talos/clamav/issues/1169" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/Cisco-Talos/clamav/</span><span class="invisible">issues/1169</span></a></p><p><a href="https://chaos.social/tags/itsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itsec</span></a> <a href="https://chaos.social/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://chaos.social/tags/foss" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>foss</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mastodon.social/@dzwiedziu" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>dzwiedziu</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@fj" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>fj</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.world/@signalapp" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>signalapp</span></a></span> not really, as the <a href="https://infosec.space/tags/Metadata" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Metadata</span></a> <a href="https://infosec.space/tags/FUD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FUD</span></a> cited by <a href="https://infosec.space/tags/Signal" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Signal</span></a> is mitigateable with proper measures.</p><ul><li>You can't even run Signal over <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>torproject</span></a></span> and even if that point is moot when you're forced to quasi-<a href="https://infosec.space/tags/KYC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>KYC</span></a> by virtue of a <a href="https://infosec.space/tags/PhoneNumber" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PhoneNumber</span></a> aka. <a href="https://infosec.space/tags/PII" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PII</span></a> they have neither legitimate interest nor technical reason to demand in the first place!</li></ul><p>Every claim that things like <a href="https://infosec.space/tags/ITsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ITsec</span></a>, <a href="https://infosec.space/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a>, <a href="https://infosec.space/tags/OpSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpSec</span></a> &amp; <a href="https://infosec.space/tags/ComSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ComSec</span></a> can be solved with <em>"Just use Signal!"</em> is <em>"<a href="https://infosec.space/tags/TechPopulism" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TechPopulism</span></a>"</em> at best if not being a <em>"<a href="https://infosec.space/tags/UsefulIdiot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>UsefulIdiot</span></a>"</em>!</p><ul><li>All <a href="https://infosec.space/tags/centralized" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>centralized</span></a>, <a href="https://infosec.space/tags/SingleVendor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SingleVendor</span></a> &amp; <a href="https://infosec.space/tags/SingleProbider" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SingleProbider</span></a> systems are inherently insecure!</li></ul><p><a href="https://infosec.space/tags/EOD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EOD</span></a> <a href="https://infosec.space/tags/thxbye" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>thxbye</span></a> <a href="https://infosec.space/tags/next" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>next</span></a></p>
𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕<p>What is BLAKE3?</p><p>Even if I use a big fan from the use of BLAKE3 to hash, it is not possible to use it in a very advantageous way everywhere. What kind of thing is always what you have to question as a programmer. In the case of a product, the following conditions are met.</p><p>🔏 <a href="https://academy.bit2me.com/en/que-es-blake3-algoritmo-hash/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">academy.bit2me.com/en/que-es-b</span><span class="invisible">lake3-algoritmo-hash/</span></a></p><p><a href="https://chaos.social/tags/hash" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hash</span></a> <a href="https://chaos.social/tags/BLAKE3" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BLAKE3</span></a> <a href="https://chaos.social/tags/encryption" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>encryption</span></a> <a href="https://chaos.social/tags/itsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itsec</span></a> <a href="https://chaos.social/tags/fast" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fast</span></a> <a href="https://chaos.social/tags/keyfeatures" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>keyfeatures</span></a> <a href="https://chaos.social/tags/fastcode" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fastcode</span></a> <a href="https://chaos.social/tags/itsecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>itsecurity</span></a> <a href="https://chaos.social/tags/code" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>code</span></a></p>
Kevin Karhan :verified:<p>Seriously, <a href="https://infosec.space/tags/Signal" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Signal</span></a> fans are just <a href="https://infosec.space/tags/cultists" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cultists</span></a> who are unwilling to even consider the possibility that <span class="h-card" translate="no"><a href="https://mastodon.world/@signalapp" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>signalapp</span></a></span> as a <a href="https://infosec.space/tags/VCmoneyBurningParty" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VCmoneyBurningParty</span></a> isn't sustainable or that <span class="h-card" translate="no"><a href="https://mastodon.world/@Mer__edith" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>Mer__edith</span></a></span> and her predecessor, <a href="https://infosec.space/tags/Shitcoin" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Shitcoin</span></a>-<a href="https://infosec.space/tags/Scam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Scam</span></a> - shilling <a href="https://infosec.space/tags/CryptoBro" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CryptoBro</span></a> <a href="https://infosec.space/tags/Moxie" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Moxie</span></a> ain't their best friends and would happily <a href="https://web.archive.org/web/20210606070919/twitter.com/thegrugq/status/1085614812581715968" rel="nofollow noopener noreferrer" target="_blank">risk jail for them</a>.</p><ul><li>I may sound like <a href="https://de.wikipedia.org/wiki/Hans_B%C3%BChler_(Kaufmann)" rel="nofollow noopener noreferrer" target="_blank">Hans Bühler</a> at this point, but <a href="https://youtube.com/watch?v=tJoO2uWrX1M" rel="nofollow noopener noreferrer" target="_blank">Signal has a stench</a> that is very much reminiscent of <a href="https://infosec.space/tags/AN%C3%98M" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ANØM</span></a> &amp; <a href="https://infosec.space/tags/CryptoAG" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CryptoAG</span></a>!</li></ul><p>I <a href="https://infosec.space/tags/ToldYaSo" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ToldYaSo</span></a> and when the evidence is there, I do expect public apologies from every single one of you shills that <a href="https://infosec.space/@kkarhan/111968251463697943" rel="nofollow noopener noreferrer" target="_blank">live</a> on a <em>"<a href="https://infosec.space/tags/TrustMeBro" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TrustMeBro</span></a>!"</em> mentality believing every <a href="https://www.youtube.com/watch?v=G1thc5DSHwA" rel="nofollow noopener noreferrer" target="_blank">advertising lie</a>!</p><ul><li>Teach kids proper <a href="https://infosec.space/tags/TechLiteracy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TechLiteracy</span></a> instead and <em>get gud</em> at it. Do a <span class="h-card" translate="no"><a href="https://mastodon.earth/@cryptoparty" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>cryptoparty@mastodon.earth</span></a></span> / <span class="h-card" translate="no"><a href="https://chaos.social/@cryptoparty" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>cryptoparty@chaos.social</span></a></span> / <a href="https://infosec.space/tags/CryptoParty" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CryptoParty</span></a> and use <em>real <a href="https://infosec.space/tags/E2EE" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>E2EE</span></a></em> like <a href="https://infosec.space/tags/PGP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PGP</span></a>/MIME &amp; <a href="https://infosec.space/tags/XMPP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>XMPP</span></a>+<a href="https://infosec.space/tags/OMEMO" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OMEMO</span></a> FFS!</li></ul><p>If Signal was actually secure, it would be used by <a href="https://archive.org/details/darknet_drug_lord" rel="nofollow noopener noreferrer" target="_blank">every</a> <a href="https://pastebin.com/GrV3uYh5" rel="nofollow noopener noreferrer" target="_blank">single</a> <em>"Darknet Drug Lord"</em>! </p><ul><li>But guess why they'd rather <a href="https://www.youtube.com/watch?v=vdab4T_CoN8" rel="nofollow noopener noreferrer" target="_blank">teach</a> stuff like <a href="https://infosec.space/tags/OfflinePGP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OfflinePGP</span></a> method instead?</li></ul><p>Because <a href="https://infosec.space/tags/ComSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ComSec</span></a> requires <a href="https://infosec.space/tags/OpSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpSec</span></a>, <a href="https://infosec.space/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> &amp; <a href="https://infosec.space/tags/ITsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ITsec</span></a>!</p>