Yay, another time #pwned. Thank $whoever for password managers and generated password. And I guess the rest is probably burned in other places (I have a Impressum in my personal website), but damn, if I wanted/needed that hidden...
Also: 2019, that's 4+ years of possible abuse.
Dat feeling when you #pwned your first System...
Kinda like this track...
It's the Friday before Christmas and Have I Been Pwned drops an early present of a breach notification.
Wer oder was zum Frick ist #Hopamedia und warum haben die Daten von mir? #pwned
"Pwned", The Book, Is Now Available for Free
by @troyhunt
In PDF & EPUB formats.
https://www.troyhunt.com/pwned-the-book-is-now-available-for-free/
@kasiandra @torproject Ich fasse das als bedingungslose Kapitulation auf...
@0xabad1dea : if we'd have Device Bound Session Credentials (https://www.heise.de/en/news/FBI-Agency-issues-warning-about-session-cookie-theft-10007940.html and https://blog.chromium.org/2024/04/fighting-cookie-theft-using-device.html), cookie theft via some specific attacks may be prevented. But in general:
If your device is compromised, it's game over.
INB4 "U CAN'T SAY THAT ABOUT TRUMP SUPPORTERS PENISES!!!!"
Learn to take a #joke, snowflakes.
THIS is where I disagree...
You may think it's elitist, but if people are too lazy to learn even fundamentals like how to use #Tails then maybe they should just not do #tech at all?
I'll gladly teach #TechIlliterates but I won't waste my time on people that spread disinfo...
It's 2024: @tails_live / @tails has been out for over a decade and there are a shitload of guides ranging from written documentation to Zoomer-friendly TikTok-Style shorts on how to get started.
I don't expect people to do #airgapped pffline-PGP but with @thunderbird including #Enigmail and not requiring any external dependencies like the god-awful #GPG4Win stuff's easier than ever.
Same with #mobile: #Appls like @monocles / #monoclesChat are so easy, I've been able to onboard literal tech-illiterates remotely with few steps and simple instructions.
FOR THE LAST TIME:
*STOP MAKING EXCUSES TO JUSTIFY ESCALATING COMMITMENT TO EVIDENTLY BAD SOLUTIONS!"
Whereas with #SelfCustody of all the keys as well as #ReproduceableBuilds and real #decentralization, this would be evidently impossible even if all the devs wanted to comply honestly and not just because they could be held at gunpoint.
Compare that to #monocles where you do pay like €2 p.m. but in return get #standard #protocols like #IMAP, #SMTP & #XMPP and can pay anonymously and not have to provide any PII whatsoever!
Make of that what you will, but just like allowing flatearthers to roam freely without caretaker supervision doesn't make the world less round, so won't the facts change about #ITsec, #InfoSec, #OpSec & #ComSec.
Because all #centralized, #SingleVendor & #SingleProvider solutions are bad, and if they don't even allow for #SelfCustody then they are just a #grift to #scam tech-illiterates that don't know and/or don't care!
@lauren @Ulrich_the_elder @torproject
Oh no, the first breach my primary email address has been in. It was inevitable it would happen one day but I'm surprised it took a whole 5 years.
you can never mitigate security issues. you can only postpwn them.
@marcan nodds in agreement #Apple doesn't need to have backdoors in Hardware when their entire #iCould is backdoored and can be weaponized to brick devices.
Either way, these are not inherent to the used #Silicon, but entirely #Firmware-based.
#pwned "Vaccine" today. The box was a lot of fun! Didn't need to lookup the writeup until the #privilegeescalation part. #Hackthebox really is a great resource for learning.
#htb #learntohack
@ben OFC that works...
Holy shit. Interesting insights. But what I mainly take from this is that wiz.io apparently has really good lawyers?!
What were they thinking doing so much lateral movement in the network after the first proof-of-concept
https://www.wiz.io/blog/sapwned-sap-ai-vulnerabilities-ai-security