cybersecurity

!cybersecurity

@infosec.pub
Create post
Mentorship Monday - Discussions for career and learning!

Mentorship Monday - Discussions for career and learning!

Weekly thread for any and all career, learning and general guidance questions. Thinking of taking a training or going for a cert? Wondering how to level up your career? Wondering what NOT to do? Got other questions? This is the time and place to ask!

data was exfiltrated from a corp I did not even know had my data; then they offer to have a privacy abuser (Cloudflare) MitM credit monitoring txns. WTF?

data was exfiltrated from a corp I did not even know had my data; then they offer to have a privacy abuser (Cloudflare) MitM credit monitoring txns. WTF?

Apparently some company I do business with shared my data with another corp without me knowing,

WTF?

then that corp who I did not know had my data was breached.

WTF?

Then the breached corp who could not competently secure the data in the first place offers victims gratis credit monitoring services (read: offers to let yet another dodgy corp also have people’s sensitive info thus creating yet another breach point). Then the service they hired as a “benefit” to victims outsources to another corp and breach point: Cloudflare.

WTF?

So to be clear, the biggest privacy abuser on the web is being used to MitM a sensitive channel between a breach victim and a credit monitoring service who uses a configuration that blocks tor (thus neglecting data minimization and forcing data breach victims to reveal even more sensitive info to two more corporate actors, one of whom has proven to be untrustworthy with private info).

I am now waiting for someone to say “smile for the camera, you’ve been punk’d!”.

(update)
Then the lawyers representing data breach victims want you to give them your e-mail address so they can put Microsoft Outlook in the loop. WTF? The shit show of incompetence has no limit.

Off-Topic Friday

Off-Topic Friday

Wanna chat about something non-infosec amongst those of us who frequent /c/cybersecurity? Here’s your chance! (Keep things civil & respectful please)

Off-Topic Friday

Off-Topic Friday

Wanna chat about something non-infosec amongst those of us who frequent /c/cybersecurity? Here’s your chance! (Keep things civil & respectful please)

What are You Working on Wednesday

What are You Working on Wednesday

Weekly thread to discuss whatever you’re working on, big or small, at work or in your free time.

Mentorship Monday - Discussions for career and learning!

Mentorship Monday - Discussions for career and learning!

Weekly thread for any and all career, learning and general guidance questions. Thinking of taking a training or going for a cert? Wondering how to level up your career? Wondering what NOT to do? Got other questions? This is the time and place to ask!

Off-Topic Friday

Off-Topic Friday

Wanna chat about something non-infosec amongst those of us who frequent /c/cybersecurity? Here’s your chance! (Keep things civil & respectful please)

Roast the security of my app

Roast the security of my app

im aiming to make a chat app secure as theorhetically possible as a webapp. for transparency its open source. id like the user experience to be as close to possible to a regular chat app. its important to note; there are limitation with p2p and webapps such that messages cant be sent if the peer isnt connected.

to keep this post brief, please take a look at the readme. it has all the information and links.

i dont think its ready to replace any app or service, but id love to get feedback on what you think would make it so you would use it more than once.

apps .. repo or not

apps .. repo or not

Open link in next tab

Kristoff Bonne 🇪🇺 🇧🇪 (@kristoff@m.krbonne.net)

https://m.krbonne.net/@kristoff/112984731113603232

@organicmaps@fosstodon.org OK fair point. However, if I look at this from a hacker perspective, you post looks like the ideal opportunity to post a message similar to yours, but pointing to a fake app containing malware. Proposing to people to download an app at some random URL, even if it has organiscmaps.app in it, is a bad idea. Also by mentioning that your app got blocked by google in a platform like fosstodon, directs people attention away from "is this real or mallware?" to "grr. I hate google"

Mentorship Monday - Discussions for career and learning!

Mentorship Monday - Discussions for career and learning!

Weekly thread for any and all career, learning and general guidance questions. Thinking of taking a training or going for a cert? Wondering how to level up your career? Wondering what NOT to do? Got other questions? This is the time and place to ask!