Security

JonsJava , (edited ) in Amazon storing classified US government documents improperly
@JonsJava@lemmy.world avatar

In their defense:

TakiMinase , in If the Internet where to be redesigned, what would you change to improve security?

Fully open architecture so every point can be audited by every connection.

Godort , (edited ) in If the Internet where to be redesigned, what would you change to improve security?

Stop using email as a trusted authentication source.

This is a case where using it was super convenient because you could have a personal identifier, an easy way to contact the user, and be reasonably sure that password resets would only reach the intended user all in one convenient plaintext string.

However it's also a single point of failure and if a malicious actor can get access to your email account, they can get access to most of your other accounts that use that same address

Edit: MFA being available in more places has reduced the risk of this happening, assuming that you use it and it's also deployed correctly. ie: it can't be reset from the same email address that your password resets go to.

ratman150 , in AnyDesk revokes certs, passwords after IT security breach

This seems like a good course of action compared to how most breaches are handled.

vk6flab , in This Undisclosed WhatsApp Vulnerability Lets Governments See Who You Message
@vk6flab@lemmy.radio avatar

You mean, a messaging app offered by Meta isn't secure? I'm shocked, I say, shocked!

Anyway..

Buddahriffic , in After XZ Utils, More Open-Source Maintainers Under Attack

I'm kinda glad this happened because I was assuming bad actors were fucking with open source stuff before the XZ stuff came out and now it's on the radar.

Though I wonder if there's any way to automate watching for stuff like this. Like the XZ backdoor involved changing what was supposed to be a bad test file, it would be nice to have a system that treats all input files as immutable and if anything needs to be processed, it goes into a separate output folder plus has a reasoning included as to why the input file needs more processing, especially something that doesn't change from system to system.

TrudeauCastroson , in Gmail And YouTube Hackers Bypass Google’s 2FA Account Security

Crazy that it's just clicking a sketchy link that can do that

Quereller , in How the Pentagon Learned to Use Targeted Ads to Find Its Targets—and Vladimir Putin

It is so important that people are aware of the Ad-surveillance. But most just do not care, to abstract is the danger.

DarkSpoon , in Vehicle thefts - Insecure vehicles should be banned, not security tools like the Flipper Zero

That would mean banning all vehicles because none of them are secure.

PowerCrazy ,

Seems like a good compromise to me.

HenchmanNumber3 , in If the Internet where to be redesigned, what would you change to improve security?

Top down design of protocols by a security- and privacy-conscious organization rather than leaving security to corporations as a side item or PR campaign topic when their primary focuses are marketing, advertising, data collection, and intellectual property.

ohto , in Twilio Authy Desktop app, new death date

What?? That’s a month away. That feels really unprofessional and doesn’t foster trust in the company, which is really important when you’re in the security field.

When I heard the news about killing the desktop apps in August I immediately started transitioning my accounts to use the TOTP authenticator built into Bitwarden. Now I’m really glad I did.

FirstCircle OP ,
@FirstCircle@lemmy.ml avatar

Long-time Bitwarden customer, and I did the exact same thing. Prior to that I hadn't even been aware of the OTP functionality in the BW desktop app. Glad I made the move early and don't have to scramble now. This new deadline is going to be a real pain for a lot of Authy desktop users. Weird that the company didn't even feel the need to explain to users the reason for the drastic EOL change. I've used some of their voice/sms services in the past but if I need that kind of thing in the future I'm going to have a good look around at the competitors before I write a line of code or open my wallet again.

lemmyseizethemeans , in Netherlands reveals Chinese spies attacked its defense dept

When Americans do it they are 'script kiddies'. When China does it, it's 'State Sponsored or something

wahming ,

If you had bothered reading the article, the methods used are extremely advanced. Nothing 'script kiddy' about it.

nieminen , in Amazon storing classified US government documents improperly

Second result for me was a document about Russian hackers and their demands that we enstate trump as president after he lost.

friend_of_satan , in High Court orders temporary suspension of Telegram's services in Spain

Are they suspending all email servers too?

Noodle07 , in Firmware flaw affects numerous generations of Intel CPUs — UEFI code execution vulnerability found for Intel CPUs from 14th Gen Raptor Lake to 6th Gen Skylake CPUs, and TPM will not save you

Me with 3rd gen cpu: 🤣

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • security@lemmy.ml
  • test
  • worldmews
  • mews
  • All magazines