-
18 votes
-
You've got Mali: UK Ministry of Defence accidentally emails Russia ally
18 votes -
On attestation on the web and why this could threaten the open web
13 votes -
How Chinese surveillance methods are going global
12 votes -
How do I get started in self hosting?
I'm curious on how to get started in self hosting. I have computer experience, being an Android Developer, but I hardly have experience in Linux and backend/networking work. I've been wanting to...
I'm curious on how to get started in self hosting. I have computer experience, being an Android Developer, but I hardly have experience in Linux and backend/networking work.
I've been wanting to start up a Plex/Jellyfin server for a while, and I have an old system sitting around with a Ryzen 1700 with a graphics card in there as well that's been begging for attention, and maybe I can throw on a Minecraft server in there as well. Since I travel a bunch, it would be nice too to be able to access my media for when I'm traveling, or to let my parents or friends access some shows if they so desire!
What I'm worried about is exposing my network to the internet basically. I used to run a Minecraft server with port forwarding and such on a personal computer but now I'm realizing that that's probably a bit unsafe lol.
Basically, are there any guides that I can look at, or any of your own experiences that could potentially help me or anyone who's interested?
28 votes -
Microsoft lost its keys, and the US government got hacked
25 votes -
Concerns about new facial recognition software implemented by TSA at US airports
42 votes -
Mastodon social network patches critical flaws allowing server takeover
18 votes -
Cops are already treating self-driving cars as 'surveillance cameras on wheels'
16 votes -
RowPress: Amplifying Read Disturbance in Modern DRAM Chips
6 votes -
Exclusive: CNN obtains the tape of former US President Donald Trump’s 2021 conversation about classified documents
99 votes -
NeverSSL
12 votes -
Proton Pass, open-source and encrypted password manager
17 votes -
LastPass users locked out due to MFA resets
64 votes -
Apple fixes zero-days used to deploy Triangulation spyware via iMessage
8 votes -
Phasing out passwords: Apple to automatically assign each user a Passkey
57 votes -
How to keep a secret in Python apps
5 votes -
Security expert defeats Lenovo laptop BIOS password with a screwdriver
13 votes -
The US is openly stockpiling dirt on all its citizens
25 votes -
Former US President Donald Trump indicted for second time, sources say
130 votes -
Google Authenticator now supports Google Account synchronization
After 11 years of life, Google Authenticator has added cloud backups for OTP keys in version 6.0. Google Security Blog: Google Authenticator now supports Google Account synchronization This is...
After 11 years of life, Google Authenticator has added cloud backups for OTP keys in version 6.0.
Google Security Blog: Google Authenticator now supports Google Account synchronization
This is surprising news to me, because historically Authenticator had no way to backup keys by design. Here's a 2017 quote from a Google engineer who maintains Authenticator:
There is by design NO account backups in any of the apps. [source]
This design choice always made sense to me, as the point of 2FA is that you've got (1) something you know, and (2) something you have. The second factor should be tied to a physical device. If you lose the physical device, the second factor should be gone, and you'll need to use one of those 10-ish backup codes that we all definitely keep somewhere safe. I'm quite befuddled that Google is reversing this design choice and walking back their previously strong, security-centric design for the sake of user convenience in the case of a lost phone. I used to advise my friends and family to choose Google Authenticator over Authy for this specific reason.
If you want further reading, here's a PCWorld article with an altogether different tone than Google's announcement: Google Authenticator’s long-awaited cloud 2FA feature carries hidden risk
11 votes -
Should I be using a passkey?
I saw all the hype about Google's new passkey rollout on Hacker News and Ars Technica in the past month, and have even read an article stating that, paraphrased, "I should start using passkeys...
I saw all the hype about Google's new passkey rollout on Hacker News and Ars Technica in the past month, and have even read an article stating that, paraphrased, "I should start using passkeys immediately, even if the tech is not all the way there yet."
Some questions:
- Are you using passkeys currently? Which provider?
- Is there a fear of vendor lock-in (looking at you, Apple) or ditching the product in the future (looking at you, Google)?
- Any other concerns I should be aware of, e.g. what happens if my phone gets run over by a bulldozer?
25 votes -
Amazon Ring cameras were used to spy on customers
32 votes -
KeePass 2.54 is out
8 votes -
1Password releases Passkeys in public beta channels
12 votes -
Stop silly security awards
6 votes -
$100 million gone in twenty-seven minutes
6 votes -
Generate a secure password using lyrics from Kenny Loggins. It's funny and useful!
4 votes -
Google released a .zip web domain and people can't decide if it's the phishing apocalypse or just as bad as any other dodgy link
13 votes -
"SHA-1 is a Shambles" - A demonstration of a chosen-prefix collision for SHA-1 (2020)
5 votes -
SolarWinds: The untold story of the boldest supply-chain hack ever
7 votes -
Google's adoption of passkeys (security blog article)
11 votes -
NSO group’s Pegasus spyware returns in 2022 with a trio of iOS 15 and iOS 16 zero-click exploit chains
4 votes -
Upgrade your LUKS key derivation function
7 votes -
Prompt injection: What’s the worst that can happen?
8 votes -
Norway has expelled fifteen Russian officials that it had accused of spying under diplomatic cover
8 votes -
Samsung meeting notes and new source code are now in the wild after being leaked in ChatGPT
5 votes -
Talkback: An aggregator of security news, articles and posts
5 votes -
AI can fool voice recognition used to verify identity by Centrelink and Australian tax office
11 votes -
A flock of chickens, held for ransom — Growing cyberattacks on Canada's food system threaten disaster
9 votes -
Monitor and respond to security alerts from within Minecraft
7 votes -
Belgium launches nationwide safe harbor for ethical hackers
10 votes -
LockPickingLawyer (literally) slaps open a MojoBox digital lockbox
22 votes -
Danish parliament urges lawmakers and employees to remove TikTok on work phones as a cybersecurity measure, saying “there is a risk of espionage”
4 votes -
Reddit was hacked
16 votes -
SolarWinds and market incentives
8 votes -
Upgraded to Windows 10, what do I need to do to optimize?
I finally got around to upgrading my mom’s computer (an Asus laptop from 2015) from Windows 8.1 to Windows 10. I’ve already deleted a few apps she won’t use (e.g., Xbox) and disabled/stopped some...
I finally got around to upgrading my mom’s computer (an Asus laptop from 2015) from Windows 8.1 to Windows 10. I’ve already deleted a few apps she won’t use (e.g., Xbox) and disabled/stopped some unneeded services. What else can I do to keep her computer fast? Particularly interesting in more services I can disable and the best browser/ad blocker combo. Thanks y’all!
10 votes -
What we learned from building GovSlack
6 votes -
Anker finally comes clean about its Eufy security cameras
23 votes -
US airline accidentally exposes ‘No Fly List’ on unsecured server
17 votes