-
15 votes
-
"Disable SMT/Hyperthreading in all Intel BIOSes"
23 votes -
Should Grindr users worry about what China will do with their data?
16 votes -
Making C less dangerous
16 votes -
The Performance Cost Of Spectre, Meltdown, & Foreshadow Mitigations On Linux 4.19 with Intel & AMD processors
14 votes -
Here's why your static website needs HTTPS
30 votes -
Venmo's public API exposes millions of transactions, startling users
10 votes -
Phone Numbers Were Never Meant as ID. Now We’re All At Risk
22 votes -
Epic's first Fortnite Installer allowed hackers to download and install anything on your Android phone silently
26 votes -
The Tunisian-Libyan border: Security aspirations and socioeconomic realities
6 votes -
Over 1400 Western Australian government officials used 'Password123' as their password
27 votes -
How I recorded user behaviour on my competitor’s websites
32 votes -
Intel Publishes Microcode Security Patches, No Benchmarking Or Comparison Allowed!
12 votes -
How One Guy Hacked BlackHat 2018
16 votes -
OpenSSH Username Enumeration Vulnerabilty
11 votes -
Observatory by Mozilla
28 votes -
Security research underway to ensure you will not be carjacked by hackers
4 votes -
Faxploit: Sending Fax Back to the Dark Ages
8 votes -
Elon Musk announces plan to open source part of Tesla's vehicle security software
@elonmusk: Great Q&A @defcon last night. Thanks for helping make Tesla & SpaceX more secure! Planning to open-source Tesla vehicle security software for free use by other car makers. Extremely important to a safe self-driving future for all.
7 votes -
DIYers hack insulin pump - create artificial pancreas
13 votes -
Cybersecurity experts from Homeland Security, the National Intelligence director's office, and private industry discussed how they're working to counter the most urgent threats
3 votes -
Hacker Finds Hidden 'God Mode' on Old x86 CPUs
23 votes -
‘It’s our time to serve the Motherland’ How Russia’s war in Georgia sparked Moscow’s modern-day recruitment of criminal hackers
6 votes -
WPA3: How and why the Wi-Fi standard matters
15 votes -
How I gained commit access to Homebrew in 30 minutes
19 votes -
Experts criticize West Virginia’s plan for smartphone voting
13 votes -
Let's Encrypt Is Now Officially Trusted by All Major Root Programs
25 votes -
Facebook in talks with banks to add your financial information to Messenger
18 votes -
The federal government's My Health Record system is capable of storing genomic information, which could turbocharge medical research but has intensified privacy and security fears
5 votes -
Reddit servers breached; full backup from 2007 (including hashed+salted passwords) obtained by attackers
77 votes -
TSA looks at doing away with security screening at 150 smaller airports in US
15 votes -
Two-Factor Auth / Security
I’m still in awe of what’s happening here and wish I had a crystal ball to see the change this type of community will drive in broader social discourse. If that goal is realized, there will be...
I’m still in awe of what’s happening here and wish I had a crystal ball to see the change this type of community will drive in broader social discourse. If that goal is realized, there will be very sophisticated folks looking to disrupt that progress.
As a security guy (especially in light of Reddit’s recent announcement) I had a few questions!
1.) How open are we to integrating some type of optional 2FA for users? Maybe a simple TOTP integration?
2.) Are the admins of the site implementing the right amount of fundamental controls for the backend? I’m 100% happy to provide thoughts on this if necessary! The decisions you make now, could impact us 5-6 years from now. And they’re oh-so-easy to change this early :-D.16 votes -
India looking to compel e-commerce, social media firms to store data locally
5 votes -
Need help dispelling myths about how hackers access websites
I hope I’m posting this in the correct place. I’ve been having a disagreement with someone over the abilities of hackers. I kinda hope Deimorz pops in because he wrote automod. I said that the...
I hope I’m posting this in the correct place. I’ve been having a disagreement with someone over the abilities of hackers. I kinda hope Deimorz pops in because he wrote automod.
I said that the only way for someone to gain access to a subreddit to make changes is if they steal a moderator’s account password or they are added to the mod team. The person I’m having a disagreement with believes that adding text to the wiki for users to view (like the extensive wiki r/skincareaddiction has) would make it easier for hackers to insert malicious code in order to gain access to the sub. This person also mentioned being able to change the subreddit through browser tools. She insists the sidebar and wiki are potential access points for scripting attacks. Automod just so happens to be enabled which is why I mentioned Deimorz.
I’m not an IT professional. My brothers currently are which helped me learn most of what I know. I’ve supplemented that over the years with whatever info I came across online. What she’s saying sounds like crazy town to me. But since I’m not a hacker, is there a way to use the sidebar or wiki area to hack into a subreddit?
Thanks in advance to anyone who pities me by providing a detailed answer to this thinly veiled request to help me win an internet argument 🙇🏾♀️.
10 votes -
The spy who drove me
7 votes -
What are you using for your firewall in your home lab, hardware and OS?
What are you using for your firewall at home?
8 votes -
Departing Facebook security officer's memo: "We need to be willing to pick sides"
6 votes -
How to block ads like a pro
34 votes -
The SIM Hijackers
8 votes -
Riot's approach to anti-cheat
3 votes -
Top Voting Machine Vendor Admits It Installed Remote-Access Software on Systems Sold to States
21 votes -
Riot's approach to anti-cheat
10 votes -
"If you are denied an Australian visa, you will be denied by a human officer. They might be assisted by AI, but it's a human that will deny your visa. We call that the 'golden rule'."
3 votes -
Breach 'inevitable' in digital health records
7 votes -
Despite Chrome’s pending “mark of shame,” three major news sites aren’t HTTPS
18 votes -
VPNFilter, malware that targets network infrastructure discovered in May, deployed against Ukranian water system.
7 votes -
Guccifer 2.0 slipped up and revealed he was a Russian intelligence officer
6 votes -
Sabotage laws give Australian PM Peter Dutton new powers over energy, port facilities
0 votes -
npm package "eslint-scope" compromised, npm is invalidating all login tokens created before 2018-07-12 12:30 UTC
16 votes -
Chinese hackers breach Australian National University, putting national security at risk
5 votes