-
10 votes
-
New 2021 GPS accuracy issue impacting some Garmin, Suunto, other GPS devices
12 votes -
How human activity threatens the world’s carbon-rich peatlands
2 votes -
Amid warnings of surging worldwide poverty, planet's 500 richest people added $1.8 trillion to combined wealth in 2020
9 votes -
Plan to straighten out entire life during weeklong vacation yields mixed results
36 votes -
Both sides claim victory in massive EVE Online battle
17 votes -
Awesome Games Done Quick 2021 event schedule (Jan 3 - 10)
20 votes -
WakaTime 2020 Programming Stats
4 votes -
US passes ‘historic’ anti-corruption law that effectively bans anonymous shell companies
26 votes -
New type of atomic clock keeps time even more precisely: The design, which uses entangled atoms, could help scientists detect dark matter and study gravity's effect on time
13 votes -
How were you as a child/young-person?
Did you obey your parents? Tortured small animals? Did we’ll school? Popular or outcast? Bully our bullied?
10 votes -
I spent a year deleting my address online, then it popped up on Bing
20 votes -
Beyond Cyberpunk: Towards a Solarpunk future
24 votes -
Linux for Apple Silicon effort kicks off
24 votes -
Saturday Security Brief
Saturday Security Brief Topics: Attack Surface Management, Active iMessage exploit targetting journalists, Academic research on unique EM attack vectors for air-gapped systems. Any feedback or...
Saturday Security Brief
Topics: Attack Surface Management, Active iMessage exploit targetting journalists, Academic research on unique EM attack vectors for air-gapped systems.
Any feedback or thoughts on the experience of receiving and discussing news through this brief or in general are welcome. I'm curious about this form of staying informed so I want to experiment. (Thanks again for the suggestion to post the topics as comments.)
Attack Surface Management
This concept is about ensuring that your network is equipped to handle the many issues that arise from accommodating various "Servers, IoT devices, old VPSs, forgotten environments, misconfigured services and unknown exposed assets" with an enterprise environment. Some of the wisdom here can be applied better think about protecting our personal networks as well. Outdated phones, computers, wifi extenders, and more can be a foothold for outside attackers to retain persistant access. Consider taking steps to migigate and avoid potential harm from untamed devices.
Consider putting certain devices on the guest network if your router supports doing so and has extra rules for devices on that network so they can't cause damage to your other devices directly.
"A report from 2016 predicted that 30% of all data breaches by 2020 will be the result of shadow IT resources: systems, devices, software, apps and services that aren’t approved, and in use without the organization’s security team’s knowledge. But shadow IT isn’t the only area where security and IT teams face issues with tracking and visibility."
Attack Surface Management: You Can’t Secure What You Can’t See ~ Security Trails
Multiple Journalists Hacked with ‘Zero-Click’ iMessage Exploit
Mobile spyware is continuing to evolve and tend towards professional solutions. Recently this technology has been abused to conduct espionage on journalists of major networks. Where once these exploits typically required some mistaken click from the user, new developments are allowing their activities without any trace or requiring interaction from the target.
"NSO Group’s Pegasus spyware is a mobile phone surveillance solution that enables customers to remotely exploit and monitor devices. The company is a prolific seller of surveillance technology to governments around the world, and its products have been regularly linked to surveillance abuses."
"In July and August 2020, government operatives used NSO Group’s Pegasus spyware to hack 36 personal phones belonging to journalists, producers, anchors, and executives at Al Jazeera. The personal phone of a journalist at London-based Al Araby TV was also hacked."
"The journalists were hacked by four Pegasus operators, including one operator MONARCHY that we attribute to Saudi Arabia, and one operator SNEAKY KESTREL that we attribute to the United Arab Emirates."
"More recently, NSO Group is shifting towards zero-click exploits and network-based attacks that allow its government clients to break into phones without any interaction from the target, and without leaving any visible traces."
Security researchers exfiltrate data from air-gapped systems by measuring the vibrations made by PC fans.
Besides this potential exploit the article mentions past research done by Guri and his team which is worth checking out, like:
-
LED-it-Go - exfiltrate data from air-gapped systems via an HDD's activity LED
-
AirHopper - use the local GPU card to emit electromagnetic signals to a nearby mobile phone, also used to steal data
-
MAGNETO & ODINI - steal data from Faraday cage-protected systems
-
PowerHammer - steal data from air-gapped systems using power lines
-
BRIGHTNESS - steal data from air-gapped systems using screen brightness variations
"Academics from an Israeli university have proven the feasibility of using fans installed inside a computer to create controlled vibrations that can be used to steal data from air-gapped systems."
Academics steal data from air-gapped systems using PC fan vibrations ~ Zdnet
Good Practices
"Hundreds of popular websites now offer some form of multi-factor authentication (MFA), which can help users safeguard access to accounts when their password is breached or stolen. But people who don’t take advantage of these added safeguards may find it far more difficult to regain access when their account gets hacked, because increasingly thieves will enable multi-factor options and tie the account to a device they control. Here’s the story of one such incident."
16 votes -
-
Baby Yoda's message
1 vote -
Penelope Scott - Cigarette Ahegao (2020)
6 votes -
The history of Super Mario Bros. 2 world records
4 votes -
The illusion only some can see
12 votes -
Body found in Norwegian landslide – rescuers and dog handlers began a risky ground search for ten people missing in a hillside collapse
5 votes -
Young Marble Giants - Final Day (1980)
3 votes -
January 1, 2021 is Public Domain Day: Works from 1925 are open to all!
28 votes -
Friday Security Brief
Friday Security Brief This release is trial for a weekly security brief compiled from trusted sources that encourage a general awareness of cyber security issues. I'm still not sure about how to...
Friday Security Brief
This release is trial for a weekly security brief compiled from trusted sources that encourage a general awareness of cyber security issues. I'm still not sure about how to do this so any thoughts or feedback will be appreciated.
Brexit deal mandates a limit to security standards
"In what is surely an unthinking cut-and-paste issue, page 921 of the Brexit deal mandates the use of SHA-1 and 1024-bit RSA:"
Brexit Deal Mandates Old Insecure Crypto Algorithms ~ Schneier on Security
FBI Warns of Hijacked Security Devices being exploited for Swatting
"Stolen email passwords are being used to hijack smart home security systems to “swat” unsuspecting users, the Federal Bureau of Investigation warned this week. The announcement comes after concerned device manufacturers alerted law enforcement about the issue."
FBI Warn Hackers are Using Hijacked Home Security Devices for Swatting ~ Threatpost
A look back at some email attacks of 2020
"In 2020, our spam folders bulged with malware-laced emails, phishing lures linking to ransomware schemes, impersonation attacks, spoofed brand and fake domain missives, and dubious requests from legit-sounding companies. So, what defined 2020 in spam?"
Inbox Attacks: The Miserable Year (2020) That Was ~ Threatpost
SolarWinds hackers accessed Microsoft source code
"The hackers behind the SolarWinds supply chain attack managed to escalate access inside Microsoft's internal network and gain access to a small number of internal accounts, which they used to access Microsoft source code repositories, the company said on Thursday."
SolarWinds hackers accessed Microsoft source code ~ Zdnet
CISA updates SolarWinds guidance
"The US Cybersecurity and Infrastructure Security Agency has updated its official guidance for dealing with the fallout from the SolarWinds supply chain attack.
In an update posted late last night, CISA said that all US government agencies that still run SolarWinds Orion platforms must update to the latest 2020.2.1HF2 version by the end of the year."
CISA updates SolarWinds guidance, tells US govt agencies to update right away
24 votes -
Susan Schneider Williams watched her husband suffer with undiagnosed Lewy body dementia before he killed himself in 2014. Her new film tries to educate others about the condition
7 votes -
A monster wind turbine is upending an industry
30 votes -
Hi, how are you? Mental health support and discussion thread (January 2021)
This is a monthly thread for those who need it. Vent, share your experiences, ask for advice, talk about how you are doing. Let's make this a compassionate space for all who may need one.
18 votes -
What have you been listening to this week?
What have you been listening to this week? You don't need to do a 6000 word review if you don't want to, but please write something! If you've just picked up some music, please update on that as...
What have you been listening to this week? You don't need to do a 6000 word review if you don't want to, but please write something! If you've just picked up some music, please update on that as well, we'd love to see your hauls :)
Feel free to give recs or discuss anything about each others' listening habits.
You can make a chart if you use last.fm:
http://www.tapmusic.net/lastfm/
Remember that linking directly to your image will update with your future listening, make sure to reupload to somewhere like imgur if you'd like it to remain what you have at the time of posting.
7 votes -
What did you do this week?
As part of a weekly series, these topics are a place for users to casually discuss the things they did — or didn't do — during their week. Did you accomplish any goals? Suffer a failure? Do...
As part of a weekly series, these topics are a place for users to casually discuss the things they did — or didn't do — during their week. Did you accomplish any goals? Suffer a failure? Do nothing at all? Tell us about it!
9 votes -
Why didn't the Virginias reunite?
4 votes -
The design of the Roland Juno Oscillators
8 votes -
Historic change to Advance Australia Fair, Australia's national anthem, in the 'spirit of unity'
7 votes -
Happy New Years! Feliz Año! Guter Rutsch und Gutes Neues!!
Thats all the languages I know. Please expand! I wish you all a happy new years and that next year is gonna be (even) better ;-) I'm really greatful to be part of this community, one of the...
Thats all the languages I know. Please expand! I wish you all a happy new years and that next year is gonna be (even) better ;-)
I'm really greatful to be part of this community, one of the brigtest spots of friendlyness and respect in the wide internet :-) thank you all!
19 votes -
The dark night sky paradox
7 votes -
ABBA - Happy New Year (1980)
6 votes -
MF DOOM has passed at 49
26 votes -
Shamelessness as a strategy
13 votes -
The news you may have missed in 2020
8 votes -
Tildes Game Giveaway Thread: Welcoming a New Year
Important: This will be a noisy thread. If you do not wish to see it in your feed, please use the "Ignore" feature to hide it! 2021 Enough has been said about 2020 — let’s put some good out into...
Important: This will be a noisy thread. If you do not wish to see it in your feed, please use the "Ignore" feature to hide it!
2021
Enough has been said about 2020 — let’s put some good out into the world in the form of game giveaways as we welcome a new and hopefully brighter year!
Gifters
Post your available games, the platform and method of delivery, rules for your giveaways (e.g. first-come first-serve, random draw, etc.), and any additional info or requirements. Feel free to get creative!
Giftees
Request giveaways according to the gifter's guidelines!
Rules
Anyone can choose to be a gifter, giftee, or both! Giveaway rules are set by individual gifters, but there are handful of guidelines everyone should follow:
-
No grey market keys! Only giveaway games from reputable sources. If you're not sure what this means, please ask.
-
Requests for games should be done in the thread, but if the gift is a key, those should be delivered by PMs only. Please don't post keys publicly, even obfuscated ones.
28 votes -
-
US consumes more green energy than coal for first time since 1885
15 votes -
Nineteen weird things you can watch drop online if you stay home for New Year’s
7 votes -
Thirteen tech luminaries we lost in 2020
3 votes -
What are you reading these days?
What are you reading currently? Fiction or non-fiction or poetry, any genre, any language! Tell us what you're reading, and talk about it a bit.
14 votes -
Fitness Weekly Discussion
What have you been doing lately for your own fitness? Try out any new programs or exercises? Have any questions for others about your training? Want to vent about poor behavior in the gym? Started...
What have you been doing lately for your own fitness? Try out any new programs or exercises? Have any questions for others about your training? Want to vent about poor behavior in the gym? Started a new diet or have a new recipe you want to share? Anything else health and wellness related?
5 votes -
Trump took a wrecking ball to media credibility—can Biden repair it?
7 votes -
India's huge farmer protests, explained
7 votes -
Iceland's innovations to reach net-zero – in pictures
16 votes -
Anthony Fauci sees US gaining control over pandemic by next autumn
5 votes -
‘Wonder Woman 1984’ is a massive hit on pirate sites after early HBO premiere
10 votes -
Jair Bolsonaro: 2020 person of the year in organized crime and corruption
8 votes -
Animation representing the global annual temperature anomaly over time, discretised by month, from 1880–2020
@Scott Duncan: Wait for it...Our planet is pulsing warmer and warmer. 2020 will serve as a stark reminder that our climate is continuing to rapidly change.Each bar of colour represents a month of global temperature as we loop through 140 years of data from 1880 to 2020.[THREAD] pic.twitter.com/geNg2kDeYd
13 votes