-
17 votes
-
WinRAR zero-day exploited since April to hack trading accounts
31 votes -
A new weapon in the war against robocalls
42 votes -
ProtonMail complied with 5,957 data requests in 2022 – still secure and private?
24 votes -
Unknown tracker alert on Android
I just received an Unknown Tracker alert on my Pixel 7 running Android 14 beta 5 for an Apple air tag that was on my son in laws key chain as I had borrowed his car. I heard this was coming but...
I just received an Unknown Tracker alert on my Pixel 7 running Android 14 beta 5 for an Apple air tag that was on my son in laws key chain as I had borrowed his car.
I heard this was coming but didn't expect it so soon!
Quite impressed with both the information given and the general advice and steps to take offered.
The first notification was "Tracker Travelling With You: Unknown Apple air tag detected. The owner can see your location."
Touching "more info" then shows a map of where the tracker has been with me and the option to make the tracker play a sound to help locate it, with a note that the owner won't know you've done that.
Then more advice and options:
- If you feel unsafe, get help.
- Get and save tracker info
- Disable the tracker (with a how-to guide on battery removal)
And a ”need more help" link.
As I said, I had heard about this coming but was pleasantly surprised at how good it was and the general advice and help offered up.
Nice seeing things like this done right.
34 votes -
FedFingerprinting: A federated learning approach to website fingerprinting attacks in Tor networks
6 votes -
Hackers exploited a zero-day flaw in Ivanti's software undetected for at least three months, US and Norwegian cybersecurity agencies warn
14 votes -
You've got Mali: UK Ministry of Defence accidentally emails Russia ally
18 votes -
On attestation on the web and why this could threaten the open web
13 votes -
How Chinese surveillance methods are going global
12 votes -
Microsoft lost its keys, and the US government got hacked
25 votes -
Mastodon social network patches critical flaws allowing server takeover
18 votes -
NeverSSL
12 votes -
Apple fixes zero-days used to deploy Triangulation spyware via iMessage
8 votes -
How to keep a secret in Python apps
5 votes -
Security expert defeats Lenovo laptop BIOS password with a screwdriver
13 votes -
The US is openly stockpiling dirt on all its citizens
25 votes -
Google Authenticator now supports Google Account synchronization
After 11 years of life, Google Authenticator has added cloud backups for OTP keys in version 6.0. Google Security Blog: Google Authenticator now supports Google Account synchronization This is...
After 11 years of life, Google Authenticator has added cloud backups for OTP keys in version 6.0.
Google Security Blog: Google Authenticator now supports Google Account synchronization
This is surprising news to me, because historically Authenticator had no way to backup keys by design. Here's a 2017 quote from a Google engineer who maintains Authenticator:
There is by design NO account backups in any of the apps. [source]
This design choice always made sense to me, as the point of 2FA is that you've got (1) something you know, and (2) something you have. The second factor should be tied to a physical device. If you lose the physical device, the second factor should be gone, and you'll need to use one of those 10-ish backup codes that we all definitely keep somewhere safe. I'm quite befuddled that Google is reversing this design choice and walking back their previously strong, security-centric design for the sake of user convenience in the case of a lost phone. I used to advise my friends and family to choose Google Authenticator over Authy for this specific reason.
If you want further reading, here's a PCWorld article with an altogether different tone than Google's announcement: Google Authenticator’s long-awaited cloud 2FA feature carries hidden risk
11 votes -
Should I be using a passkey?
I saw all the hype about Google's new passkey rollout on Hacker News and Ars Technica in the past month, and have even read an article stating that, paraphrased, "I should start using passkeys...
I saw all the hype about Google's new passkey rollout on Hacker News and Ars Technica in the past month, and have even read an article stating that, paraphrased, "I should start using passkeys immediately, even if the tech is not all the way there yet."
Some questions:
- Are you using passkeys currently? Which provider?
- Is there a fear of vendor lock-in (looking at you, Apple) or ditching the product in the future (looking at you, Google)?
- Any other concerns I should be aware of, e.g. what happens if my phone gets run over by a bulldozer?
25 votes -
Amazon Ring cameras were used to spy on customers
32 votes -
Stop silly security awards
6 votes -
Generate a secure password using lyrics from Kenny Loggins. It's funny and useful!
4 votes -
SolarWinds: The untold story of the boldest supply-chain hack ever
7 votes -
Google's adoption of passkeys (security blog article)
11 votes -
NSO group’s Pegasus spyware returns in 2022 with a trio of iOS 15 and iOS 16 zero-click exploit chains
4 votes -
Upgrade your LUKS key derivation function
7 votes -
Prompt injection: What’s the worst that can happen?
8 votes -
AI can fool voice recognition used to verify identity by Centrelink and Australian tax office
11 votes -
A flock of chickens, held for ransom — Growing cyberattacks on Canada's food system threaten disaster
9 votes -
Belgium launches nationwide safe harbor for ethical hackers
10 votes -
Danish parliament urges lawmakers and employees to remove TikTok on work phones as a cybersecurity measure, saying “there is a risk of espionage”
4 votes -
Reddit was hacked
16 votes -
SolarWinds and market incentives
8 votes -
What we learned from building GovSlack
6 votes -
Anker finally comes clean about its Eufy security cameras
23 votes -
Three lessons from Threema: Analysis of a secure messenger
7 votes -
Comcast Xfinity accounts hacked in widespread 2FA bypass attacks
9 votes -
Anker’s Eufy lied to us about the security of its security cameras. Despite claims of only using local storage, Eufy has been uploading identifiable footage to the cloud.
18 votes -
Never-before-seen malware is nuking data in Russia’s courts and mayors’ offices. CryWiper masquerades as ransomware, but its real purpose is to permanently destroy data.
12 votes -
LastPass recent security incident
7 votes -
Twitter’s SMS two-factor authentication is melting down
21 votes -
Revealed: US Military bought mass monitoring tool that includes internet browsing, email data
11 votes -
During his testimony before the Senate Judiciary Committee, Peiter "Mudge" Zatko claims Twitter only has live production environment that all engineers can access
@Benjamin Powers: Mudge walking through Twitter's construction - they only have live production environment, no test environment.
17 votes -
Prompt injection attacks against GPT-3
14 votes -
Bitwarden raises $100 million from PSG Equity
12 votes -
Cloudflare blocks Kiwi Farms
36 votes -
iOS 12.5.6 rolling out to older iPhone and iPad devices with important security fixes
6 votes -
Erik Prince wants to sell you a “secure” smartphone that’s too good to be true
12 votes -
Ex-Twitter exec blows the whistle, alleging reckless and negligent cybersecurity policies
13 votes -
Plex breach exposes usernames, emails, and encrypted passwords
12 votes