framapiaf.org est l'un des nombreux serveurs Mastodon indépendants que vous pouvez utiliser pour participer au fédiverse.
Un service Mastodon fourni par l'association d’éducation populaire Framasoft.

Administré par :

Statistiques du serveur :

1,4K
comptes actifs

#security

418 messages257 participants49 messages aujourd’hui

How to Protect Yourself From Phone Searches at the US #Border

Customs and Border Protection has broad authority to search travelers’ devices when they cross into the United States. Here’s what you can do to protect your digital life while at the US border.
#privacy #security #cbp #4thAmendment

wired.com/story/how-to-protect

WIRED · How to Protect Yourself From Phone Searches at the US BorderPar Lily Hay Newman

Deep dive into supply chain security with the latest Open Source Security podcast! Josh Bressers and Alan Pope unpack the power of Syft and Grype, and other tools focusing on Software Bills of Materials (SBOMs) and vulnerability scanning. They explore not just the what, but also the why behind some key open source projects in this space. Learn how these tools are evolving to give you deeper insights into your s... #OSS #Security #SBOM #VulnerabilityManagement #Syft #Grype opensourcesecurity.io/2025/202

A handbag belonging to the homeland #security secy #KristiNoem containing her passport, dept security badge & $3,000 in cash was stolen on Sunday night at a restaurant in Washington. [zero irony]

Noem confirmed the theft at the White House Easter Egg Roll on Monday morning.

DHS did not give specifics, but said it could confirm the details of a CNN article, which said that Noem’s bag also contained her driver’s license, medication, apartment keys & blank checks.

#law
nytimes.com/2025/04/21/us/poli

A handbag belonging to Kristi Noem, the secretary of the Department of Homeland Security, was stolen at a Washington restaurant on Easter.
The New York Times · Kristi Noem’s Bag, With Security Badge and $3,000, Is StolenPar Victor Mather
A répondu dans un fil de discussion

@jakub I understand, that's why I prefer things already packaged by my distro, they take care of that. And since it's just a internal tool, well, you can do a lot to minimize exposition, just like for your tool. I do agree that the #golang way is not the best for this; I wish there was an alternative, as in a static and a dynamic version of each tool, but I can't really expect that of my distro.

There is quite a bit of buzz related to CVE-2025-24054 which covers attackers causing victims to leak NTLM hashes if they open certain files or view certain directories. In short, this forces victims running Windows to make a connection to an attacker controlled SMB share.

Note: A patch was provided by Microsoft on March 11.

If you prevent SMB traffic from leaving your networks then you don't have to worry about this unless the attacker has already setup shop in your network. Like, patch anyway but, IMO, it would be a better use of your time to ensure that outbound SMB is blocked first. Don't forget to account for mobile devices that are off-network.

Reference:
Check Point - CVE-2025-24054, NTLM Exploit in the Wild
research.checkpoint.com/2025/c

Check Point Research · CVE-2025-24054, NTLM Exploit in the Wild - Check Point ResearchKey Points Introduction NTLM (New Technology LAN Manager) is a suite of authentication protocols developed by Microsoft to verify user identities and protect the integrity and confidentiality of network communications. NTLM operates through a direct client-server exchange known as the NTLM challenge/response mechanism, in which the server challenges the client to prove its identity without […]

Encryption is a cornerstone of security on the modern internet. In this video we dive into how it works and explain why it's so important.

This is especially crucial as many governments around the world are pushing to ban encryption and breach our fundamental right to privacy.

privacyguides.org/videos/2025/

I just read that credit cards are due to go 'numberless' by 2030. The familiar 16-digit number is going away to be replaced by a 'random number' that is created each time you want to pay for something.

I like the extra #security - no credit card number to steal - but what about convenience? Do I need to authorise every monthly subscription payment, every Amazon purchase and every PayPal transaction (in addition to the 2FA I already have on PayPal)? 🤷🏼‍♂️