HELP! This instance will close down in one month without funds.

*WORKING BEE*

We're donating 10 SOLID HOURS of VISUAL DESIGN WORK as pro-designers ready to work for a AUD$250+ donation for this great instance. No email pls, DMs only! *some work pictured

Help 'activism' open-worlds to those who need it.

BOOST to help a miracle happen. Maybe such miracles are only reserved for those with () "connections"?

@witchescauldron

#mitm #testfediverse

Last updated 1 year ago

Marcel SIneM(S)US · @simsus
222 followers · 5534 posts · Server social.tchncs.de

@jcbrand
We were wrong about the above — is not man-in-the-middled by CloudFlare…

It's 'd by

The landing and product pages were CloudGlare, and its seems CloudGlare palm the hapless Aussie to (sc)amazon, to watch and control the actual portal part of the site.

#BendigoBank #mitm #AmazonCloudfront #banking #Scamazon #scams #medibankwasamazoncloudfront #computerSaysNo #bankruns #orchestratedbankruns #australia #bitcoinnow

Last updated 1 year ago

LisPi · @lispi314
739 followers · 15851 posts · Server mastodon.top

@RecursiveElegance Not sure where in particular, most of my old resources seem to be gone now.

But generally for users it's an annoyance as its anti-bot measures are very user-hostile.

It also makes mandatory to enable in one's , which in general but especially in conjunction with is a hazard.

Depending on the settings used, it can also act as a general attacker.

#javascript #browser #JIT #security #mitm #tor

Last updated 1 year ago

Strypey · @strypey
2468 followers · 24998 posts · Server mastodon.nzoss.nz

Using CloudFlare and other corporate MitM "services" to protect your server against DDOS attacks? Looking for an ethical replacement? Cory Doctorow is using Deflect for pluralistic.net:

deflect.ca/

#ddos #mitm #cloudflare #deflectca

Last updated 1 year ago

@boingbot
The 'operative word', or phrase here, being "UK forces"?

Other , totes okay.

Speaking of backdoors, your instance, mastodon.cloud has been attacked by for years.

#backdoors #mitm #cloudflare

Last updated 1 year ago

Billy Smith · @BillySmith
424 followers · 7612 posts · Server social.coop

BT faced this in 2000/2001, when it was found that people using BT as an ISP were having the adverts changed by an attack.

BT were replacing the advverts with their own, breaking the ( limited ) Common Carrier laws in the UK, as well as the laws on computer-hacking that were UK law at that time.

According to UK case-law and precedent, every single advert would be a separate charge.

It would have bankrupted BT.

#mitm

Last updated 1 year ago

Marcel Waldvogel · @marcel
778 followers · 505 posts · Server waldvogel.family

Certificate Authorities are the backbone of in the Internet and the protocol is the workhorse powering Let's Encrypt & Co.

A chinese CA reseller finds an bug in an ACME client that allows CAs (maybe also Man In The Middle ?) to execute arbitrary code on (millions? of) client machines.

Instead of reporting this major security risk, they start using it to provide commercial CA services over ACME. And are convinced they are the good guys🥴

Update now!
github.com/acmesh-official/acm

#CA #trust #acme #mitm

Last updated 1 year ago

@gabriel @victor
Always nice to see the icon being used! :)

We never thought was a particularly viable option for us over and above . We are not surprised to hear that they have questionable backers, or are 'd, given they seemed to do a lot via the matrix.org domain — a 'd service.

#matrix #xmpp #mitm #cloudflare

Last updated 1 year ago

neto consulting · @neto
4 followers · 102 posts · Server mastodontech.de

Ein Man-in-the-Middle-Angriff bezeichnet einen Cyber-Angriff, bei dem sich ein Hacker zwischen zwei Zielpersonen einschaltet, z. B. beim Lesen von E-Mails, Online-Banking, Einloggen auf Plattformen etc.
Dadurch können Daten unbemerkt abgegriffen oder verändert werden.
Die Übersicht mit unserem Glossar finden Sie auf unserer Website: news.neto.consulting/#Glossar

#Glossar #cybersecurity #cyberangriff #itsicherheit #maninthemiddleattack #hacker #mitm

Last updated 1 year ago

This may sound controversial but…

For suppressed people who value basic , knowing that almost all in are being man-in-the-middled () by the likes of , CloudFlare et al. We propose a weirdly radical solution…

Start using .

Call the bank and ask for a . The current attackers cannot stop us from paying with a cheque and we can sign with a message of our choosing. *wink

#digitalsovereignity #banks #australia #mitmd #amazon #cheques #chequebook #mitm #censorshipresistance #cloudflare #stopcagemafia

Last updated 1 year ago

Tarnkappe.info · @tarnkappeinfo
2042 followers · 4384 posts · Server social.tchncs.de
po̊lættïx · @polettix
70 followers · 1378 posts · Server octodon.social
Lennart Hengstmengel · @lhengstmengel
108 followers · 435 posts · Server mastodon.nl

So Github changed their RSA SSH host key. If you get this warning message, don't freak out (like I did for a short moment). But do check the fingerprint before updating your known_hosts file.

github.blog/2023-03-23-we-upda

#security #mitm #ssh #rsa #github

Last updated 1 year ago

Emory L. · @emory
155 followers · 1070 posts · Server soc.kvet.ch

@h3artbl33d it never stops driving me crazy that people pay shady people to their traffic to protect their privacy 🙃

#mitm

Last updated 1 year ago

Chema Alonso :verified: · @chemaalonso
789 followers · 178 posts · Server ioc.exchange
Daniel · @wall_e
26 followers · 149 posts · Server ioc.exchange

So in conclusion:

A company that seems to actively try to hide who they are, markets a new browser to young german audiences via TikTok, with the promise of free access to Video content.

They say they're using a VPN to secure their users' traffic, but instead just proxy it through a shadowsocks server under their control.

On top of that, they do not show any indicators of whether you're using HTTPS in the Browser UI and even show no errors or warning messages for any of the certificate errors listed on badssl.com.

In my (admittedly, now very tired) mind this is the perfect setup for a large scale attack, no?

Am I completely crazy or is this a bit worrying?

@linuzifer @zerforschung [6/6]

#mitm

Last updated 1 year ago

Daniel · @wall_e
26 followers · 149 posts · Server ioc.exchange

So in conclusion:

A company that seems to actively try to hide who they are, markets a new browser to young german audiences via TikTok, with the promise of free access to Video content.

They say they're using a VPN to secure their users' traffic, but instead just proxy it through a shadowsocks server under their control.

On top of that, they do not show any indicators of whether you're using HTTPS in the Browser UI and even show no errors or warning messages for any of the certificate errors listed on badssl.com.

In my (admittedly, now very tired) mind this is the perfect setup for a large scale attack, no?

Am I completely crazy or is this a bit worrying?

@linuzifer
@zerforschung
[6/6]

#mitm

Last updated 1 year ago

Michael Paepcke · @paepcke
7 followers · 39 posts · Server infosec.exchange