Karl Voit :emacs: :orgmode: · @publicvoit
2104 followers · 15975 posts · Server graz.social
LisPi · @lispi314
648 followers · 13434 posts · Server mastodon.top
Obi Łan Łąki Kenobi · @kmic
187 followers · 41606 posts · Server qoto.org
teufelernie · @teufelernie
170 followers · 603 posts · Server norden.social

ist wohl, wenn man dieses Internet bei diversen Adressen mal mit dem Useragent „docker“ scannt.

Grow up, folks! Setzt Passwörter auf eure Registrys. Heftig…

„Ja, aber da ist nichts relevantes drin“

🤦🏼‍♂️

#securitybyobscurity

Last updated 1 year ago

Rename all files without file extensions

#securitybyobscurity

Last updated 1 year ago

LisPi · @lispi314
456 followers · 9171 posts · Server mastodon.top
Philipp · @derfopps
97 followers · 826 posts · Server digitalcourage.social

Stell dir vor, du besitzt ein Auto eines relativ weit verbreiten Modells, und jetzt haben Leute einen Weg gefunden, es zu entsperren und wegzufahren. Patches nicht möglich, weil der Hersteller auf gesetzt und Authentifizierung gar nicht vorgesehen hat. Unangenehm.
golem.de/news/can-spoofing-die

#canbus #toyota #securitybyobscurity

Last updated 1 year ago

LisPi · @lispi314
370 followers · 5571 posts · Server mastodon.top

@torrentfreak Relying on infrastructure seems like a much bigger planning flaw than any amount of sharing publicly.

Relying on secrecy means that your entire infrastructure's functionality & design is dependent on and so is irremediably brittle.

#clearnet #securitybyobscurity

Last updated 1 year ago

Josua · @josuagrw
173 followers · 643 posts · Server todon.eu

@marianisoehartono exactly, there is bascially no way to authenticate myself except through (a) a previously set up mechanism or (b) a replacement screen. To me this is just . Because I would rather not accidentally delete my data (afterall the whole point is to retrieve my data), I gave up and ordered a very cheap LCD. It's a lot cheaper than the original OLED display. I'm just very disappointed that the devs really implemented no other way to authenticate a user

#securitybyobscurity #android

Last updated 1 year ago

Falk Appel · @FalkAppel
74 followers · 129 posts · Server digitalcourage.social

There is a special place in hell for people that block pasting data in password fields or login names...

#securitybyobscurity

Last updated 1 year ago

Cymaphore · @Cymaphore
33 followers · 110 posts · Server techhub.social

TL;DR: Wir haben ein Schloss am Serverraum. Wir müssen nicht das Türschild abschrauben.

Erklärung:

Der Verfassungsschutz beschwert sich, dass zu viele Informationen über Infrastruktur frei zugänglich ist.

Das eigentliche Problem aber benennen sie nicht. Das Problem ist nämlich nicht OpenData, sondern das man Infrastruktur möglichst so aufbauen sollte, dass es egal ist, wenn jemand die Struktur kennt.

heise.de/news/Verfassungsschut

#opendata #securitybyobscurity

Last updated 2 years ago

· @tpa
129 followers · 178 posts · Server mas.to

Egad. Another breach? Or, I guess, the last one was a lot worse than originally disclosed?

The last time this happened, I tried to switch to ... but they wouldn't let me use a long password. At the time, they capped password length at 12 letters and numbers.

Been on since. I have few illusions that it's secure, but maybe will give me the tiniest advantage just this once.

#securitybyobscurity #vaultwarden #dashlane #lastpass

Last updated 2 years ago

HB9KNS · @hb9kns
21 followers · 48 posts · Server mastodon.radio

Oh those stupid Wifi networks, blocking all ports except for 80 and 443! Forcing me to get to one of my machines by tunneling through my other server running an sshd on port 443.

#securitytheater #securitybyobscurity

Last updated 2 years ago

Kjell 🐧:arch: :golang: · @jinxd
112 followers · 400 posts · Server fosstodon.org

Find two faults: To access the (new) bank account, kid had to a) install an 2fa app and the mobile bank app. Now to activate the 2fa, we needed an activation code, and a password. Where do they send that? Email and SMS.

#securitybyobscurity

Last updated 2 years ago

mirk0dex :gnulightened: · @Mirk0dex
60 followers · 825 posts · Server social.linux.pizza

Linux kernel source code apparently just got leaked by 4Chan hackers - read more on my website: mirkodi.tech/linux-source-code.

#hackers #4chan #linuxkernel #securitybyobscurity #news

Last updated 2 years ago

· @bojkotiMalbona
111 followers · 1137 posts · Server infosec.exchange

If you visit an archived page on webarchive.library.unt.edu which contains phone numbers, and you copy-paste a phone number, the digits are reversed so you end up pasting the wrong number. Of course if you scrape their site you’re likely to figure that out and your script can simply reverse the digits. This only inconveniences humans not bots. .

#bbb #securitybyobscurity

Last updated 2 years ago

· @bojkotiMalbona
111 followers · 1137 posts · Server infosec.exchange

redirects users to a ".well-known/captcha" link using "meta http-equiv" in the body instead of a normal 301/302 server redirect & instead of giving a 403 status, it gives a 200. E.g., run this:

curl --ssl --socks4a 127.0.0.1:9050 -L -w $'\n''(effective URL => "%{url_effective}")' 'samsonbanking.com/'

It seems they are trying to conceal their detection of bots from bots. But it's just another thing for the bot to check.

Is this an example of ?

#Siteground #tor #securitybyobscurity

Last updated 3 years ago

Doc Edward Morbius ⭕​ · @dredmorbius
2071 followers · 14632 posts · Server toot.cat

Expanding this further, you might also frame this as surveillance by obscurity.

Or the whole suite of information-monopoly vices: surveillance, censorship, disinformation, propaganda, manipulation.

joindiaspora.com/posts/7bfcf17

All rely on a level of indirection between the target and the attacker, and on systems whose malicious behaviour is brokered by a not-immediately-apparent flaw.

#securitybyobscurity #InsecurityByObscurity #SurveillanceByObscurity #monopoly #surveillance

Last updated 3 years ago

Doc Edward Morbius ⭕​ · @dredmorbius
2071 followers · 14632 posts · Server toot.cat

We’ve been thinking about it wrong: The norm has been Insecurity by obscurity

The Crypto AG CIA backdoor story (2020) clarifies to me much of the neverending flood of “outlaw strong crypto” thinkpieces and “lawful access” (a/k/a mandated backdoors) proposals.

I realised today that the whole discussion was missing a major insight: For much of the Cold War period, the operational standard has been instead ...

joindiaspora.com/posts/b596219

#securitybyobscurity #InsecurityByObscurity

Last updated 3 years ago

Doc Edward Morbius ⭕​ · @dredmorbius
2071 followers · 14632 posts · Server toot.cat

@natecull Crypto AG clarifies to me much of the "outlaw strong crypto" and "lawful access" (a/k/a mandated backdoors) proposals.

Thinking about that earlier today (before seeing your toot), I realised that the whole discussion was missing a major insight.

For much of the Cold War period, the operational standard has been instead

Crypto AG was an allegedly secure system which was, obscure to the public, insecure. And that insecurity (along with fear, suprise, ruthless efficiency, and an almost fanatical devotion to the Pope), seems to have been a key element of US (and ) surveillance capabilities from the 1950s onward. (I'm aware Crypto AG's role under the CIA begain ~1970.)

But yeah, insecurity by obscurity as an operational norm. Describes much of the present Web as well.

@enkiv2

#securitybyobscurity #InsecurityByObscurity #fiveeyes

Last updated 3 years ago