GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices tagged with security

  1. Embed this notice
    The Japan Times (thejapantimes@mastodon.social)'s status on Monday, 22-Dec-2025 10:11:23 JST The Japan Times The Japan Times

    The world isn’t becoming multipolar — it’s becoming "multisphere." Overlapping power, blurred norms and rising coercion are redefining global risk in 2026. https://www.japantimes.co.jp/commentary/2025/12/22/world/strategic-outlook-geopolitics-2026/?utm_medium=Social&utm_source=mastodon #commentary #worldnews #geopolitics #china #us #defense #sanaetakaichi #security #ukraine #europe

    In conversation about a day ago from mastodon.social permalink

    Attachments


  2. Embed this notice
    Morten Linderud (foxboron@chaos.social)'s status on Saturday, 20-Dec-2025 18:46:37 JST Morten Linderud Morten Linderud

    TIL;
    You can use `systemd-creds` to store wireguard private keys in `systemd.netdev` files.

    #systemd #wireguard #security #til

    In conversation about 3 days ago from chaos.social permalink
  3. Embed this notice
    Aral Balkan (aral@mastodon.ar.al)'s status on Friday, 19-Dec-2025 18:45:33 JST Aral Balkan Aral Balkan

    Node.js devs, so picture this: you run npm install and you get a bunch of packages with audit errors.

    The one thing I want to know at that point: what’s the root package that these dependencies belong to. (Running npm audit fix is a last resort as I don’t like it fiddling around with the dependencies of nested packages.)

    It’s also not a straightforward thing to do, but it’s nothing jq and a bit of piping can’t fix:

    npm audit --json | jq -r '.vulnerabilities[].name' | xargs -n1 npm ls

    If you’re using fish shell, add an abbr(aviation) or an alias to that with a name like npm-audit-tree and you’re golden ;)

    Enjoy 💕

    #NodeJS #npm #audit #security #JavaScript #JSON #jq #xargs #dev #tip

    In conversation about 4 days ago from mastodon.ar.al permalink
  4. Embed this notice
    Damage Control Blog (damagecontrolblog@mastodon.social)'s status on Thursday, 18-Dec-2025 11:40:03 JST Damage Control Blog Damage Control Blog

    Random Roar: Your Personal Recaps Should Alarm You
    Merry Christmas! Here's what we have on you!
    https://www.dcgameblog.com/2025/12/random-roar-your-personal-recaps-should-alarm-you/
    #DataCollection #RandomRoar #security

    In conversation about 5 days ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/115/737/701/698/261/304/original/55fd07ad7a772032.jpg
    2. Domain not in remote thumbnail source whitelist: www.dcgameblog.com
      Random Roar: Your Personal Recaps Should Alarm You
      from Joseph Daniels
      Merry Christmas! Here's what we have on you!
  5. Embed this notice
    Aral Balkan (aral@mastodon.ar.al)'s status on Thursday, 18-Dec-2025 00:25:48 JST Aral Balkan Aral Balkan

    Just updated Node Pebble to support latest release version of Let’s Encrypt’s Pebble testing server.

    https://codeberg.org/small-tech/node-pebble

    Enjoy!

    💕

    #LetsEncrypt #Pebble #testing #tls #ssl #security #NodeJS #JavaScript

    In conversation about 6 days ago from mastodon.ar.al permalink
  6. Embed this notice
    Nonilex (nonilex@masto.ai)'s status on Tuesday, 16-Dec-2025 03:24:10 JST Nonilex Nonilex
    in reply to

    #Zelensky said on Sunday that the #US, #Europe & other partners' #security guarantees instead of #NATO membership were a compromise on #Ukraine's side.

    "From the very beginning, Ukraine's desire was to join NATO, these are real security guarantees. Some partners from the US & Europe did not support this direction," he said in answer to questions from reporters in a WhatsApp chat.

    #geopolitics #Russia #war #StandWithUkraine

    In conversation about 8 days ago from masto.ai permalink
  7. Embed this notice
    Nonilex (nonilex@masto.ai)'s status on Tuesday, 16-Dec-2025 03:24:09 JST Nonilex Nonilex
    in reply to

    "Thus, today, bilateral #security guarantees between #Ukraine & the #US, Article 5-like guarantees for us from the US, & security guarantees from European colleagues, as well as other countries — #Canada, #Japan — are an opportunity to prevent another Russian invasion," #Zelensky said.

    "And it is already a compromise from our part," he said, adding that the security guarantees should be legally binding.

    #geopolitics #Europe #Russia #war #StandWithUkraine

    In conversation about 8 days ago from masto.ai permalink
  8. Embed this notice
    heise Security (heisec@social.heise.de)'s status on Tuesday, 16-Dec-2025 02:12:42 JST heise Security heise Security

    BSI checkt E-Mail-Programme

    Das Bundesamt für Sicherheit in der Informationstechnik hat getestet, wie sicher E-Mail-Programme sind. Die sind offenbar ok.

    https://www.heise.de/news/BSI-checkt-E-Mail-Programme-11115384.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon

    #BSI #EMail #IT #Journal #Security #Test #news

    In conversation about 8 days ago from social.heise.de permalink
  9. Embed this notice
    Sune Auken (suneauken@mastodon.world)'s status on Friday, 12-Dec-2025 11:10:58 JST Sune Auken Sune Auken

    Much as I admire American friends, colleagues and allies, this and then this again.

    #InternationalPolitics #Security #UsPol #EUPol

    https://www.readtheline.ca/p/matt-gurney-we-will-never-fucking

    In conversation about 11 days ago from mastodon.world permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: images.unsplash.com
      Matt Gurney: 'We will never fucking trust you again'
      from Matt Gurney
      Some blunt talk for our American neighbours at the Halifax International Security Forum.
  10. Embed this notice
    Netscape Navigator (netscapenavigator@social.vivaldi.net)'s status on Friday, 12-Dec-2025 09:30:56 JST Netscape Navigator Netscape Navigator

    RE: https://social.vivaldi.net/@NetscapeNavigator/115671312844470695

    ⚠️ Please double-check to make sure your site is using the latest Fediverse software:

    Misskey: 2025.12.0
    Mastodon: 4.5.3
    PeerTube: 8.0.0
    PixelFed: 0.12.6
    Loops: 1.0.0 Beta 5
    Mbin: 1.8.4
    Lenny: 0.19.14
    Akkoma: 2025.12
    Sharkey: 2025.4.4
    Pleroma: 2.9.1

    #Fediverse #ActivityPub #Mastodon #Misskey #PixelFed #PeerTube #Sharkey #Loops #Akkoma #Pleroma #Mbin #Lemmy #InfoSec #Security #Hack #Foss #OpenSource #Linux #SystemAdmin #Administrator #WebMaster #ITTech #FediAdmin

    In conversation about 11 days ago from social.vivaldi.net permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Netscape Navigator (@NetscapeNavigator@vivaldi.net)
      from Netscape Navigator
      5 Fediverse sites have been hacked due to running outdated software. Please take a moment to ensure that your instance of Mastodon, Misskey, PeerTube, PixelFed, or any other Fediverse platform is fully up-to-date. It may also be wise to log into your server and update your operating system. Debian / Ubuntu servers: sudo apt update sudo apt dist-upgrade sudo reboot Fedora / CentOS / Red Hat / Alma Linux: sudo dnf update --refresh sudo dnf upgrade sudo reboot If you update your OS, your server will be briefly offline during the reboot. If you have not configured your web services — including your Fediverse service — to start automatically on boot, you may need to start them manually afterward. Always make a backup before performing upgrades. If any of this is confusing or feels overwhelming, you should reconsider whether you want to be a server administrator. This is not meant as an insult. It’s great that you wanted to contribute to the Fediverse, but you may be better off participating as a user rather than an admin. People depend on you to keep services running smoothly, and that requires knowing how to maintain your system safely and correctly. #Fediverse #ActivityPub #Mastodon #Misskey #PixelFed #PeerTube #Sharkey #Loops #Akkoma #Pleroma #Mbin #Lemmy #InfoSec #Security #Hack #Foss #OpenSource #Linux
  11. Embed this notice
    Yellow Flag (wpalant@infosec.exchange)'s status on Wednesday, 10-Dec-2025 23:59:35 JST Yellow Flag Yellow Flag

    Nice, BSI tested password manager security and their analysis actually makes sense: https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/DVS-Berichte/passwortmanager.pdf (German).

    Two questions are particularly interesting: can the vendor access passwords (5/10 no) and is the entire storage encrypted (3/10 yes). Which leaves 1Password, Keepass2 Android and KeePassXC usable without reservations, while Avira Password Manager and Firefox Password Manager are usable with some concerns (the former uses crypto that cannot be verified, the latter requires a main password to be set explicitly). The other five tested products (Chrome Password Manager, mSecure, PassSecurium, SecureSafe, S-Trust) should not be used.

    Not exactly news to me but good to see this confirmed – and good to see a proper analysis rather than grabbing low-hanging fruit for some bullshit statements.

    #PasswordManager #security

    In conversation about 13 days ago from infosec.exchange permalink

    Attachments


  12. Embed this notice
    Marcus "MajorLinux" Summers (majorlinux@toot.majorshouse.com)'s status on Wednesday, 10-Dec-2025 00:30:32 JST Marcus "MajorLinux" Summers Marcus "MajorLinux" Summers

    I know there are some pet owners out there.

    Y'all might wanna start checking on some things.

    Petco Data Breach Exposes Customer Data, Including SSNs, Credit Card Info

    https://www.pcmag.com/news/petco-data-breach-exposes-customer-data-including-ssns-credit-card-info

    #Petco #Data #Breach #Security #Privacy #Tech

    In conversation about 14 days ago from toot.majorshouse.com permalink

    Attachments


    1. https://s3.amazonaws.com/majortoot/media_attachments/files/115/690/261/951/213/334/original/13fdde0d01f4cb7f.jpeg

  13. Embed this notice
    knoppix (knoppix95@mastodon.social)'s status on Tuesday, 09-Dec-2025 03:52:29 JST knoppix knoppix
    • LibreOffice

    Schleswig-Holstein reports €15M yearly savings by replacing Microsoft 365 with LibreOffice across most government workplaces 💶

    About 80% of offices have migrated, with a €9M one-time investment planned for 2026 to finish the shift and strengthen open-source tools 🧩

    @libreoffice

    🔗 https://itsfoss.com/news/german-state-ditch-microsoft/

    #TechNews #OpenSource #Privacy #Security #Government #EU #Data #Sovereignty #IT #PublicSector #Digital #Microsoft #Office #Software #Tech #Cloud #FOSS #Germany #German #LibreOffice

    In conversation about 15 days ago from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: itsfoss.com
      Hurray! This German State Decides to Save €15 Million Each Year By Kicking Out Microsoft for Open Source
      from @sourav_rudra_xD
      Schleswig-Holstein's migration to LibreOffice reaches 80% completion, with a one-time €9 million investment on cards for 2026.
  14. Embed this notice
    Toni Aittoniemi (gimulnautti@mastodon.green)'s status on Monday, 08-Dec-2025 07:09:47 JST Toni Aittoniemi Toni Aittoniemi

    It couldn’t be more clear than this.

    #usnationalsecuritystrategy #russia #europe #nato #security

    In conversation about 15 days ago from mastodon.green permalink

    Attachments


    1. https://files.mastodon.green/media_attachments/files/115/680/499/847/933/666/original/ef47ce2202188e2a.jpeg
  15. Embed this notice
    Julian Del Vecchio (redflegias@mastodon.uno)'s status on Friday, 05-Dec-2025 20:11:05 JST Julian Del Vecchio Julian Del Vecchio

    Avevamo ragione, come sempre, nel comunicare che fino ad Aprile 2026 il chat control sarebbe tornato a massacrarci l'esistenza! A molti di voi potrebbe non interessare ma consegnare i nostri dati a Big Tech, far indebolire la cifratura dei certificati ssl e stravolgere le regole per un controllo di massa anche no!
    Agite al link sottostante:

    https://fightchatcontrol.eu

    #stopchatcontrol #fightchatcontrol #privacy #security #freedom

    In conversation about 18 days ago from mastodon.uno permalink
  16. Embed this notice
    Peter B. (p3ter@mastodon.social)'s status on Friday, 05-Dec-2025 15:40:48 JST Peter B. Peter B.

    How much is this "worth" (in money)?

    (my) webservers (!) running without reboot for almost 10 years 🖖 🥳
    /WITHOUT/ changing anything.
    (only security patches)

    Thanks to #Debian's #FOSS-developer best-practice of:

    "**fixing a security problem is to make as few changes as possible**"
    [quote src=https://www.debian.org/security/faq#oldversion]

    And other distros building on top of each other, in collaboration.

    I ♥️ *stable, professional #OpenSource tech*

    #StableIT #Ubuntu #GNU #linux #security #dltp #longterm #bash

    In conversation about 18 days ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/115/662/064/607/769/629/original/f3f40eeece5cd125.png
  17. Embed this notice
    GrapheneOS (grapheneos@grapheneos.social)'s status on Friday, 05-Dec-2025 15:07:27 JST GrapheneOS GrapheneOS

    Vanadium version 143.0.7499.52.0 released:

    https://github.com/GrapheneOS/Vanadium/releases/tag/143.0.7499.52.0

    See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

    Forum discussion thread:

    https://discuss.grapheneos.org/d/28639-vanadium-version-14307499520-released

    #GrapheneOS #privacy #security #browser

    In conversation about 18 days ago from grapheneos.social permalink
  18. Embed this notice
    David J. Atkinson (meltedcheese@c.im)'s status on Friday, 05-Dec-2025 09:18:58 JST David J. Atkinson David J. Atkinson
    in reply to
    • Mathew Ingram

    @mathewi 4/
    I’m going to delay elaborating my other concerns about the maturity of #SelfDriving #autonomous vehicles. For now, please consider the following:

    1. #AI in general, self-driving cars in particular, are not people. These technology systems do not have our human-lived experiences, they do not think like us, even if you believe that thinking is computational. With a few exceptions, such systems have no common sense ability to reason about the world. They don’t understand human behavior the way we do.

    2. They will not make the same mistakes that humans make while driving. That is not only a requirement, it follows from 1. Instead, they will make their own mistakes. We are already seeing plenty of these. Sure, engineers will grind out most of these, but not all.

    3. The first two points mean that the behavior of self-driving cars will be difficult to predict in all but the most common vanilla driving situations. People complain about how rigid the current vehicles are at following the law. What? Now you want them to break the law when it is expedient?

    4. There are a near infinite number of “edge cases” and those are when safe driving is the most difficult — exactly when we want self-driving vehicles to excel. There are too many to test. The complexity of the real-world, specifically edge cases, cannot be simulated in a laboratory. A decade or more experience on the road is required.

    5. Cars are increasingly connected and computerized, and that makes them a new #security threat. Any modern car today can be hacked and remotely controlled. AI systems add multiple new attack vectors. Yes, companies are working on security, but so are the bad guys. #Infosec people will tell you their world is hand-to-hand combat. The more such cars are on the road, the greater the opportunity and attraction for mischief (or worse).

    The big question is when will we, as a society, feel safe and convinced by the benefits of self-driving cars? That question is a trap, because most people don’t know the details. It is already happening.

    Speaking as an expert and a grandfather, I will not be putting my grandchildren in the back seat of a self-driving car any time soon.

    In conversation about 18 days ago from c.im permalink
  19. Embed this notice
    Yogthos (yogthos@social.marxist.network)'s status on Thursday, 04-Dec-2025 15:01:12 JST Yogthos Yogthos

    A maximum-severity vulnerability in React could enable remote code execution (RCE), and may affect more than a third of cloud service providers.

    https://www.wiz.io/blog/critical-vulnerability-in-react-cve-2025-55182

    #javascript #react #security #programmig

    In conversation about 19 days ago from social.marxist.network permalink
  20. Embed this notice
    Tommaso Gagliardoni (tomgag@infosec.exchange)'s status on Monday, 01-Dec-2025 20:58:27 JST Tommaso Gagliardoni Tommaso Gagliardoni

    Oh, this is so f***ing gold. This post is a juice concentrate of the many reasons why Matrix sucks:

    https://yaky.dev/2025-11-30-self-hosting-matrix/

    Among others:

    Users cannot be deleted
    This is simply not an option in the API. Server admin can perform a "deactivate" (disable login) and "erase" (remove related data, which claims to be GDPR-compliant) on user accounts, but the accounts themselves stay on the server forever.

    LOL.

    Here is my take on why you should trash Matrix and use XMPP, or ta least Signal instead:

    https://gagliardoni.net/#im_battle_2025

    #im #matrix #jabber #xmpp #signal #privacy #security #enshittification #cypherpunk

    In conversation about 22 days ago from infosec.exchange permalink
  • Before

Feeds

  • Activity Streams
  • RSS 1.0
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.