GNU social JP
  • FAQ
  • Login
GNU social JPใฏๆ—ฅๆœฌใฎGNU socialใ‚ตใƒผใƒใƒผใงใ™ใ€‚
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ (chetwisniewski@securitycafe.ca), page 2

  1. Embed this notice
    Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ (chetwisniewski@securitycafe.ca)'s status on Friday, 12-Jul-2024 02:47:48 JST Chester Wisniewski 🇨🇦 Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ
    • Catalin Cimpanu
    • Kevin Beaumont

    @GossiTheDog @campuscodi I did an analysis at RSA 6 years ago on who hosts the bad... https://youtu.be/FQLlt-7gsYI?si=iuXrCpLn1VVvgBfc

    In conversation Friday, 12-Jul-2024 02:47:48 JST from securitycafe.ca permalink

    Attachments

    1. RSAC TV: Does Malware Have Citizenship? Who's Infecting Us and Does It Matter
      from RSA Conference
      Chester Wisniewski, Principal Research Scientist, SOPHOSWe often hear that malware attacks are characteristic of country Y and nation-state X. Some companies...
  2. Embed this notice
    Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ (chetwisniewski@securitycafe.ca)'s status on Saturday, 22-Jun-2024 05:09:58 JST Chester Wisniewski 🇨🇦 Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ
    • Kevin Beaumont

    @GossiTheDog Yes, this happens a lot too.

    In conversation Saturday, 22-Jun-2024 05:09:58 JST from gnusocial.jp permalink
  3. Embed this notice
    Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ (chetwisniewski@securitycafe.ca)'s status on Friday, 21-Jun-2024 20:41:32 JST Chester Wisniewski 🇨🇦 Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ
    • Kevin Beaumont

    @GossiTheDog we see the same last I checked. You don't need to believe me either, but I believe it is true.

    In conversation Friday, 21-Jun-2024 20:41:32 JST from securitycafe.ca permalink
  4. Embed this notice
    Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ (chetwisniewski@securitycafe.ca)'s status on Friday, 14-Jun-2024 08:28:25 JST Chester Wisniewski 🇨🇦 Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ
    in reply to
    • Kevin Beaumont

    @GossiTheDog This whole thing feels like a desperate ploy to explain to people why they should throw out their PCs to get a new one with an "NPU". Don't want, don't need. They have to include something that "requires" it, even though as already proven, it isn't even needed for this.

    In conversation Friday, 14-Jun-2024 08:28:25 JST from securitycafe.ca permalink
  5. Embed this notice
    Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ (chetwisniewski@securitycafe.ca)'s status on Friday, 17-May-2024 21:03:05 JST Chester Wisniewski 🇨🇦 Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ
    • Kevin Beaumont
    • Corey Quinn

    @GossiTheDog @Quinnypig Everyone gives me the side eye for running my own mail server, IRC, nextcloud, etc. I have seen this play before and it ends in tears. Trust no one.

    In conversation Friday, 17-May-2024 21:03:05 JST from securitycafe.ca permalink
  6. Embed this notice
    Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ (chetwisniewski@securitycafe.ca)'s status on Sunday, 21-Apr-2024 08:21:00 JST Chester Wisniewski 🇨🇦 Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ
    in reply to
    • Techmeme

    @Techmeme Hadn't this already been debunked?

    In conversation Sunday, 21-Apr-2024 08:21:00 JST from securitycafe.ca permalink
  7. Embed this notice
    Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ (chetwisniewski@securitycafe.ca)'s status on Saturday, 27-Jan-2024 06:20:06 JST Chester Wisniewski 🇨🇦 Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ
    • Kevin Beaumont
    • metlstorm

    @GossiTheDog @metlstorm I'm surprised this was effective considering many more ransomware crews are doing "remote ransomware", effectively running the encryption on an unprotected device and connecting to the shares over the network. Would work against Netware shares as well as anything else...

    In conversation Saturday, 27-Jan-2024 06:20:06 JST from securitycafe.ca permalink
  8. Embed this notice
    Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ (chetwisniewski@securitycafe.ca)'s status on Saturday, 27-Jan-2024 04:30:26 JST Chester Wisniewski 🇨🇦 Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ

    Looks like Lush Cosmetics were victims of Akira as they have appeared on their leak site. Akira has exploited unpatched Cisco ASA VPNs in the past, wondering if the same here? They use them according to Shodan data.

    In conversation Saturday, 27-Jan-2024 04:30:26 JST from securitycafe.ca permalink
  9. Embed this notice
    Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ (chetwisniewski@securitycafe.ca)'s status on Saturday, 20-Jan-2024 09:53:28 JST Chester Wisniewski 🇨🇦 Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ

    It's getting harder and harder to not publicly say critical things about the competition...

    In conversation Saturday, 20-Jan-2024 09:53:28 JST from securitycafe.ca permalink
  10. Embed this notice
    Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ (chetwisniewski@securitycafe.ca)'s status on Friday, 01-Dec-2023 05:43:06 JST Chester Wisniewski 🇨🇦 Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ
    • Bob Lord ๐Ÿ” :donor:
    • Per Thorsheim

    Great! TransUnion, whom I have the pleasure of receiving free credit monitoring from due to the MGM Casino breach in Sept, has a policy of only allowing 15 characters or less. Not like anything important is on the line or anything. Oh, they get bonus points for letting me skip the password with a trivial security question! #InfoSec #NotAFeature @boblord @thorsheim

    In conversation Friday, 01-Dec-2023 05:43:06 JST from securitycafe.ca permalink

    Attachments


    1. https://securitycafe.ca/system/media_attachments/files/111/491/619/473/573/872/original/15904c46b44cb4c7.png

    2. https://securitycafe.ca/system/media_attachments/files/111/491/633/581/200/337/original/e0270cb8722a4b80.png
  11. Embed this notice
    Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ (chetwisniewski@securitycafe.ca)'s status on Monday, 26-Jun-2023 15:07:37 JST Chester Wisniewski 🇨🇦 Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ
    in reply to
    • Chris Trottier
    • iameli

    @atomicpoet @iameli It sounds good, but I don't see it being possible without compromising many people's safety. Suggesting it is safe without having studied the underlying risks is dangerous and irresponsible. (2/2)

    In conversation Monday, 26-Jun-2023 15:07:37 JST from securitycafe.ca permalink
  12. Embed this notice
    Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ (chetwisniewski@securitycafe.ca)'s status on Monday, 26-Jun-2023 15:07:37 JST Chester Wisniewski 🇨🇦 Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ
    in reply to
    • Chris Trottier
    • iameli

    @atomicpoet @iameli federation by definition will decrease security and privacy. We all want a pony, but it's just not possible. Side channel attacks, differential communication analysis, key distribution/generation and many other issues make federation a dangerous compromise.

    We would all like CSAM to be eliminated, but it isn't possible to have secure & private communication and yet still scan for it. Similarly federation requires compromises that would put many people at risk. (1/2)

    In conversation Monday, 26-Jun-2023 15:07:37 JST from securitycafe.ca permalink
  13. Embed this notice
    Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ (chetwisniewski@securitycafe.ca)'s status on Monday, 26-Jun-2023 14:42:37 JST Chester Wisniewski 🇨🇦 Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ
    in reply to
    • Chris Trottier
    • iameli

    @atomicpoet @iameli I'm sure the women and minorities who will be stalked and harassed when their privacy is impacted by your proposed solution will find solace in the world being a more just place.

    In conversation Monday, 26-Jun-2023 14:42:37 JST from securitycafe.ca permalink
  14. Embed this notice
    Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ (chetwisniewski@securitycafe.ca)'s status on Monday, 26-Jun-2023 14:38:04 JST Chester Wisniewski 🇨🇦 Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ
    in reply to
    • Chris Trottier
    • iameli

    @atomicpoet @iameli I don't disagree, but you are making a decision for others. You are asking they sacrifice their safety and security to achieve some misinformed version of fairness. My 30 years of working in security and privacy tell me this is a very bad way to solve the problem you are trying to solve. You are trying to reinvent SMS, which we already have and is already terrible.

    In conversation Monday, 26-Jun-2023 14:38:04 JST from securitycafe.ca permalink
  15. Embed this notice
    Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ (chetwisniewski@securitycafe.ca)'s status on Monday, 26-Jun-2023 14:32:53 JST Chester Wisniewski 🇨🇦 Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ
    in reply to
    • Chris Trottier
    • iameli

    @atomicpoet @iameli Being a zealot helps no one. Understanding risks, benefits and politics are all important factors. Spreading misinformation and then insisting that people should work harder to achieve likely impossible goals is not helping anyone.

    Is Meta evil? Absolutely. Is federation the answer to all problems? Absolutely not. Stick to what you know and work to help people make better choices.

    In conversation Monday, 26-Jun-2023 14:32:53 JST from securitycafe.ca permalink

    Attachments


  16. Embed this notice
    Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ (chetwisniewski@securitycafe.ca)'s status on Monday, 26-Jun-2023 14:23:12 JST Chester Wisniewski 🇨🇦 Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ
    in reply to
    • Chris Trottier

    @atomicpoet What? I'm quite sure that WhatsApp uses the Signal protocol these days.

    In conversation Monday, 26-Jun-2023 14:23:12 JST from securitycafe.ca permalink
  17. Embed this notice
    Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ (chetwisniewski@securitycafe.ca)'s status on Monday, 26-Jun-2023 14:23:10 JST Chester Wisniewski 🇨🇦 Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ
    in reply to
    • Chris Trottier

    @atomicpoet I don't think Federation is really possible with secure protocols like Signal. WhatsApp apparently completed the transition in 2016 https://signal.org/blog/whatsapp-complete/

    In conversation Monday, 26-Jun-2023 14:23:10 JST from securitycafe.ca permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: signal.org
      WhatsApp's Signal Protocol integration is now complete
      from @signalapp
      At Open Whisper Systems, our goal is to make private communication simple. A year ago, we announced a partnership with WhatsApp and committed to integrating the Signal Protocol into their product, moving towards full end-to-end encryption for all of their users by default. Over the past year, we...
  • After

User actions

    Chester Wisniewski 🇨🇦

    Chester Wisniewski ๐Ÿ‡จ๐Ÿ‡ฆ

    Director, Global Field CISO at Sophos, frequent speaker and press go to. Said opinions are mine, not the company.Co-host of the Security Take(s) Two (@securitytaketwo) podcast.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          139937
          Member since
          26 Jun 2023
          Notices
          37
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP็ฎก็†ไบบ. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.