GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Avoid the Hack! :donor: (avoidthehack@infosec.exchange)

  1. Embed this notice
    Avoid the Hack! :donor: (avoidthehack@infosec.exchange)'s status on Tuesday, 18-Mar-2025 17:12:25 JST Avoid the Hack! :donor: Avoid the Hack! :donor:

    AI #search engines cite incorrect sources at an alarming 60% rate, study says

    Misinformation has always been present on the internet, but #AI certainly isn't helping here.

    Additionally, many AI tools ignored Robot Exclusion Protocol settings. AKA they said that robots.txt doesn't apply to them.

    (Grok 3's error rate is 94%, lol.)

    #misinformation

    https://arstechnica.com/ai/2025/03/ai-search-engines-give-incorrect-answers-at-an-alarming-60-rate-study-says/

    In conversation about a year ago from infosec.exchange permalink
  2. Embed this notice
    Avoid the Hack! :donor: (avoidthehack@infosec.exchange)'s status on Tuesday, 14-Jan-2025 02:42:09 JST Avoid the Hack! :donor: Avoid the Hack! :donor:
    in reply to
    • j@mastodon

    @jcast You can block ads beyond the browser. Ads can also be blocked on the device and network levels.

    There is no universal protection against fingerprinting, but you can certainly resist it. There's a nuance to it and part of it is reliant on user threat model.

    In conversation Tuesday, 14-Jan-2025 02:42:09 JST from gnusocial.jp permalink
  3. Embed this notice
    Avoid the Hack! :donor: (avoidthehack@infosec.exchange)'s status on Tuesday, 14-Jan-2025 02:38:13 JST Avoid the Hack! :donor: Avoid the Hack! :donor:
    in reply to
    • j@mastodon
    • Hyde 📷 🖋 :debian:

    @jcast @hyde This is actually beyond browser fingerprinting. The change "permits" fingerprinting devices, which would presumably extend to apps using Google's advertising ecosystem in particular. So, you'll see devices like Smart TVs, gaming consoles, etc far more susceptible.

    Additionally, Tor is not a viable daily driver primarily because logging into personal accounts while using Tor is bad opsec. If that level of fingerprinting protection is needed, I recommend the Mullvad browser (it is a Tor fork configured to run off the Tor network.)

    In conversation Tuesday, 14-Jan-2025 02:38:13 JST from gnusocial.jp permalink
  4. Embed this notice
    Avoid the Hack! :donor: (avoidthehack@infosec.exchange)'s status on Tuesday, 14-Jan-2025 00:21:54 JST Avoid the Hack! :donor: Avoid the Hack! :donor:

    #Google Starts Tracking All Your Devices In 6 Weeks—Forget Chrome And #Android

    Long story short is that Google has made updates to its advertising ecosystem essentially _permitting_ the fingerprinting of devices for use in targeted advertising. In their words they are going to be “less prescriptive with partners in how they target and measure ads.”

    Doesn’t mean fingerprinting wasn’t happening before, just that Google is giving the green signal to the rest of the ecosystem to do so… and will likely use this to maybe replace third-party cookies.

    Use an adblocker. Seriously.

    #privacy #ads #privacymatters #useadblockers

    https://www.forbes.com/sites/zakdoffman/2025/01/11/google-starts-tracking-all-your-devices-in-6-weeks-forget-chrome-and-android/

    In conversation Tuesday, 14-Jan-2025 00:21:54 JST from infosec.exchange permalink
  5. Embed this notice
    Avoid the Hack! :donor: (avoidthehack@infosec.exchange)'s status on Saturday, 11-Jan-2025 03:43:45 JST Avoid the Hack! :donor: Avoid the Hack! :donor:

    :beber:

    #useadblockers #privacy #meme

    In conversation Saturday, 11-Jan-2025 03:43:45 JST from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/804/520/609/757/821/original/84a3f11dd73c3da9.png
  6. Embed this notice
    Avoid the Hack! :donor: (avoidthehack@infosec.exchange)'s status on Friday, 15-Nov-2024 01:51:27 JST Avoid the Hack! :donor: Avoid the Hack! :donor:

    Pregnancy Tracking #App ‘What to Expect’ Refuses to Fix Issue that Allows Full Account Takeover

    What to Expect is a popular pregnancy tracking app available for #ios and #android.

    An exposed API endpoint handling password reset requests for the app does not require authentication or enforce rate limits and is vulnerable to brute force attacks.

    #privacy #security #cybersecurity

    https://www.404media.co/pregnancy-tracking-app-what-to-expect-refuses-to-fix-issue-that-allows-full-account-takeover-2/

    In conversation Friday, 15-Nov-2024 01:51:27 JST from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.404media.co
      Pregnancy Tracking App ‘What to Expect’ Refuses to Fix Issue that Allows Full Account Takeover
      from @josephfcox
      Vulnerabilities in the popular What to Expect app include one that allows a full account take over, and another that exposes that email address of forum admins.
  7. Embed this notice
    Avoid the Hack! :donor: (avoidthehack@infosec.exchange)'s status on Monday, 23-Sep-2024 23:41:53 JST Avoid the Hack! :donor: Avoid the Hack! :donor:

    Researcher reveals ‘catastrophic’ #security flaw in the Arc browser

    (CVE-2024-45489)

    The Arc Browser is a fork of #chromium with a lot of built-in features and integrations... and requires an account to use.

    Arc Browser uses Firebase to store user information for features like Arc Boosts. Arc Boosts can contain arbitrary javascript... with knowing the CreatorID, an attacker could inject code into other users' browsing sessions.

    Crazy to me because this implementation appeared to rely solely on user-provided identities (the CreatorID) without implementing any checks.

    This has been patched in the newest version of the Arc browser.

    #browsers #cybersecurity #cve

    https://www.theverge.com/2024/9/20/24249919/arc-browser-boost-firebase-vulnerability-patched

    In conversation Monday, 23-Sep-2024 23:41:53 JST from infosec.exchange permalink
  8. Embed this notice
    Avoid the Hack! :donor: (avoidthehack@infosec.exchange)'s status on Saturday, 10-Feb-2024 20:41:20 JST Avoid the Hack! :donor: Avoid the Hack! :donor:
    • It's FOSS
    • BleepingComputer
    • Ars Technica
    • AlternativeTo
    • Skiff

    Skiff Privacy has been acquired, will be shutting down

    Skiff @skiff has “joined” (read: been acquired) by Notion.

    Skiff privacy is (was?) an #opensource and #privacy friendly product suite, featuring email, pages, drive and calendar.

    According to their blog post and an email mirroring that blog post, Skiff will be “sunsetting” in the next 6 months. In plainspeak, in about 6 months (no definitive date as of writing this post) Skiff’s services will no longer work. Users will not be automatically migrated to Notion.

    Users must migrate/download their data, including migrating skiff domains and redirecting emails. From what I currently understand, email aliases must be handled by hand - so the redirect only works for the primary address.

    @alternativeto @BleepingComputer @arstechnica @itsfoss

    I will be pulling the recommendation for Skiff on Avoidthehack.com ASAP.

    #privacy #privacymatters #skiff #skiffprivaacy

    https://skiff.com/data-migration

    In conversation Saturday, 10-Feb-2024 20:41:20 JST from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/111/904/747/076/025/862/original/14dff26b5aa6e466.jpeg

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/111/904/751/390/998/335/original/3668c94eda80db59.jpeg

    3. https://media.infosec.exchange/infosec.exchange/media_attachments/files/111/905/035/437/780/424/original/2036f9e1d8b0b1f3.jpeg
    4. Domain not in remote thumbnail source whitelist: Avoidthehack.com
      Avoid the Hack | The intersection of cybersecurity and privacy
      from avoidthehack!
      Avoid the Hack (avoidthehack) promotes online privacy and cybersecurity awareness for all users.
  9. Embed this notice
    Avoid the Hack! :donor: (avoidthehack@infosec.exchange)'s status on Wednesday, 10-Jan-2024 04:50:31 JST Avoid the Hack! :donor: Avoid the Hack! :donor:
    in reply to
    • carl marks

    @tillshadeisgone

    Sure do. I am really enjoying 2FAS, but there’s also Aegis (which is Android only).

    If you need/want desktop+mobile compatibility, Bitwarden Premium is great.

    More recs (all #opensource):

    https://avoidthehack.com/best-mfa-2fa

    In conversation Wednesday, 10-Jan-2024 04:50:31 JST from infosec.exchange permalink
  10. Embed this notice
    Avoid the Hack! :donor: (avoidthehack@infosec.exchange)'s status on Wednesday, 10-Jan-2024 02:41:17 JST Avoid the Hack! :donor: Avoid the Hack! :donor:

    #Authy is shutting down its #desktop app

    Authy is a a #2fa / #MFA authentication app, though one that is not recommended in the #privacy space primarily because it does not offer easy export of codes (making it difficult to switch apps) and is closed source.

    However, many people used it because it was one of the only apps not integrated into a password manager that allowed easy syncing across different devices.

    I am urging any Authy users/holdouts to switch to an #opensource alternative that allows exporting 2FA secrets.

    https://www.theverge.com/2024/1/8/24030477/authy-desktop-app-shutting-down

    In conversation Wednesday, 10-Jan-2024 02:41:17 JST from infosec.exchange permalink
  11. Embed this notice
    Avoid the Hack! :donor: (avoidthehack@infosec.exchange)'s status on Thursday, 19-Oct-2023 00:12:18 JST Avoid the Hack! :donor: Avoid the Hack! :donor:

    Malicious Notepad++ #Google ads evade detection for months

    Otherwise known as the "Sponsored" results section, which is conveniently right at the top of Google SERPs.

    The domains in this particular campaign drop malicious scripts when users download the "Notepad++" files on these deceptive sites.

    Use an adblocker.

    #cybersecurity #infosec #adblock

    https://www.bleepingcomputer.com/news/security/malicious-notepad-plus-plus-google-ads-evade-detection-for-months/

    In conversation Thursday, 19-Oct-2023 00:12:18 JST from infosec.exchange permalink

User actions

    Avoid the Hack! :donor:

    Avoid the Hack! :donor:

    An initiative promoting the intersection of internet #privacy and #cybersecurity for all users.
Based in the USA. You are more than just a data point.Operated by: @ashwritesEstablished in 2020.#fedi22 #infosec #opsec

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          202278
          Member since
          18 Oct 2023
          Notices
          11
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.