Netsec – Telegram
Netsec
7.41K subscribers
22.4K links
This channel posts the feed from r/netsec.
For any suggestions dm @streaak
Donate to keep the bot running https://www.paypal.me/akhilgv
Download Telegram
Two-factor authentication flowsheets
I'm looking for flowsheets for implementing two-factor authentication in a web application, including registration, login, forgotten password, and lost authentication device.I can probably work these out for myself, but with all things crypto, I'm hesitant to develop my own algorithms because I risk missing something vital and leaving a security hole that an attacker can exploit.Any recommendations of blogs or books that cover this?

Submitted November 27, 2017 at 09:29PM by grkuntzmd
via reddit http://ift.tt/2iVVkLZ
Imgur confirms email addresses, passwords stolen in 2014 hack
http://ift.tt/2A6P1z0

Submitted November 27, 2017 at 11:51PM by volci
via reddit http://ift.tt/2zsBcqX
The future of cyberwar: ​Weaponised ransomware, IoT attacks and a new arms race
http://ift.tt/2z4GI76

Submitted November 27, 2017 at 11:43PM by SecurityTrust
via reddit http://ift.tt/2zsnEvv
Early Warning: A New Mirai Variant is Spreading Quickly on Port 23 and 2323
http://ift.tt/2B6Nmq4

Submitted November 28, 2017 at 12:09AM by speckz
via reddit http://ift.tt/2Ae3Kpf
So, there are essentially no security features on Google Home devices?
I just wanted to share how ridiculous the security is using Google Home mini, and this seemed like a place to voice that concern.I just purchased a Google Home Mini, and I am quite concerned with the essentially non-existant security with these devices. By simply being connected to the same wifi connection you can boot up the Google Home app and change pretty much any setting you want to either the Chromecast or the Home Mini. The aforementioned Chromecast was setup by my roommate using a different android phone and google account, and I was able to have full access and change all of the settings, or even reset the device wirelessly. I can play any content I want to either of these devices, change the settings, see what content is being played on the device ( or change the setting that "hides" the content that is casting ) or enable or disable the "Guest" mode.This seems like a blatant and horrible risk for security, as many users are likely sharing wifi networks in places like college dorms and apartment complexes, and may not know how easy it is to access settings and such from these devices.Google's official response to any concerns like this is to "make your Home Wi-Fi network password protected and only give out the password to people you trust.", which is ridiculous. This works under the assumption that families and those who share Wifi want each-other to have complete access to the casting devices or content being consumed on them. I am genuinely astonished that Google released the product only relying on a Wifi password to prevent changes.It doesn't seem like the Echo Dot has the same blatant security issues as installing the Alexa app prompted me to log into my Amazon account, and the only device visible was my own Amazon Firestick, and not the Echo Dot connected to my wifi network that I do not own.

Submitted November 28, 2017 at 04:10AM by dclems
via reddit http://ift.tt/2nanCqn
Hot Singles in Your Area Want to Putin 💋: Click here to like 👍 the new global cyber-war on social media
http://ift.tt/2AEypPP

Submitted November 28, 2017 at 08:08AM by Paul-B-Robinson1
via reddit http://ift.tt/2AdUELv
How to backup VeraCrypt drives?
Today I found out Symantec Recovery and Veeam can't recognize fully encrypted disks (VeraCrypt AES).The only way I can find as a temporary solution is to robocopy the drive to a backup external drive (also encrypted).Is anyone aware of a good backup solution that can handle fully encrypted disks? Any advice is appreciated, thanks!

Submitted November 28, 2017 at 11:17AM by mr_norr
via reddit http://ift.tt/2icaek2
Unofficial Guide to Mimikatz & Command Reference
http://ift.tt/1Qou989

Submitted November 28, 2017 at 07:36PM by FireFart
via reddit http://ift.tt/2BjRove