Netsec – Telegram
Netsec
7.43K subscribers
22.4K links
This channel posts the feed from r/netsec.
For any suggestions dm @streaak
Donate to keep the bot running https://www.paypal.me/akhilgv
Download Telegram
Privacy aware Todo app?
HiI really would like to use a Todo/Calendar app on my Android. But most apps sync your data to the cloud, which i'm not comfortable with.Do you know any todo/calendar app that's privacy aware?

Submitted December 23, 2017 at 02:29PM by b00h
via reddit http://ift.tt/2BsCqDq
Basic security for Linux
http://ift.tt/2kLtqDp

Submitted December 24, 2017 at 12:00AM by wewewawa
via reddit http://ift.tt/2BJ9wTR
PassGAN: A deep learning approach for password guessing
http://ift.tt/2yZEaSD

Submitted December 24, 2017 at 03:45AM by brannondorsey
via reddit http://ift.tt/2DD0YLF
Thoughts about SS7 vulnerabilities and 2FA over SMS?
Hey guys, so recently I was reading articles about SMS being an insecure method of transmitting 2FA codes. This makes sense reading about the SS7 breaches and inherently social engineering also increases the risk of this being a 'bad' method of authentication.In fact if I understand this correctly this means SMS basically is not 'true' 2FA, since the whole point is to require something you HAVE and proves you HAVE it, if SMS is this insecure then it fails this litmus test.My biggest conundrum on this is recoverability, obviously they still need my Google password, which is rather long and secure, however it still opens a hole however small.However, closing that hole means that should my phone be lost/destroyed, my tablet/work PC/home PC and smattering of backup envelopes be lost/inaccessible (basically a natural disaster), I would lose everything.I guess this is kind of the point, and TECHNICALLY I could reach out to Google and see if I could get access again, but they are notoriously troublesome when it comes to this.What are your thoughts, is the risk with SS7/SMS vulnerabilities 'big' enough to warrant being extra paranoid, or is it largely fools gold? I am not an important person, nor am I rich, the likelyhood of someone directly targeting me is unlikely and all the computers I use on a daily basis belong to me. I also have Google Prompt setup so even if something did happen I would be able to select that it wasn't me/see a notification.I am pretty sure I am massively overthinking this, but figure I would ask the experts. Thanks for any help or clarification you can provide!

Submitted December 24, 2017 at 05:26AM by Vorteth
via reddit http://ift.tt/2poQlJe
How I Got Paid $0 From the Uber Security Bug Bounty
http://ift.tt/2BuvTZa

Submitted December 25, 2017 at 02:14AM by jailbird
via reddit http://ift.tt/2DGwQPD
PassGAN: A deep learning approach to password guessing
http://ift.tt/2yZEaSD

Submitted December 25, 2017 at 06:38AM by brannondorsey
via reddit http://ift.tt/2l5Wu81
If an ISP deletes your Ip address does that mean any site holding your Ip adress cant do anything ?
I live in Canada and just curios and wanted to, I hear all the time is if someone has your Ip address can trace you. But as I stated if your internet service provider deletes your Ip address which my Isp rogers says it does after a year you stop using their service, are your off the raydar ?edit: this not because i did anything illegal lol

Submitted December 25, 2017 at 10:00AM by jeff101001
via reddit http://ift.tt/2l6Th8a
How I Got Paid $0 From the Uber Security Bug Bounty [x-post from /programming]
http://ift.tt/2BuvTZa

Submitted December 26, 2017 at 04:37AM by ElectroNeutrino
via reddit http://ift.tt/2ByQ5ZW
Bad passwords - this one from the DISA STIG
Recently learned the “standard” DISA STIG compliant password is asdf1234ASDF!@#$16 characters4-Of-4 compliantAnd stupidly-simple to guess

Submitted December 26, 2017 at 08:11AM by volci
via reddit http://ift.tt/2C9R32j