Recent Reddit account hacking spree could be a text book example of internal security threat. Reset link weakness identified. Email hacking/malware can be ruled out (read thread), it seems like an insider job (details in thread).
http://ift.tt/2DFmbUo
Submitted January 01, 2018 at 08:15PM by geekmonk
via reddit http://ift.tt/2CAp0XD
http://ift.tt/2DFmbUo
Submitted January 01, 2018 at 08:15PM by geekmonk
via reddit http://ift.tt/2CAp0XD
reddit
I've done some tests, this is how reddit accounts might be... • r/btc
So I have been trying different things to compromise my own accounts and these are my conclusions: 1) It is impossible from the reddit username...
Question about 2-factor authentication
Hi guys,Not sure if this can be posted here, please let me know if I should publish it anywhere else.I have one account where I have activated the 2-FA. When I tried to log in it said that the code was incorrect (I added the 2-FA to the android app through the QR code). I also tried to delete it from the app and add it again (I have both the initial QR pic and the text code) but it´s still not working.I also tried to sync the time within the app and nothing as well. Any idea what might be going on or how to solve it?Thanks a lot!
Submitted January 01, 2018 at 08:28PM by Heco1331
via reddit http://ift.tt/2lwPSQV
Hi guys,Not sure if this can be posted here, please let me know if I should publish it anywhere else.I have one account where I have activated the 2-FA. When I tried to log in it said that the code was incorrect (I added the 2-FA to the android app through the QR code). I also tried to delete it from the app and add it again (I have both the initial QR pic and the text code) but it´s still not working.I also tried to sync the time within the app and nothing as well. Any idea what might be going on or how to solve it?Thanks a lot!
Submitted January 01, 2018 at 08:28PM by Heco1331
via reddit http://ift.tt/2lwPSQV
reddit
Question about 2-factor authentication • r/security
Hi guys, Not sure if this can be posted here, please let me know if I should publish it anywhere else. I have one account where I have activated...
Firefox Send - is it the most secure file sharing app??
https://youtube.com/watch?list=PL4Z_2mButeI4GOjMALx6E-aQS-wFzM5yo&v=N5DuOhY1XN0
Submitted January 01, 2018 at 10:47PM by dre_russ
via reddit http://ift.tt/2Cy8Xt9
https://youtube.com/watch?list=PL4Z_2mButeI4GOjMALx6E-aQS-wFzM5yo&v=N5DuOhY1XN0
Submitted January 01, 2018 at 10:47PM by dre_russ
via reddit http://ift.tt/2Cy8Xt9
YouTube
Firefox Send - A Self Destructive File Sharing 📁
Earlier this year in 2017 Mozilla launched Firefox send which is a self-destructive encrypted file sharing service. you can send any type of file with it and...
No boundaries for user identities: Web trackers exploit browser login managers
http://ift.tt/2lgYsSV
Submitted January 02, 2018 at 12:55AM by bigshmoo
via reddit http://ift.tt/2DHvumE
http://ift.tt/2lgYsSV
Submitted January 02, 2018 at 12:55AM by bigshmoo
via reddit http://ift.tt/2DHvumE
34c3 talks
http://ift.tt/2l9k30q
Submitted January 02, 2018 at 01:39AM by pheexx
via reddit http://ift.tt/2lC18e1
http://ift.tt/2l9k30q
Submitted January 02, 2018 at 01:39AM by pheexx
via reddit http://ift.tt/2lC18e1
media.ccc.de
media.ccc.de -
34C3: TUWAT
34C3: TUWAT
Video Streaming Portal des Chaos Computer Clubs
A fun video describing some of the many Federation security vulnerabilities in the first Star Wars movie.
https://player.vimeo.com/video/148946917
Submitted January 02, 2018 at 01:44AM by aasreddit
via reddit http://ift.tt/2qg9NZp
https://player.vimeo.com/video/148946917
Submitted January 02, 2018 at 01:44AM by aasreddit
via reddit http://ift.tt/2qg9NZp
reddit
A fun video describing some of the many Federation... • r/security
6 points and 0 comments so far on reddit
The Reddit reset link issue makes Reddit users vulnerable to hacks from Reddit employees. u/spez you must URGENTLY FIX reset link vulnerability so that they work only when clicked in users' email. users are at risk!
http://ift.tt/2lB3KZG
Submitted January 02, 2018 at 02:38AM by geekmonk
via reddit http://ift.tt/2DJrlPk
http://ift.tt/2lB3KZG
Submitted January 02, 2018 at 02:38AM by geekmonk
via reddit http://ift.tt/2DJrlPk
reddit
The Reddit reset link issue makes Reddit users vulnerable... • r/btc
Reddit reset links do not expire and work even if not clicked by the user in the reset email. Anyone with access to outbound emails in Reddit's...
ropchain: bypassing ASLR+DEP+stack canaries
http://ift.tt/2lz93JR
Submitted January 02, 2018 at 06:22AM by dgryski
via reddit http://ift.tt/2CnevKv
http://ift.tt/2lz93JR
Submitted January 02, 2018 at 06:22AM by dgryski
via reddit http://ift.tt/2CnevKv
reddit
ropchain: bypassing ASLR+DEP+stack canaries • r/netsec
0 points and 0 comments so far on reddit
The nasty surprises hackers have in store for us in 2018
http://ift.tt/2DO36iZ
Submitted January 02, 2018 at 11:59AM by aasreddit
via reddit http://ift.tt/2qanU2j
http://ift.tt/2DO36iZ
Submitted January 02, 2018 at 11:59AM by aasreddit
via reddit http://ift.tt/2qanU2j
MIT Technology Review
Six Cyber Threats to Really Worry About in 2018
From AI-powered hacking to tampering with voting systems, here are some of the big risks on our radar screen.
The mysterious case of the Linux Page Table Isolation patches
http://ift.tt/2C5VZ53
Submitted January 02, 2018 at 12:01AM by Kerrovitar
via reddit http://ift.tt/2lFFu8D
http://ift.tt/2C5VZ53
Submitted January 02, 2018 at 12:01AM by Kerrovitar
via reddit http://ift.tt/2lFFu8D
Ad targeters are pulling data from your browser’s password manager
http://ift.tt/2CeNfNU
Submitted January 02, 2018 at 02:25PM by rhabarba
via reddit http://ift.tt/2A3TQ7Y
http://ift.tt/2CeNfNU
Submitted January 02, 2018 at 02:25PM by rhabarba
via reddit http://ift.tt/2A3TQ7Y
The Verge
Ad targeters are pulling data from your browser’s password manager
New research shows an alarming new way to track web users
Question regarding data shared with 2FA
Hope this makes sense. I have two accounts set up with a provider that I need to keep entirely separate, so use different usernames, passwords, IP addresses, payment details etc.However, 2FA is now compulsory, so I need to implement it on the second account. Can I use the same 2FA app (i.e. Google authenticator) for both accounts, or is some data shared with the provider that would show a link, i.e. the mac address, IP address or even the mobile phone number associated?I had considered setting up Authy for the separate account, but that now requests the mobile phone number too, before you can use it...again, leading to me wondering if the same problem applies or shared data?
Submitted January 02, 2018 at 05:51PM by ianmd
via reddit http://ift.tt/2EzTl97
Hope this makes sense. I have two accounts set up with a provider that I need to keep entirely separate, so use different usernames, passwords, IP addresses, payment details etc.However, 2FA is now compulsory, so I need to implement it on the second account. Can I use the same 2FA app (i.e. Google authenticator) for both accounts, or is some data shared with the provider that would show a link, i.e. the mac address, IP address or even the mobile phone number associated?I had considered setting up Authy for the separate account, but that now requests the mobile phone number too, before you can use it...again, leading to me wondering if the same problem applies or shared data?
Submitted January 02, 2018 at 05:51PM by ianmd
via reddit http://ift.tt/2EzTl97
reddit
Question regarding data shared with 2FA • r/security
Hope this makes sense. I have two accounts set up with a provider that I need to keep entirely separate, so use different usernames, passwords, IP...
New vulnerability exposed for smartphones
http://ift.tt/2Ch1j9F
Submitted January 02, 2018 at 05:22PM by silverf0x001
via reddit http://ift.tt/2DOuBc4
http://ift.tt/2Ch1j9F
Submitted January 02, 2018 at 05:22PM by silverf0x001
via reddit http://ift.tt/2DOuBc4
Digitaljournal
New vulnerability exposed for smartphones
Hackers can easily guess your phone PIN using its sensor data, according to new research into mobile device security vulnerabilities from Nanyang Technological University.
Data Breach Report: December 2017
http://ift.tt/2CaL4XO
Submitted January 02, 2018 at 06:05PM by Uminekoshi
via reddit http://ift.tt/2lJc1dU
http://ift.tt/2CaL4XO
Submitted January 02, 2018 at 06:05PM by Uminekoshi
via reddit http://ift.tt/2lJc1dU
Nehemiah Security
Data Breach Report: December 2017 - Nehemiah Security
Below is a compilation of news articles covering some of the notable data breaches that occurred in December 2017. Doesn’t this really put things into perspective? Morrisons found liable for data breach – UPDATED – Dec 1 PayPal Unit TIO Networks Discloses…
Leveraging "French Kiss Attack" to boost your phishing campaign
http://ift.tt/2EABAGM
Submitted January 02, 2018 at 06:11PM by Void_Sec
via reddit http://ift.tt/2C99EIx
http://ift.tt/2EABAGM
Submitted January 02, 2018 at 06:11PM by Void_Sec
via reddit http://ift.tt/2C99EIx
VoidSec
Uncommon Phishing and Social Engineering Techniques - VoidSec
Leveraging French Kiss Attack to boost your phishing campaign
Fingerprinting with Zero-Width Characters
http://ift.tt/2Cm640V
Submitted January 02, 2018 at 07:47PM by speckz
via reddit http://ift.tt/2EASdCe
http://ift.tt/2Cm640V
Submitted January 02, 2018 at 07:47PM by speckz
via reddit http://ift.tt/2EASdCe
reddit
Fingerprinting with Zero-Width Characters • r/security
1 points and 0 comments so far on reddit
Security In 5: File Progress Episode 143 - How To Secure Your Video Game Consoles - Switch, Xbox One, PS4
http://ift.tt/2lGz0Y5
Submitted January 02, 2018 at 07:32PM by BinaryBlog
via reddit http://ift.tt/2A6fbOh
http://ift.tt/2lGz0Y5
Submitted January 02, 2018 at 07:32PM by BinaryBlog
via reddit http://ift.tt/2A6fbOh
Libsyn
Security In Five Podcast: File
Progress Episode 143 - How To Secure Your Video Game Consoles - Switch, Xbox One, PS4
Progress Episode 143 - How To Secure Your Video Game Consoles - Switch, Xbox One, PS4
Your video games systems are powerful computers running operating systems similar to those driving your desktops. Requiring internet connectivity exposes these machines and your information exposed if not taken care of. This episode goes through each of the…
Attacking Read-Only Domain Controllers (RODCs) to Own Active Directory
http://ift.tt/2Er77ej
Submitted January 01, 2018 at 10:04PM by based2
via reddit http://ift.tt/2CF36lS
http://ift.tt/2Er77ej
Submitted January 01, 2018 at 10:04PM by based2
via reddit http://ift.tt/2CF36lS
reddit
Attacking Read-Only Domain Controllers (RODCs) to Own... • r/netsec
0 points and 1 comments so far on reddit
Stop Procrastinating and Get Things Done! From Senior Security Analyst/Malware Reverser to WebDev/SecDevOps
http://ift.tt/2A7cRGx
Submitted January 02, 2018 at 09:59PM by marcomcse
via reddit http://ift.tt/2lF2wNU
http://ift.tt/2A7cRGx
Submitted January 02, 2018 at 09:59PM by marcomcse
via reddit http://ift.tt/2lF2wNU
SecDevOps
Stop Procrastinating and Get Things Done!
From Senior Security Analyst/Malware Reverser to WebDev/SecDevOps
The password requirements for the Social Security Administration website are horrifying. How is this even allowed?
http://ift.tt/2lFYWTQ
Submitted January 02, 2018 at 09:31PM by jklick
via reddit http://ift.tt/2qcBqSN
http://ift.tt/2lFYWTQ
Submitted January 02, 2018 at 09:31PM by jklick
via reddit http://ift.tt/2qcBqSN
Imgur
Imgur: The magic of the Internet
Multiple vulnerabilities in the online services of (GPS) location tracking devices
http://ift.tt/2CsgagZ
Submitted January 02, 2018 at 10:53PM by cybergibbons
via reddit http://ift.tt/2EDkMiA
http://ift.tt/2CsgagZ
Submitted January 02, 2018 at 10:53PM by cybergibbons
via reddit http://ift.tt/2EDkMiA