Netsec – Telegram
Netsec
7.42K subscribers
22.4K links
This channel posts the feed from r/netsec.
For any suggestions dm @streaak
Donate to keep the bot running https://www.paypal.me/akhilgv
Download Telegram
Beginning to become more and more targeted.
It has been a few months I have noticed I am becoming more and more targeted in login attempts on various online services.2FA is active whenever I have a chance however, some services don't offer it (traditional banks for example) as well as I Simply forget where I have accounts.Does anyone have any tips or a guideline on how I can begin to find where the heck I have accounts and begin locking things down? 2FA is on my gmail and hotmail of course.

Submitted January 09, 2018 at 10:19PM by Pm_me_your_motocycle
via reddit http://ift.tt/2mjss1F
Brute force password attack prevention
What does this community think about my ideas. Obviously, I cannot possibly be the first guy to think in these ways, or ...?http://ift.tt/2CLcKmx

Submitted January 09, 2018 at 09:44PM by mr-gaiasoul
via reddit http://ift.tt/2CLd5pj
practicalities of a primenumber rainbow table
how much effort would go in a programm/rainbowtable that goes to all values that you can make with, say, 4096 bit, check if its a prime number, if so, store it, then mutiply with every other found prime numer and store the result with some backlink to the correponding primenumber. how much would it cost in terms of cpu cycles and storage/memory, how good is this problem parallelisable? TL;DR: can such thing practicly break RSA

Submitted January 10, 2018 at 12:19AM by simcup
via reddit http://ift.tt/2CVFOvp
S/Mime Email security
More context at the bottom of the page.I have to encrypt and sign an email with an attachment per some instructions, but I don't know enough about cryptology to know how to interpret the instructions.I took the instructions below to mean "encrypt only the attachment (not the full e-mail), encrypt it with AES 256, using the RSA public key as the secret, (which means generating a random IV")The problem is that the secret key in C# doesn't appear that it can be more than 32 bytes. If I use the public key byte array, it is 270 bytes and it is not allowed.My guess at this point is that I should NOT be creating the AES key from the RSA public key, but that's where it loses me. Should I be creating a random key, or using the same one, how are they able to decrypt it if they don't have this key?"Using the secure/multipurpose internet mail exchange (S/MIME) standard, the email must be encrypted using AES-256 (AES cipher with a 256-bit key length) and FMCSA’s ELD public key. The message must be signed using the manufacturer’s ELD private key that corresponds with the ELD public key submitted to FMCSA by the provider when self-certifying the ELD.(a) The ELD must attach a file to an email message to be sent using RFC 5321 Simple Mail Transfer Protocol (SMTP) (incorporated by reference, see § 395.38), to a specific email address, which will be shared with the ELD providers during the technology registration process. (b)The file must have the format described in section 4.8.2.1 of this appendix and must be encrypted using the Secure/Multipurpose Internet Mail Extensions as described in RFC 5751 (incorporated by reference, see § 395.38), and the RSA algorithm as 116 described in RFC 4056 (incorporated by reference, see § 395.38), with the FMCSA public key compliant with NIST SP 800-32 (incorporated by reference, see § 395.38) to be provided to the ELD provider at the time of registration. The content must be encrypted using AES in FIPS Publication 197 (incorporated by reference, see § 395.38), and RFC 3565 (incorporated by reference, see § 395.38). (c)The email must be formatted using the RFC 5322 Internet Message Format (incorporated by reference, see § 395.38), as follows: Element Format To : <Address Provided by FMCSA during online registration> From : <Desired return address for confirmation> Subject : ELD records from <ELD Registration ID><’:’> <ELD Identifier> Body : <Output File Comment> Attachment : MIME encoded AES-256 encrypted file with <filename>.<Date string>.<unique identifier>.aes "

Submitted January 10, 2018 at 01:13AM by educated_female
via reddit http://ift.tt/2CZt6M8
Find put if phone is cellphone is tapped by govt
Hi Reddit. We are in the middle of a electoral fraud crisis in Honduras and the government has actively cracked down on those of us that denounced the fraud by harassing and murdering people (38 people so far). I'm becoming paranoid my cellphone could be tapped and I want to know if there's a way to tell and hopefully remove the tap or take preventive measures before me or the people I care about die misteriously or get exiled by the government. Thanks.

Submitted January 10, 2018 at 01:03AM by hollow_504
via reddit http://ift.tt/2AIG5w5
Major Computer Chip Bugs Show the Need for Open Security Research
http://ift.tt/2D8wzF3

Submitted January 10, 2018 at 01:54AM by punkthesystem
via reddit http://ift.tt/2CM7a3j
Website Glitch Let Me Overstock My Coinbase
http://ift.tt/2DeaZyW

Submitted January 10, 2018 at 01:37AM by volci
via reddit http://ift.tt/2qLXC6L
CPUs: information leak using speculative execution (GPZ #1272)
http://ift.tt/2CYeo7x

Submitted January 10, 2018 at 03:15AM by InfrasonicCuneiform
via reddit http://ift.tt/2CJDuDU
Allegation that Telegram was Compromised by Russian Intelligence - Pg 233, Ln 20
http://ift.tt/2EqalOf

Submitted January 10, 2018 at 03:50AM by timcotten
via reddit http://ift.tt/2mc4bd8
Match.com password requirements...
They require a password between 2-16 characters, and special characters are not allowed. I successfully created an account with the password "aa". How could their password requirements be so bad?

Submitted January 10, 2018 at 07:17AM by kyto32
via reddit http://ift.tt/2ALvrV2
NIST Looking for Post-Quantum Cryptography
http://ift.tt/2yDZmkY

Submitted January 10, 2018 at 06:47AM by sloth_lifestyle
via reddit http://ift.tt/2CXSphO