Netsec – Telegram
Netsec
7.43K subscribers
22.4K links
This channel posts the feed from r/netsec.
For any suggestions dm @streaak
Donate to keep the bot running https://www.paypal.me/akhilgv
Download Telegram
5 surefire cloud security certifications to boost your career (and your paycheck): They did the math
http://ift.tt/2GMI9rq

Submitted March 20, 2018 at 10:08PM by yourbasicgeek
via reddit http://ift.tt/2FOPiKF
2FA Best Practices: Why you shouldn’t use Google Authenticator and what to use instead
http://ift.tt/2u5GieG

Submitted March 20, 2018 at 09:07PM by ddusko
via reddit http://ift.tt/2GPTozq
Yubikey NEO TOTP/U2F configuration and secret backup
Hello everyone, I purchased a Yubikey Neo and am a little confused. From what I understand, I do not need to use the desktop manager app and change any settings in order for my yubikey neo to function in CCID mode (this contains OATH-TOTP, which I want to use as a replacement for google authenticator) and by default, it also has u2f enabled. Is this correct, or do I need to change any configuration out-of-the-box to enable these features?Also, is there a way to backup my yubikey OTP and u2f secrets? I know the yubikey is write-only, but is there a way to basically generate the secrets/the whole configuration in the yubikey manager, and then write them to the device while also encrypting and saving them somewhere else so that I can restore these secrets if my yubikey fails? Thanks for any feedback!

Submitted March 21, 2018 at 12:56AM by RiBc_
via reddit http://ift.tt/2IEWkzp
Account Hacked or only Attempted compromise?
So I consider myself careful when it comes to internet security. Although today, some individual had managed to successfully get into my Macy's account (of which I never really use) to place an order to someone else within my state of residence, but different address and credit card number. It seems as though the only information used of mine was my email address.Now aside from this, my email address received ~100-200 new account creation/password reset emails from mom & pop ecom stores and affiliate programs. Basically stores I've never heard of but follow the same pattern for their emails (maybe had the same backend software between them all)Now none of these messages were read, I have 2FA enabled and checking my security on my Google account, I don't believe my email was compromised. I checked my credit cards/financials and nothing seems out of the ordinary.I called Macy's and they were no help. They said because only my email was used and none of the other information was my own, I could not cancel the order as it doesn't count as a fraud purchase. They said the address looks legitimate on their end, it just wasn't mine. I changed my password/email/security question on my account once that occurred, but that's all I seem to be able to do at this point.So my question is, has anyone dealt with this before? What the hell is going on, what are they trying to accomplish when creating hundreds of accounts with my email/password changes if they can't access my information? It was either a noscript or bot because no human could create that many accounts so quickly.What other security steps should I do? I am a bit alarmed as this never happened to me before.

Submitted March 21, 2018 at 02:36AM by curious_wanderer14
via reddit http://ift.tt/2FW1aX4
15-Year-old Finds Flaw in Ledger Crypto Wallet
http://ift.tt/2u2q1ah

Submitted March 21, 2018 at 03:59AM by alessiodelv
via reddit http://ift.tt/2DHSjX4
Final Year Project Ideas
Hi all I am currently studying Computer Forensics & Security and I will be going into my final year of college next year. Just making this post as I am trying to come up with ideas for a project as early as possible so I can mess around with different noscripts and programs over the summer. I want to do my project in Python and have it be focused in the area of Computer Forensics. The project has to be complex and challenging. I want to try have a foundation planned out before I go back to college. At the moment I want to use some of the following in my project:PythonBashMalware analysisComplex vulnerabilityLinuxForensics & Security basedAny help would be appreciated I have been on Forensics Focus but none of the project ideas they have there seem appealing or are extremely vague.

Submitted March 21, 2018 at 05:39AM by Irishladdoyle
via reddit http://ift.tt/2DGdQ2s
Th3inspector Tool - All in one tool for Information Gathering
http://ift.tt/2HIiQ99

Submitted March 21, 2018 at 03:47AM by TechLord2
via reddit http://ift.tt/2GaoofC
What does your home network setup looks like?
Looking at products like the bitdefender box, I wonder what are people doing to secure their home networks? What does your setup look like?

Submitted March 21, 2018 at 01:32PM by gaijinboricua
via reddit http://ift.tt/2puMSpt
Expedia's Orbitz Says 880,000 Payment Cards Compromised in Security Breach
http://ift.tt/2IBjxlP

Submitted March 21, 2018 at 01:17PM by Horus_Sirius
via reddit http://ift.tt/2pu74rh
How secure is Mobile Pay?
Just out of curiosity, how safe is Mobile pay?
I don't know much about it and have never set it up on my phone but have been thinking about it.
I have a galaxy, so it would be Samsung Pay.
I haven't heard of issues with it, but just curious.
Thanks in advance.

Submitted March 21, 2018 at 02:43PM by GreekNord
via reddit http://ift.tt/2HRIKaE
Windows Remote Assistance XXE vulnerability
http://ift.tt/2ppryla

Submitted March 21, 2018 at 02:06PM by Mempodipper
via reddit http://ift.tt/2u7RqHY