Search

Items tagged with: Security

(((Arthur Schiwon)))
7 years ago
#Security in companies is a big joke if you're using #Windows. If you really cared, Windows would be disallowed. No control whatsoever.

Mark Burnett on Twitter

“I have this Win10 Enterprise vm that I was using to test out various privacy settings. Here's some of the stuff I found out so far...”
Jason Robinson
7 years ago
#Security in companies is a big joke if you're using #Windows. If you really cared, Windows would be disallowed. No control whatsoever.

Mark Burnett on Twitter

“I have this Win10 Enterprise vm that I was using to test out various privacy settings. Here's some of the stuff I found out so far...”
Guido Arnold
7 years ago
Cyberpeace statt Cyberwar! Ein Kurzfilm kann gesehen werden? nur auf youtube? Make #Cyberpeace, not #Cyberwar! #breakfast #worm #virus #security #privacy #backdoor #sleep

[Fundstück] Cyberpeace statt Cyberwar! (datenschutzhelden.o...

[Fundstück] Cyberpeace statt Cyberwar! (https://datenschutzhelden.org/2017/05/10/fundstueck-cyberpeace-statt-cyberwar/)
Wer Wind sät, wird Sturm ernten Altes Testament, Hosea, Kapitel 8, Vers 7 Alexander Lehmann hat schon in seiner Serie "Einfach erklärt" viele wichtige Informationen zum Thema Online-Sicherheit anschaulich aufbereitet. Jetzt ist er zurück und klärt in seinem neuen Video für den[...]
#Datenschutzhelden #CC BY 4 0
Quelle: https://datenschutzhelden.org/2017/05/10/fundstueck-cyberpeace-statt-cyberwar/ (https://datenschutzhelden.org/2017/05/10/fundstueck-cyberpeace-statt-cyberwar/)
Cyberpeace statt Cyberwar! Ein Kurzfilm kann gesehen werden? nur auf youtube? Make #Cyberpeace, not #Cyberwar! #breakfast #worm #virus #security #privacy #backdoor #sleep

[Fundstück] Cyberpeace statt Cyberwar! (datenschutzhelden.o...

[Fundstück] Cyberpeace statt Cyberwar! (https://datenschutzhelden.org/2017/05/10/fundstueck-cyberpeace-statt-cyberwar/)
Wer Wind sät, wird Sturm ernten Altes Testament, Hosea, Kapitel 8, Vers 7 Alexander Lehmann hat schon in seiner Serie "Einfach erklärt" viele wichtige Informationen zum Thema Online-Sicherheit anschaulich aufbereitet. Jetzt ist er zurück und klärt in seinem neuen Video für den[...]
#Datenschutzhelden #CC BY 4 0
Quelle: https://datenschutzhelden.org/2017/05/10/fundstueck-cyberpeace-statt-cyberwar/ (https://datenschutzhelden.org/2017/05/10/fundstueck-cyberpeace-statt-cyberwar/)
(((Arthur Schiwon)))
7 years ago

Open Source und die Update-Resistenz | OSB – Open Source Business Alliance


Die Grünen erklärten beispielsweise, dass es sei nur ein unwichtiger Server mit altem Wahlkampfmaterial betroffen. Das zeigt offenkundige Unwissenheit darüber, wie solche Angriffe ablaufen. Und eine sträflich nachlässige Haltung gegenüber der IT-Sicherheit. Organisationen und Privatleute verwenden Nextcloud und Owncloud, weil sie den Public-Cloud-Speicherangeboten misstrauen, Datenverluste oder ein Ausschnüffeln ihrer Privatsphäre befürchten. Daraus sollte eigentlich selbstverständlich folgen, dass Anwender auch Maßnahmen treffen, um solche Angriffe auf ihre eigenen Cloud-Speicher zu verhindern. Updates sind dafür unverzichtbar. Allerdings sind da nicht nur die Anwender in der Pflicht.

http://osb-alliance.de/blog/open-source-und-die-update-resistenz

#foss #security #it #nextcloud

Open Source und die Update-Resistenz

Nextcloud hat entdeckt, dass hunderte private Cloud-Speicher angreifbar sind, weil sie auf überholten Versionen aufsetzen. Das Drumherum um diese Meldung zeigt viel Gutes – und eine Schwachstelle.
Von Ludger Schmitz*

Diesmal ist nicht ein gefährlicher Bugs in aktueller Open-Source-Software das Problem. Vielmehr hat sich herausgestellt, dass zigtausende private Cloud-Server mit alten Versio ...
(((Arthur Schiwon)))
7 years ago from Feed
Owncloud und Nextcloud: Parteien und Ministerien nutzen unsichere Cloud-Dienste - Golem.de
https://www.golem.de/news/owncloud-und-nextcloud-parteien-und-ministerien-nutzen-unsichere-cloud-dienste-1703-126553.html
#Nextloud #BSI #Owncloud #Server #Applikationen #Security

Alte Owncloud und Nextcloud-Versionen: Parteien und Ministerien nutzen unsichere Cloud-Dienste - Golem.de

Das BSI warnt Organisationen und Parteien vor Schwachstellen in ihren Cloud-Diensten. Viele haben bis heute nicht darauf reagiert. Golem.de konnte entsprechende Warnungen
Golem (inoffiziell)
7 years ago from Feed
Owncloud und Nextcloud: Parteien und Ministerien nutzen unsichere Cloud-Dienste - Golem.de
https://www.golem.de/news/owncloud-und-nextcloud-parteien-und-ministerien-nutzen-unsichere-cloud-dienste-1703-126553.html
#Nextloud #BSI #Owncloud #Server #Applikationen #Security

Alte Owncloud und Nextcloud-Versionen: Parteien und Ministerien nutzen unsichere Cloud-Dienste - Golem.de

Das BSI warnt Organisationen und Parteien vor Schwachstellen in ihren Cloud-Diensten. Viele haben bis heute nicht darauf reagiert. Golem.de konnte entsprechende Warnungen
Carol Chen
7 years ago
diasporist wrote the following post:

Tor at the Heart: Qubes OS



https://blog.torproject.org/blog/tor-heart-qubes-os Qubes OS is a security and privacy-oriented free and open source operating system that provides you with a safe platform for communications and information management. Its architecture is built to enable you to define different security environments (or "qubes") on your computer to manage the various parts of your digital life, including safely using Tor. #qubes #qubesos #tor #torattheheart #privacy #opensource #OS #security #edwardsnowden #anonymity #whonix #vm #virtualization

Tor at the Heart: Qubes OS | The Tor Blog

Jason Robinson
7 years ago from mobile
https://twitter.com/sehnaoui/status/817266179429593088

So true.

#Security

Khalil Sehnaoui on Twitter

“If the media stopped saying 'hacking' and instead said 'figured out their password', people would take password security more seriously.”
diasporist
7 years ago

Tor at the Heart: Qubes OS



https://blog.torproject.org/blog/tor-heart-qubes-os Qubes OS is a security and privacy-oriented free and open source operating system that provides you with a safe platform for communications and information management. Its architecture is built to enable you to define different security environments (or "qubes") on your computer to manage the various parts of your digital life, including safely using Tor. #qubes #qubesos #tor #torattheheart #privacy #opensource #OS #security #edwardsnowden #anonymity #whonix #vm #virtualization

Tor at the Heart: Qubes OS | The Tor Blog

Björn Schießle
8 years ago from mobile
Sounds really interesting, some people want to work on a new Android ROM with a focus on privacy and software freedom. Especially, I like the idea of having a custom ROM which comes with build in microG support.

Please help them by participating in their survey https://form.responster.com/qVIgex

#android #microG #FreeSoftware #privacy #security
Image/photo
(((Arthur Schiwon)))
8 years ago

Into the symmetry: The RFC 5114 saga


In a nutshell the authors of the paper were able to reuse some theory from the '90s and introduce a backdoor into a 1024 prime such that:
1. it would be feasible for the creator of the backdoor to calculate discrete log
2. it would be impossible for anybody else to prove that this particular number was actually backdoored!
As we said at the begin of the post, RFC5114 violates the Nothing up my sleeve principle making it a possible backdoor candidate (but here is where the speculations start).

http://blog.intothesymmetry.com/2016/10/the-rfc-5114-saga.html

#dh #security #backdoor #rfc #rfc5114

The RFC 5114 saga

Back in January I posed a question "to the Internet": What the heck is RFC 5114? It looks like a lot happened since then around it. I would...
Brad Koehn
8 years ago

Someone Is Learning How to Take Down the Internet


Over the past year or two, someone has been probing the defenses of the companies that run critical pieces of the Internet. These probes take the form of precisely calibrated attacks designed to determine exactly how well these companies can defend themselves, and what would be required to take them down. We don't know who is doing this, but it feels like a large a large nation state. China or Russia would be my first guesses.

https://www.schneier.com/blog/archives/2016/09/someone_is_lear.html

#schneier #internet #security

Someone Is Learning How to Take Down the Internet - Schneier on Security

Arthur Schiwon
8 years ago
jospoortvliet Poortvliet wrote the following post:
Image/photo
I just published a blog with an overview of the #Nextcloud conference program! It'll be a great event, share the news ;-)

#privacy #selfhosting #security #Nextcloud #ownCloud #cloud #Dropbox #googledrive #google #seeallthosetags #berlin
Image/photo
I just published a blog with an overview of the #Nextcloud conference program! It'll be a great event, share the news ;-)

#privacy #selfhosting #security #Nextcloud #ownCloud #cloud #Dropbox #googledrive #google #seeallthosetags #berlin
For those in or around Munich, Meredith L. Patterson, a developer, writer, blogger, and journalist, currently contributing e.g. to the Tor project, will be giving a talk next week.


view full size



Hosted by the Ethereum Meetup group on Tuesday, the 20th of September.

https://www.meetup.com/de-DE/Ethereum-Munich/events/233581689/

(We, the Bitcoin Meetup group, originally wanted to co-host, but our usual location is not available on that date, so we'll do an additional event with a different program the next day.)

#event #meetup #ethereum #blockchain #security #privacy #cryptography #tor #muc #munich

Meredith L. Patterson - Wikipedia, the free encyclopedia

Arthur Schiwon
8 years ago from Diaspora
mjg59 | Circumventing Ubuntu Snap confinement • https://goo.gl/CvMCX9 • I've produced a quick proof of concept of this. Grab XEvilTeddy from git, install Snapcraft (it's in 16.04), snapcraft snap, sudo snap install xevilteddy*.snap, /snap/bin/xevilteddy.xteddy . An adorable teddy bear! How cute. Now open Firefox and start typing, then check back in your terminal window. Oh no! All my secrets. Open another terminal window and give it focus. Oh no! An injected command that could instead have been a curl session that uploaded your private SSH keys to somewhere that's not going to respect your privacy.
#Ubuntu #snappy #snap #security #xorg #x #Mir #Wayland
- via Diaspora* Publisher -

mjg59 | Circumventing Ubuntu Snap confinement

Mikaela Suomalainen
8 years ago from Diaspora
mjg59 | Circumventing Ubuntu Snap confinement • https://goo.gl/CvMCX9 • I've produced a quick proof of concept of this. Grab XEvilTeddy from git, install Snapcraft (it's in 16.04), snapcraft snap, sudo snap install xevilteddy*.snap, /snap/bin/xevilteddy.xteddy . An adorable teddy bear! How cute. Now open Firefox and start typing, then check back in your terminal window. Oh no! All my secrets. Open another terminal window and give it focus. Oh no! An injected command that could instead have been a curl session that uploaded your private SSH keys to somewhere that's not going to respect your privacy.
#Ubuntu #snappy #snap #security #xorg #x #Mir #Wayland
- via Diaspora* Publisher -

mjg59 | Circumventing Ubuntu Snap confinement

Cristóbal Gallardo Lüttecke
9 years ago from Diaspora
Image/photo

The importance of COMMENTING


Translated from Spanish into English. Thanks to @Diego* (diaspora-fr.org) for the original post. I've written this post to Exercise my English abilities. Generally I translate in the other sense (English/Spanish); so I request you to apologize me grammatical errors.
"If you have and apple and I have an apple, and we exchange these apples, then You and I will still each have one apple. But, if you have an Idea and I have an Idea and we exchange these ideas, then each of us will have two ideas." George Bernard Shaw

There are several differences amongst #Diaspora and other traditional #socialnetworks. But; obviously there is one that everyone can distinguish with a simple view: the user's posts quality

Permanently, we can see/read excellent posts about many subjects: #art, #traveling, #gnulinux #freesoftware #libresoftware, #security, #privacy, etc. The list can grow and grow. However; the posts can't generate by themselves: We have this richness of stuff by the effort of #Diaspora User Community. They put on their posts their time, their work (for example, formatting text in #markdown) to publish things that like, love or interest them.

The Magic Word is #Sharing



The strength of #Diaspora belongs to its Community. The Community shines by itself, spreading light to each part of Diaspora and make us feeling it alive. Who signs up and walks its first steps on #Diaspora is reaching a environment where kindness and coolness have their realm. But Diaspora is too much. It means a way of life, almost a life philosophy. It's all about #freedom. The freedom to have the choosing power to share whatever you want with those ones you wish. And it is a fantastic thing, because this social network fills itself with interesting stuff.

The key is #interaction



Every social network commentary final purpose is the #interaction that the members make amongst them. If we are here is because we want sharing things and interact with people. When someone shares something, Diaspora gives us the tools to participate with that post. We would add it to our favorites, clicking on "#Like" (or the famous #heart if you are on mobile version), we would reshare it and our third option: we could make some comment

We need to be honest here: We made some commentary on the posts that we read/saw a few. We are not accustomed to leave comments. The many of us are clicking on "#Like" or "#Reshare" as our better option; in a mechanic way. Without know it or ignoring it, we are losing all the fun that the Diaspora social network can provide us. Of course, people have their reasons to don't leaving comments. Let's check them out.

Reasons because We don't comment

  • Because We agreed with the things what we had read.

    "Why Do I need to leave some comment? When you agreed with something, it doesn't appear necessary adding more stuff, It's all said.. !!
  • Because, We didn't agree with the post content, but We didn't how to say our thoughts/opinions

    I didn't want to start a discuss with people who I didn't know. Besides; Why should I say that I didn't agree with the things those I was reading? Perhaps, It could mean anyone would answer me, starting a discuss. A lot of work. My best option is to keep silence saying anything.
  • Because when sometimes I commented a post leaving my thoughts, I never received a reply (T.T)

    I remember the time when I was a full time Diaspora active member, but I didn't receive any reply. So, I decided no losing time writing comments.

Why commenting is an Important thing?



Please ; watch out the following graphic:Image/photo

This summarize the thing that I want to tell you. Give a thought and receive another. It's all about creating communication, to show us amongst ourselves; and; to support/help us to ourselves. This is the core/essence of a community. I could say this is the core of all communities.

Commenting is an important thing because:

  • It creates a mutual relationship in several sensesWe feed and benefit with comments amongst us. It's a interesting thing knowing how the other people are thinking about particular matters. It's necessary to get started a communication in two both senses, and, to get that other users will answer your commentary.
  • Sharing your thoughts with others is a good way to get new relationshipsWhen you discover a publishing that you like or interest you, you will ever find to say some things on the text what you have read. Searching people whose have the same thought isn't easy, but finding people who discusses a matter on a healthy way (without trolling, for example) is really, really hard. However it is greatly pleasing, and it could give you some personal satisfaction.
  • You can know wonderful peopleThe commentaries are our first step to get started a community, I don't talk of posting activity; I am talking about the people, it is about the community that can be born around Diaspora Users. We are making a great space here to share and talk. It would be the first point to start a friendship with people who commenting and would have same interests with you. Open your mind and believe in this possibility, I said you it for experience ;)
  • You can find people who help youWith commentaries we are making the place to us, a place in where exists the possibility to have kindness and wonderful conversations. We don't have the sames thoughts or opinions. We don't need them. However, the thing that the many have is the wish to learn, teach or talk. The experience and the possibility to request help to people who live in different parts of the world, it's so cool.
  • It's a way to acknowledge the author for its work writing that post.
If you find useful the information or if you like what you had read; commenting transforms itself on a way to say "thanks" to its author and show her/him that exists someone who finds useful the information.

For this; besides publishing your own posts, you could participate on the other user posts. Comment and get started some discuss. It will make a richness commentary "rain" to two both; who comments it and- who answers it. :)

If you liked this post, please share and comment it :)
#diaspora #newhere #community #en #translating

comentar www.diasporalibre.com.ar/diasp_logo.jpg La importancia de COMENTAR Si hay algo que distingue a diaspora* de las demás red...

comentar http://www.diasporalibre.com.ar/diasp_logo.jpg
La importancia de COMENTAR
Si hay algo que distingue a diaspora* de las demás redes sociales, sin dudas es la calidad de sus publicaciones. Permanentemente vemos excelentes posts de diversos temas: #arte, #fotografía, #viajes, #música, #salud, #linux, #softwarelibre, #seguridad, #privacidad, etc. La lista puede hacerse interminable. Esa riqueza de contenido la tenemos gracias a los usuarios de la comunidad, que con esmero y dedicación comparten día a día las cosas que les gustan, que les apasionan, que les interesan.
La palabra mágica es compartir
Justamente, lo más destacable de diaspora* es su comunidad. Quienes se registran y comienzan a dar sus primeros pasos dentro de la red social, se encuentran con un ambiente cordial y ameno, donde abunda el altruismo y la buena onda. Pero diaspora* es más que eso. Es casi una filosofía de vida. Es tener la libertad de poder (por fin) elegir y compartir lo que quieras, con quien quieras...
James Valleroy
9 years ago from Diaspora
You can use apt-transport-tor to download #debian packages over #tor. Good for #privacy, #security, and #anonymity.

Just run:apt install apt-transport-tor
Then in your /etc/apt/sources.list, just put "tor+" in front of the http:// URLs, like this:deb tor+http://http.debian.net/debian unstable main

404 Not Found

Max der Zerstörer
9 years ago from Diaspora
Android hat ja bekanntermaßen einige schwachstellen. Nachdem wir an der Uni auf eine schwachstelle in der wlan konfiguration hingewiesen wurden, die es recht leicht möglich macht die zugangsdaten zu bekommen haben wir eine app geschrieben die das ganze absichert, allerdings ist diese nicht opensource. Ich habe die möglichkeit genutzt und angefangen eine oss app zu schreiben die allgemein für jedes WPA/WPA2-Enterprise netzwerk funktioniert. Momentan befindet sich die app und die github seite dazu noch im aufbau.
Wen der Bug interessiert: http://syssec.rub.de/media/infsec/veroeffentlichungen/2015/05/07/eduroam_WiSec2015.pdf Und hier meine app: https://github.com/enterpriseWifiSafeguard/EnterpriseWifiSafeguard

Aktuell sind noch einige schreibfehler und schönheitsfehler vorhanden die werden in den nächsten tagen entfernt :D Aber wer möchte ist dazu eingeladen die app zu testen und eventuell issues zu schreiben :D #wifi #android #security #wpa-enterprise #wpa2 #wpa
Max Mehl
9 years ago from Diaspora
Ach übrigens: Ich bin #NeuHier und bin an #freesoftware #privacy und #politics interessiert. Im IT-Bereich sind #linux #hosting und #security meine Favouriten. Weitere Tags wären #fsfe #scouting #guitar
André Koot RCX
9 years ago from Diaspora
Two Factor Authentication for #ownCloud https://www.howtoforge.com/tutorial/two-factor-authentication-with-owncloud/ #2FA #security

Two Factor Authentication for ownCloud

This tutorial shows you how to protect ownCloud logins with two factor authentication by using privacyIDEA to manage the second authentication factor....
Franz R.
9 years ago from Twitter for Android
#BSI #owncloud #IT #ITSecurity #security

Der Pate auf Twitter

“Das #BSI hat ein Dokument veröffentlicht, um #owncloud sicher zu betreiben https://t.co/8AuOtGljRF #IT #ITSecurity #security”
Brad Koehn
9 years ago from Diaspora
News that the Transportation Security Administration missed a whopping 95% of guns and bombs in recent airport security "red team" tests was justifiably shocking. It's clear that we're not getting value for the $7 billion we're paying the TSA annually.

But there's another conclusion, inescapable and disturbing to many, but good news all around: we don't need $7 billion worth of airport security. These results demonstrate that there isn't much risk of airplane terrorism, and we should ratchet security down to pre-9/11 levels.
https://www.schneier.com/blog/archives/2015/06/reassessing_air.html

#schneier #security #tsa #terrorism #aviation

Reassessing Airport Security - Schneier on Security

ownCloud
9 years ago from Diaspora
We just released the 8.0.4, 7.0.6 & 6.0.8 updates with many smaller and larger improvements and fixes. Get them while they're still hot ;-) #privacy #security

Changelog | ownCloud.org

jospoortvliet Poortvliet
9 years ago from Diaspora
Secure your #ownCloud ! Learn about the basics in the Security Guide #security #server

Owncloud: ownCloud Server Administration Manual

ownCloud aims to ship with secure defaults that do not need to get modified by administrators. However, in some cases some additional security hardening can only be applied in scenarios were the administrator have complete control over the ownCloud instance. This document lists some security hardenings which require manual interaction by administrators.
newer older