Email or username:

Password:

Forgot your password?
30 posts total
Kevin Beaumont

The security of the average enterprise grade VPN product.

Show previous comments
C.Suthorn :prn:

@GossiTheDog

It works perfectly to keep wheelchairs out.

DELETED

@GossiTheDog you act like avpn will do anything in the future when we have widespread quantum computing

labria

@GossiTheDog @bread80 nah, that’s not Enterprise Grade. _this_ is!

Kevin Beaumont

How to out compete any major tech vendor right now: work in the same space as their core products - but just don't put anything AI in the product.

They're all so distracting tickling their own bollocks with AI right now they've completely lost focus on their core products and real customer needs.

CaliCarol

@GossiTheDog

For sure. Google maps has lost its goddam mind. I'm guessing it's a deliberate degradation of a free service in order to roll out paid, but it could just be eyes off the ball.

il_fritz

@GossiTheDog

oh noes you have joined in with the anti-AI hysteria too

Show previous comments
hnapel

@GossiTheDog

"the investigation was focused on a lack of moderators on Telegram"

If I were a billionaire with a private jet, owner of a notorious social media platform and the initials E.M. I would take notice.

Ban El Al from our skies

@GossiTheDog He has dual citizenship - so being arrested by the French may be safer than being targeted by the FSB

Kevin Beaumont

Every so often some Linux guy replies to me saying ‘no critical infrastructure runs Windows’, so I just gotta say, today is education for you.

Show previous comments
Soul Dessin

@GossiTheDog
Hehe

We're still alive. So, it wasn't that critical. ;p

IAG

@GossiTheDog no critical infrastructure should* run Windows

Jimmy Hoke :tardis:

@GossiTheDog

Correction: no critical infrastructure *should* run windows.

But this once isn’t actually a windows problem, just a problem that happened to be on windows.

Kevin Beaumont

Crowdstrike published a faulty update. Causes Windows to bluescreen. Driver is C-00000291*.sys. Will cause worldwide outages. Thread follows, I suspect. 🧵

Kevin Beaumont

I am obtaining a copy of the driver to see if malicious or bad coding, if anybody else checking let me know.

Kevin Beaumont

Okay I knew Opera browser was bad but I had no idea how crazy the situation was until reading this.

spacebar.news/stop-using-opera

Show previous comments
JKN

@GossiTheDog Wait till you learn about Brave!

PublicLewdness

@GossiTheDog

I would have never used Opera due to it not being FOSS but it's always nice to have more reasons.

Nihl L'Amas

@GossiTheDog Opera Mini for java phones will randomly redirect you to full-screen ads instead of whatever link you clicked on.

Kevin Beaumont

Google search thinks you should use glue to stick together a pizza as its AI is trained on Reddit, where 11 years ago a user called “fucksmith” posted suggesting it was a good idea.

Show previous comments
IanMoore3000

@GossiTheDog I am unable to replicate this result.

Tallawk

@GossiTheDog Google Search is now a gullible 6-year old my how far we've come

Kevin Beaumont

For those who aren’t aware, Microsoft have decided to bake essentially an infostealer into base Windows OS and enable by default.

From the Microsoft FAQ: “Note that Recall does not perform content moderation. It will not hide information such as passwords or financial account numbers."

Info is stored locally - but rather than something like Redline stealing your local browser password vault, now they can just steal the last 3 months of everything you’ve typed and viewed in one database.

Show previous comments
David Plisken 🏳️‍⚧️ BLM!

@GossiTheDog gotta train the AI. Nothing is now important to MS than AI. Gotta create that corpus of data to sell to other AI companies. The products are no longer for us, we and its behaviors are just data to save and sell.

Andreas Bulling

@GossiTheDog The solution is simple and has been around for decades: Use Linux.

I don't understand why people bother with Microsoft and Windows at all anymore.

Positive side effect (out of many more): I don't even remember the last time that I've installed/used an "anti virus" software.

Kevin Beaumont

I've written up my thoughts on the Copilot Recall feature in Microsoft Copilot+ PCs

I think it will enable fraud and endanger users, and is not the sign of a company who are committed to security first.

doublepulsar.com/how-the-new-m

Kevin Beaumont

Slack have decided to start training AI on enterprise customer data, including DMs, private workspaces and files. You have to have admin opt out via email. HT @Quinnypig

slack.com/intl/en-gb/trust/dat

Show previous comments
Räucherkäse

@GossiTheDog And of course they're not explaining *how* they're going to implement those "controls".

Jigme Datse

@GossiTheDog @Quinnypig or as I've been doing for years, opt out of Slack. I'd say go with something like Jitsi/Matrix but that's not for everyone.

Show previous comments
pinkdrunkenelephants

@GossiTheDog *sigh* So now I need to put Linux on the one computer I had set up for casual use. More work for me, yay 😞

Paradigma

@GossiTheDog The absurdity of this manufactured society never stop to amusing me. Thankfully we have great minds and open source.

Kevin Beaumont

HT to @wdormann here - somebody has backdoored the open source project XZ which has downstream impacts.

For example, although OpenSSH doesn’t use XZ, Debian patch OpenSSH and introduced a dependency which translates as the XZ changes introducing a sshd authentication bypass backdoor it appears.

One dude bothered to investigate in his free time about why ssh was running slow, so it was caught fairly early - i.e. hopefully before distros started bundling it.

openwall.com/lists/oss-securit

HT to @wdormann here - somebody has backdoored the open source project XZ which has downstream impacts.

For example, although OpenSSH doesn’t use XZ, Debian patch OpenSSH and introduced a dependency which translates as the XZ changes introducing a sshd authentication bypass backdoor it appears.

One dude bothered to investigate in his free time about why ssh was running slow, so it was caught fairly early - i.e. hopefully before distros started bundling it.

Show previous comments
Binary Large Octopus

@GossiTheDog @wdormann Several linux distros have already investigated how they're impacted by this (thanks @mgorny and @VoidLinux). Any takes on this from @almalinux and @alpinelinux?

alys

@GossiTheDog Debian Sid's and testing's liblzma has the backdoor, although it looks like it was reverted already. I don't think any official releases of Debian or Ubuntu had the compromised packaging. metadata.ftp-master.debian.org

Kevin Beaumont

Tabletop scenario: you lay off lots of IT staff to pivot to AI and automation with a goal to cost cut, and then your remaining IT staff, who don’t understand what they are doing due to lack of institutional knowledge, deploy an automation that breaks a critical business process and plunges the business into chaos.

Show previous comments
@infosec_jcp 🐈🃏 done differently

@GossiTheDog

No Notes. 📰

Don't tell this to the MBAs though. 🤫👂

Risotto

@GossiTheDog @hacks4pancakes the "onion is no longer satire it's prediction"

but for "tabletops I don't want to be real but are going to become real"

PointlessSpike

@GossiTheDog Taking shortcuts and conning people is capitalism 101. With technology that doesn't really work, or doors start falling off airplanes mid-flight. This is what happens when all you have is a degree in business with no knowledge of what your business actually does.

Show previous comments
Kevin Karhan :verified:

@GossiTheDog Also adding "Taiwanese" as Language or "Taiwan" as favorite cuisine / tourism destination may also work... ^^

fool

@GossiTheDog
And what if you don't want be phished via people in India?
"Modi"?

Kevin Beaumont

Queer.af mastodon instance has been shut down by the Taliban (not a joke, they seized the domain name).

akko.erincandescent.net/notice

Show previous comments
propapanda :verified:

@GossiTheDog

Welcome to Taliban IT services.

If you're part of a minority, press 1. Otherwise press 0.

A customer representative will be available shortly.

Matthew Skelton

@GossiTheDog "who owns or controls the registry for the TLD" seems a fairly important consideration for domain names, tbf

Jeena

@GossiTheDog i mean it's a cool tld but come on, once the Taliban took over the country the writing was on the wall.

Kevin Beaumont

2025 spoiler: middle managers at large corporations sucking up the water supply of Finland to use Copilot AI to generate PowerPoint pressos about their fake green initiatives.

Show previous comments
midka

@GossiTheDog we ain't got that much water :blob_smile_sweat:

It's super odd that I never see in the news how much natural resources and electricity all AI stuff actually use. Most people I've talked to have no idea.

Frank Bajak

@GossiTheDog how did I know that PowerPoint would eventually destroy the planet?

patrislav

@GossiTheDog and the UN climate conference will be hosted by an oil corporation ...oh wait that was already 2023

Kevin Beaumont

Pretty incredible report here about what is likely lawful interception of TLS encrypted communications (used by basically every web service) targeted at an instant messaging service popular in Russia..

the TLS communications were being recertificated in the middle (similar to how enterprise firewalls do TLS decryption) for six months to snoop on communications.. it only got rumbled as somebody (drum roll) let the interception certificate expire by mistake.

notes.valdikss.org.ru/jabber.r

Pretty incredible report here about what is likely lawful interception of TLS encrypted communications (used by basically every web service) targeted at an instant messaging service popular in Russia..

the TLS communications were being recertificated in the middle (similar to how enterprise firewalls do TLS decryption) for six months to snoop on communications.. it only got rumbled as somebody (drum roll) let the interception certificate expire by mistake.

Show previous comments
GrumpSec Spottycat

@GossiTheDog I assume they did the ACME bit from somewhere else or the MITM box and then just MITMed the rest of the ACME flow that should’ve gone to the actual VM?

Kevin Beaumont

Back in the 90s, when I was 11, I had a conversation on Usenet with this dude called Todd Howard, who said he wanted to make a space RPG. I am 41. Today, it arrived.

Show previous comments
Tony Hoyle

@GossiTheDog I don't think there has been a game this hyped ever. Even cyberpunk seemed less (and that literally had fanboys saying 'this will change gaming forever' until it was released and they actually saw it..).

Kevin Beaumont

Random bit of Microsoft telemetry dropped in this WSJ piece, good to know they’re tracking key presses.

Show previous comments
Josh Carlson

@GossiTheDog
Depending on your job, keyboard activity and productivity aren't necessarily the same thing. I spend a lot of keystrokes when I am responding to ridiculous inter-departmental emails, and that usually has no productive value at all.

What is the benefit of knowing when people are typing a lot?

Chase :unverified: :verified: :loading:

@GossiTheDog i wonder how they are using this data internally other than for marketing.

Kevin Beaumont

Mastodon has hit 2 million active users today. 🎉

Go Up