Email or username:

Password:

Forgot your password?
10 posts total
BrianKrebs

TIL you can quickly find your own posts by including "from:me" in the search box and then a key word or phrase you're searching for. Yes, it took me this long to figure that out.

Show previous comments
CatSalad🐈🥗 (D.Burch) :blobcatrainbow:

@briankrebs Seems you can also negate that field.

-from:catsalad

(everything but 🐈🥗)

Tim Bray

@briankrebs In the default Masto web app (which I don't normally use) if you start typing in the search box, it pops up lots of helpful hints about useful things search can do.

BrianKrebs

It's always amazed me that ID.me, which you have to use in order to interact w/ the IRS online these days, has a top level domain from the country of Montenegro. Ublock Origin says they're injecting tracking links from Italy's TLD when you login at the irs.gov website.

What's next? Cookies from Colombia? AI from Anguilla?

Show previous comments
Mike Loukides

@briankrebs Do the cookies from Columbia come with coffee?

Victor S Sigmoid

@briankrebs I propose a law that bars third party data brokers from any site or interaction which directly or indirectly requires government ID per law. KYC and tax are two examples. Any related data should be tainted as "fruit of the ID Tree" and restricted from outside the authority collecting it.

Christie Dudley

@briankrebs What's worse is that this is for a US government website. You would think they would have access to their own domain names or something.

BrianKrebs

Google is too big to fail, and yet they seem to be failing at basic things they used to do well (like search) while removing useful features (like cache) and adding a bunch of crap nobody needs or wants.

Want to know if a given domain name shows up anywhere in search? Well screw you, we're not going to tell you that anymore, but here's 1,400 completely useless and irrelevant results that could possibly have some info (but don't). When the search engine could have done what it's done for years, and admit that it doesn't know WTF you're talking about and say "no results found." Now it just makes shit up if it doesn't know the answer.

Hey cool! My search result shows the term I was looking for is present on 7 websites. Shoot! None of them are online anymore. How about showing us your cached version of the site, you know the one that was used to create this search result? Oh wait, no, you can't see that anymore. Why? Here's Danny Sullivan's dismissive and mystifying explanation: "“It was meant for helping people access pages when way back, you often couldn’t depend on a page loading,” Sullivan wrote on X. “These days, things have greatly improved. So, it was decided to retire it.”

Want software? Great, Google will serve a malicious ad on top that looks a lot like an organic search result but which is paid for by scammers and installs malware.

Google is too big to fail, and yet they seem to be failing at basic things they used to do well (like search) while removing useful features (like cache) and adding a bunch of crap nobody needs or wants.

Want to know if a given domain name shows up anywhere in search? Well screw you, we're not going to tell you that anymore, but here's 1,400 completely useless and irrelevant results that could possibly have some info (but don't). When the search engine could have done what it's done for years, and...

Show previous comments
💡𝚂𝗆𝖺𝗋𝗍𝗆𝖺𝗇 𝙰𝗉𝗉𝗌📱

@briankrebs
What they say: too big to fail
What I hear: we have a financial interest

Curious Boy

@briankrebs

Not only google search
The same thing applied to YouTube

Rupert Reynolds

@briankrebs Cory Doctorow has a word fot that for that :-)

BrianKrebs

Didn't realize my wireless plan capped tethering speeds, but now it makes sense. When your phone gets ~10-15 mbps and your tethered computer gets .5 or .6 consistently, you know they're screwing w/ the service you paid for.

Welp, I'm ashamed it took me this long to realize, but changing the TTL on my computer seems to have released the throttling.

reddit.com/r/Android/comments/

Show previous comments
Bai Shen

@briankrebs Hak5 did a whole segment on this back in the day. I want to say they showed up to configure the phone to change the ttl to 64 but it's been ages since I watched the episode.

Dominik

@briankrebs I have 350 Mbit/s but as a hotspot I only get 20-40 Mbit/s out of it. Also there is no option at all to get a wired wifi here. So it is sadly the only option.

rdfhrn

@briankrebs do you know where such things are done by providers? I've never heard of such here in germany and never had bandwidth issues on tethered devices.

BrianKrebs

One of the more limiting things about Signal is you have to give out your mobile number to everyone. Even if it is a burner, I still don't want to advertise to the world that it's mine.

Was happy to read today that Signal is now beta testing a new username feature.

community.signalusers.org/t/pu

BrianKrebs

Today marks one year since I walked away from 360,000 followers on that other site and joined this incredible community here!

That was easily one of the most positive moves I've ever made, and I frankly haven't looked back. Thank you to @jerry and everyone else who keeps this place humming. Come to think of it, it's time to renew our annual support!

joinmastodon.org/sponsors

Show previous comments
mnb

@briankrebs @jerry just downloaded this app and like 20% of the posts i see are about X lmao

Arsimael Inshan

@briankrebs @jerry I don't miss the constant arguing, insulting and gaslightning.

I also don't miss Mrs. Smith, Hair stylist talking about how Covid vaccines spread turbo-cancer, because Mr. Braindead, her Sisters cousins colleague from work at McDonald's said so.

I don't have any remorse emptying the old account and leave it there to rot.

And I bet, you still have those followers. Just not all of them have a mastodon account. Which you don't need since Mastodon isn't blocking content and ask you to please create an account.

@briankrebs @jerry I don't miss the constant arguing, insulting and gaslightning.

I also don't miss Mrs. Smith, Hair stylist talking about how Covid vaccines spread turbo-cancer, because Mr. Braindead, her Sisters cousins colleague from work at McDonald's said so.

I don't have any remorse emptying the old account and leave it there to rot.

BrianKrebs

There's an important vulnerability being disclosed today that allows attackers to massively increase the size of DDoS attacks.

The flaw is being tracked as CVE-2023-44487, a.k.a. "HTTP/2 Rapid Reset Attack." According to Damian Menscher at Google, the attack "works by sending a request and then immediately cancelling it (a feature of HTTP/2). This lets attackers skip waiting for responses, resulting in a more efficient attack."

More info:

cloud.google.com/blog/products

aws.amazon.com/blogs/security/

aws.amazon.com/security/securi

cloudflare.com/press-releases/

There's an important vulnerability being disclosed today that allows attackers to massively increase the size of DDoS attacks.

The flaw is being tracked as CVE-2023-44487, a.k.a. "HTTP/2 Rapid Reset Attack." According to Damian Menscher at Google, the attack "works by sending a request and then immediately cancelling it (a feature of HTTP/2). This lets attackers skip waiting for responses, resulting in a more efficient attack."

Show previous comments
Karsten Johansson

@briankrebs I used to teach in my penetration testing course that all you need to do to find your own 0-days is ... rtfm!

Григорий Клюшников

I'm confused by the HTTP 1.1 diagram. What about request pipelining? Or do common web servers work such that the client is required to receive the response to their first request before the second one will be processed?

BrianKrebs

404 Media found that when you write about LSD, MDMA, guns, and stolen credit cards for sale on Instagram, IG flags you for not following their recommended guidelines -- i.e. for calling attention to stuff that is blatantly in violation of their own policies but that is nevertheless inexplicably left alone.

404media.co/instagram-throttle

Hey, this bury your head in the sand approach has worked for Meta/FB for years. Why stop now?

404 Media found that when you write about LSD, MDMA, guns, and stolen credit cards for sale on Instagram, IG flags you for not following their recommended guidelines -- i.e. for calling attention to stuff that is blatantly in violation of their own policies but that is nevertheless inexplicably left alone.

Show previous comments
Del

@briankrebs They are concerned about their profits. The most efficient solution to prevent damage to their profits is to stop people from noticing there’s a problem, rather than attempting to fix the problem.

Anca

@briankrebs @lisamelton oof. It’s like it’s easier to shoot the messenger than to correct the problem.

BrianKrebs

I recently profiled a person involved in a series of particularly aggressive spam campaigns advertising crypto scams that involved so many fake new accounts that it briefly disrupted registration on some Mastodon communities.

krebsonsecurity.com/2023/05/in

Trend Micro has a new report out which states that the person I profiled was an affiliate of the "Impulse Team," a Russian-language moneymaking scheme that pays people to promote fake crypto investment platforms. Impulse Team has been operating since at least Sept. 2021.

trendmicro.com/en_us/research/

I recently profiled a person involved in a series of particularly aggressive spam campaigns advertising crypto scams that involved so many fake new accounts that it briefly disrupted registration on some Mastodon communities.

krebsonsecurity.com/2023/05/in

BrianKrebs

I'm pretty sure Mastodon is the first social network I've been on that didn't immediately ask me to betray all of the people in my address book.

Show previous comments
Evan Holt

@briankrebs @chad It’s funny you should say that. I just installed Artifact (from the original creators of Instagram) which curates news articles that it thinks you will enjoy reading. So far so good… up until yesterday when out of the blue it asked me for my address book *sigh*.

ṫẎℭỚ◎ᾔ ṫ◎ℳ

@briankrebs At least didn't immediately get betrayed by Medical Group Inc👨‍⚕️ security breach notification letter I
just got✉️ 📬 🤦 "Ransomware cyber attack" :blob_dizzy_face: Credit monitoring Norton LifeLock offer 1 year meanwhile, SSN, DOB, address, medical info :headdesk: :fire_angry:

According to the Southern California health-care organizations, which include Regal Medical Group, Lakeside Medical Organization, ADOC Medical Group, and Greater Covina Medical, the security breach happened around December 1, 2022.

Medicine wholesaler AmerisourceBergen has also come under attack from Lorenz ransomware.

The American biz, currently under investigation by the US Department of Justice for allegedly misplacing "hundreds of thousands" of prescription opioids, confirmed a limited breach of its systems on Friday.

"AmerisourceBergen's internal investigation quickly identified that a subsidiary's IT system was compromised," it said. "We immediately engaged the appropriate teams to limit the intrusion, contained the disruption and took precautionary measures to ensure all systems were and are now clear of any intrusions."

"After extensive review, malware was detected on some of our servers, which a threat actor utilized to access and exfiltrate data," according to a notice posted on Regal's website and filed with the California Attorney General's office.

The medical outfit said it hired third-party incident responders to assist and worked with security vendors to restore access to its systems and determine what data was impacted.

Judging from the filings with various state and federal agencies, the news wasn't good.

Extortionists stole, among other things, from the medical groups: patients' names, social security numbers, addresses, dates of birth, diagnosis and treatment information, laboratory test results, prescription data, radiology reports, health plan member numbers, and phone numbers.

And according to the US Department of Health and Human Services, which is investigating the database breach, it affected 3,300,638 people.

Further reading:1

As required by section 13402(e)(4) of the HITECH Act, the Secretary must post a list of breaches of unsecured protected health information affecting 500 or more individuals.

This page lists all breaches reported within the last 24 months that are currently under investigation by the Office for Civil Rights.

1 U.S. Department of Health and Human Services Office for Civil Rights — Breach Portal: Notice to the Secretary of HHS Breach of Unsecured Protected Health Information, last updated 3 Feb. 2023, ocrportal.hhs.gov/ocr/breach/b

@briankrebs At least didn't immediately get betrayed by Medical Group Inc👨‍⚕️ security breach notification letter I
just got✉️ 📬 🤦 "Ransomware cyber attack" :blob_dizzy_face: Credit monitoring Norton LifeLock offer 1 year meanwhile, SSN, DOB, address, medical info :headdesk: :fire_angry:

According to the Southern California health-care organizations, which include Regal Medical Group, Lakeside Medical Organization, ADOC Medical Group, and Greater Covina Medical, the security breach happened around...

Go Up