home.social

#badsecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #badsecurity, aggregated by home.social.

  1. After signing out of Netflix on the hotel TV before going to sleep, I browsed around all the various internet-connected apps and streaming services…

    …and logged out of probably 6 or 7 other accounts (no name duplicates) in various apps.

    Wild that people just leave these connections “lying around” all over the place.

    Probably worthless me signing those other people’s accounts out, but still…

    #internetsecurity #digitalsecurity #digitalbreadcrumbs #badsecurity

  2. @signalapp Signal IMO has bad security because when someone decides they are not interested in an overpriced, underperforming service of "phone number" and stops using their SIM, they cannot deregister the number from Signal and the new owner of the number either can hijack their Signal account, or people may be blocked from using newly purchased SIMs with Signal.

    Also, authoritarian regimes IMO can temporarily transfer a number into a provider's internal SIM in order to hijack a Signal account and impersonate a dissident against another dissident, facilitating abduction, torture and murder.

    I feel

    c o n t e m p t

    towards Signal when it is designed this way.

    #badsecurity #incompetence #signal #phonenumberasidentity #security #SIM #contempt #securityhole #securityflaw #attack #hijacking #torture #murder #abduction #authoritarianism #regime #authoritarian

  3. @signalapp Signal IMO has bad security because when someone decides they are not interested in an overpriced, underperforming service of "phone number" and stops using their SIM, they cannot deregister the number from Signal and the new owner of the number either can hijack their Signal account, or people may be blocked from using newly purchased SIMs with Signal.

    Also, authoritarian regimes IMO can temporarily transfer a number into a provider's internal SIM in order to hijack a Signal account and impersonate a dissident against another dissident, facilitating abduction, torture and murder.

    I feel

    c o n t e m p t

    towards Signal when it is designed this way.

    #badsecurity #incompetence #signal #phonenumberasidentity #security #SIM #contempt #securityhole #securityflaw #attack #hijacking #torture #murder #abduction #authoritarianism #regime #authoritarian

  4. @signalapp Signal IMO has bad security because when someone decides they are not interested in an overpriced, underperforming service of "phone number" and stops using their SIM, they cannot deregister the number from Signal and the new owner of the number either can hijack their Signal account, or people may be blocked from using newly purchased SIMs with Signal.

    Also, authoritarian regimes IMO can temporarily transfer a number into a provider's internal SIM in order to hijack a Signal account and impersonate a dissident against another dissident, facilitating abduction, torture and murder.

    I feel

    c o n t e m p t

    towards Signal when it is designed this way.

    #badsecurity #incompetence #signal #phonenumberasidentity #security #SIM #contempt #securityhole #securityflaw #attack #hijacking #torture #murder #abduction #authoritarianism #regime #authoritarian

  5. @signalapp Signal IMO has bad security because when someone decides they are not interested in an overpriced, underperforming service of "phone number" and stops using their SIM, they cannot deregister the number from Signal and the new owner of the number either can hijack their Signal account, or people may be blocked from using newly purchased SIMs with Signal.

    Also, authoritarian regimes IMO can temporarily transfer a number into a provider's internal SIM in order to hijack a Signal account and impersonate a dissident against another dissident, facilitating abduction, torture and murder.

    I feel

    c o n t e m p t

    towards Signal when it is designed this way.

    #badsecurity #incompetence #signal #phonenumberasidentity #security #SIM #contempt #securityhole #securityflaw #attack #hijacking #torture #murder #abduction #authoritarianism #regime #authoritarian

  6. @signalapp Signal IMO has bad security because when someone decides they are not interested in an overpriced, underperforming service of "phone number" and stops using their SIM, they cannot deregister the number from Signal and the new owner of the number either can hijack their Signal account, or people may be blocked from using newly purchased SIMs with Signal.

    Also, authoritarian regimes IMO can temporarily transfer a number into a provider's internal SIM in order to hijack a Signal account and impersonate a dissident against another dissident, facilitating abduction, torture and murder.

    I feel

    c o n t e m p t

    towards Signal when it is designed this way.

    #badsecurity #incompetence #signal #phonenumberasidentity #security #SIM #contempt #securityhole #securityflaw #attack #hijacking #torture #murder #abduction #authoritarianism #regime #authoritarian

  7. I'm not a hacker of any kind, but I was able to use native tools in Chrome to remove the "security measures" in place so I could remove the disabled copy/paste.

    But then I get my account created and I get logged in and then I find that the site doesn't have 2 Factor Authentication as an option for actual security?

    So.. I just thought I would share that experience.

  8. Today, #Simplii is driving me nuts. Apparently, this is not a strong enough password.

    No wonder people write them down on a post-it on their monitors.

    #Security #BadSecurity #Passwords #on #Postits #SimpliiFinancial #Banks #CyberSecurity #CIBC

  9. Today, #Simplii is driving me nuts. Apparently, this is not a strong enough password.

    No wonder people write them down on a post-it on their monitors.

    #Security #BadSecurity #Passwords #on #Postits #SimpliiFinancial #Banks #CyberSecurity #CIBC

  10. Today, #Simplii is driving me nuts. Apparently, this is not a strong enough password.

    No wonder people write them down on a post-it on their monitors.

    #Security #BadSecurity #Passwords #on #Postits #SimpliiFinancial #Banks #CyberSecurity #CIBC

  11. Today, #Simplii is driving me nuts. Apparently, this is not a strong enough password.

    No wonder people write them down on a post-it on their monitors.

    #Security #BadSecurity #Passwords #on #Postits #SimpliiFinancial #Banks #CyberSecurity #CIBC

  12. Today, #Simplii is driving me nuts. Apparently, this is not a strong enough password.

    No wonder people write them down on a post-it on their monitors.

    #Security #BadSecurity #Passwords #on #Postits #SimpliiFinancial #Banks #CyberSecurity #CIBC

  13. I opened a ticket at work because a [Mastodon site] in my network of places-to-go-for-news-and-help is blocked by our firewall. Response is “[IT Security has] asked for Manager approval and if the site is necessary to perform their duties. If you can please have ___ send us an approval we can send it to IT Security “

    Now the site is not _necessary_ for my job, but it sure is useful. It’s in the same mental bucket for me as Twitter and Reddit, neither of which are blocked.
    🧵
    #rant #BadSecurity

  14. So, here is what I am faced with. When asking why it is necessary to create an account to do something that is free to use, I am present with this. Instead of being able to do it the quick and easy way, I have to do a multi-step semi-complex process to get the same functionality.

    #unnecessarylogin #badsecurity #webdev #gamedev

  15. So, am I just old and out of touch or does anyone else have an issue with everything on the internet requiring a login account even when one is completely unnecessary? If I just need to download something that is free to download and use, I shouldn't be forced to create an account, right?

    #unnecessarylogin #badsecurity #webdev

  16. So, I have been playing Core Keeper for a while now. Today, they launched their built in Mod API and integration with Mod.io. That was kind of exciting at first. It is an easy way to use mods for the game after all. But unfortunately, it is not that simple. I have to create an account with Modio before it will let me install any mods. That is dumb and there is no reason it should be that way.

    #corekeeper #mods #techfails #badsecurity