home.social

#cryptographically — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cryptographically, aggregated by home.social.

fetched live
  1. The #LG [1] privacy / security debacle - where merely plugging in one of their monitors *silently* installs a spyware/adware application with system-level #privileges [2] and sets it to auto-start, also silently - reminded me of a question I've wondered about.

    The last version of Windows that I ran was Win98, so I'm rather out-of-date on my knowledge. It now supports #cryptographically signing programs [3] so you can #authenticate the source. I gather things distributed by the Microsoft store are all signed this way, but also #software distributed independently by larger companies.

    So my questions are:

    a) are programs from different companies signed with those companies' keys? Or is everything signed with a #Microsoft key so you can't differentiate between sources?

    b) can users blocklist particular #signing #keys? Or are these solely for Microsoft's benefit and only they can decide what keys are acceptable?

    Because if I was a #Windows user now, I would definitely want to #blocklist LG's signing key.

    [1] Am I the only one who used to sell their stuff when they used their full name?

    [2] Only with #Windows, natch.

    [3] I'll start calling programs "apps" when I'm dead, thanks.

    #LuckyGoldstar #adware #spyware #untrustworthy #UntrustedSoftware

  2. The #LG [1] privacy / security debacle - where merely plugging in one of their monitors *silently* installs a spyware/adware application with system-level #privileges [2] and sets it to auto-start, also silently - reminded me of a question I've wondered about.

    The last version of Windows that I ran was Win98, so I'm rather out-of-date on my knowledge. It now supports #cryptographically signing programs [3] so you can #authenticate the source. I gather things distributed by the Microsoft store are all signed this way, but also #software distributed independently by larger companies.

    So my questions are:

    a) are programs from different companies signed with those companies' keys? Or is everything signed with a #Microsoft key so you can't differentiate between sources?

    b) can users blocklist particular #signing #keys? Or are these solely for Microsoft's benefit and only they can decide what keys are acceptable?

    Because if I was a #Windows user now, I would definitely want to #blocklist LG's signing key.

    [1] Am I the only one who used to sell their stuff when they used their full name?

    [2] Only with #Windows, natch.

    [3] I'll start calling programs "apps" when I'm dead, thanks.

    #LuckyGoldstar #adware #spyware #untrustworthy #UntrustedSoftware

  3. The #LG [1] privacy / security debacle - where merely plugging in one of their monitors *silently* installs a spyware/adware application with system-level #privileges [2] and sets it to auto-start, also silently - reminded me of a question I've wondered about.

    The last version of Windows that I ran was Win98, so I'm rather out-of-date on my knowledge. It now supports #cryptographically signing programs [3] so you can #authenticate the source. I gather things distributed by the Microsoft store are all signed this way, but also #software distributed independently by larger companies.

    So my questions are:

    a) are programs from different companies signed with those companies' keys? Or is everything signed with a #Microsoft key so you can't differentiate between sources?

    b) can users blocklist particular #signing #keys? Or are these solely for Microsoft's benefit and only they can decide what keys are acceptable?

    Because if I was a #Windows user now, I would definitely want to #blocklist LG's signing key.

    [1] Am I the only one who used to sell their stuff when they used their full name?

    [2] Only with #Windows, natch.

    [3] I'll start calling programs "apps" when I'm dead, thanks.

    #LuckyGoldstar #adware #spyware #untrustworthy #UntrustedSoftware

  4. The #LG [1] privacy / security debacle - where merely plugging in one of their monitors *silently* installs a spyware/adware application with system-level #privileges [2] and sets it to auto-start, also silently - reminded me of a question I've wondered about.

    The last version of Windows that I ran was Win98, so I'm rather out-of-date on my knowledge. It now supports #cryptographically signing programs [3] so you can #authenticate the source. I gather things distributed by the Microsoft store are all signed this way, but also #software distributed independently by larger companies.

    So my questions are:

    a) are programs from different companies signed with those companies' keys? Or is everything signed with a #Microsoft key so you can't differentiate between sources?

    b) can users blocklist particular #signing #keys? Or are these solely for Microsoft's benefit and only they can decide what keys are acceptable?

    Because if I was a #Windows user now, I would definitely want to #blocklist LG's signing key.

    [1] Am I the only one who used to sell their stuff when they used their full name?

    [2] Only with #Windows, natch.

    [3] I'll start calling programs "apps" when I'm dead, thanks.

    #LuckyGoldstar #adware #spyware #untrustworthy #UntrustedSoftware

  5. The #LG [1] privacy / security debacle - where merely plugging in one of their monitors *silently* installs a spyware/adware application with system-level #privileges [2] and sets it to auto-start, also silently - reminded me of a question I've wondered about.

    The last version of Windows that I ran was Win98, so I'm rather out-of-date on my knowledge. It now supports #cryptographically signing programs [3] so you can #authenticate the source. I gather things distributed by the Microsoft store are all signed this way, but also #software distributed independently by larger companies.

    So my questions are:

    a) are programs from different companies signed with those companies' keys? Or is everything signed with a #Microsoft key so you can't differentiate between sources?

    b) can users blocklist particular #signing #keys? Or are these solely for Microsoft's benefit and only they can decide what keys are acceptable?

    Because if I was a #Windows user now, I would definitely want to #blocklist LG's signing key.

    [1] Am I the only one who used to sell their stuff when they used their full name?

    [2] Only with #Windows, natch.

    [3] I'll start calling programs "apps" when I'm dead, thanks.

    #LuckyGoldstar #adware #spyware #untrustworthy #UntrustedSoftware

  6. #MissKittyPolitics went right for the conclusion.
    -
    Applying distributed ledger technology to the financial records of the United States government is not a security threat, but rather a structural #upgrade to national #accountability. Transitioning #public #accounts to a #cryptographically ...

  7. For the 2nd time in weeks, #Microsoft packages laced with #credential stealer

    Dozens of #cryptographically verified #opensource packages from Microsoft were #compromised late last week to add advanced credential-stealing code that was triggered when #developers opened them in #AI coding #agents.

    In all, multiple researchers said, 73 packages were flagged as #malicious when automated systems on #GitHub blocked them on the platform. Rather than noting they are malicious—and that developers who used #AIagents to work with them should assume their systems are compromised—the Microsoft-owned GitHub said it disabled the packages “due to a violation of GitHub's terms of service.” The text went on to encourage the package owner to contact GitHub.
    #security

    arstechnica.com/security/2026/

  8. For the 2nd time in weeks, #Microsoft packages laced with #credential stealer

    Dozens of #cryptographically verified #opensource packages from Microsoft were #compromised late last week to add advanced credential-stealing code that was triggered when #developers opened them in #AI coding #agents.

    In all, multiple researchers said, 73 packages were flagged as #malicious when automated systems on #GitHub blocked them on the platform. Rather than noting they are malicious—and that developers who used #AIagents to work with them should assume their systems are compromised—the Microsoft-owned GitHub said it disabled the packages “due to a violation of GitHub's terms of service.” The text went on to encourage the package owner to contact GitHub.
    #security

    arstechnica.com/security/2026/

  9. For the 2nd time in weeks, #Microsoft packages laced with #credential stealer

    Dozens of #cryptographically verified #opensource packages from Microsoft were #compromised late last week to add advanced credential-stealing code that was triggered when #developers opened them in #AI coding #agents.

    In all, multiple researchers said, 73 packages were flagged as #malicious when automated systems on #GitHub blocked them on the platform. Rather than noting they are malicious—and that developers who used #AIagents to work with them should assume their systems are compromised—the Microsoft-owned GitHub said it disabled the packages “due to a violation of GitHub's terms of service.” The text went on to encourage the package owner to contact GitHub.
    #security

    arstechnica.com/security/2026/

  10. For the 2nd time in weeks, packages laced with stealer

    Dozens of verified packages from Microsoft were late last week to add advanced credential-stealing code that was triggered when opened them in coding .

    In all, multiple researchers said, 73 packages were flagged as when automated systems on blocked them on the platform. Rather than noting they are malicious—and that developers who used to work with them should assume their systems are compromised—the Microsoft-owned GitHub said it disabled the packages “due to a violation of GitHub's terms of service.” The text went on to encourage the package owner to contact GitHub.

    arstechnica.com/security/2026/

  11. For the 2nd time in weeks, #Microsoft packages laced with #credential stealer

    Dozens of #cryptographically verified #opensource packages from Microsoft were #compromised late last week to add advanced credential-stealing code that was triggered when #developers opened them in #AI coding #agents.

    In all, multiple researchers said, 73 packages were flagged as #malicious when automated systems on #GitHub blocked them on the platform. Rather than noting they are malicious—and that developers who used #AIagents to work with them should assume their systems are compromised—the Microsoft-owned GitHub said it disabled the packages “due to a violation of GitHub's terms of service.” The text went on to encourage the package owner to contact GitHub.
    #security

    arstechnica.com/security/2026/

  12. Your AI-Generated Password Could Be Cracked in Hours: Why ChatGPT and LLMs Make Terrible Random Number Generators New research from Kaspersky reveals that passwords generated by ChatGPT, Llama, and...

    #AISecurityPro #AI #generated #passwords #weak #ChatGPT #password #generator #cryptographically #secure #password

    Origin | Interest | Match
  13. $391.5 million restitution from @[email protected] for data privacy lawsuit, #cryptographically signing ZIP files, and a new privacy attack #exploiting every WiFi device in your building. Listen to Steve Gibson and @leo for more topics like this on Security Now:
    twit.tv/shows/security-now/epi

  14. $391.5 million restitution from @[email protected] for data privacy lawsuit, #cryptographically signing ZIP files, and a new privacy attack #exploiting every WiFi device in your building. Listen to Steve Gibson and @leo for more topics like this on Security Now:
    twit.tv/shows/security-now/epi

  15. $391.5 million restitution from @[email protected] for data privacy lawsuit, #cryptographically signing ZIP files, and a new privacy attack #exploiting every WiFi device in your building. Listen to Steve Gibson and @leo for more topics like this on Security Now:
    twit.tv/shows/security-now/epi

  16. $391.5 million restitution from @[email protected] for data privacy lawsuit, #cryptographically signing ZIP files, and a new privacy attack #exploiting every WiFi device in your building. Listen to Steve Gibson and @leo for more topics like this on Security Now:
    twit.tv/shows/security-now/epi

  17. $391.5 million restitution from @[email protected] for data privacy lawsuit, #cryptographically signing ZIP files, and a new privacy attack #exploiting every WiFi device in your building. Listen to Steve Gibson and @leo for more topics like this on Security Now:
    twit.tv/shows/security-now/epi