home.social

#digisec — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #digisec, aggregated by home.social.

fetched live
  1. Sometimes even I have trouble discerning #phishing from safe emails, and I do #digisec for a living!

    That's why it's always best to verify emails, texts and calls that look remotely like phishing.

  2. Sometimes even I have trouble discerning #phishing from safe emails, and I do #digisec for a living!

    That's why it's always best to verify emails, texts and calls that look remotely like phishing.

  3. Sometimes even I have trouble discerning #phishing from safe emails, and I do #digisec for a living!

    That's why it's always best to verify emails, texts and calls that look remotely like phishing.

  4. Sometimes even I have trouble discerning #phishing from safe emails, and I do #digisec for a living!

    That's why it's always best to verify emails, texts and calls that look remotely like phishing.

  5. Sometimes even I have trouble discerning #phishing from safe emails, and I do #digisec for a living!

    That's why it's always best to verify emails, texts and calls that look remotely like phishing.

  6. So I'm a #digisec trainer and consultant and I need to get a work phone so I can have a better work/life balance (and also for security reasons.)

    I currently have a Pixel 7 which I plan to keep as my personal phone. Should I...

    a) Get an iPhone for work and keep standard Android OS on my personal phone so I can give better guidance to users on each platform?

    b) Get an iPhone for work and switch to #GrapheneOS for my personal phone since I can already guide people on Android pretty well?

    c) Get a Pixel whatever for my work phone and put GrapheneOS on both phones, meaning I won't be able to help people on iPhones very well but I'll be rid of all this corporate spyware?

    What say ye?

  7. So I'm a #digisec trainer and consultant and I need to get a work phone so I can have a better work/life balance (and also for security reasons.)

    I currently have a Pixel 7 which I plan to keep as my personal phone. Should I...

    a) Get an iPhone for work and keep standard Android OS on my personal phone so I can give better guidance to users on each platform?

    b) Get an iPhone for work and switch to #GrapheneOS for my personal phone since I can already guide people on Android pretty well?

    c) Get a Pixel whatever for my work phone and put GrapheneOS on both phones, meaning I won't be able to help people on iPhones very well but I'll be rid of all this corporate spyware?

    What say ye?

  8. So I'm a #digisec trainer and consultant and I need to get a work phone so I can have a better work/life balance (and also for security reasons.)

    I currently have a Pixel 7 which I plan to keep as my personal phone. Should I...

    a) Get an iPhone for work and keep standard Android OS on my personal phone so I can give better guidance to users on each platform?

    b) Get an iPhone for work and switch to #GrapheneOS for my personal phone since I can already guide people on Android pretty well?

    c) Get a Pixel whatever for my work phone and put GrapheneOS on both phones, meaning I won't be able to help people on iPhones very well but I'll be rid of all this corporate spyware?

    What say ye?

  9. So I'm a #digisec trainer and consultant and I need to get a work phone so I can have a better work/life balance (and also for security reasons.)

    I currently have a Pixel 7 which I plan to keep as my personal phone. Should I...

    a) Get an iPhone for work and keep standard Android OS on my personal phone so I can give better guidance to users on each platform?

    b) Get an iPhone for work and switch to #GrapheneOS for my personal phone since I can already guide people on Android pretty well?

    c) Get a Pixel whatever for my work phone and put GrapheneOS on both phones, meaning I won't be able to help people on iPhones very well but I'll be rid of all this corporate spyware?

    What say ye?

  10. So I'm a #digisec trainer and consultant and I need to get a work phone so I can have a better work/life balance (and also for security reasons.)

    I currently have a Pixel 7 which I plan to keep as my personal phone. Should I...

    a) Get an iPhone for work and keep standard Android OS on my personal phone so I can give better guidance to users on each platform?

    b) Get an iPhone for work and switch to #GrapheneOS for my personal phone since I can already guide people on Android pretty well?

    c) Get a Pixel whatever for my work phone and put GrapheneOS on both phones, meaning I won't be able to help people on iPhones very well but I'll be rid of all this corporate spyware?

    What say ye?

  11. Anyone have any trusted resources for #digisec protection while traveling into or out of the US? (I've already got the ones from the EFF!)

  12. Anyone have any trusted resources for #digisec protection while traveling into or out of the US? (I've already got the ones from the EFF!)

  13. Anyone have any trusted resources for #digisec protection while traveling into or out of the US? (I've already got the ones from the EFF!)

  14. Anyone have any trusted resources for #digisec protection while traveling into or out of the US? (I've already got the ones from the EFF!)

  15. Anyone have any trusted resources for #digisec protection while traveling into or out of the US? (I've already got the ones from the EFF!)

  16. In 30 minutes I'm gonna guide a #trans organization through a #digisec threat modeling session and I'm gonna do everything I can to make it less-horrible for the participants and I hope that I don't cry

  17. In 30 minutes I'm gonna guide a #trans organization through a #digisec threat modeling session and I'm gonna do everything I can to make it less-horrible for the participants and I hope that I don't cry

  18. In 30 minutes I'm gonna guide a #trans organization through a #digisec threat modeling session and I'm gonna do everything I can to make it less-horrible for the participants and I hope that I don't cry

  19. In 30 minutes I'm gonna guide a #trans organization through a #digisec threat modeling session and I'm gonna do everything I can to make it less-horrible for the participants and I hope that I don't cry

  20. In 30 minutes I'm gonna guide a #trans organization through a #digisec threat modeling session and I'm gonna do everything I can to make it less-horrible for the participants and I hope that I don't cry

  21. Lots of folks at progressive nonprofits are freaked out because they see mailing list signups from [email protected] and other .gov email addresses and think that they are being monitored by the feds.

    That is a REAL email address that the federal government is using to let people snitch on their coworkers if they are secretly doing DEIA work.

    But I don't think the gov't is doing it to spy on orgs. These are public newsletters with (hopefully) non-sensitive content.

    So, this is my take on what's happening, from most to least likely:

    1) Individual or organized assholes are signing up real and fake opm.gov email addresses to scare people (apparently some of the signups are from addresses like [email protected])

    2) The federal government are signing up the real email address to intimidate organizers, or

    3) Someone who hates what's the federal government is doing thinks they are clever and are subscription bombing them on purpose to inundate the inbox with actual DEIA stuff, but don't get that they're scaring the very organizations they support.

    My suggestions for orgs who are experiencing this:

    1) Change the settings on your mailing list providers so that people need to click a link in a signup confirmation email in order to complete the signup. That way people who are signing up from fake email addresses can't complete the signup.

    2) Remove any opm.gov email addresses who successfully signed up, mostly for peace of mind.

    3) Don't ever share anything sensitive or private in your public newsletters!!!

    #digisec #fud #nonprofit

  22. Lots of folks at progressive nonprofits are freaked out because they see mailing list signups from [email protected] and other .gov email addresses and think that they are being monitored by the feds.

    That is a REAL email address that the federal government is using to let people snitch on their coworkers if they are secretly doing DEIA work.

    But I don't think the gov't is doing it to spy on orgs. These are public newsletters with (hopefully) non-sensitive content.

    So, this is my take on what's happening, from most to least likely:

    1) Individual or organized assholes are signing up real and fake opm.gov email addresses to scare people (apparently some of the signups are from addresses like [email protected])

    2) The federal government are signing up the real email address to intimidate organizers, or

    3) Someone who hates what's the federal government is doing thinks they are clever and are subscription bombing them on purpose to inundate the inbox with actual DEIA stuff, but don't get that they're scaring the very organizations they support.

    My suggestions for orgs who are experiencing this:

    1) Change the settings on your mailing list providers so that people need to click a link in a signup confirmation email in order to complete the signup. That way people who are signing up from fake email addresses can't complete the signup.

    2) Remove any opm.gov email addresses who successfully signed up, mostly for peace of mind.

    3) Don't ever share anything sensitive or private in your public newsletters!!!

    #digisec #fud #nonprofit

  23. Lots of folks at progressive nonprofits are freaked out because they see mailing list signups from [email protected] and other .gov email addresses and think that they are being monitored by the feds.

    That is a REAL email address that the federal government is using to let people snitch on their coworkers if they are secretly doing DEIA work.

    But I don't think the gov't is doing it to spy on orgs. These are public newsletters with (hopefully) non-sensitive content.

    So, this is my take on what's happening, from most to least likely:

    1) Individual or organized assholes are signing up real and fake opm.gov email addresses to scare people (apparently some of the signups are from addresses like [email protected])

    2) The federal government are signing up the real email address to intimidate organizers, or

    3) Someone who hates what's the federal government is doing thinks they are clever and are subscription bombing them on purpose to inundate the inbox with actual DEIA stuff, but don't get that they're scaring the very organizations they support.

    My suggestions for orgs who are experiencing this:

    1) Change the settings on your mailing list providers so that people need to click a link in a signup confirmation email in order to complete the signup. That way people who are signing up from fake email addresses can't complete the signup.

    2) Remove any opm.gov email addresses who successfully signed up, mostly for peace of mind.

    3) Don't ever share anything sensitive or private in your public newsletters!!!

    #digisec #fud #nonprofit

  24. Lots of folks at progressive nonprofits are freaked out because they see mailing list signups from [email protected] and other .gov email addresses and think that they are being monitored by the feds.

    That is a REAL email address that the federal government is using to let people snitch on their coworkers if they are secretly doing DEIA work.

    But I don't think the gov't is doing it to spy on orgs. These are public newsletters with (hopefully) non-sensitive content.

    So, this is my take on what's happening, from most to least likely:

    1) Individual or organized assholes are signing up real and fake opm.gov email addresses to scare people (apparently some of the signups are from addresses like [email protected])

    2) The federal government are signing up the real email address to intimidate organizers, or

    3) Someone who hates what's the federal government is doing thinks they are clever and are subscription bombing them on purpose to inundate the inbox with actual DEIA stuff, but don't get that they're scaring the very organizations they support.

    My suggestions for orgs who are experiencing this:

    1) Change the settings on your mailing list providers so that people need to click a link in a signup confirmation email in order to complete the signup. That way people who are signing up from fake email addresses can't complete the signup.

    2) Remove any opm.gov email addresses who successfully signed up, mostly for peace of mind.

    3) Don't ever share anything sensitive or private in your public newsletters!!!

    #digisec #fud #nonprofit

  25. Lots of folks at progressive nonprofits are freaked out because they see mailing list signups from [email protected] and other .gov email addresses and think that they are being monitored by the feds.

    That is a REAL email address that the federal government is using to let people snitch on their coworkers if they are secretly doing DEIA work.

    But I don't think the gov't is doing it to spy on orgs. These are public newsletters with (hopefully) non-sensitive content.

    So, this is my take on what's happening, from most to least likely:

    1) Individual or organized assholes are signing up real and fake opm.gov email addresses to scare people (apparently some of the signups are from addresses like [email protected])

    2) The federal government are signing up the real email address to intimidate organizers, or

    3) Someone who hates what's the federal government is doing thinks they are clever and are subscription bombing them on purpose to inundate the inbox with actual DEIA stuff, but don't get that they're scaring the very organizations they support.

    My suggestions for orgs who are experiencing this:

    1) Change the settings on your mailing list providers so that people need to click a link in a signup confirmation email in order to complete the signup. That way people who are signing up from fake email addresses can't complete the signup.

    2) Remove any opm.gov email addresses who successfully signed up, mostly for peace of mind.

    3) Don't ever share anything sensitive or private in your public newsletters!!!

    #digisec #fud #nonprofit

  26. Worried about what's to come in January and beyond (and before that)? Want to start upping your digital security as part of your preparation? Check out my piece on five things you can do to start increasing your #digisec ASAP!

    jackaponte.com/blog/2024/11/08

  27. Worried about what's to come in January and beyond (and before that)? Want to start upping your digital security as part of your preparation? Check out my piece on five things you can do to start increasing your #digisec ASAP!

    jackaponte.com/blog/2024/11/08

  28. Worried about what's to come in January and beyond (and before that)? Want to start upping your digital security as part of your preparation? Check out my piece on five things you can do to start increasing your #digisec ASAP!

    jackaponte.com/blog/2024/11/08

  29. Worried about what's to come in January and beyond (and before that)? Want to start upping your digital security as part of your preparation? Check out my piece on five things you can do to start increasing your #digisec ASAP!

    jackaponte.com/blog/2024/11/08

  30. Worried about what's to come in January and beyond (and before that)? Want to start upping your digital security as part of your preparation? Check out my piece on five things you can do to start increasing your #digisec ASAP!

    jackaponte.com/blog/2024/11/08

  31. If you could make only ONE recommendation to an organization trying to improve their data security, what would it be?

    #digisec

  32. If you could make only ONE recommendation to an organization trying to improve their data security, what would it be?

    #digisec

  33. If you could make only ONE recommendation to an organization trying to improve their data security, what would it be?

    #digisec

  34. If you could make only ONE recommendation to an organization trying to improve their data security, what would it be?

    #digisec

  35. If you could make only ONE recommendation to an organization trying to improve their data security, what would it be?

    #digisec

  36. Does anyone have recommendations for image search websites besides PimEyes?

    #digisec #privacy

  37. Does anyone have recommendations for image search websites besides PimEyes?

    #digisec #privacy

  38. Does anyone have recommendations for image search websites besides PimEyes?

    #digisec #privacy

  39. Does anyone have recommendations for image search websites besides PimEyes?

    #digisec #privacy

  40. Does anyone have recommendations for image search websites besides PimEyes?

    #digisec #privacy

  41. #TechCare is a step-by-step guide to create help desks to support civil society organisations and individuals facing digital security issues.

    Visit tech-care.cc to download the guide!

    #digitalsecurity #digisec #humanrights

  42. #TechCare is a step-by-step guide to create help desks to support civil society organisations and individuals facing digital security issues.

    Visit tech-care.cc to download the guide!

    #digitalsecurity #digisec #humanrights

  43. #TechCare is a step-by-step guide to create help desks to support civil society organisations and individuals facing digital security issues.

    Visit tech-care.cc to download the guide!

    #digitalsecurity #digisec #humanrights

  44. #TechCare is a step-by-step guide to create help desks to support civil society organisations and individuals facing digital security issues.

    Visit tech-care.cc to download the guide!

    #digitalsecurity #digisec #humanrights

  45. In my #digisec work with #nonprofits I've noticed that time and time again, loss of trust comes up as one of the possible and most serious consequences of a digisec breach. The trust of staff, community members, people accessing services, donors, funders and allied organizations are all crucial to a nonprofit being able to carry out its mission. It is rightfully a huge concern!

  46. In my #digisec work with #nonprofits I've noticed that time and time again, loss of trust comes up as one of the possible and most serious consequences of a digisec breach. The trust of staff, community members, people accessing services, donors, funders and allied organizations are all crucial to a nonprofit being able to carry out its mission. It is rightfully a huge concern!

  47. In my #digisec work with #nonprofits I've noticed that time and time again, loss of trust comes up as one of the possible and most serious consequences of a digisec breach. The trust of staff, community members, people accessing services, donors, funders and allied organizations are all crucial to a nonprofit being able to carry out its mission. It is rightfully a huge concern!

  48. In my #digisec work with #nonprofits I've noticed that time and time again, loss of trust comes up as one of the possible and most serious consequences of a digisec breach. The trust of staff, community members, people accessing services, donors, funders and allied organizations are all crucial to a nonprofit being able to carry out its mission. It is rightfully a huge concern!

  49. In my #digisec work with #nonprofits I've noticed that time and time again, loss of trust comes up as one of the possible and most serious consequences of a digisec breach. The trust of staff, community members, people accessing services, donors, funders and allied organizations are all crucial to a nonprofit being able to carry out its mission. It is rightfully a huge concern!

  50. I'm in New Orleans this week for the #CreatingChangeConference! Let me know if you're here and want to meet up and talk #digisec, #nptech or what's going down in grassroots #queer and #trans organizing these days, especially on the community security front.

  51. I'm in New Orleans this week for the #CreatingChangeConference! Let me know if you're here and want to meet up and talk #digisec, #nptech or what's going down in grassroots #queer and #trans organizing these days, especially on the community security front.

  52. I'm in New Orleans this week for the #CreatingChangeConference! Let me know if you're here and want to meet up and talk #digisec, #nptech or what's going down in grassroots #queer and #trans organizing these days, especially on the community security front.

  53. I'm in New Orleans this week for the #CreatingChangeConference! Let me know if you're here and want to meet up and talk #digisec, #nptech or what's going down in grassroots #queer and #trans organizing these days, especially on the community security front.

  54. I'm in New Orleans this week for the #CreatingChangeConference! Let me know if you're here and want to meet up and talk #digisec, #nptech or what's going down in grassroots #queer and #trans organizing these days, especially on the community security front.

  55. CryptPad is end-to-end encrypted... but I'm assuming that's true only if you log in? Or is it true for any document that anyone can access by simply visiting a publicly accessible link?

    Trying to figure out why so many folks are using CryptPad instead of Etherpad these days besides the fact that it's prettier.

    #digisec #encryption

  56. CryptPad is end-to-end encrypted... but I'm assuming that's true only if you log in? Or is it true for any document that anyone can access by simply visiting a publicly accessible link?

    Trying to figure out why so many folks are using CryptPad instead of Etherpad these days besides the fact that it's prettier.

    #digisec #encryption

  57. CryptPad is end-to-end encrypted... but I'm assuming that's true only if you log in? Or is it true for any document that anyone can access by simply visiting a publicly accessible link?

    Trying to figure out why so many folks are using CryptPad instead of Etherpad these days besides the fact that it's prettier.

    #digisec #encryption

  58. CryptPad is end-to-end encrypted... but I'm assuming that's true only if you log in? Or is it true for any document that anyone can access by simply visiting a publicly accessible link?

    Trying to figure out why so many folks are using CryptPad instead of Etherpad these days besides the fact that it's prettier.

    #digisec #encryption

  59. CryptPad is end-to-end encrypted... but I'm assuming that's true only if you log in? Or is it true for any document that anyone can access by simply visiting a publicly accessible link?

    Trying to figure out why so many folks are using CryptPad instead of Etherpad these days besides the fact that it's prettier.

    #digisec #encryption