home.social

#infosecfail — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #infosecfail, aggregated by home.social.

fetched live
  1. 1) Ban smartphones in schools, preventing the use of convenient MFA TOTP apps
    2) attackers phish schoolkids' accounts
    3) attackers set up MFA on the stolen accounts to make it harder for admins to recover
    4) admins disable the ability to set up MFA on all accounts to prevent attackers from doing it first
    5) ...
    6) Profit?

    Original source post: bsky.app/profile/did:plc:bya76

    #EdTech #EdPolicy #TechPolicy #InfosecFail

  2. 1) Ban smartphones in schools, preventing the use of convenient MFA TOTP apps
    2) attackers phish schoolkids' accounts
    3) attackers set up MFA on the stolen accounts to make it harder for admins to recover
    4) admins disable the ability to set up MFA on all accounts to prevent attackers from doing it first
    5) ...
    6) Profit?

    Original source post: bsky.app/profile/did:plc:bya76

    #EdTech #EdPolicy #TechPolicy #InfosecFail

  3. Oops‼️ Microsoft Used China-Based Engineers to Support Product Recently Hacked by China - And just how did this happen? Cause the whole thing sounds counterintuitive; or, I suppose, utterly incompetent. #Microsoft #hacking #hacked #infosec #InfosecFail #fail propublica.org/article/microso

  4. Oops‼️ Microsoft Used China-Based Engineers to Support Product Recently Hacked by China - And just how did this happen? Cause the whole thing sounds counterintuitive; or, I suppose, utterly incompetent. #Microsoft #hacking #hacked #infosec #InfosecFail #fail propublica.org/article/microso

  5. They changed their password requirements. So the password that I had *already set up* and *used* was no longer valid. I had to reset it.
    😠

    #infosec #InfosecFail #PasswordFail

  6. They changed their password requirements. So the password that I had *already set up* and *used* was no longer valid. I had to reset it.
    😠

    #infosec #InfosecFail #PasswordFail

  7. Der vermehrte Einsatz von #Passwort-Tresor-Anwendungen ist eine gute Sache, weil man damit
    a) ausreichend lange und nicht vorhersagbare sowie
    b) separate Passwörter für jeden Login
    erzeugen und ablegen kann.

    Aber wenn man nur ein schwaches Master-Passwort (oder sogar nur eine PIN) verwendet, serviert man alle seine Daten Angreifern frei Haus.

    Also:
    - starkes Master-Passwort (oder #2FA),
    - nur die PW zugreifbar, die man wirklich braucht,
    - am besten keine Online-Tresore.

    #InfoSecFail

  8. Der vermehrte Einsatz von #Passwort-Tresor-Anwendungen ist eine gute Sache, weil man damit
    a) ausreichend lange und nicht vorhersagbare sowie
    b) separate Passwörter für jeden Login
    erzeugen und ablegen kann.

    Aber wenn man nur ein schwaches Master-Passwort (oder sogar nur eine PIN) verwendet, serviert man alle seine Daten Angreifern frei Haus.

    Also:
    - starkes Master-Passwort (oder #2FA),
    - nur die PW zugreifbar, die man wirklich braucht,
    - am besten keine Online-Tresore.

    #InfoSecFail

  9. As of Feb 24th City of #Oakland #Cyber #InfoSecFail
    #Ransomware attack persists weeks later, and continues to cripple citizen communications with city and between departments during cold spell. New Mayor Sheng Thao has issued no updates on restoration of services or city's 311 hotline as storm looms.
    sfchronicle.com/eastbay/articl

  10. As of Feb 24th City of #Oakland #Cyber #InfoSecFail
    #Ransomware attack persists weeks later, and continues to cripple citizen communications with city and between departments during cold spell. New Mayor Sheng Thao has issued no updates on restoration of services or city's 311 hotline as storm looms.
    sfchronicle.com/eastbay/articl

  11. ok... what numpty designed a system that requires a one time password sent to an email account, before you can log into said email account?
    #InfosecFail #OTP #ITFail