home.social

#infosecfail — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #infosecfail, aggregated by home.social.

fetched live
  1. 1) Ban smartphones in schools, preventing the use of convenient MFA TOTP apps
    2) attackers phish schoolkids' accounts
    3) attackers set up MFA on the stolen accounts to make it harder for admins to recover
    4) admins disable the ability to set up MFA on all accounts to prevent attackers from doing it first
    5) ...
    6) Profit?

    Original source post: bsky.app/profile/did:plc:bya76

    #EdTech #EdPolicy #TechPolicy #InfosecFail

  2. 1) Ban smartphones in schools, preventing the use of convenient MFA TOTP apps
    2) attackers phish schoolkids' accounts
    3) attackers set up MFA on the stolen accounts to make it harder for admins to recover
    4) admins disable the ability to set up MFA on all accounts to prevent attackers from doing it first
    5) ...
    6) Profit?

    Original source post: bsky.app/profile/did:plc:bya76

    #EdTech #EdPolicy #TechPolicy #InfosecFail

  3. 1) Ban smartphones in schools, preventing the use of convenient MFA TOTP apps
    2) attackers phish schoolkids' accounts
    3) attackers set up MFA on the stolen accounts to make it harder for admins to recover
    4) admins disable the ability to set up MFA on all accounts to prevent attackers from doing it first
    5) ...
    6) Profit?

    Original source post: bsky.app/profile/did:plc:bya76

    #EdTech #EdPolicy #TechPolicy #InfosecFail

  4. 1) Ban smartphones in schools, preventing the use of convenient MFA TOTP apps
    2) attackers phish schoolkids' accounts
    3) attackers set up MFA on the stolen accounts to make it harder for admins to recover
    4) admins disable the ability to set up MFA on all accounts to prevent attackers from doing it first
    5) ...
    6) Profit?

    Original source post: bsky.app/profile/did:plc:bya76

    #EdTech #EdPolicy #TechPolicy #InfosecFail

  5. 1) Ban smartphones in schools, preventing the use of convenient MFA TOTP apps
    2) attackers phish schoolkids' accounts
    3) attackers set up MFA on the stolen accounts to make it harder for admins to recover
    4) admins disable the ability to set up MFA on all accounts to prevent attackers from doing it first
    5) ...
    6) Profit?

    Original source post: bsky.app/profile/did:plc:bya76

    #EdTech #EdPolicy #TechPolicy #InfosecFail

  6. Oops‼️ Microsoft Used China-Based Engineers to Support Product Recently Hacked by China - And just how did this happen? Cause the whole thing sounds counterintuitive; or, I suppose, utterly incompetent. #Microsoft #hacking #hacked #infosec #InfosecFail #fail propublica.org/article/microso

  7. Oops‼️ Microsoft Used China-Based Engineers to Support Product Recently Hacked by China - And just how did this happen? Cause the whole thing sounds counterintuitive; or, I suppose, utterly incompetent. #Microsoft #hacking #hacked #infosec #InfosecFail #fail propublica.org/article/microso

  8. Oops‼️ Microsoft Used China-Based Engineers to Support Product Recently Hacked by China - And just how did this happen? Cause the whole thing sounds counterintuitive; or, I suppose, utterly incompetent. #Microsoft #hacking #hacked #infosec #InfosecFail #fail propublica.org/article/microso

  9. Oops‼️ Microsoft Used China-Based Engineers to Support Product Recently Hacked by China - And just how did this happen? Cause the whole thing sounds counterintuitive; or, I suppose, utterly incompetent. #Microsoft #hacking #hacked #infosec #InfosecFail #fail propublica.org/article/microso

  10. Oops‼️ Microsoft Used China-Based Engineers to Support Product Recently Hacked by China - And just how did this happen? Cause the whole thing sounds counterintuitive; or, I suppose, utterly incompetent. #Microsoft #hacking #hacked #infosec #InfosecFail #fail propublica.org/article/microso

  11. They changed their password requirements. So the password that I had *already set up* and *used* was no longer valid. I had to reset it.
    😠

    #infosec #InfosecFail #PasswordFail

  12. They changed their password requirements. So the password that I had *already set up* and *used* was no longer valid. I had to reset it.
    😠

    #infosec #InfosecFail #PasswordFail

  13. They changed their password requirements. So the password that I had *already set up* and *used* was no longer valid. I had to reset it.
    😠

    #infosec #InfosecFail #PasswordFail

  14. They changed their password requirements. So the password that I had *already set up* and *used* was no longer valid. I had to reset it.
    😠

    #infosec #InfosecFail #PasswordFail

  15. They changed their password requirements. So the password that I had *already set up* and *used* was no longer valid. I had to reset it.
    😠

    #infosec #InfosecFail #PasswordFail

  16. CW: Cybersecurity satire / national facepalm

    "Did your data get breached?
    Did your backup disappear?
    Did your government email get leaked?"

    Don’t worry! BSSN™ — Big Silent Shadow Network™ has your back.

    🛡️ No press
    🛡️ No plans
    🛡️ No passwords
    🛡️ No presence

    “Your insecurity is our priority.”

    #Cybersecurity #Infosec #Indonesia #Satire #Infosecfail

  17. Der vermehrte Einsatz von #Passwort-Tresor-Anwendungen ist eine gute Sache, weil man damit
    a) ausreichend lange und nicht vorhersagbare sowie
    b) separate Passwörter für jeden Login
    erzeugen und ablegen kann.

    Aber wenn man nur ein schwaches Master-Passwort (oder sogar nur eine PIN) verwendet, serviert man alle seine Daten Angreifern frei Haus.

    Also:
    - starkes Master-Passwort (oder #2FA),
    - nur die PW zugreifbar, die man wirklich braucht,
    - am besten keine Online-Tresore.

    #InfoSecFail

  18. Der vermehrte Einsatz von #Passwort-Tresor-Anwendungen ist eine gute Sache, weil man damit
    a) ausreichend lange und nicht vorhersagbare sowie
    b) separate Passwörter für jeden Login
    erzeugen und ablegen kann.

    Aber wenn man nur ein schwaches Master-Passwort (oder sogar nur eine PIN) verwendet, serviert man alle seine Daten Angreifern frei Haus.

    Also:
    - starkes Master-Passwort (oder #2FA),
    - nur die PW zugreifbar, die man wirklich braucht,
    - am besten keine Online-Tresore.

    #InfoSecFail

  19. Der vermehrte Einsatz von #Passwort-Tresor-Anwendungen ist eine gute Sache, weil man damit
    a) ausreichend lange und nicht vorhersagbare sowie
    b) separate Passwörter für jeden Login
    erzeugen und ablegen kann.

    Aber wenn man nur ein schwaches Master-Passwort (oder sogar nur eine PIN) verwendet, serviert man alle seine Daten Angreifern frei Haus.

    Also:
    - starkes Master-Passwort (oder #2FA),
    - nur die PW zugreifbar, die man wirklich braucht,
    - am besten keine Online-Tresore.

    #InfoSecFail

  20. Der vermehrte Einsatz von #Passwort-Tresor-Anwendungen ist eine gute Sache, weil man damit
    a) ausreichend lange und nicht vorhersagbare sowie
    b) separate Passwörter für jeden Login
    erzeugen und ablegen kann.

    Aber wenn man nur ein schwaches Master-Passwort (oder sogar nur eine PIN) verwendet, serviert man alle seine Daten Angreifern frei Haus.

    Also:
    - starkes Master-Passwort (oder #2FA),
    - nur die PW zugreifbar, die man wirklich braucht,
    - am besten keine Online-Tresore.

    #InfoSecFail

  21. Der vermehrte Einsatz von #Passwort-Tresor-Anwendungen ist eine gute Sache, weil man damit
    a) ausreichend lange und nicht vorhersagbare sowie
    b) separate Passwörter für jeden Login
    erzeugen und ablegen kann.

    Aber wenn man nur ein schwaches Master-Passwort (oder sogar nur eine PIN) verwendet, serviert man alle seine Daten Angreifern frei Haus.

    Also:
    - starkes Master-Passwort (oder #2FA),
    - nur die PW zugreifbar, die man wirklich braucht,
    - am besten keine Online-Tresore.

    #InfoSecFail

  22. I needed to make a few #dns changes to a client's domain, who uses a third party for their website and DNS stuff.

    Contacted the third party to ask them to add the TXT records and they instead sent me their company login details for the registrar in plaintext via email. This account has access to all their clients sites and DNS stuff.

    Wtf.

    #infosec #fail #infosecfail

  23. As of Feb 24th City of #Oakland #Cyber #InfoSecFail
    #Ransomware attack persists weeks later, and continues to cripple citizen communications with city and between departments during cold spell. New Mayor Sheng Thao has issued no updates on restoration of services or city's 311 hotline as storm looms.
    sfchronicle.com/eastbay/articl

  24. As of Feb 24th City of #Oakland #Cyber #InfoSecFail
    #Ransomware attack persists weeks later, and continues to cripple citizen communications with city and between departments during cold spell. New Mayor Sheng Thao has issued no updates on restoration of services or city's 311 hotline as storm looms.
    sfchronicle.com/eastbay/articl

  25. As of Feb 24th City of #Oakland #Cyber #InfoSecFail
    #Ransomware attack persists weeks later, and continues to cripple citizen communications with city and between departments during cold spell. New Mayor Sheng Thao has issued no updates on restoration of services or city's 311 hotline as storm looms.
    sfchronicle.com/eastbay/articl

  26. As of Feb 24th City of #Oakland #Cyber #InfoSecFail
    #Ransomware attack persists weeks later, and continues to cripple citizen communications with city and between departments during cold spell. New Mayor Sheng Thao has issued no updates on restoration of services or city's 311 hotline as storm looms.
    sfchronicle.com/eastbay/articl

  27. As of Feb 24th City of #Oakland #Cyber #InfoSecFail
    #Ransomware attack persists weeks later, and continues to cripple citizen communications with city and between departments during cold spell. New Mayor Sheng Thao has issued no updates on restoration of services or city's 311 hotline as storm looms.
    sfchronicle.com/eastbay/articl

  28. O.M.G (the men’s room of the restaurant we were at) #InfosecFail

  29. O.M.G (the men’s room of the restaurant we were at) #InfosecFail

  30. O.M.G (the men’s room of the restaurant we were at) #InfosecFail

  31. ok... what numpty designed a system that requires a one time password sent to an email account, before you can log into said email account?
    #InfosecFail #OTP #ITFail

  32. ok... what numpty designed a system that requires a one time password sent to an email account, before you can log into said email account?
    #InfosecFail #OTP #ITFail

  33. ok... what numpty designed a system that requires a one time password sent to an email account, before you can log into said email account?
    #InfosecFail #OTP #ITFail

  34. ok... what numpty designed a system that requires a one time password sent to an email account, before you can log into said email account?
    #InfosecFail #OTP #ITFail

  35. According to @GossiTheDog #CloudOffice and web hosting provider #Rackspace manages around 2m biz email boxes for tens of thousands of customers and has been down for two wks due to #Ransomware attack after failing to apply avail security patches released since August. Customers have not fully had access restored, but were simply migrated to a competitor Microsoft365 and no backups of contacts or contents exist unless customer had used own or third party backup service.

    cybersecuritydive.com/news/rac #InfoSecFail

  36. According to @GossiTheDog #CloudOffice and web hosting provider #Rackspace manages around 2m biz email boxes for tens of thousands of customers and has been down for two wks due to #Ransomware attack after failing to apply avail security patches released since August. Customers have not fully had access restored, but were simply migrated to a competitor Microsoft365 and no backups of contacts or contents exist unless customer had used own or third party backup service.

    cybersecuritydive.com/news/rac #InfoSecFail