home.social

#proxies — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #proxies, aggregated by home.social.

  1. Nearly Half of #LG Smart #TV #Apps Are Laced with #Proxies

    source: spur.us/blog/smart-tv-apps-res…

    Once a TV app can act as a proxy, the risk is not limited to someone borrowing your public IP address. The app is running inside your home #network. If the #proxy provider decides to allow requests to private or local addresses, or if their filtering fails, that TV becomes a foothold for reaching things that were never meant to be exposed to the internet: router admin panels, NAS devices, printers, cameras, developer machines, and other apps listening on local ports.

    #software #news #cybersecurity #security #online #internet #capitalism #money #crime #cybercrime #malware #privacy #entertainment #sell #businessmodel #economy #smarttv #fail #app #backdoor

  2. Nearly Half of #LG Smart #TV #Apps Are Laced with #Proxies

    source: spur.us/blog/smart-tv-apps-res…

    Once a TV app can act as a proxy, the risk is not limited to someone borrowing your public IP address. The app is running inside your home #network. If the #proxy provider decides to allow requests to private or local addresses, or if their filtering fails, that TV becomes a foothold for reaching things that were never meant to be exposed to the internet: router admin panels, NAS devices, printers, cameras, developer machines, and other apps listening on local ports.

    #software #news #cybersecurity #security #online #internet #capitalism #money #crime #cybercrime #malware #privacy #entertainment #sell #businessmodel #economy #smarttv #fail #app #backdoor

  3. Nearly Half of #LG Smart #TV #Apps Are Laced with #Proxies

    source: spur.us/blog/smart-tv-apps-res…

    Once a TV app can act as a proxy, the risk is not limited to someone borrowing your public IP address. The app is running inside your home #network. If the #proxy provider decides to allow requests to private or local addresses, or if their filtering fails, that TV becomes a foothold for reaching things that were never meant to be exposed to the internet: router admin panels, NAS devices, printers, cameras, developer machines, and other apps listening on local ports.

    #software #news #cybersecurity #security #online #internet #capitalism #money #crime #cybercrime #malware #privacy #entertainment #sell #businessmodel #economy #smarttv #fail #app #backdoor

  4. @pake_preacher : I forgot the details of PAKE and SRP, but in the end the most secure client authentication requires:

    1️⃣ Strong, long term, human comprehensible, *serving endpoint* authentication;
    *AND*
    2️⃣ TLS channel binding (enforcing known endpoints).

    (Apart from those, both serving endpoint AND client MUST be trustworthy).

    🚨 The -corrupt- CA/B forum breaks 1️⃣ by:
    a) Advocating anonymous Domain Validated certificates, which render secure account creation IMPOSSIBLE;
    b) Continuously decreasing certificate lifetime.

    🚨 Furthermore, "legitimate" MitM's * break 2️⃣.

    * Man in the Middle, like on-device virusscanners and firewalls that "open" TLS tunnels (both requiring installation of a dedicated root certificate) and proxies such as (definitely not limited to) Cloudflare and Fastly.

    😱 Passkeys enforce NEITHER 1️⃣ NOR 2️⃣.

    😱😱 Worse, because passkeys (or FIDO2 hardware keys) can be easily irretrievably "lost", servers typically provide WAY EASIER phishable authentication methods (such as "rescue codes").

    @cendyne @soatok @chazh

    #AitM #MitM #SecureOnlineAuthIsHARD #SecureAuthentication #OnlineAuthentication #Authentication #Impersonation #ChannelBinding #TLSchannelBinding #UTM #TLS #TLSinterception #TLSscanning #Proxy #Proxies #GoogleIsEvil #CloudflareIsEvil

  5. @pake_preacher : I forgot the details of PAKE and SRP, but in the end the most secure client authentication requires:

    1️⃣ Strong, long term, human comprehensible, *serving endpoint* authentication;
    *AND*
    2️⃣ TLS channel binding (enforcing known endpoints).

    (Apart from those, both serving endpoint AND client MUST be trustworthy).

    🚨 The -corrupt- CA/B forum breaks 1️⃣ by:
    a) Advocating anonymous Domain Validated certificates, which render secure account creation IMPOSSIBLE;
    b) Continuously decreasing certificate lifetime.

    🚨 Furthermore, "legitimate" MitM's * break 2️⃣.

    * Man in the Middle, like on-device virusscanners and firewalls that "open" TLS tunnels (both requiring installation of a dedicated root certificate) and proxies such as (definitely not limited to) Cloudflare and Fastly.

    😱 Passkeys enforce NEITHER 1️⃣ NOR 2️⃣.

    😱😱 Worse, because passkeys (or FIDO2 hardware keys) can be easily irretrievably "lost", servers typically provide WAY EASIER phishable authentication methods (such as "rescue codes").

    @cendyne @soatok @chazh

    #AitM #MitM #SecureOnlineAuthIsHARD #SecureAuthentication #OnlineAuthentication #Authentication #Impersonation #ChannelBinding #TLSchannelBinding #UTM #TLS #TLSinterception #TLSscanning #Proxy #Proxies #GoogleIsEvil #CloudflareIsEvil

  6. @pake_preacher : I forgot the details of PAKE and SRP, but in the end the most secure client authentication requires:

    1️⃣ Strong, long term, human comprehensible, *serving endpoint* authentication;
    *AND*
    2️⃣ TLS channel binding (enforcing known endpoints).

    (Apart from those, both serving endpoint AND client MUST be trustworthy).

    🚨 The -corrupt- CA/B forum breaks 1️⃣ by:
    a) Advocating anonymous Domain Validated certificates, which render secure account creation IMPOSSIBLE;
    b) Continuously decreasing certificate lifetime.

    🚨 Furthermore, "legitimate" MitM's * break 2️⃣.

    * Man in the Middle, like on-device virusscanners and firewalls that "open" TLS tunnels (both requiring installation of a dedicated root certificate) and proxies such as (definitely not limited to) Cloudflare and Fastly.

    😱 Passkeys enforce NEITHER 1️⃣ NOR 2️⃣.

    😱😱 Worse, because passkeys (or FIDO2 hardware keys) can be easily irretrievably "lost", servers typically provide WAY EASIER phishable authentication methods (such as "rescue codes").

    @cendyne @soatok @chazh

    #AitM #MitM #SecureOnlineAuthIsHARD #SecureAuthentication #OnlineAuthentication #Authentication #Impersonation #ChannelBinding #TLSchannelBinding #UTM #TLS #TLSinterception #TLSscanning #Proxy #Proxies #GoogleIsEvil #CloudflareIsEvil

  7. @pake_preacher : I forgot the details of PAKE and SRP, but in the end the most secure client authentication requires:

    1️⃣ Strong, long term, human comprehensible, *serving endpoint* authentication;
    *AND*
    2️⃣ TLS channel binding (enforcing known endpoints).

    (Apart from those, both serving endpoint AND client MUST be trustworthy).

    🚨 The -corrupt- CA/B forum breaks 1️⃣ by:
    a) Advocating anonymous Domain Validated certificates, which render secure account creation IMPOSSIBLE;
    b) Continuously decreasing certificate lifetime.

    🚨 Furthermore, "legitimate" MitM's * break 2️⃣.

    * Man in the Middle, like on-device virusscanners and firewalls that "open" TLS tunnels (both requiring installation of a dedicated root certificate) and proxies such as (definitely not limited to) Cloudflare and Fastly.

    😱 Passkeys enforce NEITHER 1️⃣ NOR 2️⃣.

    😱😱 Worse, because passkeys (or FIDO2 hardware keys) can be easily irretrievably "lost", servers typically provide WAY EASIER phishable authentication methods (such as "rescue codes").

    @cendyne @soatok @chazh

    #AitM #MitM #SecureOnlineAuthIsHARD #SecureAuthentication #OnlineAuthentication #Authentication #Impersonation #ChannelBinding #TLSchannelBinding #UTM #TLS #TLSinterception #TLSscanning #Proxy #Proxies #GoogleIsEvil #CloudflareIsEvil

  8. you can use ip2 through tor browser with a few mods - whonix has a writeup on it #portable apps #wonix #tor browser #ip2 #proxies

  9. you can use ip2 through tor browser with a few mods - whonix has a writeup on it #portable apps #wonix #tor browser #ip2 #proxies

  10. Excited for #JCON EUROPE 2024? See Abdel Sghiouar at #JCON2024 in Cologne talking about '#Proxies, #Gateways, and Service #Mesh. Why Are Words so Confusing?'

    Can you tell the difference between an #API Gateway, the API Gateway, …

    Get your free #JUG Ticket: jcon.one

  11. Excited for #JCON EUROPE 2024? See Abdel Sghiouar at #JCON2024 in Cologne talking about '#Proxies, #Gateways, and Service #Mesh. Why Are Words so Confusing?'

    Can you tell the difference between an #API Gateway, the API Gateway, …

    Get your free #JUG Ticket: jcon.one

  12. Excited for #JCON EUROPE 2024? See Abdel Sghiouar at #JCON2024 in Cologne talking about '#Proxies, #Gateways, and Service #Mesh. Why Are Words so Confusing?'

    Can you tell the difference between an #API Gateway, the API Gateway, …

    Get your free #JUG Ticket: jcon.one

  13. If you are interested in the chemical tracers of wildfires, and how those might vary with burn severity, check out our new #preprint authorea.com/doi/full/10.22541

    We leached wildfire ashes and soils from karst areas, so we can better understand the speleothem palaeofire proxy signal. Another team effort, with co-authors from #UNSW (👋 @Andbaker) #ANSTO, #UWA, and #GNSScience

    #palaeofire #paleofire #processUnderstanding #Proxy #proxies #paleoenvironment

  14. If you are interested in the chemical tracers of wildfires, and how those might vary with burn severity, check out our new #preprint authorea.com/doi/full/10.22541

    We leached wildfire ashes and soils from karst areas, so we can better understand the speleothem palaeofire proxy signal. Another team effort, with co-authors from #UNSW (👋 @Andbaker) #ANSTO, #UWA, and #GNSScience

    #palaeofire #paleofire #processUnderstanding #Proxy #proxies #paleoenvironment

  15. More #EarthSystemScience #UpGoer5
    Trees can tell us is what the world was like in the past. The rings inside a tree can show us how much it grew each year. In wet years, the tree will grow a thick ring, and in dry years, it will grow a small ring. People can study tree rings to see how hot and cold the world has been and how it has changed over time. It helps us understand how the world is changing now and how it may change. [S. H.-R.]
    #Proxies #McGillUniversity #SimpleWords

  16. More
    Trees can tell us is what the world was like in the past. The rings inside a tree can show us how much it grew each year. In wet years, the tree will grow a thick ring, and in dry years, it will grow a small ring. People can study tree rings to see how hot and cold the world has been and how it has changed over time. It helps us understand how the world is changing now and how it may change. [S. H.-R.]

  17. More #EarthSystemScience #UpGoer5
    Trees can tell us is what the world was like in the past. The rings inside a tree can show us how much it grew each year. In wet years, the tree will grow a thick ring, and in dry years, it will grow a small ring. People can study tree rings to see how hot and cold the world has been and how it has changed over time. It helps us understand how the world is changing now and how it may change. [S. H.-R.]
    #Proxies #McGillUniversity #SimpleWords

  18. More #EarthSystemScience #UpGoer5
    Trees can tell us is what the world was like in the past. The rings inside a tree can show us how much it grew each year. In wet years, the tree will grow a thick ring, and in dry years, it will grow a small ring. People can study tree rings to see how hot and cold the world has been and how it has changed over time. It helps us understand how the world is changing now and how it may change. [S. H.-R.]
    #Proxies #McGillUniversity #SimpleWords

  19. More #EarthSystemScience #UpGoer5
    Trees can tell us is what the world was like in the past. The rings inside a tree can show us how much it grew each year. In wet years, the tree will grow a thick ring, and in dry years, it will grow a small ring. People can study tree rings to see how hot and cold the world has been and how it has changed over time. It helps us understand how the world is changing now and how it may change. [S. H.-R.]
    #Proxies #McGillUniversity #SimpleWords

  20. Is anyone using #loadbalancers in their #homelab or is it all reverse proxies? Looking for something to do TLS termination and, ideally, make highly available. I tried doing this with #caddy and ehh it's not really working how I want to. I also think I didn't configure it correctly. Documentation is a little sparse.

    #homelab #networking #load #balancers #revers #proxies #minilab

  21. Is anyone using #loadbalancers in their #homelab or is it all reverse proxies? Looking for something to do TLS termination and, ideally, make highly available. I tried doing this with #caddy and ehh it's not really working how I want to. I also think I didn't configure it correctly. Documentation is a little sparse.

    #homelab #networking #load #balancers #revers #proxies #minilab