home.social

#securitytheater — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #securitytheater, aggregated by home.social.

fetched live
  1. In today's thrilling episode of "Security Theater 101," Z.ai bombards us with an eye-watering jumble of numbers and acronyms that would confuse even the most seasoned conspiracy theorist. 🤯 Amongst the chaos, we're told something about Apple's Safari and FreeBSD's #vulnerabilities, but you'll need a decoder ring and a PhD in #cryptography to figure out the rest. 🔍💾
    cvd.z.ai #SecurityTheater #Zai #AppleSafari #FreeBSD #HackerNews #ngated

  2. Auf diese Problematik weist auch der IT-Sicherheitsforscher Bruce Schneier in einem kurzen Blogpost hin. Er sieht keine Anhaltspunkte dafür, dass diese Art von Kleidungsstücken einen wirksamen Schutz darstellt, und sieht das ganze eher als Sicherheits-Theater.
    #SecurityTheater #FaceRecognition #Gesichtserkennung
    schneier.com/blog/archives/202

  3. 🎉 FIPS 140-3: the glittering security badge everyone pays for but no one uses. 🤦‍♂️ #Auditors chuckle knowingly as companies fork out cash for paperwork, only to flip the security switch to "off." 📝➡️🚫 Welcome to the world of buying security theater—where #compliance is king, but actual security is just a quaint notion! 👑🔒
    808bits.com/articles/fips-140- #FIPS1403 #SecurityTheater #Cybersecurity #HackerNews #ngated

  4. @dewomser Und wer netcat auch für ein böses Hackertool und Sicherheitsrisiko hält, kann auch busybox nehmen:

    busybox nc towel.blinkenlights.nl 23

    #securitytheater

  5. Oh joy, another riveting adventure in "open source" land where you can't even get past the front gate without invoking the wrath of Cloudflare. 🚧🛑 Pro tip: If you require a PhD in cyber-sorcery just to access your "open" project, maybe rethink your security theater. 🎭🔒
    x.ai/open-source #openSource #securityCloudflare #cyberSecurity #accessIssues #securityTheater #HackerNews #ngated

  6. I get really tired of pages like this. I had to wrestle with this page no less than 6 times before purchasing tickets.

    1. Everyone has an adblocker. Everyone. Build your website with this in mind.
    2. The internet operated before JavaScript
    3. Your "security" measures are losing you more legitimate customers than saving you from fraud
    4. You sell tickets to tourists. Ofc their connections will look sketchy, not match regions, etc

    #enshittification #securitytheater #webdesign

  7. I have to scream into the void about #CyberEssentials, just for a minute. I apparently have bend over backwards to prove a bug in their product to an ASV which doesn't know the difference between a Windows 11 ntoskrnl.exe version and a Windows Server ntoskrnl.exe version. This is really helping me reduce cyber security risk. Just like being Cyber Essentials compliant helped M&S and Co-op. SO much time wasted. #cyberessentials #securitytheater

  8. ⚠️ How SMS 2FA Destroys Authentication Logic

    A recent experience while changing my account info reminded me why relying on telecom routing for security is an absolute nightmare, and why the infosec community needs to kill off SMS authentication for good.

    🚩 Battle.net SMS 2FA Failure and Security Theater:

    I attempted to log into Battle.net using a phone number I had legitimately owned for months, assuming I had added to my alt profile when I switched to that number. Instead of asking for a secondary 2FA, the platform sent an SMS code, accepted it, and provided me access to a complete stranger's account.

    🚩 The Architectural Flaw:

    The platform's backend treated a single SMS verification token not as a supplementary second factor, but as a primary identity credential. Because a stranger had left my number on their account months prior, the system assumed current possession of the SIM trumped all other security metrics.

    🏳 The Legal Reality of Intent:

    From a legal standpoint (like the CFAA), navigating into an account this way lacks the malicious intent required for criminal unauthorized access (Mens Rea); it's an accidental entry caused entirely by broken corporate infrastructure. But the fact that a user can simply input their own phone number and inadvertently hijack a stranger's digital life without a single exploit is a staggering failure of AppSec logic.

    ✅ The Solution:

    SMS is not identity proof. It is a highly volatile, easily routed carrier token. If a platform allows SMS to override or bypass a standard password barrier without out-of-band verification (like a mandatory email confirmation), it isn't secure.

    Stop letting telcos act as your root of trust. Switch to cryptographic hardware standards like NFC Yubikeys or standard TOTP apps.

    #CyberSecurity #Infosec #MFA #SecurityTheater #AppSec #Yubikey #CFAA #Hacking

  9. I can hand on heart say that when we finally rip out our Cisco ISE devices, I will not miss those useless pieces of shite in the slightest #SecurityTheater

    Crossposted with @openvibe

  10. Nothing makes me feel like a valued employee quite like ongoing phishing expeditions from our own security team. 🙁

    #InfoSec
    #SecurityTheater
    #Phishing
    #IT

  11. I often hear people in tech complaining that the industry is oversaturated and they can't find a job but let's be real about this:

    The entry-level resume pile is oversaturated with people who have a theoretical degree or a paper cert but have never actually touched a terminal, built a home lab, or popped a box. HR departments are flooded with thousands of identical, low-effort applications.

    There is a catastrophic shortage of people who have a deeply ingrained offensive mindset, who understand networking down to the packet level, and who can look at a custom enterprise system and figure out how it fails.

    Regardless of whether you love or hate AI, we are in a high-stakes tech race where our adversaries are operating with zero ethical speed brakes, and Silicon Valley’s response is to gatekeep the very tools that could turn raw tech savvy students into elite defenders at scale.

    You can't even ask AI how to tweak a simple reverse shell without it panicking and saying "I can't help you hack the mAiNfRaMe and destroy the entire grid." As if the feds wouldn't be at some script kiddies door within minutes if they dared touch critical infrastructure or as if enterprise environments don't have robust EDR and network segmentation in place. They really act like APTs are asking AI how to learn ethical hacking, treating a simple Python script that is less than 10 lines of code like a piece of precision-engineered, state-sponsored cyber-weaponry designed to spin centrifuges out of control (Stuxnet 2.0).

    We're really shooting ourselves in the foot. Our adversaries aren't using Anthropic, ChatGPT, Gemini, etc. to learn how to make reverse shells or priv esc exploits for sandboxed CTFs to prepare for the field. They have AI pipelines that don't have guardrails and APTs that are already hacking into our telecom companies, healthcare networks, etc. Who is big tech really helping here? Certainly not us.

    Look, I am not really even the biggest fan of AI (and obviously not a fan of big tech) but if I can crunch 8 hours of learning down into 1 hour, why wouldn't I? I'll still spend the 8 hours learning some new concept without the force multiplier because this is what I am passionate about and what I am studying for but the amount of security theater I see from big tech absolutely gets on my nerves. In fact, I think because I have learned so much about cybersecurity is exactly why it annoys me that much more. Watching a multi-billion dollar AI panic over a 10-line Python socket connection feels like being treated like a child by someone who doesn't even understand basic syntax.

    #givemeabreak

    #securitytheater

    #CorporatePR

    #CorporateNannyFilters

    #bigtech is #shortsighted

    I guess I'll have to just #RTFM so some skript kiddie doesn't cause a catastrophic blackout ... #sarcasm 🙄

  12. MY FUCKING FAVORITE IS THE WEB FORM PASSWORD FIELD THAT WILL NOT LET YOU PASTE YOUR PASSWORD YOU GUYS ARE SO GODDAM SMART WHAT A SNEAKY MOVE TO FOIL THE BAD GUYS I FEEL SO SECURE YOU FUCKING MORONS

    #securitytheater #security #password

  13. "Full tunnel or nothing" is a security theater that kills network performance. If your CISO still pushes 0.0.0.0/0 through a 1Gbps pipe for remote workers streaming Netflix, you're not securing anything—you're just bottlenecking your own business. Split tunnel for corporate traffic. Let home traffic stay local. Stop pretending your firewall inspects TLS 1.3. #NetworkEngineering #SecurityTheater

    valtersit.com/guides/networkin