home.social

#securitytheater — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #securitytheater, aggregated by home.social.

fetched live
  1. In today's thrilling episode of "Security Theater 101," Z.ai bombards us with an eye-watering jumble of numbers and acronyms that would confuse even the most seasoned conspiracy theorist. 🤯 Amongst the chaos, we're told something about Apple's Safari and FreeBSD's #vulnerabilities, but you'll need a decoder ring and a PhD in #cryptography to figure out the rest. 🔍💾
    cvd.z.ai #SecurityTheater #Zai #AppleSafari #FreeBSD #HackerNews #ngated

  2. In today's thrilling episode of "Security Theater 101," Z.ai bombards us with an eye-watering jumble of numbers and acronyms that would confuse even the most seasoned conspiracy theorist. 🤯 Amongst the chaos, we're told something about Apple's Safari and FreeBSD's #vulnerabilities, but you'll need a decoder ring and a PhD in #cryptography to figure out the rest. 🔍💾
    cvd.z.ai #SecurityTheater #Zai #AppleSafari #FreeBSD #HackerNews #ngated

  3. In today's thrilling episode of "Security Theater 101," Z.ai bombards us with an eye-watering jumble of numbers and acronyms that would confuse even the most seasoned conspiracy theorist. 🤯 Amongst the chaos, we're told something about Apple's Safari and FreeBSD's #vulnerabilities, but you'll need a decoder ring and a PhD in #cryptography to figure out the rest. 🔍💾
    cvd.z.ai #SecurityTheater #Zai #AppleSafari #FreeBSD #HackerNews #ngated

  4. In today's thrilling episode of "Security Theater 101," Z.ai bombards us with an eye-watering jumble of numbers and acronyms that would confuse even the most seasoned conspiracy theorist. 🤯 Amongst the chaos, we're told something about Apple's Safari and FreeBSD's #vulnerabilities, but you'll need a decoder ring and a PhD in #cryptography to figure out the rest. 🔍💾
    cvd.z.ai #SecurityTheater #Zai #AppleSafari #FreeBSD #HackerNews #ngated

  5. In today's thrilling episode of "Security Theater 101," Z.ai bombards us with an eye-watering jumble of numbers and acronyms that would confuse even the most seasoned conspiracy theorist. 🤯 Amongst the chaos, we're told something about Apple's Safari and FreeBSD's #vulnerabilities, but you'll need a decoder ring and a PhD in #cryptography to figure out the rest. 🔍💾
    cvd.z.ai #SecurityTheater #Zai #AppleSafari #FreeBSD #HackerNews #ngated

  6. Auf diese Problematik weist auch der IT-Sicherheitsforscher Bruce Schneier in einem kurzen Blogpost hin. Er sieht keine Anhaltspunkte dafür, dass diese Art von Kleidungsstücken einen wirksamen Schutz darstellt, und sieht das ganze eher als Sicherheits-Theater.
    #SecurityTheater #FaceRecognition #Gesichtserkennung
    schneier.com/blog/archives/202

  7. Auf diese Problematik weist auch der IT-Sicherheitsforscher Bruce Schneier in einem kurzen Blogpost hin. Er sieht keine Anhaltspunkte dafür, dass diese Art von Kleidungsstücken einen wirksamen Schutz darstellt, und sieht das ganze eher als Sicherheits-Theater.
    #SecurityTheater #FaceRecognition #Gesichtserkennung
    schneier.com/blog/archives/202

  8. Auf diese Problematik weist auch der IT-Sicherheitsforscher Bruce Schneier in einem kurzen Blogpost hin. Er sieht keine Anhaltspunkte dafür, dass diese Art von Kleidungsstücken einen wirksamen Schutz darstellt, und sieht das ganze eher als Sicherheits-Theater.
    #SecurityTheater #FaceRecognition #Gesichtserkennung
    schneier.com/blog/archives/202

  9. Auf diese Problematik weist auch der IT-Sicherheitsforscher Bruce Schneier in einem kurzen Blogpost hin. Er sieht keine Anhaltspunkte dafür, dass diese Art von Kleidungsstücken einen wirksamen Schutz darstellt, und sieht das ganze eher als Sicherheits-Theater.
    #SecurityTheater #FaceRecognition #Gesichtserkennung
    schneier.com/blog/archives/202

  10. Auf diese Problematik weist auch der IT-Sicherheitsforscher Bruce Schneier in einem kurzen Blogpost hin. Er sieht keine Anhaltspunkte dafür, dass diese Art von Kleidungsstücken einen wirksamen Schutz darstellt, und sieht das ganze eher als Sicherheits-Theater.
    #SecurityTheater #FaceRecognition #Gesichtserkennung
    schneier.com/blog/archives/202

  11. A #Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide

    source: wired.com/story/a-security-pro…

    Given the danger of those breaches—both in terms of the exposure of sensitive data and the ongoing theft of cryptocurrency enriching the North Korean regime—the real concern shouldn’t necessarily be the companies Stykas has named but rather the ones he hasn’t. Those companies include hundreds that never responded to his warnings, he says, as well as more added to the list every day.


    And this, folks, is called security theater. Companies know that cyber threats are real.
    They know that #cybercriminals attack them every day. But many companies respond with checklists. Someone has to tick the boxes. Again and again. Often, these people have little cybersecurity training. They may not fully understand what they are checking.
    The checklist may be outdated. And sometimes, nobody in the company even knows why the checklist exists. It looks like security. But looking secure is not the same as being secure. This is where things can get almost absurd.

    Companies may spend huge amounts of money on expensive security software. Sometimes, the software is not even very good. Sometimes, it creates more complexity and more possible ways for attackers to get in. But that is not always the real goal. The real goal can be to say later: “We did everything we could.” It is like putting a security camera on the front door, never checking whether it works, and then pointing at it after the robbery. The company wants to prove that it did not act carelessly. Real security becomes secondary. In cybersecurity, this is the difference between security and security theater. And even the biggest idiot should notice the problem when there is nobody left in the company to deal with the warnings. That is exactly what can happen. The security system sends alerts. Nobody reads them. Nobody investigates them. Nobody has the time, the skills, or sometimes even the job to deal with them. So the alerts are simply ignored.

    And here is the really strange part. The internet still works. It works partly because, for cybercriminals, stealing from badly protected companies is often more profitable than destroying the whole system. It is like a city where every door is unlocked. Criminals do not need to burn down the city. They can simply walk inside and take what they want.

    That may be the biggest lesson of all: Cybersecurity is not about having the right boxes checked. It is about knowing what can go wrong, finding the real risks, and making sure that someone is actually there when the alarm goes off.

    #cybersecurity #security #software #news #northkorea #crypto #cyberattack #fail #internet #economy #warning #danger #securitytheater #hack #hacker #crime #network #cyberspace #knowledge #knowhow #cybercrime #cyberattack #cyber

  12. A #Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide

    source: wired.com/story/a-security-pro…

    Given the danger of those breaches—both in terms of the exposure of sensitive data and the ongoing theft of cryptocurrency enriching the North Korean regime—the real concern shouldn’t necessarily be the companies Stykas has named but rather the ones he hasn’t. Those companies include hundreds that never responded to his warnings, he says, as well as more added to the list every day.


    And this, folks, is called security theater. Companies know that cyber threats are real.
    They know that #cybercriminals attack them every day. But many companies respond with checklists. Someone has to tick the boxes. Again and again. Often, these people have little cybersecurity training. They may not fully understand what they are checking.
    The checklist may be outdated. And sometimes, nobody in the company even knows why the checklist exists. It looks like security. But looking secure is not the same as being secure. This is where things can get almost absurd.

    Companies may spend huge amounts of money on expensive security software. Sometimes, the software is not even very good. Sometimes, it creates more complexity and more possible ways for attackers to get in. But that is not always the real goal. The real goal can be to say later: “We did everything we could.” It is like putting a security camera on the front door, never checking whether it works, and then pointing at it after the robbery. The company wants to prove that it did not act carelessly. Real security becomes secondary. In cybersecurity, this is the difference between security and security theater. And even the biggest idiot should notice the problem when there is nobody left in the company to deal with the warnings. That is exactly what can happen. The security system sends alerts. Nobody reads them. Nobody investigates them. Nobody has the time, the skills, or sometimes even the job to deal with them. So the alerts are simply ignored.

    And here is the really strange part. The internet still works. It works partly because, for cybercriminals, stealing from badly protected companies is often more profitable than destroying the whole system. It is like a city where every door is unlocked. Criminals do not need to burn down the city. They can simply walk inside and take what they want.

    That may be the biggest lesson of all: Cybersecurity is not about having the right boxes checked. It is about knowing what can go wrong, finding the real risks, and making sure that someone is actually there when the alarm goes off.

    #cybersecurity #security #software #news #northkorea #crypto #cyberattack #fail #internet #economy #warning #danger #securitytheater #hack #hacker #crime #network #cyberspace #knowledge #knowhow #cybercrime #cyberattack #cyber

  13. A #Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide

    source: wired.com/story/a-security-pro…

    Given the danger of those breaches—both in terms of the exposure of sensitive data and the ongoing theft of cryptocurrency enriching the North Korean regime—the real concern shouldn’t necessarily be the companies Stykas has named but rather the ones he hasn’t. Those companies include hundreds that never responded to his warnings, he says, as well as more added to the list every day.


    And this, folks, is called security theater. Companies know that cyber threats are real.
    They know that #cybercriminals attack them every day. But many companies respond with checklists. Someone has to tick the boxes. Again and again. Often, these people have little cybersecurity training. They may not fully understand what they are checking.
    The checklist may be outdated. And sometimes, nobody in the company even knows why the checklist exists. It looks like security. But looking secure is not the same as being secure. This is where things can get almost absurd.

    Companies may spend huge amounts of money on expensive security software. Sometimes, the software is not even very good. Sometimes, it creates more complexity and more possible ways for attackers to get in. But that is not always the real goal. The real goal can be to say later: “We did everything we could.” It is like putting a security camera on the front door, never checking whether it works, and then pointing at it after the robbery. The company wants to prove that it did not act carelessly. Real security becomes secondary. In cybersecurity, this is the difference between security and security theater. And even the biggest idiot should notice the problem when there is nobody left in the company to deal with the warnings. That is exactly what can happen. The security system sends alerts. Nobody reads them. Nobody investigates them. Nobody has the time, the skills, or sometimes even the job to deal with them. So the alerts are simply ignored.

    And here is the really strange part. The internet still works. It works partly because, for cybercriminals, stealing from badly protected companies is often more profitable than destroying the whole system. It is like a city where every door is unlocked. Criminals do not need to burn down the city. They can simply walk inside and take what they want.

    That may be the biggest lesson of all: Cybersecurity is not about having the right boxes checked. It is about knowing what can go wrong, finding the real risks, and making sure that someone is actually there when the alarm goes off.

    #cybersecurity #security #software #news #northkorea #crypto #cyberattack #fail #internet #economy #warning #danger #securitytheater #hack #hacker #crime #network #cyberspace #knowledge #knowhow #cybercrime #cyberattack #cyber

  14. 🎉 FIPS 140-3: the glittering security badge everyone pays for but no one uses. 🤦‍♂️ #Auditors chuckle knowingly as companies fork out cash for paperwork, only to flip the security switch to "off." 📝➡️🚫 Welcome to the world of buying security theater—where #compliance is king, but actual security is just a quaint notion! 👑🔒
    808bits.com/articles/fips-140- #FIPS1403 #SecurityTheater #Cybersecurity #HackerNews #ngated

  15. 🎉 FIPS 140-3: the glittering security badge everyone pays for but no one uses. 🤦‍♂️ #Auditors chuckle knowingly as companies fork out cash for paperwork, only to flip the security switch to "off." 📝➡️🚫 Welcome to the world of buying security theater—where #compliance is king, but actual security is just a quaint notion! 👑🔒
    808bits.com/articles/fips-140- #FIPS1403 #SecurityTheater #Cybersecurity #HackerNews #ngated

  16. 🎉 FIPS 140-3: the glittering security badge everyone pays for but no one uses. 🤦‍♂️ #Auditors chuckle knowingly as companies fork out cash for paperwork, only to flip the security switch to "off." 📝➡️🚫 Welcome to the world of buying security theater—where #compliance is king, but actual security is just a quaint notion! 👑🔒
    808bits.com/articles/fips-140- #FIPS1403 #SecurityTheater #Cybersecurity #HackerNews #ngated

  17. 🎉 FIPS 140-3: the glittering security badge everyone pays for but no one uses. 🤦‍♂️ #Auditors chuckle knowingly as companies fork out cash for paperwork, only to flip the security switch to "off." 📝➡️🚫 Welcome to the world of buying security theater—where #compliance is king, but actual security is just a quaint notion! 👑🔒
    808bits.com/articles/fips-140- #FIPS1403 #SecurityTheater #Cybersecurity #HackerNews #ngated

  18. 🎉 FIPS 140-3: the glittering security badge everyone pays for but no one uses. 🤦‍♂️ #Auditors chuckle knowingly as companies fork out cash for paperwork, only to flip the security switch to "off." 📝➡️🚫 Welcome to the world of buying security theater—where #compliance is king, but actual security is just a quaint notion! 👑🔒
    808bits.com/articles/fips-140- #FIPS1403 #SecurityTheater #Cybersecurity #HackerNews #ngated

  19. Im nächsten Leben lerne ich etwas vernünftiges. Wenn die firmeninternen Auftraggeber deine Arbeit nur minimal und gerade das absolute Minimum erfüllt haben wollen, um compliant zu sein und ständig anmäkeln man täte zu viel, dann nervt es irgendwann gewaltig. Andere Stakeholder mischen sich natürlich permanent ein und untergraben die offiziellen Strukturen. Gestern war einer dieser Tage, die man konzentriert wegatmen musste 🖕🏻.

    #infosec #obdassorichtigist #mimimi #securitytheater

  20. @dewomser Und wer netcat auch für ein böses Hackertool und Sicherheitsrisiko hält, kann auch busybox nehmen:

    busybox nc towel.blinkenlights.nl 23

    #securitytheater

  21. @dewomser Und wer netcat auch für ein böses Hackertool und Sicherheitsrisiko hält, kann auch busybox nehmen:

    busybox nc towel.blinkenlights.nl 23

    #securitytheater

  22. @dewomser Und wer netcat auch für ein böses Hackertool und Sicherheitsrisiko hält, kann auch busybox nehmen:

    busybox nc towel.blinkenlights.nl 23

    #securitytheater

  23. @dewomser Und wer netcat auch für ein böses Hackertool und Sicherheitsrisiko hält, kann auch busybox nehmen:

    busybox nc towel.blinkenlights.nl 23

    #securitytheater

  24. @dewomser Und wer netcat auch für ein böses Hackertool und Sicherheitsrisiko hält, kann auch busybox nehmen:

    busybox nc towel.blinkenlights.nl 23

    #securitytheater

  25. Oh joy, another riveting adventure in "open source" land where you can't even get past the front gate without invoking the wrath of Cloudflare. 🚧🛑 Pro tip: If you require a PhD in cyber-sorcery just to access your "open" project, maybe rethink your security theater. 🎭🔒
    x.ai/open-source #openSource #securityCloudflare #cyberSecurity #accessIssues #securityTheater #HackerNews #ngated

  26. Oh joy, another riveting adventure in "open source" land where you can't even get past the front gate without invoking the wrath of Cloudflare. 🚧🛑 Pro tip: If you require a PhD in cyber-sorcery just to access your "open" project, maybe rethink your security theater. 🎭🔒
    x.ai/open-source #openSource #securityCloudflare #cyberSecurity #accessIssues #securityTheater #HackerNews #ngated

  27. Oh joy, another riveting adventure in "open source" land where you can't even get past the front gate without invoking the wrath of Cloudflare. 🚧🛑 Pro tip: If you require a PhD in cyber-sorcery just to access your "open" project, maybe rethink your security theater. 🎭🔒
    x.ai/open-source #openSource #securityCloudflare #cyberSecurity #accessIssues #securityTheater #HackerNews #ngated

  28. Oh joy, another riveting adventure in "open source" land where you can't even get past the front gate without invoking the wrath of Cloudflare. 🚧🛑 Pro tip: If you require a PhD in cyber-sorcery just to access your "open" project, maybe rethink your security theater. 🎭🔒
    x.ai/open-source #openSource #securityCloudflare #cyberSecurity #accessIssues #securityTheater #HackerNews #ngated

  29. Oh joy, another riveting adventure in "open source" land where you can't even get past the front gate without invoking the wrath of Cloudflare. 🚧🛑 Pro tip: If you require a PhD in cyber-sorcery just to access your "open" project, maybe rethink your security theater. 🎭🔒
    x.ai/open-source #openSource #securityCloudflare #cyberSecurity #accessIssues #securityTheater #HackerNews #ngated

  30. I get really tired of pages like this. I had to wrestle with this page no less than 6 times before purchasing tickets.

    1. Everyone has an adblocker. Everyone. Build your website with this in mind.
    2. The internet operated before JavaScript
    3. Your "security" measures are losing you more legitimate customers than saving you from fraud
    4. You sell tickets to tourists. Ofc their connections will look sketchy, not match regions, etc

    #enshittification #securitytheater #webdesign

  31. I get really tired of pages like this. I had to wrestle with this page no less than 6 times before purchasing tickets.

    1. Everyone has an adblocker. Everyone. Build your website with this in mind.
    2. The internet operated before JavaScript
    3. Your "security" measures are losing you more legitimate customers than saving you from fraud
    4. You sell tickets to tourists. Ofc their connections will look sketchy, not match regions, etc

    #enshittification #securitytheater #webdesign

  32. I get really tired of pages like this. I had to wrestle with this page no less than 6 times before purchasing tickets.

    1. Everyone has an adblocker. Everyone. Build your website with this in mind.
    2. The internet operated before JavaScript
    3. Your "security" measures are losing you more legitimate customers than saving you from fraud
    4. You sell tickets to tourists. Ofc their connections will look sketchy, not match regions, etc

    #enshittification #securitytheater #webdesign

  33. I get really tired of pages like this. I had to wrestle with this page no less than 6 times before purchasing tickets.

    1. Everyone has an adblocker. Everyone. Build your website with this in mind.
    2. The internet operated before JavaScript
    3. Your "security" measures are losing you more legitimate customers than saving you from fraud
    4. You sell tickets to tourists. Ofc their connections will look sketchy, not match regions, etc

    #enshittification #securitytheater #webdesign

  34. I get really tired of pages like this. I had to wrestle with this page no less than 6 times before purchasing tickets.

    1. Everyone has an adblocker. Everyone. Build your website with this in mind.
    2. The internet operated before JavaScript
    3. Your "security" measures are losing you more legitimate customers than saving you from fraud
    4. You sell tickets to tourists. Ofc their connections will look sketchy, not match regions, etc

    #enshittification #securitytheater #webdesign

  35. I have to scream into the void about #CyberEssentials, just for a minute. I apparently have bend over backwards to prove a bug in their product to an ASV which doesn't know the difference between a Windows 11 ntoskrnl.exe version and a Windows Server ntoskrnl.exe version. This is really helping me reduce cyber security risk. Just like being Cyber Essentials compliant helped M&S and Co-op. SO much time wasted. #cyberessentials #securitytheater

  36. I have to scream into the void about #CyberEssentials, just for a minute. I apparently have bend over backwards to prove a bug in their product to an ASV which doesn't know the difference between a Windows 11 ntoskrnl.exe version and a Windows Server ntoskrnl.exe version. This is really helping me reduce cyber security risk. Just like being Cyber Essentials compliant helped M&S and Co-op. SO much time wasted. #cyberessentials #securitytheater

  37. I have to scream into the void about #CyberEssentials, just for a minute. I apparently have bend over backwards to prove a bug in their product to an ASV which doesn't know the difference between a Windows 11 ntoskrnl.exe version and a Windows Server ntoskrnl.exe version. This is really helping me reduce cyber security risk. Just like being Cyber Essentials compliant helped M&S and Co-op. SO much time wasted. #cyberessentials #securitytheater

  38. I have to scream into the void about #CyberEssentials, just for a minute. I apparently have bend over backwards to prove a bug in their product to an ASV which doesn't know the difference between a Windows 11 ntoskrnl.exe version and a Windows Server ntoskrnl.exe version. This is really helping me reduce cyber security risk. Just like being Cyber Essentials compliant helped M&S and Co-op. SO much time wasted. #cyberessentials #securitytheater

  39. I have to scream into the void about #CyberEssentials, just for a minute. I apparently have bend over backwards to prove a bug in their product to an ASV which doesn't know the difference between a Windows 11 ntoskrnl.exe version and a Windows Server ntoskrnl.exe version. This is really helping me reduce cyber security risk. Just like being Cyber Essentials compliant helped M&S and Co-op. SO much time wasted. #cyberessentials #securitytheater

  40. ⚠️ The Password Bypass Illusion: How SMS 2FA Destroys Authentication Logic

    A recent experience while changing my account info reminded me why relying on telecom routing for security is an absolute nightmare, and why the infosec community needs to kill off SMS authentication for good.

    🚩 Battle.net SMS 2FA Failure and Security Theater:

    I attempted to log into Battle.net using a phone number I had legitimately owned for months, assuming I had added to my alt profile when I switched to that number. Instead of asking for a password or throwing an error, the platform sent an SMS code, accepted it, and instantly logged me into a complete stranger's legacy account.

    🚩 The Architectural Flaw:

    The platform's backend treated a single SMS verification token not as a supplementary second factor, but as a primary identity credential that bypassed traditional password authentication entirely. Because a stranger had left my number on their account months prior, the system assumed current possession of the SIM trumped all other security metrics.

    🏳 The Legal Reality of Intent:

    From a legal standpoint (like the CFAA), navigating into an account this way lacks the malicious intent required for criminal unauthorized access (Mens Rea); it's an accidental entry caused entirely by broken corporate infrastructure. But the fact that a user can simply input their own phone number and inadvertently hijack a stranger's digital life without a single exploit is a staggering failure of AppSec logic.

    ✅ The Solution:

    SMS is not identity proof. It is a highly volatile, easily routed carrier token. If a platform allows SMS to override or bypass a standard password barrier without out-of-band verification (like a mandatory email confirmation), it isn't secure.

    Stop letting telcos act as your root of trust. Switch to cryptographic hardware standards like NFC Yubikeys or standard TOTP apps.

    #CyberSecurity #Infosec #MFA #SecurityTheater #AppSec #Yubikey #CFAA #Hacking

  41. ⚠️ How SMS 2FA Destroys Authentication Logic

    A recent experience while changing my account info reminded me why relying on telecom routing for security is an absolute nightmare, and why the infosec community needs to kill off SMS authentication for good.

    🚩 Battle.net SMS 2FA Failure and Security Theater:

    I attempted to log into Battle.net using a phone number I had legitimately owned for months, assuming I had added to my alt profile when I switched to that number. Instead of asking for a secondary 2FA, the platform sent an SMS code, accepted it, and provided me access to a complete stranger's account.

    🚩 The Architectural Flaw:

    The platform's backend treated a single SMS verification token not as a supplementary second factor, but as a primary identity credential. Because a stranger had left my number on their account months prior, the system assumed current possession of the SIM trumped all other security metrics.

    🏳 The Legal Reality of Intent:

    From a legal standpoint (like the CFAA), navigating into an account this way lacks the malicious intent required for criminal unauthorized access (Mens Rea); it's an accidental entry caused entirely by broken corporate infrastructure. But the fact that a user can simply input their own phone number and inadvertently hijack a stranger's digital life without a single exploit is a staggering failure of AppSec logic.

    ✅ The Solution:

    SMS is not identity proof. It is a highly volatile, easily routed carrier token. If a platform allows SMS to override or bypass a standard password barrier without out-of-band verification (like a mandatory email confirmation), it isn't secure.

    Stop letting telcos act as your root of trust. Switch to cryptographic hardware standards like NFC Yubikeys or standard TOTP apps.

    #CyberSecurity #Infosec #MFA #SecurityTheater #AppSec #Yubikey #CFAA #Hacking