home.social

#securitytip — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #securitytip, aggregated by home.social.

fetched live
  1. if your domain has no DMARC record, here's your 5-minute fix:

    1. Run a DMARC check to confirm you have nothing published

    2. Add this TXT record to `_dmarc.yourdomain.com`: `v=DMARC1; p=none; rua=mailto:[email protected]`

    3. Wait 48 hours for reports to arrive

    you're not enforcing yet. you're listening.

    those aggregate reports will show you every IP address sending email as your domain.

    dmarcguard.io/tools/dmarc-gene

    #DMARC #EmailSecurity #QuickWin #SecurityTip

  2. if your domain has no DMARC record, here's your 5-minute fix:

    1. Run a DMARC check to confirm you have nothing published

    2. Add this TXT record to `_dmarc.yourdomain.com`: `v=DMARC1; p=none; rua=mailto:[email protected]`

    3. Wait 48 hours for reports to arrive

    you're not enforcing yet. you're listening.

    those aggregate reports will show you every IP address sending email as your domain.

    dmarcguard.io/tools/dmarc-gene

    #DMARC #EmailSecurity #QuickWin #SecurityTip

  3. Saturday DMARC tip: check your subdomains

    your main domain might be at p=reject

    but what about mail.yourdomain.com?

    or marketing.yourdomain.com?

    DMARC policies automatically cascade to subdomains (but not all MTA providers respect it!)

    you are strongly recommended to explicitly set `sp=reject` in your organizational domain's record

    without it, every subdomain inherits p=none by default

    dmarcguard.io/tools/dmarc-chec

    #DMARC #EmailSecurity #DNSTips #SecurityTip

  4. Saturday DMARC tip: check your subdomains

    your main domain might be at p=reject

    but what about mail.yourdomain.com?

    or marketing.yourdomain.com?

    DMARC policies automatically cascade to subdomains (but not all MTA providers respect it!)

    you are strongly recommended to explicitly set `sp=reject` in your organizational domain's record

    without it, every subdomain inherits p=none by default

    dmarcguard.io/tools/dmarc-chec

    #DMARC #EmailSecurity #DNSTips #SecurityTip

  5. If, like me, you have older parents who sometimes struggle with technology, but you want them to move off of using FB messenger, sms, etc and onto Signal, my tip is to drop the Signal app icon in a group with the normal text message app icon, so they have to look at both before messaging. This is useful to develop new patterns in general, not just good for technophobes :)

    #SecurityTip

  6. get a tattoo of a qr code for a rickroll on your ass. that way if anyone tries to take a pic of you naked they'll be watching rick astley instead #securitytip #netsec

  7. get a tattoo of a qr code for a rickroll on your ass. that way if anyone tries to take a pic of you naked they'll be watching rick astley instead #securitytip #netsec

  8. Fun little vulnerability I found recently:
    Change any user's profile picture based on the provided `?id=x` query parameter! 😈

    Always pull User ID from the Auth system, rather than rely on a value from the browser...
    #PHP #Laravel #SecurityTip

  9. Fun little vulnerability I found recently:
    Change any user's profile picture based on the provided `?id=x` query parameter! 😈

    Always pull User ID from the Auth system, rather than rely on a value from the browser...
    #PHP #Laravel #SecurityTip

  10. A quick #securitytip on how to block password-protected attachments in emails.

    If you have #Microsoft #Defender for #Office365 licenses, you can use the technology called Safe Attachments. Safe Attachments do advanced scanning of attachments through so called detonations, where these attachments are run on a test environment and what the file does when it is run is monitored.

    If an email contains a password-protected attachment, then these detonations cannot take place. In the Safe Attachments settings, you can set what should happen if the scan couldn't complete for some reason, which is exactly the case with the password-protected attachment. In this case, it is recommended to set the email to be blocked. #email #mdo #cybersecurity #bes

  11. A quick #securitytip on how to block password-protected attachments in emails.

    If you have #Microsoft #Defender for #Office365 licenses, you can use the technology called Safe Attachments. Safe Attachments do advanced scanning of attachments through so called detonations, where these attachments are run on a test environment and what the file does when it is run is monitored.

    If an email contains a password-protected attachment, then these detonations cannot take place. In the Safe Attachments settings, you can set what should happen if the scan couldn't complete for some reason, which is exactly the case with the password-protected attachment. In this case, it is recommended to set the email to be blocked. #email #mdo #cybersecurity #bes

  12. Periodic reminder that no one should be able to log on to your production database. Especially not your developers

    #infosec #security #securitytip

  13. Periodic reminder that no one should be able to log on to your production database. Especially not your developers

    #infosec #security #securitytip

  14. @hacks4pancakes for the best security, lock yourself in a dark room alone and just never leave. #infosec #securitytip

  15. @hacks4pancakes for the best security, lock yourself in a dark room alone and just never leave. #infosec #securitytip