toad.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mastodon server operated by David Troy, a tech pioneer and investigative journalist addressing threats to democracy. Thoughtful participation and discussion welcome.

Administered by:

Server stats:

258
active users

#insecure

0 posts0 participants0 posts today
Replied in thread

@boelder
RE
corporations putting confidential data in #insecure #datastorage owned by Amazon

@not2b
RE
using it for training...

@Haste
RE
AI scribe taking session notes.... the rooms are capable of recording now, but assured me that it is⭕ "completely deleted” in a “timely fashion”

IMO, the #AI is ⭕listing and using the sentences that go into the #LLM after this the original TEXT and AUDIO can be deleted.
This deletion is not the issue, right⁉️

#LargeLanguageModel
en.wikipedia.org/wiki/Large_la

en.wikipedia.orgLarge language model - Wikipedia

→ SMS 2FA is not just insecure, it's also hostile to mountain people
blog.stillgreenmoss.net/sms-2f

“there are 1.1 million people in these western north carolina mountains, 25 million in the rest of the appalachians, and many millions more in the mountain west and pacific ranges.

we have internet, but we have F-tier cell service — what are we supposed to do?”

stillgreenmoss · SMS 2FA is not just insecure, it's also hostile to mountain peoplei have a friend -- she's an old lady born and raised here in the western north carolina mountains. she hates computers, yes, but she's be...
#SMS#2FA#insecure
Replied in thread

@signalapp It's not #disinfo when one points out that you demand #PII aka. #PhoneNumbers from Users and that is literally a architectural vulnerability, alongside your #proprietary & #Centralized #Infrastructure.

Not to mention the lack of @torproject / #Tor support with an #OnionService or the willingness to fulfill #cyberfacist "Embargoes" or shilling a #Shitcoin #Scam named #MobileCoin!

  • #KYC is the illicit activity!!!

And don't get me started on the #cyberfacism that is #CloudAct.

  • If you were secure, criminals would've used your platform so hard, it would've been shutdown like #EncroChat and #SkyECC.

I may nit have allvthe.evidence yet, but #Signal stenches like #ANØM: #Honeypot-esque!

Guide to Interpreting Security Incident #Announcements:

"extremely sophisticated attack" : The attackers put more time into the attack than we spent designing our defences.

"no evidence customer #data was accessed" : We lack audit records and the logs have been rotated out.

"due to a misconfiguration issue" : We deployed with default #insecure settings.

"possible for only a short window" : We didn't dig too deep to determine how far back the bug existed.

"crafted invalid request data" : We forgot to add input #validation.

"supplementary fix" : We didn't understand the problem as well as we thought, so our previous fix was insufficient.

"may have been exploited" : We're positive they got away with data, but they deleted our #logs.

"multiple threat actors" : Everyone was in our systems before we noticed.

"most customers are unaffected" : There are corner cases that aren't as #vulnerable.

"error in a third-party component" : We forgot to update our dependencies.

"could lead to remote code execution" : You're #p0wned.

"malicious activity has been observed" : The issue has already appeared in the press.

"review equipment inventory to verify if devices require other mitigations" : You need to buy new stuff.

"remotely exploited to allow authentication bypass" : We forgot to require #login for this function.

"not aware of any exploits in the wild" : The attackers aren't bragging on darkweb fora yet.

Computerworld: US Government sued after mass emails to federal workforce allegedly sent from insecure server

"...Musk appointees allegedly plugged their own email server into OPM network, breaking data security rules. ... The suit was filed after OPM sent two test emails to an estimated 2.3 million federal employees in a way that, the suit alleges, broke the E-Government Act of 2002 and was inherently insecure. Those rules require that a Privacy Impact Assessment (PIA) be carried out first.... The OPM did not immediately respond to questions sent to the hr@opm.gov email address."

computerworld.com/article/3812 #cybersecurity #email #insecure #hacking #Musk #Politics #USpol

Computerworld · US Government sued after mass emails to federal workforce allegedly sent from insecure serverBy John E. Dunn
Continued thread

#ElonMusk’s posts serve as “merely a trigger mechanism” to his followers, Donovan said, often prompting them to scour social media profiles, look up information about a target’s family members, launch cyberattacks, lodge fake complaints with their employer, or flood people with texts & phone calls throughout the night.