#hacker

anonymiss@despora.de

#Microsoft's Multi-Factor Authentication (MFA) implementation, allowing attackers to bypass it

Source: https://www.oasis.security/resources/blog/oasis-security-research-team-discovers-microsoft-azure-mfa-bypass

The bypass was simple: it took around an hour to execute, required no user interaction and did not generate any notification or provide the account holder with any indication of trouble.

#news #software #cybersecurity #cloud #security #hacker #fail #mfa

simona@pod.geraspora.de

Sicherheitsvorfall im #Fefe - #Blog

Was Fefe dazu sagt: https://blog.fefe.de/?ts=99bbcb97

Einerseits nimmt er es locker was sympathisch ist und ich weiß nicht ob ich so locker reagiert hätte. Fefe ist Sicherheitsspezialist und macht sich gerne über Sicherheitslücken lustig. Natürlich machen Menschen Fehler und 100% Sicherheit gibt es nicht.

Andererseits finde ich Fefe hätte ruhig etwas ausführlicher schreiben können was vorgefallen ist und wie er den Angriffsvektor übersehen konnte. Wäre bestimmt lehrreich für uns alle.

#internet #Sicherheit #Software #web #Angriff #Problem #Autorisierung #Spaß #hack #hacker

anonymiss@despora.de

Why is proprietary #software so bad and full of #vulnerabilities?

The sales department probably doesn't know any better and only has its commission in mind and just sells the software, that's their job. I'm not so sure about the management, whether they are clueless or just think that no matter how bad the software is, we can earn even more money with support contracts. There are certainly a few clueless developers who are kept so busy that they barely manage to complete their tasks but have no time for quality assurance. However, a large part of the developers will realize what is being played and then either change jobs after 2 years if it becomes unbearable or try to justify the quality of the software according to the motto it is a feature and not a bug. Ultimately, the only option left to cybersecurity is to secure vulnerable software with supposedly better security software. Bugs are not fixed unless public pressure is so strong that it is unavoidable and with one fixed bug, three new ones are installed. The supposedly secure security software all too often turns out to be snake oil, which only brings further security risks, which then have to be secured by further security software and you find yourself in a never-ending cascade, which becomes ever more dangerous and expensive but brings no security gain. There is even a technical term for this, called security theater. At the end of the day, all the management wants to say in its press release is that the hackers were diabolical criminals and probably had state support, but that the company had done everything it could to defend itself with the latest security software. The starting position is therefore clear. There is money to be made from security vulnerabilities and proper security means a lot of work. Economic considerations are therefore made here, according to which quality assurance can be saved because the customer can find and report the errors after all.

I'm pretty sure I'm not the smartest or the best developer, but I've figured it out and I'm always surprised that I often meet colleagues who are very confident about cybersecurity in the company because there is security training every year. I don't see any possibility of developing secure software at all under capitalism because profit is always valued higher than security.


#developer #management #economy #capitalism #profit #finance #security #cybersecurity #bug #fail #system #problem #hack #hacker #malware

scriptkiddie@anonsys.net

AI Group

#AI #software #Technology #Art #image #Experiment #join #group


anonymiss - 2024-11-16 00:53:31 GMT

We play around with different #AI #image #generators. On the picture above you can see the results of different users on the same prompt but with different models. You can participate or just watch in our group with the following URI: click here - or shorter link here: is.gd/aigroupYou need to install the #FLOSS #software #SimpleX.chat: f-droid.org/en/packages/chat.s…
If you don't want to use the app on your #Smartphone you can find a #desktop version here: simplex.chat/downloads/#deskto…

#technology #hacker #girl #art #artwork #group #join #chat #picture #generator #prompt

anonymiss@despora.de

We play around with different #AI #image #generators. On the picture above you can see the results of different users on the same prompt but with different models. You can participate or just watch in our group with the following URI: click here - or shorter link here: https://is.gd/aigroup

You need to install the #FLOSS #software #SimpleX.chat: https://f-droid.org/en/packages/chat.simplex.app
If you don't want to use the app on your #Smartphone you can find a #desktop version here: https://simplex.chat/downloads/#desktop-app

#technology #hacker #girl #art #artwork #group #join #chat #picture #generator #prompt

anonymiss@despora.de

#Amazon confirms #employee data stolen after #hacker claims #MOVEit #breach

source: https://techcrunch.com/2024/11/11/amazon-confirms-employee-data-stolen-after-hacker-claims-moveit-breach/

“Amazon and AWS systems remain secure, and we have not experienced a #security event. We were notified about a security event at one of our property management vendors that impacted several of its customers including Amazon. The only Amazon information involved was employee work contact information, for example work email addresses, desk phone numbers, and building locations,” Montgomery said.

If not even a company like Amazon can store its data securely, is there any security at all? Amazon doesn't lack money or experts, but it does seem to lack secure software.

#fail #cybersecurity #problem #software #internet #news #economy #hack #cloud

anonymiss@despora.de

Hackers take control of #robot vacuums in multiple cities, yell racial slurs

Source: https://www.abc.net.au/news/2024-10-11/robot-vacuum-yells-racial-slurs-at-family-after-being-hacked/104445408

The PIN code system protecting the robot's video feed — and remote control feature — was also known to be faulty, and the warning sound that is meant to play when the #camera is being watched was able to be disabled from afar.

These #security issues could explain how attackers took control of multiple robots in separate locations, and how they could've silently surveilled their victims once they'd gotten in.

#cybersecurity #news #hack #hacker #privacy #surveillance #Software #vulnerability #Problem #fail #economy #technology

anonymiss@despora.de

U.S. #Wiretap Systems Targeted in #China - Linked #Hack

Source: http://www.wsj.com/tech/cybersecurity/u-s-wiretap-systems-targeted-in-china-linked-hack-327fc63b

The #surveillance systems believed to be at issue are used to cooperate with requests for domestic information related to criminal and national security investigations. Under federal law, telecommunications and broadband companies must allow authorities to intercept electronic information pursuant to a court order. It couldn’t be determined if systems that support foreign #intelligence surveillance were also vulnerable in the breach.

Like all backdoors, this #backdoor is also a #security risk and not a gain.

#news #cybersecurity #cybercrime #privacy #politics #police #justice #communication #crime #Problem #USA #fail #hacker #Software #vulnerability #spy