mastodontech.de ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
Offen für alle (über 16) und bereitgestellt von Markus'Blog

Serverstatistik:

1,5 Tsd.
aktive Profile

#itsec

8 Beiträge6 Beteiligte0 Beiträge heute
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mastodon.gamedev.place/@afreytes" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>afreytes</span></a></span> +9001%</p><ul><li><p>It's impossible to get <a href="https://infosec.space/tags/GDPR" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GDPR</span></a> compliance with <a href="https://infosec.space/tags/GAFAMs" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GAFAMs</span></a>' products!</p></li><li><p>It's impossible to get <a href="https://infosec.space/tags/ITsec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ITsec</span></a>, <a href="https://infosec.space/tags/InfoSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InfoSec</span></a>, <a href="https://infosec.space/tags/OpSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpSec</span></a> &amp; <a href="https://infosec.space/tags/ComSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ComSec</span></a> on a compliant level when a literal <a href="https://infosec.space/tags/Govware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Govware</span></a> (<a href="https://infosec.space/tags/Windows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows</span></a>) is being used.</p></li><li><p>I cannot work as <a href="https://infosec.space/tags/Linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Linux</span></a> Sysadmin unter WinShit just like a cardiologist can't perform a heart transplant just cutlery from a prison mess hall and NSAIDs and just like a nurse can't CPR a toddler with a pneumatic jackhammer!</p></li></ul>
Oliver Brandmüller<p>Made my day. Auf so vielen Ebenen. ⅔ verstehen IT Sicherheit? I doubt that. Ist das bei älteren Erwachsenen etwa besser? I doubt that either.</p><p>Aber IT-Sicherheit ist sicher ein prima Gadget Trend 👍</p><p><a href="https://berlin.social/tags/DigitalNatives" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DigitalNatives</span></a> <a href="https://berlin.social/tags/ITSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ITSec</span></a></p>
Duncan Blues<p>Brauche einmal <a href="https://norden.social/tags/ITsec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ITsec</span></a> <a href="https://norden.social/tags/fedihelp" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>fedihelp</span></a> <br>Hat jemand belastbare(!), unabhängige Sicherheitseinschätzungen oder Un(?)bedenklichkeitserklärungen für die Verwendung von <a href="https://norden.social/tags/Microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Microsoft</span></a> Defender for Endpoint auf Workstations mit Zugriff auf sensible Daten?<br>Möglichst von seriösen Institutionen wie <a href="https://norden.social/tags/BSI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BSI</span></a> oder auch dem <a href="https://norden.social/tags/CCC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CCC</span></a>.<br>Es geht nicht um die Threat Erkennung durch MDE sondern um <a href="https://norden.social/tags/Privacy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Privacy</span></a> Bedenken für Mitarbeiter und Risiken *durch* die Verwendung von MDE.<br>Bitte keine individuellen Meinungen, davon gibt's genug.</p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://chaos.social/@martinsteiger" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>martinsteiger</span></a></span> <span class="h-card" translate="no"><a href="https://climatejustice.social/@KarlHeinzHasliP" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>KarlHeinzHasliP</span></a></span> <span class="h-card" translate="no"><a href="https://fedifreu.de/@cryptgoat" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>cryptgoat</span></a></span> <span class="h-card" translate="no"><a href="https://toots.ch/@dalai" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>dalai</span></a></span> <em>nope</em>, sondern Alltag!</p><ul><li>Weil <a href="https://infosec.space/tags/InfoSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InfoSec</span></a>, <a href="https://infosec.space/tags/OpSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpSec</span></a>, <a href="https://infosec.space/tags/ComSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ComSec</span></a>, <a href="https://infosec.space/tags/ITsec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ITsec</span></a> &amp; Co. stets ineinandergreifen und jene Technologien nachweislich sicher funktionieren… </li></ul><p><a href="https://infosec.space/tags/EOD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EOD</span></a> <a href="https://infosec.space/tags/THXBYE" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>THXBYE</span></a> <a href="https://infosec.space/tags/NEXT" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NEXT</span></a></p>
𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕<p>Rethinking Regex: Smarter detection for a modern threat landscape</p><p>Using regular expressions, or regex, was once a convenient and powerful way for web application firewalls (WAFs) to find malicious code in web requests.</p><p>🛡️ <a href="https://www.scworld.com/resource/rethinking-regex-smarter-detection-for-a-modern-threat-landscape" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">scworld.com/resource/rethinkin</span><span class="invisible">g-regex-smarter-detection-for-a-modern-threat-landscape</span></a></p><p><a href="https://chaos.social/tags/regex" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>regex</span></a> <a href="https://chaos.social/tags/thread" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>thread</span></a> <a href="https://chaos.social/tags/firewall" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>firewall</span></a> <a href="https://chaos.social/tags/code" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>code</span></a> <a href="https://chaos.social/tags/web" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>web</span></a> <a href="https://chaos.social/tags/itsec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>itsec</span></a> <a href="https://chaos.social/tags/request" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>request</span></a> <a href="https://chaos.social/tags/webapp" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>webapp</span></a> <a href="https://chaos.social/tags/threat" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>threat</span></a> <a href="https://chaos.social/tags/waf" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>waf</span></a> <a href="https://chaos.social/tags/itsecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>itsecurity</span></a> <a href="https://chaos.social/tags/websecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>websecurity</span></a></p>
𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕<p>»Bundesamt für Verkehr warnt Bahnbetriebe vor Cloud-Risiken:<br>Das BAV sieht bei der Auslagerung von Daten und Anwendungen gewisse Gefahren. Deshalb hat das Bundesamt die Regeln für die Bahnbetriebe verschärft.«</p><p>Jegliche Firmen &amp; Behörden sollten ihre IT-Sicherheit ernst nehmen, egal wie klein oder/und populär die sind. Es ist ein Mehraufwand der auftaucht durch die vergangenen Vernachlässigung.</p><p>🚆 <a href="https://www.inside-it.ch/bundesamt-fuer-verkehr-warnt-bahnbetriebe-vor-cloud-risiken-20250617" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">inside-it.ch/bundesamt-fuer-ve</span><span class="invisible">rkehr-warnt-bahnbetriebe-vor-cloud-risiken-20250617</span></a></p><p><a href="https://chaos.social/tags/sbb" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>sbb</span></a> <a href="https://chaos.social/tags/bav" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>bav</span></a> <a href="https://chaos.social/tags/cloud" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cloud</span></a> <a href="https://chaos.social/tags/schweiz" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>schweiz</span></a> <a href="https://chaos.social/tags/bahn" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>bahn</span></a> <a href="https://chaos.social/tags/daten" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>daten</span></a> <a href="https://chaos.social/tags/verkehr" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>verkehr</span></a> <a href="https://chaos.social/tags/schweiz" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>schweiz</span></a> <a href="https://chaos.social/tags/bundesamt" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>bundesamt</span></a> <a href="https://chaos.social/tags/itsec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>itsec</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mastodon.social/@renardboy" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>renardboy</span></a></span> same goes for <a href="https://infosec.space/tags/InfoSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InfoSec</span></a>, <a href="https://infosec.space/tags/OpSe" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpSe</span></a>, <a href="https://infosec.space/tags/ComSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ComSec</span></a> &amp; <a href="https://infosec.space/tags/ITsec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ITsec</span></a>:</p><p><em>NEVER EVER</em> use a service that demands <em>"<a href="https://infosec.space/tags/KYC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>KYC</span></a>"</em> no matter the <em>"legitimate interest"</em> they claim.</p><p>Because any information that <em>can be</em> weaponized against a user <em>will be!</em></p><p><a href="https://infosec.space/@kkarhan/114695158410619458" translate="no" rel="nofollow noopener" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.space/@kkarhan/1146951</span><span class="invisible">58410619458</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://infosec.exchange/@pascal_f" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>pascal_f</span></a></span> <span class="h-card" translate="no"><a href="https://social.tchncs.de/@kuketzblog" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>kuketzblog</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.net2o.de/@forthy42" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>forthy42</span></a></span> <span class="h-card" translate="no"><a href="https://bonn.social/@ulrichkelber" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>ulrichkelber</span></a></span> </p><p>Eben! Ich betrachte es ferner als naiv angesichts <a href="https://infosec.space/tags/CloudAct" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CloudAct</span></a>, Anbietern proprietärer <a href="https://infosec.space/tags/SingleVendor" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SingleVendor</span></a> / <a href="https://infosec.space/tags/SingleProvider" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SingleProvider</span></a>-"Lösungen" wie <span class="h-card" translate="no"><a href="https://mastodon.world/@signalapp" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>signalapp</span></a></span> das vertrauen zu schenken!</p><ul><li>Und wenn das bedeutet dass Leute <a href="https://infosec.space/tags/Windows11" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows11</span></a> &amp; Co. rausschmeißen dann ist dem so.</li></ul><p>Gerade weil <a href="https://infosec.space/tags/ITsec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ITsec</span></a>, <a href="https://infosec.space/tags/InfoSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InfoSec</span></a>, <a href="https://infosec.space/tags/OpSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpSec</span></a> &amp; <a href="https://infosec.space/tags/ComSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ComSec</span></a> zusammenhängen und nur zusammen funktionieren...</p>
Nerdfallmanagement<p>In ein paar Wochen habe ich mal wieder die Ehre, einen Vortrag zu <a href="https://social.tchncs.de/tags/DigitalerGewalt" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DigitalerGewalt</span></a> <a href="https://social.tchncs.de/tags/Cyberstalking" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Cyberstalking</span></a> <a href="https://social.tchncs.de/tags/Spionage" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Spionage</span></a> halten zu dürfen. Die Basics zu Technik und Psychologie zzgl. Statistiken sind alle drin. Aber mich würde interessieren, welche <a href="https://social.tchncs.de/tags/Fakten" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Fakten</span></a> und Webseiten euch dazu besonders einfallen/ berühren, welche Hilfsangebote außer dem <a href="https://social.tchncs.de/tags/Wei%C3%9FerRing" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WeißerRing</span></a> und den <a href="https://social.tchncs.de/tags/Haeksen" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Haeksen</span></a> ihr erwähnen würdet. Kurz: Was würdet ihr hören wollen?<br>Gerne <a href="https://social.tchncs.de/tags/boost" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>boost</span></a> <br><a href="https://social.tchncs.de/tags/Schwarmintelligenz" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Schwarmintelligenz</span></a> <a href="https://social.tchncs.de/tags/ITSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ITSec</span></a> <a href="https://social.tchncs.de/tags/Cybersec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Cybersec</span></a> <a href="https://social.tchncs.de/tags/KI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>KI</span></a> <a href="https://social.tchncs.de/tags/hauslichegewalt" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>hauslichegewalt</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mastodon.social/@mshelton" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>mshelton</span></a></span> <span class="h-card" translate="no"><a href="https://social.freedom.press/@freedomofpress" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>freedomofpress</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@eff" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>eff</span></a></span> I did prepare peoples' devices for that in the past.</p><p>My suggestions:</p><p><code>0.</code> Never assume you'll have any <a href="https://infosec.space/tags/HumanRights" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HumanRights</span></a> or <a href="https://infosec.space/tags/CivilRights" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CivilRights</span></a>. Always assume <a href="https://infosec.space/tags/TSA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TSA</span></a> staff is looking for a reason to jail, deport, deny entry or shoot one on the spot.</p><p><code>1.</code> Do not have data on them! <a href="https://infosec.space/tags/CPB" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CPB</span></a> <em>will seize any storage media under threat of lethal violence</em>! Use a <a href="https://infosec.space/tags/ThinClient" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ThinClient</span></a>-like device without any persistent storage. Keep anything important in your head or don't keep it at all.</p><p><code>2.</code> Have someone to setup a <a href="https://infosec.space/tags/RemoteDesktop" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>RemoteDesktop</span></a> for you post-entry and enshure you've got a <em><a href="https://infosec.space/tags/SafeWord" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SafeWord</span></a></em> to indicate you're acting under duress, so they can redirect stuff to a inconspicuous system.</p><p><code>3.</code> Have a <a href="https://infosec.space/tags/decoy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>decoy</span></a> system ready. CPB have full, unrestricted bulk access to all data from companies that are located, do business in or have an office within the <a href="https://infosec.space/tags/USA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>USA</span></a> as per <a href="https://infosec.space/tags/CloudAct" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CloudAct</span></a>. So much so that they consider it <em>"suspicious"</em> if one doesn't have an <a href="https://infosec.space/tags/NSABook" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NSABook</span></a> account.</p><p><code>4.</code> Make shure <em>all your devices</em> are <a href="https://infosec.space/tags/clean" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>clean</span></a>. Get yourself new <em>throwaway</em> devices and don't trust them if you ever let them out of sight for a second!</p><p><code>5.</code> Test your setup <em>before</em> you travel to the <a href="https://infosec.space/tags/US" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>US</span></a> <em>on a different system.</em> </p><p><code>6.</code> This applies to <em>every single device</em> from <a href="https://infosec.space/tags/SimCard" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SimCard</span></a> to <a href="https://infosec.space/tags/Laptop" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Laptop</span></a>. Assume that if authorities plug anything in them, they are <em>irredeemably compromised</em>!</p><p><code>7.</code> Practise proper <a href="https://infosec.space/tags/ITsec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ITsec</span></a>, <a href="https://infosec.space/tags/InfoSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InfoSec</span></a>, <a href="https://infosec.space/tags/OpSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpSec</span></a> &amp; <a href="https://infosec.space/tags/ComSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ComSec</span></a>. Have proper contingencies and emergency contacts in place.</p>
Kevin Karhan :verified:<p>Wer so'n shice programmieren kann, kann auch gefälligst ne Seite baun die ohne <a href="https://infosec.space/tags/JavaScript" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>JavaScript</span></a> auskommt! </p><p><a href="https://infosec.space/tags/NoJS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NoJS</span></a> <a href="https://infosec.space/tags/Malware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Malware</span></a> <a href="https://infosec.space/tags/NoJavascript" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NoJavascript</span></a> <a href="https://infosec.space/tags/Accessibility" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Accessibility</span></a> <a href="https://infosec.space/tags/Privacy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Privacy</span></a> <a href="https://infosec.space/tags/ITsec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ITsec</span></a> <a href="https://infosec.space/tags/InfoSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InfoSec</span></a> <a href="https://infosec.space/tags/OpSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpSec</span></a> <a href="https://infosec.space/tags/ComSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ComSec</span></a> <a href="https://infosec.space/tags/Webdesign" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Webdesign</span></a> <a href="https://infosec.space/tags/Enshittification" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Enshittification</span></a></p>
Kevin Karhan :verified:USpol, Trump, US-centric Internet Infrastructure, National Internet Blackout
Kevin Karhan :verified:USpol, trans genocide
𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕<p>Wann macht VPN Sinn und wann nicht habe ich mal in dieser verlinkten Toot-Reihe aufgeführt, denn privat - sprich anonym - ist es nicht:</p><p>:mastodon: <a href="https://mastoreader.io/?url=https%3A%2F%2Fchaos.social%2F%40kubikpixel%2F108311048569452123" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">mastoreader.io/?url=https%3A%2</span><span class="invisible">F%2Fchaos.social%2F%40kubikpixel%2F108311048569452123</span></a></p><p><a href="https://chaos.social/tags/vpn" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>vpn</span></a> <a href="https://chaos.social/tags/internet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>internet</span></a> <a href="https://chaos.social/tags/privatsphare" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>privatsphare</span></a> <a href="https://chaos.social/tags/privat" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>privat</span></a> <a href="https://chaos.social/tags/web" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>web</span></a> <a href="https://chaos.social/tags/anonym" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>anonym</span></a> <a href="https://chaos.social/tags/toot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>toot</span></a> <a href="https://chaos.social/tags/zusammenfassen" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>zusammenfassen</span></a> <a href="https://chaos.social/tags/itsec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>itsec</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://ard.social/@tagesschau" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>tagesschau</span></a></span> ja wenn überall dieselbrige <a href="https://infosec.space/tags/backdoor" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>backdoor</span></a>|te <a href="https://infosec.space/tags/Govware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Govware</span></a> (<a href="https://infosec.space/tags/Windows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows</span></a>) benutzt wird ist das nunmal systemisches Versagen und politisch so gewollt!</p><p><a href="https://www.youtube.com/watch?v=_7583HNrZJs" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">youtube.com/watch?v=_7583HNrZJs</span><span class="invisible"></span></a></p><p><a href="https://infosec.space/tags/DEpol" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DEpol</span></a> <a href="https://infosec.space/tags/EUpol" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EUpol</span></a> <a href="https://infosec.space/tags/ITsec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ITsec</span></a> <a href="https://infosec.space/tags/InfoSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InfoSec</span></a> <a href="https://infosec.space/tags/OpSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpSec</span></a> <a href="https://infosec.space/tags/ComSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ComSec</span></a> <a href="https://infosec.space/tags/GAFAMs" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GAFAMs</span></a> <a href="https://infosec.space/tags/CloudAct" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CloudAct</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://hostsharing.coop/@cdonat" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>cdonat</span></a></span> <span class="h-card" translate="no"><a href="https://toots.ch/@dalai" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>dalai</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@ip6li" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>ip6li</span></a></span> also ich würde darüber garnicht erst diskutieren:</p><p>Entweder fliegt sower hochkant und ich krieg' den Job &amp; Gehalt oder ich gehe und das <a href="https://infosec.space/tags/BSI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BSI</span></a> zerlegt den Laden so heftig dass keiner der CxO's mehr irgendwo nen Job bekommt, noch nichtmals als Lieferfahrer*in!</p><p><a href="https://infosec.space/@kkarhan/114621798932871398" translate="no" rel="nofollow noopener" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.space/@kkarhan/1146217</span><span class="invisible">98932871398</span></a></p><p>Ich meine wo kommen wir da hin? Leute die <a href="https://infosec.space/tags/NanoCore" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NanoCore</span></a> unsarkastisch zur <a href="https://infosec.space/tags/Administration" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Administration</span></a> von <em>'<a href="https://infosec.space/tags/WindowsServer" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WindowsServer</span></a>"</em> nutzen?</p><p><a href="https://infosec.space/tags/NotLegalAdvice" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NotLegalAdvice</span></a> <a href="https://infosec.space/tags/Sarkasmus" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Sarkasmus</span></a> <a href="https://infosec.space/tags/ITsec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ITsec</span></a> <a href="https://infosec.space/tags/InfoSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InfoSec</span></a> <a href="https://infosec.space/tags/OpSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpSec</span></a> <a href="https://infosec.space/tags/ComSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ComSec</span></a></p>
Kevin Karhan :verified:<p><a href="https://infosec.space/tags/HotTake" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HotTake</span></a>: Wer <em>"<a href="https://infosec.space/tags/KI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>KI</span></a>"</em> im <a href="https://infosec.space/tags/Recruiting" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Recruiting</span></a> einsetzt gehört mit <a href="https://infosec.space/tags/Berufsverbot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Berufsverbot</span></a> wegen mangelnder <a href="https://infosec.space/tags/Berufsethik" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Berufsethik</span></a> belegt!</p><p><a href="https://infosec.space/tags/AI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AI</span></a> <a href="https://infosec.space/tags/AIslop" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AIslop</span></a> <a href="https://infosec.space/tags/Enshittification" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Enshittification</span></a> <a href="https://infosec.space/tags/Datenschutz" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Datenschutz</span></a> <a href="https://infosec.space/tags/InfoSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InfoSec</span></a> <a href="https://infosec.space/tags/OpSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpSec</span></a> <a href="https://infosec.space/tags/ComSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ComSec</span></a> <a href="https://infosec.space/tags/ITsec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ITsec</span></a> <a href="https://infosec.space/tags/GAFAMs" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GAFAMs</span></a> <a href="https://infosec.space/tags/DSGVO" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DSGVO</span></a> <a href="https://infosec.space/tags/BDSG" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BDSG</span></a> <a href="https://infosec.space/tags/Diskriminierung" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Diskriminierung</span></a> <a href="https://infosec.space/tags/InformationelleSelbstbestimmung" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InformationelleSelbstbestimmung</span></a></p>
Felix Eckhardt<p>Security needs to be considered in the early phases of software projects. To fix security issues is more expensive the later they are discovered/fixed. This is similar to bugs, which get more expensive to fix, the later we tackle these.</p><p>And remeber: security is a process, start implementing it as early as possible.</p><p><a href="https://det.social/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a> <a href="https://det.social/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a> <a href="https://det.social/tags/itsec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>itsec</span></a> <a href="https://det.social/tags/itsecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>itsecurity</span></a></p>
𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕<p>»Per Coredump – Angreifer können unter Linux Passwort-Hashes abgreifen:<br>Mehrere Versionen von <span class="h-card" translate="no"><a href="https://ubuntu.social/@ubuntu" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>ubuntu</span></a></span>, <span class="h-card" translate="no"><a href="https://fosstodon.org/@fedora" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>fedora</span></a></span> und RHEL sind angreifbar. Böswillige Akteure können Anwendungen crashen und vertrauliche Daten erbeuten.«</p><p>Mist aber auch! Ich muss mir dies noch genauer ansehen, auf welche Rechner welche Updates eingespielt werden muss, wenn dies nicht schon automatisch geschah.</p><p>🐧 <a href="https://www.golem.de/news/per-coredump-angreifer-koennen-unter-linux-passwort-hashes-abgreifen-2506-196786.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">golem.de/news/per-coredump-ang</span><span class="invisible">reifer-koennen-unter-linux-passwort-hashes-abgreifen-2506-196786.html</span></a></p><p><a href="https://chaos.social/tags/linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>linux</span></a> <a href="https://chaos.social/tags/itsicherheit" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>itsicherheit</span></a> <a href="https://chaos.social/tags/passwort" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>passwort</span></a> <a href="https://chaos.social/tags/hash" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>hash</span></a> <a href="https://chaos.social/tags/rhel" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>rhel</span></a> <a href="https://chaos.social/tags/itsec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>itsec</span></a> <a href="https://chaos.social/tags/crash" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>crash</span></a> <a href="https://chaos.social/tags/updates" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>updates</span></a> <a href="https://chaos.social/tags/ubuntu" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ubuntu</span></a> <a href="https://chaos.social/tags/fedora" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>fedora</span></a> <a href="https://chaos.social/tags/update" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>update</span></a> <a href="https://chaos.social/tags/daten" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>daten</span></a></p>
𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕<p>»Amazon-Entwickler am Limit – KI-Druck verwandelt Programmieren in Fließbandarbeit:<br>Software-Entwickler:innen bei Amazon beklagen widrige Arbeitsumstände. Sie müssen mittlerweile Code wie am Fließband schreiben. Welche Ursache dieser neue Leistungsdruck hat.«</p><p>Wenn dies nicht mehr Fehler so wie anfälligeren Code und unbehobene Probleme durch "ungebildete" Lösungen der Angestellten ergibt?</p><p>🧑‍💻 <a href="https://t3n.de/news/amazon-entwickler-limit-ki-druck-programmieren-fliessbandarbeit-1689722/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">t3n.de/news/amazon-entwickler-</span><span class="invisible">limit-ki-druck-programmieren-fliessbandarbeit-1689722/</span></a></p><p><a href="https://chaos.social/tags/amazon" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>amazon</span></a> <a href="https://chaos.social/tags/ki" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ki</span></a> <a href="https://chaos.social/tags/flie%C3%9Fbandproduktion" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>fließbandproduktion</span></a> <a href="https://chaos.social/tags/code" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>code</span></a> <a href="https://chaos.social/tags/it" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>it</span></a> <a href="https://chaos.social/tags/software" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>software</span></a> <a href="https://chaos.social/tags/angestellten" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>angestellten</span></a> <a href="https://chaos.social/tags/limit" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>limit</span></a> <a href="https://chaos.social/tags/itsec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>itsec</span></a></p>