soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin email
social@octade.net

Search results for tag #security

[?]WIRED - The Latest in Technology, Science, Culture and Business [Unofficial] » 🌐
@wired.com@web.brid.gy

How to Watch the Knicks Parade on NYC Traffic Surveillance Cameras

Artist Morry Kolman will be livestreaming feeds of the NBA champions’ ticker-tape parade from NYC’s traffic cameras—and this time, the city’s Department of Transportation isn’t demanding he stop.

How to Watch the Knicks Parade on NYC Traffic Surveillance Cameras

Alt...How to Watch the Knicks Parade on NYC Traffic Surveillance Cameras

[?]:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉 » 🌐
@nemo@mas.to

:boost: :boostplease:

Four easy steps to elevate your privacy & security this year:

Choose a privacy-respecting browser 🌐 Check out: privacytests.org/

Use a privacy-first search engine 🔎 (Startpage, DuckDuckGo, self-hosted options etc.) further reading: privacyguides.org/en/search-en

Use privacy-respecting email 📧 (Proton, Tuta, ) further reading: privacyguides.org/en/email/

Use only E2EE messaging apps 🔒 (cross-platform with minimal metadata: Signal) further reading: privacyguides.org/en/real-time

You're welcome… spread the word! Sharing is caring 🎁💬

The gift that keeps on giving: data retention, compartmentalization, FOSS, privacy & security. stick it to them… 🖕Privacy security isn't a sprint; it is a marathon… Even a journey of over 9k steps begins with the first one… 🙏 💚Use E2EE, full-disk encryption, back up, and update…

:boost: :boostplease:

Alt...cat eating watermelon

    [?]Jesus Michał von Gentoo 🏔 (he) » 🌐
    @mgorny@social.treehouse.systems

    0 days since provenance checks protected us from [checks notes] another project starting to upload distributions via .

      Light boosted

      [?]xoron :verified: » 🌐
      @xoron@infosec.exchange

      WhatsApp Clone, but Decentralized with P2P Messaging

      App: Enkrypted.Chat

      "Secure and private" is the general goal.

      This is a technical/concept demo of a fairly unique approach using a browser-based, local-first and webrtc.

      This is intended to introduce a new paradigm in client-side managed secure cryptography. We can avoid registration of any sort.

      Features:

      * P2P
      * End to end encryption
      * Signal protocol
      * Post-Quantum cryptography
      * File transfer
      * Local-first
      * No registration
      * No installation
      * No database
      * TURN server

      Feel free to reach out for clarity instead of diving into the docs/code.

      IMPORTANT: While this is aiming to provide a secure experience, it isnt audited or reviewed. **Shared for testing, feedback and demo purposes only.** Please use responsibly.

        [?]Freezenet » 🌐
        @freezenet@noc.social

        Canadian Government Gears Up to Pretend to Care About Privacy

        Reports are surfacing saying that privacy reform is going to be tabled soon. We've been through this song and dance before.

        freezenet.ca/canadian-governme

          JJDavis :terminal: boosted

          [?]Brian Greenberg :verified: » 🌐
          @brian_greenberg@infosec.exchange

          The most interesting thing about the new SearchLeak attack on Microsoft 365 Copilot isn't any single bug. It's that none of the three pieces was dangerous on its own. Varonis combined a prompt injection via a URL parameter, an HTML rendering race condition, and a server-side request forgery in Bing's image search. Each of these is a common bug that security teams usually consider minor. But when you put them together with a Copilot that can access your mailbox, OneDrive, and SharePoint, they create a critical flaw. Microsoft has since patched this issue (CVE-2026-42824).

          This is how the attack worked:

          * The victim clicks a link. That's the whole interaction. They type nothing.

          * The link instructs Copilot to search the mailbox, find sensitive information such as access codes, and place it into an image URL.

          * Bing retrieves that image, which sends the stolen data to the attacker's server. Bing serves as the delivery service, allowing the attack to bypass the content security policy intended to stop it.

          From the user's perspective, Copilot just pauses for a moment. There is no visible sign that any data has been taken.

          In the past, we've spent years rating bugs by their severity on their own. An SSRF here, an HTML injection there—each seemed minor. But when an AI assistant can follow instructions from untrusted input and access your real data, those minor bugs become much more serious. Old types of vulnerabilities become important again in this new context.

          If your company uses Copilot or any AI assistant that can access company data, it is important to ask your team how they are rating bugs that affect it. The way we judge what is low risk has changed.

          bleepingcomputer.com/news/secu

            [?]WIRED - The Latest in Technology, Science, Culture and Business [Unofficial] » 🌐
            @wired.com@web.brid.gy

            Meta Tapped a Pentagon Supplier to Prototype Face Recognition for Its Glasses

            Rank One, whose board includes a former CIA deputy director and a former FBI science chief, supplied face recognition to Meta for internal development of its smart glasses app.

            Meta Tapped a Pentagon Supplier to Prototype Face Recognition for Its Glasses

            Alt...Meta Tapped a Pentagon Supplier to Prototype Face Recognition for Its Glasses

            [?]:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉 » 🌐
            @nemo@mas.to

            :awesome: Things that make me instantly happy: beautiful night sky, beautiful forests and nature (night or day), fireflies, aurora borealis, rain, the smell of rain, good food, good satire, good coffee, good movies, good music, good art, happy animals, Linux, privacy, security, human rights… etc. 🌌🐧🌲🌿🌧️ ✨

            What makes you instantly happy… 🤔

              [?]GamingOnLinux 🐧🎮 » 🌐
              @gamingonlinux@mastodon.social

              Iron Bug boosted

              [?]Alexey Skobkin » 🌐
              @skobkin@gts.skobk.in

              Господа арчеводы (и арчебейздоводы на Manjaro, CachyOS, EdeavourOS, etc), вам там подвезли добра в AUR:

              https://ioctl.fail/preliminary-analysis-of-aur-malware/

              TL;DR: в ~400+ пакетов (о которых известно на данный момент) в AUR добавили малварь, которая ворует креды и имеет встроенный руткит.
              Если недавно (несколько дней) обновлялись из AUR не вычитывая сорцы пакетов - стоит напрячься.

              Вот тут есть список пакетов, о которых известно:
              https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/

              @rf
              #Linux #Arch #AUR #security #malware #rootkit #news

                [?]:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉 » 🌐
                @nemo@mas.to

                Le Monde's research showed ad data from smartphone SDKs. can expose identities and daily movements of police, military, and intelligence personnel… sold by data brokers from everyday apps. If those people can get exposed, everyone can. Mitigation below! Read: proton.me/blog/ad-tech-privacy 🛰️📱

                "…What can you do about it?
                There’s no way to stop all kinds of tracking, but you can take the following actions to reduce the granularity of the datasets collected:

                Turn off location services(new window) when not in use and deny apps location permissions.
                Use a VPN(new window) to hide your real IP address. DNS filtering features such as Proton VPN’s NetShield Ad-blocker(new window) can also help bock ad and tracker scripts.
                Delete your advertising ID on Android (Settings → Google → All services → Ads → Privacy and security → Ads → Delete advertising ID). iPhones don’t provide this option."

                Use GrapheneOS without Google

                screenshot of how to delete advertising ids, OCR'd text: " Delete your advertising ID on Android (Settings —- Google — All services — Ads —
Privacy and security —- Ads — Delete advertising ID). iPhones don't provide this
option.
<€
Manage the info used to show you ads and
measure ad performance
Reset advertising ID
This generates a new advertising ID that apps can use from
now on
Delete advertising ID
Apps can no longer use this advertising ID to show you
personalised ads
@
These settings help you control what data advertisers can
use to show you ads
Advertising ID:
daa08b66-6b6c-4876-a283-d4e53064c155,
Learn more about advertising |D"

Quote: "Delete your advertising ID on Android (Settings → Google → All services → Ads → Privacy and security → Ads → Delete advertising ID). iPhones don’t provide this option.
"

                Alt...screenshot of how to delete advertising ids, OCR'd text: " Delete your advertising ID on Android (Settings —- Google — All services — Ads — Privacy and security —- Ads — Delete advertising ID). iPhones don't provide this option. <€ Manage the info used to show you ads and measure ad performance Reset advertising ID This generates a new advertising ID that apps can use from now on Delete advertising ID Apps can no longer use this advertising ID to show you personalised ads @ These settings help you control what data advertisers can use to show you ads Advertising ID: daa08b66-6b6c-4876-a283-d4e53064c155, Learn more about advertising |D" Quote: "Delete your advertising ID on Android (Settings → Google → All services → Ads → Privacy and security → Ads → Delete advertising ID). iPhones don’t provide this option. "

                  [?]AmnyX Messenger » 🌐
                  @AmnyX@mastodon.social

                  New AmnyX website is live now www.amnyx.com


                  @AmnyX

                    [?]xoron :verified: » 🌐
                    @xoron@infosec.exchange

                    Enkrypted.Chat

                    This is intended to introduce a unique approach in client-side managed secure cryptography. We can avoid registration of any sort.

                    Features:

                    PWA
                    P2P
                    End to end encryption
                    Signal protocol
                    Post-Quantum cryptography
                    Multimedia
                    File transfer
                    Video calls
                    Local-first
                    No registration
                    No installation
                    No database
                    TURN server

                    reddit.com/r/positive_intentio

                    Send Messages Securely. No cloud. No trace.
Decentralized P2P encrypted messaging - No setup required

                    Alt...Send Messages Securely. No cloud. No trace. Decentralized P2P encrypted messaging - No setup required

                      [?]Open for Business » 🌐
                      @ofb@mastodon.faithtree.social

                      Dennis E. Powell writes, "As has been noted here many times, it is not possible to do anything online (and often elsewhere) without being tracked." But there are things we can do 👉🏻 ofb.biz/sa1426

                        [?]Metin Seven » 🌐
                        @metin@graphics.social

                        Meme, showing a continuous circle of data breach messages from corporations…

Ahaha you're not gonna believe this but we had a bit of a data breach.

Your data is probably for sale online now.

That means someone could easily impersonate you.

Going forward we're gonna need more of your data to make sure its you.

                        Alt...Meme, showing a continuous circle of data breach messages from corporations… Ahaha you're not gonna believe this but we had a bit of a data breach. Your data is probably for sale online now. That means someone could easily impersonate you. Going forward we're gonna need more of your data to make sure its you.

                          [?]Profoundly Nerdy » 🌐
                          @profoundlynerdy@bitbang.social

                          I can't seem to delete my ProFlowers account. The option to do so was removed from their UI at some point. Calling in to their helpless desk results in me being told "I can't delete accounts, someone will call you back."

                          I never get a call back. IM chat: same result.

                          Just Delete Me has no pointers for this one.

                          Suggestions?

                            [?]Joanie Foster 😷 » 🌐
                            @clickhere@mastodon.ie

                            If An Garda Síochána can't get a grip on these low-level petit-fash events today, then that will only serve to confirm that Ireland is so utterly fucked for security during the EU Presidency, which starts in - *checks notes* - 20 days.

                            toot.wales/@HarriettMB/1167260

                            (cc @EUCommission)

                              [?]Signal News & Tips » 🌐
                              @aboutsignal@mastodon.social

                              New on AboutSignal ✨

                              Signal Security & Privacy Guide 🔒: A complete guide to Signal’s encryption, metadata protection, and privacy features

                              👉 aboutsignal.com/signal-securit

                                [?]WIRED - The Latest in Technology, Science, Culture and Business [Unofficial] » 🌐
                                @wired.com@web.brid.gy

                                Trump Risks Key Surveillance Authority Over ‘Unqualified’ Spy-Chief Pick

                                US lawmakers are alarmed that Bill Pulte, a housing official with no intelligence experience, is poised to take charge of one of the government's most powerful surveillance tools.

                                Trump Risks Key Surveillance Authority Over ‘Unqualified’ Spy-Chief Pick

                                Alt...Trump Risks Key Surveillance Authority Over ‘Unqualified’ Spy-Chief Pick

                                [?]Kaybee's toots [any] » 🌐
                                @kb01@chaos.social

                                Meta AI embedded into WhatsApp lies to you!
                                About Privacy and about how it works. That's fucked up!!

                                Here is how you try it:
                                - Text to the AI about whatever topic, generate a picture or whatever.
                                - Go to the Profile
                                - Click "Clear Chat" and also "Clear Chat" hidden in the Three Dot Menu top right.
                                - To make sure everything is Gone, go to your chats-List and delete the Chat with Meta-AI

                                Now start a new Conversation with "Hi" and be surprised!!

                                  [?]WIRED - The Latest in Technology, Science, Culture and Business [Unofficial] » 🌐
                                  @wired.com@web.brid.gy

                                  Mapping Every Flock License Plate Reader Near US World Cup Stadiums

                                  Most US World Cup stadiums are surrounded by surveillance cameras. Want to know if you’re being watched on your way to a match? These maps will help you.

                                  Mapping Every Flock License Plate Reader Near US World Cup Stadiums

                                  Alt...Mapping Every Flock License Plate Reader Near US World Cup Stadiums

                                  [?]The Shufflecake Project » 🌐
                                  @shufflecake@fosstodon.org

                                  💥 ❤️ 📣 NEW RELEASE 📣 ❤️ 💥 v0.6.0 is a *major refactor* with a *TON* of news! Full refactor of the codebase, automated installer, packetization-readiness, DKMS, list of opened volumes, bugfixes... There is really *too much to list*, make sure to check the CHANGELOG. *External contributions are now open again!*

                                  codeberg.org/shufflecake/shuff

                                    [?]Freezenet » 🌐
                                    @freezenet@noc.social

                                    Mainstream Media is Already Lying About Age Verification

                                    It took one day for the word to get out about a forthcoming age verification bill and the lies are already being published.

                                    freezenet.ca/mainstream-media-

                                      0 ★ 3 ↺

                                      [?]OCTADE » 🌐
                                      @octade@soc.octade.net

                                      "... If I sold Google some data cables, and months later sent them an email “btw in 5 business days your cables will start sending all the data going through them to me, even though you specifically told me not to enable this feature, unless you re-disable it”, I would go to jail for hacking."
                                      It is [evil hat] hacking, and it is a crime. The government is run by criminals who want Google spying on their behalf, so they allow this surveillance crime spree to continue.


                                        OCTADE boosted

                                        [?]Freezenet » 🌐
                                        @freezenet@noc.social

                                        Utah’s VPN Ban Law Goes Into Effect in Age Verification Escalation

                                        Utah is attempting to cover up the failures of their age verification law by effectively banning VPNs.

                                        freezenet.ca/utahs-vpn-ban-law

                                          [?]Jesus Michał von Gentoo 🏔 (he) » 🌐
                                          @mgorny@social.treehouse.systems

                                          Fun post pointed out by Werner Koch on the GPG "post-quantum defaults" thread:

                                          metzdowd.com/pipermail/cryptog

                                          """
                                          Quantum Cryptography, while intellectually neat, does not present a
                                          practical attack that we need protection against at this time.
                                          Kleptographic Standards on the other hand are very much a practical
                                          attack that we need to protect against at this time.

                                          When a standards body tells you that you should cast aside well-studied
                                          cryptographic algorithms which have earned their trust through dozens of
                                          years of examination, testing, and motivated attackers, for the sake of
                                          protection against Quantum Crypto? The attack you should be protecting
                                          against isn’t Quantum Crypto.
                                          """

                                            OCTADE boosted

                                            [?]🅺🅸🅼 🆂🅲🅷🆄🅻🆉:~$ ▓ » 🌐
                                            @kimschulz@social.data.coop

                                            The Cryptographic Zombie: How Keybase Went from Privacy Darling to Zoom’s Cleanup Crew

                                            Once the ultimate geek flex for cypherpunks, Keybase promised to make PGP cryptography accessible to mere mortals. Today, it hovers in the digital ether as a "zombie" app. Here is the story of how a revolutionary open-sour

                                            schulz.dk/2026/04/06/the-crypt

                                              3 ★ 7 ↺

                                              [?]OCTADE » 🌐
                                              @octade@soc.octade.net

                                              OS Age Verification: Millions Of Evil People With GPS In Your Kid's Pocket, Required By Law!

                                              https://www.youtube.com/watch?v=adCMNAVBGSQ

                                              Age Verification is beyond Epstein 2.0.

                                              "You are basically laying out your children on a silver platter in the name of protecting them."
                                              "Once these OS-level age verification laws take hold, we're about 3 months from a real-time GPS-located database of verified children for creeps, politicians, and rich Ep-style people to use."

                                                1 ★ 8 ↺

                                                [?]OCTADE » 🌐
                                                @octade@soc.octade.net

                                                @cypherpunk@soc.octade.net @cryptography@soc.octade.net @crypto@infosec.pub @cryptography@fed.dyne.org

                                                Al Gore Invented the Internet.
                                                Joe Biden invented PGP encryption.
                                                Cypherpunks write code.

                                                Joe Biden gifted humanity with PGP encryption (in a roundabout way). Phil Zimmermann created PGP in response to a anti-privacy bill clause proposed by Senator Joe Biden.

                                                https://www.americanscientist.org/article/cypherpunks-write-code

                                                "In 1990, the FBI launched an over-the-top crackdown on computer hackers, known as Operation Sundevil. This was swiftly followed, in early 1991, by a proposed piece of U.S. Senate legislation that would force electronic communications service providers to hand over people’s personal data. (The key clause, S.266, was pushed by the then chairman of the U.S. Senate Judiciary Committee, Senator Joe Biden.)"
                                                "On learning of Biden’s S.266 clause, Zimmermann feverishly set out to complete the project, almost losing his house in the process. When he finished his software in 1991, he published it all online, free for anyone who wanted to use it. He called it “Pretty Good Privacy,” or PGP for short, and within weeks it had been downloaded and shared by thousands of people around the world. “Before PGP, there was no way for two ordinary people to communicate over long distances without the risk of interception,” said Zimmermann in a later interview. “Not by phone, not by FedEx, not by fax.” It remains the most widely used form of email encryption to this day."
                                                Joe Biden's first panopticon bill:

                                                https://www.congress.gov/bill/102nd-congress/senate-bill/266

                                                "SEC. 2201. COOPERATION OF TELECOMMUNICATIONS PROVIDERS WITH LAW ENFORCEMENT. It is the sense of Congress that providers of electronic communications services and manufacturers of electronic communications service equipment shall ensure that communications systems permit the government to obtain the plain text contents of voice, data, and other communications when appropriately authorized by law."
                                                As they say in Texas: That dinosaur don't hunt.


                                                  OCTADE boosted

                                                  [?]𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕™ » 🌐
                                                  @kubikpixel@chaos.social

                                                  New AirSnitch attack breaks Wi-Fi encryption in homes, offices, and enterprises

                                                  That guest network you set up for your neighbors may not be as secure as you think.

                                                  🛜 arstechnica.com/security/2026/

                                                    OCTADE boosted

                                                    [?]WIRED - The Latest in Technology, Science, Culture and Business [Unofficial] » 🌐
                                                    @wired.com@web.brid.gy

                                                    How to Organize Safely in the Age of Surveillance

                                                    From threat modeling to encrypted collaboration apps, we’ve collected experts’ tips and tools for safely and effectively building a group—even while being targeted and tracked by the powerful.

                                                    How to Organize Safely in the Age of Surveillance

                                                    Alt...How to Organize Safely in the Age of Surveillance

                                                    OCTADE boosted

                                                    [?]BiyteLüm » 🌐
                                                    @biytelum@mastodon.social

                                                    📌 End-to-end encryption doesn’t protect everything you think it does. It secures content in transit, but not metadata, backups, logins, or account access.

                                                    Whether you’re a user or a business leader, understanding this gap between privacy marketing and technical reality matters.

                                                    👉 Read more: medium.com/@biytelum/end-to-en

                                                    OCTADE boosted

                                                    [?]James House-Lantto (He/Him) [(He/Him)] » 🌐
                                                    @Theeo123@mastodon.social

                                                    eff.org/deeplinks/2026/01/intr

                                                    the EFF is now launching "Encrypt It Already" a push to try and get companies to invest in stronger privacy protections for Data & communications

                                                    You can find out more at the announcement/article above, and the official website here: encryptitalready.org/

                                                      OCTADE boosted

                                                      [?]Autonomie und Solidarität » 🌐
                                                      @autonomysolidarity@todon.eu

                                                      Seven people are put on trial in for:
                                                      - using encrypted apps like Signal
                                                      - participating in digital security training

                                                      “8 December” case: why is encryption on trial?
                                                      "On 3 October, the trial of the so-called “8 December” case began. Seven people are prosecuted for being a “terrorist group”.

                                                      The intelligence services in charge of the judicial investigation (Direction générale de la Sécurité intérieure, DGSI), the National Antiterrorist Prosecution Office (Parquet National Antiterroriste, PNAT), and the investigating judge based their case on the fact that the defendants were using different tools to protect their privacy and encrypt their communications on a daily basis.

                                                      This trial is part of an increased political push by states and law enforcement for surveillance measures and the criminalisation of encryption. That is why the trial is crucial in the battle against the state’s ongoing attempts to criminalise commonplace, secure and healthy digital practices.

                                                      EDRi member in France La Quadrature du Net has continuously defended people’s right to privacy and fought for strong protections of everyone’s digital security. Now, once again, they stand up for the last pillar of our digital ."
                                                      via @edri
                                                      @surveillance@a.gup.pe edri.org/our-work/8-december-c

                                                        [?]Tommaso Gagliardoni » 🌐
                                                        @tomgag@infosec.exchange

                                                        I wish people would stop giving credit to "prominent cybersecurity/cryptography experts" just because they released some "cypherpunk" book or software of unproven impact 30 years ago and have since then retreated into golden tenure, writing technically empty but catchy preprints with provocative titles. These "Ludd grandpas" (you know at least a couple of names of who I'm referring to) are, unfortunately, still worshipped by a large number of semireligious followers, who contribute to the spread of their moldy ignorance.

                                                        Thinking deeper, maybe mine is a typical case of rejection for the image in the mirror: I hope I will never become like that in the future.

                                                        The world does not stop at your rants. Keep moving and stay open-minded, or become obsolete.