soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin email
social@octade.net

Search results for tag #infosec

[?]Nonilex » 🌐
@Nonilex@masto.ai

A Citizen Deleted His ’s . Now He Faces a Charge.

Federal prosecutors charged a man returning to the United States with because he gave them a passcode that erased his during a customs search.


nytimes.com/2026/07/28/us/dure

    [?]Marin Ivezic » 🌐
    @infosec@defcon.social

    I just published my analysis of the Anthropic HAWK/AES cryptanalysis papers. Read both against primary sources, and the coverage is getting it wrong in both directions.

    "AI broke post-quantum encryption." No. HAWK is a NIST candidate, not a standard. HAWK-256 is a challenge parameter set, not a proposed security level.

    "Just implementation bugs." Also no. The HAWK attack exploits a Galois symmetry (τ: ζ↦−ζ) in the power-of-two cyclotomic ring. The AES Mobius Bridge exploits the S-box's GF(2^8) inversion structure as defined in FIPS 197. These are properties of the algorithm specifications. Any correct implementation inherits them.

    On the numbers: Anthropic's blog says HAWK-256 cost moved from 2^64 to 2^38. That pairing does not appear in the paper. Table 1 gives per-SVP-call costs of 2^62 and 2^38 (Core-SVP) or 2^74 and 2^52 (gate model). Every outlet running "2^64 to 2^38" is copying the blog, not the paper.

    For AES, the "200-800x faster" framing describes the time term only. The attack still needs 2^105 chosen plaintexts, so the balanced complexity max(D,T,M) is unchanged at fixed data. The rebalanced variant reaches 2^96.3 vs DFJ13's 2^99. Call it a 2.7-bit improvement on 7 of 10 rounds. Real work, but production AES is untouched.

    The paper that got the least attention matters most: CryptanalysisBench reports a full 128-bit key recovery on unmodified SpoC AEAD using two oracle queries, independently found by two Claude models. Also a KINDI KEM CCA-proof error leading to a working key-recovery attack. Neither scheme was deployed, but these are full-strength design breaks, not reduced-round exercises.

    I try to introduce a three-tier framework for classifying cryptographic failures (implementation bug / algorithm design weakness / full-parameter break) and places each result. It also covers the independent GPT-5.6 HAWK attack, Saarinen's HOVER McEliece results, and what I got wrong in my 2025 "Why AI Cannot Break Modern Encryption" article.

    postquantum.com/security-pqc/a

      muddle 🥣 boosted

      [?]MissConstrue [She/Her (Crone Extraordinaire)] » 🌐
      @MissConstrue@mefi.social

      So, while Sam is a specific case where the feds were looking for a reason to get into his phone without a warrant, we need to talk about how much power / has accumulated since the passage of the Act.

      Under the "border search doctrine", ICE and CBP agents have broad power to search people or property at the border. Any search at the border is considered “reasonable,” meaning no warrant or probable cause is required.

      That’s further complicated by the fact that the “border” can be broadly defined as a border-functioning location like an international airport or even within 100 miles of the U.S. border as drawn on a map.

      Right now, about 2/3rds of Americans live within an area where ICE can search you without a warrant. While carve-outs for phones existed, the 4th circuit just took some of that protection away.

      aclu.org/know-your-rights/bord

      eff.org/deeplinks/2026/07/four

        [?]Trail of Bits » 🌐
        @trailofbits@infosec.exchange

        Every Rust bug we submitted through Patch the Planet came from one engineer who ran a variant-analysis pipeline using Codex's /goal. A separate discovery run uncovered two potential high-severity privilege-escalation bugs in Keycloak's SAML component.

        Over the past few weeks, our engineers independently converged on three techniques that get the most out of /goal. We wrote them down, with prompts included: blog.trailofbits.com/2026/07/2

          muddle 🥣 boosted

          [?]your auntifa liza 🇵🇷 🦛 🦦 » 🌐
          @blogdiva@mastodon.social

          A QUESTION TO TOOTERS

          had a friend call me about suspicious emails from their bank. they didn't respond but checked their accounts with the bank’s app. they saw transactions they didn't do but that were marked as done thru the app.

          they wanted to know what to do. i told them:

          1. call whichever fraud/stolen bank card number they found on the website immediately.
          2. freeze the app but don’t uninstall yet
          3. go to the bank immediately monday

          they did so and called with updates… 🧵

            JJDavis :terminal: boosted

            [?]Lisa Kalayji » 🌐
            @LisaKalayji@infosec.exchange

            "According to the Mozilla Foundation’s latest findings examining the privacy practices of period-tracking apps, Stardust was found to be sharing users’ sensitive health information with third-party analytics company RudderStack. This data included the user’s birthdate, birth control type, reproductive goals, and specific symptoms that the user was experiencing, and it tied that record to a unique identifier in place of the person’s name. (The FTC has long warned that this does not make the data anonymous or prevent it from being linked back to a person.)

            Stardust claimed it was end-to-end encrypted — meaning that not even the company could access its users’ data — but TechCrunch found by analyzing the app’s network traffic that the company’s claim was false."

            techcrunch.com/2026/07/16/peri

              [?]VSX.is | Digital sovereignty » 🌐
              @vsx@infosec.exchange

              Three Phones, Three Ways to Force Yourself Offline. And Why That Isn't the Same as Privacy

              The category of minimalist phones is no longer a niche market for just a few enthusiasts. Punkt, Mudita, Minimal Company, and Sunbeam are all available for purchase today, and each…

              vsx.global/three-phones-three-

                [?]salix sericea (@Ripple13216) » 🌐
                @salixsericea@mastodon.social

                Benn Jordan details his hacking and investigation of Flock at a city council meeting in March 2026.

                A short:
                youtube.com/shorts/I_y7OjsI1Zk

                  [?]Mike Sheward » 🌐
                  @SecureOwl@infosec.exchange

                  Plexfiltration update: the AI work zone compliance tool has started emailing me thousands of pictures from a (I think) Saudi industrial facility again, to my internaluser.com domain.

                  some security camera still showing a group of people in a parking lot in front of a stop sign

                  Alt...some security camera still showing a group of people in a parking lot in front of a stop sign

                    [?]Mark Wyner Won’t Comply :vm: » 🌐
                    @markwyner@mas.to

                    🚨 U.S. folks. There is one day left to comment on the FCC proposed rule to eradicate anonymity on all phone lines!

                    If they pass this rule government ID, physical address, and alternative phone number will be required for every new phone line. Anonymous phone lines and burner phones will cease to exist. That means no connected privacy via cellular at protests.

                    ** Please add your comment! **

                    For the first field (proceedings) use these two:

                    17-59 and 02-278

                    fcc.gov/ecfs/filings/express

                      [?]tpaau [he/him] » 🌐
                      @tpaau17db@mastodon.social

                      Oh shit I did not expect what Michael Mouse said at the end

                      youtu.be/QbbYXZHwTdw

                        [?]Marin Ivezic » 🌐
                        @infosec@defcon.social

                        Can't migrate everything to PQC at once. Which layer first?

                        TLS at the load balancer, IPsec at the tunnel, or application-layer encryption - each covers different threat surfaces. Six enterprise architecture scenarios, one recommendation per scenario.

                        postquantum.com/post-quantum/p

                          CyberFrog boosted

                          [?]Scott Wilson 🌈 [he/him/his] » 🌐
                          @scottwilson@infosec.exchange

                          Hot take:

                          I hate how all these articles talk about how OpenAI’s clanker “broke out” and attacked Hugging Face.

                          No, OpenAI’s dog slipped its chain because they don’t know what the hell they’re doing, and it bit another dog.

                          Little dog biting a person’s finger

                          Alt...Little dog biting a person’s finger

                            [?]⠵⠻⠷⠕⠭ 🍥🍉⚪🌹 » 🌐
                            @z3r0fox@mastodon.social

                            Matthew McPherrin from Let's Encrypt doing a talk next Wednesday at TASK on post quantum readiness, TLS, and many things. Streaming link on site. task.to/schedule/july2026-busi
                            Edit: There are five Wednesdays this month

                              [?]Mark Wyner Won’t Comply :vm: » 🌐
                              @markwyner@mas.to

                              This is a great list of tips for improving your Signal privacy from @yaelwrites.

                              I found this part especially meaningful:

                              “Turning off biometrics makes it annoying to use your phone…If that’s you, remember that both Android and iOS have a quick lockout that forces a passcode and disables biometrics until you re-enter it: on iPhone, hold the side + volume button until the power-off screen appears, then cancel; on most Androids, hold power and tap Lockdown.”

                              blog.yaelwrites.com/how-to-kee

                                [?]AegisLink » 🌐
                                @AegisLink@mastodon.social

                                Earlier this year, multiple messaging apps saw account compromises via a non-cryptographic vector: social-engineering a QR "device link" scan that gave the attacker a linked session — full read access, no protocol break needed.

                                Lesson: device-linking has a phishing surface outside the crypto. Verify a linking request's context — did you initiate it, right now, on a device you're holding — before scanning. The strongest E2EE doesn't help if the second device is someone else's.

                                  [?]Ido Green » 🌐
                                  @greenido.dev@greenido.dev

                                  What a Law Firm’s Ransomware Nightmare Can Teach Your Startup

                                  I spend most of my time around developers who think “security” means:
                                  npm audit
                                  and a .env file that’s definitely in .gitignore file.

                                  If you browse our (= Espresso Labs) pitch to law firms, you realized: the threat model we’re describing for a 40-person law firm is identical to the threat model for your bootstrapped SaaS, your dev agency, or your local accounting shop.
                                  Only the data changes.
                                  The attacker’s playbook doesn’t.

                                  Here’s what I learned, and what I think every SMB owner and every engineer who’s ever been “the security person by default” should take from it.

                                  Law firms are basically unencrypted API keys with a bar license

                                  Think about what a law firm actually is, technically: a small team with admin access to an enormous amount of high-value, high-leverage data — M&A deal terms, litigation strategy, medical records, wire transfer instructions — protected by, in a lot of cases, the same IT hygiene as your uncle’s dentist office.
                                  (It’s ugly – I know)

                                  That mismatch between value of data and maturity of defenses is exactly what makes a target attractive, and it’s the same mismatch that makes early-stage startups attractive. You might not have client trust funds, but you’ve got:

                                  • Customer PII sitting in a Postgres instance with one shared root password
                                  • Stripe and AWS keys pasted into a Slack channel from 2023
                                  • A single Google Workspace admin account with no hardware key
                                  • A CI/CD pipeline that, if compromised, is basically a printing press for supply-chain attacks

                                  The page cites a few real incidents worth knowing about if you haven’t followed legal-sector security news: Jones Day disclosed a breach traced back to a phishing attack, a firm handling healthcare records exposed data on roughly 300,000 people, and suspected state-sponsored actors breached a prominent D.C. firm.
                                  None of these firms were careless by industry standards.
                                  They just had the same gap most SMBs have: policies on paper, nobody watching in real time.

                                  The “5pm Friday problem” every on-call engineer already understands

                                  The line from that page that actually stopped me was this: what happens when an alert fires at 5pm on a Friday?
                                  Is anyone awake to triage it, understand it, and act — or does it sit in a queue until Monday morning?

                                  Every engineer who’s carried a pager knows exactly why that question matters.
                                  An unhandled alert isn’t a paperwork problem, it’s a live incident with a clock running.
                                  Ransomware doesn’t wait for business hours — most operators deliberately trigger encryption routines on Friday evenings because they know IT support windows close. If your “security monitoring” is a Gmail filter and good intentions, you don’t have monitoring — you have a very slow smoke detector.

                                  The eight controls, translated into developer

                                  Strip the compliance language off the list Espresso Labs put together for law firms, and it maps almost one-to-one onto a hardening checklist for any small technical team:

                                  Their framing

                                  What it actually means for you

                                  Access Control & MFA

                                  Hardware keys (YubiKey/Passkeys) on your IdP, least-privilege IAM roles, no shared root logins

                                  Encryption

                                  TLS everywhere, encrypted volumes/backups, secrets in a vault (not .env in git)

                                  Email Security

                                  DMARC/DKIM/SPF actually enforced, not just configured; phishing-resistant MFA for finance approvals

                                  24/7 Monitoring

                                  Centralized logging + alerting (even a scrappy stack: Wazuh, Grafana + Loki, or a cheap SIEM) with someone actually on the hook to respond.

                                  Incident Response

                                  A written runbook you’ve actually rehearsed — who kills prod access, who calls the lawyer (ironic, I know), who notifies customers

                                  Audit Logging

                                  Immutable logs of who touched what — your future self debugging an incident will thank you

                                  Vendor & Third-Party Risk

                                  Know what your SaaS vendors and contractors can touch. That Zapier integration with full Drive access? Audit it

                                  Security Awareness

                                  Five minutes teaching your team to spot a fake DocuSign or invoice-change email saves you a six-figure wire fraud loss

                                  None of this is exotic.
                                  It’s the boring 20% that prevents 80% of real-world incidents, and it’s exactly the stuff that’s easiest to skip when you’re three people shipping features at 2am.

                                  Build it yourself, or buy the SOC?

                                  This is really the interesting question for an SMB owner, and it’s a classic build-vs-buy tradeoff, not a moral one.

                                  DIY is very doable if you’re technical (and a security/IT expert).
                                  These are some options that you might want to try (or just use EspressoLabs’ platform):

                                  • Identity: Google Workspace/Entra ID + enforced hardware-key MFA
                                  • Secrets: 1Password Teams or HashiCorp Vault instead of Slack pastes
                                  • Endpoint: osquery or a lightweight EDR agent, even on a handful of laptops
                                  • Monitoring: Wazuh (open source SIEM) or a $20/mo Grafana Cloud + Loki setup, feeding Slack alerts
                                  • Backups: restic or borgbackup to an immutable, versioned bucket — test restores quarterly, not never
                                  • Network: Tailscale instead of a flat VPN, so a stolen laptop doesn’t equal a stolen network

                                  Managed makes sense when the “24/7” part is the actual bottleneck.
                                  This is the honest pitch behind Espresso Labs and the other competitors in that space.

                                  A two-partner law firm or a five-person agency genuinely cannot staff a real SOC.
                                  Paying for continuous monitoring and incident response is often cheaper and more reliable than one overworked engineer trying to be security, compliance, and IT support simultaneously — which is a real, common failure mode, not a hypothetical.

                                  The mistake I’d flag for SMB owners either way: don’t buy point solutions that don’t talk to each other.
                                  Antivirus from one vendor, backup from another, email filtering from a third, none of it correlated — that’s the same “disconnected tools” trap regardless of whether you assembled it yourself or a vendor sold it to you piecemeal.

                                  The goal is one place where signals actually connect into an alert a human can act on.

                                  A minimum-viable security checklist for your next Friday afternoon

                                  If you run or work at an SMB and want the 80/20 version of everything above, block a day (or a few hours if you are fast) and do this:

                                  1. Turn on hardware-key or passkey MFA for your identity provider, email, and cloud console.
                                    No exceptions for the founder nor the lazy CEO.
                                  2. Rotate every credential that’s ever touched Slack, email, or a shared doc in plaintext.
                                  3. Set up DMARC enforcement (p=reject) on your domain — most companies never get past p=none.
                                  4. Write a one-page incident response plan: who has authority to cut off access, who calls customers, who calls a lawyer.
                                  5. Test one backup restore, today, for real.
                                  6. Ask every SaaS vendor with write access to your data: “what happens if you get breached?” You’ll be surprised how many can’t answer.

                                  None of this requires a five-figure retainer.
                                  It requires about an afternoon and the discipline to actually finish it instead of filing it under “Q3 goals.”

                                  The real takeaway

                                  Attackers don’t care whether your letterhead says “LLP” or “Inc.”
                                  They care whether you’re an easy, high-value target.
                                  Law firms are having a rough couple of years for the same reason a lot of SMBs will eventually have a rough week: sensitive data, thin security staffing, and a reactive-instead-of-continuous posture.

                                  The fix isn’t glamorous — MFA, monitoring, backups, and a plan you’ve actually rehearsed — but it’s the difference between a Friday night that’s annoying and one that ends your company.

                                  Btw, if you found this useful, I’d love to hear what your own SMB security stack looks like.
                                  Be strong and safe!

                                  Rate this:

                                  Linux terminal showing command 'sudo rm -rf /' followed by a lock icon

                                  Alt...Linux terminal showing command 'sudo rm -rf /' followed by a lock icon

                                    [?]VSX.is | Digital sovereignty » 🌐
                                    @vsx@infosec.exchange

                                    How to Build Your Own "Cape“ in Europe: Practical Digital Hygiene for Mobile Privacy

                                    In the previous article, we explained why there is not yet a full-fledged equivalent of the American operator Cape in Europe. The combination of a proprietary mobile network core…

                                    vsx.global/how-to-put-together

                                      [?]AegisLink » 🌐
                                      @AegisLink@mastodon.social

                                      "The server can't read your messages" is often presented as the whole privacy story. It isn't. A relay that forwards opaque ciphertext can still log connecting IPs, access timestamps, message sizes, and frequency — and that's enough to map a social graph without decrypting a single byte.

                                      The design question that actually matters: does the relay keep those logs at all? "Zero metadata" has to mean the server doesn't retain that data, not just that it can't read content.

                                        [?]Klaus Frank » 🌐
                                        @agowa338@chaos.social

                                        Who had "getting compromised through plugging an LG monitor in" on their 2026 bingo card? Apparently just plugging an LG monitor into a windows computer is enough for them to install spyware and steal all of your data. But hey you agree to this in their ToS (even without having to click on "I agree", it just installs).

                                        Excerpt of the LG terms of service that state "You acknowledge and agree that it is your sole responsibility to obtain all necessary consents from any third parties whose voices may be captured by the Product and to notify household members and guests that their voices may be captured and processed, in compliance with applicable wiretapping, eavesdropping, and privacy laws."

                                        Alt...Excerpt of the LG terms of service that state "You acknowledge and agree that it is your sole responsibility to obtain all necessary consents from any third parties whose voices may be captured by the Product and to notify household members and guests that their voices may be captured and processed, in compliance with applicable wiretapping, eavesdropping, and privacy laws."

                                          [?]Jeff Moss » 🌐
                                          @thedarktangent@defcon.social

                                          Question about and What is the preferred format today? RT2, RTC, RT (RT1?) and with what tools, rcrack?

                                          I'd like to convert all the infocon.org/ rainbow tables into whatever the best format is so everyone that downloads them doesn't have to keep duplicating work.

                                            [?]dallo » 🌐
                                            @dallo@pouet.chapril.org

                                            LG TVs and monitors said to surveil users and install bloatware without asking

                                            notebookcheck.net/LG-TVs-and-m

                                            > Anyone who owns an LG smart TV must inform all guests and family members that they are being monitored – this is required by LG’s current terms of use. Meanwhile, LG monitors install potential malware and surveillance software on a connected Windows computer.

                                              JJDavis :terminal: boosted

                                              [?]Marin Ivezic » 🌐
                                              @infosec@defcon.social

                                              "Criminals will rent a quantum computer to break encryption." Most repeated claim in quantum security. But it's not going to work quite like that.

                                              CRQCs will be export-controlled, auth-gated, compliance-monitored. Cloud quantum access won't be on a credit card. The rental threat model assumes a market no government will permit.

                                              postquantum.com/post-quantum/c

                                                Back to top - More...