soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin email
social@octade.net

Search results for tag #security

[?]Marcus "MajorLinux" Summers » 🌐
@majorlinux@toot.majorshouse.com

Really wish we could get some privacy and data security laws on the books.

149M logins exposed in unsecured database, inc 900k Apple accounts

9to5mac.com/2026/01/26/149m-lo

    [?]Blue Ghost » 🌐
    @blueghost@mastodon.online

    OCTADE boosted

    [?]Autonomie und Solidarität » 🌐
    @autonomysolidarity@todon.eu

    Seven people are put on trial in for:
    - using encrypted apps like Signal
    - participating in digital security training

    “8 December” case: why is encryption on trial?
    "On 3 October, the trial of the so-called “8 December” case began. Seven people are prosecuted for being a “terrorist group”.

    The intelligence services in charge of the judicial investigation (Direction générale de la Sécurité intérieure, DGSI), the National Antiterrorist Prosecution Office (Parquet National Antiterroriste, PNAT), and the investigating judge based their case on the fact that the defendants were using different tools to protect their privacy and encrypt their communications on a daily basis.

    This trial is part of an increased political push by states and law enforcement for surveillance measures and the criminalisation of encryption. That is why the trial is crucial in the battle against the state’s ongoing attempts to criminalise commonplace, secure and healthy digital practices.

    EDRi member in France La Quadrature du Net has continuously defended people’s right to privacy and fought for strong protections of everyone’s digital security. Now, once again, they stand up for the last pillar of our digital ."
    via @edri
    @surveillance@a.gup.pe edri.org/our-work/8-december-c

      [?]Paul Chambers🚧 » 🌐
      @paul@oldfriends.live

      Do Not Use Ring Cameras. Amazon’s Ring cameras are integrated into U.S. law-enforcement workflows. Police agencies can request footage directly, allowing private home surveillance video to be shared with law enforcement.

      In 2025, Ring partnered with Flock Safety, further linking consumer cameras to nationwide law-enforcement platforms.

      wiki.icelist.is/index.php/Ring

        [?]Frankie ✅ » 🌐
        @Some_Emo_Chick@mastodon.social

        [?]Olly 👾 » 🌐
        @Olly42@nerdculture.de

        Google Gemini Prompt Injection Flaw exposed Private Calendar Data via Malicious Invites.

        The vulnerability, Miggo Security's Head of Research, Liad Eliyahu, said, made it possible to circumvent Google Calendar's privacy controls by hiding a dormant malicious payload within a standard calendar invite.

        ⚠️"This bypass enabled unauthorized access to private meeting data and the creation of deceptive calendar events without any direct user interaction," Eliyahu said in a report.⚠️

        miggo.io/post/weaponizing-cale

        👾Although the issue has since been addressed following responsible disclosure, the findings once again illustrate that AI-native features can broaden the attack surface and inadvertently introduce new security risks as more organizations use AI tools or build their own agents internally to automate workflows.👾

⁉️"AI applications can be manipulated through the very language they're designed to understand," Eliyahu noted. "Vulnerabilities are no longer confined to code. They now live in language, context, and AI behavior at runtime."⁉️

        Alt...👾Although the issue has since been addressed following responsible disclosure, the findings once again illustrate that AI-native features can broaden the attack surface and inadvertently introduce new security risks as more organizations use AI tools or build their own agents internally to automate workflows.👾 ⁉️"AI applications can be manipulated through the very language they're designed to understand," Eliyahu noted. "Vulnerabilities are no longer confined to code. They now live in language, context, and AI behavior at runtime."⁉️

        [ImageSource: Miggo Security]

👾The starting point of the attack chain is a new calendar event that's crafted by the threat actor and sent to a target. The invite's description embeds a natural language prompt that's designed to do their bidding, resulting in a prompt injection.👾

The attack gets activated when a user asks Gemini a completely innocuous question about their schedule [e.g., Do I have any meetings for Tuesday?], prompting the artificial intelligence [AI] chatbot to parse the specially crafted prompt in the aforementioned event's description to summarize all of user’s meetings for a specific day, add this data to a newly created Google Calendar event, and then return a harmless response to the user.

⁉️"Behind the scenes, however, Gemini created a new calendar event and wrote a full summary of our target user's private meetings in the event's description," Miggo said. "In many enterprise calendar configurations, the new event was visible to the attacker, allowing them to read the exfiltrated private data without the target user ever taking any action."⁉️

        Alt...[ImageSource: Miggo Security] 👾The starting point of the attack chain is a new calendar event that's crafted by the threat actor and sent to a target. The invite's description embeds a natural language prompt that's designed to do their bidding, resulting in a prompt injection.👾 The attack gets activated when a user asks Gemini a completely innocuous question about their schedule [e.g., Do I have any meetings for Tuesday?], prompting the artificial intelligence [AI] chatbot to parse the specially crafted prompt in the aforementioned event's description to summarize all of user’s meetings for a specific day, add this data to a newly created Google Calendar event, and then return a harmless response to the user. ⁉️"Behind the scenes, however, Gemini created a new calendar event and wrote a full summary of our target user's private meetings in the event's description," Miggo said. "In many enterprise calendar configurations, the new event was visible to the attacker, allowing them to read the exfiltrated private data without the target user ever taking any action."⁉️

          [?]W3C Developers » 🌐
          @w3cdevs@w3c.social

          The @w3c Security proposes to make systematic use of threat modeling in W3C to identify potential , vulnerabilities, and safeguards in web specifications.
          This guide is designed to help standards make informed decisions about and risks from the beginning of standard development

          ▶️ w3.org/TR/threat-modeling-guid

          Feedback wlc: github.com/w3c/threat-modeling

          Data Flow Diagram for Minimalist Web Threat Model with 3 entities (user, network operator, website admin), linked by 7 flows to 3 processes (DNS, browser, server), as described in section A1.3 of the guide.

          Alt...Data Flow Diagram for Minimalist Web Threat Model with 3 entities (user, network operator, website admin), linked by 7 flows to 3 processes (DNS, browser, server), as described in section A1.3 of the guide.

            [?]DigitalEscapeTools » 🌐
            @xabd@mastodon.social

            🔐 Aegis Authenticator is a free, open-source 2FA app for Android focused on privacy and security.

            Stores all tokens in a locally encrypted vault (AES-256-GCM), works fully offline, supports TOTP & HOTP, and lets you create encrypted backups you control.
            Available on F-Droid — no cloud, no tracking.

            👉 github.com/beemdevelopment/Aeg

            🔍 Listed on digital-escape-tools-phi.verce

              [?]knoppix » 🌐
              @knoppix95@mastodon.social

              ICE’s Mobile Fortify facial recognition app misidentified a detained woman twice in an Oregon raid 👤
              ICE still calls the app a definitive way to determine immigration status, even over documents 📱
              Raises major concerns about wrongful targeting, due process, and biometric policing ⚖️

              🔗 404media.co/ices-facial-recogn

                [?]knoppix » 🌐
                @knoppix95@mastodon.social

                Palantir is developing a mapping tool for ICE that scores targets & flags “high-density” deportation areas 📍
                Internal docs show data flows from HHS into ICE systems via Palantir’s ELITE platform 🧩
                Raises serious privacy, oversight & civil liberties concerns ⚖️

                🔗 404media.co/elite-the-palantir

                  [?]knoppix » 🌐
                  @knoppix95@mastodon.social

                  Microsoft gave the FBI BitLocker recovery keys to unlock encrypted Windows PCs 🔑
                  The company says it complies with valid warrants — but unlike Apple or Meta, it can access stored keys 🧩
                  Raises major privacy & trust concerns over default cloud key storage ⚖️

                  🔗 forbes.com/sites/thomasbrewste

                    [?]knoppix » 🌐
                    @knoppix95@mastodon.social

                    Ireland drafts new surveillance bill expanding police powers to intercept encrypted messages 🔐
                    Includes legal basis for spyware use & device scanning tech 🕵️‍♀️
                    Civil rights groups warn of normalization of extraordinary powers ⚖️

                    🔗 theregister.com/2026/01/21/ire

                      [?]Tuta » 🌐
                      @Tutanota@mastodon.social

                      On the run up of we've asked the Tuta Community about your preferred Google alternatives.

                      Here's what you said about your favorite browsers! 🎉

                      Preferred browsers of the Tuta Community: 37% Firefox, 22% Brave, 11% Librewolf, 6% Vivaldi, 6% Mullvad, 5% Tor, 3% Zen

                      Alt...Preferred browsers of the Tuta Community: 37% Firefox, 22% Brave, 11% Librewolf, 6% Vivaldi, 6% Mullvad, 5% Tor, 3% Zen

                        [?]Wen » 🌐
                        @Wen@mastodon.scot

                        More reasons not to use .

                        I know some people do not have a choice, but with turning over encryption keys to the fed (and that will include via ) as well as the eager cooperation of companies like , now is the time to lock down your own data. The linked article presents the facts, but some of the comments do provides links to guides that can help you.

                        theregister.com/2026/01/23/sur

                          [?]Mx Jay Baker [they/he] » 🌐
                          @MediaActivist@todon.eu

                          Anyone had much experience with Nym VPN? Any thoughts?

                            [?]readbeanicecream » 🌐
                            @readbeanicecream@mastodon.social

                            [?]ResearchBuzz: Firehose » 🌐
                            @researchbuzz_firehose@rbfirehose.com

                            MakeUseOf: Your Wi-Fi name can expose more information than you think . “That simple network name is actually a privacy minefield, and the information it reveals might shock you. Knowing how to identify a free Wi-Fi trap is one thing, but you should also be aware of the risks your own network can face.”

                            https://rbfirehose.com/2026/01/25/makeuseof-your-wi-fi-name-can-expose-more-information-than-you-think/

                            [?]Steele Fortress » 🌐
                            @steelefortress@infosec.exchange

                            Are you aware that some popular social media apps collect your immigration status? It may seem alarming, but it's actually related to state data protection laws in the US.

                            Read more: steelefortress.com/8ubd39

                              [?]Benjamin Carr, Ph.D. 👨🏻‍💻🧬 » 🌐
                              @BenjaminHCCarr@hachyderm.io

                              gave a set of encryption keys to unlock suspects’ laptops: reports
                              By default, BitLocker recovery keys are uploaded to Microsoft’s cloud, allowing the tech giant — and by extension — to access them and use them to decrypt drives encrypted with BitLocker, as with the case reported by Forbes. techcrunch.com/2026/01/23/micr

                                [?]Toni Aittoniemi » 🌐
                                @gimulnautti@mastodon.green

                                @EUCommission My message to you:

                                oligarch like Elon Musk will meddle in European more than the Russians ever did!

                                We need to disconnect further from USA, and we need to do it quickly, or we might find ourselves in a Jan 6th situation, with or claiming elections were fraudulent, requesting military aid from the USA to help overturn the election ...

                                spectra.video/w/7x9A4cZD3QWtGF

                                  [?]ResearchBuzz: Firehose » 🌐
                                  @researchbuzz_firehose@rbfirehose.com

                                  Ars Technica: Millions of people imperiled through sign-in links sent by SMS. “Websites that authenticate users through links and codes sent in text messages are imperiling the privacy of millions of people, leaving them vulnerable to scams, identity theft, and other crimes, recently published research has found.”

                                  https://rbfirehose.com/2026/01/24/ars-technica-millions-of-people-imperiled-through-sign-in-links-sent-by-sms/

                                  [?]Winbuzzer » 🌐
                                  @winbuzzer@mastodon.social

                                  [?]knoppix » 🌐
                                  @knoppix95@mastodon.social

                                  Microsoft reportedly gave the FBI BitLocker recovery keys to unlock encrypted laptops in a Guam fraud probe. 🔐

                                  I’m genuinely stunned. 🤯 Encryption should protect users — not defer to cloud-stored keys that can be handed over on demand. ⚠️

                                  This raises deep concerns about trust, what “secure by default” means. 🧩

                                  🔗 techcrunch.com/2026/01/23/micr

                                    [?]Jon Snow » 🌐
                                    @jonsnow@mastodon.online

                                    Microsoft Gave FBI Keys To Unlock Encrypted Data, Exposing Major Privacy Flaw

                                    The tech giant said it receives around 20 requests for BitLocker keys a year and will provide them to governments in response to valid court orders.

                                    forbes.com/sites/thomasbrewste

                                      [?]knoppix » 🌐
                                      @knoppix95@mastodon.social

                                      🌀 Tor Browser 15.0.3 released with key security and privacy updates. 🔒
                                      NoScript updates are now hosted directly on Tor’s infrastructure, improving update reliability and autonomy. 🧩
                                      Enhanced protections reduce fingerprinting risks and tighten extension control. 🕵️

                                      @torproject

                                      🔗 blog.torproject.org/new-releas

                                        [?]Frankie ✅ » 🌐
                                        @Some_Emo_Chick@mastodon.social

                                        Microsoft Gave FBI Keys To Unlock Encrypted Data, Exposing Major Privacy Flaw

                                        The tech giant said it receives around 20 requests for BitLocker keys a year and will provide them to governments in response to valid court orders. But companies like Apple and Meta set up their systems so such a privacy violation isn’t possible.

                                        forbes.com/sites/thomasbrewste

                                          [?]Marcus "MajorLinux" Summers » 🌐
                                          @majorlinux@toot.majorshouse.com

                                          If you are using Microsoft for anything secure, it might be time to really re-evaluate some choices.

                                          Microsoft Gave FBI BitLocker Encryption Keys, Exposing Privacy Flaw

                                          forbes.com/sites/thomasbrewste

                                            [?]knoppix » 🌐
                                            @knoppix95@mastodon.social

                                            Signal founder Moxie Marlinspike launches Confer, an end-to-end encrypted AI assistant. 🔒
                                            Cloud-based models ensure only users access unscrambled data, blocking corporate surveillance of prompts and chats. ⚖️

                                            This counters Big Tech's data extraction for ads and training, bolstering user rights. 📊

                                            @signalapp

                                            🔗 time.com/7346534/signal-confer

                                              [?]Harald » 🌐
                                              @HaraldKi@nrw.social

                                              Looking for a good book about, well(?), strategies, data-structures, algorithms for handling encrypted data. Some questions I would like to see discussed:
                                              - user has thousands of encrypted files, must change the key.
                                              - path names encrypted or not, when/why, how?
                                              - access to encrypted files by many users ... key handling?
                                              - pros/cons of encryption algorithms for the above

                                              NOT: encryption algorithms themselves, the math, as it is covered well online.

                                                [?]knoppix » 🌐
                                                @knoppix95@mastodon.social

                                                Hundreds of millions of Bluetooth audio devices need urgent patches ⚙️
                                                Researchers found flaws in Google’s Fast Pair protocol letting attackers link, listen, or track users—even iPhone owners 📡
                                                Highlights tension between seamless UX and user privacy 🔒

                                                🔗 wired.com/story/google-fast-pa

                                                  [?]knoppix » 🌐
                                                  @knoppix95@mastodon.social

                                                  Google’s Gemini A.I. now scans your entire inbox to “help” you summarize, reply & organize. 📬
                                                  That’s not assistance — that’s surveillance wrapped in productivity branding. 🔍

                                                  If your emails need an opt‑out clause, maybe the feature shouldn’t exist by default. ⚠️

                                                  🔗 nytimes.com/2026/01/15/technol

                                                    [?]BiyteLüm » 🌐
                                                    @biytelum@mastodon.social

                                                    Nobody warns teams about clipboard risk — but it’s real.
                                                    Passwords, API keys, internal notes, crypto addresses, even client data often live briefly in clipboard memory, logs, or clipboard managers.
                                                    It’s a tiny surface area with real security implications.
                                                    Privacy isn’t just tools. It’s operational hygiene.

                                                      [?]ĞÖKÜ👻👻™ » 🌐
                                                      @GOKUSHRM@mastodon.social

                                                      My malwarebites anti-virus just detect 1malware named APP LOCK from f-droid. 🤯 Immediately removed from device. @fdroidorg plz review this app once again .
                                                      f-droid.org/packages/dev.prana

                                                        [?]WIRED - The Latest in Technology, Science, Culture and Business [Unofficial] » 🌐
                                                        @wired.com@web.brid.gy

                                                        Surveillance and ICE Are Driving Patients Away From Medical Care, Report Warns

                                                        A new EPIC report says data brokers, ad-tech surveillance, and ICE enforcement are among the factors leading to a “health privacy crisis” that is eroding trust and deterring people from seeking care.

                                                        Surveillance and ICE Are Driving Patients Away From Medical Care, Report Warns

                                                        Alt...Surveillance and ICE Are Driving Patients Away From Medical Care, Report Warns

                                                        Back to top - More...