sfba.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Mastodon instance for the San Francisco Bay Area. Come on in and join us!

Server stats:

2.3K
active users

#securitytheater

3 posts2 participants0 posts today
Nick Espinosa<p>WhatsApp's new Advanced Chat Privacy is pointless</p><p><a href="https://mastodon.social/tags/News" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>News</span></a> <a href="https://mastodon.social/tags/TechNews" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TechNews</span></a> <a href="https://mastodon.social/tags/Technology" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Technology</span></a> <a href="https://mastodon.social/tags/WhatsApp" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WhatsApp</span></a> <a href="https://mastodon.social/tags/Meta" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Meta</span></a> <a href="https://mastodon.social/tags/Facebook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Facebook</span></a> <a href="https://mastodon.social/tags/SecurityTheater" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SecurityTheater</span></a></p><p><a href="https://youtu.be/QGaUvCVUdPs" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">youtu.be/QGaUvCVUdPs</span><span class="invisible"></span></a></p>
Nick Espinosa<p>Daily Podcast: WhatsApp's new Advanced Chat Privacy is pointless</p><p><a href="https://mastodon.social/tags/News" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>News</span></a> <a href="https://mastodon.social/tags/TechNews" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TechNews</span></a> <a href="https://mastodon.social/tags/Technology" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Technology</span></a> <a href="https://mastodon.social/tags/WhatsApp" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WhatsApp</span></a> <a href="https://mastodon.social/tags/Meta" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Meta</span></a> <a href="https://mastodon.social/tags/Facebook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Facebook</span></a> <a href="https://mastodon.social/tags/SecurityTheater" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SecurityTheater</span></a> <a href="https://mastodon.social/tags/podcast" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>podcast</span></a></p><p><a href="https://soundcloud.com/nickaesp/wcp" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">soundcloud.com/nickaesp/wcp</span><span class="invisible"></span></a></p>
Wolfgang Stief<p>»Your password must contain: At least 12 characters.« Und genau das ist jetzt mein Passwort, wenn euch meine 10 alphanumerischen, nicht lexikalisch angeordneten Zeichen nebst Sonderzeichen nicht reichen. Zefix. <a href="https://mastodon.social/tags/uxfromhell" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>uxfromhell</span></a> <a href="https://mastodon.social/tags/pseudosecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>pseudosecurity</span></a> <a href="https://mastodon.social/tags/securitytheater" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>securitytheater</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://climatejustice.social/@KarlHeinzHasliP" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>KarlHeinzHasliP</span></a></span> <span class="h-card" translate="no"><a href="https://mastodontech.de/@denki" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>denki</span></a></span> OFC I do wish for a real <em>"<a href="https://infosec.space/tags/TransEuropeanExpress" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TransEuropeanExpress</span></a>"</em> that gets people from <a href="https://infosec.space/tags/Lisbon" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Lisbon</span></a> to <a href="https://infosec.space/tags/Helsinki" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Helsinki</span></a> and from <a href="https://infosec.space/tags/Oslo" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Oslo</span></a> to <a href="https://infosec.space/tags/Athens" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Athens</span></a> faster than flying (if we account for the <a href="https://infosec.space/tags/SecurityTheater" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SecurityTheater</span></a> at <a href="https://infosec.space/tags/Aorports" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Aorports</span></a>)…</p>
🆘Bill Cole 🇺🇦<p>Yes, this is about MailMate being EXTORTED by Google but it's also about every other 3rd-party MUA and every major mailbox provider, because they have imposed a web-centric authentication and authorization system on the world which moronically relies on annual security audits of MUAs to certify them for use with the fragile snowflakes which behemoth mail systems apparently are... </p><p><a href="https://toad.social/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> <a href="https://toad.social/tags/SecurityTheater" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SecurityTheater</span></a></p>
🆘Bill Cole 🇺🇦<p>Fuck <a href="https://toad.social/tags/Google" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Google</span></a> and the garbage imitation of IMAP that they foist on users &amp; fuck their <a href="https://toad.social/tags/SecurityTheater" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SecurityTheater</span></a> of demanding CASA audits of every IMAP client before they allow it to do OAuth2. </p><p>If you use <a href="https://toad.social/tags/GMail" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GMail</span></a> (or Google Workspace) you are actively supporting the enclosure of <a href="https://toad.social/tags/email" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>email</span></a>. Google does not want independent standards-compliant MUAs to touch their mail system. Google wants all of its users using their shit web interface or their shoddy apps. They want to own your email. </p><p><a href="https://toad.social/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> <a href="https://toad.social/tags/Rant" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Rant</span></a></p>
🆘Bill Cole 🇺🇦<p>The iOS *app* works fine (using FaceID even) but the browser workflow has a "use phone" link and QR code, which sends the phone to a web page that wants to take a pic, but since the idiots at Jumio don't ASK for Camera access, iOS offers no means for me to give it to them. </p><p>It's stupid broken tools like this that make me wish I could bullshit well. Some slimeball sold this "service" to my CU, costing me money as a shareholder &amp; it's junk. </p><p><a href="https://toad.social/tags/Jumio" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Jumio</span></a> <a href="https://toad.social/tags/MichiganFirstCU" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>MichiganFirstCU</span></a> <a href="https://toad.social/tags/SecurityTheater" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SecurityTheater</span></a> <a href="https://toad.social/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a></p>
🆘Bill Cole 🇺🇦<p>Yes, the problem in Safari persists with Lockdown disabled for the site. I gather it's just lazy insecure garbage code. <br><a href="https://toad.social/tags/Jumio" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Jumio</span></a> <a href="https://toad.social/tags/SecurityTheater" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SecurityTheater</span></a> <a href="https://toad.social/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a></p>
🆘Bill Cole 🇺🇦<p>It has finally happened, my CU has decided that in addition to a password &amp; a security question for every login, they need to use some scam outfit called <a href="https://toad.social/tags/Jumio" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Jumio</span></a> to get "enhanced identity verification" which seems to be nothing more than a 3rd-party cookie. </p><p>Totally broken for macOS &amp; iOS in "lockdown mode." I can't even get Safari to accept the "Start verification" link as a link. Phone-based flow wants to take a selfie, but it doesn't ASK for camera access, so no.<br><a href="https://toad.social/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> <a href="https://toad.social/tags/SecurityTheater" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SecurityTheater</span></a></p>
Schneier on Security RSS<p>Rational Astrologies and Security</p><p>John Kelsey and I wrote a short paper for the Rossfest Festschrift: “Rational Astrolo... <a href="https://www.schneier.com/blog/archives/2025/04/rational-astrologies-and-security.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">schneier.com/blog/archives/202</span><span class="invisible">5/04/rational-astrologies-and-security.html</span></a></p><p> <a href="https://burn.capital/tags/psychologyofsecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>psychologyofsecurity</span></a> <a href="https://burn.capital/tags/securitytheater" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>securitytheater</span></a> <a href="https://burn.capital/tags/Uncategorized" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Uncategorized</span></a> <a href="https://burn.capital/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a></p>
koehntopp ~ :<p>Dieser Quatsch geht mir sooooo auf den Keks...<br><a href="https://infosec.exchange/tags/SecurityTheater" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SecurityTheater</span></a></p>
BeyondMachines :verified:<p>My dear cybersecurity auditors: We are following the best practices of TSA!</p><p><a href="https://infosec.exchange/tags/SecurityTheater" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SecurityTheater</span></a></p>
Daryl 🇺🇦 ✔️ :Verified:<p>After doing all that, when I got to the tax form I needed, I had to go through yet another text message code verification hoop to actually see the statement.</p><p><a href="https://vmst.io/tags/SecurityTheater" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SecurityTheater</span></a></p>
My camera shoots fascists<p>Everyone should become familiar with the term &quot;border-industrial complex.&quot; This article, dealing with wasting vast sums of money on ineffectual technology, is one small part of it.</p><p>The first time I heard the term? I was chatting with a Border Patrol agent who used it. The agency tightly controls PR, but off the record, in private conversations, most of the agents will be quite open about what a boondoggle the whole thing is.</p><p><a href="https://sfba.social/tags/Border" class="mention hashtag" rel="tag">#<span>Border</span></a> <a href="https://sfba.social/tags/Immigration" class="mention hashtag" rel="tag">#<span>Immigration</span></a> <a href="https://sfba.social/tags/SecurityTheater" class="mention hashtag" rel="tag">#<span>SecurityTheater</span></a></p><p><a href="https://www.eff.org/deeplinks/2024/10/us-border-surveillance-towers-have-always-been-broken" target="_blank" rel="nofollow noopener noreferrer" translate="no"><span class="invisible">https://www.</span><span class="ellipsis">eff.org/deeplinks/2024/10/us-b</span><span class="invisible">order-surveillance-towers-have-always-been-broken</span></a></p>