sfba.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Mastodon instance for the San Francisco Bay Area. Come on in and join us!

Server stats:

2.4K
active users

#hacker

37 posts33 participants1 post today

Il 19enne membro della cyber-gang d’élite Scattered Spider rischia 60 anni di reclusione

📌 Link all'articolo : redhotcyber.com/post/il-19enne

Un membro del gruppo #hacker di Scattered Spider, è stato accusato di furto di criptovaluta su larga scala e #operazioni di hacking dei #sistemi aziendali. Noah Michael Urban è stato arrestato all’inizio del 2024 , patteggiando le accuse in Florida, dove è stato accusato di #frode e furto di #identità.

il blog della sicurezza informatica · Il 19enne membro della cyber-gang d'élite Scattered Spider rischia 60 anni di reclusioneNoè Michael Urban, membro di Scattered Spider, patteggia per furto e hacking. Rischia 60 anni e perde milioni di cripto. E la corona di King Bob.

So what is the most Discord- or Slack-like thing that one can self-host for a Hacker Club?

edit: an idea of requirements...

I guess I need it to have an easy web page front end so rank beginners will know how to use it; I'll give up as much fancy functionality as I need to for that.

Also needs to be self-hosted with no surveillance or shitty commercial license or capitalist issues. Again, I will give up as much fancy functionality as I have to.

From there, I'd like to have as much Nice Stuff as possible, groups, spaces for admin, different topics, etc.

Thinking Matrix via a web frontend? Not sure about the licensing/beholdenness of Matrix.

Continued thread

The thing that happens is, I create a new unique address for a business I'm dealing with. I put the company's name in the local-part of the email address I give them (that's the part before the "@" symbol in an email address).

And then they contact me demanding to know why (or how) I'm using "their" email. They see their company name or domain name in the local-part of my address and get incensed, thinking it's impossible, or illegal even. It makes no sense; would the greeting card mafia have a case against a big webmail provider if one of their users created the "hallmark@BigWebmailProviderDomain" address?

On more than one occasion, I have picked up the phone to find someone YELLING at me about "hacking their server" because of this.

I spend some time explaining it to them. Half the time, they kinda/sorta get it and calm down. The other half refuse to even stop yelling and think about what I'm telling them.

And this isn't some random one-person business I'm dealing with. Today, it was *my bank* that called me to demand to know why my support request email address had "their email" in it.

You would hope a bank, operating an online banking site, would have staff that have at least a passing familiarly with email and the internet. But nope.

To make it worse, this is actually the second time my bank has gotten upset about it.

3/3

Replied in thread

Zwecks Auffindbarkeit ein paar Hastags dazu:
Untersuchte Hersteller: #Huawei #Sungrow #GinlongSolis #Goodwatt #GoodWe #SMA
Allgemein: #PV #WR #Wechselrichter #Solar #Inverter #SunDown #Forescout #China #Hacker #SmartHome #IoT
forescout.com/research-labs/su
@bsi

Recommendations
Manufacturers
Development • Devices: holistic security architecture including secure boot, binary hardening, anti-exploitation features, permission separation etc
• Applications: proper authorization checks on web applications, mobile applications and cloud backends
Testing • Regular penetration testing on applications and devices • Consider bug bounty programs
Monitoring Web Application Firewalls Remember that a WAF does not protect against logical flaws

Users
Residential and commercial users • Change default passwords and credentials • Use role-based access control • Configure the recording of events in a log • Update software regularly • Backup system information • Disable unused features • Protect communication connections
Commercial and utility installations (in addition) •
Include security requirements into procurement considerations
• Conduct a risk assessment when setting up devices • Ensure network visibility into solar power systems • Segment these devices into their own sub-networks • Monitor those network segments

We're meeting tomorrow (Fri 4th Apr) at #Glasgow #hackerspace - @thegamerclub at 153 Bath Lane from 6pm 'til late - all welcome!

Hackers, crackers, geeks, hats of any colour, technology enthusiasts, hacktivists, and other like-minded folks are most welcome. We do not judge anyone and everyone has something to contribute, no matter their level of expertise!

Also join us in Matrix at #2600:glasgow.social (invite link: glasgow.social/matrix)

glasgow.socialYou're invited to talk on MatrixYou're invited to talk on Matrix
Replied in thread
@ekaitz_zarraga@mastodon.social

The #Guix leaders are indeed the reason I don't even give it a try despite some great people like you working on it.

I will reconsider when I'll read a public apology for this personal attack to a neurodivergent #hacker such as #RMS.

It worth to remember how that "joint stab in the back" was published while RMS was under attack because he dared defend Minsky's memory from the same sort of mob justice that was then redirected (and amplified on #BigTech social media) against RMS himself.

Some of those "leaders" who signed that "joint statement" a couple years later signed an even worse attack built on top of lies.

These sort of personal attacks have clear political goals, "incidentally" aligned with BigTech interests.

Now @zimoun@sciences.re could try to sort me among #Stallman fanboys to reinforce his beliefs, but in fact I'm pretty critical of RMS work: ultimately I think he based free software on a cold-war biased ideology, without a proper balance between communion (aka sharing strongly protected commons) and freedom. This huge error left space to #opensource and to the current use of #FreeSoftware by all sort of large corporations to abuse and subdue people.
Another (related) issue has been the total lack of a cohesive architectural design for #GNU system: RMS was too (inconsciously) fond of free market ideology to lead the movement's technically, and this lack of cohordination was turned by #ESR to the "bazaar" (not so subtle) sublimation of free market, to ease corporate exploitation of the high skilled labour of #hackers.

But in fact, with all of his political errors, he's still the most coherent and commited free software activist out there.

So I will consider Guix again when they will publish a joint apology with the same visibility the back-stab had in 2019.
guix.gnu.orgJoint statement on the GNU Project — 2019 — Blog — GNU GuixBlog posts about GNU Guix.