mastodon.ie is one of the many independent Mastodon servers you can use to participate in the fediverse.
Irish Mastodon - run from Ireland, we welcome all who respect the community rules and members.

Administered by:

Server stats:

1.6K
active users

#authentication

8 posts7 participants4 posts today
Erik van Straten<p><span class="h-card" translate="no"><a href="https://kolektiva.social/@LukefromDC" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>LukefromDC</span></a></span> : it won't be that bad (it will be bad, but in a different way).</p><p>ANY website may ask a user to confirm they are 18+ (or whatever age).</p><p>There will be a huge amount of AitM (Attacker in the Middle) websites where naive people will be lured to (using fake emails, SMS, chat app messages or falsified QR-codes) and asked to confirm their age.</p><p>That AitM website will subsequently obtain a "ticket" (session cookie) from a real "relying party" website (with a potentially very different type of content than the victim is told).</p><p>Those "tickets" will be sold (or traded for watching ads and/or paying with privacy).</p><p>Reliable authentication requires a trustworthy identity verifier (even if identification is restricted to age+).</p><p><span class="h-card" translate="no"><a href="https://sigmoid.social/@drgroftehauge" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>drgroftehauge</span></a></span> <span class="h-card" translate="no"><a href="https://manganiello.social/users/fabio" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>fabio</span></a></span> <span class="h-card" translate="no"><a href="https://chaos.social/@SylvieLorxu" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>SylvieLorxu</span></a></span> </p><p><a href="https://infosec.exchange/tags/AgeVerification" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AgeVerification</span></a> <a href="https://infosec.exchange/tags/ByPass" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ByPass</span></a> <a href="https://infosec.exchange/tags/Phishing" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Phishing</span></a> <a href="https://infosec.exchange/tags/AitM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AitM</span></a> <a href="https://infosec.exchange/tags/MitM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MitM</span></a> <a href="https://infosec.exchange/tags/Identification" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Identification</span></a> <a href="https://infosec.exchange/tags/IdentityVerification" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IdentityVerification</span></a> <a href="https://infosec.exchange/tags/Authentication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Authentication</span></a> <a href="https://infosec.exchange/tags/Impersonation" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Impersonation</span></a> <a href="https://infosec.exchange/tags/ForSale" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ForSale</span></a></p>
Erik van Straten<p><span class="h-card" translate="no"><a href="https://social.wildeboer.net/@jwildeboer" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>jwildeboer</span></a></span> : modern certificates are used for authentication only, not for secure connections.</p><p>OTOH, if you have no certainty that your software is communicating with the server you intended, a secure connection to it is pointless - but the connection remains secure.</p><p>Using TLS v1.3, the connection is even secured before the server is authenticated (if, after encrypting the connection, the authentication of the server fails, then the client should at least warn the user - if not immediately disconnect).</p><p>Yes, I know, these are boring details, but they are misunderstood way too often by people who SHOULD know how this works (I know you do, but please don't simplify things too much).<br> </p><p><a href="https://infosec.exchange/tags/TLS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TLS</span></a> <a href="https://infosec.exchange/tags/https" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>https</span></a> <a href="https://infosec.exchange/tags/X509" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>X509</span></a> <a href="https://infosec.exchange/tags/Certificates" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Certificates</span></a> <a href="https://infosec.exchange/tags/Certs" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Certs</span></a> <a href="https://infosec.exchange/tags/Identification" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Identification</span></a> <a href="https://infosec.exchange/tags/Authentication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Authentication</span></a> <a href="https://infosec.exchange/tags/Impersonation" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Impersonation</span></a> <a href="https://infosec.exchange/tags/TLSv1_3" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TLSv1_3</span></a> <a href="https://infosec.exchange/tags/ForwardSecrecy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ForwardSecrecy</span></a> <a href="https://infosec.exchange/tags/DH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DH</span></a> <a href="https://infosec.exchange/tags/DHE" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DHE</span></a> <a href="https://infosec.exchange/tags/DiffieHellman" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DiffieHellman</span></a></p>
ResearchBuzz: Firehose<p>Sandia Lab: Two-factor authentication just got easier. “Researchers at Sandia have announced a more efficient way to generate and send temporary security codes. Unlike conventional methods, the new technique does not depend on the time, which could help secure small and remote network-connected devices, including drones, remote sensors, agricultural equipment and industrial control systems.”</p><p><a href="https://rbfirehose.com/2025/07/29/sandia-lab-two-factor-authentication-just-got-easier/" class="" rel="nofollow noopener" target="_blank">https://rbfirehose.com/2025/07/29/sandia-lab-two-factor-authentication-just-got-easier/</a></p>
|7eter l-|. l3oling 🧰<p>ANN: :ruby: omniauth-identity v3.1.4</p><p>Release Notes: <a href="https://dev.to/galtzo/ann-omniauth-identity-v314-2371" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">dev.to/galtzo/ann-omniauth-ide</span><span class="invisible">ntity-v314-2371</span></a></p><p><a href="https://ruby.social/tags/Ruby" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Ruby</span></a> <a href="https://ruby.social/tags/Authentication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Authentication</span></a> <a href="https://ruby.social/tags/Security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Security</span></a> <a href="https://ruby.social/tags/Rails" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Rails</span></a></p>
IT News<p>OpenAI’s ChatGPT Agent casually clicks through “I am not a robot” verification test - Maybe they should change the button to say, "I am a robot"?<br>... - <a href="https://arstechnica.com/information-technology/2025/07/openais-chatgpt-agent-casually-clicks-through-i-am-not-a-robot-verification-test/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">arstechnica.com/information-te</span><span class="invisible">chnology/2025/07/openais-chatgpt-agent-casually-clicks-through-i-am-not-a-robot-verification-test/</span></a> <a href="https://schleuss.online/tags/computer" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>computer</span></a>-usingagent <a href="https://schleuss.online/tags/aidevelopmenttools" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>aidevelopmenttools</span></a> <a href="https://schleuss.online/tags/computerusemodel" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>computerusemodel</span></a> <a href="https://schleuss.online/tags/machinelearning" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>machinelearning</span></a> <a href="https://schleuss.online/tags/authentication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>authentication</span></a> <a href="https://schleuss.online/tags/websecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>websecurity</span></a> <a href="https://schleuss.online/tags/aibehavior" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>aibehavior</span></a> <a href="https://schleuss.online/tags/aisecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>aisecurity</span></a> <a href="https://schleuss.online/tags/cloudflare" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cloudflare</span></a> <a href="https://schleuss.online/tags/agenticai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>agenticai</span></a> <a href="https://schleuss.online/tags/aiagents" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>aiagents</span></a> <a href="https://schleuss.online/tags/captcha" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>captcha</span></a> <a href="https://schleuss.online/tags/chatgpt" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>chatgpt</span></a> <a href="https://schleuss.online/tags/biz" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>biz</span></a>⁢ <a href="https://schleuss.online/tags/openai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>openai</span></a> <a href="https://schleuss.online/tags/ai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ai</span></a></p>
Erik van Straten<p><span class="h-card" translate="no"><a href="https://infosec.exchange/@adfichter" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>adfichter</span></a></span> : I'm trying to warn people for such holes.</p><p>Published earlier this month: <a href="https://www.heise.de/en/news/BSI-and-ANSSI-warn-against-VideoIdent-for-the-EU-digital-wallet-10476045.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">heise.de/en/news/BSI-and-ANSSI</span><span class="invisible">-warn-against-VideoIdent-for-the-EU-digital-wallet-10476045.html</span></a> (there of course is a German version as well).</p><p>It refers to a recent joint publication (in English) by the German BSI and the French ANSSI titled:</p><p>"Remote ldentity Proofing for EUDI Wallet Onboarding: Strengthening Assurance Against Evolving Threats"</p><p>(EUDI Wallet = European Digital Identity Wallet aka EDIW aka EUDIW).</p><p>It's about the risks of VideoIdent (getting bigger every day, see e.g. <a href="https://www.theverge.com/report/714402/uk-age-verification-bypass-death-stranding-reddit-discord" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">theverge.com/report/714402/uk-</span><span class="invisible">age-verification-bypass-death-stranding-reddit-discord</span></a> - not to mention AI).</p><p>However, like in their previous publication (PDF: <a href="https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/ANSSI-BSI-joint-releases/ANSSI-BSI_joint-release_2023.pdf?__blob=publicationFile&amp;v=3" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bsi.bund.de/SharedDocs/Downloa</span><span class="invisible">ds/EN/BSI/Publications/ANSSI-BSI-joint-releases/ANSSI-BSI_joint-release_2023.pdf?__blob=publicationFile&amp;v=3</span></a>) they ignore one HUGE risk: AitM's (Attacker in the Middle).</p><p>The unmentioned gaping security hole here are fake websites, where people are being directed to via falsified emails, SMS, chat app messages and possibly QR-codes.</p><p>Step 1️⃣:<br>————<br>Victim (contacts AitM site as instructed)<br> |<br> | "Please give me my EDIW"<br> v<br>AitM site: contacts site below and forwards<br> |<br> | "Please give me my EDIW"<br> v<br>True EDIW identity verification site</p><p>Step 2️⃣:<br>————<br>Victim<br> ^<br> | "Please perform VideoIdent"<br> |<br>AitM site: forwards<br> ^<br> | "Please perform VideoIdent"<br> |<br>True EDIW identity verification site</p><p>Step 3️⃣:<br>————<br>Victim<br> |<br> | VideoIdent showing victim<br> v<br>AitM site: forwards<br> |<br> | VideoIdent showing victim<br> v<br>True EDIW identity verification site</p><p>Step 4️⃣:<br>————<br>Victim<br> ^<br> | "Something went wrong"<br> |<br>AitM site: stores victim's EDIW on their device<br> ^<br> | EDIW<br> |<br>True EDIW identity verification site</p><p>The same may happen to people who are tricked into *authenticating* using EDIW on AitM websites.</p><p><span class="h-card" translate="no"><a href="https://mastodon.nl/@ellent" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>ellent</span></a></span> <br> </p><p><a href="https://infosec.exchange/tags/EDIW" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EDIW</span></a> <a href="https://infosec.exchange/tags/EUDIW" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EUDIW</span></a> <a href="https://infosec.exchange/tags/AitM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AitM</span></a> <a href="https://infosec.exchange/tags/MitM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MitM</span></a> <a href="https://infosec.exchange/tags/VideoIdent" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VideoIdent</span></a> <a href="https://infosec.exchange/tags/OnlineAuthentication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OnlineAuthentication</span></a> <a href="https://infosec.exchange/tags/Authentication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Authentication</span></a> <a href="https://infosec.exchange/tags/Impersonation" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Impersonation</span></a> <a href="https://infosec.exchange/tags/Identification" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Identification</span></a> <a href="https://infosec.exchange/tags/IdentityFraud" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IdentityFraud</span></a> <a href="https://infosec.exchange/tags/InfoSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InfoSec</span></a></p>
Tao of Mac<p>Open ID Connect</p><p>OpenID Connect (OIDC) is an authentication protocol built on top of the OAuth 2.0 framework. It allows clients to verify the identity of end-users based on the authentication perfo(...)</p><p><a href="https://mastodon.social/tags/authentication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>authentication</span></a> <a href="https://mastodon.social/tags/identitymanagement" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>identitymanagement</span></a> <a href="https://mastodon.social/tags/oauth2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>oauth2</span></a> <a href="https://mastodon.social/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a> <a href="https://mastodon.social/tags/sso" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>sso</span></a></p><p><a href="https://taoofmac.com/space/protocols/oidc" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">taoofmac.com/space/protocols/o</span><span class="invisible">idc</span></a></p>
🧿🪬🍄🌈🎮💻🚲🥓🎃💀🏴🛻🇺🇸<p>&gt; <a href="https://mastodon.social/tags/Google" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Google</span></a> informed me that I already had a <a href="https://mastodon.social/tags/passkey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>passkey</span></a> on my device. If that's the case, why didn't it work when I attempted to log into my Google account on the tablet? When I was logging into the tablet, Google should have been aware I had <a href="https://mastodon.social/tags/passkeys" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>passkeys</span></a> on my Pixel 9 Pro and request <a href="https://mastodon.social/tags/authentication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>authentication</span></a> with either a fingerprint or face scan. It didn't. No passkey was recognized… even though it's there.</p><p>&gt; It's a recursive nightmare from which I can't seem to escape.</p><p><a href="https://www.zdnet.com/article/passkeys-wont-be-ready-for-primetime-until-google-and-other-companies-fix-this/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">zdnet.com/article/passkeys-won</span><span class="invisible">t-be-ready-for-primetime-until-google-and-other-companies-fix-this/</span></a></p><p><a href="https://mastodon.social/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a></p>
Brandon H :csharp: :verified:<p>via <span class="h-card" translate="no"><a href="https://dotnet.social/@dotnet" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>dotnet</span></a></span> : MCP C# SDK Gets Major Update: Support for Protocol Version 2025-06-18</p><p><a href="https://ift.tt/qeagVHY" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">ift.tt/qeagVHY</span><span class="invisible"></span></a><br><a href="https://hachyderm.io/tags/MCP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MCP</span></a> <a href="https://hachyderm.io/tags/CSharpSDK" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CSharpSDK</span></a> <a href="https://hachyderm.io/tags/DotNet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DotNet</span></a> <a href="https://hachyderm.io/tags/AI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AI</span></a> <a href="https://hachyderm.io/tags/SoftwareDevelopment" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SoftwareDevelopment</span></a> <a href="https://hachyderm.io/tags/Authentication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Authentication</span></a> <a href="https://hachyderm.io/tags/Elicitation" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Elicitation</span></a> <a href="https://hachyderm.io/tags/StructuredOutput" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>StructuredOutput</span></a> <a href="https://hachyderm.io/tags/ResourceLinks" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ResourceLinks</span></a> <a href="https://hachyderm.io/tags/SDKUpdate" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SDKUpdate</span></a> <a href="https://hachyderm.io/tags/Programming" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Programming</span></a> <a href="https://hachyderm.io/tags/OpenSource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSource</span></a> <a href="https://hachyderm.io/tags/ModelCo" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ModelCo</span></a>…</p>
Erik van Straten<p><span class="h-card" translate="no"><a href="https://infosec.exchange/@tbortels" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>tbortels</span></a></span> : even if we disagree, thank you for a fair discussion.</p><p>You wrote:<br>❝Asking any third party to ensure "trust" is doomed from the start. In the history of humanity no govermnment or organization whatsoever has managed to eliminate fraud, and none ever will.❞</p><p>You are right, not for 100%. That will never be achieved; what I think is seriously needed is risk *reduction*.</p><p>By typing the toot you sent to me, you had to trust the manufacturers of hardware and software you used. You'll have to trust your bank for prudently guarding your savings. Trust is a very basic requirement in our lives, even if we are to be very disappointed now and then.</p><p>We have chambers of commerce for a reason (in my country: <a href="https://www.kvk.nl/en/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">kvk.nl/en/</span><span class="invisible"></span></a>).</p><p>Among other things, I wrote a section<br> {1} WHAT IS A DECENT WEBPKI<br>in my (long) proposal <a href="https://infosec.exchange/@ErikvanStraten/113079966331873386" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.exchange/@ErikvanStrat</span><span class="invisible">en/113079966331873386</span></a> (the current CA/B forum is pointless: it's big tech for big tech, zero consumer orgs are involved).</p><p>To decrease the (enormous) impact of cybercrime, IMO we can and should provide users with as much information about a website as possible, in particular when it is the first time they visit it (or if ownership may have changed).</p><p>❝The reality is this: people need to learn basic defensive cynicism.❞</p><p>That is simpy impossible. Even I sometimes find it hard to determine whether a website is authentic (and like you, I have a lot of infosec experience - that dates back to around the time that "internet" became accessible to universities).</p><p>The web is being FLOODED with criminal websites (example: see the image below) while no big tech org cares - on the contrary, they're making money by condoning it. Guess why Google introduced zillions of stupid TLD's. There are way too many people who will not and cannot become forensic researchers.</p><p>❝The internet is just another place where doing dumb things gets you hurt, and it can't be made safe without destroying it.❞</p><p>I disagree. Like I wrote in <a href="https://infosec.exchange/@ErikvanStraten/114241359684890759" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.exchange/@ErikvanStrat</span><span class="invisible">en/114241359684890759</span></a>:<br>"I am not against (free) Domain Validated certificates. They're fine if visitors do exactly know the domain name in advance, such as of your home NAS (and are not easily fooled by IDN's)."</p><p>❝Security and Trust are two different unrelated things. And people need to understand it.❞</p><p>Agreed, but we can still help them *a lot* making better decisions whom to trust. Again, I mean trust based on reputation and the ability to "see them in court" if you know who you're dealing with - in cases where that matters.</p><p><span class="h-card" translate="no"><a href="https://mastodon.scot/@UndisScot" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>UndisScot</span></a></span> </p><p><a href="https://infosec.exchange/tags/FakeWebsites" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FakeWebsites</span></a> <a href="https://infosec.exchange/tags/Phishing" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Phishing</span></a> <a href="https://infosec.exchange/tags/BigTechIsEvil" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BigTechIsEvil</span></a> <a href="https://infosec.exchange/tags/GoogleIsEvil" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GoogleIsEvil</span></a> <a href="https://infosec.exchange/tags/CloudflareIsEvil" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CloudflareIsEvil</span></a> <a href="https://infosec.exchange/tags/DV" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DV</span></a> <a href="https://infosec.exchange/tags/EV" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EV</span></a> <a href="https://infosec.exchange/tags/Certificates" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Certificates</span></a> <a href="https://infosec.exchange/tags/Authentication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Authentication</span></a> <a href="https://infosec.exchange/tags/Impersonation" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Impersonation</span></a></p>
Pyrzout :vm:<p>Review: Passwork 7.0, self-hosted password manager for business <a href="https://www.helpnetsecurity.com/2025/07/17/review-passwork-7-0-password-manager-for-business/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">helpnetsecurity.com/2025/07/17</span><span class="invisible">/review-passwork-7-0-password-manager-for-business/</span></a> <a href="https://social.skynetcloud.site/tags/authentication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>authentication</span></a> <a href="https://social.skynetcloud.site/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybersecurity</span></a> <a href="https://social.skynetcloud.site/tags/Don" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Don</span></a>'tmiss <a href="https://social.skynetcloud.site/tags/passwords" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>passwords</span></a> <a href="https://social.skynetcloud.site/tags/Hotstuff" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Hotstuff</span></a> <a href="https://social.skynetcloud.site/tags/Passwork" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Passwork</span></a> <a href="https://social.skynetcloud.site/tags/software" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>software</span></a> <a href="https://social.skynetcloud.site/tags/Reviews" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Reviews</span></a> <a href="https://social.skynetcloud.site/tags/review" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>review</span></a> <a href="https://social.skynetcloud.site/tags/News" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>News</span></a></p>
Grumpy Website<p>This dialog always confuses me. I have to read small print to really understand what does it want</p><p><a href="https://mastodon.online/tags/Apple" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Apple</span></a> <a href="https://mastodon.online/tags/macOS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>macOS</span></a> <a href="https://mastodon.online/tags/Dialog" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Dialog</span></a> <a href="https://mastodon.online/tags/VisualHierarchy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VisualHierarchy</span></a> <a href="https://mastodon.online/tags/Fingerprint" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Fingerprint</span></a> <a href="https://mastodon.online/tags/Authentication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Authentication</span></a></p>
Pyrzout :vm:<p>Why silent authentication is the smarter way to secure BYOD <a href="https://www.helpnetsecurity.com/2025/07/17/silent-authentication-byod-video/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">helpnetsecurity.com/2025/07/17</span><span class="invisible">/silent-authentication-byod-video/</span></a> <a href="https://social.skynetcloud.site/tags/authentication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>authentication</span></a> <a href="https://social.skynetcloud.site/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybersecurity</span></a> <a href="https://social.skynetcloud.site/tags/Don" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Don</span></a>'tmiss <a href="https://social.skynetcloud.site/tags/Hotstuff" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Hotstuff</span></a> <a href="https://social.skynetcloud.site/tags/strategy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>strategy</span></a> <a href="https://social.skynetcloud.site/tags/Vonage" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Vonage</span></a> <a href="https://social.skynetcloud.site/tags/Video" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Video</span></a> <a href="https://social.skynetcloud.site/tags/video" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>video</span></a> <a href="https://social.skynetcloud.site/tags/News" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>News</span></a> <a href="https://social.skynetcloud.site/tags/BYOD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BYOD</span></a> <a href="https://social.skynetcloud.site/tags/CISO" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CISO</span></a> <a href="https://social.skynetcloud.site/tags/tips" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>tips</span></a></p>
Pyrzout :vm:<p>7 obsolete security practices that should be terminated immediately <a href="https://www.csoonline.com/article/4022848/7-obsolete-security-practices-that-should-be-terminated-immediately.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">csoonline.com/article/4022848/</span><span class="invisible">7-obsolete-security-practices-that-should-be-terminated-immediately.html</span></a> <a href="https://social.skynetcloud.site/tags/DataandInformationSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DataandInformationSecurity</span></a> <a href="https://social.skynetcloud.site/tags/IntrusionDetectionSoftware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IntrusionDetectionSoftware</span></a> <a href="https://social.skynetcloud.site/tags/SecurityPractices" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SecurityPractices</span></a> <a href="https://social.skynetcloud.site/tags/SecuritySoftware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SecuritySoftware</span></a> <a href="https://social.skynetcloud.site/tags/NetworkSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NetworkSecurity</span></a> <a href="https://social.skynetcloud.site/tags/Authentication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Authentication</span></a> <a href="https://social.skynetcloud.site/tags/Compliance" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Compliance</span></a> <a href="https://social.skynetcloud.site/tags/ITStrategy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ITStrategy</span></a></p>
Pyrzout :vm:<p>Inorganic DNA: How nanoparticles could be the future of anti-counterfeiting tech <a href="https://www.helpnetsecurity.com/2025/07/15/inorganic-dna-nanoparticles-anti-counterfeiting-tech/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">helpnetsecurity.com/2025/07/15</span><span class="invisible">/inorganic-dna-nanoparticles-anti-counterfeiting-tech/</span></a> <a href="https://social.skynetcloud.site/tags/authentication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>authentication</span></a> <a href="https://social.skynetcloud.site/tags/supplychain" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>supplychain</span></a> <a href="https://social.skynetcloud.site/tags/Don" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Don</span></a>'tmiss <a href="https://social.skynetcloud.site/tags/Elementag" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Elementag</span></a> <a href="https://social.skynetcloud.site/tags/Features" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Features</span></a> <a href="https://social.skynetcloud.site/tags/Hotstuff" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Hotstuff</span></a> <a href="https://social.skynetcloud.site/tags/hardware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>hardware</span></a> <a href="https://social.skynetcloud.site/tags/QRcodes" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>QRcodes</span></a> <a href="https://social.skynetcloud.site/tags/Europe" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Europe</span></a> <a href="https://social.skynetcloud.site/tags/News" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>News</span></a> <a href="https://social.skynetcloud.site/tags/EU" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EU</span></a></p>
Frontend Dogma<p>JWTs Are Not Session Tokens, Stop Using Them Like One, by (not on Mastodon or Bluesky):</p><p><a href="https://archive.fo/01UkP" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">archive.fo/01UkP</span><span class="invisible"></span></a></p><p><a href="https://mas.to/tags/jsonwebtokens" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>jsonwebtokens</span></a> <a href="https://mas.to/tags/authentication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>authentication</span></a> <a href="https://mas.to/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a></p>
Strypey<p>The UX of 2FA could be improved considerably, and security along with it, by using a circles of trust model.</p><p>Take the example of a code forge, hosting the canonical version of some crucial piece of kit like the Linux kernel, OpenSSL, or GnuPG. You would want a maintainer to be 100% authenticated before they can commit changes to these repositories. Basic security culture.</p><p>But ...</p><p>(1/2)</p><p><a href="https://mastodon.nzoss.nz/tags/2FA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>2FA</span></a> <a href="https://mastodon.nzoss.nz/tags/authentication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>authentication</span></a></p>
PrivacyDigest<p>Critical <a href="https://mas.to/tags/CitrixBleed" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CitrixBleed</span></a> 2 <a href="https://mas.to/tags/vulnerability" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>vulnerability</span></a> has been under active <a href="https://mas.to/tags/exploit" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>exploit</span></a> for weeks</p><p>A critical vulnerability allowing <a href="https://mas.to/tags/hackers" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>hackers</span></a> to bypass <a href="https://mas.to/tags/multifactor" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>multifactor</span></a> <a href="https://mas.to/tags/authentication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>authentication</span></a> in network management devices made by <a href="https://mas.to/tags/Citrix" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Citrix</span></a> has been actively <a href="https://mas.to/tags/exploited" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>exploited</span></a> for more than a month, researchers said. The finding is at odds with advisories from the vendor saying there is no evidence of in-the-wild <a href="https://mas.to/tags/exploitation" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>exploitation</span></a>.<br><a href="https://mas.to/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a> <a href="https://mas.to/tags/privacy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>privacy</span></a></p><p><a href="https://arstechnica.com/security/2025/07/critical-citrixbleed-2-vulnerability-has-been-under-active-exploit-for-weeks/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">arstechnica.com/security/2025/</span><span class="invisible">07/critical-citrixbleed-2-vulnerability-has-been-under-active-exploit-for-weeks/</span></a></p>
cybertrapped<p><span class="h-card" translate="no"><a href="https://fosstodon.org/@link2xt" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>link2xt</span></a></span> </p><p>I'M TROUBLED BY THE FOLLOWING:</p><p>The email was sent using oraclecloud servers, and when I checked the SPF records using the MXTOOLBOX.COM </p><p>I see what I think would be other authorized domains </p><p>v=spf1 exists:%{i}._i.%{d}._d.espf.agari-dns.net include:%{d}.ff.spf-protect.agari-dns.net include:_spf.salesforce.com include:spf.somedomain.com include:spf-d.somedomain.com include:spf-c.somedomain.com include:spf.protection.outlook.com -all</p><p><a href="https://mastodon.social/tags/spf" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>spf</span></a> <a href="https://mastodon.social/tags/email" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>email</span></a> <a href="https://mastodon.social/tags/authentication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>authentication</span></a> <a href="https://mastodon.social/tags/legitimacy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>legitimacy</span></a> <a href="https://mastodon.social/tags/question" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>question</span></a></p>
Bill<p>Spike in credential theft. Probably comes as no surprise to anyone. Use MFA!</p><p><a href="https://www.infosecurity-magazine.com/news/hackers-target-employee-credentials/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">infosecurity-magazine.com/news</span><span class="invisible">/hackers-target-employee-credentials/</span></a></p><p><a href="https://infosec.exchange/tags/authentication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>authentication</span></a> <a href="https://infosec.exchange/tags/mfa" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>mfa</span></a></p>