Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

dangoodin@infosec.exchangeD

dangoodin@infosec.exchange

@dangoodin@infosec.exchange
About
Posts
17
Topics
9
Shares
0
Groups
0
Followers
0
Following
0

View Original

Posts

Recent Best Controversial

  • Filippo is spot on.
    dangoodin@infosec.exchangeD dangoodin@infosec.exchange

    RE: https://abyssdomain.expert/@filippo/116296240048747450

    Filippo is spot on. The question we should be asking now is: "What does Google know that the rest of us don't?"

    Uncategorized

  • I was lucky enough to cover Cindy Cohn's trailblazing work BEFORE she joined @eff .
    dangoodin@infosec.exchangeD dangoodin@infosec.exchange

    I was lucky enough to cover Cindy Cohn's trailblazing work BEFORE she joined @eff . Here's one of several stories I wrote about her when she was still an associate attorney in private practice.

    Uncategorized

  • Wow, TeamPCP is hacking open-source developers faster than we can report on them.
    dangoodin@infosec.exchangeD dangoodin@infosec.exchange

    For context, please see:

    Link Preview Image
    Self-propagating malware poisons open source software and wipes Iran-based machines

    Development houses: It's time to check your networks for infections.

    favicon

    Ars Technica (arstechnica.com)

    Uncategorized

  • Wow, TeamPCP is hacking open-source developers faster than we can report on them.
    dangoodin@infosec.exchangeD dangoodin@infosec.exchange

    Wow, TeamPCP is hacking open-source developers faster than we can report on them. The latest (that I'm aware of, anyway) is LiteLLM. They worked with Trivy but didn't bother to change their credentials after Trivy was hacked, despite an ample amount of advice to do so.

    Folks, if any of you used LiteLLM, now is the time to change your credentials, at an atomic level. Now, as in immediately.

    Link Preview Image
    Malicious litellm_init.pth in litellm 1.82.8 PyPI package – credential stealer | Hacker News

    favicon

    (news.ycombinator.com)

    Uncategorized

  • Does anybody with a STRONG BACKGROUND IN WEBSITE PRIVACY have time to vet this research?
    dangoodin@infosec.exchangeD dangoodin@infosec.exchange

    Does anybody with a STRONG BACKGROUND IN WEBSITE PRIVACY have time to vet this research? Are TikTok and Meta pixels REALLY doing the things claimed? I'm concerned it may be overstating things in an attempt to sell its tag monitoring tools.

    Link Preview Image
    The Collection of Commercial Intelligence: TikTok & Meta Ad Pixels

    Jscrambler analyzed the TikTok and Meta ad pixels used on websites and found that their default behavior requires immediate attention.

    favicon

    Jscrambler (jscrambler.com)

    Uncategorized

  • Dear readers.
    dangoodin@infosec.exchangeD dangoodin@infosec.exchange

    Dear readers. If you're not willing to support the families of those you want to read then we regretfully will be preventing you from obtaining our work for free.

    Link Preview Image
    Infosec Exchange

    A Mastodon instance for info/cyber security-minded people.

    favicon

    Mastodon hosted on infosec.exchange (infosec.exchange)

    Link Preview Image
    Infosec Exchange

    favicon

    (infosec.exchange)

    Uncategorized

  • Tire pressure "transmissions are sent without any encryption or secure mechanisms and include a unique identifier.
    dangoodin@infosec.exchangeD dangoodin@infosec.exchange

    @mossmann @ghostsarespooky

    Sigh. removing the sensors may be viable. Do the sensors come with the tires (and hence change each time they're replaced)? Sounds like swapping out the sensors would be a lot of work for the average vehicle owner.

    Uncategorized

  • Tire pressure "transmissions are sent without any encryption or secure mechanisms and include a unique identifier.
    dangoodin@infosec.exchangeD dangoodin@infosec.exchange

    @mossmann @ghostsarespooky

    OK, so it's just for tracking people's TPMS? It's not for changing your own?

    Uncategorized

  • Tire pressure "transmissions are sent without any encryption or secure mechanisms and include a unique identifier.
    dangoodin@infosec.exchangeD dangoodin@infosec.exchange

    @mossmann @ghostsarespooky

    I'll rephrase: To prevent TPMS from identifying my vehicle, do I use this kit to regularly change my TPMS? If not, how does this mitigation work?

    Uncategorized

  • Tire pressure "transmissions are sent without any encryption or secure mechanisms and include a unique identifier.
    dangoodin@infosec.exchangeD dangoodin@infosec.exchange

    @ghostsarespooky

    Very cool. Now I want to do it for my vehicle. How do I get started? Has anyone put together a how-to article?

    Uncategorized

  • Tire pressure "transmissions are sent without any encryption or secure mechanisms and include a unique identifier.
    dangoodin@infosec.exchangeD dangoodin@infosec.exchange

    @mossmann @ghostsarespooky

    Interesting. So is the idea to regularly change the TPMS?

    Uncategorized

  • Tire pressure "transmissions are sent without any encryption or secure mechanisms and include a unique identifier.
    dangoodin@infosec.exchangeD dangoodin@infosec.exchange

    @ghostsarespooky

    Please say more. What does one buy? How easy is it for people with only intermediate tech skills to do? Are there any tutorials explaining all of this?

    Uncategorized

  • Tire pressure "transmissions are sent without any encryption or secure mechanisms and include a unique identifier.
    dangoodin@infosec.exchangeD dangoodin@infosec.exchange

    Tire pressure "transmissions are sent without any encryption or secure mechanisms and include a unique identifier. This allows anyone with affordable equipment like a low-cost spectrum receiver and a standard off-the-shelf antenna to capture and track them throughout time and space."

    Just a moment...

    favicon

    (www.securityweek.com)

    Uncategorized

  • RIP burner accounts
    dangoodin@infosec.exchangeD dangoodin@infosec.exchange

    RIP burner accounts

    Link Preview Image
    LLMs can unmask pseudonymous users at scale with surprising accuracy

    Pseudonymity has never been perfect for preserving privacy. Soon it may be pointless.

    favicon

    Ars Technica (arstechnica.com)

    Uncategorized

  • Google has devised a means for securing HTTPS certificates against quantum computing attacks without massive performance hits stemming from the considerably longer size of data required to be included.
    dangoodin@infosec.exchangeD dangoodin@infosec.exchange

    @andrei_chiffa

    Great question . . . and one I don't know the answer to.

    Uncategorized

  • Google has devised a means for securing HTTPS certificates against quantum computing attacks without massive performance hits stemming from the considerably longer size of data required to be included.
    dangoodin@infosec.exchangeD dangoodin@infosec.exchange

    Google has devised a means for securing HTTPS certificates against quantum computing attacks without massive performance hits stemming from the considerably longer size of data required to be included.

    Is anyone following this work?

    Link Preview Image
    Cultivating a robust and efficient quantum-safe HTTPS

    Posted by Chrome Secure Web and Networking Team Today we're announcing a new program in Chrome to make HTTPS certificates secure against ...

    favicon

    Google Online Security Blog (security.googleblog.com)

    Uncategorized

  • That guest SSID you set up for your neighbors may not be as secure as you think
    dangoodin@infosec.exchangeD dangoodin@infosec.exchange

    That guest SSID you set up for your neighbors may not be as secure as you think

    https://arstechnica.com/security/2026/02/new-airsnitch-attack-breaks-wi-fi-encryption-in-homes-offices-and-enterprises/

    Uncategorized
  • Login

  • Login or register to search.
  • First post
    Last post
0
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups