Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

masek@infosec.exchangeM

masek@infosec.exchange

@masek@infosec.exchange
About
Posts
111
Topics
26
Shares
0
Groups
0
Followers
0
Following
0

View Original

Posts

Recent Best Controversial

  • I realize my view on whether it is ever okay to pay #ransom in a #hackandleak situation is contentious.
    masek@infosec.exchangeM masek@infosec.exchange

    @PogoWasRight @amvinfe @euroinfosec Counter-question: Do you believe that this averted more ill than it will cause in the long run?

    I don't think so.

    I understand the dilemma the decision makers were in. I would have probably argued against paying, but I don't know the full details and have a safe emotional distance.

    Where the potential troubles for others the main reason for paying up or did they secretly hope it would safe their own asses?

    If a significant part of the ransom came from the execs, that would be an indicator that avoiding ill was the main reason.

    Uncategorized ransom hackandleak incidentrespons mitigation responsibility

  • A friend abroad is in a bit of trouble.
    masek@infosec.exchangeM masek@infosec.exchange

    @katzenjens I somehow suspect that may be an intended message indeed, but you know me: I'm not that good at listening 🙂.

    Uncategorized

  • A friend abroad is in a bit of trouble.
    masek@infosec.exchangeM masek@infosec.exchange

    A friend abroad is in a bit of trouble. As assistance, she asked for Amazon gift cards.

    "Easy enough," thought innocent, unsuspecting Martin.

    The first thing I learned was that an Amazon.de gift card cannot be redeemed at an Amazon store abroad. So I tried logging into the local Amazon site instead.

    That actually worked with my German account, after entering a code they emailed me. However, they immediately forced me to set a new password. Which I did.

    I now have absolutely no idea whether this also changed the password for my German account.

    Then I had to confirm the login using an authenticator token. Surprisingly, the token from my German account worked.

    At this point, I was finally able to put the gift card into the shopping cart. But paying for it turned into its own separate side quest.

    Amazon proudly displayed all the credit cards I have stored with them, but for the actual payment they insisted on using an (Amazon-branded) credit card I normally never use and which permanently lives locked away in a safe.

    The system recognized the card, of course, but in order to proceed with the order it demanded the three-digit security code. So I retrieved the card from the safe and entered the code.

    Getting to that safe has become a painful undertaking these days because I made the strategic error of bolting it to the floor and my knees are no longer enthusiastic supporters of that design decision.

    But what won’t one do for friends.

    The order was then confirmed. I even received the confirmation email. At this point I believed I had succeeded and leaned back in relief.

    About five minutes later, this email arrived:

    We believe that an unauthorized party may have accessed your Amazon account. As a security measure, we have taken the following action. We have taken the following actions to protect your account:

    • Canceled any suspicious pending orders and removed them from "Your Orders" section in "Your Account"
    • If you were using a password for your Amazon account, it has been disabled and you need to reset your password.
    • Reversed any changes made by this unauthorized party.
    • Removed suspicious devices from your account.
    • Existing security features, such as Passkey or Two-Step Verification, might have been affected during this process because we couldn't verify if recent changes were made by you. After regaining access, visit the "Login & security" page in your "Account settings" to verify if these features are still enabled and add them back if needed.

    The email then continues for several more pages.

    So now I get to go through the entire circus again from the very beginning. Everything! Completely! Only this time I used SMS verification instead of email codes. I hope that way Amazon will believe, it is really me.

    Once again I confirmed that yes, astonishingly enough, I was in fact myself.

    And now I’m sitting here fully expecting another one of those emails to arrive at any moment.

    This entire masterpiece of modern digital convenience has now taken well over 30 minutes.

    On some days you can't eat as much as you want to throw up. Globalization is not intended for inferior peons like us but just for nobles like Bezos.

    Uncategorized

  • Ein Freund von mir sucht im Raum #kiel einen Network Engineer:
    masek@infosec.exchangeM masek@infosec.exchange

    @EinsTux Wenn Du keine brauchst, ist dann das "haben" nicht etwas unfair 😉 ?

    Uncategorized kiel fedijobs

  • I realize my view on whether it is ever okay to pay #ransom in a #hackandleak situation is contentious.
    masek@infosec.exchangeM masek@infosec.exchange

    @PogoWasRight @amvinfe There may be exceptions, where I would perhaps judge differently.

    An example is: Someone will die if I don't pay up. But I have never seen those in cybercrime.

    Guideline should be like: Would you rob a bank (commit a crime, put others at risk) for your harm to be reduced?

    I would not do that to save my company, but if my wife's life were at risk?

    Uncategorized ransom hackandleak incidentrespons mitigation responsibility

  • Ein Freund von mir sucht im Raum #kiel einen Network Engineer:
    masek@infosec.exchangeM masek@infosec.exchange

    @EinsTux Ich glaube, das ist auch "etwas" unterhalb Deines Skill-Sets 🙂

    Uncategorized kiel fedijobs

  • Ein Freund von mir sucht im Raum #kiel einen Network Engineer:
    masek@infosec.exchangeM masek@infosec.exchange

    Ein Freund von mir sucht im Raum #kiel einen Network Engineer:

    Link Preview Image
    Systemadministrator (m/w/d) - OSI Maritime Systems

    favicon

    OSI Maritime Systems - The Leader in Naval Integrated Navigation & Tactical Solutions (osimaritime.com)

    Er baut für eine Kanadische Firma den neuen deutschen Standort auf. D.h. man kommt dort an eine Stelle, wo man noch ein paar Dinge mit gestalten kann, auch über den lokalen Standort hinaus.

    Außerdem, das kann ich sicher sagen, kriegt man jemanden als Chef, der mit IT-Menschen umgehen kann.

    Bei Interesse kann ich vor einer formellen Bewerbung einen Vorab-Kontakt herstellen.

    Allerdings ist der Job im Defense-Sektor, was die üblichen Nachteile (Security Clearance, eingeschränktes Remote Work) mit sich bringt.

    #fedijobs

    Uncategorized kiel fedijobs

  • Nvidia’s market cap is equal to over 17% of the US GDP.
    masek@infosec.exchangeM masek@infosec.exchange

    @jerry I was there, Gandalf. I was there three thousand 26 years ago. I was there the day the strength of dotcon failed.

    Uncategorized

  • I realize my view on whether it is ever okay to pay #ransom in a #hackandleak situation is contentious.
    masek@infosec.exchangeM masek@infosec.exchange

    @PogoWasRight @amvinfe Nowadays even having common sense is contentious 😏.

    I tell my customers to never pay ransom and, should they ever do, to leave me completely out of it.

    Uncategorized ransom hackandleak incidentrespons mitigation responsibility

  • TIL: Ein in Deutschland gekaufter Amazon-Gutschein kann nicht bei Amazon in den USA oder Kanada eingelöst werden.
    masek@infosec.exchangeM masek@infosec.exchange

    TIL: Ein in Deutschland gekaufter Amazon-Gutschein kann nicht bei Amazon in den USA oder Kanada eingelöst werden.

    Globalisierung gilt nicht für Dich, Du Bauer!

    Uncategorized

  • get him on the China Trump plane
    masek@infosec.exchangeM masek@infosec.exchange

    @GossiTheDog Ah, this aged well like a good wine 🙂

    Uncategorized

  • Ihr seid wahrscheinlich wie ich mit PCs groß geworden und habt deshalb ein bestimmtes Bild davon, was ein „Computer“ ist: CPU im Sockel, RAM-Riegel, Steckkarten, Laufwerke, Kabel.
    masek@infosec.exchangeM masek@infosec.exchange

    @isotopp Das Jammern in der Zeitung war initial fälschlicherweise wegen
    Datenschutz. Der hat hier keine Aktien drinnen. Es ist auch kein Sicherheitsproblem.

    Es ist ein rein ökonomisches Problem und leider können heute Journalisten das nicht vermitteln. Der Restwert der Geräte ist den notwendigen Aufwand nicht wert.

    Das zu erklären, dafür braucht man halt Dich 🙂.

    Dazu kommt, dass die Personalausstattung für die Schul-IT den Zeiten nicht mehr angemessen ist.

    Uncategorized

  • Ich hasse solche Schlagzeilen: https://www.kn-online.de/lokales/kiel/kiel-ausrangierte-ipads-an-schulen-datenschutz-verhindert-weitergabe-Y2E3TAMICJHWVDIFSWIGGC55ZQ.html(Paywall, Anriß reicht aber)
    masek@infosec.exchangeM masek@infosec.exchange

    Ich hasse solche Schlagzeilen: https://www.kn-online.de/lokales/kiel/kiel-ausrangierte-ipads-an-schulen-datenschutz-verhindert-weitergabe-Y2E3TAMICJHWVDIFSWIGGC55ZQ.html
    (Paywall, Anriß reicht aber)

    Das Problem sind fehlende Prozesse und KnowHow.

    Uncategorized

  • @EinsTux 🤬
    masek@infosec.exchangeM masek@infosec.exchange

    @EinsTux 🤬

    Uncategorized

  • Ich hab vor 15(!) Jahren jemanden eine Hicom100E verkauft, und jetzt meldet sich die Person und braucht eine Umkonfiguration, ob ich noch im Geschaeft sei und Dinge tun koennte?
    masek@infosec.exchangeM masek@infosec.exchange

    @EinsTux Wir waren so eine Art "Beta-Kunde" für deren System. Da wir direkten Kontakt zu den Entwicklern hatten, bekam es eine Menge Features die in der Zeit von ISDN-Einwahl relevant waren. Die Anlage konnte z.B. SPVs handhaben. Aber sie war nie weit verbreitet und das Produkt wurde irgendwann auch eingestellt.

    Uncategorized

  • Ich hab vor 15(!) Jahren jemanden eine Hicom100E verkauft, und jetzt meldet sich die Person und braucht eine Umkonfiguration, ob ich noch im Geschaeft sei und Dinge tun koennte?
    masek@infosec.exchangeM masek@infosec.exchange

    @EinsTux Ich vermisse Hagenuk in der Liste 🙂

    Uncategorized

  • Q: How old are you
    masek@infosec.exchangeM masek@infosec.exchange

    @draeath @madcannedtuna https://www.smbc-comics.com/comic/terminal

    Uncategorized

  • Ich hab vor 15(!) Jahren jemanden eine Hicom100E verkauft, und jetzt meldet sich die Person und braucht eine Umkonfiguration, ob ich noch im Geschaeft sei und Dinge tun koennte?
    masek@infosec.exchangeM masek@infosec.exchange

    @EinsTux Konfiguriert habe ich nur Hagenuk-Anlagen 😁

    Uncategorized

  • Q: How old are you
    masek@infosec.exchangeM masek@infosec.exchange

    @draeath Wait a few days …

    Uncategorized

  • Q: How old are you
    masek@infosec.exchangeM masek@infosec.exchange

    @madcannedtuna Wait a few days and use the link I included in an answer. It will be there.

    Uncategorized
  • Login

  • Login or register to search.
  • First post
    Last post
0
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups