Showing posts with label that would be great. Show all posts
Showing posts with label that would be great. Show all posts

Friday, October 14, 2022

No location tracking data for you!

from here and here

The newest thing that's supposed to be the end of passwords is the passkey, and colour me shocked but it requires a cell phone. Now cell phone based authentication has been misused for tracking so many times now I'm not even going to pretend to believe there was any other motive involved in that particular design decision.

Tuesday, August 30, 2022

Let's make data brokers broke

from here and here

125 million phones could cover more than a third of the population of the entire United States, and yet I've never even heard of the company Kochava before. If this single unknown company is tracking that many people, just think of how many people are being tracked by all the other unknown data brokers out there. 

Monday, May 23, 2022

How will they SCARE up new customers then?

from here and here

A common element in most VPN marketing is talking about all the privacy threats their service protects you against because it encrypts your traffic - even though most websites are already encrypted. It's almost as if they're stuck in the past (when sites weren't encrypted), but of course the real reason is probably just that fear sells. 

Tuesday, April 26, 2022

What is xyz.exe?

from here and here

Never mind the annoyance at seeing these new binaries popping up at regular intervals, there's also the issue of investigative fatigue and the diminishing value skepticism has when most of the new binaries your security software alerts you to are just additional Microsoft detritus that came in on the most recent Windows Update.

Thursday, March 17, 2022

Every modern tech company

from here and here

I'm having difficulty thinking of an example that violates this rule, how about you?

Tuesday, September 7, 2021

Nothingburgers for everyone

from here

$15 - $25 per user for tricking users into thinking their communications were secure and private seems completely inadequate as either a form of restitution or as a deterrent to keep Zoom or other companies from doing it again.

Wednesday, January 13, 2021

If unsatisfied customers disappear, is there still a problem?

from here

Thanks to Naomi Wu for working so hard to raise awareness of what is clearly a serious issue, and shame on Signal for not doing more to educate users on the safety considerations of using their app.

In theory, secure messaging is meant to protect those who might otherwise be in danger if the contents of their messages were found out. If at-risk Signal users are getting disappeared under normal usage conditions then the question has to be asked whether Signal is fit for purpose.

Friday, August 28, 2020

And stop changing the settings back to default all the time

from here

Supposedly you can change the authentication method to OAuth2, but that didn't seem to work properly for me and even if it had, I'm not sure how many authentication tokens it will keep separate (I'm using an email client because I have multiple accounts and I don't want them getting linked)

Thursday, January 30, 2020

But bypassWordList might contain hard-coded credentials

from here

I care about application security as much as the next developer (maybe more) but this particular heuristic (and the false alarms it generates) drives me nuts.

Thursday, September 19, 2019

Scammer identity crisis

from here

It's almost like they aren't even trying.

Friday, July 26, 2019

Don't quit your day jobs

from here

This browser from Avast isn't the first time I've seen a security vendor shipping their own browser, and it probably won't be the last. But frankly, if I wanted all my apps to come from the same place, I'd have stuck with Microsoft. I can't help but think the resources that went into making a browser no one wants could have been better spent improving their anti-malware product.

Friday, July 19, 2019

What are you trying to say about me, Google?

from here

No, I'm not reminding myself to get bigger or last longer or transfer funds or anything like that. For all the smarts that goes into GMail, you'd think it could tell that an email I compose to myself while logged into the web interface would be enough to rule out the possibility of spam. Apparently that's not the case.

Tuesday, May 14, 2019

Who updates the updates?

from here

Crashing ankle monitors seems like a worst case scenario for the people trying to keep criminals in line. It's the kind of thing that might make people rethink the wisdom of applying updates at all.

Monday, March 18, 2019

I know what you're providing and it ain't managed security

found on Imgur

If you're thinking of selling managed security as a service, you better be able to provide your own employees with security services (like facilities for sharing documents securely) before you try offering them to others. Otherwise you're just providing bullshit with a fancy name. According to the Imgur post, not every provider sees it that way.

Tuesday, February 19, 2019

To be on the cutting edge of security

from here

Just because changing your fingerprints is something only a drug trafficker or other criminal would do today doesn't mean it won't become mainstream in the future.

Friday, January 4, 2019

Pay no attention to the malware behind the curtain

from here

It seems like Apple hasn't yet grown out of that old habit of pretending their users have nothing to worry about. They're taking action to mitigate threats without informing anyone and in the process leaving the people their efforts can't reach out in the cold.

Monday, December 31, 2018

My screen, it's full of ads

from here

The Christmas season is a time for visiting family and, by extension, using strange WiFi. So you might have been tempted to go searching for VPN apps (like I did) and you may have discovered (like I did) that the results were so full of paid results that there were no organic search results anywhere on the screen.

You'd think Google would have some sort of limit that prevents a screen full of ads being displayed, but I guess we can't expect that much from an ad company.

Tuesday, December 11, 2018

'Tis the season to protect your privacy in your secret santa posts

found on Imgur

From what I can gather, that trend where people post pictures of their bank and credit cards online has branched out into other items with sensitive information on them.

Thursday, November 15, 2018

As if the world's biggest ad company cares about privacy

from here

Having reached the pinnacle of online invasiveness in the name of serving you increasingly relevant ads, and after gaining a foothold in the real world with their personal electronics, Google has now moved on to gathering data from entire cities. Try opting out of that.

Thursday, October 11, 2018

Which one(s) do I whitelist in NoScript to make it work?

from here

And if that wasn't bad enough, frequently adding a source to the whitelist will uncover still more untrusted sources that you didn't even know about before.