#OpSec

Kevin Karhan :verified:kkarhan@infosec.space
2025-12-23

In case anyone needs some #testing #CreditCard numbers for #API tests:

Here are some from official payment processors' public documentation.

  • Obviously these WON'T WORK on any non-testing payment system (blocklisted by the payment processors!) so all one will get is declines and being listed as fraudster on any live payment network.

  • So definitely don't hand them to #scammers (obviously if they're stupid enough to accept 4242 4242 4242 4242 they should get jailtime just for being "criminally stupid") and only use them for responsible testing uses as outlined by payment processors.

These are merely documented for reference for ethical development purposes and cases where one needs something for mockups, as these have the optics of realness (and they checkout as legit numbers per algorithm) but obviously no real card would ever be issued and I'd see this as a more ethical way to test things that to use i.e. Wirecard's assigned BINs cuz those may be reassigned to a different card issuer and thus could actually incur fraudulent charges!

  • You're all welcome!

#payment #PaymentProcessing #CC #CreditCards #OnlinePayment #development #OpenSource #OpenData #PublicData #OSINT #tech #devs #dev #ITsec #InfoSec #OpSec #ComSec

2025-12-22

Decided to make the jump to a secure and even a verifiably secure laptop. Love the temper evident screws, packing , cryptographically secure boot etc etc. But really made the mistake of not having the nitro key shipped in the same shipment, looks like I am waiting for the new year to make the switch...
#OPSEC #QubesOS

Off-Grid Lorekeeperdaemonlogger
2025-12-21
2025-12-21

Free Christmas #opsec advice:

Don't bring your two year old Christmas shopping. Those jerks can't keep secrets.

Kevin Karhan :verified:kkarhan@infosec.space
2025-12-20

@jesterchen @heiseonline #Funfact: Der #BND darf garnicht innerhalb #Deutschland|s gegen deutsche #Staatsbürger*innen operativ tätig werden.

Und alle die "von Interesse" sind haben entsprechende #OpSec, #InfoSec, #ITsec & #ComSec...

2025-12-19

I'll be hosting a "Privacy Ultras Meetup" at #39C3 for everyone interested in raising their privacy/OPSEC to the max.

The idea is to share practical solutions and ideas about addressing various threat models in the digital and real worlds, and learning from each other.

If you're interested, please mark the session as favorite in the hub so an adequate room can be made available!

See events.ccc.de/congress/2025/hu for details.

Currently planned schedule is Day 2 @ 14:30.

#privacy #opsec

2025-12-19

I know, I know. Subletting your Identity & security access seemed like such an obvious no-no but yeah just go ahead & add it to the employee manual Bob, thanks.

scworld.com/brief/us-jails-mar

#OpSec

US jails Maryland man over North Korean IT worker scheme involvement

By SC Staff


The U.S. Justice Department has announced that Maryland resident Minh Phuong Ngoc Vong has been sentenced to 15 months imprisonment and three years of supervised release after permitting North Korean nationals to leverage his identity to work as a software developer at over a dozen U.S. firms between 2021 and 2024 as part of North Korea's IT worker scheme, reports The Record, a news site by cybersecurity firm Recorded Future.
Linkeazlinkeaz
2025-12-18

Incident cyber au ministère de l'Intérieur. Intrusion détectée mi-décembre 2025, entraînant l'extraction d'une centaine de fiches TAJ. Le vecteur d'attaque identifié est un phishing menant à la compromission de mots de passe stockés en clair. Un suspect a été arrêté.
⚡️ linkeaz.net/fr/posts/french-in

Cyberattaque au ministère de l'Intérieur : Analyse de l'incident
Kevin Karhan :verified:kkarhan@infosec.space
2025-12-17

@m I mean, #Copaganda like this actively harms everyone by making #MediaIlliterates and #TechIlliterates cause #FalseAlarms due to #FalseSuspicion and teaching #kids proper #OpSec, #InfoSec, #ComSec & #ITsec, preventing actually necessary interventions when it comes to 'much worse things...

2025-12-17

📬 tv-bunker.to: Interview mit dem Admin des neuen CS- & IPTV-Forums
#Interviews #IPTV #Szene #csservice #nologging #opsec #resellerpanel #tvbunkerto #zeur sc.tarnkappe.info/4a512b

🆘Bill Cole 🇺🇦grumpybozo@toad.social
2025-12-16

@JustinDerrick Text scammers have adopted stalker tactics.
Edgy marketers for legit companies often adopt them too.
They can fake any calling number they like. They can buy name+address+phone data on the open commercial market in the US.
#InfoSec #OpSec

Mark Wyner Won’t Comply :vm:markwyner@mas.to
2025-12-16

It’s interesting how many people think wanting privacy means you’re doing something nefarious. The fact is, privacy is about sharing what you want with whom you choose.

(I don’t recall who wrote these words or where I originally saw them. I only made the graphic.)

#Privacy #InfoSec #OpSec #BigBrother

Illustration of some eyes looking straight at you followed by text that reads “I need privacy, not because my actions are questionable. But because your judgment and intentions are.”
Мяу Машина 4.0meowmashine@ioc.exchange
2025-12-16

Давай строй свои деревья меркеля падлюка, с overlay tmpfs dm verity должен сработать. Правда из за говно накопителя ждать приходится по 2 часа каждый раз :/
Хоть бы сейчас не запролся
#opsec

2025-12-16

Hey #OPSEC and #Infosec folks…. Something weird happened to a friend and I want a second opinion. This weekend, they received a creepy message from an unknown phone number from the same area code that said….

“Hey , [Firstname] did I just see you crossing [major street in their neighbourhood]?”

Clearly, the person who sent it knew their name, approximate location where they lived, and their mobile phone number, and provided zero info about who they were, and never followed up.

To me, this feels like some sort of confirmation attack — verifying the number is active, the name and location of the recipient….

Is this a known thing, or is my OPSEC dial turned up too far?

Edit: Angle brackets replaced with square brackets…. Damn HTML.

EDIT2: After some digging on the incoming number, it turns out it was someone they hadn't heard from for 5+ years. So yeah, my OPSEC dial was turned a little too far.

2025-12-16

It's funny seeing people talk about multiple decades old #OPSEC rules (that no longer apply) WITHOUT them even being able to follow the most fundamental two rules of OPSEC that even Fight Club got right:

Rule 1 and 2: You don't talk about the Fight Club [aka. the operation].

Literally get your basics right before you worry about anything else...

2025-12-15

A cautionary tale for those who rely on messaging apps for secure communication. “Super secure” MAGA-themed messaging app leaks everyone’s phone number…

ericdaigle.ca/posts/super-secu #messagingapp #security #Converse #SMS #OpSec

Calling all paperscfp@callingallpapers.com
2025-12-15

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst