#PrivateKey

2025-02-06

Don't share your private key online! 😅

#gpg #pgp #ladygaga #privatekey #meme #joke #cybersecurity #MikkoHypponen

Kevin Karhan :verified:kkarhan@infosec.space
2024-12-26

@hon1nbo @foone yeah, but all these things would essentially necessitate a fundamentally incompatible #Fork of the #USB standard, creating #costs, #fragmentation and lessen the likelyhood of success.

  • Not to mention it'll require significant investments in #UserAwareness, #Training and would still have some issues...

I gues a sort-of "Secure HID Port" that mandates proper authentification and does full #E2EE from the Keyboard Matrix / Pointing Device controller up is an option, but you'd have to expect state-sponsored attackers willing to do "Kamikaze" Hacks...

#TLDW: It requires custom silicon and a hard root of trust

infosec.space/@kkarhan/1137164

Kevin Karhan :verified:kkarhan@infosec.space
2024-12-01

@puppygirlhornypost2 @navi And whilst it's easy to blame #GoldenKeyBoot, a leaked #PrivateKey that was impossible to be removed, the problem is that #Windows is architecturally "insecure-able" because any changes necessary to make this not a problem would inherently mean the end for Windows as it's known to most.

  • In fact, everything is done better by #Linux on the #Desktop for almost two decades, which is why classic #Malware isn't a thing on Linux systems.

Shure, you get some #Cryptojacking and some #CMS|es like #WordPress that are constantly being attacked but generally, the way #updates and #distribution of #Software works on Linux Distros for the most part is completely antithetical to Windows.

And anything #Microsoft could do at this point if they weren't horny for money but avtually cared is to scrap Windows and instead invest into #Wine to ease the transition...

A comic with a person sitting in front of their laptop, with either Linux, Windows and macOS.

Thex get a Message: "An Update is available.for your computer!"

Linux User: "Cool, more free stuff!"
Windows User: "Not again!"
Mac User: "Oh, only $99!"
Daniel Böhmerdboehmer@ieji.de
2024-10-25

Why is everyone using #base64 to encode their private SSH keys to store them in masked variables in #GitLab CI?! 🤔

⚠️ GitLab cannot effectively mask your private key in CI logs if you only give it a base64-encoded version of it!

Instead I found a solution that stores the *original* private key format from #OpenSSH in a one-line CI variable and recreates the begin/end markers for a valid OpenSSH identity file with commands inside the CI.

stackoverflow.com/a/79124959/4

#ITsecurity #CICD #privatekey

2024-10-10

📬 Criminal Assets Bureau: Zugriff auf 378 Mio. USD in Bitcoin-Wallets verwehrt
#DarkCommerce #Krypto #Bitcoin #CliftonCollins #CriminalAssetsBureau #Irland #PrivateKey #Wallet sc.tarnkappe.info/84ffe3

2024-03-13

#Tagesschau, 20-Uhr-Ausgabe: Ist da tatsächlich ein nutzbarer privater Schlüssel abgebildet? 🧐 Der ist doch sicher noch mit einem Passwort geschützt, oder?

#security #privatekey

Foto eines Computerbildschirms, auf dem zwei vertikal geteilte Fenster auffallen. Links ein Browser, der "Azure Container Registry Documentation" mit Erklärungen zu "List container images" und "Run image from registry". Rechts eine Konsole, auf der via "cat creds.json" der Inhalt einer Zugangsdatendatei im JSON-Format ausgegeben wird. Diese Zugangsdatendatei enthält eine Eigenschaft "private_key", dessen Inhalt eine ASCII-Zeichenkette ist, die mit "-----BEGIN PRIVATE KEY-----" beginnt und mit "-----END PRIVATE KEY-----" endet.

Private Schlüssel stellen die geheime Information dar, die der Schlüsselinhaber vor der Öffentlichkeit dauerhaft geheimhalten muss, um mithilfe dieses Schlüssels sicher kommunizieren zu können.
2024-01-04

Do you know where your certificates reside when you use AWS ACM with a “Trusted Enclave”?
~~
I was surprised at what I discovered when digging into the details
~~
#AWS #ACM #Certificate #TLS #PrivateKey

medium.com/cloud-security/do-y

Juan-Pablo Paredes 🌀💻🐧jpp4redes
2023-10-20

Contame tu secreto más profundo 🔑📤💬📩

Un usuario solicita a otro su secreto más profundo mediante un servicio de mensajería y como respuesta recibe la clave privada de su conexión ssh
Alan E. Yue (He/Him)alaneyue@infosec.exchange
2023-09-01

That priceless moment (59m 59s) when you realize that your live stream needs to end.
Like, NOW.
😂​

#12words #privatekey #oops

youtube.com/watch?v=0CgT3_gseb

EncryptedFenceEncryptedFence
2023-06-22

📣 Important Update: Starting June 1, 2023, a new rule applies to Standard and EV Certificates! 📜 - certerassl.com/blog/new-privat

Your must be stored in a FIPS 140-2 Level 2 or Common Criteria EAL 4+ compliant device

EncryptedFenceEncryptedFence
2023-05-19

🔐🔑 YubiKey FIPS 140-2 Token: Generate and attest private keys like a pro! 🚀 - certerassl.com/blog/yubikey-ke

Strengthen your security game with this informative read!

2023-05-07

#Intel OEM #PrivateKey Leak: A Blow to #UEFI #SecureBoot #Security

The #MSI #databreach led to the leakage of the Intel OEM private key, which could significantly undermine UEFI’s secure boot security.

securityonline.info/intel-oem-

2023-04-11

Attention gamers! Motherboard maker MSI admits to breach, issues “rogue firmware” alert - Stealing private keys is like getting hold of a medieval monarch's personal signet ring..... nakedsecurity.sophos.com/2023/ #supplychain #ransomware #databreach #privatekey #blackmail #extortion #malware #msi

Kingsley Uyi Idehenkidehen
2023-03-01

@atomicpoet @davidslifka @blaine @mike @fediversenews We (@openlink) provide a product (@youid) that aids user-controlled self-sovereign authenticity and , using existing open standards, in the form of a verifiable credentials generator that emits the following:

[1] Certificate and associated

[2] portable based profile document (i.e., variety) that provides a public paring for item 1 (live example: kingsley.idehen.net/DAV/home/k)

HTML-based Link In Bio oriented portable Profile DocumentEmbedded metadata included in HTML-based profile document generated by YouID.More embedded metadata included in HTML-based profile document generated by YouID.

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst