#unencrypted

N-gated Hacker Newsngate
2025-03-18

🤖📧 Oh no, a fumbled by sending sensitive data via email! 🚨 But don't worry, Register's bot has you covered with a polite "403 forbidden" ✋—the perfect shield against your curiosity. 😂👌
theregister.com/2025/03/17/dog

Gea-Suan Lingslin@abpe.org
2025-02-27

小紅書的明碼 (未加密) 傳輸

之前 TikTok (國際版的抖音) 在美國的事情,所以有不少人跳去小紅書,所以才有歐美的 security company 去研究小紅書的問題:「TikTok alternative RedNote (Xiaohongshu) fails basic security measures」。

好久

blog.gslin.org/archives/2025/0

#API #Computer #Murmuring #Network #Security #Service #Social #Software #app #encrypted #privacy #rednote #security #unencrypted #vulnerability

2025-02-25

You wouldn’t hand a stranger your bank info, your medical records, or a list of your fears. But every time you accept cookies, leave GPS on, or use #unencrypted messaging, you are handing that #data over.

#Privacy isn’t about secrecy - it’s about agency. Know what’s being taken from you.

Demand digital boundaries.

#KeepDataPrivate #dataprivacy #Snooping #privacyMatters #DigitalBoundaries

2025-02-09

#DeepSeek #iOS app sends data #unencrypted to ByteDance-controlled servers - Ars Technica

Apple's defenses that protect data from being sent in the clear are globally disabled.
> that’s globally disabled within that specific app
#bytedance #China #privacy #encryption #security

arstechnica.com/security/2025/

Kevin Karhan :verified:kkarhan@infosec.space
2024-12-08

@AdminKirsty @delta nodds in agreement

Add to that there are sufficient tools that allow for #secure, #E2EE #communication.

  • Like: Even if they don't like #PGP/MIME there's nothing that prevents them from supporting #XMPP+#OMEMO or having any #secure means to communicate.

I do go out of my way to implement better alternatives to existing bad option...

TBH, #unencrypted and thus #insecure communication should disqualify every #company and #organization as a matter or principle and it's high time #GDPR & #BDSG make support for proper #encryption mandatory, regardless if #2FA or general communications!

2024-10-27

1. Tr^mp's lawyers did not dispute anything disclosed in the new filing. 2. If he believed overturning the election was part of his official acts, why was he using a burner phone routed outside of the U.S., unencrypted? 3. How many countries may be planning to blackmail him as a result of this #security #breach, or others?
#AdamCochran #Smith #filing #burner #phone #SpamRiskEgypt #EspionageAct #indict #espionage #risk #blackmail #foreign #intelligence #unencrypted #official #act #SCOTUS #king

Bullet points about the recently unsealed Smith filing: >Trump used a burner phone, routed through a foreign coutnry to contact MI house speaker. >He pressured the speaker in this off-book call. >Speaker McCarthy knew about the burner phone. >The phone showed up as "Spam Risk Egypt" on caller ID. 
If the Presdient thought his attempt to overturn the election and forge elector documents were legitimate "official acts" why was he using an insecure, foreign-routed burner phone for these calls? How many other sensitive calls did the former President have on this unencrypted line with co-conspirators, that could now be used as blackmail against him, by any foreign nation which may have tapped that line? (And before the reply bots get here, let me remind them: Trump's legal team did not disupte the authenticity of *anything* unsealed from the Smith filing.)
2024-09-28

Over 600 million #Meta #passwords stored in plain text

The issue was first uncovered in 2019 when #Facebook admitted to "hundreds of millions" of passwords being stored #unencrypted. Facebook said that the passwords were not available outside of the company — but also admitted that around 2,000 engineers had made about 9 million queries on that user database
#privacy #security

appleinsider.com/articles/24/0

2024-09-20

@root@mindly.social @mindly.social@mindly.social

We have received a bunch of empty Admin Reports from
@mindly.social and our reaction have been to Suspended their system account to avoid further spam from them, and Silenced them to help keeping they users of the grid. This is also done to protect the fediverse against CloudFlare's tracking and spying on users and absorbance of [PII](/articles/MTX-A-79/PII) data

![Silenced mindly.social by matrix.rocks](image.png){width=280px}

## About mindly.social

A review of their instance shows us a miss configured instance

Host mindly.social
Software mastodon / 4.2.12
Administrator (Unknown) ((Unknown))

When investigating the privacy violating server, we find it is under CloudFlare's control, now I start to get suspicious of the lowlifes running
mindly.com
mindly.social.  3600    IN      NS      duke.ns.cloudflare.com.
mindly.social.  3600    IN      NS      jean.ns.cloudflare.com.
mindly.social.  300     IN      A       188.114.97.3
mindly.social.  300     IN      A       188.114.96.3

Taking a look at the MITM infected instance true a Virtual machine running on Open Source, reveille the following accounts to hang out to dry for spamming fediverse admins with their nonsense of forwarding empty spam reports with no comment or explanations on why a post was reported, The only thing we can come to thing of, is it some newly converted Israelis super puritan Jews who tries to overtake the new world order by their terrorism.

* contact@mindly.social
*
@root@mindly.social
Mindly.Social aims to be a friendly, non-topic specific community focused on spreading positivity, expanding your knowledge and experiences, and just being plain old happy on social media for once.
What?? you just proven the opposed by attacking matrix.rocks with spam bombs

## The false reports
All notes mentioned below, is marked with CW and the attachment are marked as sensitive, all in compliance with our
rules and guidelines.

-
https://matrix.rocks/notes/9y8vfzoqyw reported eight time...
![9y8vfzoqyw](image1.png)

Welcome to the
#hallofshame of #stupidity

@matrix.rocks

## tags
#MindlySocial #admin #antiprivacy #cloudflare #cloudflarecyberattack #fediverse #hallofshame #infosec #internetsecurity #mastodonadmin #mastodonadminspammers #mastodonmoderation #mastodonreportspam #mastodonspam #mastodonspamadmins #MITM #moderators #privacy #reportspam #reportspamming #suspended #tracking #unencrypted

Issue:
https://kb.mypdns.org/issue/MR-3 #nsfw #bikini

2024-09-20

@root@mindly.social @mindly.social@mindly.social

We have received a bunch of empty Admin Reports from
@mindly.social and our reaction have been to Suspended their system account to avoid further spam from them, and Silenced them to help keeping they users of the grid. This is also done to protect the fediverse against CloudFlare's tracking and spying on users and absorbance of [PII](/articles/MTX-A-79/PII) data

![Silenced mindly.social by matrix.rocks](image.png){width=280px}

## About mindly.social

A review of their instance shows us a miss configured instance

Host mindly.social
Software mastodon / 4.2.12
Administrator (Unknown) ((Unknown))

When investigating the privacy violating server, we find it is under CloudFlare's control, now I start to get suspicious of the lowlifes running
mindly.com
mindly.social.  3600    IN      NS      duke.ns.cloudflare.com.
mindly.social.  3600    IN      NS      jean.ns.cloudflare.com.
mindly.social.  300     IN      A       188.114.97.3
mindly.social.  300     IN      A       188.114.96.3

Taking a look at the MITM infected instance true a Virtual machine running on Open Source, reveille the following accounts to hang out to dry for spamming fediverse admins with their nonsense of forwarding empty spam reports with no comment or explanations on why a post was reported, The only thing we can come to thing of, is it some newly converted Israelis super puritan Jews who tries to overtake the new world order by their terrorism.

* contact@mindly.social
*
@root@mindly.social
Mindly.Social aims to be a friendly, non-topic specific community focused on spreading positivity, expanding your knowledge and experiences, and just being plain old happy on social media for once.
What?? you just proven the opposed by attacking matrix.rocks with spam bombs

## The false reports
All notes mentioned below, is marked with CW and the attachment are marked as sensitive, all in compliance with our
rules and guidelines.

-
https://matrix.rocks/notes/9y8vfzoqyw reported eight time...
![9y8vfzoqyw](image1.png)

Welcome to the
#hallofshame of #stupidity

@matrix.rocks

## tags
#MindlySocial #admin #antiprivacy #cloudflare #cloudflarecyberattack #fediverse #hallofshame #infosec #internetsecurity #mastodonadmin #mastodonadminspammers #mastodonmoderation #mastodonreportspam #mastodonspam #mastodonspamadmins #MITM #moderators #privacy #reportspam #reportspamming #suspended #tracking #unencrypted

Kevin Karhan :verified:kkarhan@infosec.space
2024-09-18

@CStamp @persagen whilst it's easy to attribute #Unit8200 for that, I'd say this is a too easy kind of explaination as it would be in the best interest if the #IDF to keep enemies like #Hezbollah in blissful ignorance about their #vulnerable #tech whilst maximizing #SIGINT effectiveness by not giving them a reason to implement secure #comms.

To me that sounds like a project some recruit of that unit would've to plan as a means to qualify for membership of that unit.

  • It doesn't make sense to pull that #PagerHack off given it's quite newly deployed (older batteries would've more reliably and faster gone critical due to #Overdischarge!) and having pulled this #exploit also means Hezbollah will clearly fix those issues, starting with devices using #NiCd or #LiFePO4 batteries if not employing proper #E2EE instead of using insecure & #unencrypted #POCSAG...

But since I'm not getting paid for fixing that shitshow AND don't work with or for terrorists (!!!) I won't plug any projects that would've prevented this...

@marcan
Be careful out there. Its amazing that we use #email, #unencrypted email, for business purposes.

no personal and private information should ever be put in an email that travels in the clear; no account numbers, bdays, transaction info etc.

We need to demand that corps provide their #publicKey and accept our public key before we do business with them.
or
at least demand that they use an encrypted email service.

Learn about public/private key #encryption it's not that hard.

Bebef 🦦🇪🇺🏴‍☠️🏳️‍🌈🏳️‍⚧️🚙🐼🥦🚩🏴Bebef
2024-07-09

When your force you to disable and do everything .

That's just to/from the cloud VM. Everyone else on the planet can do whatever they like, of course. The policy is just forced on the owners of the VM.

BUUUUUT everything is great because it's compliant and that is the MOST thing!

Tadaa 🎉🎉🎉

ipv6rsipv6rs
2024-07-04

is a giant [1] that can read all of your that you send to websites that use CloudFlare (almost all of them) including . It's also a central point of to the Internet [2].

Cloudflare is the exact opposite of .

[1] blog.ipv6.rs/understanding-tls

[2] blog.cloudflare.com/cloudflare

2024-06-06

Another common attack is , where the attacker watches DNS traffic between a and a , collecting the client's .

This is a serious problem for user . The reason this is possible is that DNS was originally .

In order to be a starting point for the protocols that build on top of it, DNS needs to be both & .

2024-05-13

@bascule @matthew_d_green

Exactly !
This is, what 's
about is all about. and are worldwide accessible at any given for the , while their - are pretty well hidden for normal .
They do a for and , but call out Others for doing more in this . . It's a fucking .

Kevin Karhan :verified:kkarhan@infosec.space
2024-04-22

@BenjaminHCCarr IMHO #HTML-#eMails should be banned by law - like any #unencrypted #communications should be #illegal...

Kevin Karhan :verified:kkarhan@infosec.space
2024-03-08

@kaiengert @map Yeah, I'm aware of @delta / #deltaChat and other tools like it...

The Idea I have is to force all eMails to be encrypted in the sense of #PGP/MIME and/or S/MIME!

Such in that it bans all #unencrypted #eMails!

Kevin Karhan :verified:kkarhan@mstdn.social
2023-11-20

@hllizi It's 2023 and @thunderbird has #PGP/MIME built in.

There's no excuse for having #unencrypted #eMails except (catering to) lazyness (of others) to properly configure their setup.

Kevin Karhan :verified:kkarhan@mstdn.social
2023-10-31

A little personal post I should propably pin:

Don't sent me any links/invites to #centralized, #SingleVendor / #SingleProvider #Chat or whatever sites/services.

I WILL IGNORE THEM!

If you want to contact me, you'll find all the info you want on my profile.

To protect against #Spam, all #unencrypted messages/eMails get automatically filtered as junk on server-side.

If you want a reply, add your #Pubkey to those.

Thanks for your attention!

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst