After signing out of Netflix on the hotel TV before going to sleep, I browsed around all the various internet-connected apps and streaming services…

…and logged out of probably 6 or 7 other accounts (no name duplicates) in various apps.

Wild that people just leave these connections “lying around” all over the place.

Probably worthless me signing those other people’s accounts out, but still…

#internetsecurity #digitalsecurity #digitalbreadcrumbs #badsecurity

@signalapp Signal IMO has bad security because when someone decides they are not interested in an overpriced, underperforming service of "phone number" and stops using their SIM, they cannot deregister the number from Signal and the new owner of the number either can hijack their Signal account, or people may be blocked from using newly purchased SIMs with Signal.

Also, authoritarian regimes IMO can temporarily transfer a number into a provider's internal SIM in order to hijack a Signal account and impersonate a dissident against another dissident, facilitating abduction, torture and murder.

I feel

c o n t e m p t

towards Signal when it is designed this way.

#badsecurity #incompetence #signal #phonenumberasidentity #security #SIM #contempt #securityhole #securityflaw #attack #hijacking #torture #murder #abduction #authoritarianism #regime #authoritarian

I'm not a hacker of any kind, but I was able to use native tools in Chrome to remove the "security measures" in place so I could remove the disabled copy/paste.

But then I get my account created and I get logged in and then I find that the site doesn't have 2 Factor Authentication as an option for actual security?

So.. I just thought I would share that experience.

#NotAHacker #BadSecurity

Today, #Simplii is driving me nuts. Apparently, this is not a strong enough password.

No wonder people write them down on a post-it on their monitors.

#Security #BadSecurity #Passwords #on #Postits #SimpliiFinancial #Banks #CyberSecurity #CIBC

What's up with these potential douche bags?

#403
#Cetera
#assholes?
#BadSecurity?
#AreYouTools?
#VPNMuch?

Are we really still doing security questions like this???
#BadSecurity https://t.co/VUuMUN8NwQ

— Daniel Glenn (@danielglenn)
Jul 1, 2024

Daniel Glenn (@DanielGlenn) on X

Are we really still doing security questions like this??? #BadSecurity

X (formerly Twitter)
I opened a ticket at work because a [Mastodon site] in my network of places-to-go-for-news-and-help is blocked by our firewall. Response is “[IT Security has] asked for Manager approval and if the site is necessary to perform their duties. If you can please have ___ send us an approval we can send it to IT Security “

Now the site is not _necessary_ for my job, but it sure is useful. It’s in the same mental bucket for me as Twitter and Reddit, neither of which are blocked.
🧵
#rant #BadSecurity

And it gets worse....
You can't paste a password.... Seriously?

#Broadcom #BadUX #BadSecurity #FuckPasswordManagersRight?

Also just the startling causality of so many things. I’ve been sitting outside this one empty manager’s office for 10 minutes and there’s separate people have gone in, sorted through papers on the desk, pick one up and walk out.

There’s just piles of papers, probably containing a fair amount of PII, just sitting there in plain sight and no one to oversee who sees or takes it.

#BadSecurity #OpSec

It shocks me how bad car dealerships are at OpSec. Or maybe it’s just this one?

I’m sitting here in the waiting area and I can see the unlocked screens of 4 computers that are otherwise unattended. One of them is in the “Finance Office”, with the door wide open and no one else around.

I wonder what someone could get up to if they just walked up and sat down or quickly plugged something into one?

#BadSecurity #OpSec