😆 this is excellent #TheCrux @daedalus

"We take security seriously!!
Cover up that incident with this handy sticking plaster."

https://www.redbubble.com/shop/ap/174240626

#infosec #slop #security #nosecurity

We Hacked Burger King: How Authentication Bypass Led to Drive-Thru Audio Surveillance

Critical authentication bypass vulnerabilities in Restaurant Brands International's assistant platform allowed complete control over 30,000+ Burger King, Tim Hortons, and Popeyes locations worldwide - including access to customer drive-thru audio recordings.

New Zealand Company’s ‘Impossible-to-Hack’ Security Turns Out to Be No Security at All

Teammate App had a publicly exposed database and told me to stop harassing them after I emailed them about it.

The Hub of Stupi.. *misconfigs
Planes, Ferries and Automobiles - The Code Lab

Thoughts and experiments on software, security and better coding practises.

1 in 2 people in France have data stolen in massive cyberattack

One in two French people’s data was stolen in a major cybersecurity breach - the largest ever in France - leaving 33 million at risk.

euronews
@toxtethogrady I never completely believe any article on intel...we do not know what we do not know, until we do [often by accident].#camo #balllons #LeakedDocuments #NoSecurity

Bonne nouvelle,

À dĂ©faut que le feu vert ne soit pas officiellement donnĂ©, nous sommes trĂšs fiers de voir une dĂ©cision ayant un impact positif sur la sĂ©curitĂ© des donnĂ©es de plus de 190 000 travailleurs au QuĂ©bec.

Toute application/entreprise de pointage mobile devra : “... obtenir une certification de sĂ©curitĂ© reconnue au Canada (ISO 27001, audit de type SOC 2 - types 1 et 2 ou CyberSĂ©curitaire Canada). À dĂ©faut, l’application de ces fabricants ne peut ĂȘtre utilisĂ©e conformĂ©ment au texte de la convention rĂ©sidentielle. Les donnĂ©es recueillies par l’application doivent ĂȘtre conservĂ©es au QuĂ©bec.”

PrĂ©sentement, il semble qu'une seule entreprise ait une certification ISO 27001 et ce n'est pas celle citĂ©e dans l’article, soit Mobile-Punch. De plus, la majoritĂ© si ce n'est pas toutes ses entreprises n'ont aucune Ă©quipe de sĂ©curitĂ© pour gĂ©rer les donnĂ©es de centaines de milliers de travailleurs.

Ainsi, avec ce jugement, nous verrons une augmentation de la sécurité dans nos entreprises au Québec ce qui est une excellente nouvelle pour tous!

https://www.journaldequebec.com/2023/03/23/feu-vert-a-limplantation-de-lappli-qui-permet-de-puncher-en-ligne

#polqc #polcan #hacking #certification #cybersecurite #cybersecurite #NOSECURITY #quebec #syndicat #travailleur #construction #mobilepunch #pointage #pointagemobile

Feu vert Ă  l’implantation de l’appli qui permet de gĂ©rer ses heures de travail en ligne

Une forte majorité de travailleurs de la construction disent aimer Mobile-Punch.

Le Journal de Québec

Mi chiama un cliente dicendo che non riesce ne a ricevere ne a inviare la posta... Vedo che effettivamente Evolution su (PopOS 20.04) rifiutava l'handshake TLS... Poi scopro che la versione e' la 1.0 e il altri casi la 1.1....

Deprecata oramai da mezzo mondo... Cercando di far un mezzo revert di GNUTLS perche altrimenti oltre 30 caselle email erano inutilizzabili ho scoperto un ragazzo con problemi simili. Buona lettura

https://blog.reyboz.it/2020/04/03/fix-evolution-and-aruba-tls-error/

#boycottAruba #nosecurity #cheservizioe

Fix Evolution and Aruba TLS error

Se per pura sfiga stai usando Aruba - il triste ma fortunato provider di servizi italiano - e lo stai usando per della posta elettronica, e vorresti usare il client GNOME Evolution, e ti funziona perfettamente la ricezione della posta ma porcalamiseria quando provi ad inviare ricevi l'errore: TLS handshake: A packet with illegal or...

Reyboz Blog
123456 Is the Most Used Password for the 5th Year in a Row

For the 5th year in a row, "123456" is most used password, with "password" coming in at second place. Even in the wake of a constant stream of data breaches, hacks, and ransomware attack reports people continue to utilize weak passwords that not only put their information at jeopardy, but also their organization's data.