3/n #infosec #IdentityTheft

Lessons learned (a growing list):
- Trust your instinct! If something feels off, stop whatever you are doing. Exit. Take time to think carefully before you act. There is no downside to this.
- If it involves your personal identifiable information (#PII) then you should absolutely not reveal it without rock solid proof of who you are talking too, the security of who or what is receiving the info, and so on. Small puzzle pieces and complete the picture for the thieves.
- Multiple malicious actors may be involved, tricking you by various means into verifying each others’ credentials.
- Avoid linking accounts at multiple institutions to each other. It makes it easy for the bad guys to get in. Detach and compartmentalize everything that is sensitive.
- Have very strong password manager and encryption on your devices. NEVER have PII or sensitive financial information stored as plain text on any of your digital devices.

Ugh. There is a lot more that can't be shared now. I just wanted to take advantage of a teachable moment. Peace and good luck!

Mass Assignment Vulnerability Exposes Max Verstappen Passport and F1 Drivers PII

https://ian.sh/fia

#HackerNews #MassAssignment #Vulnerability #MaxVerstappen #F1Drivers #PII #Cybersecurity #DataBreach

Hacking Formula 1: Accessing Max Verstappen's passport and PII through FIA bugs

We found vulnerabilities in the FIA's Driver Categorisation platform, allowing us to access PII and password hashes of any racing driver with a categorisation rating.

Hacking Formula 1: Accessing Max Verstappen's passport and PII through FIA bugs

Obviously, this is not #disinformation given the #facts and circumstantial evidence.

  • TELL ME WHERE I'M WRONG!

I do expect the reinstatement of my original post!

@cartocalypse @sigmasternchen @pallenberg Gibt zuviele Indizien:

#PII wie #Rufnummer wird abgefragt; Geolokation bzw. Service-Beschränkungen aufgrund dessen erfolgen

Aus den #USA = #CloudAct greift

Struktur und Setup ähnelt #ANØM und "Ausfälle" erinnern an #EncroChat .

Wenn @signalapp so sicher wäre wie beworben dann wären #Moxie und @Mer__edith seit Jahren in #Beugehaft wegen #Missbrauch durch Nutzer*innen.

  • Ich kann die ganze Woche weiter machen, aber die Tatsache dass #Signal durch ein AWS-#Datacenter down geht zeugt von schlampiger Infrastruktur und Mehr Geld als Verstand!

Jedenfalls ist es kein deut besser als #CryptoAG - technisch sogar schlechter denn letztere versuchte wenigstens nicht dauerhaft Kritiker*innen zu gaslighten sondern wurde in der #Schweiz hinter ne #Tarnfirma gepackt.

Es stinkt jedenfalls wie #OperationIronside aka. #OperationTrøjanShield!

byte::Arc<Eepy> :neobot_sign_beep: :rabiesPride: :blobhaj_flag_nonbinary: (@byte@awawa.club)

signal: we are so secure it’s unreal also signal: burgerreich jurisdiction and a fucking AWS that broke again and took it with it lol, lmao even. no matter how good your encryption is, why would ...

»The Privacy Theater of Hashed PII:
A 2020 MacBook Air can hash every North American phone number in four hours«

Good article that clearly shows that only hashing alone is not yet data safe. That's where HMAC belongs at the SHA-2 min. but also not to save passwords and the same.

🤷 https://matthodges.com/posts/2025-10-19-privacy-theater-pii-phone-numbers/

#usphonehack #privacy #hash #hashtag #itsecurity #phone #america #macbook #pii #saas #md5 #hmac #sha2 #itsec #it

The Privacy Theater of Hashed PII

It takes a 2020 Macbook Air four hours to hash every North American phone number

Matt Hodges

@DarkWebInformer why would anyone use #Telegram instead of #IRC over #Tor?

Seriously, #Signal / @signalapp is bad and everyone who relies on @Mer__edith et. al. to not break when handed a duely issued warrant (or being held at gunpoint) by #US authorities is as dellusional as the users of #ANØM and #EncroChat!

There's no valid excuse to collect #PII like a #PhoneNumber!

  • And Signal being not just able but entirely willing to "restrict services" based off the presumed location of the users is just a big red flag.

If they took #Security seriously, they'd use #XMPP+#OMEMO over #Tor and let users have 100% #SelfCustody of all the keys as well as completely #decentralize, including the ability to #SelfHost on @torproject.

https://www.youtube.com/watch?v=tJoO2uWrX1M&t=887s

Signal's Terrible MobileCoin Betrayal

YouTube

#Hackers #Dox Hundreds of #DHS , #ICE , #FBI , and #DOJ Officials

A group of hackers from the Com, a loose-knit community behind some of the most significant data #breaches in recent years, have posted the names and personal information of hundreds of government officials, including people working for the Department of Homeland Security (DHS) and #Immigration and Customs Enforcement (ICE).
#privacy #pii

https://www.404media.co/hackers-dox-hundreds-of-dhs-ice-fbi-and-doj-officials/

Hackers Dox Hundreds of DHS, ICE, FBI, and DOJ Officials

Scattered LAPSUS$ Hunters—one of the latest amalgamations of typically young, reckless, and English-speaking hackers—posted the apparent phone numbers and addresses of hundreds of government officials, including nearly 700 from DHS.

404 Media

@Jerry FOR WHAT FUCKIBG PURPOSE DOES @signalapp EVEN WANT #Location DATA BUT #Spying ON IT'S USERS?

Also it's not even #FLOSS (why else is there no #Signal #App on @fdroidorg ?)

  • My verdict is that Signal - like #ANØM - is a #HoneyPot… I don't have evidenye - yet - but so far my track record has been excellent…
Pii(Awesome City ClubのPORIN)、新曲「SPIRITUAL;」配信リリース | Daily News | Billboard JAPAN

 PORIN(Awesome City Club)のソロプロジェクト・Piiが、2025年10月22

Billboard JAPAN