EINGFOAN  

@eingfoan@infosec.exchange
226 Followers
270 Following
2.8K Posts

Once IT architect now in cyber.


Don’t forget to 
donate to keep this place ad free: https://liberapay.com/Infosec.exchange/ 
Or donate to mastodon
 https://www.patreon.com/mastodon/
And thank @jerry for his great work here.

🇪🇺🇦🇹 EU citizen

Fulltext search enabled via tootfinder

My #windowsphone 8 lockscreen in 2012 looked something like this photo I found. New nice Bing wallpaper every day, next calendar event over the full with of the screen (or just nothing), icons if there were missed calls, unread sms, unread email.

In 2025 I still cannot achieve this on #iOS . The calendar widget shows "No events" text instead of hiding, no way to add counters for missed calls or unread sms.

The iOS response to everything seems to be "here is a ton of notifications all at once, have fun".

I hate notifications, I do not allow alert notifications for apps, just badges for a few important apps so the Windows Phone approach was just ideal for me.

Passkeys: Microsoft drückt Neukunden Anmeldung ohne Passwort auf

Microsoft setzt die Abschaffung von Passwörtern weiter fort. Neue Microsoft-Konten sind jetzt standardmäßig passwortlos. 

https://www.heise.de/news/Passkeys-Microsoft-drueckt-Neukunden-Anmeldung-ohne-Passwort-auf-10369464.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon

#IT #Microsoft #Passkey #news

Passkeys: Microsoft drückt Neukunden Anmeldung ohne Passwort auf

Microsoft setzt die Abschaffung von Passwörtern weiter fort. Neue Microsoft-Konten sind jetzt standardmäßig passwortlos. 

heise online
Microsoft sets all new accounts passwordless by default

Microsoft announced that all new accounts will be "passwordless by default" to increase their level of security.

Security Affairs

Liebe Susi, lieber Uwe! Euer kleines Papierboot hat es bis zur Prießnitzmündung geschafft. Meine Tochter (9) hat es kurz vor 18 Uhr vorm Ertrinken gerettet, es hatte schon leichte Schlagseite.

Wir senden euch liebe Grüße aus der Neustadt, Experiment geglückt!

Are you focusing on the important parts of cybersecurity first?

It's critical to ruthlessly prioritize in cybersecurity because there is an infinite number of ways that attackers could possibly attack your systems.

What you need to spend time thinking about is what is easiest and most effective for the adversaries, not what is possible.

You can use the 3 P's to remember what to focus on first:

1. Prevalent

2. Proven

3. Possible

Never go to the next stage until you are done with the first stage.

If you are tempted to research that cool new technique you just heard 'nation state X' did against a high profile target but you haven't effectively mitigated password spray or pass the hash, STOP!! 🛑⛔🚫🛑🛑!!!

…go back and take care of those basics before wasting your precious time and effort on something that is likely not to affect you.

The attacks you will see most are the ones that will get the job done easiest and most reliably for attackers:

1. Attackers will prefer prevalent well-known methods with a successful track record

2. They will fall back on other proven methods that are also likely to work

3. …and most will explore other potential options if needed (and if they have the skills/resources/funding/etc. to develop those into usable attack methods).

This slide visual is from the upcoming Security Matrix standard from The Open Group that captures this implication.

For a copy of this slide, see the downloadable MCRA deck - https://aka.ms/MCRA

For a webinar discussing the security matrix and other current and upcoming standards from The Open Group, see https://aka.ms/TOG-standards

Microsoft Cybersecurity Reference Architectures (MCRA)

Detailed technical reference architectures for multicloud cybersecurity including Microsoft and third party platforms

UN Gives the Encrypted Open-Source Office Suite CryptPad a Try - FOSS Force

The United Nations became the latest large organization to embrace CryptPad when it used it to replace Google Forms.

FOSS Force

Ein starkes Passwort - so wichtig ... PS: Der Welttag des Passworts geht uns natürlich alle an.

#WelttagDesPassworts #ZweiFaktorAuthentifizierung #Internet

🤣 I laughed entirely too hard at this.
You cannot secure an environment without first gaining the trust of those who you are trying to secure.