Security learner, interested in everything.
| Keybase | https://keybase.io/ldurufle |
| Keybase | https://keybase.io/ldurufle |
Just signed the papers....
There may be no future, but there will be another fwd:cloudsec.
June 30th - July 1st 2025 in Denver CO
Some possible good news for a change: T-Mobile settled with The Federal Communications Commission (FCC) and agreed to pay a paltry $31.5 million over multiple data breaches that compromised the personal info of millions of US consumers.
But that's not the good news: Under the settlement, T-Mobile has agreed to require multifactor authentication for their bajillion employees.
We'll see if and how soon this happens, and if it's decent multifactor. It's still progress. Last year I reported that three different criminal SIM-swapping groups had phished or breached access to T-Mobile employee accounts in more than 100 separate incidents throughout 2022.
It's unclear whether T-Mobile's competitors will be held to the same standard.
By me:
Chief among them: mandatory resets, required or restricted use of certain characters, and the use of security questions
🚀Introducing OpenRelik: Open-source platform for digital forensic investigations. Modular workflows, collaboration, central artifact repository and easily extendable to support new tools in a clean, easy to use interface.
Community discussion: https://github.com/orgs/openrelik/discussions/1
C’est une histoire abracadabrante que raconte la société de sécurité watchTowr Labs. Les chercheurs ont en effet réussi à s’emparer de l’ancienne adresse utilisée pour les requêtes WHOIS du domaine de premier niveau MOBI. La manipulation, qu’ils décrivent comme très simple, met en évidence ce type de danger pour les TLD (top-level domains). Les chercheurs […]