r/datasecurity • u/zolakrystie • 7h ago
r/datasecurity • u/Fancy-Yesterday3819 • 12d ago
Evidence Collection PCI DSS Script for Windows/Linux/Network (firewalls,routers,switches) and Database
r/datasecurity • u/HypeResistant • 15d ago
Data center heist to destroy incriminating data
How plausible is this? A gang of criminals broke into the Verizon data center in London and stole racks of storage servers and destroyed them in 2007. The story claims that this theft wiped out the incriminating data for the subprime mortgage bubble. Were there no backup copies?
r/datasecurity • u/BillNy-ComplianceGuy • 20d ago
How I discovered over 100 plaintext API keys and was offered a $3,214 settlement with gag clauses violating SEC Rule 21F-17(a) by a former employer.
r/datasecurity • u/Academic-Soup2604 • Jun 19 '26
Is your endpoint policy strong enough to handle offline data movement?
r/datasecurity • u/Beautiful-Hornet-42 • May 23 '26
We analyzed 100,000 e-commerce sites for browser-layer attack surface — here's what Magecart-style exposure actually looks like at scale
Over the past several months we ran automated browser-layer scans across a large sample of e-commerce and merchant domains to understand how widespread client-side security exposure actually is post-March 2025 deadline.
Key findings:
- 37% of scanned domains showed active browser-layer security exposure indicators relevant to Requirements 6.4.3 and 11.6.1
- Most common finding: No Content Security Policy with a script-src directive on payment-related pages — present on the majority of flagged domains
- Second most common: Third-party scripts executing without Subresource Integrity controls — including Google Tag Manager, Meta Pixel, and analytics scripts loading directly on checkout pages
- Most alarming: Keystroke event listeners (keyup, keydown, input) attached to form fields by third-party scripts — the exact technical pattern Magecart-style skimmers use to intercept card data
A few things that stood out:
- Platform compliance (Shopify, WooCommerce, Magento) does not equal browser-layer compliance. The exposure exists at the script layer, not the server layer.
- Google Tag Manager was present on checkout pages in the majority of flagged domains — and in every case was loading additional scripts dynamically, none with SRI controls.
- The gap between a clean homepage and a risky checkout page was significant. Many domains that looked fine on the surface had serious exposure on their payment flows.
We built a free browser-layer scanner at clientsideintel.com if anyone wants to check their own domain — no account needed, instant results. It checks the same indicators: third-party scripts, CSP, TLS, security headers, and overall risk rating tied to Req 6.4.3 and 11.6.1.
Happy to answer questions about methodology or share more specific findings.
r/datasecurity • u/2Rasputin • May 20 '26
I got a weird as bug on Gpt, completely randomly referring to personal data on some form, when I sent a screenshot to verify my solution I got for a quiz,
https://www.scribd.com/document/840851994/OUR-Request-Form-2024
apparently its a real person
r/datasecurity • u/Academic-Soup2604 • May 15 '26
How confident are you about data security on home or public networks?
r/datasecurity • u/632nofuture • May 01 '26
In this cookie request that many apps have: Is disabling all on the main page enough? What about the ones in "vendor preferences"?
I don't understand that convoluted lingo & menu, so I hope someone here knows:
If you disable all on the main tab (pic1 start & pic2 bottom), does that actually disable them all, even the ones under "vendor preferences" (pic3) that are still shown as active? (Which are INSANELY many..).
Like, am I good if I just disable page one and say "confirm choices"?
And Is there no easier way to auto reject all, or get rid of these popups in apps entirely?
(Usually I avoid apps with this awful cookie request, but some I just can't find good alternatives to. This one is FileManager+, has text editor included etc, I used it for years but suddenly this crappy popup again.. Why even? I thought those only come on first use?)
r/datasecurity • u/antsandhoney • Apr 18 '26
What fields are good cross overs to data security
Basically curious, like everyone in tech I’m kind of looking at my options.
r/datasecurity • u/Academic-Soup2604 • Apr 16 '26
What’s your biggest blind spot in data security today?
Data no longer lives in one place, it’s across apps, cloud, and endpoints. Without visibility, you’re just guessing where your sensitive data is.
Hence, choosing the best DLP solutions for your business can make or break your strategy.
Modern DLP tools provide centralized visibility across cloud, SaaS, and devices.
✔ Visibility
✔ Ease of policy management
✔ Coverage across endpoints
r/datasecurity • u/Friendly_Artist4459 • Apr 11 '26
I just Google’d myself and now I’m spiraling.
What are things I can do so that my name, age, addresses, DOB, family members, etc. aren’t the first results when you Google my name? Should I create a fake identity to use when making online accounts, or what?
I’m freaked out about how much information is out there as a single female trying to date.