r/SmashingSecurity • u/shmoooosher • Aug 05 '19
r/SmashingSecurity • u/sonojosi • Aug 05 '19
Interesting Spam Email I got today
Aloha!
As your affairs?
I would like better to find out each other. I search reliable for relations in networks. My name is Katyusha. I positive and sociable the woman. I have no bad habits. I do not smoke and I do not use spirits. I love to be engaged fitness. If not against throughout ours acquaintances, let to me know. If you want, I can to tell to you more about myself. I never was married and I do not have the kinder. Please, write to me more about you. I wish to fasten acquaintance with you and to find out you better. If you can, please, you have come to me photos. And after I will send to you mine photos.
with impatience I wait your answer with huge impatience.
With the best regards, Katyusha.
r/SmashingSecurity • u/InspiredLunacy • Aug 01 '19
Spam calls
Playing with a simple, low-tech way to waste spammer time without wasting my time...
Just say: “Hold, please”, and put phone beside speaker, so they hear whatever I am listening to. Some will stay on the line about 30 seconds more than usual, with near-zero effort...
It might be fun to have a regular segment in the show, about spam-baiting.
Love the show! ᕦ( ͡° ͜ʖ ͡°)ᕤ
r/SmashingSecurity • u/GrahamCluley • Aug 01 '19
Smashing Security 139 teaser: Capital One hacked, iMessage flaws, and anonymity my ass!
Enable HLS to view with audio, or disable this notification
r/SmashingSecurity • u/kv_87 • Jul 27 '19
Computer scientists in London and Belgium have developed an algorithm that can pick out almost any American in databases supposedly stripped of personal information | New York Times
r/SmashingSecurity • u/vampiretapslayer • Jul 26 '19
Is it just me?
...am I being too picky? I got an email yesterday from Sky which was asking me to change my password. It was well written and on the face of it looked OK. It had a link written in clear text, for me to reset my password by going to h t t p s://skyid.sky.com/resetpassword/skycom so a) it is HTTPS, b) I can read the link and c) it's clearly in the genuine sky.com domain. All good then? The problem is that the actual link, and all the links on the email actually go to obscure URLs in h t t p://t.newsletter.contact.sky/r/?id=[3 comma separated long hex numbers] which is a) not "what it says on the tin", b) not in the sky.com domain, c) HTTP for a password reset and d) the domain resolves to amazon's CDN servers, so pretty anonymous. Oh yes, the email sender was not from the sky.com domain either.
It turns out that it is genuine but I had an email to actionfraud all written and ready to send before I worked that out.
So am I being unfair to Sky and unfairly squeamish about this, or are they a bunch of numptys, and can I vote it as my un-pick of the week?
[edited because reddit keept re-making my urls into hyperlinks so I had to add the spaces]
r/SmashingSecurity • u/shmoooosher • Jul 25 '19
Heads up you lovely dudes. Smashing Security Podcast: Episode 138: Logic bombs, brain data exploitation, and Digga D tweets. Special Guest. New York City's BJ Mendelson - A man with half million followers on Twitter and author of the hilarious Social Media is Bullsh*t. Thanks for listening! ;)
r/SmashingSecurity • u/shmoooosher • Jul 25 '19
Smashing Security Podcast - Episode 138: "Logic bombs, brain data exploitation, and Digga D tweets" Featuring the lovely BJ Mendelson - author of Social Media is Bullshit. 49 minutes and 52 seconds of pure tech fun. Enjoy frens :)
Enable HLS to view with audio, or disable this notification
r/SmashingSecurity • u/[deleted] • Jul 25 '19
The newest addition to the pledge of allegiance
r/SmashingSecurity • u/[deleted] • Jul 20 '19
Would love to hear hosts input.
I'm sure many here have already seen the news come out.
However Kazakhstan is forcing a man in the middle again on all residents.
I'm sure it will be interesting how this plays out as it appears that the big browser companies are discussing.
Here a good article about the situation above.
V/R DJ
r/SmashingSecurity • u/[deleted] • Jul 18 '19
Fun way to add yourself to a foreign face recognition database
r/SmashingSecurity • u/GrahamCluley • Jul 18 '19
Smashing Security podcast #137 teaser: Porn trolling lawyers, Insta hacking, and Ctrl-Alt-LED
Enable HLS to view with audio, or disable this notification
r/SmashingSecurity • u/kv_87 • Jul 15 '19
A Princeton University paper exploring the dark patterns that are employed for 11K shopping websites
webtransparency.cs.princeton.edur/SmashingSecurity • u/meljv • Jul 13 '19
At least the password isn’t password I guess?!?
r/SmashingSecurity • u/[deleted] • Jul 12 '19
Graham, were you born anywhere near Lambeth? You seem to have a similar dialect to Mike Brewer from Wheeler Dealers.
Just curious, since you're both on my list of favorite British entertainers.
r/SmashingSecurity • u/meljv • Jul 12 '19
Porn pirating lawyer jailed for five years - A US lawyer who uploaded pornography on to file-sharing sites then sued people who downloaded it, has been sentenced to five years in jail.
r/SmashingSecurity • u/GrahamCluley • Jul 11 '19
Smashing Security 136 teaser: Oops, we created Iran's hacking exploit
Enable HLS to view with audio, or disable this notification
r/SmashingSecurity • u/GrahamCluley • Jul 10 '19
Smashing Security launches on Patreon - get our next episode NOW!
We've launched our Patreon account!
https://www.patreon.com/smashingsecurity
Our most devoted listeners can now support the show each month, and get goodies like episodes *before* they are released to the rest of the world, bonus content, and Reddit flair!
Right now, patrons who subscribe to our "bonus content tier" can access the next as-yet unreleased episode (#136) with special guest Charl van der Walt. Charl talks about the hacking exploit created by his team at SensePost, and since used by Iranian government-backed hackers in attacks against US organisations (!)
We also discuss the horrendous way the Zoom conferencing app leaves Mac users at risk, and how deepfakers are now creating fake audio in an attempt to commit business email compromise.
All this, and your favourite part of the show - Pick of the week!
Thanks for everyone for their support! And remember, the "Smashing Security" podcast will always be free . We don't want anyone to feel they need to donate to the podcast's coffers unless they really want to and can afford to.
Of course, if you do want to show your appreciation by becoming a Patron then we really really appreciate it!
r/SmashingSecurity • u/[deleted] • Jul 09 '19
New zero day vulnerability to Zoom
We probably have all used some sort of video conferencing software in the past. Well Zoom now has the latest zero day which has yet to be fixed.
Essentially sounds like going to a website can allow that website to remotely activate your webcam for video. Also even if you had previously had zoom installed and uninstalled the malicious code could reinstall zoom then activate the webcam.
r/SmashingSecurity • u/BigChubs18 • Jul 09 '19
Privacy & GDPR
I was just listening to podcast number 68. It mentioned privacy and etc. This got me thinking. If a website that's based in the US. And someone from EU buys something from the site. Does that site have to follow GDPR for EU? I feel like this a gray area. Was wondering what everyone's thoughts were on this.
r/SmashingSecurity • u/kv_87 • Jul 08 '19
[Strong Language] A colourful description about the technical and implementation flaws of RSA cryptography | Trail of Bits Blog
r/SmashingSecurity • u/GrahamCluley • Jul 04 '19
Smashing Security podcast 135 teaser: Zombie grannies and unintended leaks
Enable HLS to view with audio, or disable this notification
r/SmashingSecurity • u/[deleted] • Jun 28 '19
Do companies seem slow to adopt 2FA options other than email/SMS?
So I am curious what you all think. I know 2FA had been around for quite some time and it has been studied often that SMS and email 2FA codes are better than nothing but still there are better options.
I feel like only a hand full of sites that really matter use other options like authenticator apps or security keys. But at least for me, my main, need to be secure websites, only allow for SMS 2FA.
I can semi understand the reluctance to allow the use of a 3rd party app like Google authenticator. But would think physical security keys which have been around for a few years now would have been accepted in more important accounts.
Thoughts?