#opsec

49 posts · Last used 7d

Back to Timeline
eteryu @eteryu@infosec.exchange · Aug 08, 2026
W nawiązaniu do wczorajszego tekstu o tym, że prywatność prosto z pudełka nie istnieje, przypominam moją serię o cyfrowej higienie. Pokazuję tam w praktyce, że bezpieczeństwo to codzienne nawyki. Część pierwsza o odzyskiwaniu kontroli: https://eteryu.space/cyfrowa-higiena-podczas-przerwy-na-kawe-jak-atwo-odzyskac-kontrole-nad-telefonem/ Część druga o izolacji toksycznych aplikacji: https://eteryu.space/cyfrowa-higiena-bez-kompromisow-jak-atwo-odizolowac-toksyczne-aplikacje/ Część trzecia o odcinaniu algorytmów: https://eteryu.space/cyfrowa-higiena-bez-podgladaczy-jak-atwo-odciac-algorytmy-i-zabezpieczyc-zdjecia/ Ta seria będzie kontynuowana. W kolejnych tekstach weźmiemy na warsztat bezpieczne zarządzanie hasłami oraz dywersyfikację danych. Zanim to jednak nastąpi, na blogu pojawi się bardzo ważny wpis tłumaczący od podstaw modelowanie zagrożeń. Zanim go opublikuję, mam dla Was zadanie na start. Zastanówcie się i odpowiedzcie sobie szczerze na jedno pytanie: przed kim dokładnie chronicie swoje informacje? Sprecyzowanie przeciwnika to absolutny fundament, od którego musicie zacząć budowę własnego modelu bezpieczeństwa. #infosec #cyberbezpieczenstwo #prywatnosc #bezpieczenstwo #opsec #higienacyfrowa #threatmodeling #cybersec
0
0
0
eteryu @eteryu@infosec.exchange · Aug 07, 2026
Często powtarzanym mitem w świecie cyfrowej higieny jest przekonanie o magicznej prywatności prosto z pudełka. W nowym wpisie na blogu rozkładam na czynniki pierwsze architekturę microG oraz obietnice popularnych systemów. Wyjaśniam zjawisko teatru prywatności oraz dlaczego poleganie na domyślnych ustawieniach to pułapka. Prawdziwe bezpieczeństwo to nawyki, a nie tylko zmiana oprogramowania. Pełny tekst znajdziecie tutaj: https://eteryu.space/zudzenie-prywatnosci-z-pudeka-dlaczego-podejscie-set-and-forget-to-puapka/ #infosec #prywatnosc #cyberbezpieczenstwo #grapheneos #android #degoogle #cyberhigiena #opsec
8
9
5
PH4NTXM :verified: @PH4NTXMOFFICIAL@infosec.exchange · Aug 05, 2026
Another small improvement to PH4NTXM. The Nuke Kernel now allocates available RAM and zero-fills allocated memory before powering off. The goal has never been to add features for the sake of features. It's to make every session end as cleanly as possible while keeping the implementation simple and reliable. Small changes. Big impact. Thank you. #ph4ntxm #linux #debian #os #live #privacy #security #opsec #infosec #research #tech #technology
0
0
0
PH4NTXM :verified: @PH4NTXMOFFICIAL@infosec.exchange · Aug 05, 2026
Update... Update! PH4NTXM includes now an overall ph4ntxm-health cli, so you can check your identity and more, including score. Almost every important spoofed value is on your screen so you can verify at any mean time that everything is safe and as expected. Thank you! #ph4ntxm #linux #debian #os #live #privacy #security #opsec #infosec #research #tech #technology
0
0
0
Oscar @oscaractual@infosec.exchange · Aug 04, 2026
First known US federal prosecution over a phone's duress PIN: a traveler at Atlanta airport hands border agents a passcode, the device (GrapheneOS, per the indictment) irreversibly wipes itself - and he's now charged with destruction of property to prevent seizure. Up to 5 years. He's pleaded not guilty; a court decides this fall whether destroyed key material counts as "property." The operational lesson isn't about the tool. The tech did its job - the keys are unrecoverable, exactly as designed. Owning it is legal - triggering it during an active search is what produced the charge. A safeguard became a legal problem at the exact moment it was supposed to protect. After 30 years in security ops, my travel rule is simpler: the best defense isn't a wipe button, it's a device with nothing on it. Clean device or clean work profile · only what the trip needs · mail in the browser, nothing offline · company access and VPN after arrival · backups stay home. What you don't carry can't be seized - and nothing gets destroyed. Not just a US thing: under Schedule 7 in the UK, port officers can demand device passwords with no prior suspicion, and refusing can itself be an offence. Source: https://techcrunch.com/2026/07/24/us-accuses-american-of-allegedly-wiping-his-phone-using-a-duress-password-during-border-search/ #opsec #privacy #infosec #grapheneos
0
0
0
GlitchRat @aglitchrat@infosec.exchange · Jul 31, 2026
Hey guys, I'm #newhere ! I'm also a beginner in #opsec #cybersecurity #osint so if you have nice resources to learn please tell me! :linux: I'm using Linux since 2015, the day before Windows 10 release. I mainly use RSS to keep being informed.
0
1
0
Thomas Schmall @oxpal@mastodon.coffee · Jul 30, 2026
A useful talk about privacy on the internet. It starts with good reasons why it matters. Then gives some basic tips and ends with some more radical tactics to avoid tracking... which I'm not sure are necessary in the EU. https://www.youtube.com/watch?v=i0IfCfhOHN4 #Privacy #Tracking #VPN #Cookies #DigitalPrivacy #Cybersecurity #OpSec
0
0
2
xoron :verified: @xoron@infosec.exchange · Jul 29, 2026

Decentralized browser-based P2P E2EE messaging.

The key detail that sets this apart from other messaging apps is the browser-based client-side cryptography philosophy.

No need to install anything. Your ID is crypto-random and so the app doesnt need to rely on any central registration system like phone numbers. Your ID is unguessable and to connect to someone, you have to explicitly share it.

WebRTC has other nuances like being to route through a shared network for secure/faster transfer.

I hope this project has reached a level i can share the following details. I've made a genuine effort towards documentation and transparancy. I dont think it'll ever be enough and so im still concerned it isnt ready to share. While im using AI throughout. This is not a vibecoded project. There is attention throughout for unit tests and formal-verification. With your feedback, id like to make improvements for clarity throughout.

This version of the app demonstrates a fairly unique approach using a browser-based, local-only and webrtc approach. I know it's impossible for any system to be the "world's most secure", but that isnt a reason to not try. By rigorously implementing an exhaustive list of security features and practices, the aim is to get as close as possible.

This is intended to demonstrate client-side managed secure cryptography.

I know ive tried to compress a lot of my journey into one post. The project above is going to be tricky to understand. Feel free to reach out for clarity on any of the details.

IMPORTANT: While this is aiming to provide a secure experience, It is not audited or reviewedShared for testing, feedback and demo purposes only. Please use responsibly.

#Privacy #OnlinePrivacy #DataPrivacy #Infosec #CyberSecurity #OpSec #DigitalRights #AntiSurveillance #DataOwnership #E2EE #P2P #PeerToPeer #WebRTC #LocalFirst #LocalOnly #NoCloud #NoRegistration #PWA #SignalProtocol #PostQuantum #Cryptography #SecureMessaging #PrivateChat #EncryptedChat #Decentralized #OpenSource #SelfHosted #BetaTesting #FeedbackWelcome #TechDemo #ProofOfConcept #BuildInPublic #IndieDev #DevCommunity

4
0
4
AwattoAnalog @AwattoAnalog@mastodon.social · Jul 28, 2026
The Net turns 31 years old today. It premiered back in 1995. As such, I treated myself to a re-watch. With how fast technology was moving in 1995, it's not surprising that it doesn't hold up in 2026. Still, It's a great look back. #OTD #Movies #Film #TheNet #SandraBullock #DennisMiller #Analog #CRT #OPSEC #OSINT #InfoSec #Privacy #Surveillance
1
0
0
Netzblockierer @Netzblockierer@tech.lgbt · Jul 28, 2026
Replying to @shadowwwind@mastodon.social
@shadowwwind@mastodon.social @kkarhan@mastodon.social @gdmalan@infosec.exchange @maddad@mastodon.world @ZoidbergForPresident@kolektiva.social @nakal@mastodon.social @arstechnica@mastodon.social @EUCommission@ec.social-network.europa.eu still doesn't fix the Problem that one needs to support Tech-Illiterates… Claiming 'GrapheneOS is a solution' for the masses is like expecting the average Normie to learn to build their own OpenBSD from scratch before turning on a computer for the first time: Absolutely deranged elitism!And if the masses don't adopt something, one will always stand out! https://mastodon.social/@kkarhan/116996717672902739 #Tech #TechLiteracy #TechIlliterates #GrapheneOS #OpenBSD #ITsec #ComSec #TouchGrass #InfoSec #OpSec #Normies #TechLiterates
4
4
2
eteryu @eteryu@infosec.exchange · Jul 25, 2026
Mała aktualizacja wpisu o moim setupie Pixela 8 z GrapheneOS! Zamieniłem Sunup na ntfy do obsługi powiadomień przez UnifiedPush i dodałem krótki wątek o fotografii. Opisuję w nim, jak korzystam z pełnej jakości Pixel Camera bez wpuszczania Google do sieci oraz jak sterylizuję metadane zdjęć przed publikacją za pomocą Image Toolbox. Cały wpis po zmianach znajdziecie tutaj: https://eteryu.space/moj-zero-trust-setup-w-2026-roku-google-pixel-8-grapheneos/ #GrapheneOS #Prywatność #DeGoogle #OpSec #UnifiedPush #Android
5
1
4
Mark Wyner Won’t Comply :vm: @markwyner@mas.to · Jul 24, 2026

🚨 U.S. folks. There is one day left to comment on the FCC proposed rule to eradicate anonymity on all phone lines!

If they pass this rule government ID, physical address, and alternative phone number will be required for every new phone line. Anonymous phone lines and burner phones will cease to exist. That means no connected privacy via cellular at protests.

** Please add your comment! **

For the first field (proceedings) use these two:

17-59 and 02-278

https://www.fcc.gov/ecfs/filings/express

#Privacy #InfoSec #OpSec #FCC #Anonymity #Phones #Protest

35
4
83
Xeno Kovah @xenokovah@infosec.exchange · Jul 24, 2026
🔵🦷🔒📈🆙‼️Bluetooth Security Timeline Update 2026-07-18!
(Meant to post this last week but forgot) 2026-06-27 "Pwning Bluetooth Devices in Unexpected Ways" By Damien Cauquil @virtualabs@mamot.fr Added to the Bluetooth Security Timeline: https://darkmentor.com/bt.html#Pwning%20Bluetooth%20Devices%20in%20Unexpected%20Ways:%5B%5BPwning%20Bluetooth%20Devices%20in%20Unexpected%20Ways%5D%5D%20%5B%5BBluetooth%20Security%20Timeline%5D%5D%20%24%3A%2FTagManager 2026-06-05 "The BlueFrag Zero-Click: A System Replay" By Akshit Singh Added to the Bluetooth Security Timeline: https://darkmentor.com/bt.html#The%20BlueFrag%20Zero-Click%3A%20A%20System%20Replay:%5B%5BThe%20BlueFrag%20Zero-Click%3A%20A%20System%20Replay%5D%5D%20%5B%5BBluetooth%20Security%20Timeline%5D%5D%20%24%3A%2FTagManager 2026-06-03 "Pwnd Blaster: Hacking your PC using your speaker without ever touching it" By Rasmus Moorats Added to the Bluetooth Security Timeline: https://darkmentor.com/bt.html#Pwnd%20Blaster%3A%20Hacking%20your%20PC%20using%20your%20speaker%20without%20ever%20touching%20it:%5B%5BPwnd%20Blaster%3A%20Hacking%20your%20PC%20using%20your%20speaker%20without%20ever%20touching%20it%5D%5D%20%5B%5BBluetooth%20Security%20Timeline%5D%5D%20%24%3A%2FTagManager 2026-04-17 "Opsec oopsie: Dutch navy frigate location outed by mailing it a Bluetooth tracker" By Just Vervaart @just@journa.host Added to the Bluetooth Security Timeline: https://darkmentor.com/bt.html#Opsec%20oopsie%3A%20Dutch%20navy%20frigate%20location%20outed%20by%20mailing%20it%20a%20Bluetooth%20tracker:%5B%5BOpsec%20oopsie%3A%20Dutch%20navy%20frigate%20location%20outed%20by%20mailing%20it%20a%20Bluetooth%20tracker%5D%5D%20%5B%5BBluetooth%20Security%20Timeline%5D%5D%20%24%3A%2FTagManager 2026-01-15 "WhisperPair: Hijacking Bluetooth Accessories Using Google Fast Pair" By Sayon Duttagupta et al. Added to the Bluetooth Security Timeline: https://darkmentor.com/bt.html#WhisperPair%3A%20Hijacking%20Bluetooth%20Accessories%20Using%20Google%20Fast%20Pair:%5B%5BWhisperPair%3A%20Hijacking%20Bluetooth%20Accessories%20Using%20Google%20Fast%20Pair%5D%5D%20%5B%5BBluetooth%20Security%20Timeline%5D%5D%20%24%3A%2FTagManager 2026-01-06 "Reverse engineering my cloud-connected e-scooter and finding the master key to unlock all scooters" By Rasmus Moorats Added to the Bluetooth Security Timeline: https://darkmentor.com/bt.html#Reverse%20engineering%20my%20cloud-connected%20e-scooter%20and%20finding%20the%20master%20key%20to%20unlock%20all%20scooters:%5B%5BReverse%20engineering%20my%20cloud-connected%20e-scooter%20and%20finding%20the%20master%20key%20to%20unlock%20all%20scooters%5D%5D%20%5B%5BBluetooth%20Security%20Timeline%5D%5D%20%24%3A%2FTagManager 2025-10-10 "Paint it Blue: Attacking the Bluetooth stack" By Mehdi Talbi and Etienne Helluy-Lafont Added to the Bluetooth Security Timeline: https://darkmentor.com/bt.html#Paint%20it%20Blue%3A%20Attacking%20the%20Bluetooth%20stack:%5B%5BPaint%20it%20Blue%3A%20Attacking%20the%20Bluetooth%20stack%5D%5D%20%5B%5BBluetooth%20Security%20Timeline%5D%5D%20%24%3A%2FTagManager 2025-09-01 "Sniffing established BLE connections with HackRF One" By Clément Ballabriga Added to the Bluetooth Security Timeline: https://darkmentor.com/bt.html#Sniffing%20established%20BLE%20connections%20with%20HackRF%20One:%5B%5BSniffing%20established%20BLE%20connections%20with%20HackRF%20One%5D%5D%20%5B%5BBluetooth%20Security%20Timeline%5D%5D%20%24%3A%2FTagManager 2025-08-04 "The Perfect BLEnd: Reverse engineering a bluetooth controlled blender for better smoothies" By Edward Farrell and Ryan Mast Added to the Bluetooth Security Timeline: https://darkmentor.com/bt.html#The%20Perfect%20BLEnd%3A%20Reverse%20engineering%20a%20bluetooth%20controlled%20blender%20for%20better%20smoothies:%5B%5BThe%20Perfect%20BLEnd%3A%20Reverse%20engineering%20a%20bluetooth%20controlled%20blender%20for%20better%20smoothies%5D%5D%20%5B%5BBluetooth%20Security%20Timeline%5D%5D%20%24%3A%2FTagManager 2025-06-17 "nRF54L15 Electromagnetic Fault Injection" By Matthias Kesenheimer @mkesenheimer@mastodon.social Added to the Bluetooth Security Timeline: https://darkmentor.com/bt.html#nRF54L15%20Electromagnetic%20Fault%20Injection:%5B%5BnRF54L15%20Electromagnetic%20Fault%20Injection%5D%5D%20%5B%5BBluetooth%20Security%20Timeline%5D%5D%20%24%3A%2FTagManager 2025-03-28 "Is Your Bluetooth Chip Leaking Secrets via RF Signals?" By Yanning Ji et al. Added to the Bluetooth Security Timeline: https://darkmentor.com/bt.html#Is%20Your%20Bluetooth%20Chip%20Leaking%20Secrets%20via%20RF%20Signals%3F:%5B%5BIs%20Your%20Bluetooth%20Chip%20Leaking%20Secrets%20via%20RF%20Signals%3F%5D%5D%20%5B%5BBluetooth%20Security%20Timeline%5D%5D%20%24%3A%2FTagManager 2025-01-12 "Detecting BLE Trackers for the price of a Gas Station Hot Dog" By Bill Swearingen and Larry Pesce Added to the Bluetooth Security Timeline: https://darkmentor.com/bt.html#Detecting%20BLE%20Trackers%20for%20the%20price%20of%20a%20Gas%20Station%20Hot%20Dog:%5B%5BDetecting%20BLE%20Trackers%20for%20the%20price%20of%20a%20Gas%20Station%20Hot%20Dog%5D%5D%20%5B%5BBluetooth%20Security%20Timeline%5D%5D%20%24%3A%2FTagManager 2024-10-29 "Brightway security revisted: Xiaomi 4 Pro 2nd Gen" By robocoffee Added to the Bluetooth Security Timeline: https://darkmentor.com/bt.html#Brightway%20security%20revisted%3A%20Xiaomi%204%20Pro%202nd%20Gen:%5B%5BBrightway%20security%20revisted%3A%20Xiaomi%204%20Pro%202nd%20Gen%5D%5D%20%5B%5BBluetooth%20Security%20Timeline%5D%5D%20%24%3A%2FTagManager 2024-09-26 "LibrePods: AirPods liberated from Apple's ecosystem" By Kavish Devar Added to the Bluetooth Security Timeline: https://darkmentor.com/bt.html#LibrePods%3A%20AirPods%20liberated%20from%20Apple's%20ecosystem:%5B%5BLibrePods%3A%20AirPods%20liberated%20from%20Apple's%20ecosystem%5D%5D%20%5B%5BBluetooth%20Security%20Timeline%5D%5D%20%24%3A%2FTagManager 2024-03-28 "ChatTracer: Large Language Model Powered Real-time Bluetooth Device Tracking System" By Qijun Wang et al. Added to the Bluetooth Security Timeline: https://darkmentor.com/bt.html#ChatTracer%3A%20Large%20Language%20Model%20Powered%20Real-time%20Bluetooth%20Device%20Tracking%20System:%5B%5BChatTracer%3A%20Large%20Language%20Model%20Powered%20Real-time%20Bluetooth%20Device%20Tracking%20System%5D%5D%20%5B%5BBluetooth%20Security%20Timeline%5D%5D%20%24%3A%2FTagManager 2023-02-22 "Hacking Brightway scooters: A case study" By robocoffee Added to the Bluetooth Security Timeline: https://darkmentor.com/bt.html#Hacking%20Brightway%20scooters%3A%20A%20case%20study:%5B%5BHacking%20Brightway%20scooters%3A%20A%20case%20study%5D%5D%20%5B%5BBluetooth%20Security%20Timeline%5D%5D%20%24%3A%2FTagManager 2022-06-27 "BLAP: Bluetooth Link Key Extraction and Page Blocking Attacks" By Changseok Koh et al. Added to the Bluetooth Security Timeline: https://darkmentor.com/bt.html#BLAP%3A%20Bluetooth%20Link%20Key%20Extraction%20and%20Page%20Blocking%20Attacks:%5B%5BBLAP%3A%20Bluetooth%20Link%20Key%20Extraction%20and%20Page%20Blocking%20Attacks%5D%5D%20%5B%5BBluetooth%20Security%20Timeline%5D%5D%20%24%3A%2FTagManager 2022-04-18 "Exploring Xiaomi's new firmware security measures" By robocoffee Added to the Bluetooth Security Timeline: https://darkmentor.com/bt.html#Exploring%20Xiaomi's%20new%20firmware%20security%20measures:%5B%5BExploring%20Xiaomi's%20new%20firmware%20security%20measures%5D%5D%20%5B%5BBluetooth%20Security%20Timeline%5D%5D%20%24%3A%2FTagManager That’s it for now. As always, LMK any I missed!
0
0
0
Axel Gutmann @virbonus@sueden.social · Jul 23, 2026
RE: https://sueden.social/@virbonus/116968379335973356 Hat irgend jemensch eine Ahnung, wieso es so viele umständliche und untaugliche Identifizierungsverfahren bei Banken, Versicherungen, Krankenkassen etc. gibt, aber kaum eine Institution en e-Perso nutzt? #Banken #Sicherheit #Verifikation #Identifikation #ePerso #OpSec
Quoting
Axel Gutmann @virbonus@sueden.social
@vowe@social.heise.de Ich streite mich grade mit der Raisin-Bank (ex Weltsparen) rum, die für Adressnachweis nur leicht fälschbare Dokumentenscans (z.B. aktuelle Strom- oder Gas-, aber nicht Telefonrechnungen, Kontoauszüge - aber nicht von Kreditkarten) oder Scan des Persos, aber keinesfalls einfachste und einzig sichere Methode akkzeptieren, nämlich E-Perso und PIN. Das ist eine so chaotische Simulation von Sicherheit, über die offenbar nie jemand nachdenkt und niemand meine Kritik versteht.
Open quoted post
0
0
0
Mark Wyner Won’t Comply :vm: @markwyner@mas.to · Jul 22, 2026
This is a great list of tips for improving your Signal privacy from @yaelwrites@mastodon.social. I found this part especially meaningful: “Turning off biometrics makes it annoying to use your phone…If that’s you, remember that both Android and iOS have a quick lockout that forces a passcode and disables biometrics until you re-enter it: on iPhone, hold the side + volume button until the power-off screen appears, then cancel; on most Androids, hold power and tap Lockdown.” https://blog.yaelwrites.com/how-to-keep-the-feds-out-of-your-signal-messages #Signal #Privacy #InfoSec #OpSec
5
0
4
Simon Zerafa @simonzerafa@infosec.exchange · Jul 18, 2026
Replying to @bermudianbrit@mastodon.online
@bermudianbrit@mastodon.online Seems like a great way to capture audio of people's voices for later "AI" reproduction or cloning 🙂🤷‍♂️ Probably best not to willingly hand over biometrics, especially if your bank uses any sort of Voice ID technology 🤔 #OpSec #Security #VoiceCloning
0
0
0
Patrick.sh @psh@infosec.exchange · Jul 16, 2026
I thought at first the meta pervert glasses were a continuous connection, only to realize now that you need the meta AI app in order to export. You need the ...Meta AI app... in order... to export...okayyy lol. Damn the user privacy really is zero; not to mention every other person's privacy in their sweep. This is just an attempt to lock-in another market - now that their VR world is dead, and facebook/instagram is slowly dying, they're refocusing to another market that's dependent on wanna-be influencers and gross manosphere idiots. I really was hoping meta would die off eventually but people keep taking the bait. Between flock cameras, waymo cameras, ring cameras, tesla cameras, meta glasses cameras., etc etc etc...we are really becoming quite a multi-perspective surveillance state. #privacy #meta #metaAI #metaglasses #facebook #instagram #surveillance #opsec
18
0
15