#security

1459 posts · Last used 2d

Back to Timeline
Lazou @lazou@kanoa.de · 3d ago
Mein PGP-Keygenerator auf dem Weg zu Post-Quantum Ich möchte euch nur kurz informieren, dass Post-Quantum-Kryptografie in PGP nicht mehr allzu weit entfernt ist. Mit RFC 9980 wurde inzwischen der offizielle IETF-Standard für Post-Quantum-Kryptografie in OpenPGP veröffentlicht. ➡️ Verschlüsselung: hybride Verfahren mit ML-KEM + ECC ➡️ Signaturen: hybride Verfahren mit ML-DSA + EdDSA Jetzt fehlt im Wesentlichen noch die entsprechende Umsetzung in OpenPGP.js. Sobald diese Unterstützung dort sauber integriert ist, werde ich auch meinen PGP-Keygenerator um standardkonforme Post-Quantum-OpenPGP-Schlüssel erweitern. :boost_ok: #OpenPGP #PGP #Verschlüsselung #Keygenerator #Datenschutz #Security #Secunis #ITSecurity
1
1
4
Peter N. M. Hansteen @pitrh@mastodon.social · 3d ago
0
0
0
heise Security @heisec@social.heise.de · 3d ago
Sicherheitslücken: Angreifer können Wachdienst von ClamAV stören Der Open-Source-Virenscanner ClamAV ist verwundbar. Im schlimmsten Fall kann Schadcode auf Instanzen gelangen. https://www.heise.de/news/Sicherheitsluecken-Angreifer-koennen-Wachdienst-von-ClamAV-stoeren-11409730.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon #Virenscanner #IT #Patchday #Security #Sicherheitslücken #Updates #news
2
0
6
heise online English @heiseonlineenglish@social.heise.de · 3d ago
Security vulnerabilities: Attackers can disrupt ClamAV's watch service The open-source virus scanner ClamAV is vulnerable. In the worst case, malicious code can reach instances. https://www.heise.de/en/news/Security-vulnerabilities-Attackers-can-disrupt-ClamAV-s-watch-service-11409811.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon #Virenscanner #IT #Patchday #Security #Sicherheitslücken #Updates #news
0
0
0
China Business Forum @cnbusinessforum@mstdn.business · 3d ago
[#TRADESHOW] #Security #China 2026 – China #International #Exhibition on #Public #Safety and Security will be held from November 3 to 6, 2026, at China International Exhibition Center (Shunyi Hall), #Beijing. As one of China’s most #influential #events dedicated to public safety, #intelligent security #technologies, and #digital #governance, the #expo brings together #government authorities, #industry #leaders, and #global #technology #providers. https://cnbusinessforum.com/event/security-china-2026-china-international-exhibition-on-public-safety-and-security/
0
0
0
heise Security @heisec@social.heise.de · 4d ago
Jetzt patchen! Admin-Attacken auf Metabase beobachtet Angreifer nutzen zurzeit eine kritische Sicherheitslücke in der Business-Intelligence-Plattform Metabase aus. Admins müssen jetzt handeln. https://www.heise.de/news/Jetzt-patchen-Admin-Attacken-auf-Metabase-beobachtet-11404526.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon #Cyberangriff #Exploit #IT #Patchday #Security #Sicherheitslücken #Updates #news
0
0
1
Luna Lactea @jackemled@furry.engineer · 4d ago
Do mini PCIe hardware security modules or standalone cryptographically strong pRNGs exist? If they do, where can I get one? NetBSD is complaining about low entropy (laptop from 2011) & suggests I keysmash, use an entropy file, or get a USB pRNG. I would prefer to have all of my USB ports free. I have no idea where to find such a thing & I can't even find USB HSMs besides the one that YubiCo sells. The closest thing I have found is a bunch of TPM2 chips with SPI headers on them & I don't think I have any free SPI connectors in the laptop. For now I'll use an entropy file but I would rather do something better like using a proper RNG device. I think people watching these tags might know more than I can find with a search engine. Thank you. #Security #BSD #NetBSD #Linux #Cryptography
6
1
12
PrivacyDigest @PrivacyDigest@mas.to · 4d ago
Nobody Knows if OpenAI’s and Anthropic’s #AI #Hacking Sprees Are #illegal Both major AI labs’ models broke containment, escaped onto the internet, and #hacked other companies. If a human had done that, the law would likely be against them. But a #bot ? #openai #anthropic #security #privacy https://www.wired.com/story/openai-anthropic-ai-hacking-sprees-illegal/
0
0
2
eteryu @eteryu@infosec.exchange · 5d ago
Cześć! Jak tam Wasze niedzielne poranki? Ja kończę śniadanie i zaraz biorę się za pisanie tekstu na bloga o tym, od czego w ogóle zacząć własne modelowanie zagrożeń (threat modeling). Jeżeli macie jakieś swoje ulubione podejścia albo pytania w tym temacie, dajcie znać! #cyberbezpieczeństwo #infosec #threatmodeling #security
1
1
3
Hab da mal was gebastelt... man hat am Wochenende ja nichts Besseres zu tun: Secure Your ServerZwei praktische Checks. Ein seriöser Sicherheitsbericht. Prüfe eine Domain auf die Härtungsdetails, auf die Angreifer und Audits zuerst schauen. Teste danach, ob deine echten E-Mails sauber authentifiziert und zugestellt werden. Kein Konto, kein Tracking, keine Bezahlschranke. Domain-Sicherheitsscan Vollständige externe Sicht auf TLS/SSL, SSH, offene Ports, DNS, SPF, DKIM, DMARC, MTA-STS, HTTP-Security-Header, WHOIS und PGP/WKD. Mail-Zustellungstest Erzeuge eine einmalige Testadresse, schick eine Mail aus deinem Postfach und sieh SPF, DKIM, DMARC, TLS, rDNS, Spam-Signale und Zustellungsdetails. Bugs, Verbesserungswünsche bitte an "hallo [at] chrislo.de" Mehr Infos: https://www.sichere-deinen-server.de/ #chrislo #sys #secureyourserver #sicheredeinenserver #sicherheit #security #server #domain #tls #ssh
0
0
0