InfoSec Person | Alt-Account#2

  • 1 Post
  • 12 Comments
Joined 2 years ago
cake
Cake day: September 28th, 2023

help-circle

  • A Basil Plant@lemmy.worldtoTechnology@lemmy.worldfake keepass repo on github
    link
    fedilink
    English
    arrow-up
    46
    arrow-down
    1
    ·
    7 months ago

    I need a recognisable domain name website that google or duckduckgo has picked as the product.

    This doesn’t always work. For example, I used to (and still do) see a lot of fake websites when I l type revanced (https://revanced.app/) on duckduckgo, and I’ve nearly fallen for two of the fake ones before (I think two of .com / .org / .to…?)

    Thankfully ublock origin warns users of this:

    Otherwise, I’d have 100% downloaded some malware-loaded crap.



  • Not exactly what you asked, but do you know about ufw-blocklist?

    I’ve been using this on my multiple VPSes for some time now and the number of fail2ban failed/banned has gone down like crazy. Previously, I had 20k failed attempts after a few months and 30-50 currently-banned IPs at all times; now it’s less than 1k failed after a year and maybe 3-ish banned at any time.

    There was also that paid service where users share their spammy IP address attempts with a centralized network, which does some dynamic intelligence monitoring. I forgot the name and search these days isn’t great. Something to do with “Sense”? It was paid, but well recommended as far as I remember.

    Edit: seems like the keyword is " threat intelligence platform"




  • That’s not a very valid argument.

    First and foremost, most devs probably see it as a job and they do what they’re told. They don’t have the power to refute decisions coming from above.

    Second, in this economy where jobs are scarer than a needle in multiple haystacks, people are desperate to get a job.

    Third, yes, there may be some Microsoft (M$) fan-people who end up being devs at M$. Sure, they may willingly implement the things upper management may request. However, I’m not sure whether that’s true for most of the people who work at M$.

    Your comment suggests to shift the blame to the devs who implement the features that upper management request for. Don’t shoot the (MSN) messenger.


  • Looks cool and I’m glad something new has arrived after nitter.

    A few things, however:

    1. It doesn’t look like I can view comments on tweets; I can only view the tweet. (Firefox mobile if that matters)
    2. It’s pretty slow. It’s not a big problem, but it is very noticeable.
    3. Somewhat irrelevant, but why is it called TWStalker? It’s a… bit of a weird name. ‘Stalker’ makes me feel like I’m doing something illegal even though I definitely am not.


  • Will you (the community) be setting your username to your public username (a username you use everywhere) or something that’s different from your public username?

    Idk why, but signal feels more… personal(?) and I’d hate for general people to stumble across my signal account just by guessing whether my signal username is my public username.

    I’d be fine if they got my Discord account, mastodon account, Lemmy account (they’re all different usernames anyway) because they’re public-ish accounts. Signal feels less public and I’d want to go with a username that only I can send to people I know.

    It looks like there will be a message requests area and it looks like usernames can also be changed (should a username ever be doxxed).

    I’m still on the fence.