LastPass has revealed more details about how its systems were compromised via an attack on a home PC used by one of its senior DevOps engineers.
It shows not only the extent of the attack, but also how dev machines can be exploited by miscreants
#bot
Original tweet : https://nitter.1d4.us/TheRegister/status/1630638906889867264
One thing @medium got right from the start with its Mastodon instance at me.dm: Domain length matters. It’s not always visible. But when displayed, shorter names fit better within certain display limitations.
Full usernames end up being similar to email addresses. Not enough attention has been paid to short domains yet as a feature and a nice side benefit to a good host/moderator. Some soon-to-be instances will target similar ultra-short domains, and new users may naturally gravitate to them.
Ron DeFascist shows how not to run an education system - His bullying vulnerable people and pandering to White grievance are morally objectionable and anti-American. The price is an accelerating decline of the state’s education system. https://www.washingtonpost.com/opinions/2023/02/28/desantis-florida-school-performance/ #DeFascist
Rovio Delists Last Paid ‘Angry Birds’ Game Because The Free Version Is More Profitable https://www.techdirt.com/2023/02/28/rovio-delists-last-paid-angry-birds-game-because-the-free-version-is-more-profitable/
NEW: @team has launched #DontBanTikTok, a campaign calling for US lawmakers to stop their unserious and xenophobic handwringing around TikTok and pass a goddamn data privacy law to actually protect people from corporate & government surveillance https://www.dontbantiktok.com
Twitter updates its violent speech policy to prohibit users from expressing "wishes of harm" and similar sentiments, a reversal of its previous policy (Karissa Bell/Engadget)
https://www.engadget.com/twitter-updates-violent-speech-policy-to-ban-wishes-of-harm-214320985.html
http://www.techmeme.com/230228/p29#a230228p29
This tiny motherboard features the most powerful Alder Lake-N processor https://www.fanlesstech.com/2023/03/up-squared-pro-7000-announced.html
"Rant: File Sharing on #Linux is A Mess" #Samba 🐧
I had to share this video from @thelinuxcast because I agree. Linux does so many things better than Windows, but simple file-sharing on a network is not one of them.
The Fox "News" documents show a network that inhabits a funhouse non-reality that it created and cannot escape. They've warped people's minds so much that they must play along with blatant lies because otherwise they'll lose viewers who are delusional *because* of their own programs. What a dystopian mess.
How to Create an Email Server in Linux with Mail-In-A-Box https://buff.ly/3Zv0kJp
Voice.AI: GPL Violations with a Side of DRM
https://undeleted.ronsor.com/voice.ai-gpl-violations-with-a-side-of-drm/
Discussions: https://discu.eu/q/https://undeleted.ronsor.com/voice.ai-gpl-violations-with-a-side-of-drm/
Redmi’s 300W fast charging can fully charge a 4,100 mAh battery in 5 minutes https://liliputing.com/redmis-300w-fast-charging-can-fully-charge-a-4100-mah-battery-in-5-minutes/
Quote from article (with hashtags added):
In related news, I still remember the days when #Republicans supported limited government and decried anything that resembled government overreach.
When Chris Sununu, New Hampshire’s #Republican governor, recently suggested that #DeSantis was becoming a “big-government #authoritarian ,” he clearly had a point.
T-Mobile has been a dumpster fire of terrible security practices. But since regulators and Congress have been so indifferent over the years about your privacy and security, it goes on and on and on. Read @briankrebs for the latest in a rogue company's malpractice: https://krebsonsecurity.com/2023/02/hackers-claim-they-breached-t-mobile-more-than-100-times-in-2022/
LastPass says hackers stole password vault data in 2022 by exploiting an RCE flaw in third-party software to install a keylogger on a #DevOps engineer's computer https://www.bleepingcomputer.com/news/security/lastpass-devops-engineer-hacked-to-steal-password-vault-data-in-2022-breach/
What a fucking disaster and this will likely kill them.
Like I said, you should migrate off #LastPass or any other cloud password managing solution, (yes, #1Password too) to a offline password managing solution such as #KeePassXC and one of these companion apps:
iOS: #Strongbox
Android: #KeePassDX