bleepingcomputer.com

pineapplelover, to selfhosted in what if your cloud=provider gets hacked ?

I am my cloud provider. Don’t have duplicate copies of my server yet so I guess I’m kinda fucked.

dai,

But man, I’ll be able to amend all those TODO items that have been accumulating of the last 12 months and fix all those issues while rebuilding my raid.

I mean that’s only if my GITs aren’t hijacked during the ransomware attack.

And I mean, I’ll probably just push the same config to my server and let it on its merry way again.

kristoff,

Well, based on advice of Samsy, take a backup of home-server network to a NAS on your home-network. (I do home that your server-segment and your home-segment are two seperated networks, no?) Or better, set up your NAS at a friend’s house (and require MFA or a hardware security-key to access it remotely)

Fleppensteijn, to linux in Lazarus hackers now push Linux malware via fake job offers
@Fleppensteijn@feddit.nl avatar

Wouldn’t it show the icon of an executable file and ask if you want to open it or execute it?

Chewget, to privacy in Haier hits Home Assistant plugin dev with takedown notice

Why does that building look like a failed print?

FutileRecipe,

I was gonna say air filter.

sxan,
@sxan@midwest.social avatar

A royally abused heat pump.

Damage, to privacy in Haier hits Home Assistant plugin dev with takedown notice

Too bad they own Hoover as well

Damage, to homeassistant in Haier hits Home Assistant plugin dev with takedown notice

eh, another one for the blacklist… it’s getting difficult.

chaosppe, to privacy in Have I Been Pwned adds 71 million emails from Naz.API stolen account list
@chaosppe@lemmy.world avatar

I’ve checked the list on mine, those are some really really old passwords… Must’ve been a long time ago.

bfg9k,
@bfg9k@lemmy.world avatar

How were you able to search the list? I can’t find it anywhere

chaosppe, (edited )
@chaosppe@lemmy.world avatar
bfg9k,
@bfg9k@lemmy.world avatar

Cheers mate.

Looks like my decision to start using keepass was a good idea, these are all very old passwords

nexusband, to homeassistant in Haier hits Home Assistant plugin dev with takedown notice
@nexusband@lemmy.world avatar

Never considered buying Haier anyway, but i am looking specifically for appliances that have HAOS support. So them pulling this shit will put them on my black list for ever. I get why Mazda did it, but the car doesn’t need the app to be useful, i can just ignore that part. But this is an home appliance that looses a big part of it’s usefulness…

Septimaeus, (edited ) to selfhosted in what if your cloud=provider gets hacked ?

Dammit, I came here hoping to see at least one “I have a very special set of skills.” Oh well.

Yeah I’d cut bait, rebuild from latest tapes. But also…

Septimaeus, (edited )

I’d put the corrupted backups in an eye-catching container, like a Lisa Frank backpack or Barbie lunchbox, to put on the wall in my office.

nix, to privacy in Signal tests usernames that keep your phone number private
@nix@merv.news avatar

Still sucks you will need a phone number to use it though. Hopefully they adopt meshnet type technology similar to berty.tech so people can communicate even when the internet is shut off across all platforms with end to end encryption

butter,

Another day, another chat service.

SecurityPro, to privacy in Signal tests usernames that keep your phone number private
@SecurityPro@lemmy.ml avatar

Download and installed but it still insists on a phone number. I don’t see a way to bypass.

BobGnarley,

I believe they still require a phone number for the TESTING phase but it can be the same oje you already use for your regular Signal (if im understanding it correctly)

isa, to privacy in Signal tests usernames that keep your phone number private

omg i’m so excited for this

ErKaf, to privacy in Signal tests usernames that keep your phone number private

What is this stupid website. Cant open it because they have banned my IP. Why the fuck do they ban MullvadVPN servers?

muhyb,

Surprisingly it’s fine on Tor.

AeroLemming,

Is it even possible to block Tor? You could block specific exit nodes, but not all of them unless you had a way to detect when someone was using Tor.

ZeroEcks, to privacy in Signal tests usernames that keep your phone number private

Finally

MazonnaCara89, to linux in Free Download Manager site redirected Linux users to malware for years
@MazonnaCara89@lemmy.ml avatar

Now I need to know who the hell has installed Free Download Manager on Linux.

MNByChoice, to selfhosted in what if your cloud=provider gets hacked ?

I wonder if the specifics of the hack would make backing up elsewhere fail. Possibly by spreading the hack to new machines.

In any case, testing backups is important.

kristoff,

I have been thinking the same thing.

I have been looking into a way to copy files from our servers to our S3 backup-storage, without having the access-keys stored on the server. (as I think we can assume that will be one of the first thing the ransomware toolkits will be looking for).

Perhaps a script on a remote machine that initiate a ssh to the server and does a “s3cmd cp” with the keys entered from stdin ? Sofar, I have not found how to do this.

Does anybody know if this is possible?

  • All
  • Subscribed
  • Moderated
  • Favorites
  • localhost
  • All magazines
  • Loading…
    Loading the web debug toolbar…
    Attempt #