mastodon.online is one of the many independent Mastodon servers you can use to participate in the fediverse.
A newer server operated by the Mastodon gGmbH non-profit

Server stats:

11K
active users

#airgapped

1 post1 participant0 posts today

#servicetoot Am 31. März ist #worldbackupday #world #backup #day #weltdatensicherungstag
Und läuft deutlich entspannter wenn man bereits jetzt mit den Vorbereitungen beginnt 😉
Meine Checkliste muss ich dringend erweitern.
Das Wichtigste.
#1
#homeassistant Image in den #cloudspeicher
#2
#cloudspeicher #pcloud auf lokale #ssd für den #schrank #offline #airgapped
#3
#Smartphone meiner Mutter von #iCloud auf #pcloud umstellen. Kontingent 100GB 9,99€ für mich. #spass
Ich hoffe die Erinnerung hilft euch.

This is what innovation can do!

#AirGapped #Offline #PKI #PrivateKeys #TwoFactor- #2FA #Yubico #Yubikey

======

Vincent Bernat Turns Three YubiKeys and a Cheap Single-Board Computer Into a Secure Offline PKI
hackster.io/news/vincent-berna

---
Developer Vincent Bernat demonstrates how to turn three Yubico YubiKey USB two-factor authentication dongles into an offline public key infrastructure (PKI) using a low-cost single-board computer as an air-gapped host.

Oh, look, another thrilling blog post about creating your own offline PKI system with 3 #YubiKeys and a computer that can barely run Tetris! 😂 Because nothing screams "fun weekend project" like locking yourself in an air-gapped bunker just to feel marginally more secure while the rest of us enjoy the cloud, amirite? ☁️🔒
vincent.bernat.ch/en/blog/2025 #offlinePKI #security #humor #weekendproject #airgapped #HackerNews #ngated

vincent.bernat.ch · Offline PKI using 3 YubiKeys and an ARM single board computerSetup of an offline PKI system with 3 YubiKeys and a Libre Computer Sweet Potato ARM64 SBC. This may contain some traces of Nix.
Replied in thread

@hisold OFC #Cheats are a way to learn how to "#hack" as in "What if I change the value at this address?"

And I still do recommend anyone interested in #IT and espechally #ITsec to build themselves their own #airgapped #HomeLab to "#FuckAroundAndFindOut!" safely within.

  • Kinda like a "Dojo" (something that costs $$ per hour in terms of a "remote lab" to even be given access in)...

And with #AntiP2W becoming mainstream as well as Players despising #P2W / #PayToWin / #Pay2Win (aka. #P2L / #PayToLoose / #Pay2Loose) as well as literal #gambling on some #Minecraft servers, I don't blame Kids that feel shafted (harder than #Millenials like myself back in the days of #HabboHotel) if they decide to fuck with servers rather than scamming other players

www.youtube.com- YouTubeEnjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.
Replied in thread

@dalias @lauren
@pixelschubsi

Also the blatant dismissal of absolitely basic #OpSec & #ComSec is just flabberghasting.

Only #decentralized, #OpenSource & #OpenStandards can actuall survive long-term and remain #secure.

It's the same reasons we use #PGPG/MIME & #SSH and not #X400 & #X25!

IOW: Think "How can you weaponize Signal?" and see what you csn do just holding key people in contempt...

The less #info a provider has, the less they can be forced to snitch upon customers.

"#JustUseSgnal!" is a form of dangerous "#TechPopulism" aimed at bamboozling #TechIlliterates who don't know better, abusing information asymetry to pull rank instead of investing the time and effort to *explain "how" and "why" this is indeed a good or bad idea.

The only ones that have a chance to beat that are @delta / #deltaChat but that's just #PGP/MIME #eMail in a nice UI...

  • You may now laugh at me and think my "#TinfoilHat sits too tight" but I'm shure sooner or later I'll be evidenced as correct...
Replied in thread

@0xF21D OFC it's way worse as #NorthKorea is basically #airgapped and the average person there most likely doesn't even know what the Internet is.

  • And the few people who dare to speak in prearranged settings will say that they'd love to visit the CSR or GDR cuz they had worked with folks from there half a century ago...

Still, #Iran is well known for doing #HostageDiplomacy so having someone with a #US #passport do #journalism in #Tehran is kinda asking for trouble...

  • I guess they only got booted out because legally they had #journalist #visa but still, I don't see much gained from the trip and IDK any good ways to have extracted more that wouldn't have raised so many eyebrows that they would've likely been charged with "#espionage" and held in reserve for a swap...
Replied in thread

@gborn @MichaelD @Bundesligatrainer @Ihazchaos nein, eben nicht.

Dass #Windows10 [und besonders #Windows11] nicht #DSGVO- & #BDSG-konform sein können ist evidenzierte Tatsache und ich habe noch keine*n Anwält*in gesehen die etwas anderes behaupten und dafür im Zweifelsfalle auch die #Haftung übernehmen würden.

  • Wohingegen ich mir sicher bin dass @SUSE & @ubuntu mir im Zweifelsfalle sogar ne #Versicherung der #Compliance ab Werk anbieten würden, was #Microsoft aufgrund von #CloudAct inhärent nicht kann!

  • Außerdem verbietet sich das Procurement von Anbietern die in "illegaler Agententätigkeit" [u.a. #PRISM] involviert sind (!!!) schon aus oberflächlicher due diligence...

Von einfach ausnutzbaren #Govware - #Backdoors in der #CryptoAPI unter #Windows hab ich noch garnicht angefangen!

Replied in thread

@teajaygrey @halva @lynn @signalapp @deilann @monocles @Mer__edith @torproject

I remember #SLIC but sadly it never got traction.

  • Needless to say #XMPP with #OMEMO & #PGP/MIME nowadays has excellent support by clients for every relevant platform and there are various other options depending on the use case, threat model and scenario.

I do gladly advice clients/employers directly...

  • So far only #Tor and #Monero have reached a level of #decentralization that makes it basically impossible to shut them down even if (key) people working on it were to be arrested/forcibly disappeared/murdered (as had been the case!), with #SelfHosting-capable projects being close behind.

For example, #Briar as a "#airgapped" (or rather '#offline-capable') messenger may be the hottest thing if one needs to #chat with someone stuck exactly in the middle of North Korea and out of reach for Chinese, Russian or South Korean phone networks, tho that still relies on the local #SneakerNet (or rather #TrampingNet) to facilitate the transfer, which is rather common given the fact that #USB #flashdrives and #microSD cards are smuggled there en masse...

Version 0.8.0 of #GitOps playground #GOP is here:
github.com/cloudogu/gitops-pla

It brings us closer to fully support #airgapped, least privileged and namespace-isolated environments:

You can now enable image pull secrets for all tools, and our example pipelines can now be configured to run in airgapped envs.

We also started work on enabling network policies, that make GOP run on #OpenShift. We're working on extending #netpols support to complete namespace-isolation on all #k8s clusters.

1/2

Replied in thread

@ditol @samueljohn @linuzifer

THIS is where I disagree...

You may think it's elitist, but if people are too lazy to learn even fundamentals like how to use #Tails then maybe they should just not do #tech at all?

  • Like: We expect people to show at the every least theoretical proficiency in terms of #TrafficCode and #VehicleSafety in +every juristiction I'm aware of* and literally mandated #DrivingLicense|s for that reason.

I'll gladly teach #TechIlliterates but I won't waste my time on people that spread disinfo...

It's 2024: @tails_live / @tails has been out for over a decade and there are a shitload of guides ranging from written documentation to Zoomer-friendly TikTok-Style shorts on how to get started.

FOR THE LAST TIME:

*STOP MAKING EXCUSES TO JUSTIFY ESCALATING COMMITMENT TO EVIDENTLY BAD SOLUTIONS!"

Whereas with #SelfCustody of all the keys as well as #ReproduceableBuilds and real #decentralization, this would be evidently impossible even if all the devs wanted to comply honestly and not just because they could be held at gunpoint.

  • #Signal is not your friend. It's merely a tax-exempt "non-profit" corporation, and corporations are explicitly nobodys friend - espechally when they demand #PII like phone numbers for useage.

Compare that to #monocles where you do pay like €2 p.m. but in return get #standard #protocols like #IMAP, #SMTP & #XMPP and can pay anonymously and not have to provide any PII whatsoever!

  • And unlike #Signal they ain't dependent on #VC funding and #grant money to keep the lights on.

Make of that what you will, but just like allowing flatearthers to roam freely without caretaker supervision doesn't make the world less round, so won't the facts change about #ITsec, #InfoSec, #OpSec & #ComSec.

Because all #centralized, #SingleVendor & #SingleProvider solutions are bad, and if they don't even allow for #SelfCustody then they are just a #grift to #scam tech-illiterates that don't know and/or don't care!

Catweazle @Catweazle@vivaldi.net

@baeuchle @kkarhan @Linux @torproject @Vivaldi, no, don't misunderstand me, I only said that TOR is for what it is and that you have way more option on the OpenWeb with browsers like Mullvad, which is as private as TOR, but way better and compatible for the OpenWeb.
Well, Vivaldi is a good private browser, but it's main feature is it's funcionality which make innecessary the use of most extensions or plug-ins.
Infosec.SpaceKevin Karhan :verified: (@kkarhan@infosec.space)Attached: 1 image @Catweazle@vivaldi.net @baeuchle@chaos.social @Linux@kitty.social @torproject@mastodon.social @Vivaldi@vivaldi.net Claiming that ["[...] Mullvad is as private as Tor [...]"]( https://social.vivaldi.net/@Catweazle/113344664983833218 ) disqualified your for any future discussion. - If you can't distinguish between a #VPN and #Tor then you are either *criminally incompetent* or *acting as a #UsefulIdiot* by *spreading #FUD and known #disinfo*, which *can get people killed* who believe this bs! I'll set you some timeout, so you can think about it and apologize in due time! #thxbye #EOD #next

European govt air-gapped systems breached using custom malware

An APT hacking group known as GoldenJackal has successfully breached air-gapped government systems in Europe using two custom toolsets to steal sensitive data, like emails, encryption keys, images, archives, and documents

#europe #ESET #APT #GoldenJackel #airgapped #USB #databreach #security #cybersecurity #hakers #hacking #hacked

bleepingcomputer.com/news/secu

BleepingComputer · European govt air-gapped systems breached using custom malwareBy Bill Toulas

European govt air-gapped systems breached using custom #malware

"An APT hacking group known as GoldenJackal has successfully #breached #AirGapped government systems in Europe using two custom toolsets to steal sensitive data, like emails, encryption keys, images, archives, and documents."
#KRITIS
bleepingcomputer.com/news/secu

BleepingComputer · European govt air-gapped systems breached using custom malwareBy Bill Toulas