Spyke

Posts

The challenge of deleting old online accounts | Loudwhisper

cross-posted from: https://infosec.pub/post/32096847

In the last days I spent a disproportionate amount deleting old accounts I found in my password manager, and mostly because so many companies - despite the GDPR - have rudimentary, manually when not completely nonexistent processes to delete your data.

In this post I describe my process going through about 100 old accounts and trying to delete them all, including a top 10 for the weirdest, funniest or most interesting cases I encountered while doing so.

https://loudwhisper.me/blog/deleting-accounts/Open linkView original on infosec.pub
14
technology·Technologybyloudwhisper

The challenge of deleting old online accounts | Loudwhisper

In the last days I spent a disproportionate amount deleting old accounts I found in my password manager, and mostly because so many companies - despite the GDPR - have rudimentary, manually when not completely nonexistent processes to delete your data.

In this post I describe my process going through about 100 old accounts and trying to delete them all, including a top 10 for the weirdest, funniest or most interesting cases I encountered while doing so.

https://loudwhisper.me/blog/deleting-accounts/Open linkView original on infosec.pub
73
technology·Technologybyloudwhisper

Using Clouds for too long might have made you incompetent

My take on how a decade (or more) of using cloud services for everything has seemingly deskilled the workforce.

Just recently I found myself interviewing senior security engineers just to realize that in many cases they had absolutely no idea about how the stuff they supposedly worked with, actually worked.

This all made me wonder, is it possible that over-reliance on cloud services for everything has massively deskilled the engineering workforce? And if it is so, who is going to be the European clouds, so necessary for EU's digital sovereignty?

I did not copy-paste the post in here because of the different writing style, but I get no benefit whatsoever from website visits.

https://loudwhisper.me/blog/cloud-deskilling/Open linkView original on infosec.pub
155
cybersecurity·Cybersecuritybyloudwhisper

Email Security for Every Taste

cross-posted from: https://infosec.pub/post/16642151

(I have just learned you can cross-post!)

As someone who has read plenty of discussions about email security (some of them in this very community), including all kind of stuff (from the company groupie to tinfoil-hat conspiracy theories), I have decided to put too many hours some time to discuss the different threat models for email setups, including the basic most people have, the "secure email provider" one (e.g., Protonmail) and the "I use arch PGP manually BTW".

Jokes aside, I hope that it provides an overview comprehensive and - I don't want to say objective, but at least rational - enough so that everyone can draw their own conclusion, while also showing how certain "radical" arguments that I have seen in the past are relatively shortsighted.

The tl;dr is that email is generally not a great solution when talking about security. Depending on your risk profile, using a secure email provider may be the best compromise between realistic security and usability, while if you really have serious security needs, you probably shouldn't use emails, but if you do then a custom setup is your best choice.

Cheers

https://loudwhisper.me/blog/email-security/Open linkView original on infosec.pub
5
technology·Technologybyloudwhisper

Email Security for Every Taste

As someone who has read plenty of discussions about email security (some of them in this very community), including all kind of stuff (from the company groupie to tinfoil-hat conspiracy theories), I have decided to put too many hours some time to discuss the different threat models for email setups, including the basic most people have, the "secure email provider" one (e.g., Protonmail) and the "I use arch PGP manually BTW".

Jokes aside, I hope that it provides an overview comprehensive and - I don't want to say objective, but at least rational - enough so that everyone can draw their own conclusion, while also showing how certain "radical" arguments that I have seen in the past are relatively shortsighted.

The tl;dr is that email is generally not a great solution when talking about security. Depending on your risk profile, using a secure email provider may be the best compromise between realistic security and usability, while if you really have serious security needs, you probably shouldn't use emails, but if you do then a custom setup is your best choice.

Cheers

https://loudwhisper.me/blog/email-security/Open linkView original on infosec.pub
45
selfhosted·Selfhostedbyloudwhisper

Basic Security for your Website | Loudwhisper

Hi, recently (ironically, right after sharing some of my posts here on Lemmy) I had a higher (than usual, not high in general) number of "attacks" to my website (I am talking about dumb bots, vulnerability scanners and similar stuff). While all of these are not really critical for my site (which is static and minimal), I decided to take some time and implement some generic measures using (mostly) Crowdsec (fail2ban alternative?) and I made a post about that to help someone who might be in a similar situation.

The whole thing is basic, in the sense that is just a way to reduce noise and filter out the simplest attacks, which is what I argue most of people hosting websites should be mostly concerned with.

https://loudwhisper.me/blog/basic-web-security/Open linkView original on infosec.pub
74
selfhosted·Selfhostedbyloudwhisper

PSA: GoDaddy gated their own API. DDNS users warned

GoDaddy really lived up to its bad reputation and recently changed their API rules. The rules are simple: either you own 10 (or 50) domains, you pay $20/month, or you don't get the API. I personally didn't get any communication, and this broke my DDNS setup. I am clearly not the only one judging from what I found online. A company this big gating an API behind such a steep price... So I will repeat what many people said before me (being right): don't. use. GoDaddy.

https://loudwhisper.me/blog/yak-shaving-godaddy/Open linkView original on infosec.pub
322
technology·Technologybyloudwhisper

I hate Clouds - a personal perspective on why I think Clouds suck

I hope this won't be counted as some form of self-promotion, even though I am sharing a post from my own blog.

As a tech worker who works in a Cloud shop, I wanted to elaborate the many reasons why I find working with Clouds terrible, from multiple points of view.

I tried to organize my thoughts in a (relatively long) post, in which both technical aspects and political aspects (which are very related) are covered.

I am sure many people will have different perspectives, and this could be potentially also a nice prompt for a discussion.

https://loudwhisper.me/blog/hating-clouds/Open linkView original on infosec.pub
239

You reached the end