#opsec

62 posts · Last used 13d

Just spotted a really specific #opsec role with Amnesty. They're hiring an Investigator for Arms & Armed conflict. Can be based in Dakar, Johannesburg, London, Mexico City or Nairobi. Working with multidisciplinary team with technical, legal, academic and other stakeholders. Experience with armed conflict investigation needed. To £66k (for London) Apply by Oct 6th #FediHire https://careers.amnesty.org/jobs/vacancy/investigator-arms-and-armed-conflict-4274/4302/description/
2
0
18
0
Inside PH4NTXM: #31 Firewall Supervision A firewall can be correct at boot and different five minutes later. PH4NTXM's normal-mode firewall guard polls the active ruleset every two seconds and compares its fingerprint with the expected state. Source rules are integrity-checked and syntax-checked before application, including the required NFQUEUE arrangement and disabled bypass behavior. A detected mismatch removes readiness and activates emergency Lockdown before restoration. Readiness returns after successful verification. This is ongoing, periodic supervision of the expected policy, giving Boot Pilot and Health a current protection signal instead of a one-time startup assumption. #ph4ntxm #linux #debian #os #live #privacy #security #opsec #infosec #research #tech #technology
1
0
5
0
Inside PH4NTXM: #29 System Ηardening Protection services need boundaries of their own. PH4NTXM combines selected kernel restrictions with component-specific systemd controls. The native packet worker, for example, uses a restricted capability set, protected system paths, limited address families, disabled core dumps, and a watchdog. The configuration constrains what individual services can access and exposes failures through their startup or runtime checks. The live operator still has passwordless sudo, so administrative access remains a trust boundary. Hardening reduces available interfaces within that model. Ιt does not survive a fully compromised kernel by assumption. #ph4ntxm #linux #debian #os #live #privacy #security #opsec #infosec #research #tech #technology
0
0
4
0
Inside PH4NTXM: #27 Network Drift Packet timing can change throughout a session. PH4NTXM's Network Drift uses netem to vary delay, jitter, and loss on qualifying Linux/Windows default-route interfaces. Profiles update every 20–59 seconds, with separate caps for wireless jitter and loss. Small duplication and reordering settings are also applied. Recognized tunnel, container, bridge, loopback, and ghost interfaces are skipped. This feature deliberately changes network behavior, so latency and throughput tradeoffs are real. Lonewolf does not apply this local shaping. Ιts network path follows Tor. #ph4ntxm #linux #debian #os #live #privacy #security #opsec #infosec #research #tech #technology
0
0
4
0
Inside PH4NTXM: #20 Display Persona Resolution, refresh rate, and pixel ratio form a profile together. PH4NTXM generates nominal display metadata from the selected hardware and GPU class. Laptop, desktop, gaming, and supported Apple personas receive bounded combinations, including connector identity and optional secondary-display metadata where applicable. The completed screen environment becomes input for the viewport generator and participating reporting components. Lone Wolf derives its own display state. These are managed persona values. Publishing display metadata does not physically change the monitor attached to the machine. #ph4ntxm #linux #debian #os #live #privacy #security #opsec #infosec #research #tech #technology
0
0
4
0
Inside PH4NTXM: #18 Protected CPU Reporting Different system commands should not disagree about the same session. PH4NTXM builds CPU model, feature, and topology information from the generated capability profile. It installs selected read-only cpuinfo and CPU sysfs views, while protected lscpu, nproc, and free commands expose corresponding session values. Unsupported reporting options return an explicit error instead of silently promising coverage they do not provide. This gives the managed reporting paths a consistent view, with a defined boundary around the interfaces PH4NTXM actually controls. #ph4ntxm #linux #debian #os #live #privacy #security #opsec #infosec #research #tech #technology
1
0
4
0
Apologies for the constant rebuilds and refactoring on PH4NTXM lately. Perfectionism is a curse, and I just can't let it go. Appreciate your patience while I'm fine-tuning the beast. If you have any questions, about it feel free to ask them, I will reply and respect all of them. As well some people keep on asking me about the commit date, why it's "35 years ago". As of this one, I'll let you search the exact date of the commit, and tell me what you think it is! #ph4ntxm #linux #debian #os #live #privacy #security #opsec #infosec #research #tech #technology
1
0
5
0
Inside PH4NTXM: #11 Authenticated DNS-over-TLS DNS deserves an explicit transport policy. In Linux and Windows modes, PH4NTXM points local resolution at Unbound and configures authenticated DNS-over-TLS forwarding. TLS authentication uses provider names and the system CA bundle, with encrypted forwarding required and no plaintext upstream fallback. The configured upstream sets follow the selected mode. Unbound also uses memory caching and conservative resolver settings, while a watchdog checks local resolution and requests a restart when the required conditions indicate a failure. Resolver availability and transport policy are both part of the design. #ph4ntxm #linux #debian #os #live #privacy #security #opsec #infosec #research #tech #technology
1
0
4
0
IMPORTANT MASTODON PASSWORD SECURITY/PRIVACY ISSUE…

For everyone:

If you are using the same password for Mastodon that you use anywhere else, CHANGE YOUR PASSWORD NOW.

A hacker is stealing accounts using something called “credential stuffing.” This means they use email/password combinations stolen from other sites.

You can check if your email is in a data breach elsewhere:

https://haveibeenpwned.com

Create a new strong password:

  1. 12+ characters
  2. Capital/lowercase letters
  3. At least one special character

For admins:

The hacker is using the same unique user agent.

Go-http-client/1.1

We’re seeing a pattern of IPs, but they’re from varying ISPs. They’re also not changing the account emails.

#Mastodon #Password #InfoSec #OpSec #Security #Privacy #Hacked #Hacker

167
19
360
4
W dyskusjach o cyberbezpieczeństwie coraz częściej pojawia się cyfrowy fatalizm. Wizja taniej inwigilacji zautomatyzowanej przez sztuczną inteligencję potrafi przytłoczyć, zniechęcając do jakichkolwiek działań ochronnych. To prawda, że nie mamy wpływu na rozwój tych technologii oraz na to, że rządy po nie sięgają. Warto jednak pamiętać o podstawowej zasadzie analizy ryzyka i skupić się na tym, co realnie kontrolujemy. Sztuczna inteligencja nie jest jasnowidzem. Aby zautomatyzowany system mógł zadziałać i wytypować obywatela, bezwzględnie potrzebuje odpowiedniego wsadu. Te algorytmy predykcyjne karmią się danymi z telemetrii gromadzonej przez korporacje oraz informacjami, które sami dobrowolnie udostępniamy w sieci poprzez OSINT. Dlatego właśnie podstawowa cyfrowa higiena to wciąż nasza najskuteczniejsza tarcza. Odcinając urządzenia od ciągłego wysyłania danych w tle oraz zachowując rozsądek w publikowaniu informacji o sobie, zatrzymujemy produkcję paliwa dla tych systemów u samego źródła. Brak danych u pośredników oznacza ślepe algorytmy. #cyberbezpieczenstwo #prywatnosc #higienacyfrowa #infosec #cybersecurity #privacy #opsec #threatmodeling #osint
4
1
3
0
Wczoraj pisałem, że wygoda to największy wróg bezpieczeństwa. Obrona prywatności często wymaga radykalnych kroków i odcinania telemetrii. To prawda, ale nie oznacza to wcale, że cyfrowa higiena zawsze musi pochłaniać mnóstwo czasu i wymagać zaawansowanej wiedzy inżynieryjnej. Dla zachowania zdrowej równowagi wrzuciłem nowy materiał do sekcji /guides. Zawarłem w nim absolutne minimum cyfrowego przetrwania dla każdego. To cztery fundamentalne kroki (w tym sprawdzony model 3 Tier Password System), które wdrożysz w zaledwie 15 minut. Zbudujesz solidny fundament, zyskasz cyfrowy spokój i odetniesz lwią część realnych zagrożeń. Zapraszam do lektury: https://eteryu.space/guides/jak-zabezpieczyc-telefon-w-15-minut/ #cyberbezpieczenstwo #infosec #prywatnosc #opsec #android #ios #poradnik #cyfrowahigiena
6
2
9
0
W nawiązaniu do wczorajszego tekstu o tym, że prywatność prosto z pudełka nie istnieje, przypominam moją serię o cyfrowej higienie. Pokazuję tam w praktyce, że bezpieczeństwo to codzienne nawyki. Część pierwsza o odzyskiwaniu kontroli: https://eteryu.space/cyfrowa-higiena-podczas-przerwy-na-kawe-jak-atwo-odzyskac-kontrole-nad-telefonem/ Część druga o izolacji toksycznych aplikacji: https://eteryu.space/cyfrowa-higiena-bez-kompromisow-jak-atwo-odizolowac-toksyczne-aplikacje/ Część trzecia o odcinaniu algorytmów: https://eteryu.space/cyfrowa-higiena-bez-podgladaczy-jak-atwo-odciac-algorytmy-i-zabezpieczyc-zdjecia/ Ta seria będzie kontynuowana. W kolejnych tekstach weźmiemy na warsztat bezpieczne zarządzanie hasłami oraz dywersyfikację danych. Zanim to jednak nastąpi, na blogu pojawi się bardzo ważny wpis tłumaczący od podstaw modelowanie zagrożeń. Zanim go opublikuję, mam dla Was zadanie na start. Zastanówcie się i odpowiedzcie sobie szczerze na jedno pytanie: przed kim dokładnie chronicie swoje informacje? Sprecyzowanie przeciwnika to absolutny fundament, od którego musicie zacząć budowę własnego modelu bezpieczeństwa. #infosec #cyberbezpieczenstwo #prywatnosc #bezpieczenstwo #opsec #higienacyfrowa #threatmodeling #cybersec
6
1
6
0
Często powtarzanym mitem w świecie cyfrowej higieny jest przekonanie o magicznej prywatności prosto z pudełka. W nowym wpisie na blogu rozkładam na czynniki pierwsze architekturę microG oraz obietnice popularnych systemów. Wyjaśniam zjawisko teatru prywatności oraz dlaczego poleganie na domyślnych ustawieniach to pułapka. Prawdziwe bezpieczeństwo to nawyki, a nie tylko zmiana oprogramowania. Pełny tekst znajdziecie tutaj: https://eteryu.space/zudzenie-prywatnosci-z-pudeka-dlaczego-podejscie-set-and-forget-to-puapka/ #infosec #prywatnosc #cyberbezpieczenstwo #grapheneos #android #degoogle #cyberhigiena #opsec
11
9
7
0
Another small improvement to PH4NTXM. The Nuke Kernel now allocates available RAM and zero-fills allocated memory before powering off. The goal has never been to add features for the sake of features. It's to make every session end as cleanly as possible while keeping the implementation simple and reliable. Small changes. Big impact. Thank you. #ph4ntxm #linux #debian #os #live #privacy #security #opsec #infosec #research #tech #technology
0
0
0
0
First known US federal prosecution over a phone's duress PIN: a traveler at Atlanta airport hands border agents a passcode, the device (GrapheneOS, per the indictment) irreversibly wipes itself - and he's now charged with destruction of property to prevent seizure. Up to 5 years. He's pleaded not guilty; a court decides this fall whether destroyed key material counts as "property." The operational lesson isn't about the tool. The tech did its job - the keys are unrecoverable, exactly as designed. Owning it is legal - triggering it during an active search is what produced the charge. A safeguard became a legal problem at the exact moment it was supposed to protect. After 30 years in security ops, my travel rule is simpler: the best defense isn't a wipe button, it's a device with nothing on it. Clean device or clean work profile · only what the trip needs · mail in the browser, nothing offline · company access and VPN after arrival · backups stay home. What you don't carry can't be seized - and nothing gets destroyed. Not just a US thing: under Schedule 7 in the UK, port officers can demand device passwords with no prior suspicion, and refusing can itself be an offence. Source: https://techcrunch.com/2026/07/24/us-accuses-american-of-allegedly-wiping-his-phone-using-a-duress-password-during-border-search/ #opsec #privacy #infosec #grapheneos
0
0
0
0