mathstodon.xyz is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Mastodon instance for maths people. We have LaTeX rendering in the web interface!

Server stats:

2.9K
active users

#opsec

20 posts19 participants0 posts today

RaspberryPi Zero2w serves whole world and terrain from 256 GB MicroSD card. Pictured white box contains RPi and creates wifi access point. Phone attached to AP and browser allows you to browse full world map. No need for Internet connectivity or SIM card in you phone. Perfect tool for preparedness and denied area planning.
youtube.com/shorts/TAY2yY8TAoY

youtube.comBefore you continue to YouTube

I talked a boatload of shit today about RFK, the Federal judiciary enabling Ostarbeiter to take place in the US, RFK's desire for concentration camps for ADHD & autistic folks, & the DOJ dropping charges on the Texas doctor who went after trans patients & violated HIPAA.

At the end of the day, every patient agreed that deleting their ASD diagnosis was the right thing to do right now.

Why do I share this?

Im urging all providers to have similar conversations with patients before September. Some may glean services from ASD diagnosis. Factor in a risks benefit discussion. Let them decide.

It's urgent.

Sources:

Federal enabling: apnews.com/article/illegal-imm

Ostarbeiter: mstdn.social/@Npars01/11431606

RFK 1: cbsnews.com/news/rfk-jr-cause-

RFK 2: motherjones.com/politics/2024/

DOJ: texastribune.org/2025/01/24/tr

Further, autism self diagnosis is largely valid & UWash website has links.

depts.washington.edu/uwautism/

depts.washington.edu/uwautism/

#question #didyouknow #todayilearned #til

Windows is reinstating Recall,
Snapshots of screen saved every 3 seconds and fed to AI.
Previously introduced in May, 2024 to some backlash.

(...)"a gold mine for malicious insiders, criminals, or nation-state spies if they managed to gain even brief administrative access to a Windows device."
(...)"nothing stopping Recall from preserving sensitive disappearing content sent through privacy-protecting messengers such as Signal."
(...)"Windows 11 Build 26100.3902 preview version. Over time, the feature will be rolled out more broadly."
(...)"That would indiscriminately hoover up all kinds of User A's sensitive material, including photos, passwords, medical conditions, and encrypted videos and messages."
(...)"That level of detailed archival material will undoubtedly be subject to subpoena by lawyers and governments."

etc. etc.
Yeah...

#microsoft#windows#os

One MicroSD card and Raspberry PI. With $35 + $24 you get totally off the grid planning environment for your tasks. Plan and coordinate regardless access to infrastructure like cellular or satcom. Sometimes it's also good if you don't leave traces to great firewalls. Edgemap is open source and available at my Github for free!
#edgemap #preparedness #offthegrid #opsec #tak #atak #mesh #manet #meshtastic

youtu.be/CMUB8S3AKzw

youtu.be- YouTubeEnjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.

The Mother of All Breaches (MOAB), revealed in January 2024, is the largest data leak ever recorded. It exposed over 26 billion records from more than 3800 separate data breaches. Discovered by security researcher Bob Dyachenko, the dataset was found sitting openly online and included login credentials, emails, and other sensitive information from services like Tencent, LinkedIn, Twitter, MySpace, and Canva.

What makes MOAB so dangerous is not just the size but the consolidation. Having all this data in one place makes it far easier for attackers to launch phishing campaigns, credential stuffing, and identity theft on a massive scale. Many of the records were from past breaches, but their combination into a single archive magnifies the threat.

It is a brutal reminder of how exposed our online lives really are and how critical it is to use strong, unique passwords, enable multi-factor authentication, and regularly check breach notification services.

Replied in thread

@ulrichkelber gibt es Informationen darüber, wie @zendis sich gegen #supplyChain -Attacken und Sicherheitslücken in den zugrundeliegenden #OpenSource -Lösungen von #OpenDesk und #OpenCode wappnet, um zusätzlich zur #Souveränität auch die IT-Sicherheit der Systeme ausreichend sicherzustellen? Wie wird bei der Weiterenwicklung und Updates geprüft, damit kein Schadcode eingeschleust wird?
#ITSecurity #Zendis #OpenSource #HybriderKrieg #OpSec #Kritis

Here's a somewhat novel #LinkedIn connection request scam.
I am not, actually, connected to the person named in the message sent with this connection request. In other words, "Notice you're connected with her," is simply a lie. Did they think I wouldn't notice, or what? I suppose maybe some people wouldn't.
Needless to say I blocked this person. I am careful in general about whom I connect with on LinkedIn, but I especially don't want to interact with dirtbag scammers.
#infosec #opsec #scam

Replied to Robert [KJ5ELX] :donor:

@0xF21D The way I see it is that even if end-user device security is poor, proper E2EE such as that used by Signal still provides a significant benefit: It shifts the burden of an attacker from wholesale dragnet surveillance (which is easy to do in bulk) to focused attack targetting (very difficult to do in bulk, especially inconspiciously).

*Even if* device security sucks, which would equally impact other services as well, that *still* provides a privacy benefit.

Don't let the mainstream news media convince you that #signal is a bad choice for end-to-end encryption. What the media fails to do is convince you that the state of security on end user devices ends up bad because people are prone to making bad decisions.