WhatsApp's new Advanced Chat Privacy is pointless
#News #TechNews #Technology #WhatsApp #Meta #Facebook #SecurityTheater
WhatsApp's new Advanced Chat Privacy is pointless
#News #TechNews #Technology #WhatsApp #Meta #Facebook #SecurityTheater
Daily Podcast: WhatsApp's new Advanced Chat Privacy is pointless
#News #TechNews #Technology #WhatsApp #Meta #Facebook #SecurityTheater #podcast
»Your password must contain: At least 12 characters.« Und genau das ist jetzt mein Passwort, wenn euch meine 10 alphanumerischen, nicht lexikalisch angeordneten Zeichen nebst Sonderzeichen nicht reichen. Zefix. #uxfromhell #pseudosecurity #securitytheater
I need to alter some details with a money-adjacent entity. They want me to fill in a PDF form, accessible from the authenticated area of their portal.
They then complains that they can't authenticate the squiggle because “it's electronic” (Firefox can now sign PDF from within the browser, so why shouldn't I use that?).
They want a scanned manually signed printout of the form... because it's more authentic? ... And all that time, I need to hold on to my screams that I was in a strongly-authenticated web-session at the start of the dance...
Apparently, strong authentication rests on demonstrating access to a printer, a pen and a scanner.
@KarlHeinzHasliP @denki OFC I do wish for a real "#TransEuropeanExpress" that gets people from #Lisbon to #Helsinki and from #Oslo to #Athens faster than flying (if we account for the #SecurityTheater at #Aorports)…
Yes, this is about MailMate being EXTORTED by Google but it's also about every other 3rd-party MUA and every major mailbox provider, because they have imposed a web-centric authentication and authorization system on the world which moronically relies on annual security audits of MUAs to certify them for use with the fragile snowflakes which behemoth mail systems apparently are...
Fuck #Google and the garbage imitation of IMAP that they foist on users & fuck their #SecurityTheater of demanding CASA audits of every IMAP client before they allow it to do OAuth2.
If you use #GMail (or Google Workspace) you are actively supporting the enclosure of #email. Google does not want independent standards-compliant MUAs to touch their mail system. Google wants all of its users using their shit web interface or their shoddy apps. They want to own your email.
The iOS *app* works fine (using FaceID even) but the browser workflow has a "use phone" link and QR code, which sends the phone to a web page that wants to take a pic, but since the idiots at Jumio don't ASK for Camera access, iOS offers no means for me to give it to them.
It's stupid broken tools like this that make me wish I could bullshit well. Some slimeball sold this "service" to my CU, costing me money as a shareholder & it's junk.
Yes, the problem in Safari persists with Lockdown disabled for the site. I gather it's just lazy insecure garbage code.
#Jumio #SecurityTheater #InfoSec
It has finally happened, my CU has decided that in addition to a password & a security question for every login, they need to use some scam outfit called #Jumio to get "enhanced identity verification" which seems to be nothing more than a 3rd-party cookie.
Totally broken for macOS & iOS in "lockdown mode." I can't even get Safari to accept the "Start verification" link as a link. Phone-based flow wants to take a selfie, but it doesn't ASK for camera access, so no.
#InfoSec #SecurityTheater
Rational Astrologies and Security
John Kelsey and I wrote a short paper for the Rossfest Festschrift: “Rational Astrolo... https://www.schneier.com/blog/archives/2025/04/rational-astrologies-and-security.html
Dieser Quatsch geht mir sooooo auf den Keks...
#SecurityTheater
My dear cybersecurity auditors: We are following the best practices of TSA!
After doing all that, when I got to the tax form I needed, I had to go through yet another text message code verification hoop to actually see the statement.
Na toll: MS Defender blockiert eine #Cloudflare-Adresse, und jetzt habe ich auf dem Arbeitsrechner an zufälligen Stellen Löcher in beliebigen Webseiten.
#RIP #FirefoxOS, cuz @mozillaofficial refusing to sell #develooers devices made it a stillborn!
Oh joy, it's 2025 and some websites (mostly financial websites and apps) still don't let you paste passwords. Guess I'll just type m9!HfX7*pL^z2$BvK by hand then. So convenient! So secure #SecurityTheater
@GrapheneOS I guess #Revolut does the worst #SecurityTheater there can be when they allow Android 8.1 devices ...
Had a literally less-than-a-second power outage - just enough to make the light blink - and now my Firefox browsers, including @zenbrowser, are throwing a "captive portal detection" warning on my home wifi. What the actual fuck!?