himazawa

joined 2 years ago
MODERATOR OF
[–] [email protected] 3 points 2 years ago (1 children)

I don't know why the author of the video didn't mention it but LockDown mode is really useful.

At least for me the default is lockdown mode on and appropriate exceptions for websites I trust.

[–] [email protected] 3 points 2 years ago* (last edited 2 years ago) (2 children)

I believe the risk of running outdated software is super inflated and mediatic, 99% of people would be absolutely fine running a version of Android from 3 years ago or Windows 8.

That's the same thing people running windows XP on internet were thinking in 2017.

Then WannaCry arrived and they got their data encrypted :)

[–] [email protected] 3 points 2 years ago* (last edited 2 years ago)

Perhaps images, video, font etc. rendering could be compromised?

Yes, it already happen in the past. Also the Wi-Fi and Bluetooth stack got exploited, like multiple kernel drivers.

But it shouldn't be a matter of "in the past was X exploited?" but more on having a correct security posture.

Honestly if you are arguing about wasting a "perfectly working phone" you should blame it on the vendor, especially Android devices vendors have this let's say "defect" of dropping the support after 4/5 years.

Also not going to talk about custom ROMs (with the super rare exclusion of some) managed by god knows who, without any security team behind.

Since even the NFC and Cellular Network stack got vulnerabilities the only way you would consider an old phone "safe" to use is just turning it into the equivalent of a local ARM server.

Also pretty fun seeing the replies in the original post talking about how Google Play store shouldn't have malware on it.

[–] [email protected] 6 points 2 years ago (3 children)

Do anyone knows if it support local-only without joining the p2p network?

[–] [email protected] 1 points 2 years ago* (last edited 2 years ago) (1 children)

Exploited in the wild, reported in April, no fix since then?

Edit: looks like it was fixed on the 26th of April, why is tagged as 0day?

[–] [email protected] 1 points 2 years ago* (last edited 2 years ago)

Ahaha I had this exact same experience. Locked out because bitwarden didn’t get the code correctly. “Luckily” the jwt token never expires so I was able to log back in without the 2FA.

[–] [email protected] 5 points 2 years ago

So in the end you got removed.. I honestly have no idea how they want to do an IPO like that

[–] [email protected] 1 points 2 years ago

I wonder if people when talking about AI just ignore the fact that it’s software and has the same issues and vulnerabilities related to that.. recently I see a lot of posts talking about “AI security” and in the end are stuff known since 1995…

[–] [email protected] 2 points 2 years ago

I was thinking about that just today, I have something like 30+ services running on a single compose file and maintenance is slowly becoming hard. Probably moving to multiple compose file.

[–] [email protected] 5 points 2 years ago (8 children)

Thanks. I have never seen the last thing, what the numbers indicates?

[–] [email protected] 9 points 2 years ago (15 children)

What am I looking at?

[–] [email protected] 1 points 2 years ago (3 children)

I use the Inbox-Zero method

https://youtu.be/al1QXFQjq1s

So far no issues.

view more: ‹ prev next ›