mastodon.xyz is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Mastodon instance, open to everyone, but mainly English and French speaking.

Administered by:

Server stats:

788
active users

#opsec

23 posts17 participants1 post today
Replied in thread

@dave_andersen @AVincentInSpace personally I consider any "#KYC" a risk-factor, and @signalapp has proven their ability and willingness to restrict functionality (i.e. their #Shitcoin-#Scam #MobileCoin) based off said #PhoneNumbers (Cuban, Russian and North Korean Numbers were excluded) which are in fact #PII (even if one doesn't have to #ID for obtaining a #SIM, they are circumstantial PII)...

  • They have neither "legitimate interest" nor legal mandate to collect said data (or to integrate a scammy Shitcoin for that matter) as the discontinuation of #ChatSecure / #TextSecure has eliminated the "technical necessity" to have those.

Either way they either have to yeet #Hegseth as client and/or stop collecting PII like PhoneNumbers - they gotta have to do something

#ITsec is a different story, but unlike #Signal these do not depend on a #PhoneNumber and work through @torproject / #Tor.

  • And I've been using Tor for almost 15 years now...

NPR Exclusive: #Trump White House looking to replace #PeteHegseth as defense secretary

The #WhiteHouse has begun the process of looking for a new leader at the #Pentagon to replace #Hegseth, according to a US official who was not authorized to speak publicly. This comes as Hegseth is AGAIN mired in controversy over sharing #military operational details in a group chat.

#NationalSecurity #OpSec #InfoSec #law
npr.org/2025/04/21/nx-s1-53713

Continued thread

"If you remember…I said no one is texting war plans," #Hegseth said on FauxNews. "What was shared over #Signal then [during the first leak, which surfaced last month] & now was informal, unclassified coordinations for media coordination [&] other things."

But the details he shared, 2hrs before airstrikes hit in Yemen, almost certainly were #classified, acc/to ret Marine Lt Col Mick Wagoner, who was a #military lawyer for 17 years & deployed to 4 war zones.

Been reading about this malware China is using written for Linux:

sysdig.com/blog/unc5174-chines

and it struck me: Why mount /tmp and /var/tmp without noexec, nodev, nosuid? Seems crazy to allow a directory anyone can write to, to run executables.

While we're at it, get rid of wget and curl and anything else that would allow them to even get a "dropper" on the system?

Isn't this common sense stuff?!

Sysdig · UNC5174’s evolution in China’s ongoing cyber warfare: From SNOWLIGHT to VShellAfter a year under the radar, the Sysdig Threat Research Team identified a new campaign from Chinese state-sponsored threat actor UNC5174.