UID_Zero

joined 1 year ago
[–] UID_Zero@infosec.pub 1 points 4 hours ago (1 children)

Fair, but I meant updates from the original manufacturer.

[–] UID_Zero@infosec.pub 28 points 23 hours ago (5 children)

You gain very little from security because nobody is targeting you...

It's not about being targeted, it's about being caught in the big fishing net that scammers are throwing. You don't have to be targeted to have security concerns.

If a phone isn't receiving regular security updates, I won't use it. My Pixel 5a just got replaced because it's coming up on end of support. My new Pixel has 7 years of support, so I feel a lot better about keeping it longer.

[–] UID_Zero@infosec.pub 1 points 1 week ago

There are probably newer ones that come with LiPos. But every consumer grade one I've seen is traditional lead acid batteries.

[–] UID_Zero@infosec.pub 21 points 1 week ago (6 children)

...(it is kinda like a bomb after all)...

WAT? I've never heard a UPS referred to as "kinda like a bomb" before.

Keep your UPS maintained, replace the batteries when they age out, and it will be fine. If your UPS supports automated self-tests, use them.

My employer has UPS units spread all over the region we operate in, and we don't have any issues, despite leaving them mostly unattended for years. I have several in my house and I've never given them a second thought aside from battery replacements.

[–] UID_Zero@infosec.pub 27 points 2 weeks ago (2 children)

My VPN app took a shit in the middle of a download and I think it exposed my IP to some “anti-piracy” bullshit firm that contacted my ISP.

I think you answered your own question.

[–] UID_Zero@infosec.pub 2 points 1 month ago (1 children)

My phone has a passcode, so does my password manager and my MFA app - all different passwords. Those are the only ones I need to remember, so it’s not too bad.

Probably not ideal, but to break that someone needs to A) physically get my phone, B) unlock my phone, C) unlock my pw vault, and D) unlock my MFA app. I’m fairly confident in my setup.

[–] UID_Zero@infosec.pub 4 points 1 month ago

Same, but my seeds are stored in a separate vault from my passwords. Seems like having MFA and passwords in the same place defeats the purpose. I used to let keepassxc auto fill MFA tokens, but finally changed to a separate app.

[–] UID_Zero@infosec.pub 6 points 1 month ago

I use it for my work mail. I can’t speak to their privacy, but I think it’s ok. So far as I know they haven’t done anything stupid, and all the connections are only from my device, no cloud intermediary.

I do like that it allows you to only apply the ActiveSync policies to the app instead of the entire device. If my employer remote wipes my device, it only impacts the app.

[–] UID_Zero@infosec.pub 3 points 1 month ago (1 children)

Also that if you’re doing CPR alone don’t bother with the breaths, the chest compressions are more important - only do breaths with a second person so you can keep compressions going uninterrupted.

I took a class last year that said this. It was "Shock and Compress." The compressions are doing more good than worrying about breaths. And delegate someone to find an AED.

It felt a little silly taking that class given that I work for a health org, and I'm fully remote. The odds of my needing to know if seem pretty low, but you never know when it might be important.

[–] UID_Zero@infosec.pub 2 points 2 months ago

I barely used my joycons, but I had drift. I don’t think I was misusing them, I only used them when mobile, and that was infrequent. And yet they drifted.

I replaced the sticks with Hall effect sticks, and they’ve been fine since.

[–] UID_Zero@infosec.pub 4 points 3 months ago

Same, and agreed. I don't listen to much, but it's been very nice.

[–] UID_Zero@infosec.pub 2 points 3 months ago

It's only as insecure as you make it. It's an option, it needs to be used responsibly.

view more: next ›