• RedGreenBlue@lemmy.zip
    link
    fedilink
    English
    arrow-up
    24
    arrow-down
    1
    ·
    2 days ago

    Hackers warns Microsoft are targeting Windows users PCs: What to know.

    Microsoft is stealing your files, cookies, etc. Microsoft have access to your 365 account, one drive and email.

    Microsoft collects documents and are able to capture keystrokes, screenshots, audio, and video, monitor the clipboard, and change your preferences and more.

  • Septimaeus@infosec.pub
    link
    fedilink
    English
    arrow-up
    42
    arrow-down
    1
    ·
    edit-2
    5 hours ago

    Seriously, this is the lowest hanging fruit. Never trust hotel WiFi.

    E: infants and their alts

    • LordCrom
      link
      fedilink
      English
      arrow-up
      9
      ·
      10 hours ago

      Wrong. Never download and install any wifi profile package, escpecially if it has certs to install. That is just asking to have all your traffic decrypted and data taken.

    • Scrubber0777@lemmy.ml
      link
      fedilink
      English
      arrow-up
      22
      ·
      2 days ago

      Agree with your sentiment especially not trusting hotel Wifi (or heck all open network for this matter).

      I’d even err on the safe side and suggest not download any certificate and encryption profile at all.

      Even if I find myself as a tech literate person, I’d not trust my ability to identify the legitimacy of the download.

    • rozodru@piefed.world
      link
      fedilink
      English
      arrow-up
      6
      ·
      2 days ago

      extremely low hanging fruit. I travel a lot for work and all my laptops have VPNs with encrypted DNS. Even had to set that up on one of my FreeBSD installs (which was a god damn pain and with the shit wifi on that there really wasn’t much of a point at the end of the day).

      it’s even more mandatory for places that have NO captive portals. Those connections are opening themselves up to a can of worms. Looking at you Union Station in Toronto Canada. seriously, fix your shit. One of the biggest transit hubs in all of Canada and their wifi is completely 100% open.

      • Septimaeus@infosec.pub
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 days ago

        lol same at Union Station WDC and all Amtrak trains (if the wifi even works). Finally switched to a gl.inet (openwrt) hotspot for work travel and haven’t looked back.

    • pHr34kY
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      7
      ·
      2 days ago

      I don’t think anything can monitor or mess with your local web traffic once you have encrypted DNS.

      VPNs don’t add any privacy over HTTPS+DoH. Installing CA certs and whatnot is insane.

      Stop getting your opsec advice from influencers on youtube. It’s snake oil.

      • Assassassin@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        2
        ·
        11 hours ago

        “VPNs don’t add any privacy over HTTPS+DoH”

        For someone so smug, you sure say some stupid shit. In what world would wrapping all of your traffic in an encrypted tunnel not provide additional privacy when using a public endpoint?

        • pHr34kY
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          2
          ·
          10 hours ago

          You’re routing all your traffic through a single inspection point. They too can scrape anything that isn’t HTTPS. They can list every site you visit without DoH.

          Corporations are just as unaccountable as ISPs and governments.

      • Septimaeus@infosec.pub
        link
        fedilink
        English
        arrow-up
        9
        arrow-down
        1
        ·
        2 days ago

        Hotel can see every site you connect to and you’re exposed to SNI fingerprinting by their ISP. Metadata leaks over both LAN and WAN (traffic volume, timing patterns, dest IPs, connection frequency) and both netadmin and ISP can infer your browsing habits without actually seeing the content. Other guests with wireshark and too much time on their hands.

        Moreover, many types of traffic aren’t HTTPS, including NTP, DHCP, SNMP, FTP, SSH (without HTTPS), most IoT devices, VoIP, gaming traffic, many application APIs, apps with embedded DNS overrides (really apps in general, especially mobile apps, especially meta and alphabet apps), even email unless TLS is explicitly configured. And many websites simply don’t serve HTTPS and will attempt to redirect to HTTP.

        This is without getting into encryption strength and post-quantum standards. And I was referring to 802.1X/MDM enterprise profiles not CA.

        • pHr34kY
          link
          fedilink
          English
          arrow-up
          4
          ·
          edit-2
          10 hours ago

          NTP, DHCP, SNMP, FTP, SSH

          • NTP just tells you time. No confidential data here.
          • DHCP and SNMP dont go over the internet. A VPN won’t save you from this.
          • FTP is dead. Not even web browsers support it anymore.
          • SSH is already encrypted. In some cases, it can literally be used as a VPN.

          Wireshark is useless on WPA3. Although hotel wifi typically doesn’t use it.

          SNI is encrypted with ECH.

          I disabled plaintext SMTP on my mail server years ago. Requiring TLS actually reduced spam by 99%. No reputable mail server will use plaintext.

          Almost nothing uses plain HTTP. The only thing I typically see is my phone’s internet connectivity check, which simply returns an HTTP 204 (No content). It’s practically a ping.

          HTTPS + DoH is enough because all of these problems are solved.

  • IWW4@lemmy.zip
    link
    fedilink
    English
    arrow-up
    23
    ·
    2 days ago

    Is this an archive article?

    Hotel WiFi has been “targetted” by hackers since the they were first put in.

    • some_designer_dude
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 days ago

      Hacking hotel wifi is like “paint by numbers” for pen-testers, I’m sure. “I’m in!” “… The door was just, like, wide open.”

  • John Richard
    link
    fedilink
    English
    arrow-up
    11
    arrow-down
    2
    ·
    2 days ago

    How do I warn people that Microsoft is targeting Windows users with adware, spyware, security vulnerabilities and surveillance?

  • Sims@lemmy.ml
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    2
    ·
    2 days ago

    Incredible that all big US tech is now suddenly trusted researchers/detectives, judge, jury and a societal security pillar alerting citizens without any intrinsic bad intentions (cough).

    I think these ridiculous scaremonger posts, with insanely biased claims, belong to either not-the-onion or similar joke subs, or should simply just be deleted. Some random tech-lord psycho corp (that never speaks the truth) claims random badness about US/Epsteins enemies… I mean ffs 1. its stupid, and 2. its racist slur without any evidence AT ALL!! …and racism don’t belong on Lemmy subs at all!

    Oh, and its incredible that they never found any of the US Gov attacks against both their own citizens, and against all other nations and their citizens. Snowden showed it all, but micro-shit are somehow not capable of catching US instigated crimes against humanity, and not capable of detecting any of the Capitalist surveillance operators that hacks every user on all sites, or anything really. I mean, Microsh*t themselves steal more information and are harming more people than any ‘hacker’. Its almost like they voluntarily participate in deliberate propaganda - coordinated with US fascist Gov.

    Here’s what Microshts best security advice should be: “Don’t use Microsoft products !”. Microsht is far far more dangerous for normal people than any ‘hacker’ threats out there…

    • klugerama
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 day ago

      Me: that’s not what racist means…

      looks at username

      Oh right.

  • ExLisper@lemmy.curiana.net
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    1
    ·
    2 days ago

    “”" Users are then prompted to download malicious files, after which the hijackers infect the user’s device with malware that collects browser cookies, passwords, documents and more, Microsoft said. The hackers are able to capture keystrokes, screenshots, audio, and video, monitor the clipboard, and operate the device remotely.

    In some instances, users attempting to access a compromised network may be redirected to fake login screens, at which point, the hijackers will be able to access the user’s Microsoft 365 account, giving them further access to the person’s email and OneDrive.“”"

    Yeah, don’t download random files or giver your credentials to random pages, on both public and private WiFi. As long as you don’t do stupid things everyone uses https now so you’ll be fine.

  • gian @lemmy.grys.it
    link
    fedilink
    English
    arrow-up
    3
    ·
    2 days ago

    On an unrelated news, Microsoft warns that water is wet.

    That hotel Wi-Fi networks are not the most secure networks is nothing new to be honest…

  • cub Gucci@lemmy.today
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    5
    ·
    2 days ago

    The only open wifi I trust is the one that doesn’t give me access to the internet unless I install their CA