veganism.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Veganism Social is a welcoming space on the internet for vegans to connect and engage with the broader decentralized social media community.

Administered by:

Server stats:

296
active users

#infosec

400 posts230 participants4 posts today

If you've got cybersecurity knowledge to share and are new to conference presenting, I'd heartily encourage you to consider applying to present at ComfyConAU. I've attended and have to say it's the most wonderful, diverse online conference I've attended with a warm, inclusive community. The presentations I've seen there range from highly technical and tools-based hacking and defence, through to broad concepts to auditing and compliance to community topics.

Give it a go and never mind the timezone - you can get up early or stay up late!

#security #conference2025 #infosec #cybersecurity #ICS #blueteam #purpleteam

@ComfyConAU

In strange #fintech #infosec #privacy news, an Estonian bank, the LHV Bank, is claiming 247.5M€ from the government's money laundering regulator over the regulator having accessed banking secrecy protected data from the bank in a roundabout way — through the judicial enforcement register, a practice that the Justice Chancellor has recently opined to be unconstitutional. Other banks may follow.

It appears that there is a vulnerability in the legal framework, in that it takes a specific and narrowly tailored court order for the money laundering regulator to get detailed transaction and/or account data directly from a bank, but the judicial enforcement register, having been built on the assumption of functioning in the world of already enforceable court orders, has procedural direct access to banking data, but no procedural safeguards to actually check for a court order existing as a precondition for such access, and the money laundering regulator seems to have been using this loophole for large-scale surveillance for about five years.

LHV bank's general term of service specify 100k€ in contractual damages per unlawful query, and I surmise they have found 2475 of such roundabout queries in their audit logs.

Source: err.ee/1609754001/lhv-nouab-ra

Eesti Rahvusringhääling | ERR · LHV nõuab rahapesu andmebüroolt pangasaladuse asjas 247 miljonitBy uudised | ERR

🦩💻 SashAlert:
I JUST GOT GOOSEBUMPS. (Not that you can tell through my fabulous plumage.)

🗣️ My friend @Tarah Wheeler is keynoting BSidesChicago 2025 with a talk titled:

“Me and What Army: Civilian Defenders vs Foreign Military Cyberattacks”

UM, EXCUSE ME?! ICONIC.

Because let’s be real—while some governments are still figuring out how DNS works, it’s us holding the line.
💅 The night-shift SOC analyst.
💥 The patch-before-panic blue teamer.
🪖 The flamingo with a firewall and a dream.

This talk is going to shake feathers.
And I will be front row, sipping Red Bull and polishing my talons.

🎟️ Tickets:events.humanitix.com/bsideschi
🗓️ Nov 1, 2025

🦩 The Flamingo Uprising has found its battle cry.

events.humanitix.comBSidesChicago 2025BSidesChicago 2025 is Oct 31–Nov 1! 🎉 Conf tix $20/$10 student. Prices rise Sept 1. Workshops TBD. Sasha says grab yours now: bsideschicago.org 🦩

For those attending @defcon the special edition of Casey Erdmann's Red Team Engineering will be available at our booth! Many resources out there focus on either tooling or infrastructure, but rarely both in practical detail.

This book aims to bridge that gap, providing hands-on instruction for writing custom offensive tools and then engineering the infrastructure to use them effectively.

I share the same common view of online ID verification as most other #infosec people: it's a ludicrous situation that *increases* risk to everybody, handing data over to a mish-mash of organisations with very little transparency or rigour.

But I am enjoying the particular absurdity of seeing it in implementation. I hit a site that requires ID verification, I tell my Tailscale/Headscale config to route through one of my servers in Europe, and no more need to provide ID.