ruby.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
If you are interested in the Ruby programming language, come join us! Tell us about yourself when signing up. If you just want to join Mastodon, another server will be a better place for you.

Administered by:

Server stats:

1.1K
active users

#opsec

32 posts19 participants3 posts today

Here's a somewhat novel #LinkedIn connection request scam.
I am not, actually, connected to the person named in the message sent with this connection request. In other words, "Notice you're connected with her," is simply a lie. Did they think I wouldn't notice, or what? I suppose maybe some people wouldn't.
Needless to say I blocked this person. I am careful in general about whom I connect with on LinkedIn, but I especially don't want to interact with dirtbag scammers.
#infosec #opsec #scam

File under "if there are people there are security holes":


Messages obtained by PressProgress suggest the group chat was created to give convoy leaders and their lawyers the ability to coordinate "media messaging / comms strategy" with "alt media/ influencers," who were cautioned that the "language we use. is incredibly important.

An 88-page document with instructions on messaging and narrative control was made available to the alt media personalities and influencers by a lawyer with the right-wing Justice Centre for Constitutional Freedoms. Numerous group chat messages show its members exchanging information, debating ways to counter anti-convoy narratives and identifying tweets to share and amplify

pressprogress.ca/conservative-

Continued thread

If you are partaking in a #protest, please do think of your and others' #OpSec (operational security). Depending on the protest, you might want to have it not linkable to your personal identity.

Some tips:

  • Consider taking measures that protect your identity. Wear a mask, wear clothes that you don't normally wear. Conceal any markings like tattoos and piercings.
  • Make sure you and fellow protestors are safe at any given time - wherever feasible. Help and advice others if you can.
  • No matter how secure your phone is - cellular connections do broadcast your location. Even if you take out the SIM. Either leave your phone at home or get a burner, paid with cash. And never, ever turn it on at home, at work or places that can be linked to you.
  • Do not link any IRL identities on that phone. Use a resilient app like @briar for communication during the protest. Briar is able to withstand internet and comms blackouts.

2/🧵

So, folks - we need to have a chat. I've seen a large number of #handsoff #protest photos. While I am deeply grateful to anyone protesting in whatever form, please keep from posting photos that reveal faces and/or identities of people you haven't have explicit permission from.

#OpSec is incredibly hard - protestors might not be aware of the (possible) consequences of having their identities posted and shared online.

It still needs to be a choice, whether any individual wants to be linked to the protest they've partaken in. Even if they did not wear a mask.

1/🧵

Continued thread

The review also will “review compliance with classification & records retention requirements,” Stebbins wrote. He requested that the #Defense Dept designate 2 points of contact within 5 days, with work done both in Washington & at the headquarters of US Central Command in Tampa, Florida.

The #Defense Dept inspector general’s office said Thurs that it will scrutinize top #Trump admin officials’ use of #Signal, an unclassified messaging app to coordinate a highly sensitive #military operation last month in Yemen, complying with a request from #Republicans & #Democrats in #Congress.

#Trump #NationalSecurity #OpSec #SignalGate
washingtonpost.com/national-se

The Washington Post · Inspector general to scrutinize Trump team’s Signal chatBy Dan Lamothe
Replied in thread

@rufposten @kuketzblog super spannendes Projekt! Ich freue mich jetzt schon auf den Artikel. Ich warte ja seit Ewigkeiten darauf, dass Firefox Relay (relay.firefox.com/) endlich auch Nummern anbietet. Aber da gibt es seit gefühlt Jahren nur eine Warteliste für das Feature. #FirefoxRelay #mozilla #OPSEC

relay.firefox.comFirefox Relay⁨Firefox Relay⁩ makes it easy to create email masks that forward your messages to your true inbox. Use them to protect your online accounts from hackers and unwanted messages.

My god, I just realized one of the simplest opsec things you can do (something I've been doing for years and don't even think about anymore) is set your browsers to open links in private/secure instances AS A DEFAULT.

If it needs to be opened in a window that you want to keep open or bookmark, you can always manually copy and paste it.

It makes no sense to be using a secure shared tool like cryptpad, if you're just gonna open it where you're logged in as you.

Remember the #SocialEngineering motto:
If there are people, there are security holes.

🚨 OPSEC Disaster at the Top: How Michael Waltz Just Compromised U.S. National Security—AGAIN! 🤦🏻‍♂️ 🤬

While the Trump administration lectures about digital security, National Security Adviser Michael Waltz has been using Gmail to coordinate military operations and sharing after-action strike reports in Signal group chats that accidentally included a journalist.

Let’s be clear:
・Personal Gmail was used to discuss weapons systems & troop movements
・Israeli surveillance was exposed—jeopardizing a key intelligence partnership
・Sensitive coordination went through Signal, not JWICS
・Waltz, who attacked Hillary Clinton for email practices, is now guilty of worse

This is not a technical mistake. It’s a policy failure, a hypocritical breach, and a serious threat to U.S. operational integrity.

If you lead in national security, you do not get to bypass your own secure systems. And you certainly don’t blame “legacy contacts” when you get caught.

Accountability isn’t partisan. It’s essential.

👉 washingtonpost.com/national-se

The Washington Post · Waltz and staff used Gmail for government communications, officials sayBy John Hudson