• 22 Posts
  • 921 Comments
Joined 3 years ago
cake
Cake day: December 20th, 2021

help-circle







  • “This is a particularly sophisticated supply chain attack,” noted Mika Aalto, Principal Threat Researcher at Withsecure.

    Mika Aalto is an incompetent clown. A “Principal Threat Researcher” at any company should understand the difference between a trojanized version of an app distributed through phishing, and a supply chain attack.

    Security experts have identified multiple attack vectors, with the primary distribution channel being tampered download links spread through phishing emails and malicious advertisements that redirect users to convincing but fraudulent KeePass download pages.

    🤡




  • there is no need to be rude and combative about it.

    Actually, I think that when anyone makes claims that their software is “private,” being combative is strictly necessary.

    The bar needs to be set very high for any software that is handling our personal data and claiming to be private, because when these systems fail it can lead literally to the death of the user in some places in the world.

    How do users in dangerous situations know what software they can rely on for private communications? It is through peer-review and reputation that we as a community filter down the available software to those things that we actually recommend. And peer-review is inherently combative, because it requires pointing out every potential weakness in any part of a system, and any hint of suboptimal behaviour.