Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Zack Whittaker
@zackwhittaker@mastodon.social  ·  activity timestamp 5 days ago

According to Nevada's report into its recent ransomware attack, a state employee "searched Google for a system administration tool to download and was instead shown a malicious advertisement that led to a fraudulent website impersonating the legitimate project."

Yeah, that happens a lot! An ad-blocker is one of your top security and privacy defenses online. If you work in an enterprise org, consider rolling out an ad-blocker to your company network!

Here's more from me: https://this.weekinsecurity.com/why-ad-blockers-are-a-top-security-and-privacy-defense-for-everyone/

~this week in security~

Why ad blockers are a top security and privacy defense for everyone

Ad blockers can help defend against some of the top hacks, scams, and surveillance today. Here are some of the best ad blockers that you can use.
  • Copy link
  • Flag this post
  • Block
Sean Boots
@sboots@mastodon.sboots.ca replied  ·  activity timestamp 3 days ago

@zackwhittaker @sleepycat 💯💯💯

  • Copy link
  • Flag this comment
  • Block
The Lack Thereof :v_bi:
@lackthereof@beige.party replied  ·  activity timestamp 5 days ago

@zackwhittaker
Lol I had ublock installed on my browser at work and it was auto-uninstalled by some IT script after a week or so

  • Copy link
  • Flag this comment
  • Block
SpaceLifeForm
@SpaceLifeForm@infosec.exchange replied  ·  activity timestamp 5 days ago

@zackwhittaker

Why isn't Gemini smart enough to drop from search? /s

  • Copy link
  • Flag this comment
  • Block
lemgandi
@lemgandi@mastodon.social replied  ·  activity timestamp 5 days ago

@zackwhittaker Also, Google.

  • Copy link
  • Flag this comment
  • Block
JohnnyJingle
@JohnnyJingle@mastodon.social replied  ·  activity timestamp 5 days ago

@zackwhittaker There's a common thread between Chromium's adblock hobbling and Android Developer Verification - both want to technologically keep you from circumventing Google's slop, using security as a pretext, but their vetting is so dogwater that you're actually less safe than if you use f-droid and an adblocker.

  • Copy link
  • Flag this comment
  • Block
Dries V.
@verbedr@mastodon.sdf.org replied  ·  activity timestamp 5 days ago

@zackwhittaker it's about time to make the liable for the ads they publish. Google earned money from this attack.

  • Copy link
  • Flag this comment
  • Block
James Valleroy
@jvalleroy@fosstodon.org replied  ·  activity timestamp 5 days ago

@zackwhittaker
I've seen this happen to a coworker who was trying to install Firefox on Windows.

  • Copy link
  • Flag this comment
  • Block
David Chisnall (*Now with 50% more sarcasm!*)
@david_chisnall@infosec.exchange replied  ·  activity timestamp 5 days ago

@zackwhittaker

Given this and the recent Facebook news, there's a very strong case to be made that an ad provider is legally an accomplice to any crime committed by their ads. If they are profiting financially from enabling crime, they are criminals.

  • Copy link
  • Flag this comment
  • Block
Multimilliardaire
@multimilliardaire@piaille.fr replied  ·  activity timestamp 5 days ago

@zackwhittaker

Well, a person pretending he/she is a professional in sysadmin who does such things should consider a career change or be more seriously supervised, first of all.

#AdaptiveManagement

  • Copy link
  • Flag this comment
  • Block
WhoDisturbsMySlumber
@WhoDisturbsMySlumber@mastodon.social replied  ·  activity timestamp 5 days ago

@zackwhittaker the average consumer is marketing fodder. We get little protections from these marketing agencies and search engins putting these in front of our faces. I don't fall for I but I know 20 who would

  • Copy link
  • Flag this comment
  • Block
ts 🚉
@tsyum@thepit.social replied  ·  activity timestamp 5 days ago

@zackwhittaker this reminds me of a question I've had: Can we get ad-blockers that don't *tell* the advertiser we're blocking them?

  • Copy link
  • Flag this comment
  • Block
VessOnSecurity
@bontchev@infosec.exchange replied  ·  activity timestamp 5 days ago

@zackwhittaker Uhm, how would have an ad blocked helped in that case? It seems that the employee was a victim of SEO poisoning, not of a malicious ad. They weren't just shown an ad for the malicious site out of the blue - they searched for a tool and clicked on one of the results displayed by Google.

  • Copy link
  • Flag this comment
  • Block
S★m V★rm★
@samvarma@fosstodon.org replied  ·  activity timestamp 5 days ago

@zackwhittaker @briankrebs Honest question: I have had 1Blocker installed since iOS enabled blockers. To what extent does an app like this intercept and identify my legitimate web traffic? In this case the developer is Russian from what I can see, which, while not immediately rendering them untrustworthy, does raise my eyebrows ...

  • Copy link
  • Flag this comment
  • Block
Zack Whittaker
@zackwhittaker@mastodon.social replied  ·  activity timestamp 5 days ago

@samvarma @briankrebs I have recommendations for iOS in my piece. some apps like Wipr 2 hook into your Safari browser, but they don't see or access your browsing history or the websites you visit.

  • Copy link
  • Flag this comment
  • Block
Eggs now in different baskets.
@the_wub@mastodon.social replied  ·  activity timestamp 5 days ago

@zackwhittaker
Another thing that can help is an updated and fully functioning pi-hole between you and the internet.

pi-hole runs on anything that runs a supported OS although I use a Raspberry Pi 2 for this purpose.

#pihole #raspberrypi

  • Copy link
  • Flag this comment
  • Block
Hey Gus
@elebertus@mastodon.social replied  ·  activity timestamp 5 days ago

@zackwhittaker I hadn’t used windows for many years and just started again a few weeks ago.

I searched for “windows rsat” and the MS download link was not the first result. There were several shady looking domains all throughout the result. It’s honestly kind of nuts.

  • Copy link
  • Flag this comment
  • Block
Kaito
@kaito02@mastodon.social replied  ·  activity timestamp 5 days ago

@zackwhittaker funny thing is that Google is THE company that thrives on ads

  • Copy link
  • Flag this comment
  • Block
MostlyBlindGamer
@MostlyBlindGamer@dragonscave.space replied  ·  activity timestamp 5 days ago

@zackwhittaker it’s also essential for #accessibility!

I don’t need any light gray X buttons in my life.

  • Copy link
  • Flag this comment
  • Block
Zack Whittaker
@zackwhittaker@mastodon.social replied  ·  activity timestamp 5 days ago

@MostlyBlindGamer this is good to know! thank you for sharing

  • Copy link
  • Flag this comment
  • Block
nemo™ 🇺🇦
@nemo@mas.to replied  ·  activity timestamp 5 days ago

@zackwhittaker 💯

  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login