Forumi
Home Pravila i pomoć Članovi Kalendar Današnji postovi


Povratak   PC Ekspert Forum > Ostalo > Razno
Ime
Lozinka

Odgovori
 
Uređivanje
Staro 19.06.2025., 18:06   #211
Neo-ST
Buying Bitcoin
Moj komp
 
Neo-ST's Avatar
 
Datum registracije: Feb 2007
Lokacija: Croatia
Postovi: 8,194
Glavno pitanje je mogu li oni uopće sa tim passwordima šta su ukrali išta. Ako su passwordi enkriptirani, onda su informacije nepotpune. Tehnički su ukrali passworde, ali ako ne mogu ništa s njima onda ne bi trebalo biti panike? Osim šta su hackeri opet pokazali najvećim firmama da nisu nedodirljivi.

Koliki je koeficijent da je opet Lazarus u pitanju...
Neo-ST je offline   Reply With Quote
Staro 19.06.2025., 18:22   #212
Night
Premium
 
Datum registracije: Oct 2008
Lokacija: Dbk
Postovi: 1,227
Citiraj:
Autor spawn Pregled postova
2FA od google-a ili mircosoft-a?

Google Authenticator je samo implementacija otvorenog TOTP protokola, mislim da je na Androidima bolje koristiti Aegis koji je open source i podržava import i export seedova.

Još bolje je ne koristiti TOTP aplikacije preko moba nego preko hadverskog standalone uređaja poput ovoga : https://www.token2.swiss/shop/produc...hardware-token

Seedove naravno kod kreiranja TOTPa pospremiti negdje na sigurno, po mogućnosti na enkriptirani vanjski medij i ne držati ih na računalu. Po mogućnosti koristiti Linux kod kreiranje i spremanja seedova, jer su Windowsi postali spyware.
Night je offline   Reply With Quote
Staro 19.06.2025., 19:23   #213
mkey
Premium
Moj komp
 
Datum registracije: Sep 2018
Lokacija: tu
Postovi: 3,250
Citiraj:
Autor Neo-ST Pregled postova
Glavno pitanje je mogu li oni uopće sa tim passwordima šta su ukrali išta. Ako su passwordi enkriptirani, onda su informacije nepotpune. Tehnički su ukrali passworde, ali ako ne mogu ništa s njima onda ne bi trebalo biti panike? Osim šta su hackeri opet pokazali najvećim firmama da nisu nedodirljivi.

Koliki je koeficijent da je opet Lazarus u pitanju...
Enkriptirani password je siguran dok ne otkriješ neki password pa onda tražiš sve enkriptirane passworde koji odgovaraju provaljenom. I to vrijedi samo ako se ne koristi salt.
__________________
Citiraj:
Autor George Carlin
But there’s a reason. There’s a reason. There’s a reason for this, there’s a reason education sucks, and it’s the same reason that it will never, ever, ever be fixed. It’s never gonna get any better. Don’t look for it. Be happy with what you got. Because the owners of this country don't want that. I'm talking about the real owners now, the real owners, the big wealthy business interests that control things and make all the important decisions. Forget the politicians. The politicians are put there to give you the idea that you have freedom of choice. You don't. You have no choice. You have owners. They own you. They own everything. They own all the important land. They own and control the corporations. They’ve long since bought and paid for the senate, the congress, the state houses, the city halls, they got the judges in their back pockets and they own all the big media companies so they control just about all of the news and information you get to hear. They got you by the balls. They spend billions of dollars every year lobbying, lobbying, to get what they want. Well, we know what they want. They want more for themselves and less for everybody else, but I'll tell you what they don’t want: They don’t want a population of citizens capable of critical thinking. They don’t want well informed, well educated people capable of critical thinking. They’re not interested in that. That doesn’t help them. Thats against their interests. Thats right. They don’t want people who are smart enough to sit around a kitchen table to figure out how badly they’re getting f*cked by a system that threw them overboard 30 f*cking years ago. They don’t want that. You know what they want? They want obedient workers. Obedient workers. People who are just smart enough to run the machines and do the paperwork, and just dumb enough to passively accept all these increasingly shittier jobs with the lower pay, the longer hours, the reduced benefits, the end of overtime and the vanishing pension that disappears the minute you go to collect it, and now they’re coming for your Social Security money. They want your retirement money. They want it back so they can give it to their criminal friends on Wall Street, and you know something? They’ll get it. They’ll get it all from you, sooner or later, 'cause they own this f*cking place. It's a big club, and you ain’t in it. You and I are not in the big club. And by the way, it's the same big club they use to beat you over the head with all day long when they tell you what to believe. All day long beating you over the head in their media telling you what to believe, what to think and what to buy. The table is tilted folks. The game is rigged, and nobody seems to notice, nobody seems to care. Good honest hard-working people -- white collar, blue collar, it doesn’t matter what color shirt you have on -- good honest hard-working people continue -- these are people of modest means -- continue to elect these rich c*cksuckers who don’t give a f*ck about them. They don’t give a f*ck about you. They don’t give a f*ck about you. They don't care about you at all -- at all -- at all. And nobody seems to notice, nobody seems to care. That's what the owners count on; the fact that Americans will probably remain willfully ignorant of the big red, white and blue dick that's being jammed up their assholes everyday. Because the owners of this country know the truth: it's called the American Dream, because you have to be asleep to believe it.
mkey je offline   Reply With Quote
Staro 19.06.2025., 19:58   #214
tomek@vz
Premium
 
tomek@vz's Avatar
 
Datum registracije: May 2006
Lokacija: München/Varaždin
Postovi: 4,601
Citiraj:
Autor Neo-ST Pregled postova
Glavno pitanje je mogu li oni uopće sa tim passwordima šta su ukrali išta. Ako su passwordi enkriptirani, onda su informacije nepotpune. Tehnički su ukrali passworde, ali ako ne mogu ništa s njima onda ne bi trebalo biti panike? Osim šta su hackeri opet pokazali najvećim firmama da nisu nedodirljivi.

Koliki je koeficijent da je opet Lazarus u pitanju...

Pitaj se kakvi informatičari rade u tim firmama i što je moderan programer pa će ti sve biti jasnije
Citiraj:
Autor Night Pregled postova
Google Authenticator je samo implementacija otvorenog TOTP protokola, mislim da je na Androidima bolje koristiti Aegis koji je open source i podržava import i export seedova.

Još bolje je ne koristiti TOTP aplikacije preko moba nego preko hadverskog standalone uređaja poput ovoga : https://www.token2.swiss/shop/produc...hardware-token

Seedove naravno kod kreiranja TOTPa pospremiti negdje na sigurno, po mogućnosti na enkriptirani vanjski medij i ne držati ih na računalu. Po mogućnosti koristiti Linux kod kreiranje i spremanja seedova, jer su Windowsi postali spyware.
Potpis ko kuća na ovo
tomek@vz je offline   Reply With Quote
Staro 19.06.2025., 20:05   #215
xlr
49%winner
Moj komp
 
xlr's Avatar
 
Datum registracije: Sep 2007
Lokacija: PU
Postovi: 9,967
Ako nista drugo, barem neka se koristi Aegis te backup seedova cuva na sigurnom i mracnom mjestu. Vec to je veliki korak.
__________________
Keep calm and fastboot oem unlock.
xlr je offline   Reply With Quote
Staro 19.06.2025., 22:26   #216
medo
#erase startup-config
Moj komp
 
medo's Avatar
 
Datum registracije: Nov 2001
Lokacija: Zagreb
Postovi: 3,610
Privatnost i sigurnost podataka i korisnika

Citiraj:
Autor spawn Pregled postova
2FA od google-a ili mircosoft-a?

Siguran je koliko je siguran app. Ako netko ili nešto uspije izvući secret iz aplikacije ili iz cloud backupa, game over.

Osobno koristim Yubikey za TOTP umjesto takvih autenticatora. Tamo su TOTP parametri za 2FA/MFA upečeni u ključeve pa se ne može do toga.
__________________
"It's not a bug, it's a feature!"
1N6pJsvusP7afu23qs1uBscK16wfcG7C8m
medo je offline   Reply With Quote
Staro 20.06.2025., 05:35   #217
kopija
DIY DILETANT
 
kopija's Avatar
 
Datum registracije: Jan 2009
Lokacija: Čistilište
Postovi: 3,439
kopija je offline   Reply With Quote
Staro 20.06.2025., 09:54   #218
strikoo
Premium
 
strikoo's Avatar
 
Datum registracije: Nov 2004
Lokacija: HR
Postovi: 939
Citiraj:
Autor medo Pregled postova
Siguran je koliko je siguran app. Ako netko ili nešto uspije izvući secret iz aplikacije ili iz cloud backupa, game over.

Osobno koristim Yubikey za TOTP umjesto takvih autenticatora. Tamo su TOTP parametri za 2FA/MFA upečeni u ključeve pa se ne može do toga.
KeepassXC/KeepassDX imaju TOTP
strikoo je offline   Reply With Quote
Staro 20.06.2025., 13:15   #219
medo
#erase startup-config
Moj komp
 
medo's Avatar
 
Datum registracije: Nov 2001
Lokacija: Zagreb
Postovi: 3,610
Privatnost i sigurnost podataka i korisnika

Ima i obični KeePass samo se sad više ne sjećam da li sam morao staviti plugin ili je to radilo out of the box.

S KeePassom je potencijalni problem što čuvaš oba faktora na istom mjestu (password + TOTP)
__________________
"It's not a bug, it's a feature!"
1N6pJsvusP7afu23qs1uBscK16wfcG7C8m
medo je offline   Reply With Quote
Staro 20.06.2025., 14:30   #220
strikoo
Premium
 
strikoo's Avatar
 
Datum registracije: Nov 2004
Lokacija: HR
Postovi: 939
Citiraj:
Autor medo Pregled postova
Ima i obični KeePass samo se sad više ne sjećam da li sam morao staviti plugin ili je to radilo out of the box.

S KeePassom je potencijalni problem što čuvaš oba faktora na istom mjestu (password + TOTP)
da, preporuka je koristiti zasebnu bazu za totp
strikoo je offline   Reply With Quote
Staro 20.06.2025., 19:51   #221
tomek@vz
Premium
 
tomek@vz's Avatar
 
Datum registracije: May 2006
Lokacija: München/Varaždin
Postovi: 4,601
Citiraj:
Keylogging malware is a particularly dangerous threat, as it is typically designed to capture login credentials or other sensitive data from users. When you add a compromised Exchange server to the mix, it creates an even nastier situation for any organization.
Researchers from Positive Technologies recently unveiled a new study on a keylogger-based campaign targeting organizations worldwide. The campaign, which resembles a similar attack discovered in 2024, focuses on compromised Microsoft Exchange Server installations belonging to 65 victims across 26 countries.

> Techspot
tomek@vz je offline   Reply With Quote
Staro 21.06.2025., 09:16   #222
quazar912
Premium
 
quazar912's Avatar
 
Datum registracije: Nov 2008
Lokacija: north-northwest
Postovi: 1,954
Citiraj:
Autor spawn Pregled postova
Ne znam jednog korisnika koje ide na facebook preko web browsera.
.
ja na većinu webova idem preko pcja i web browsera.peeglednije, brže i sigurnije

andoid mi je nužno zlo.

radije bi imao neki W OS mob nego android.
čudim se da nisu počeli gurat android za PC OSove...
__________________
...and fly...

Thule nosač

Zadnje izmijenjeno od: quazar912. 22.06.2025. u 08:39.
quazar912 je offline   Reply With Quote
Staro 23.06.2025., 09:15   #223
Night
Premium
 
Datum registracije: Oct 2008
Lokacija: Dbk
Postovi: 1,227
Whitepaper o tome kako Smart TV profilira korisnika (TL;DR : puca screenshotove par puta u sekundi i radi prepoznavanje sadržaja, to šalje u svoj cloud) : https://dl.acm.org/doi/pdf/10.1145/3646547.3689013

Pored whitepaper verzije ima i redhead verzija : https://www.youtube.com/watch?v=jeq2m-OM53A

Razlog više zašto Smart TV ne bi smio imati nikakav pristup mreži čak ni ako se koristi kao glupi monitor spojen na PC. Screenshotovi se kupe i sa HDMIja, a podaci onda idu preko mrežnog sučelja (ethernet, wifi) u cloud.
Night je offline   Reply With Quote
Staro 23.06.2025., 09:32   #224
Ivo_Strojnica
PRO
Moj komp
 
Ivo_Strojnica's Avatar
 
Datum registracije: Apr 2010
Lokacija: Zagreb
Postovi: 4,675
meni je blokiran sav promet sa TV-a prema van, može samo lokalno pristupati, tako da, nek im je sa srićom

Preporučujem, ako imate opciju na ruteru, da je iskoristite. pustite samo ono šta koristite (netflix, hbo, disney...) a ostalo blacklist sa tog uređaja.
__________________
"Who is your daddy and what does he do?"
Ivo_Strojnica je offline   Reply With Quote
Staro 02.07.2025., 10:59   #225
strikoo
Premium
 
strikoo's Avatar
 
Datum registracije: Nov 2004
Lokacija: HR
Postovi: 939
nez jesmo spominjali

https://www.joindns4.eu/for-public#resolver-options

Citiraj:
What is DNS4EU?
DNS4EU is an initiative by the European Commission that aims to offer an alternative to the public DNS resolvers currently dominating the market.
Supported by the European Commission, the European Union's DNS4EU secure-infrastructure project provides a protective, privacy-compliant, and resilient DNS service to strengthen the EU’s digital sovereignty and enhance digital security for European Union citizens, governments, and institutions.
https://www.joindns4.eu/about
strikoo je offline   Reply With Quote
Staro 02.07.2025., 15:04   #226
xlr
49%winner
Moj komp
 
xlr's Avatar
 
Datum registracije: Sep 2007
Lokacija: PU
Postovi: 9,967
Nisam cuo za ove gore.

Evo jos jednog iza kojeg stoje suosnivaci popularnog NextDNS-a, takodjer se hvale potpuno europejskim DNS rjesenjem:

https://www.dns0.eu/
__________________
Keep calm and fastboot oem unlock.
xlr je offline   Reply With Quote
Staro 02.07.2025., 15:31   #227
d0X
Kostolomac
Moj komp
 
d0X's Avatar
 
Datum registracije: Jun 2006
Lokacija: Rijeka
Postovi: 1,430
Osobno koristim Mullvadov DNS, nisam znao za ove.
__________________
PSN Steam
d0X je offline   Reply With Quote
Staro 02.07.2025., 16:10   #228
medo
#erase startup-config
Moj komp
 
medo's Avatar
 
Datum registracije: Nov 2001
Lokacija: Zagreb
Postovi: 3,610
I onda spojiš log od tog DNSa sa logovima spajanja od telekoma….

dnscrypt ftw
__________________
"It's not a bug, it's a feature!"
1N6pJsvusP7afu23qs1uBscK16wfcG7C8m
medo je offline   Reply With Quote
Staro 03.07.2025., 20:59   #229
kopija
DIY DILETANT
 
kopija's Avatar
 
Datum registracije: Jan 2009
Lokacija: Čistilište
Postovi: 3,439
Može se i pare zaradit na špijanju.
Šalu na stranu, najgore sumnje potvrđene.
kopija je offline   Reply With Quote
Staro 03.07.2025., 21:08   #230
spawn
Premium
Moj komp
 
spawn's Avatar
 
Datum registracije: Aug 2004
Lokacija: Istra
Postovi: 8,322
Privatnost i sigurnost podataka i korisnika

Kruha i igara. 300mil. Sica za farbanje ociju raje

Zadnje izmijenjeno od: spawn. 03.07.2025. u 21:13.
spawn je offline   Reply With Quote
Staro 03.07.2025., 21:42   #231
mkey
Premium
Moj komp
 
Datum registracije: Sep 2018
Lokacija: tu
Postovi: 3,250
Ma kakve oči, s time se ni tunele ne može 12 puta ofarbat.
__________________
Citiraj:
Autor George Carlin
But there’s a reason. There’s a reason. There’s a reason for this, there’s a reason education sucks, and it’s the same reason that it will never, ever, ever be fixed. It’s never gonna get any better. Don’t look for it. Be happy with what you got. Because the owners of this country don't want that. I'm talking about the real owners now, the real owners, the big wealthy business interests that control things and make all the important decisions. Forget the politicians. The politicians are put there to give you the idea that you have freedom of choice. You don't. You have no choice. You have owners. They own you. They own everything. They own all the important land. They own and control the corporations. They’ve long since bought and paid for the senate, the congress, the state houses, the city halls, they got the judges in their back pockets and they own all the big media companies so they control just about all of the news and information you get to hear. They got you by the balls. They spend billions of dollars every year lobbying, lobbying, to get what they want. Well, we know what they want. They want more for themselves and less for everybody else, but I'll tell you what they don’t want: They don’t want a population of citizens capable of critical thinking. They don’t want well informed, well educated people capable of critical thinking. They’re not interested in that. That doesn’t help them. Thats against their interests. Thats right. They don’t want people who are smart enough to sit around a kitchen table to figure out how badly they’re getting f*cked by a system that threw them overboard 30 f*cking years ago. They don’t want that. You know what they want? They want obedient workers. Obedient workers. People who are just smart enough to run the machines and do the paperwork, and just dumb enough to passively accept all these increasingly shittier jobs with the lower pay, the longer hours, the reduced benefits, the end of overtime and the vanishing pension that disappears the minute you go to collect it, and now they’re coming for your Social Security money. They want your retirement money. They want it back so they can give it to their criminal friends on Wall Street, and you know something? They’ll get it. They’ll get it all from you, sooner or later, 'cause they own this f*cking place. It's a big club, and you ain’t in it. You and I are not in the big club. And by the way, it's the same big club they use to beat you over the head with all day long when they tell you what to believe. All day long beating you over the head in their media telling you what to believe, what to think and what to buy. The table is tilted folks. The game is rigged, and nobody seems to notice, nobody seems to care. Good honest hard-working people -- white collar, blue collar, it doesn’t matter what color shirt you have on -- good honest hard-working people continue -- these are people of modest means -- continue to elect these rich c*cksuckers who don’t give a f*ck about them. They don’t give a f*ck about you. They don’t give a f*ck about you. They don't care about you at all -- at all -- at all. And nobody seems to notice, nobody seems to care. That's what the owners count on; the fact that Americans will probably remain willfully ignorant of the big red, white and blue dick that's being jammed up their assholes everyday. Because the owners of this country know the truth: it's called the American Dream, because you have to be asleep to believe it.
mkey je offline   Reply With Quote
Odgovori



Pravila postanja
Vi ne možete otvarati nove teme
Vi ne možete pisati odgovore
Vi ne možete uploadati priloge
Vi ne možete uređivati svoje poruke

BB code je Uključeno
Smajlići su Uključeno
[IMG] kod je Uključeno
HTML je Uključeno

Idi na