2023 Security Check-up Reminder

For actual advice, I would make sure to sign up with an email provider that allows for multiple aliases. Having multiple addresses that you can use to separate formal emails regarding things like bills and work from informal stuff like media accounts allows you some degree of separation while having the conveniences of a single provider. It's also useful to have an email that you can use for any kind of throwaway like store reward programs.
 
Some honest advice, learn the basics of OSINT and dox yourself. It’s fucking easy to do and you should be leveraging free online tools to get yourself unlisted from sites like Radaris, etc. that do nothing but aggregate data to annoy.
I do this on the regular, the actual cat who is "actually a cat" is basically a ghost as far as the internet is concerned. Feels good man.
 
that's the one that plugs everyone into the Microsoft niggerword scanner correcr
Correct. Bedrock edition is the “console/Microsoft store” version. It has no support for mods, has its own premium currency you have to pay money for to play custom maps, host servers, get new skins and texture packs, etc. it also requires an Xbox account for online play, lacks several key game mechanics from the Java version (it does have some cool unique ones though), has a fucking horrendous UI, and is filled with Microsoft telemetry, so… yeah, avoid it.
A good quality paid antivirus program and a reputable ad blocker also go a long way to keeping safe online.
Antivirus is nice but usually not necessary if you aren’t fucking around on any weird sites. An adblocker, though, is absolutely essential on the modern web. I use Ublock Origin. It comes pre-installed with Librewolf, an open-source privacy-centric Firefox fork which also doesn’t save cookies or your browsing history unless you allow it to. It’s my web browser of choice and I’d highly recommend it to everyone reading. Just keep in mind the privacy settings go so hard that they tend to break some sites… Shit like the normie social medias and Farms will work just fine though. Anything that doesn’t work because you turned on some privacy settings probably isn’t worth using anyways.
Who the fuck uses a password manager?
Never forget, you can't hack a pen and paper.

You can lose it in a drawer somewhere, but you'll find it as soon as you stop looking for it.
Good password managers are nifty as hell. KeePassXC is the one Null recommended IIRC, it’s free, open-source and entirely local. It doesn’t connect to any external servers or go online in any way, and has plenty of features to encrypt your password databases if your machine is compromised. I’d recommend it above all of the alternatives. As far as I’m aware, there’s no possibility of the program itself ever being “hacked” like LastPass was.
Byuu did nothing wrong. Why the fuck would you download anything anyone here sends you personally, especially considering the context of the Chudbuds hack? Absolutely deserved. I’d sooner download a piece of 20 year old shovelware from a sketchy-ass Russian WordPress site* than install literally any files from the fucking Kiwi Farms.

*I speak from experience. you go to some weird places looking for obscure old PC games
 
How could you be so retarded downloading random mods from the Internet? I mean, I seen people accidentally pressing phishing links, and I can see how people fall for it, but I assume adults are smart enough to not download random stuff from the Internet.

I trust humanity too much.

P.S. always separate your work from your personal computer!!!
You'd be surprised how trusting people can be. If you're not expecting to be a victim a lot of times nobody will question it. People want to trust and assume the best until it blows up in their face. It only takes one time where you aren't paying attention, or not thinking about it to become a target. I don't think the site admin is retarded. I think what likely happened was she was caught off guard, probably juggling a couple different things at the time, and didn't even consider that people would want to target her. Mediafire also isn't the most unusal place to share files. I think it's real easy to look back on hindsight and realize that mistakes were made, but it can happen to anyone.
 
You'd be surprised how trusting people can be. If you're not expecting to be a victim a lot of times nobody will question it. People want to trust and assume the best until it blows up in their face.
Those people are dumb.
I don't think the site admin is retarded.
Yes they are.
Mediafire also isn't the most unusal place to share files. I think it's real easy to look back on hindsight and realize that mistakes were made, but it can happen to anyone.
Only to retards who trust random mediafire links.

It's fucking retarded as hell to download and install random files from who knows where on your server. Anyone can upload anything to mediafire if you don't know where those files came from or what they are, don't fucking download them.
 
  • Like
Reactions: Neo-Nazi Rich Evans
A VPN only raises the bar to prove your identity. If being linked to your posts on kiwifarms is going to be so personally devastating, you're effectively a political dissident.

Even if you're completely squeaky clean, getting linked to your posts here opens you up to doxing, swatting and other bullshit, which is at best an inconvenience and could conceivably even get you arrested or killed if some retard hates you badly enough.
 
A VPN only raises the bar to prove your identity. If being linked to your posts on kiwifarms is going to be so personally devastating, you're effectively a political dissident.

Even then, you can identify a user easily using meta data - if someone is jumping between multiple nations then you know it's just the same person on a VPN. What they do protect you from is limited, and frankly there's no excuse for websites to use HTTP these days.
You'd be surprised how trusting people can be. If you're not expecting to be a victim a lot of times nobody will question it. People want to trust and assume the best until it blows up in their face. It only takes one time where you aren't paying attention, or not thinking about it to become a target. I don't think the site admin is retarded. I think what likely happened was she was caught off guard, probably juggling a couple different things at the time, and didn't even consider that people would want to target her. Mediafire also isn't the most unusal place to share files. I think it's real easy to look back on hindsight and realize that mistakes were made, but it can happen to anyone.
This is actually more of a sophisticated attack, in that it wasn't just some fire and forget phishing attempt - they actually used a bit of social engineering to get them to download the file. It's more investment, but more reward too.

While it's very true everyone will fuck up at some point, humans make mistakes, there are plenty of precautions that should have been put in place ahead of time so that if this did happen people wouldn't have their personal information leaked.

First off, why the fuck did she not have a work laptop, or if she's a cheap cunt some sort of virtual machine to separate things. That way she could have all her own details leaked and not the people who signed up to her site.

Second, the password security is so bad it should be criminal. She should have had the database set up so that a hacker couldn't access it.

When you handle this much data, you really should be liable for looking after it. Yet the US data protection laws are dogshit when it comes to this - they should require better.
Antivirus is nice but usually not necessary if you aren’t fucking around on any weird sites.
People as a general rule make mistakes, having something that can stop those mistakes from having consequences is almost always a great idea. Even if most people get very little benefit from it, it only takes someone clicking the wrong link on something like Twitter without one to ruin their day.
 
Just for fun, I tried to see if "mypasswordistotalshit!!" was a secure passphrase (it's not mine, I just came up with it off the top of my head) to see how long it would take a computer to crack. And this is why passphrases are better.

Screen Shot 2023-03-09 at 9.22.03 AM.png


Throw in a couple of dashes between the words (i.e. "my-password-is-total-shit!!") and it becomes:

Screen Shot 2023-03-09 at 9.24.16 AM.png

My password would have (probably) outliven me by a factor of 9x10^16. You know, I like those odds. And it's one you can easily remember without having your browser remember it. I never use the auto-login feature.
 
This is my worst fuckin fear lol
What type of files can this stuff be hidden in? How paranoid do I need to be?
Any executable or plugin or mod of any kind. If it loads and runs code, it's a potential attack vector. This includes browser extensions, which on Chrome auto-update (don't use Chrome). There've been numerous cases of extension publishers getting hacked or selling out to malware groups.

 
Fuck me, just use a physical notepad or a black book for your passwords. Keep that shit in a locked drawer. Bonus points if you have doctor's hand writing.
You don't have to go Light Yagami and build a bedside that can self-destruct if opened incorrectly by a pleb or a younger sibling.
 
Back