2023 Security Check-up Reminder

Even then, you can identify a user easily using meta data - if someone is jumping between multiple nations then you know it's just the same person on a VPN. What they do protect you from is limited, and frankly there's no excuse for websites to use HTTP these days.

This is actually more of a sophisticated attack, in that it wasn't just some fire and forget phishing attempt - they actually used a bit of social engineering to get them to download the file. It's more investment, but more reward too.

While it's very true everyone will fuck up at some point, humans make mistakes, there are plenty of precautions that should have been put in place ahead of time so that if this did happen people wouldn't have their personal information leaked.

First off, why the fuck did she not have a work laptop, or if she's a cheap cunt some sort of virtual machine to separate things. That way she could have all her own details leaked and not the people who signed up to her site.

Second, the password security is so bad it should be criminal. She should have had the database set up so that a hacker couldn't access it.

When you handle this much data, you really should be liable for looking after it. Yet the US data protection laws are dogshit when it comes to this - they should require better.

People as a general rule make mistakes, having something that can stop those mistakes from having consequences is almost always a great idea. Even if most people get very little benefit from it, it only takes someone clicking the wrong link on something like Twitter without one to ruin their day.
I'm not saying she's totally innocent, just that chudbuds was a small time operation for a niche online community. She's not a security professional and I don't think anyone should've expected that. You're right, these precautions should've been taken, but I also don't see anyone else jumping in to start up their own node and do it the "right" way.
 
Any executable or plugin or mod of any kind. If it loads and runs code, it's a potential attack vector. This includes browser extensions, which on Chrome auto-update (don't use Chrome). There've been numerous cases of extension publishers getting hacked or selling out to malware groups.
Any type of file can be an attack vector if the code that processes it has a vulnerability in it.
 
How hard is it to make a new email account ffs?

Also offline password banks are far superior to the online ones. Literally just get something like keypass and put it on a USB Stick. Plug in the USB whenever you need to login to something and then take it out. I use it in combination with veracrypt, but that's just because I'm a paranoid bastard.
 
Fuck me, just use a physical notepad or a black book for your passwords. Keep that shit in a locked drawer. Bonus points if you have doctor's hand writing.
You don't have to go Light Yagami and build a bedside that can self-destruct if opened incorrectly by a pleb or a younger sibling.
Since it's best to have a unique password for everything, a notepad is not a very good option. I think it's decent for tech illiterates but if you're on kiwifarms something like KeepassXC at least for the stuff you really shouldn't even remember.
I don't know my Farms password at all and don't store any in my browser because that's retarded.
the people who know how to do it 'the right way' are aware how much preparation and effort goes into doing everything properly, which discourages them from taking on a project like that
Not true, "the right way" is simply mundane and boring. It's not like someone broke into chudbuds or walked through the front door, she took something a stranger gave her and did presumably zero due diligence and got pwned. I guarantee if she ran it through Virustotal, which is free and easy, she'd have decided not to run it.

Update: Virustotal didn't flag it. I was wrong.
 
Last edited:
Those people are dumb.

Yes they are.

Only to retards who trust random mediafire links.

It's fucking retarded as hell to download and install random files from who knows where on your server. Anyone can upload anything to mediafire if you don't know where those files came from or what they are, don't fucking download them.
Where the fuck Jim finds these retards who just download random shit off mediafire without using shit like VMware to isolate potential harm?

Virtual machines provide additional layer of security, assuming that you disabled guest addition and prevent VMs affecting the system hardware, also use different operating systems, IE Linux - Windows or OS X - Windows.
Even better with different physical devices.

Minecraft runs off a fucking potato at this point just to give kiddy winks possibility of mingling with their favorite pedo on public servers on their off the shelf 300 USD craptop.

Side note Josh forgot to mention following
DO NOT STORE ANYTHING SENSITIVE ON CLOUD STORAGE SERVICES.
For example if you link multiple devices to single account let's say Dropbox and store your password there in plain text, a thief who steals your phone has access to your offline data and locally stored files.
Store most sensitive data on thumb drives or other removable storage like SD cards for example.

Lastly
DO NOT USE PUBLIC WIFI, EVER
Your traffic is unencrypted and your device session can be spied on same manner how could glowniggers and others could spy on you using your phone number
 
The immediate red flag was the domain name…

chudbuds.lol (most cringe URL I’ve seen in a while, even jimjokefunny.lol would have been better ffs)

If you decide to register your details on a website with a name like chudbuds.lol or one with a shitty/meme TLD, always make it throwaway as the domain name/service is likely to be offline within a year or not properly patched/secured/maintained.
 
you can't hack my accounts if I keep forgetting all my passwords DUMB BISH
Unironically that's been my password security plan for years until last year when I bought the paper notepad, I've reset everything once at least, even if a service has been hacked... who fucking cares lol, you got a dud because of childhood retardation and shit memory
 
  • Feels
Reactions: supremeautismo
Where the fuck Jim finds these retards who just download random shit off mediafire without using shit like VMware to isolate potential harm?

Virtual machines provide additional layer of security, assuming that you disabled guest addition and prevent VMs affecting the system hardware, also use different operating systems, IE Linux - Windows or OS X - Windows.
Even better with different physical devices.

Minecraft runs off a fucking potato at this point just to give kiddy winks possibility of mingling with their favorite pedo on public servers on their off the shelf 300 USD craptop.

Side note Josh forgot to mention following
DO NOT STORE ANYTHING SENSITIVE ON CLOUD STORAGE SERVICES.
For example if you link multiple devices to single account let's say Dropbox and store your password there in plain text, a thief who steals your phone has access to your offline data and locally stored files.
Store most sensitive data on thumb drives or other removable storage like SD cards for example.

Lastly
DO NOT USE PUBLIC WIFI, EVER
Your traffic is unencrypted and your device session can be spied on same manner how could glowniggers and others could spy on you using your phone number
Josh linked resources that cover much of what he didn't, he can't brief people on how not to be retarded.

Public Wifi isn't ideal but the traffic is almost always encrypted. Without getting autistic I will leave it at "Only use Public Wifi if you use a VPN." You can not reasonably expect normal people to just not use public wifi at all.
 
The good ones keep everything encrypted at all times and require your master password, but that could still leak.
If they download your password vault and hit you with a keylogger that grabs your master password, it's over. Doing this is trivial once full remote access is achieved, i.e. the second you run a bad plugin or executable. Instead of or in addition to a master password, I recommend securing your password vault with a Yubikey. Most big-name password managers support this.

 
- chudbud gets hacked bc minecraft mod
- fresh meat wants to start a kiwifarms minecraft server
- oldfag links the minecraft hack mod
- fresh meat uses the minecraft hack mod
- everyone laughs
- byuu dies for real this time
- Null has to do a safety rundown again bc we are retards
- random obscure lolcow appears and gloats on twitter
- random obscure lolcow's thread gets linked in how-to-be-not-a-retard-thread
- I learn about a new lolcow I would probably have never learned about


I like this place so much.
circle of life
 
Gmail usually requires "recovery" bullshit like emails/phone numbers. It ends up being a gay daisy chain of burners and alts. If Yahoo wasn't so broken it'd be the main email I'd use. Protonmail isn't even accepted by several websites.

It's all so very tiring…
Fastmail has strong security, doesn't mandate account recovery bullshit, and is accepted everywhere. Also lets you create aliases to mask your primary email address. But whenever Protonmail's an option and privacy's a major concern, such as on KF, stick with that.
 
I only use it when I need to spoof my location for purchases (ex. Netflix in Hungary is $5.00) but I don’t even use Netflix anymore. Now I only use it to access KiwiFarms when the site it getting messed with, or if I want to torrent something from a public site, like a Switch game update. It bypasses the Pi-Hole adblock so I only use when absolutely necessary. What happened with Nord to cause it to lose your trust?
It was seeing advertisements for it literally everywhere that rubbed me the wrong way. Internet ads, YouTube creator ads, TV ad spots... it felt wrong to me. Then they had a minor breach a few years back that they weren't really forthright about, conveniently just as my subscription was ending.
 
I'm not saying she's totally innocent, just that chudbuds was a small time operation for a niche online community. She's not a security professional and I don't think anyone should've expected that. You're right, these precautions should've been taken, but I also don't see anyone else jumping in to start up their own node and do it the "right" way.
She doesn't need to be a security expert she just needed to speak to one, and once they have the site in a workable form have them audit it, and have them try and find issues with it to fix.

It would honestly be as simple as someone with a checklist working through what is the bare minimum expected in terms of protecting data in the event of a hack, or a data leak.

Normal, right minded people wouldn't want to set one of these things up in this "sektur" because not only does it open you up to massive amounts of shit flinging, you become a target for people to fuck with, spend hours of your time developing and maintaining the site and for little to no remuneration. Only attention seeking weirdos like chudbsre would want that smoke.
 
Back