this post was submitted on 03 Sep 2026
848 points (99.1% liked)

Technology

87949 readers
3026 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
top 50 comments
sorted by: hot top controversial new old
[–] sunbytes@lemmy.world 42 points 6 days ago (2 children)

The only way to fix this is to have us upload our IDs online constantly, perhaps to prove we are adults.

It is the only way we can we safe.

[–] MadBits@europe.pub 10 points 6 days ago

But, just think about the children! ~While everyone plastered their children allover social media and they are easily identified with AI~

Woaha. Why didn't anyone think of this before you?

[–] 0x0@lemmy.zip 25 points 6 days ago (3 children)

I bought a domain, configured the webserver in the next 5m.

As soon as it started taking requests (on a domain that i haven't even announced yet) it got flooded by bots.

[–] Brimstone@lemmy.ml 18 points 6 days ago* (last edited 6 days ago) (1 children)

Yeah I worked for company with publicly exposed server, the logs were amazing.

Just bots scanning default ports trying default username and password for services like Microsoft SQL server.

It’s such a waste of energy really

[–] edgesmash@lemmy.world 6 points 6 days ago

That's been happening since forever, though. I helped manage proxy servers for my first job in the mid 00's, and those server logs were mostly automated port scans and failed login attempts, even on the newly commissioned servers.

[–] ddplf@szmer.info 9 points 6 days ago (1 children)

If your browser is based on chromium, you're employing an army of bots yourself that gets enabled each time you enter any domain.

[–] horsesaysweird@feddit.org 11 points 6 days ago

Can you explain what you mean exactly?

[–] dreadbeef@lemmy.dbzer0.com 4 points 6 days ago* (last edited 6 days ago)

Registering SSL is a centralized process with root CAs logging new ones as they come in. Cert transparency logs are a thing, and Google is very involved: https://certificate.transparency.dev/

Once a bad actor hooks up to that, they just get a realtime stream of places to start port scanning and running WHOIS queries for people who didn't get WHOIS protection. If you used letsencrypt your domains you registered certs for got sent there and anyone who wanted to know about it knew about it before you could tell anyone.

You can use something like crt.sh to look up domains

[–] Horsey@lemmy.world 10 points 6 days ago* (last edited 6 days ago) (2 children)

Wait until non Americans hear that our national social security ID number is only 4/9 digits worth of “random” numbers. (Fun fact, the entire number was procedurally generated based on where you were born and in what order at the hospital for generations until they changed it recently)

[–] hildegarde@lemmy.blahaj.zone 3 points 6 days ago

The numbers aren't random. They are sequential. The early digits are assigned geographically, but the rest are in sequence. If you know a valid social security number, adding or subtracting 1 will be another valid social security number, most likely someone born in the same hospital on the same day.

They did change it somewhat recently, but they don't re-assign the numbers when making that change, so most of the numbers are completely insecure.

[–] Blackmist@feddit.uk 1 points 6 days ago (1 children)

Yeah, we know. We just can't believe that you actually use it for anything important.

[–] Horsey@lemmy.world 2 points 6 days ago

That stupid ass number is used as one of the identifying factors when financing anything. Yes, a house is bought and mortgaged with that number next to 2 other forms of ID lmao.

[–] nanometer1625@thelemmy.club 10 points 6 days ago* (last edited 6 days ago) (1 children)

This is yet another reason why virtual ID cards are superior: In the event that the card data is compromised, the old virtual ID can be revoked and a new virtual ID can be issued. Virtual ID cards can also have a much shorter duration, because the cost of rotating it is minimal. For example, California's virtual driver licenses rotate each 30 days.

[–] Funkt4st1c@lemmy.world 1 points 6 days ago

We honestly should be using virtual vouchers for everything. The question then becomes "whats one level up from the voucher i can steal" and we're very frustratingly (for my mental exercise) back at square 1

I have had to rent cars since 2015. My license has probably been seen by 5000 breach sites by now.

[–] Bluedragon012@lemmy.world 4 points 6 days ago* (last edited 6 days ago) (1 children)

At this rate, a new ID type will have to be used. I dont have a clue what, but a new one..

[–] Blackmist@feddit.uk 4 points 6 days ago

Welcome to Rent-a-car. Please sign into your vehicle with Facebook, Google or AppleID.

[–] Magnum@infosec.pub 2 points 6 days ago (1 children)

Where can I find this nexus?

[–] FiskFisk33@startrek.website 6 points 6 days ago

Fortunately, Nexus went dark within hours of the KrebsOnSecurity scoop,

load more comments
view more: next ›