Hard Pass

8 readers
1 users here now
Rules
  1. Don't be an asshole
  2. Don't make us write more rules.

View hardpass in other ways:

Hardpass.lol is an invite-only Lemmy Instance.
founded 1 year ago
ADMINS

hard pass chief

1
2
 
 
3
 
 
4
 
 
5
 
 
6
 
 
7
 
 
8
 
 

cross-posted from: https://lemmy.world/post/51634640

A new Gamers Nexus investigation found a retail LG TV actively scanning the local network for phones, laptops, smartwatches and other connected devices, while also capturing microphone audio when the screen appeared to be in standby. The investigation found voice data being stored locally even after the TV was disconnected from the network, with the queued data uploaded once connectivity returned. Researchers also uncovered webOS vulnerabilities that could potentially turn the television into a remotely controlled surveillance device. The really unsettling part isn't just the advertising angle. It's the fact that a consumer television can sit inside your trusted network, enumerate other devices, access a microphone, store collected data locally and communicate with external infrastructure. Put that same device in a corporate office, hospital, hotel or conference room and the security implications become considerably more serious. I went through the investigation in detail, including the network scanning, microphone behavior, ACR, webOS attack surface, offline data collection and practical mitigations

9
10
 
 

“We created the first-in-the-nation Office of Worker Power to put the full weight of City Hall behind the people who keep New York running,” said [NYC Mayor] Mamdani. “The nurse working a double shift. The teacher working a second job. The warehouse workers organizing for a union. Every New Yorker working hard to build a life and support a family. On Labor Day, we honor the workers who came before us by fighting for the workers who come next.”

Julie Su, the former acting US Labor Secretary who now serves as New York City’s deputy mayor for economic justice, will oversee the new office, which will be led by longtime union organizer Tony Perlstein.

11
12
38
Canadian rule (sh.itjust.works)
submitted 1 hour ago* (last edited 1 hour ago) by QuinnyCoded@sh.itjust.works to c/onehundredninetysix@lemmy.blahaj.zone
 
 

lmao

13
 
 
14
 
 
15
16
 
 
17
18
 
 

Welp. My Forgejo instance got popped with an RCE two days ago by CVE-2026-60004. Luckily, I noticed the following morning and had the day free to figure out what happened. Let's dive in!

As a homelab enthusiast, I found this a very interesting post. Here are my take aways from the post that I'm implementing myself:

  • Miner detection. I've updated monitoring rules to now watch the CPU on my hosts. If the same thing happened to me I would not have been alerted at all as I'm doing simple up / down monitoring. Fixed.
  • Access logging. I turned on access logging for my homelab Caddy instances.
  • Log retention. I have increased the amount and retention of my logging. The hope is this will help me reconstruct what happened after a breach.
  • Logs offsite. The VPS access logs now ride along with the normal backup process, which runs hourly. The homelab side still only gets caught by the weekly VM backup, so that's next.
  • Closed an open signup. My webtrees instance (genealogy) had self registration enabled, which is the same door this guy got hit through. Oops. Fixed.
  • Built a tool. log-inventory.sh, so "could I actually reconstruct what happened" is a command I run instead of a thing I assume.
19
 
 
20
 
 
21
 
 

"New Mexico officials are talking to FedEx and UPS about using their companies to deliver mail ballots instead of the Postal Service, said Secretary of State Maggie Toulouse Oliver (D)," reported The Washington Post's Patrick Marley and Justin Jouvenal on Sunday. "The cost would be manageable because the state sends out a relatively small number of mail-in ballots, she said. 'We are still planning for plan B in a worst-case scenario,' she said. 'There are other ways to deliver ballots.'"

22
 
 

Hello!

Regarding what Gamers Nexus recently disclosed regarding LG TVs in their latest video I think its finally time to do what I can to mitigate it.

I cant root it since the firmware is too new and I cant afford a new TV either. My best bet would be blocking all LG IPs network-wide and disconnecting it from the network. (Although I understand even that might not be enough, its the best I can do right now)

I was thinking of using an old Raspberry to atleast access youtube and my media server, however I dont know what would be a good OS/distro to run this on. Preferably I would want to use something like an old PS4 controller as the remote.

Anyone here who has any suggestions or living room setups to suggest? Any and all tips are welcome.

23
24
 
 
25
 
 
view more: next ›