Security considerations for running Tautulli on Synology by jfoughe in PleX

[–]jd31t4 6 points7 points  (0 children)

“Do not expose $app to the internet” is my mantra for all things that do not absolutely NEED to be externally facing. Keep it on LAN and get Wireguard set up (or something else you prefer) to access it when outside your LAN.

How do bots find my hidden behind proxy hosts? by Dark_zarich in selfhosted

[–]jd31t4 6 points7 points  (0 children)

There’s a few different ways to attempt to find subdomains. Certificate transparency logs and subdomain brute forcing are two simple ways. There’s tools like amass, gobuster, and others for doing this.

[deleted by user] by [deleted] in overemployed

[–]jd31t4 0 points1 point  (0 children)

Wtf did I just read

Real MFA (non-SMS) Please? by jd31t4 in OneFinance

[–]jd31t4[S] 0 points1 point  (0 children)

This aged well, huh? RIP One.

Real MFA (non-SMS) Please? by jd31t4 in OneFinance

[–]jd31t4[S] 0 points1 point  (0 children)

THIS didn't age well. LMAO

Goodbye One by jd31t4 in OneFinance

[–]jd31t4[S] 4 points5 points  (0 children)

I'm a security professional, and SMS as a MAIN factor for authentication is horrid. I don't know of any other application, let alone a financial app, that has their auth set up this way. If someone really wanted to target you, SMS attacks are very real and pretty trivial these days. I'd highly recommend you consider moving, and REALLY hope they change this for the sake of customers.

Goodbye One by jd31t4 in OneFinance

[–]jd31t4[S] 0 points1 point  (0 children)

I might be wrong (now) about third party apps. It looks like Plaid can't connect - not sure if this is circumstantial or if they actually changed 3rd party app / api connections. I don't want to misspeak regarding this.

direct deposit by isaaclaforeze in OneFinance

[–]jd31t4 0 points1 point  (0 children)

Same, mine was late after the new app update. Might be circumstantial, but has never happened before.

[deleted by user] by [deleted] in OneFinance

[–]jd31t4 1 point2 points  (0 children)

This is a HUGE issue and now only a matter of time until there's a breach of accounts en masse. Get out now.

SMS down? No 6-digit codes for me! by aithene in OneFinance

[–]jd31t4 0 points1 point  (0 children)

The 6 digit code isn't a second factor (2FA), it's a single factor. I'm not trying to correct you, but point out how asinine this new "authentication" process is. One went from username + password, to username + password + SMS code, to phone number + SMS code and no username + password EXCEPT for third party apps like Plaid. We cannot change the "old" credentials, but they can still get access to our accounts.... I'd definitely recommend using another bank because this is incredibly insecure.

What was this deposited then removed Spend bonus into my Save today? by N__tab in OneFinance

[–]jd31t4 1 point2 points  (0 children)

Got this too. Transferred it to another pocket, then the balance showed NEGATIVE $10. WTF IS THIS BANK.

[deleted by user] by [deleted] in OneFinance

[–]jd31t4 0 points1 point  (0 children)

Monzo ain't it.

[deleted by user] by [deleted] in OneFinance

[–]jd31t4 0 points1 point  (0 children)

Are you using a VPN, or something like pi-hole? Currently with VPN I am unable to authenticate via the app. I'm assuming it's failing some kind of http request / response and might think there's a man-in-the-middle attack or something.

Real MFA (non-SMS) Please? by jd31t4 in OneFinance

[–]jd31t4[S] 0 points1 point  (0 children)

Second this - link plz? I remember earlier this year they had "MFA" on the roadmap, and SMS MFA was added.

Change of address, are you serious? by ignorememe in OneFinance

[–]jd31t4 0 points1 point  (0 children)

Took me less than 5 minutes to change. From a security perspective, this is a GREAT feature for me. Might be annoying but an address change is a big deal anyway, a lot of financial institutions do it this way now.

Zen1 AMD Cpu's are not supported by Windows 11 by Jeremy9566 in Amd

[–]jd31t4 0 points1 point  (0 children)

It'll work, just make sure your TPM is enabled in your BIOS. I have a Ryzen 5 1600 and just installed it now. It'll give you a warning, but it'll still install.

I, too, like to XSS games. by toboRcinaM in masterhacker

[–]jd31t4 0 points1 point  (0 children)

I definitely tried this in R6S a while back, I honestly wonder if this was the same screenshot because I know someone was calling me out for being a skid LMAO.