this post was submitted on 02 Feb 2024
56 points (100.0% liked)

Cybersecurity

6894 readers
137 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 2 years ago
MODERATORS
top 10 comments
sorted by: hot top controversial new old
[–] flathead@lemm.ee 22 points 1 year ago (1 children)

"We can confirm that the situation is under control and it is safe to use AnyDesk."

Yeah, nah.

[–] adamkempenich@lemmy.world 3 points 1 year ago (2 children)

Any other recommendations aside from TeamViewer? AnyDesk has been getting worse with each update. Can’t even use a free account to have a dedicated hostname anymore…

[–] jasep@lemmy.world 12 points 1 year ago* (last edited 1 year ago) (2 children)
[–] 0x4E4F@lemmy.dbzer0.com 5 points 1 year ago* (last edited 1 year ago)

The owners are sketchy and they have closed source pro features (which was expected to be honest). They also don't like criticism and ban accounts on reddit for questioning some of their practices (like why has a vulnerability PR not been merged for more than a year). I should know, they banned me from their subreddit for asking this and deleted my comment. I later found out that this was common practice with them.

[–] ryannathans@aussie.zone 2 points 1 year ago

Isn't that run by some dodgy chinese firm

[–] kn33@lemmy.world 3 points 1 year ago

I really like ScreenConnect.

[–] spaghettiwestern 12 points 1 year ago* (last edited 1 year ago) (1 children)

At least Anydesk didn't take Teamviewer's approach and deny the breach for 3 years while blaming their customers for the problem, but it's time to rethink using these remote access apps.

In the past year for personal use I've moved to VNC and Nomachine server apps that are inaccessible from the Internet without first activating a Wireguard tunnel. The tunnel ports don't even appear to be open when scanned. Hopefully this setup offers more security than relying on a company to make sure their systems are up to date.

[–] 0x4E4F@lemmy.dbzer0.com 1 points 1 year ago (1 children)

Doesn't mean their systems are not up to date, it just means that a security hole has been discovered. Hopefully, it's patched now.

My biggest concern is them having the source.

[–] spaghettiwestern 1 points 1 year ago

Doesn’t mean their systems are not up to date...

IMO we will never know. Every company has a vested interest in hiding the cause of a breach if it makes them look bad.

[–] Illecors@lemmy.cafe 1 points 1 year ago