Does your cybersecurity awareness training contain any hacklore?
Iโm collecting examples of hacklore in the wild. Whether itโs training slides, quiz questions, or instructions that focus on rare threats instead of the ones causing the most real-world harm, I want to see it all.
Post some screenshots or notes here, or email them to "info" at hacklore.org. Letโs help organizations replace stale guidance with advice that truly keeps people safe.
@boblord The Federal Communications Commission recently issued guidelines in Public Notice DA 25-996 for the security of broadcasters' STL (studio-to-transmitter) links that included the following:
"Change their devicesโ default passwords and replace them with robust alternatives, and regularly change passwords to promote continued security. "
I think the objectionable part is the last part of the preceding sentence. (Most of the rest of the public notice seems OK, actually...but the password lore is especially hard to root out.)
I guess they don't know about NIST.
This came in response to attacks enabled through not changing default passwords. Of course, advice to change default passwords is valid, but regular password changes....
The official notice: https://www.fcc.gov/document/fcc-urges-broadcasters-follow-cybersecurity-best-practices
Description with additional context:
https://radioinsight.com/headlines/322882/fcc-report-11-30-fcc-advises-stations-to-ensure-stl-eas-security/
@boblord I am so sick of the old tropes... Juicejacking, dangerous public Wi-Fi, etc. Will you be posting any submissions/findings?
@buherator I made the edits to the references to "URLs". Thank you for that insight that got past all the proofreaders!!!!!
As for the other part about being able to determine the risk level for a site, well, that might be more of a challenge than copy editing. ;-) But fully agree.
@buherator I posted some thoughts here:
https://medium.com/@boblord/methods-of-delivery-vs-intrusion-the-hacklore-edition-b042f51954a6
Feedback welcome!
@buherator What are the best anti-scam resources I can link to? It's not the focus on Hacklore but I can make sure there is a smoother on ramp to good guidance.