lingo.lol is one of the many independent Mastodon servers you can use to participate in the fediverse.
A place for linguists, philologists, and other lovers of languages.

Server stats:

59
active users

#googleworkspace

0 posts0 participants0 posts today
Fediverse, I have a rant I need to get off my chest. Groups in Google Workspace is a security nightmare and has been for years! Why has Google STILL not fixed the glaring problems!?

I've had admin powers at 5+ companies' Google Workspace/G Suite over the past decade or so. Every single one had groups which were misconfigured, often so anyone in the whole company could join without approval or see the message history at https://groups.google.com without being a member at all.

This is because for any sensible configuration of Google Groups when using it for email groups you have to use the "Custom" permissions mode. The default Public mode doesn't allow external people to email the group, but does allow the whole company to see all the messages. The default Team mode, has the same problem of everyone being able to see all the messages.

Also let's not forget that dangerous little "Anyone in the organisation can join" toggle at the bottom which is on by default. So any random new starter can join your confidential company directors group and get all the emails sent to it.

Giving Google the benefit of the doubt here, I think the reasoning might be that Google Groups is intended as a kind of company forum, not for private email groups. However that isn't how anyone uses it in my experience...

#security #infosec #google #googleworkspace
Replied in thread

@stefano Absolutely! And that’s ultimately what is important. I have a very healthy distrust of the cloud. My friends’ non-profit that helped with homeless veterans used #GoogleWorkspace until out of the blue their account was shut down by Google with 0 recourse. Their data was completely deleted and gone.

#onpremisesinfrastructure is vastly underrated. What are you going to do when #GoogleWorkspace or #Microsoft365 shut your account down because their AI decides to and you have no recourse. You can’t sue them because you’ve agreed to their terms of service. Oops? 🤷‍♂️

Also, what many don’t know is even if data is stored in the cloud, the customer is still responsible for backing up and archiving their data. The cloud company does some rudimentary disaster recovery but has specific indemnification against data loss. Marketing conveniently glosses over this. 😈

The #cloud cannot be trusted for small businesses. #Selfhosting is the way to go. It’s not hard at all and I am in the midst of writing a book for people with a minimal technical background to get started as easily as possible. Or even for them to have a technical friend help them out.

Google are increasing the prices for Google Workspace customers (like myself) in order to offset the "rising prices" of "technology and infrastructure" - which I understand is in large part due to Google's big investments in generative AI (Google Gemini) and the cost of the related technology and infrastructure.

Google are forcing their existing customers to pay for it, since far too few people actally need or want this - and definitely do not want to buy it.

Replied in thread

3/ Meines Erachtens nach muss die Nutzung von Maildiensten wie #MS365, #GoogleWorkspace, ... die über unverdächtige DE-Domains, oder Incoming-Mailserver von #Hornetsecurity verschleiert werden, auch in der Datenschutzerklärung der Website kenntlich gemacht werden.

Auf den Websites werden Mailadressen für die Kontaktaufnahme zu Personen, aber auch zu den Organisationen bereitgestellt, Info wohin Mails mit personenbezogenen Daten in Wirklichkeit gehen - Fehlanzeige!

Question:
Firstly, I’m disturbed that the #UK government want to be able to see all encrypted things from #Apple. (I’m not technical).

Now, somehow, I’ve managed to use #iCloud desktop on my Mac and laptop - saves just like a desktop, but it’s on iCloud. Any other providers that can do this?
Have been briefly looking into #pCloud.

Question 2:
#Tuta - better than #Proton?
I currently use #GoogleWorkspace as email domain provider (correct terms??) for my own domain, which is connected to #Siteground. Would like to keep Siteground, but wouldn’t mind moving email provider.
It took me a looooooong time to move everything from #Wix (had to get paid help), so the prospect of moving things again is dreadful. But … they’re all shit anyway.

I think it's really telling that Google, Microsoft, et al feel the need for bruteforce AI into our lives rather than sell us on it. It's clearly not for our benefit - it's for theirs. Corporate legal , IP, and data privacy concerns be damned for their commercial customers.

It's time to switch to products that serve our interests, not theirs.

That terrifying moment when Gmail shows a loading screen for much longer than you'd expect. Thoughts race through your mind: "Oh lord, they haven't added some new AI features into this free version, too?!?"

Luckily, it seemed to be just a temporary glitch. Yet this is what it's like to open any app in this age of #GenAI #enshittification. We don't trust our tools anymore. We fear for the AI magic buttons that will take over our digital world - without subscribing to anything. #GoogleWorkspace

My wife teaches at a Hebrew school. They are the chillest employer in the world, totally amazing.
She has an email address in the school's #GoogleWorkspace. It's not published anywhere. I don't think she uses it to email school parents; I believe the only reason she has it is because there was a problem with the school's payroll system (QuickBooks, of course) which they attempted to solve at one point by giving her an address at the school to use as her login.
#spam #ATT #privacy #infosec
🧵1/3

Domain owners flummoxed as strangers get #Google for their domains.

The #GoogleWorkspace business apps service sprang a leak last month. Scrotes were able to register a domain without actually owning the domain. Balderdash and piffle!

Naturally, this caused a kerfuffle with the true domain owners. In #SBBlogwatch, we deobfuscate the circumstance. At @TechstrongGroup’s @SecurityBlvd: securityboulevard.com/2024/07/

Security Boulevard · WTH? Google Auth Bug Lets Hackers Login as YouG Suite Sours: Domain owners flummoxed as strangers get Google for their domains.

Sick of the copy-paste grind when sending emails out in bulk? 🤯 There's a better way!

Let's be real – manually personalising a ton of emails is a major time suck. Enter Google Workspace's Mail Merge: your secret weapon for customised emails that don't feel mass-produced. ✨

Want to learn this productivity superpower? 🚀 Check out my latest video guide – you'll be a Mail Merge pro in no time!
🎥 buff.ly/49NZig4

Key benefits of Mail Merge:
- Save ridiculous amounts of time ⏳
- Boost open and click-through rates 📈
- Build stronger customer relationships 🤝

Continued thread

Let's delve into the details.

How did the fraudsters get the correct amounts and invoice numbers?

The answerer can be very simple.

They ask 😲

Some days or weeks before you will find an email from the "attacker" posing as the partner/customer/supplier, asking for a list of (outstanding) payments

With justifications like

  • IT problems preventing access
  • Possible data corruption
  • ...

If the helpful employee responds with the list, maybe even including the invoices the attackers have everything they need.

For this query attackers often use fake lookalike domain

Examples I have seen:

  • sm-q.de (sma.de)
  • sma-amerrica.com (sma-america.com)
  • sma-americas.com (sma-america.com)
  • smasud-america.com (sma-sudamerica.com)

but it can also just be fantasy combinations which look valid, like

  • sma-egypt.online.

The mean thing is that these lookalike domains are very hard to detect and to protect against.

The attack is also hard to detect as the question can be directed at the victim or imposed organization. While your "domain" is faked you are not part of the interaction. Therefore, spamfilters or other technical measures on your side don't help. As the fake domains are just registered for this, they will not by on any blacklist.

As the invoice generally don't contain malware, AV solutions won't help either.

Countermeasures

After you got aware of the attack (which is sadly after the attack) you can write to the abuse contact of the domain registrar. Use WhoIs to figure it out e.g
whois.com/whois/sma-amerrica.c

Side not: if you are not sure if a domain is fake, a very recent registration can be an indication of fraud.

As the fraudsters will need a function email infrastructure you can also report the abuse there. Figer out the provider by doing an MX (Mail Exchange) lookup
E.g. mxtoolbox.com/SuperTool.aspx?a

As you can see, sma-amerrica.com uses the Google email infrastructure (I believe its call #GoogleWorkspace). I haven't yet figured out how to complain to them.
Any pointers welcome

Third you can report with the police. In the US you can also try the Secret Service as they are responsible for Financial and Cyber Crime Investigations
secretservice.gov/investigatio

(2/n)

draft - Good news - “Turkish authorities force Meta to pay $160,000 daily amidst ongoing investigations…In October 2022, Turkish competition authorities charged Meta Platforms with a hefty penalty. Previously, it also conducted investigations in 2021 into Meta-owned platforms such as WhatsApp and Facebook.

The main issue between Meta and Turkish authorities was that they considered the tech giant to be destructive to competition. Turkish authorities suggested that Meta blocks competitors in the social network and online video advertising industry by combining the data it gathers from its social media platforms.

The Turkish authorities argued that Meta had violated the competition law.”

stop using -
#deletefacebook
#deletewhatsapp
#deleteinstagram

useful alternatives -
#telegram
#googleworkspace
#discord

neowin.net/news/turkish-author

NeowinTurkish authorities force Meta to pay $160,000 daily amidst ongoing investigationsMeta has been under the radar of the Turkish competition board since 2022 after it stated that Meta violated the competition law. Today, it has placed another fine that needs to be paid daily

Ahoy there, Efficiency Fans! 👋

Tired of navigating endless menus to format your Google Docs? Let me introduce you to a game-changer: Markdown! ⚡📄 With Markdown, you can kiss those menu-hunting days goodbye! 🙌💼

I've put together a quick tutorial video that reveals how Markdown in Google Docs (and Slides and Drawings too) can save you valuable time. ⏳⌨️ Watch as I demonstrate how simple keyboard shortcuts can revolutionize your document creation process. Less clicking, more creating! 🚀🎬

Ready to level up your efficiency? Dive into the tutorial now! 🤓👇

🎥 buff.ly/3Pmp1pe

⚙️ Embrace the efficiency of Markdown, freeing up your time for what truly matters. I am positive that this technique will become your new best friend, just like it has for me. ⌛🔑

#KeyboardShortcuts #GoogleDocs
#GoogleWorkspace #GoogleSlides #YouTube #Boost #FediTips