Infrastructure October 10, 2026 bearish ⇧ 5135 pts across 5 threads

Security basics keep failing in embarrassing ways

A Telegram Desktop vulnerability let any user's file be stolen, and commenters shrug that Telegram was never really secure. The Danish CPR data breach reportedly involved the password 123456 on a register tied to every resident's ID number, and a commenter praises getting a real root cause instead of silence. The Eye of Sauron research shows hidden spy cameras can be detected at long range. In older threads, a Docker Hub breach exposed 190k accounts and the FCC debated IoT security update rules.

The pattern: the headline failures are rarely clever attacks. They are weak passwords, unpatched clients and loose defaults on systems that hold very sensitive data. Readers value public post-mortems because they are how everyone else learns.

On the policy side, the old FCC thread shows the tension: automatic updates by default sound good, but people worry about manufacturers using remote access to turn features into subscriptions.