🚨 Foreigners crossing certain Chinese borders are being forced to install malware on their Android phones.
"The malware downloads a tourist’s text messages, calendar entries, and phone logs, as well as scans the device for over 70,000 different files." https://www.vice.com/en_us/article/7xgame/at-chinese-border-tourists-forced-to-install-a-text-stealing-piece-of-malware
Ever tried to manage a fleet of routers and not go insane? We did too. My colleague combined #SaltStack, #Wireguard, and #OpenWRT, and now we can deploy a config on few dozen routers without breaking a sweat.
He's giving a talk on this tomorrow at Pass the Salt:
https://2019.pass-the-salt.org/talks/55.html
Will there be a live stream? Yes!
https://passthesalt.ubicast.tv/lives/live/
Will we release our code? We already have!
https://git.occrp.org/libre/salt-routers
@bstacey godd did you hear about the situation in germany? because it's incredible
basically, the German Conference of University Deans ("HRK"), in a moment of unlikely clarity, decided that they were Tired Of This Shit and told all the publishers that from now on all german universities would make one large agreement with them, on the universities terms, for access
elsevier and springer made offers so laughable that the HRK actually literally wrote a press release about how they should "come back to the table when they're ready to make a serious offer" and since then many universities have just kind of let access contracts expire
they recently came to an agreement with wiley, rest is still ? ? ? ? ?
it's fantastic because every day this goes on is a day more scientists learn about the greatest development in science access of this century, which, lets be quite honest, is scihub
@kravietz dear Sir, do you have a moment to talk about our Lord and Saviour, Log Analytics?
https://matomo.org/faq/log-analytics-tool/faq_16301/
Also, the JS bug pings the analytics server with the view data. So, caching doesn't really make web analytics harder. :)
Seems like #cloudflare was down due to a massive DDoS launched against HK http://www.digitalattackmap.com/#anim=1&color=0&country=ALL&list=0&time=18078&view=map
Oh, #Cloudflare was having issues and brought a lot of websites down with it? That's not great.
But thankfully it's not that hard to roll out your own "DDoS protection" (or caching; just call it caching) setup. Here, you can even use our configs: https://git.occrp.org/libre/fasada
Yes, we use them in production, serving sometimes hundreds of thousands views per day.
Patches welcome. #SysAdmin
What if All Your #slack Chats Were Leaked? https://www.nytimes.com/2019/07/01/opinion/slack-chat-hackers-encryption.html
Beta #nftables #snap package available here with the latest 0.9.1 build https://snapcraft.io/nftables-pk
So we started shipping WebRender in Firefox a few weeks ago. Completely new rendering engine written in rust, big departure from how we approached rendering before. We are gradually enabling it for different hardware/OS configurations and a couple of million users have it now.
What's kind of blowing my mind, having worked on 3 large-ish rewrites, is that since WebRender shipped, telemetry has reported less crashes per user with WebRender than without.
This is *not* how big rewrites usually go.
Finally some light being shed on the ownership of the NSO Group:
https://www.theguardian.com/artanddesign/2019/jun/18/serpentine-galleries-chief-yana-peel-resigns-in-spyware-firm-row
We need more of such reporting. Cyberwarfare actors need to be exposed.
NEW: During the rule of Hugo #Chávez, the #Venezuela's government awarded generous electricity contracts and oil concessions to a group of young businessmen, the Bolichicos, who built power plants during a series of widespread #blackouts. Almost 10 years later, as Venezuela continues to struggle with its #electricity supply, leaked documents reveal more about the deals.
https://www.occrp.org/en/investigations/plunging-venezuela-into-the-dark
Tired to fuel surveillance capitalism?
First #ungoogled #Android smartphones soon to be ready to fly!
#mydataisMYdata #opensource
https://e.foundation/e-pre-installed-smartphones/
“I want [my kids] to understand that what they’re doing [online] now is going to have consequences in the future,” says @KColemanNCSA, executive director of @StaySafeOnline.
Read his tips & strategies for working on cybersecurity w/your kids: https://archerint.com/how-to-talk-to-your-kids-about-security-online/
You've been waiting for this for a long time: we're launching the alternative map service, open and with privacy as a priority. We explain this ambitious project on
https://betterweb.qwant.com/qwant-maps-a-open-and-privacy-focused-map/
The new keybase.openpgp.org has a pretty good usage instructions for Enigmail, OpenKeychain, GnuPG etc https://keys.openpgp.org/about/usage #pgp #security
@kravietz
Publishing keys to keyserver seemed like bad idea anyway, there are better ways of publishing your public keys or signatures. Thats one of the reasons Keybase exists.
25 out of 28 introductory psychology books define or explain statistical significance wrong https://journals.sagepub.com/doi/abs/10.1177/2515245919858072?journalCode=ampa #science #psychology
Someone is actively DoSing GnuPG by adding thousands of signatures through keyserver network. Disable keyservers or switch do keys.openpgp.org #security #pgp https://gist.github.com/rjhansen/67ab921ffb4084c865b3618d6955275f
Polish expat into UK. Information security engineer. Caver & cave rescuer (thus the bat). NHS volunteer & blood donor.