Ever seen an ad so accurate you think your phone is listening to you? While that's not the case, the reality is even creepier.
Here's how Google & Facebook collect your data & use it to auction you off to advertisers for profit: https://vimeo.com/352982094 https://video.buffer.com/v/5d516f99cb137e1e4e76fd38
Ban Driven Grouse Shooting #uk #wildlife
https://petition.parliament.uk/petitions/266770
Galileo GNS monitoring https://galmon.eu/ #galileo
PSA if your like me and would like to use a ROM but keep buying the wrong phones for lineage or /e/foundation. Now /e/foundation sells their own phones. They are coming out with a system where you could mail in your phones also. Here is the shop. https://e.foundation/e-pre-installed-refurbished-smartphones/
I spent all day looking for vulns in a IoT clothes dryer. What did I find?
* HTTPS to talk to backend service
* XMPP w/ STARTTLS to steam events
* Cert pinning so no MitM
* Android app obfuscated w/ no obvious backend URLs or certs
* Dryer runs an AP for initial setup w/ DHCP and HTTPS servers
* That HTTPS requires auth with a password printed on a label near the door
Best I could do was get the DHCP server to serve the same IP to every request.
Well done GE.
My Recommended Services
Messenger: #Signal #Wire
Email: #ProtonMail #Tutanota
Search Engines: #DuckDuckGo #Qwant #Startpage
VPN: #ProtonVPN #NordVPN
Password Managers: #Bitwarden #KeePass
Browser: #Firefox #Brave #TorBrowser
SNS: #Mastodon
Cloud Storage: #Nextcloud #MEGA
Note: #StandardNotes
Encryption Software: #VeraCrypt #Cryptomator
Send File: #FirefoxSend
File Sync: #Syncthing
~Open Source Security Tool of the Day~
Cabot is a free, open-source, self-hosted infrastructure monitoring platform that provides some of the best features of PagerDuty, Server Density, Pingdom and Nagios without their cost and complexity.
If you ever wondered why most Matrix large group chats don't have E2E enabled - here's a good discussion of the problem and existing solutions https://blog.trailofbits.com/2019/08/06/better-encrypted-group-chat/ #cryptography
Attacks against #whatsapp protocol published on BlackHat 2019 https://research.checkpoint.com/black-hat-2019-whatsapp-protocol-decryption-for-chat-manipulation-and-more/
Interesting fact: #uk #imperial units are all legally defined in #metric units. Inch is 2.54 cm, pound is 0.45359237 etc https://www.legislation.gov.uk/uksi/1995/1804/schedule/made
A big step for privacy in Arizona! The state ruled that "police & govt agencies cannot obtain [a persons' online data] without a search warrant, [which] requires a showing of some criminal activity," reports @azcapmedia.
As it should be in all regions. https://azcapitoltimes.com/news/2019/07/31/court-rules-arizona-residents-have-right-to-internet-privacy/
RT @MatthewKeysLive@twitter.com
#BREAKING: Armed man driving "Trump" truck arrested outside migrant shelter in El Paso after immigration group spotted him "brandishing a knife." Police recovered a fully-loaded gun in his truck emblazoned with Donald Trump and Ted Cruz support slogans.
There's a nice #linux tool:
systemd-analyze security SERVICE
It looks at #security and confinement features used by systemd services as documented here https://www.freedesktop.org/software/systemd/man/systemd.exec.html
An example for my radvd.service
A colleague found a nice archival document that documents similar #hacking activity from 1999 from #russia https://assets.documentcloud.org/documents/6007145/National-Security-Archive-Naval-Research.pdf
Google Researcher: The iPhone Is Not Exactly a Paragon of Security
At Black Hat, a Google security researcher details numerous bugs in iMessage that could be exploited remotely without interaction from the victim.
https://www.pcmag.com/news/370065/google-researcher-the-iphone-is-not-exactly-a-paragon-of-se
Oh, I finally found a way to easily bridge #ssb to regular web: a quick note about security features of new application packaging formats #appimage #flatpak #snapcraft #electron https://viewer.scuttlebot.io/%25%2FRS0FmBCprqW7Z6z7ExSqDfPVKOZb9Xh5wIPSlngHKY%3D.sha256
This is absolutely fascinating research: "450-million years ago a switch enabled plants to delay reproduction and displace new cells downwards from the shoot tips, paving the way to plant diversification" https://phys.org/news/2019-08-genes-enabled-scientists.html #evolution #biology #science
Polish expat into UK. Information security engineer. Caver & cave rescuer (thus the bat). NHS volunteer & blood donor.