BlackBox (Security) Archiv
4.09K subscribers
183 photos
393 videos
167 files
2.67K links
👉🏼 Latest viruses and malware threats
👉🏼 Latest patches, tips and tricks
👉🏼 Threats to security/privacy/democracy on the Internet

👉🏼 Find us on Matrix: https://matrix.to/#/!wNywwUkYshTVAFCAzw:matrix.org
Download Telegram
The Great Firewall Cracked, Briefly. A People Shined Through.

China’s censors finally blocked Clubhouse, but not before users were able to bypass the caricatures painted by government-controlled media and freely discuss their hopes and fears.

For years, the Chinese government has prevented its 1.4 billion people from speaking freely online. A digital wall separated them from the rest of the world.

Then, for a precious few days, that wall was breached.

Clubhouse, a new social media app that emerged faster than the censors could block it, became a place for Mandarin Chinese speakers from the mainland and anywhere else to speak their minds. They had a lot to say.

In Clubhouse’s audio chatrooms, people from the mainland joined those from Taiwan, Hong Kong, the global Chinese diaspora and anybody else who was interested to share thoughts. The topics ranged from the politically charged (repression of Muslims in China’s Xinjiang region, the 1989 Tiananmen Square crackdown, censorship) to the mundane (hookups) to the unexpected (hemorrhoids).

The Chinese government blocked the app Monday afternoon. I knew it was coming, and yet I still didn’t expect to feel so dismayed.

For that brief moment, people in China proved that they are as creative and well spoken as people who enjoy the freedom to express themselves. They lined up, sometimes for hours, to wait for their turns to speak. They argued for the rights of the government loyalists to speak despite their disagreements. They held many honest, sincere conversations, sometimes with tears and sometimes with laughter.

https://www.nytimes.com/2021/02/09/technology/china-clubhouse.html

https://www.nytimes.com/2021/02/08/world/asia/china-clubhouse-blocked.html

#china #asia #clubhouse #blocked #GreatFirewall #repression #digitalwall #censorship #thinkabout
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
Court Orders Telegram To Block Pirated Movies, TV Shows and Music

A court has ordered Telegram to block access to pirated movies, TV shows and music following a lawsuit filed in Israel. Local anti-piracy group ZIRA complained that the messaging platform does not properly respond to takedown notices, contrary to Telegram's claims that it does. Telegram is now working with rightsholders to implement the injunction.

Last November, the RIAA and MPAA nominated popular messenger app Telegram for inclusion on the USTR’s ‘notorious markets’ list, claiming that the platform doesn’t do enough to combat piracy.

A month later, the EU added the service to its own ‘Counterfeit and Piracy Watch List’, noting that along with other social media platforms, Telegram “lags behind” in respect of efforts to combat piracy.

This opinion is shared by Israel-based anti-piracy group ZIRA. Last year, ZIRA – which represents local media companies – took its complaints to court, hoping to force Telegram to take a more serious approach to infringement mitigation.

https://torrentfreak.com/court-orders-telegram-to-block-pirated-movies-tv-shows-and-music-210210/

#tg #telegram #court #order #block #pirated #movies #music #riaa #mpaa #piracy #watchlist
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
North Dakota Senate bill targets 'monopolistic' app stores

Proponents of a North Dakota Senate bill say the legislation would clamp down on app stores seen as monopolistic, but opponents see it as interference and potentially harmful.

Sen. Kyle Davison, R-Fargo, on Tuesday introduced Senate Bill 2333 to the Senate Industry, Business and Labor Committee. The bill would ban app stores such as Apple and Google Play from requiring app developers to exclusively use their app store and payment system, and prohibit retaliating. Violations would be considered an unlawful practice under state law, opening a door to lawsuits.

"The purpose of the bill is to level the playing field for app developers in North Dakota and protect customers from devastating, monopolistic fees imposed by big tech companies," said Davison, referring to a 30% fee imposed by Apple and Google on in-app purchases, which he said penalizes small app developers "by raising prices and limiting choices for consumers."

Proponents of the bill said it addresses concerns of a monopoly by Apple and Google.

https://telegra.ph/North-Dakota-Senate-bill-targets-monopolistic-app-stores-02-11

via bismarcktribune.com

https://www.legis.nd.gov/assembly/67-2021/bill-actions/ba2333.html

#usa #monopolistic #appstores #apple #DeleteApple #google #DeleteGoogle
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
Facebook Is Said to Be Building a Product to Compete With Clubhouse

The social network, which has a history of cloning its competitors, has started working on an audio chat product.

SAN FRANCISCO —
Facebook is building an audio chat product that is similar to the popular young app Clubhouse, according to two people with knowledge of the matter, as the social network aims to expand into new forms of communication.

Clubhouse, a social networking app, has gained buzz for letting people gather in audio chat rooms to talk about various topics. Mark Zuckerberg, Facebook’s chief executive, has been interested in audio communication forms, said the people with knowledge of the matter, and he appeared in the Clubhouse app on Sunday to chat about augmented and virtual reality.

Facebook executives have ordered employees to create a similar product, known internally as Fireside, said the people, who were not authorized to speak publicly. The product is in its earliest stages of development, they said, and the project’s code name could change.

“We’ve been connecting people through audio and video technologies for many years and are always exploring new ways to improve that experience for people,” Emilie Haskell, a Facebook spokeswoman, said.

A representative for Clubhouse declined to comment.

https://www.nytimes.com/2021/02/10/technology/facebook-building-product-clubhouse.html

#facebook #DeleteFacebook #Clubhouse
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
The Crypto-Chernobyl

In recent history the mining, petroleum, and nuclear industries have all had their share of environmental disasters. These are household names that every school child learns: Chernobyl. Fukushima. Deepwater. Kingston. Valdez. However you may not know that as you read this, the tech industry is having it’s own environmental disaster moment and you may have heard its name: Bitcoin.

For those of you living in a monastery for the last decade, bitcoin is a computer protocol that provides a speculative digital pseudo-asset that is traded between individuals around the world. It is a system that aims to transcend borders, banks and laws. It’s notoriously difficult to frame bitcoin in traditional concepts because it defies many traditional terms. It’s not a currency, it’s not a payment system, it’s barely used to transact, it doesn’t support an economy, it’s not correlated to anything, and it’s unclear if there is any meaningful way to value it.

Rather that use traditional economic terms, I prefer to discuss it purely in more conceptual parlance. Cryptocurrency is an intentionally ambiguous term about a set of technologies which aim to reinvent money from first principles independent of existing power structures. Many writers, including myself, have written that the only meaningful way to describe bitcoin is as an investment bubble built around the narrative of populist rage at economic inequality and the broken state of our economy.

However, behind the philosophical ambiguities of the investment narrative there is a very concrete piece of software that is running on servers across the world. It is an enormously power-hungry and wasteful system that involves doing massive number of trial computations (a process called mining) in parallel across the world in a form of lottery in which computers race to confirm transactions. The more power you can waste, the more bitcoins you can probabilistically win in exchange for your energy waste.

Over the past ten years people have set up thousands of warehouses of computer hardware dedicated to run 24/7 consuming power and performing the trial computations required by the protocol. Left unregulated and uncontrolled this now consumes the equivalent power of several medium-sized nation states to keep it all running. Today it just passed the energy consumption of Argentina, a country of 45 million people.

The protocol itself is a runway environmental disaster that incentives an ever increasing amount of waste that can only increase with time. Increasing energy waste is an central and irremovable part of the design. Projections about this energy waste paint a bleak future.

https://www.stephendiehl.com/blog/chernobyl.html

#crypto #chernobyl #thinkabout
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
Media is too big
VIEW IN TELEGRAM
Ransomware Attacks: What Are They And How to Protect Yourself

Did you know that as much as 90% of cyberattacks are the result of human error? So, keeping up to date with proper security practices is more important than ever…and ransomware attacks are no different, threats are ever growing, and we need to be aware of the devastating damage that can follow an attack.

Large-scale attacks are also up by 273% in only the first quarter of this year, with ransomware rising by a significant 90%. So, it’s about time that we take the threat of ransomware seriously!

https://www.youtube.com/watch?v=ZiSiVi4t2oY

#ransomware #video
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
Watch_the_Asciinema_Replay_of_Your_Home_Made_Honeypot.pdf
956.4 KB
Watch hackers on your own honeypot server

At FOSDEM, two developers presented a nifty way to build your own SSH honeypot and look over the hackers' shoulders.

A honeypot is an intentionally vulnerable server that is introduced to the Internet with the purpose of attracting attackers. For example, it can be used to study the latest attack techniques that are currently in use. But not only for security experts, also as an admin a honeypot can be useful.

https://fosdem.org/2021/schedule/event/asciinema_honeypot/attachments/slides/4666/export/events/attachments/asciinema_honeypot/slides/4666/Watch_the_Asciinema_Replay_of_Your_Home_Made_Honeypot.pdf

https://github.com/ContainerSSH/auditlog/blob/main/codec/asciinema/format.go

#asciinema #honeypot #ssh #hacker #pdf
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
Media is too big
VIEW IN TELEGRAM
The Great Firewall of...America? WTZ!

This past week on Feb 2 - Feb 7, 2021 a massive attack was conducted on encrypted services, particular VPN's. VPN traffic was throttled to near unusability.

Basically in 2021, the Great Firewall of the USA was turned on. And then abrubtly turned off.

Purpose of the action was unknown. No party stepped up to acknowledge and aside from me, no one has stepped up to call any Internet Provider of their egregious action against privacy minded people.

Why did this attack happen?
Why did the attack stop?

https://www.youtube.com/watch?v=38za1LYj2XQ&t=1

#usa #greatfirewall #firewall #internet #attack #privacy #thinkabout #video
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
‘Windows is sh*t:’ Linux Users and The Technical Superiority Problem

“Windows is shit.” “That’s garbage, don’t use it.” “I don’t understand why anyone uses that crap.” ~Toxic nerds on the internet, since forever.

https://medium.com/linuxforeveryone/windows-is-sh-t-linux-users-and-the-technical-superiority-problem-196a597aa860

#linux #windows #thinkabout
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
Will smartwatch shoppers trust Facebook?

Facebook is apparently working on its own wearable, but there are big obstacles.

It looks like the next major player looking to take the Apple Watch’s crown may have the resources to seriously compete, even if it has other hurdles to overcome. According to a new report in The Information, Facebook is planning on releasing its first smartwatch, and the company may have something available as early as next year.

The story, corroborated by four anonymous sources at the company, claims that the wearable will have its own cellular connection, ensuring it can work independently of a smartphone, and it’s likely to play heavily to the company’s social appeal with Facebook Messenger baked in.

https://www.tomsguide.com/news/facebook-watch-reportedly-coming-next-year-and-apple-watch-is-laughing

#fb #facebook #DeleteFacebook #smartwatch
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
Jam

Jam is an Open Source alternative to Clubhouse, Twitter Spaces and similar audio spaces.

With Jam you can create Jams which are audio rooms that can be used for panel discussions, jam sessions, free flowing conversations, debates, theatre plays, musicals and more. The only limit is your imagination.

https://gitlab.com/jam-systems/jam

https://jam.systems/

#jam #alternatives #alternative #clubhouse #twitter #audio #spaces #opensource
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
How they harvest our data

TL;DR: everything is very bad. Prognosis is not comforting; if we do nothing all the distopias we read in fiction novels will look like a happy holiday at granny's.

It's hard to be in IT, cause your friends have no idea what you do. Engineer, product manager, QA — how does it all differ from fixing a printer in the office? (tip: you don't get $150k/year for fixing printers).

You also can't really talk to normal people about IT, because they use this industry, but they don't get it. But there's a topic you can raise with any mortal, that will get their attention: data privacy.

How do they gather data about us? Will VPN and incognito mode save us? Maybe we should all just pack our stuff and go into the woods and make friends with wolves and bears?

https://dkzlv.com/en/how-they-harvest-data/

#data #bigdata #thinkabout
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
Optimizer

Portable utility that helps you to restore your privacy and increase your security.

Optimizer is recommended after a fresh, clean installation of Windows to achieve maximum privacy and security.

Depending on your version of Windows, Optimizer will also allow you to perform some specific tweaks.

https://github.com/hellzerg/optimizer

Downloads:
https://github.com/hellzerg/optimizer/releases

#windows #optimizer #utility #tweaks #privacy #security
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
pgpp-arxiv20.pdf
7.1 MB
Pretty Good Phone Privacy

To receive service in today’s cellular architecture, phones uniquely identify themselves to towers and thus to operators. This is now a cause of major privacy violations, as operators sell and leak identity and location data of hundreds of millionsof mobile users.

In this paper, we take an end-to-end perspective on thecellular architecture and find key points of decoupling that enable us to protect user identity and location privacy with no changes to physical infrastructure, no added latency, and no requirement of direct cooperation from existing operators.

https://raghavan.usc.edu/papers/pgpp-arxiv20.pdf

#phone #privacy #study #pdf
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
Nigeria's Central Bank has now prohibited banks from processing #bitcoin and cryptocurrency transactions.

The country ranks second in P2P
#bitcoin volume.

https://nitter.nixnet.services/DocumentingBTC/status/1357679262908694529

#nigeria #bitcoin #cryptocurrency #thinkabout #why
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
New EFF Report Shows Cops Used Ring Cameras to Monitor Black Lives Matter Protests

LAPD Wanted Unknown Amount of Video for Unknown Reasons – Raising First Amendment Concerns

San Francisco -
The Electronic Frontier Foundation (EFF) has obtained emails that show that the Los Angeles Police Department (LAPD) sent at least one request—and likely many more—for Amazon Ring camera video of last summer’s Black-led protests against police violence. In a report released today, EFF shows that the LAPD asked for video related to “the recent protests,” and refused to disclose to EFF what crime it was investigating or how many hours of footage it ultimately requested.

“The emails we received raise many questions about what the LAPD wanted to do with this video,” said EFF Policy Analyst Matthew Guariglia. “Police could have gathered hours of footage of people engaged in First-Amendment-protected activity, with a vague hope that they could find evidence of something illegal. LAPD should tell the public how many hours of surveillance footage it gathered around these protests, and why.”

EFF filed its public records request with LAPD after widespread complaints about police tactics during the protests in May and June of 2020. After receiving the emails in response to our request, we asked for clarification from the LAPD about what it was looking for and how much video it wanted. The agency said simply that it was attempting to “identify those involved in criminal behavior.”

https://www.eff.org/press/releases/new-eff-report-shows-cops-used-ring-cameras-monitor-black-lives-matter-protests

https://www.eff.org/deeplinks/2021/02/lapd-requested-ring-footage-black-lives-matter-protests

#usa #lapd #amazon #ring #surveillance #blm #eff #thinkabout
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
Spy pixels in emails have become endemic

The use of "invisible" tracking tech in emails is now "endemic", according to a messaging service that analysed its traffic at the BBC's request.

Hey's review indicated that two-thirds of emails sent to its users' personal accounts contained a "spy pixel", even after excluding for spam.

Its makers said that many of the largest brands used email pixels, with the exception of the "big tech" firms.

Defenders of the trackers say they are a commonplace marketing tactic.

And several of the companies involved noted their use of such tech was mentioned within their wider privacy policies.

‼️ Emails pixels can be used to log:

if and when an email is opened

how many times it is opened

what device or devices are involved

the user's rough physical location, deduced from their internet protocol (IP) address - in some cases making it possible to see the street the recipient is on

This information can then be used to determine the impact of a specific email campaign, as well as to feed into more detailed customer profiles.

Hey's co-founder David Heinemeier Hansson says they amount to a "grotesque invasion of privacy".

https://www.bbc.com/news/technology-56071437

#spy #pixels #email #invisible #tracking #bigtech #BigData #thinkabout
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag