BlackBox (Security) Archiv
4.1K subscribers
183 photos
393 videos
167 files
2.67K links
👉🏼 Latest viruses and malware threats
👉🏼 Latest patches, tips and tricks
👉🏼 Threats to security/privacy/democracy on the Internet

👉🏼 Find us on Matrix: https://matrix.to/#/!wNywwUkYshTVAFCAzw:matrix.org
Download Telegram
Will smartwatch shoppers trust Facebook?

Facebook is apparently working on its own wearable, but there are big obstacles.

It looks like the next major player looking to take the Apple Watch’s crown may have the resources to seriously compete, even if it has other hurdles to overcome. According to a new report in The Information, Facebook is planning on releasing its first smartwatch, and the company may have something available as early as next year.

The story, corroborated by four anonymous sources at the company, claims that the wearable will have its own cellular connection, ensuring it can work independently of a smartphone, and it’s likely to play heavily to the company’s social appeal with Facebook Messenger baked in.

https://www.tomsguide.com/news/facebook-watch-reportedly-coming-next-year-and-apple-watch-is-laughing

#fb #facebook #DeleteFacebook #smartwatch
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
Jam

Jam is an Open Source alternative to Clubhouse, Twitter Spaces and similar audio spaces.

With Jam you can create Jams which are audio rooms that can be used for panel discussions, jam sessions, free flowing conversations, debates, theatre plays, musicals and more. The only limit is your imagination.

https://gitlab.com/jam-systems/jam

https://jam.systems/

#jam #alternatives #alternative #clubhouse #twitter #audio #spaces #opensource
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
How they harvest our data

TL;DR: everything is very bad. Prognosis is not comforting; if we do nothing all the distopias we read in fiction novels will look like a happy holiday at granny's.

It's hard to be in IT, cause your friends have no idea what you do. Engineer, product manager, QA — how does it all differ from fixing a printer in the office? (tip: you don't get $150k/year for fixing printers).

You also can't really talk to normal people about IT, because they use this industry, but they don't get it. But there's a topic you can raise with any mortal, that will get their attention: data privacy.

How do they gather data about us? Will VPN and incognito mode save us? Maybe we should all just pack our stuff and go into the woods and make friends with wolves and bears?

https://dkzlv.com/en/how-they-harvest-data/

#data #bigdata #thinkabout
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
Optimizer

Portable utility that helps you to restore your privacy and increase your security.

Optimizer is recommended after a fresh, clean installation of Windows to achieve maximum privacy and security.

Depending on your version of Windows, Optimizer will also allow you to perform some specific tweaks.

https://github.com/hellzerg/optimizer

Downloads:
https://github.com/hellzerg/optimizer/releases

#windows #optimizer #utility #tweaks #privacy #security
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
pgpp-arxiv20.pdf
7.1 MB
Pretty Good Phone Privacy

To receive service in today’s cellular architecture, phones uniquely identify themselves to towers and thus to operators. This is now a cause of major privacy violations, as operators sell and leak identity and location data of hundreds of millionsof mobile users.

In this paper, we take an end-to-end perspective on thecellular architecture and find key points of decoupling that enable us to protect user identity and location privacy with no changes to physical infrastructure, no added latency, and no requirement of direct cooperation from existing operators.

https://raghavan.usc.edu/papers/pgpp-arxiv20.pdf

#phone #privacy #study #pdf
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
Nigeria's Central Bank has now prohibited banks from processing #bitcoin and cryptocurrency transactions.

The country ranks second in P2P
#bitcoin volume.

https://nitter.nixnet.services/DocumentingBTC/status/1357679262908694529

#nigeria #bitcoin #cryptocurrency #thinkabout #why
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
New EFF Report Shows Cops Used Ring Cameras to Monitor Black Lives Matter Protests

LAPD Wanted Unknown Amount of Video for Unknown Reasons – Raising First Amendment Concerns

San Francisco -
The Electronic Frontier Foundation (EFF) has obtained emails that show that the Los Angeles Police Department (LAPD) sent at least one request—and likely many more—for Amazon Ring camera video of last summer’s Black-led protests against police violence. In a report released today, EFF shows that the LAPD asked for video related to “the recent protests,” and refused to disclose to EFF what crime it was investigating or how many hours of footage it ultimately requested.

“The emails we received raise many questions about what the LAPD wanted to do with this video,” said EFF Policy Analyst Matthew Guariglia. “Police could have gathered hours of footage of people engaged in First-Amendment-protected activity, with a vague hope that they could find evidence of something illegal. LAPD should tell the public how many hours of surveillance footage it gathered around these protests, and why.”

EFF filed its public records request with LAPD after widespread complaints about police tactics during the protests in May and June of 2020. After receiving the emails in response to our request, we asked for clarification from the LAPD about what it was looking for and how much video it wanted. The agency said simply that it was attempting to “identify those involved in criminal behavior.”

https://www.eff.org/press/releases/new-eff-report-shows-cops-used-ring-cameras-monitor-black-lives-matter-protests

https://www.eff.org/deeplinks/2021/02/lapd-requested-ring-footage-black-lives-matter-protests

#usa #lapd #amazon #ring #surveillance #blm #eff #thinkabout
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
Spy pixels in emails have become endemic

The use of "invisible" tracking tech in emails is now "endemic", according to a messaging service that analysed its traffic at the BBC's request.

Hey's review indicated that two-thirds of emails sent to its users' personal accounts contained a "spy pixel", even after excluding for spam.

Its makers said that many of the largest brands used email pixels, with the exception of the "big tech" firms.

Defenders of the trackers say they are a commonplace marketing tactic.

And several of the companies involved noted their use of such tech was mentioned within their wider privacy policies.

‼️ Emails pixels can be used to log:

if and when an email is opened

how many times it is opened

what device or devices are involved

the user's rough physical location, deduced from their internet protocol (IP) address - in some cases making it possible to see the street the recipient is on

This information can then be used to determine the impact of a specific email campaign, as well as to feed into more detailed customer profiles.

Hey's co-founder David Heinemeier Hansson says they amount to a "grotesque invasion of privacy".

https://www.bbc.com/news/technology-56071437

#spy #pixels #email #invisible #tracking #bigtech #BigData #thinkabout
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
Password manager: LastPass restricts free version

Users of the free version of LastPass will only be able to use the password manager across devices to a limited extent from March.

Starting in March and then again in May, the LastPass developers want to reduce the functionality of the free version. The password manager is available for popular systems such as Android, iOS and Windows. Users have access to their passwords stored in the password vault on all devices.

https://blog.lastpass.com/2021/02/changes-to-lastpass-free/

#LastPass #password #manager
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
The last search engine

Gigablast is the only non-Big Tech search engine in the U.S. that still crawls the web.

Big Tech is censoring Gigablast from indexing the "public" web.

💡 Cloudflare, Google, Bing Destroying the Infrastructure of the Free Web
https://www.gigablast.com/blog.html#anti

https://www.gigablast.com/

#gigablast #search #engine #cloudflare #google #bing #thinkabout
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
China steps up online controls with new rule for bloggers

TAIPEI, Taiwan (AP) —
Ma Xiaolin frequently wrote about current affairs on one of China’s leading microblogging sites, where he has 2 million followers. But recently, he said in a post, the Weibo site called and asked him not to post original content on topics ranging from politics to economic and military issues.

“As an international affairs researcher and a columnist, it looks like I can only go the route of entertainment, food and beverage now,” the international relations professor wrote on Jan. 31.

Ma, who often posted on developments in the Mideast, is one of many popular influencers working within the constraints of China’s heavily censored web who is finding that their space to speak is shrinking even further with the latest policy changes and a clean-up campaign run by the country’s powerful censors. He declined an interview request.

Beginning next week, the Cyberspace Administration of China will require bloggers and influencers to have a government-approved credential before they can publish on a wide range of subjects. Some fear that only state media and official propaganda accounts will get permission. While permits have been needed since at least 2017 to write about topics such as political and military affairs, enforcement has not been widespread. The new rules expand that requirement to health, economics, education and judicial matters.

“The regulators want to control the entire procedure of information production,” said Titus Chen, an expert in Chinese social media policy at National Sun Yat-Sen University in Taiwan.

https://apnews.com/article/taiwan-china-coronavirus-pandemic-blogging-50170ca73ed1f25ae769723e86c4d169

#china #blogging #microblogging #rules #netpolitics #thinkabout #why
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
LibreOffice team say they are working on a WebAssembly port

Developers hope to deliver a working example in the next few months.

Developers are reportedly getting close to bringing LibreOffice, the popular open source alternative to Microsoft Office, to the web browser using WebAssembly (WASM).

The project already offers LibreOffice Online as a collaborative, web-based version of LibreOffice. However, you can only really use it through its Collabora Online commercial variant.

Even as the Documentation Foundation (TDF), which helps develop and maintain LibreOffice, claims that it “is not planning to develop and fund a cloud solution similar to existing products from Google and Microsoft,” the developers of the WASM port hope to deliver a working demo by summer 2021.

https://www.techradar.com/news/libreoffice-team-say-they-are-working-on-a-webassembly-port

#libreoffice #opensource #webassembly #wasm #tdf
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
85: Cam the Carder
Darknetdiaries - EP 85: Cam the Carder

This is the story of Cam Harrison, aka “kilobit” and his rise and fall as a prominent carder.

https://darknetdiaries.com/episode/85/

#truecrime #darknetdiaries #podcast
🎙@cRyPtHoN_INFOSEC_FR
🎙
@cRyPtHoN_INFOSEC_EN
🎙
@cRyPtHoN_INFOSEC_DE
🎙
@BlackBox_Archiv
🎙
@NoGoolag
Behind the scenes of CityBee customer data leak

Introduction

All of this is obviously for educational and informative purpose. And I do not support any sort of crime either.

All of the information below comes from the researcher himself from his interview and some of my own tests obviously. :D

Well what even is CityBee you may ask?
It is a car, bike and scooter rental service in Lithuania.

And oh yes they store some data (can tell that just by looking at their homepage).

https://kernal.eu/posts/citybee-leak/

#citybee #lithuania #data #leak
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
When did "privacy issues" start to mean "too much privacy"?

Clubhouse draws the ire of journalists

I understand that every social media platform has to deal with misinformation, but I was surprised by the harassment and privacy issues the subtitle referred to.

My understanding of Clubhouse was that it was for pseudo-private conversations. Unless the app is leaking out information, I can’t imagine privacy to be an issue.

The NY Times article has one brief mention about privacy:

"This month, German and Italian regulators publicly questioned whether Clubhouse’s data practices complied with European data protection laws. And China blocked the app after political conversations popped up on it outside the country’s tight internet controls."

In another article linked to by the NY Times article provides more clarity regarding privacy:

"On Clubhouse, however, there are no screenshots. There is no way to drag up old Clubhouse posts years later like a user might do on Twitter. There is no way to record conversations—meaning there is no way to prove that someone said anything controversial at all. There’s no path to accountability. Users on Clubhouse know, or at least believe, that they can openly speak their mind with zero repercussions. Platforms like Twitter and Facebook have implemented robust moderation programs in recent years, a move that has been both praised and criticized by many."

This sounds like a feature, not a bug. Just between you and me, I don’t record any of my Zoom calls with friends. Just don’t mention it to any journalists.

https://mleverything.substack.com/p/when-did-privacy-issues-start-to

https://datenschutz-hamburg.de/assets/pdf/2021-02-02-press-release-clubhouse.pdf

#clubhouse #privacy
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
Dogecoin Has a Top Dog Worth $2.1 Billion

A single digital address appears to have accumulated holdings in dogecoin, the cryptocurrency that was started as a joke

The dogecoin market has a pack leader.

Records show that a person, or entity, owns about 28% of all of the cryptocurrency in circulation—a stake worth about $2.1 billion at current prices. The holder’s identity isn’t known, which is common in the opaque world of digital currencies.

It is hard to tell what to make of this giant position in what has long been a small and niche corner of the cryptocurrency world.

Dogecoin was created in 2013 as a satirical homage to bitcoin. Its developers were riffing off the meme of a Shiba Inu dog with bad spelling habits. It wasn’t designed to be used as a form of payment, or as anything except a joke. At the start of 2021, a dogecoin was worth about half a cent, even as bitcoin prices had surged to nearly $30,000.

https://telegra.ph/Dogecoin-Has-a-Top-Dog-Worth-21-Billion-02-17

via www.wsj.com

#dogecoin #cryptocurrency
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
Facebook's Australian news ban also blocked links to weather, government services, poetry, and Facebook itself

Australians woke up on Thursday morning to find their news feeds, post history, and favourite news outlets' pages scrubbed of all links to ... well, news.

Facebook followed through on its threat to ban the sharing of news links by and to Australian users, as the country's government moves closer to forcing big tech companies to pay to link media outlets' content.

The proposed news media bargaining code would see tech giants like Google and Facebook having to pay media companies for content that appears on their platforms. While Google initially threatened to pull out of Australia over the law, which has bipartisan support, it instead struck deals with dozens of platforms to pay them for content via its News Showcase. Facebook, in contrast, has chosen to take its bat and ball and go home like a big sulky baby.

But the ban's not just affecting local, national, and international news outlets.

It's also affected government websites like the Bureau of Meteorology, state governments, and health agencies; satirical news sites, like the Onion-esque larrikin "local news" The Betoota Advocate; organisations like the Australian Council of Trade Unions; and even literary journals.

https://mashable.com/article/facebook-news-ban-australia-effects

#DeleteFacebook #facebook #australia #newsban
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
Forwarded from NoGoolag
Reminder that there's a Nogoolag group and that you're missing most of the discussions if you're just commenting on the channel

Join: https://t.iss.one/joinchat/RfYPt67LSOB3BO6S
Facebook Takes Down Myanmar Military's Page

"In line with our global policies, we've removed the Tatmadaw True News Information Team Page from Facebook for repeated violations of our Community Standards prohibiting incitement of violence and coordinating harm," a Facebook representative said in a statement.

A Facebook page run by the Myanmar junta's "True News" information service was kicked off the platform Sunday after the tech giant accused it of inciting violence.

Security forces in the country have steadily increased violence against a massive and largely peaceful civil disobedience campaign demanding the return of deposed civilian leader Aung San Suu Kyi.

The Nobel laureate was taken into custody along with her top political allies at the start of the month, but the new regime has insisted it took power lawfully.

It has used Facebook to claim Suu Kyi's landslide election victory last November was tainted by voter fraud and issue stark warnings to the protest movement -- which is demanding that the army relinquish power.

A spokesperson for the platform said the Tatmadaw True News Information Team page was removed for "repeated violations of our Community Standards prohibiting incitement of violence and coordinating harm".

https://www.ndtv.com/world-news/myanmar-crisis-facebook-takes-down-main-page-of-myanmar-military-2375164

#fb #DeleteFacebook #myanmar #military #violence
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
Parents alerted to NurseryCam security breach

A webcam system that lets parents drop in and watch their children while at nursery school has written to families to tell them of a data breach.

NurseryCam said it did not believe the incident had involved any youngsters or staff being watched without their permission, but had shut down its server as a precautionary measure.

The Guildford-based company told the BBC its service was used by about 40 nurseries across the UK.

It said it had also notified the ICO.

Under UK rules, the Information Commissioner's Office must be told of a breach if it has "significant impact" within 24 hours.

NurseryCam said it first became aware of the incident shortly after 17:00GMT on Friday.

It added the service would remain suspended until a security fix was in place.

https://www.bbc.com/news/technology-56141093

#security #data #breach #webcam #uk
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
Social Analyzer

Social Analyzer - API, CLI & Web App for analyzing & finding a person's profile across +300 social media websites. It includes different string analysis and detection modules, you can choose which combination of modules to use during the investigation process.

The detection modules utilize a rating mechanism based on different detection techniques, which produces a rate value that starts from 0 to 100 (No-Maybe-Yes). This module intended to have less false positive and it's documented in this Wiki link

The analysis and extracted social media information from this OSINT tool could help in investigating profiles related to suspicious or malicious activities such as cyberbullying, cybergrooming, cyberstalking, and spreading misinformation.

This project is "currently used by some law enforcement agencies in countries where resources are limited".

https://github.com/qeeqbox/social-analyzer

#social #analyzer #qeeqbox #socialmedia #tool
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag