BlackBox (Security) Archiv
4.1K subscribers
183 photos
393 videos
167 files
2.67K links
👉🏼 Latest viruses and malware threats
👉🏼 Latest patches, tips and tricks
👉🏼 Threats to security/privacy/democracy on the Internet

👉🏼 Find us on Matrix: https://matrix.to/#/!wNywwUkYshTVAFCAzw:matrix.org
Download Telegram
Police can access suspects’ Facebook and WhatsApp messages in deal with US

WhatsApp, Facebook and other social media platforms will be forced to disclose encrypted messages from suspected terrorists, paedophiles and other serious criminals under a new treaty between the UK and the US.

Priti Patel, home secretary, will sign an agreement next month that compels US social media companies to hand over information to the police, security services and prosecutors. The data access agreement, which marks the culmination of four years of intense lobbying by the UK, is seen by Downing Street as an essential tool in the fight against terrorism and sexual abuse.

Ms Patel has previously warned social media companies that they risk empowering terrorists and urged them to take greater responsibility for criminal activity on their platforms. At present the security services are only able to obtain data if there is a need for an “emergency disclosure” due to an imminent threat to life. The police and prosecutors can also request data under the “mutual legal assistance” treaty but the process is highly bureaucratic and can take up to two years.

Under the new treaty, the police, prosecutors and the security services can submit requests for information to a judge, magistrate or “other independent authority”. The process will be overseen by the investigatory powers commissioner.

The UK has agreed it will not target people in the US and the US has agreed not to target people in the UK. The government is “confident” that the arrangement will comply with data protection regulations. Britain has also secured a guarantee that any information secured by the US from British companies cannot be used as evidence in cases that attract the death penalty, without the UK’s permission.

Last year Facebook was criticised by police investigating the murder of 13-year-old Lucy McHugh for refusing to release messages sent by Stephen Nicholson, the main suspect. After applying through the US courts for access to his account, prosecutors only received a log of his Facebook contacts with Lucy but not the content of any messages. It finally arrived the day that the trial started and Nicholson was convicted.

David Davis, the former Brexit secretary and a prominent campaigner on privacy issues, cautioned against the new powers. “The simple truth is that I’m afraid the US has a habit of using to the maximum extraterritorial laws to promote its own causes,” he said.

However, Richard Walton, a former head of counterterrorism at the Metropolitan Police, said: “US tech giants have been inadvertently putting a veil over serious criminality and terrorism. It has tilted the balance in favour of criminals and terrorists. This is very welcome, it will make a big difference.”

👉🏼 Read more (paywall)
https://www.thetimes.co.uk/article/police-can-access-suspects-facebook-and-whatsapp-messages-in-deal-with-us-q7lrfmchz

#UK #USA #Police #DeleteWhatsapp #DeleteFacebook
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_ES
📡@FLOSSb0xIN
🇪🇸 Whatsapp y otras apps tendrán "puertas traseras" en el Reino Unido para descifrar mensajes

Hoy en día, cualquier app de mensajería que se precie implementa algún tipo de protección en nuestros mensajes.

El cifrado punto a punto (o extremo a extremo) se ha generalizado en los últimos años; consiste en cifrar los mensajes y que estos permanezcan cifrados durante toda la comunicación, hasta que lleguen a su destinatario. De esta manera, ni siquiera los creadores de la app pueden leer el mensaje.

El cifrado punto a punto no es perfecto, pero sí que es mucho mejor que alternativas como el "cifrado en tránsito", en el que el servidor de la compañía sí puede descifrar y leer nuestros mensajes.

Este tipo de protección ha sido muy solicitada por los usuarios, pero para los gobiernos y servicios de inteligencia de todo el mundo es un quebradero de cabeza. Los dos gobiernos más contrarios al cifrado punto a punto han sido el del Reino Unido y el de los EEUU, y ya han dado pasos para prohibirlo o, al menos, limitar su eficacia.

La excusa usada por estos gobiernos es la misma: la seguridad. En concreto, denuncian que apps como Whatsapp o Telegram están siendo usadas por terroristas y criminales para organizarse; también se habla de redes de pedofilia creadas en estas plataformas.

Desde hace años, el gobierno británico ha presionado a las desarrolladores para obtener acceso a las llamadas "puertas traseras", métodos para saltarse el cifrado de los mensajes. Estas puertas pueden ser, por ejemplo, el acceso a una clave maestra de cifrado, capaz de descifrar cualquier mensaje, o acceso a la tecnología usada para cifrar el texto.

Las iniciativas del gobierno británico han sido duramente criticadas por expertos de seguridad de la industria. Ni que decir tiene que la mera existencia de estas puertas traseras haría inútil cualquier método de protección; sería exactamente lo mismo que no tener ningún tipo de cifrado. Desde el mismo momento en el que un mensaje se puede descifrar, esa comunicación ya no es segura.

Ahora el gobierno británico se ha encontrado con un gran aliado en su lucha contra el cifrado: EEUU. La administración Trump se ha mostrado en contra del cifrado extremo a extremo, e incluso se estaría planteando prohibirlo completamente.

Según adelanta Bloomberg, un nuevo acuerdo entre EEUU y el Reino Unido obligaría a apps de mensajería y redes sociales a aportar esa "puerta trasera" a la policía británica. El acuerdo, que se finalizaría en octubre, afectaría a Facebook, Whatsapp y otras apps similares.

El texto incluye algunas excepciones, destinadas a protegerse mutuamente. Por ejemplo, ambos gobiernos se comprometen a no usar estas puertas traseras para investigar a usuarios del otro país.

Además, inicialmente las apps sólo estarán obligadas a aportar información en casos de "crímenes graves", como terrorismo o pedofilia. Sin embargo, ya se habla de que el acuerdo abriría una "Caja de Pandora", y que en el futuro se puedan obtener mensajes que no estén relacionados con crímenes graves.
https://www.elespanol.com/omicrono/software/20190929/whatsapp-puertas-traseras-reino-unido-descifrar-mensajes/432956770_0.html

#uk #privacidad #mensajeria
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_ES
📡@FLOSSb0xIN
30 countries closed media and blocked internet access so far in 2019

In advance of the International Day for Universal Access to Information (IDUAI) on 28 September, the IFJ has condemned the fact that more than 30 countries have been guilty of closing media or blocking internet access so far in 2019, threatening citizens’ fundamental right to free access to information.

https://www.ifj.org/media-centre/news/detail/category/press-releases/article/iduai-30-countries-closed-media-and-blocked-internet-access-so-far-in-2019.html

#democracy #IDUAI #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_ES
📡@FLOSSb0xIN
Russia starts rolling out DPI filtration tech that might finally block Telegram

Russia’s federal censor has started testing new digital filtration equipment that could finally make it possible to block access to the instant messenger Telegram. A source participating in the pilot project told the news website RBC that DPI (Deep Packet Inspection) technology is rolling out in Russia’s Ural Federal District, enabling ISPs to analyze and filter specific Internet traffic (a more sophisticated form of online censorship than simply blocking whole IP addresses, which has failed against Telegram).

RBC’s sources say the company “DTsOA” has been tasked with supplying the new hardware to Internet Service Providers throughout the Ural Federal District by the end of the year. DTsOA’s former CEO is reportedly Rashid Ismailov, Nokia’s former head of Russian operations and Russia’s former deputy communications minister.

According to RBC, the new hardware is already active in Yekaterinburg, and it’s currently expanding to Chelyabinsk, Tyumen, and other cities in the region. The equipment is being supplied primarily to ISPs providing home Internet access, and the new DPI filtration apparently isn’t around the clock. All providers reportedly have access to a kill switch, in the event that the new hardware somehow malfunctions. https://www.rbc.ru/technology_and_media/26/09/2019/5d8b4c1c9a7947d3c58f9a48

☣️ Roskomnadzor will reportedly monitor how severely the new filtration systems degrade Internet speeds, and verify that the equipment blocks everything the authorities have blacklisted, and nothing else.

☣️ The pilot project is part of the government’s implementation of a controversial “RuNet isolation” initiative that takes effect on November 1, 2019, wherein the state will ensure that Russia’s domestic Internet network continues to function, even if it is disconnected from the outside world.

https://meduza.io/en/news/2019/09/27/russia-starts-rolling-out-dpi-filtration-tech-that-might-finally-block-telegram

#russia #blocking #telegram #dpi #filtration
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_ES
📡@FLOSSb0xIN
Read the full transcript of Mark Zuckerberg’s leaked internal Facebook meetings

Highlights from two hours of leaked audio from recent Q&A sessions with Facebook’s CEO

On October 1st, The Verge published text and audio from recent internal meetings at Facebook where CEO Mark Zuckerberg answered tough questions from employees who are concerned about the company’s future. In two July meetings, Zuckerberg rallied his employees against critics, competitors, and Sen. Elizabeth Warren, among others.

To provide more context around Zuckerberg’s remarks, The Verge is publishing expanded transcripts from the two meetings below. In them, Zuckerberg discussed his plan to beat TikTok, why he wants to keep absolute control of the company, and what employees should tell friends who have a dim view of Facebook. Each question below was asked by a different Facebook employee.

👉🏼 Listen to clips from the meeting:
https://www.theverge.com/2019/10/1/20756701/mark-zuckerberg-facebook-leak-audio-ftc-antitrust-elizabeth-warren-tiktok-comments

👉🏼 Read more:
https://www.theverge.com/2019/10/1/20892354/mark-zuckerberg-full-transcript-leaked-facebook-meetings

#DeleteFacebook #transcript #leak #meetings
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_ES
📡@FLOSSb0xIN
Media is too big
VIEW IN TELEGRAM
18-year-old shot by Hong Kong police in stable condition as students stage protest

A student who was shot by police with a live round at close range on Tuesday has stabilised following an operation, according to the Hospital Authority.

Tsang Chi-kin, an 18-year-old form 5 student, was shot in Tsuen Wan after a scuffle with an officer.

The officer rushed towards a group of protesters attacking another officer whilst pointing a pistol, but was also surrounded. Tsang used a metal rod to hit the surrounded officer, before he fired the shot.

https://www.hongkongfp.com/2019/10/02/18-year-old-shot-hong-kong-police-stable-condition-students-stage-protest/

#FreeHongKong #shooting #video #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_ES
📡@FLOSSb0xIN
RIAA Reports Telegram to US Govt. Over Piracy Concerns

The RIAA has submitted its most recent overview of "notorious markets" to the U.S. Government. As usual, the music industry group lists various torrent sites, download portals and stream-ripping sites as direct threats. This year, however, the messaging app Telegram is also highlighted as a problem.

Responding to a request from the Office of the US Trade Representative (USTR), the RIAA has submitted its annual list of “notorious markets.”

The submission identifies online and offline piracy hubs to help guide the U.S. Government’s position towards foreign countries when it comes to copyright enforcement.

“The online and physical markets identified in our comments are harming American creators, businesses, and the American economy,” writes George York, the RIAA’s Senior Vice President of International Policy.

Traditionally the online focus lies on classic pirate sites, such as torrent indexers, linking sites, cyberlockers, download portals, and stream-rippers. These are also listed in the latest RIAA submission. It includes many of the usual suspects, such as The Pirate Bay, Flvto, Newalbumreleases, and Uploaded.

While these mentions were expected, there’s also a new ‘issue’ highlighted by the music group – the encrypted messaging app Telegram. The software, which was launched by VKontakte founders Nikolai and Pavel Durov a few years ago, is frequently used by pirates, the RIAA notes.

The RIAA points out that messaging apps by themselves are of no special concern. However, Telegram also allows its users to share files of up to 1.5GB, a process that can be automated with scripts. This is a feature that many pirates have embraced.

“Telegram offers many user-created channels which are dedicated to the unauthorized distribution of copyrighted recordings, with some channels focused on particular genres or artists,” the RIAA notes.

Many of these files are hosted on Telegram’s servers and the RIAA says that it sent 18,000 DMCA notices to Telegram, identifying over 18,000 instances of copyright infringement.

The messaging app says that it forwards these requests to channel owners. However, according to the music group, this doesn’t have the desired effect, as many channel operators ignore the takedown requests. In addition, repeat infringers don’t appear to be punished in any way.

👉🏼 Read more:
https://torrentfreak.com/riaa-reports-telegram-to-us-govt-over-piracy-concerns-191002/

#riaa #telegram #tg #usa #govt #piracy
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_ES
📡@FLOSSb0xIN
DMCA Notice Confirms Trump Tweet Was Taken Down By Warner Music

Earlier today Twitter exploded when a tweet by US President Donald Trump was taken down for alleged copyright infringement. A copy of the DMCA notice obtained by TorrentFreak shows that Warner Music was behind the takedown. It became the seventh copyright complaint filed against Trump's Twitter account in 2019 alone, raising questions about Twitter's repeat infringer policy.

President of the United States Donald Trump is well-known for his love of Twitter.

He currently has well in excess of 65 million followers and regularly uses the platform to promote himself and attack his critics.

Earlier today, Twitter erupted when a tweet by the President, which contained a video attacking the integrity of political rival Joe Biden, received some serious editing thanks to Twitter.

While the words “LOOK AT THIS PHOTOGRAPH!” remained, the actual video had been removed following a copyright infringement complaint.

Trump’s tweet contained a video that has been doing the rounds featuring a photograph central to the recent Biden/Ukraine controversy. However, the photograph itself wasn’t the reason the video was taken down by Twitter.

The viral video contains a clip from Nickelback’s 2005 video ‘Photograph’, prompting speculation that the band itself was behind the takedown sent to Twitter. While they may have had a hand in it, the actual DMCA served on Twitter and obtained by TorrentFreak reveals that the notice was sent by Warner Music.

👉🏼 Read more:
https://torrentfreak.com/dmca-notice-confirms-trump-tweet-was-taken-down-by-warner-music/

#dmca #trump #twitter #WarnerMusic #CopyrightInfringement
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_ES
📡@FLOSSb0xIN
Vulnerabilities exploited in VPN products used worldwide

APTs are exploiting vulnerabilities in several VPN products used worldwide

💡 Introduction

The NCSC is investigating the exploitation, by Advanced Persistent Threat (APT) actors, of known vulnerabilities affecting Virtual Private Network (VPN) products from vendors Pulse secure, Palo Alto and Fortinet.

This activity is ongoing, targeting both UK and international organisations. Affected sectors include government, military, academic, business and healthcare. These vulnerabilities are well documented in open source.

Details💡

Vulnerabilities exist in several SSL VPN products which allow an attacker to retrieve arbitrary files, including those containing authentication credentials.

An attacker can use these stolen credentials to connect to the VPN and change configuration settings, or connect to further internal infrastructure.

Unauthorised connection to a VPN could also provide the attacker with the privileges needed to run secondary exploits aimed at accessing a root shell.

💡 Top vulnerabilities

The highest-impact vulnerabilities known to be exploited by APTs are listed below, although this is not an exhaustive list of CVEs associated with these products.

Sample exploit code for these vulnerabilities is publicly available online. The NCSC cautions against testing infrastructure with untrusted third-party code.

👉🏼 Read more:
https://www.ncsc.gov.uk/news/alert-vpn-vulnerabilities

#uk #govt #alert #vpn #exploiting #vulnerabilities
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_ES
📡@FLOSSb0xIN
Media is too big
VIEW IN TELEGRAM
France Set to Roll Out Nationwide Facial Recognition ID Program

Digital identity enrollment app to be rolled out in November
Privacy, absence of consent and security among concerns raised

France is poised to become the first European country to use facial recognition technology to give citizens a secure digital identity -- whether they want it or not.

👉🏼 Read more:
https://www.bloomberg.com/news/articles/2019-10-03/french-liberte-tested-by-nationwide-facial-recognition-id-plan

#france #id #FacialRecognition #nationwide #thinkabout #why #video
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_ES
📡@FLOSSb0xIN
The Eye on the Nile

Phishing attack on government opponents in Egypt - with apps from the Play Store

Specialists reveal a sophisticated phishing attack in Egypt. Android apps that made it into the Play Store without catching the eye were involved.

Back in March 2019, Amnesty International published a report that uncovered a targeted attack against journalists and human rights activists in Egypt. The victims even received an e-mail from Google warning them that government-backed attackers attempted to steal their passwords. https://www.amnesty.org/en/latest/research/2019/03/phishing-attacks-using-third-party-applications-against-egyptian-civil-society-organizations/

According to the report, the attackers did not rely on traditional phishing methods or credential-stealing payloads, but rather utilized a stealthier and more efficient way of accessing the victims’ inboxes: a technique known as “OAuth Phishing”. By abusing third-party applications for popular mailing services such as Gmail or Outlook, the attackers manipulated victims into granting them full access to their e-mails.

Recently, we were able to find previously unknown or undisclosed malicious artifacts belonging to this operation. A new website we attributed to this malicious activity revealed that the attackers are going after their prey in more than one way, and might even be hiding in plain sight: developing mobile applications to monitor their targets, and hosting them on Google’s official Play Store.

After we notified Google about the involved applications, they quickly took them off of the Play Store and banned the associated developer.

👉🏼 Read more:
https://research.checkpoint.com/the-eye-on-the-nile/

#Egypt #pishing #attacks #research #android #apps #playstore
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_ES
📡@FLOSSb0xIN
Legal firm claims Fortnite made to be "as addictive as possible"

A Montreal legal firm is pursuing legal action on behalf of parents, comparing the game to tobacco and cocaine.

Many parents know the problems with overlong sessions of their children, in Canada now two minors want to sue against manufacturer Epic Games. The development studio has specifically produced Fortnite in such a way that it is the most addictive game, her lawyers say.

A 10-year-old and a 15-year-old applied to a court in Montréal for a class-action lawsuit against Epic Games. Their lawyers' accusation: The US development studio Epic Games deliberately programmed Fortnite Battle Royale "to be the most addictive game", the newspaper La Presse quotes. Epic had worked with psychologists and tried to avoid any "loss of attention" in experiments with test persons.

👉🏼 Read more:
https://www.gamereactor.eu/legal-firm-claims-fortnite-made-to-be-as-addictive-as-possible/

👉🏼 Read more:
https://www.lapresse.ca/actualites/justice-et-faits-divers/201910/03/01-5243992-demande-daction-collective-fortnite-comme-la-cigarette-.php

#fortnite #addictive #EpicGames #lawsuit #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_ES
📡@FLOSSb0xIN
3G Internet and Confidence in Government

How does the internet affect government approval? Using surveys of 840,537 individuals from 2,232 subnational regions in 116 countries in 2008-2017 from the Gallup World Poll and the global expansion of 3G networks, we show that an increase in internet access reduces government approval and increases the perception of corruption in government. This effect is present only when the internet is not censored and is stronger when traditional media is censored. Actual incidents of corruption translate into higher corruption perception only in places covered by 3G. In Europe, the expansion of mobile internet increased vote shares of anti-establishment populist parties.

👉🏼 PDF:
https://papers.ssrn.com/sol3/Delivery.cfm/SSRN_ID3456747_code3025720.pdf?abstractid=3456747&mirid=1

https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3456747

#internet #government #study #pdf
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_ES
📡@FLOSSb0xIN
Media is too big
VIEW IN TELEGRAM
Leaked drone footage purports to show Xinjiang prisoners blindfolded and tied up

Drone footage anonymously posted to YouTube appears to show hundreds of male prisoners in Xinjiang, western China, tied up and wearing blindfolds.

China has installed a 21st century police state in the region, where the US has accused Beijing of housing more than a million Uighur Muslims in "concentration camps."

https://www.businessinsider.de/china-xinjiang-prisoners-blindfolded-tied-up-leaked-drone-footage-2019-10

#china #xinjiang #prisioners #drone #footage #why #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_ES
📡@FLOSSb0xIN
FBI misused surveillance data, spied on its own, FISA ruling finds

Contractor looked up relatives; data was used to vet agents, sources in US.

In an October 2018 ruling unsealed and posted on October 8, 2019 by the Office of the Director of Intelligence, the United States Foreign Intelligence Surveillance Court (FISC) found that the employees of the Federal Bureau of Investigation had inappropriately used data collected under Section 702 of the Foreign Intelligence Surveillance Act (FISA). The FBI was found to have misused surveillance data to look into American residents, including other FBI employees and their family members, making large-scale queries that did not distinguish between US persons and foreign intelligence targets.

The revelation drew immediate outcry from privacy advocates and renewed calls for the termination of FISA and USA FREEDOM Act that authorized bulk intelligence collection. President Donald Trump signed a bill extending Section 702 collection authorizations for six years in 2018; the Office of the Director of National Intelligence announced earlier this year that the administration would seek the extension of authority for collection of call data granted under the USA FREEDOM Act.

In a statement emailed to Ars Technica, ACLU Senior Legislative Counsel Neema Singh Guliani, said:

"The government should not be able to spy on our calls and emails without a warrant. Any surveillance legislation considered by Congress this year must include reforms that address the disturbing abuses detailed in these opinions. Congress and the courts now have even more reason to prohibit warrantless searches of our information, and to permanently close the door on any collection of information that is not to or from a surveillance target."

https://icontherecord.tumblr.com/post/188217887058/release-of-documents-related-to-the-2018-fisa

👉🏼 Read more:
https://arstechnica.com/tech-policy/2019/10/unsealed-fisa-ruling-slaps-fbi-for-misuse-of-surveillance-data/

#USA #FISA #FBI #spy #surveillance #misuse #data #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_ES
📡@FLOSSb0xIN
This is how you kick facial recognition out of your town

Bans on the technology have mostly focused on law enforcement, but there’s a growing movement to get it out of school, parks, and private businesses too.

In San Francisco, a cop can’t use facial recognition technology on a person arrested. But a landlord can use it on a tenant, and a school district can use it on students.

This is where we find ourselves, smack in the middle of an era when cameras on the corner can automatically recognize passersby, whether they like it or not. The question of who should be able to use this technology, and who shouldn’t, remains largely unanswered in the US. So far, American backlash against facial recognition has been directed mainly at law enforcement. San Francisco and Oakland, as well as Somerville, Massachusetts, have all banned police from using the technology in the past year because the algorithms aren’t accurate for people of color and women. Presidential candidate Bernie Sanders has even called for a moratorium on police use.

Private companies and property owners have had no such restrictions, and facial recognition is increasingly cropping up in apartment buildings, hotels, and more. Privacy advocates worry that constant surveillance will lead to discrimination and have a chilling effect on free speech—and the American public isn’t very comfortable with it either. According to a recent survey by Pew Research, people in the US actually feel better about cops using facial recognition than they do about private businesses.

👉🏼 Read more:
https://www.technologyreview.com/s/614477/facial-recognition-law-enforcement-surveillance-private-industry-regulation-ban-backlash/

#surveillance #facialrecognition #lawenforcement #regulation #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_ES
📡@FLOSSb0xIN
Revealed: Google made large contributions to climate change deniers

Firm’s public calls for climate action contrast with backing for conservative thinktanks

Google has made “substantial” contributions to some of the most notorious climate deniers in Washington despite its insistence that it supports political action on the climate crisis.

Among hundreds of groups the company has listed on its website as beneficiaries of its political giving are more than a dozen organisations that have campaigned against climate legislation, questioned the need for action, or actively sought to roll back Obama-era environmental protections.

The list includes the Competitive Enterprise Institute (CEI), a conservative policy group that was instrumental in convincing the Trump administration to abandon the Paris agreement and has criticised the White House for not dismantling more environmental rules.

Google said it was disappointed by the US decision to abandon the global climate deal, but has continued to support CEI.

Google is also listed as a sponsor for an upcoming annual meeting of the State Policy Network (SPN), an umbrella organisation that supports conservative groups including the Heartland Institute, a radical anti-science group that has chided the teenage activist Greta Thunberg for “climate delusion hysterics”.

SPN members recently created a “climate pledge” website that falsely states “our natural environment is getting better” and “there is no climate crisis”.

👉🏼 The obscure law that explains why Google backs climate deniers
https://www.theguardian.com/environment/2019/oct/11/obscure-law-google-climate-deniers-section-230

👉🏼 Read more:
https://www.theguardian.com/environment/2019/oct/11/google-contributions-climate-change-deniers

#DeleteGoogle #contributions #climate #deniers #thinktanks #thinkabout #why
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_ES
📡@FLOSSb0xIN
Escort forums in Italy and the Netherlands hacked, user data put up for sale

A third forum for zoophilia and bestiality fans was also hacked. User data put up for sale as well.

A Bulgarian hacker has breached two online forums dedicated to sex workers, stolen user information, which he's now selling on a hacking forum.

The two forums are EscortForumIt.xxx and Hookers.nl -- serving sex workers and customers in Italy and the Netherlands, where prostitution is legal.

Both forums have confirmed the breaches this week.

vBulletin zero-day strikes again

Both were running outdated versions of the vBulletin forum software. The hacker told ZDNet this week in an email that he used a vBulletin zero-day (CVE-2019-16759) disclosed at the end of September to breach the two sites.

The hacker is now selling the data on a publicly-available hacking forum. Stolen data includes usernames, email addresses, and password hashes -- obtained from both forums, with 33k records from the Italian one, and 300k from the Dutch one.

👉🏼 Read more:
https://www.zdnet.com/article/escort-forums-in-italy-and-the-netherlands-hacked-user-data-put-up-for-sale/

#hacker #breach #escort #forum #italy #netherlands #data #leak #vBulletin
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_ES
📡@FLOSSb0xIN
How Photos of Your Kids Are Powering Surveillance Technology

Millions of Flickr images were sucked into a database called MegaFace. Now some of those faces may have the ability to sue.

The pictures of Chloe and Jasper Papa as kids are typically goofy fare: grinning with their parents; sticking their tongues out; costumed for Halloween. Their mother, Dominique Allman Papa, uploaded them to Flickr after joining the photo-sharing site in 2005.

None of them could have foreseen that 14 years later, those images would reside in an unprecedentedly huge facial-recognition database called MegaFace. Containing the likenesses of nearly 700,000 individuals, it has been downloaded by dozens of companies to train a new generation of face-identification algorithms, used to track protesters, surveil terrorists, spot problem gamblers and spy on the public at large. The average age of the people in the database, its creators have said, is 16.

“It’s gross and uncomfortable,” said Mx. Papa, who is now 19 and attending college in Oregon. “I wish they would have asked me first if I wanted to be part of it. I think artificial intelligence is cool and I want it to be smarter, but generally you ask people to participate in research. I learned that in high school biology.”

👉🏼 Read more:
https://www.nytimes.com/interactive/2019/10/11/technology/flickr-facial-recognition.html

#flickr #facial #recognition #surveillance #MegaFace #kids #why #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_ES
📡@FLOSSb0xIN
Social Credit Scoring In China Extends To Foreign Businesses, Creates New Risks

China's Sesame Credit system of scoring Chinese citizens on a code of personal conduct moves up a notch as foreign corporations begin to fall under a similar system.

Beginning next year, compliance will be enforced by China's Ministry of Public Security over access to corporate data housed on Chinese servers.

Foreign companies are being advised to reevaluate their data collection processes in light of this new action. The effect could be a further decoupling of US-China tech and trade activities.

"Foreign companies will have to decide whether it is worth the risk to sell or manufacture in China. This new lead could lead to diversification of supply chains or decoupling," said David Jacobson, who teaches global business strategy at the SMU Cox School of Business and is a visiting professor at Tsinghua University in Beijing.

The new cybersecurity laws give the Chinese government access to files, contracts, copyrights, business strategies and phone records with no permission asked, according to Jacobson. The rules first went into effect in 2018 but compliance was not enforced.

But starting in 2020, China is demanding that businesses collect and feed internal information into a centralized data system. The data will be used to quantify the moral codes of corporations, and the individuals that run them, and reward or punish accordingly.

Corporations will be judged on compliance, bill payments, party support by both management and employees, according to Jacobson. He noted that the representation of Communist Party in Chinese company meetings or as board of director supervisors is becoming "much more pervasive."

👉🏼 Read more:
https://www.forbes.com/sites/rebeccafannin/2019/10/08/social-credit-scoring-in-china-extends-to-foreign-businesses-creates-new-risks

#SocialCredit #scoring #china #risks
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_ES
📡@FLOSSb0xIN
Breaking: Visa, Mastercard, eBay, Stripe All Leave Libra

Wow. Within the span of an hour or two, reports have revealed that Facebook’s crypto project, Libra, suffered some heavy blows.

It first started on Friday morning, with the Financial Times revealing that both eBay, the e-commerce/online marketplace giant, and Stripe, a fintech giant, have dropped out of the Libra Association.

Speaking to the outlet, an eBay spokesperson asserted that while the company “respects the vision of Libra”, the American firm will not be moving ahead with its participation in the Association, citing a focus on ” rolling out eBay’s managed payments experience for our customers.”

Stripe made a similar comment, telling the FT that it is “supportive of projects that aim to make online commerce more accessible for people”, but will not be moving forward with the Facebook-backed crypto project at this time.

Within the hour or two after the FT’s revelatory report, both Mastercard and Visa — seen by many in the crypto community to be the Association’s two most important partners — also revealed that they will be rescending their membership. In their own comment, Visa cited Libra’s inability to “fully satisfy all requisite regulatory expectations.”

FIVE household names have pulled out of $LIBRA (Visa, Paypal, Stripe, Ebay, and Mastercard). I doubt they'll be the last.

Regulators are stonewalling it.

Zuck is testifying before Congress Oct. 23rd.

Now you can long/short its chance of even launching: https://www.bloomberg.com/news/articles/2019-10-07/facebook-skeptics-now-have-derivatives-to-bet-on-libra-delays

— The Crypto Dog📈 (@TheCryptoDog) October 11, 2019

👉🏼 Read more:
https://www.newsbtc.com/2019/10/11/breaking-visa-mastercard-ebay-stripe-all-leave-libra/

#DeleteFacebook #DeleteLibra #Visa #Mastercard #eBay #Stripe
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_ES
📡@FLOSSb0xIN