BlackBox (Security) Archiv
4.1K subscribers
183 photos
393 videos
167 files
2.67K links
πŸ‘‰πŸΌ Latest viruses and malware threats
πŸ‘‰πŸΌ Latest patches, tips and tricks
πŸ‘‰πŸΌ Threats to security/privacy/democracy on the Internet

πŸ‘‰πŸΌ Find us on Matrix: https://matrix.to/#/!wNywwUkYshTVAFCAzw:matrix.org
Download Telegram
InviZible Pro - Android application for Internet privacy and security

Protect your device from dangerous sites, get rid of annoying ads, get access to blocked resources in your country

InviZible Pro includes a well-known modules DNSCrypt, Tor , Purple I2P. They are used to achieve maximum security, privacy and comfortable use of the Internet. This application is designed for Android devices with Root access .

Just press a three buttons in InviZible Pro , and you turn from a simple user to an invisible one, which is very difficult to find, block, impose on you unnecessary products and services in the form of ubiquitous advertising.

πŸ‘‰πŸΌ Read more:
https://github.com/Gedsh/InviZible

#android #app #InviZible #DNSCrypt #Tor #Purple #I2P #security #privacy #GitHub
πŸ“‘@cRyPtHoN_INFOSEC_DE
πŸ“‘@cRyPtHoN_INFOSEC_EN
πŸ“‘@cRyPtHoN_INFOSEC_ES
πŸ“‘@FLOSSb0xIN
Media is too big
VIEW IN TELEGRAM
Mind-reading technology is everyone's next big security nightmare

While the hardware can be made as secure as possible, turning our thoughts into a digital form will put them at risk just like any other data.

Technology allowing our thoughts and feelings to be translated into a digital form – and shared – is already a reality. Brain computer interfaces (BCI) allow us to connect our minds to computers for some limited purposes, and big tech companies including Facebook and many startups want to make this technology commonplace.

πŸ‘‰πŸΌ Read more:
https://www.zdnet.com/article/is-mind-reading-tech-your-next-big-security-nightmare-yes-but-not-in-the-way-you-might-expect/

#MindReading #BCI #technology #security #risk #nightmare
πŸ“‘@cRyPtHoN_INFOSEC_DE
πŸ“‘@cRyPtHoN_INFOSEC_EN
πŸ“‘@cRyPtHoN_INFOSEC_ES
πŸ“‘@FLOSSb0xIN
A_74_48037_AdvanceUneditedVersion.docx
77.4 KB
World stumbling zombie-like into a digital welfare dystopia, warns UN human rights expert

NEW YORK (17 October 2019) – A UN human rights expert has expressed concerns about the emergence of the "digital welfare state", saying that all too often the real motives behind such programs are to slash welfare spending, set up intrusive government surveillance systems and generate profits for private corporate interests.

"As humankind moves, perhaps inexorably, towards the digital welfare future it needs to alter course significantly and rapidly to avoid stumbling zombie-like into a digital welfare dystopia,".

πŸ‘‰πŸΌ PDF:
https://www.ohchr.org/Documents/Issues/Poverty/A_74_48037_AdvanceUneditedVersion.docx

πŸ‘‰πŸΌ Read more:
https://www.ohchr.org/EN/NewsEvents/Pages/DisplayNews.aspx?NewsID=25156&LangID=E

#pdf #report #dystopia #digital #welfare #humanrights
πŸ“‘@cRyPtHoN_INFOSEC_DE
πŸ“‘@cRyPtHoN_INFOSEC_EN
πŸ“‘@cRyPtHoN_INFOSEC_ES
πŸ“‘@FLOSSb0xIN
The Global Expansion of AI Surveillance

A growing number of states are deploying advanced AI surveillance tools to monitor, track, and surveil citizens. Carnegie’s new index explores how different countries are going about this.

Artificial intelligence (AI) technology is rapidly proliferating around the world. Startling developments keep emerging, from the onset of deepfake videos that blur the line between truth and falsehood, to advanced algorithms that can beat the best players in the world in multiplayer poker. Businesses harness AI capabilities to improve analytic processing; city officials tap AI to monitor traffic congestion and oversee smart energy metering. Yet a growing number of states are deploying advanced AI surveillance tools to monitor, track, and surveil citizens to accomplish a range of policy objectivesβ€”some lawful, others that violate human rights, and many of which fall into a murky middle ground.

πŸ‘‰πŸΌ Read more:
https://carnegieendowment.org/2019/09/17/global-expansion-of-ai-surveillance-pub-79847

πŸ‘‰πŸΌ PDF:
https://carnegieendowment.org/files/AI_Global_Surveillance_Index1.pdf

#global #surveillance #ai #index #pdf #thinkabout
πŸ“‘@cRyPtHoN_INFOSEC_DE
πŸ“‘@cRyPtHoN_INFOSEC_EN
πŸ“‘@cRyPtHoN_INFOSEC_ES
πŸ“‘@FLOSSb0xIN
Samsung: Anyone's thumbprint can unlock Galaxy S10 phone

A flaw that means any fingerprint can unlock a Galaxy S10 phone has been acknowledged by Samsung.

It promised a software patch that would fix the problem.

The issue was spotted by a British woman whose husband was able to unlock her phone with his thumbprint when it was stored in a cheap case.

When the S10 was launched, in March, Samsung described the fingerprint authentication system as "revolutionary".

Air gap

The scanner sends ultrasounds to detect 3D ridges of fingerprints in order to recognise users.

Samsung said it was "aware of the case of S10's malfunctioning fingerprint recognition and will soon issue a software patch".

South Korea's online-only KaKao Bank told customers to switch off the fingerprint-recognition option to log in to its services until the issue was fixed.

Previous reports suggested some screen protectors were incompatible with Samsung's reader because they left a small air gap that interfered with the scanning.

Thumb print

The British couple who discovered the security issue told the Sun newspaper it was a "real concern".

After buying a Β£2.70 gel screen protector on eBay, Lisa Neilson registered her right thumbprint and then found her left thumbprint, which was not registered, could also unlock the phone.

She then asked her husband to try and both his thumbs also unlocked it.

And when the screen protector was added to another relative's phone, the same thing happened.

https://www.bbc.com/news/technology-50080586

#phone #bug #samsung #thumbprint #unlock #galaxy #S10
πŸ“‘@cRyPtHoN_INFOSEC_DE
πŸ“‘@cRyPtHoN_INFOSEC_EN
πŸ“‘@cRyPtHoN_INFOSEC_ES
πŸ“‘@FLOSSb0xIN
Media is too big
VIEW IN TELEGRAM
Dopamine - Tinder

Are you spending hours of your day swiping left and right on Tinder? It’s normal as the app was created to be addictive by activating dopamine in your brain with every swipe drawing you in further.

πŸ“Ί #Dopamine - #Tinder #video #thinkabout

πŸ“‘@cRyPtHoN_INFOSEC_DE
πŸ“‘@cRyPtHoN_INFOSEC_EN
πŸ“‘@cRyPtHoN_INFOSEC_ES
πŸ“‘@FLOSSb0xIN
Media is too big
VIEW IN TELEGRAM
Dopamine - Facebook

Facebook is addictive. Taking advantage of our basic human instinct to socialise, the social network harvests unimaginably large amounts of personal data while never quite fulfilling our thirst for social validation.

πŸ“Ί #Dopamine - #Facebook #DeleteFacebook #video #thinkabout

πŸ“‘@cRyPtHoN_INFOSEC_DE
πŸ“‘@cRyPtHoN_INFOSEC_EN
πŸ“‘@cRyPtHoN_INFOSEC_ES
πŸ“‘@FLOSSb0xIN
Media is too big
VIEW IN TELEGRAM
Dopamine - Candy Crush

Are you wasting hours on Candy Crush when you really should be working? Appealing to our inner sense of order, the video game that millions play on their smartphones is built to draw you in with some clever sales techniques.

πŸ“Ί #Dopamine - #CandyCrush #video #thinkabout

πŸ“‘@cRyPtHoN_INFOSEC_DE
πŸ“‘@cRyPtHoN_INFOSEC_EN
πŸ“‘@cRyPtHoN_INFOSEC_ES
πŸ“‘@FLOSSb0xIN
Media is too big
VIEW IN TELEGRAM
Dopamine - Instagram

Is Instagram irresistible for you? The app was made that way to appeal to your basic need for social validation.

πŸ“Ί #Dopamine - #Instagram #video #thinkabout

πŸ“‘@cRyPtHoN_INFOSEC_DE
πŸ“‘@cRyPtHoN_INFOSEC_EN
πŸ“‘@cRyPtHoN_INFOSEC_ES
πŸ“‘@FLOSSb0xIN
Media is too big
VIEW IN TELEGRAM
Dopamine - YouTube

With sophisticated algorithms using deep learning, Youtube offers users irresistible video recommendations that become ever more sensationalist or even conspiratorial.

πŸ“Ί #Dopamine - #YouTube #video #thinkabout

πŸ“‘@cRyPtHoN_INFOSEC_DE
πŸ“‘@cRyPtHoN_INFOSEC_EN
πŸ“‘@cRyPtHoN_INFOSEC_ES
πŸ“‘@FLOSSb0xIN
Media is too big
VIEW IN TELEGRAM
Dopamine - Snapchat

Snapchat is so much fun you can’t stop yourself from getting addicted. Using the universal concept of giving and receiving gifts to keep us interacting, the messaging app gnaws its way into our lives.

πŸ“Ί #Dopamine - #Snapchat #video #thinkabout

πŸ“‘@cRyPtHoN_INFOSEC_DE
πŸ“‘@cRyPtHoN_INFOSEC_EN
πŸ“‘@cRyPtHoN_INFOSEC_ES
πŸ“‘@FLOSSb0xIN
Media is too big
VIEW IN TELEGRAM
Dopamine - Uber

You’ve made a decision to become an Uber driver hoping to make some money and be your own boss. But with Uber's clever use of nudge theory, the reality isn’t quite what you hoped for.

πŸ“Ί #Dopamine - #Uber #video #thinkabout

πŸ“‘@cRyPtHoN_INFOSEC_DE
πŸ“‘@cRyPtHoN_INFOSEC_EN
πŸ“‘@cRyPtHoN_INFOSEC_ES
πŸ“‘@FLOSSb0xIN
Media is too big
VIEW IN TELEGRAM
Dopamine - Twitter

Do you constantly check twitter on your smartphone for the latest tweets? Preying on our fear of missing out (fomo), Twitter has harnessed our natural anxiety to make…. a lot of money.

πŸ“Ί #Dopamine - #Twitter #video #thinkabout

πŸ“‘@cRyPtHoN_INFOSEC_DE
πŸ“‘@cRyPtHoN_INFOSEC_EN
πŸ“‘@cRyPtHoN_INFOSEC_ES
πŸ“‘@FLOSSb0xIN
"Dopamine": Miniseries about the addiction mechanisms of Tinder, Facebook and Co.

"They'll do anything to make you an addict," they say about #Tinder, #Facebook, #CandyCrush, #Instagram, #YouTube, #Snapchat, #Uber and #Twitter in the miniseries of #Arte. Eight episodes explain in detail which mechanisms are triggered in our brain to keep us engaged

πŸ“Ί Dopamine - Tinder

πŸ“Ί Dopamine - Facebook

πŸ“Ί Dopamine - Candy Crush

πŸ“Ί Dopamine - Instagram

πŸ“Ί Dopamine - YouTube

πŸ“Ί Dopamine - Snapchat

πŸ“Ί Dopamine - Uber

πŸ“Ί Dopamine - Twitter

πŸ’‘ Actually, we have known this for a long time:
Candy Crush, Tinder, Facebook and others are above all one thing - time wasters. Nevertheless, it's extremely difficult for us to leave the #Smartphone on the shelf and not check out what's new every few minutes. Especially since what is then presented to us as news only rarely has news value or really gets us ahead. Nevertheless, we check out pages and pages of Aunt Monika's pictures from Paris, swear to complete "only one more level" at Candy Crush, let ourselves be carried away by the autoplay function into ever more abstruse depths of Youtube and simply can't get enough of cute cat photos on Instagram. What's wrong with us?

#Tinder #Facebook #CandyCrush #Instagram #YouTube #Snapchat #Uber #Twitter #Dopamine #video #thinkabout
πŸ“‘@cRyPtHoN_INFOSEC_DE
πŸ“‘@cRyPtHoN_INFOSEC_EN
πŸ“‘@cRyPtHoN_INFOSEC_ES
πŸ“‘@FLOSSb0xIN
APT41 compromised company behind TeamViewer - which enabled them to access *any* system with TeamViewer installed πŸ‘€πŸ‘€

https://nitter.net/cglyer/status/1182413194360508419

#APT41 #TeamViewer #hacked #breach #alert #warning
πŸ“‘@cRyPtHoN_INFOSEC_DE
πŸ“‘@cRyPtHoN_INFOSEC_EN
πŸ“‘@cRyPtHoN_INFOSEC_ES
πŸ“‘@FLOSSb0xIN
Google chief: I'd disclose smart speakers before guests enter my home

It's an admission that appears to have caught Google's devices chief by surprise.

After being challenged as to whether homeowners should tell guests smart devices - such as a Google Nest speaker or Amazon Echo display - are in use before they enter the building, he concludes that the answer is indeed yes.

"Gosh, I haven't thought about this before in quite this way," Rick Osterloh begins.

"It's quite important for all these technologies to think about all users... we have to consider all stakeholders that might be in proximity."

And then he commits.

"Does the owner of a home need to disclose to a guest? I would and do when someone enters into my home, and it's probably something that the products themselves should try to indicate."

To be fair to Google, it hasn't completely ignored matters of 21st Century privacy etiquette until now.

As Mr Osterloh points out, its Nest cameras shine an LED light when they are in record mode, which cannot be overridden.

But the idea of having to run around a home unplugging or at least restricting the capabilities of all its voice- and camera-equipped kit if a visitor objects is quite the ask.

πŸ‘‰πŸΌ Read more:
https://www.bbc.com/news/technology-50048144

#DeleteGoogle #smart #speakers #privacy
πŸ“‘@cRyPtHoN_INFOSEC_DE
πŸ“‘@cRyPtHoN_INFOSEC_EN
πŸ“‘@cRyPtHoN_INFOSEC_ES
πŸ“‘@FLOSSb0xIN
This media is not supported in your browser
VIEW IN TELEGRAM
Smart Spies: Alexa and Google Home expose users to vishing and eavesdropping

Smart Spies Hack 1:
Requesting the user’s password through a simple backend change
It is possible to ask for sensitive data such as the user’s password from any voice app. To create a password phishing Skill/Action, a hacker could follow the following steps:

πŸ“Ί https://srlabs.de/bites/smart-spies/

#SmartSpies #alexa #google #vishing #eavesdropping #PoC #video
πŸ“‘@cRyPtHoN_INFOSEC_DE
πŸ“‘@cRyPtHoN_INFOSEC_EN
πŸ“‘@cRyPtHoN_INFOSEC_ES
πŸ“‘@FLOSSb0xIN
This media is not supported in your browser
VIEW IN TELEGRAM
Smart Spies: Alexa and Google Home expose users to vishing and eavesdropping

Smart Spies Hack 2:
Faking the stop Intent allows eavesdropping on users
We were able to listen in on conversations after a user believes to have stopped our voice app. To accomplish this, we use a slightly different strategy for each of the voice speaker platforms.

πŸ“Ί https://srlabs.de/bites/smart-spies/

#SmartSpies #alexa #google #vishing #eavesdropping #PoC #video
πŸ“‘@cRyPtHoN_INFOSEC_DE
πŸ“‘@cRyPtHoN_INFOSEC_EN
πŸ“‘@cRyPtHoN_INFOSEC_ES
πŸ“‘@FLOSSb0xIN
NordVPN has been hacked

The VPN provider NordVPN apparently had an incident some time ago in which an attacker had access to the servers and private keys. Three private keys appeared on the network, one of which belonged to an expired HTTPS certificate.

Several cryptographic keys and information about NordVPN configuration files have appeared in a leak. One of the keys matches an older NordVPN website certificate. The vendor has not yet commented on the incident.

The leak appeared in an online discussion. In a now deleted tweet NordVPN wrote: "Nobody can steal your online life (if you use a VPN)". In response, someone sent a link to a text file containing evidence of a VPN provider hack.

https://share.dmca.gripe/hZYMaB8oF96FvArZ.txt

https://mobile.twitter.com/NordVPN/status/1185979592374398976

πŸ‘‰πŸΌ More info (german):
https://www.golem.de/news/leak-nordvpn-wurde-gehackt-1910-144528.html

#leak #NordVPN #hack #hacker #hacked
πŸ“‘@cRyPtHoN_INFOSEC_DE
πŸ“‘@cRyPtHoN_INFOSEC_EN
πŸ“‘@cRyPtHoN_INFOSEC_ES
πŸ“‘@FLOSSb0xIN
RapidVideo Shuts Down Following Legal Pressure from Warner Bros and Netflix

RapidVideo, a popular file-hosting service with millions of users, has thrown in the towel. The site faces legal pressure from lawyers representing the MPA and ACE, including a lawsuit from Warner Bros. and Netflix. Paired with dwindling revenues and a worsening legal climate, maintaining the site is no longer viable, according to the operator.

RapidVideo is a popular file-hosting service that specializes in hosting videos.
Similar to other file-hosting services, it can be used for good and bad. The bad, in this case, is people uploading pirated videos.

Whether the site’s operators want it or not, that’s what many of RapidVideo’s users are indeed doing. Two weeks ago this resulted in yet another scathing report from movie industry group MPA, which branded the site as a β€œnotorious” piracy haven.

Behind the scenes, the website’s operator faces mounting pressure as well. RapidVideo has been targeted by lawyers from the MPA and ACE, two of the most powerful anti-piracy forces, which are demanding far-reaching copyright enforcement measures from the site.

To back up their pressure, two MPA/ACE members, Warner Bros. Entertainment and Netflix, filed a lawsuit in Germany to stop the alleged copyright infringements the site enables. While this case remains ongoing, the site’s operator decided not to await the verdict and has shut the site down effective immediately.

The millions of users who regularly visit the site currently see nothing more than a 404 error.

πŸ‘‰πŸΌ Read more:
https://torrentfreak.com/rapidvideo-shuts-down-following-legal-pressure-from-warner-bros-and-netflix-191021/

#RapidVideo #legalpressure #WarnerBros #Netflix
πŸ“‘@cRyPtHoN_INFOSEC_DE
πŸ“‘@cRyPtHoN_INFOSEC_EN
πŸ“‘@cRyPtHoN_INFOSEC_ES
πŸ“‘@FLOSSb0xIN
BlackBox (Security) Archiv
NordVPN has been hacked The VPN provider NordVPN apparently had an incident some time ago in which an attacker had access to the servers and private keys. Three private keys appeared on the network, one of which belonged to an expired HTTPS certificate. …
Apparently other VPN providers were also compromised:

It’s also believed several other VPN providers may have been breached around the same time. Similar records posted online β€” and seen by TechCrunch β€” suggest that TorGuard and VikingVPN may have also been compromised, but spokespeople did not return a request for comment.

https://mobile.twitter.com/hexdefined/status/1186106695073726466

https://techcrunch.com/2019/10/21/nordvpn-confirms-it-was-hacked/

πŸ‘‰πŸΌ NordVPN has been hacked:
https://t.iss.one/BlackBox_Archiv/677

#leak #NordVPN #TorGuard #VikingVPN #hack #hacker #hacked
πŸ“‘@cRyPtHoN_INFOSEC_DE
πŸ“‘@cRyPtHoN_INFOSEC_EN
πŸ“‘@cRyPtHoN_INFOSEC_ES
πŸ“‘@FLOSSb0xIN