BlackBox (Security) Archiv – Telegram
BlackBox (Security) Archiv
4.12K subscribers
183 photos
393 videos
167 files
2.67K links
👉🏼 Latest viruses and malware threats
👉🏼 Latest patches, tips and tricks
👉🏼 Threats to security/privacy/democracy on the Internet

👉🏼 Find us on Matrix: https://matrix.to/#/!wNywwUkYshTVAFCAzw:matrix.org
Download Telegram
Media is too big
VIEW IN TELEGRAM
Why Amazon Unionization Failed in Alabama

In this Wolff Responds, Prof. Wolff explains why Amazon workers in Alabama voted against unionization, and compares the American labor movement to that of Europe. Wolff draws from European examples to underscore what is needed for unions in the US to gain momentum.

https://www.youtube.com/watch?v=lHGQhnYhwSg

#amazon #DeleteAmazon #DickPunchBezos #unionization #alabama #usa #video #thinkabout
📽@nogoolag 📽@blackbox_archiv
Google's short-lived data-advantage

There's a lot of ways to think about the movement to tame Big Tech, but one of the more useful divisions to explore is the "Night of the Comet" people versus the "Don't Believe the Criti-Hype" people.

This is a division over the value of the data that Google, Facebook and other large tech firms have amassed over the years – data on their users, sure, but also data on the advertisers and publishers they serve with their ad-tech platforms.

Big Tech companies and their investors are really bullish on the value of this commercial data-advantage: they say that spying on us – the users – lets them manipulate our opinions and activities so that we buy or believe the things their advertisers pay them to push.

More quietly, their investors believe that the data-advantage extends to publishers and advertisers, a deep storehouse of data that makes it effectively impossible for anyone else to do the precision targeted that Big Tech manages, which is why they have such fat margins.

https://pluralistic.net/2021/04/11/halflife/#minatory-legend

#google #DeleteGoogle #facebook #DeleteFacebook #BigData #BigTech #AdTech #thinkabout #comment
📡 @nogoolag 📡 @blackbox_archiv
Media is too big
VIEW IN TELEGRAM
IoT-less IP Cameras - Hack Across America 2021

IP cameras that aren't IoT trash? What to look for when researching LAN-only cameras and upgrading "the Peanut" van with 360 surveillance for Hack Across America 2021!

👉🏼 Follow along at:
https://hak5.org/hackacrossamerica

https://www.youtube.com/watch?v=dZyZS5PIdVM

#iot #hackacrossamerica #video
📽@cRyPtHoN_INFOSEC_FR
📽
@cRyPtHoN_INFOSEC_EN
📽
@cRyPtHoN_INFOSEC_DE
📽
@BlackBox_Archiv
📽
@NoGoolag
How Bellingcat Launders National Security State Talking Points into the Press

For a self-proclaimed citizen journalism outfit, an alarming number of Bellingcat’s staff and contributors come from highly suspect backgrounds, including high-level positions in military and intelligence agencies.

AMSTERDAM —
Investigative site Bellingcat is the toast of the popular press. In the past month alone, it has been described as “an intelligence agency for the people” (ABC Australia), a “transparent” and “innovative” (New Yorker) “independent news collective,” “transforming investigative journalism” (Big Think), and an unequivocal “force for good” (South China Morning Post). Indeed, outside of a few alternative news sites, it is very hard to hear a negative word against Bellingcat, such is the gushing praise for the outlet founded in 2014.

This is troubling, because the evidence compiled in this investigation suggests Bellingcat is far from independent and neutral, as it is funded by Western governments, staffed with former military and state intelligence officers, repeats official narratives against enemy states, and serves as a key part in what could be called a “spook to Bellingcat to corporate media propaganda pipeline,” presenting Western government narratives as independent research.

Citizen journalism staffed with spies and soldiers

An alarming number of Bellingcat’s staff and contributors come from highly suspect backgrounds. Senior Investigator Nick Waters, for example, spent three years as an officer in the British Army, including a tour in Afghanistan, where he furthered the British state’s objectives in the region. Shortly after leaving the service, he was hired by Bellingcat to provide supposedly bias-free investigations into the Middle East.

https://www.mintpressnews.com/bellingcat-intelligence-agencies-launders-talking-points-media/276603/

👉🏼 Bellingcat's Online Investigation Toolkit - version 6.6 (Feb.11, 2021)
https://news.1rj.ru/str/BlackBox_Archiv/1635

#bellingcat #toolkit #research #collection
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
Clubhouse “Leak” Might Be a Simple Data Scrape

The Clubhouse "data leak" has the hallmarks of a scraper bot downloading public information, appears to not be a hack.

A data leak of Clubhouse member information has been reported. The information consists of publicly available data and does not consist of sensitive information like passwords. The so-called leak may actually be just a scrape of publicly available information.

👉🏼 Data Leak
👉🏼 Report of Clubhouse “Data Leak”
👉🏼 Was Confidential Information Leaked?
👉🏼 Possibly Not a Data Leak
👉🏼 Why This May Not be a Data Leak of Clubhouse
👉🏼 Citations

https://www.searchenginejournal.com/clubhouse-data-leak/401943/

#clubhouse #data #scrape #leak #user #records
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
Linux, macOS, and Windows running simultaneously on a 1st generation Core i5 and 8GB RAM

This is my Thinkpad T410 with a 1st generation Intel Core i5 and 8 GB of RAM. It runs Arch Linux with Xfce.

The macOS Mojave (chosen over Catalina or Big Sur for it’s lower resource usage) VM works surprisingly well with 3GB RAM, but even when the Windows VM was allocated that much, it was very sluggish.

The Windows installation was very easy. All you have to do is download the ISO from Microsoft, and fill in your username, password, and product key in the “Express Installation” feature of Gnome Boxes.

https://lukesempire.com/2021/04/11/vms

#linux #macos #windows #installation
📡 @nogoolag 📡 @blackbox_archiv
😱1
Google gamed its ad auction system to favor its own ads, generated $213 million

Google used a secret program called "Bernanke" that used historical bidding data to give its ad-buying system a major advantage over its rivals, an antitrust lawsuit filing claims, a program that earned the company hundreds of millions of dollars in revenue.

Google is in the process of dealing with an antitrust lawsuit from a group of state attorneys general, about its advertising technology and ad industry dominance. In a response to the lawsuit filed by Google in early April, the search company accidentally let slip of some of its behind-the-scenes work.

In the initial version of the filing, seen by the Wall Street Journal, Google failed to properly redact some sections, revealing the secretive business elements. A federal judge allowed Google to refile the properly-redacted version under seal.

The unredacted elements refers to a program called "Project Bernanke," a system that Google allegedly kept secret from publishers and other rivals. Bernanke was also viewed as an antitrust issue by the states in the lawsuit, due to how it operated.

The antitrust lawsuit centers around how Google's ownership of a platform for selling online advertising, as well as its position as an ad buyer for its own properties, was a problem. By being both an owner and a client, Google was thought to be able to game the system due to having access to data that ad buyers wouldn't necessarily receive.

https://appleinsider.com/articles/21/04/11/google-bernanke-revealed-in-ad-business-antitrust-lawsuit-error

#google #DeleteGoogle #AdTech #AdBusiness #lawsuit #antitrust #bernanke
📡 @nogoolag 📡 @blackbox_archiv
The Hitchhiker’s Guide to Online Anonymity (new draft version v0.9.0 with a new Tor Mirror)

Here is a new version (v0.9.0) of The Hitchhiker’s Guide to Online Anonymity.

💡 TLDR:
This is an open-source non-profit detailed and maintained guide on online anonymity (in addition to Privacy/Security). I've been writing/updating it for the past months. It covers Windows/Linux/MacOS/Whonix/TAILS/Qubes OS and more. It's written with hope for activists, journalists, scientists, lawyers, whistle-blowers, and good people being oppressed/censored anywhere!

The whole guide is backed up by many external references (over 500 external references, many of them academic) and is not sponsored by any commercial entity.

The guide is presented in a "book format" (Online ,or PDF with Light and Dark themes) and is quite a long read with over 180 pages of information (not counting the many 500+ external references). But there are ways you can read some parts and not others depending on your interest (and this is also explained in the introduction).

* Project Website: https://anonymousplanet.org/
* Mirror: https://mirror.anonymousplanet.org/
* Tor Mirror: http://thgtoa7imksbg7rit4grgijl2ef6kc7b56bp56pmtta4g354lydlzkqd.onion

💡 Online Guide:

* Online Version (Dark Theme): https://anonymousplanet.org/guide.html
* Online Version Mirror (Dark Theme): https://mirror.anonymousplanet.org/guide.html
* Online Version Tor Mirror (Dark Theme): http://thgtoa7imksbg7rit4grgijl2ef6kc7b56bp56pmtta4g354lydlzkqd.onion/guide.html

💡 PDFs:

* PDF (Light Theme): https://anonymousplanet.org/guide.pdf
* PDF (Light Theme Mirror): https://mirror.anonymousplanet.org/guide.pdf
* PDF (Light Theme Tor Mirror): http://thgtoa7imksbg7rit4grgijl2ef6kc7b56bp56pmtta4g354lydlzkqd.onion/guide.pdf
* PDF (Dark Theme): https://anonymousplanet.org/guide-dark.pdf
* PDF (Dark Theme Mirror): https://mirror.anonymousplanet.org/guide-dark.pdf
* PDF (Dark Theme Tor Mirror): http://thgtoa7imksbg7rit4grgijl2ef6kc7b56bp56pmtta4g354lydlzkqd.onion/guide-dark.pdf

💡 Changelog:

* https://anonymousplanet.org/CHANGELOG.html
* https://mirror.anonymousplanet.org/CHANGELOG.html
* http://thgtoa7imksbg7rit4grgijl2ef6kc7b56bp56pmtta4g354lydlzkqd.onion/CHANGELOG.html

💡 Archives:

* Archive.org: https://web.archive.org/web/https://anonymousplanet.org/guide.html
* Archive.today: https://archive.fo/anonymousplanet.org/guide.html
* Archive.today over Tor: http://archivecaslytosk.onion/anonymousplanet.org/guide.html
* Cryptpad.fr: https://cryptpad.fr/drive/#/2/drive/view/Ughm9CjQJCwB8BIppdtvj5zy4PyE-8Gxn11x9zaqJLI/

Feel free to share and contribute through the repository at https://github.com/AnonymousPlanet/thgtoa

👉🏼 Follow me on:

* Twitter: https://twitter.com/AnonyPla
* Mastodon: https://mastodon.online/@anonypla

Any constructive opinion/idea/criticism is welcome if you spot any issue. Many changes have been done based based on suggestions from redditors. Don't be too harsh tho. Remember it's still a "work in progress" draft.

https://redd.it/mpc5k3

#guide #online #anonymity #anonymousplanet
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
BlackBox (Security) Archiv pinned «The Hitchhiker’s Guide to Online Anonymity (new draft version v0.9.0 with a new Tor Mirror) Here is a new version (v0.9.0) of The Hitchhiker’s Guide to Online Anonymity. 💡 TLDR: This is an open-source non-profit detailed and maintained guide on online anonymity…»
requests-2020-H1-en.pdf
802.6 KB
Apple Transparency Report: Government and Private Party Requests

Apple has released more iCloud content to authorities, end-to-end encryption is still missing.

User data was mainly sent to authorities in the U.S. and Brazil. In France, Sweden, Switzerland and the United Kingdom, Apple only transmitted iCloud data for one account request each, as the report lists. It remains unclear which of the partly sensitive data was transferred in detail and for what reason. In the new transparency report, Apple has confirmed for the first time that iCloud content may also be passed on in emergency requests from authorities - for example, to search for missing persons.

https://www.apple.com/legal/transparency/pdf/requests-2020-H1-en.pdf

#icloud #apple #requests #transparency #report #pdf
📡 @nogoolag 📡 @blackbox_archiv
Security as Social Engineering: Phishing Campaigns Spoofing Locked Account Workflows

Each Blox Tale will take a look at targeted email scams, outline why they made their way into an inbox, and provide tips and recommendations to protect against such attacks. In this blog, we’ll focus on three email attacks impersonating Facebook, Microsoft, and Apple respectively. All attacks aimed to extract victims’ account credentials by spoofing automated emails informing victims that their accounts had been locked or that they had a subnoscription that was close to expiry. Phishing pages were set up using services like Omnisend and DDNS[.]net to trick security technologies and users into thinking the links were legitimate.

👉🏼 Let’s go through the attacks in greater detail:

https://www.armorblox.com/blog/security-as-social-engineering-phishing-campaigns-spoofing-locked-account-workflows/

#security #phishing #email #scam #facebook #microsoft #apple
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
CEO of a top bitcoin exchange warns a crackdown on cryptocurrencies may be coming

Governments around the world may start to clamp down on the use of bitcoin and other cryptocurrencies, the CEO of a top crypto exchange has warned.

A number of officials — from U.S. Treasury Secretary Janet Yellen to European Central Bank President Christine Lagarde — have sounded the alarm about the use of bitcoin for money laundering, terrorist financing and other illegal activities.

"I think there could be some crackdown," Jesse Powell, CEO of Kraken, told CNBC in an interview. Cryptocurrencies have surged in value lately, with bitcoin hitting a record high price of more than $61,000 last month. The world's most valuable digital coin was last trading at around $60,105.

Kraken is the world's fourth-largest digital currency exchange in terms of trading volume. The firm is considering going public through a direct listing — similar to Coinbase — next year after achieving record trading volumes in the first quarter, CNBC reported last week.

https://www.cnbc.com/2021/04/12/bitcoin-kraken-ceo-jesse-powell-warns-of-cryptocurrency-crackdown.html

#bitcoin #cryptocurrency #crackdown
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
Revealed: the Facebook loophole that lets world leaders deceive and harass their citizens

Facebook has repeatedly allowed world leaders and politicians to use its platform to deceive the public or harass opponents despite being alerted to evidence of the wrongdoing.

The Guardian has seen extensive internal documentation showing how Facebook handled more than 30 cases across 25 countries of politically manipulative behavior that was proactively detected by company staff.

The investigation shows how Facebook has allowed major abuses of its platform in poor, small and non-western countries in order to prioritize addressing abuses that attract media attention or affect the US and other wealthy countries. The company acted quickly to address political manipulation affecting countries such as the US, Taiwan, South Korea and Poland, while moving slowly or not at all on cases in Afghanistan, Iraq, Mongolia, Mexico, and much of Latin America.

“There is a lot of harm being done on Facebook that is not being responded to because it is not considered enough of a PR risk to Facebook,” said Sophie Zhang, a former data scientist at Facebook who worked within the company’s “integrity” organization to combat inauthentic behavior. “The cost isn’t borne by Facebook. It’s borne by the broader world as a whole.”

https://www.theguardian.com/technology/2021/apr/12/facebook-loophole-state-backed-manipulation

#facebook #DeleteFacebook #loophole #manipulation #investigation #thinkabout
📡 @nogoolag 📡 @blackbox_archiv
Mozilla partners with NVIDIA to democratize and diversify voice technology

As technology makes massive shift to voice-enabled products, NVIDIA invests $1.5 million in Mozilla Common Voice to transform the voice recognition landscape.

Over the next decade, speech is expected to become the primary way people interact with devices — from laptops and phones to digital assistants and retail kiosks. Today’s voice-enabled devices, however, are inaccessible to much of humanity because they cannot understand vast swaths of the world’s languages, accents, and speech patterns.

To help ensure that people everywhere benefit from this massive technological shift, Mozilla is partnering with NVIDIA, which is investing $1.5 million in Mozilla Common Voice, an ambitious, open-source initiative aimed at democratizing and diversifying voice technology development.

Most of the voice data currently used to train machine learning algorithms is held by a handful of major companies. This poses challenges for others seeking to develop high-quality speech recognition technologies, while also exacerbating the voice recognition divide between English speakers and the rest of the world.

https://blog.mozilla.org/blog/2021/04/12/mozilla-partners-with-nvidia-to-democratize-and-diversify-voice-technology/

https://venturebeat.com/2021/04/12/mozilla-winds-down-deepspeech-development-announces-grant-program/

#mozilla #firefox #nvidia #voice #technology
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag
Another huge data breach, another stony silence from Facebook

The social media giant is still a law unto itself. Can anybody hold it to account?

Half a billion Facebook users’ accounts stolen. Personal information compromised. Telephone numbers and birth dates drifting across the internet being used for God knows what. And for four days, from Facebook’s corporate headquarters, nothing but silence.

If this sounds familiar, it’s because it is. This week saw reports of a massive new Facebook breach and everything about it, from Facebook’s denials of the words “data” and “breach” to its repeated refusal to answer journalists’ questions, has been uncannily reminiscent of the Cambridge Analytica scandal.

Three years on, “Cambridge Analytica” is a byword for mass-data abuse, Facebook has been fined billions of dollars for failing to protect users’ data and... not a thing has changed. If ever there were a moment to understand how profoundly all systems of accountability have failed, and continued to fail, it is this.

Last week Nick Clegg, vice president of global affairs at Facebook, admitted on The Verge website that the Cambridge Analytica scandal had “rocked Facebook right down to its foundations”. And yet it has learned nothing. It has paid no real price (the record $5 billion fine it paid to the Federal Trade Commission (FTC) is literally no price at all to Facebook), suffered no real consequences, and failed to answer any questions over the involvement of its executives.

https://www.theguardian.com/technology/2021/apr/11/another-huge-data-breach-another-stony-silence-from-facebook

#facebook #DeleteFacebook #data #breach #comment #thinkabout
📡 @nogoolag 📡 @blackbox_archiv
Richard Stallman is trying to apologize

In a personal statement, he blames controversial remarks on personal incompetence
.

Ever since my teenage years, I felt as if there were a filmy curtain separating me from other people my age. I understood the words of their conversations, but I could not grasp why they said what they did. Much later I realized that I didn't understand the subtle cues that other people were responding to.

Later in life, I discovered that some people had negative reactions to my behavior, which I did not even know about. Tending to be direct and honest with my thoughts, I sometimes made others uncomfortable or even offended them -- especially women. This was not a choice: I didn't understand the problem enough to know which choices there were.

Sometimes I lost my temper because I didn't have the social skills to avoid it. Some people could cope with this; others were hurt. I apologize to each of them. Please direct your criticism at me, not at the Free Software Foundation.

Occasionally I learned something about relationships and social skills, so over the years I've found ways to get better at these situations. When people help me understand an aspect of what went wrong, and that shows me a way of treating people better, I teach myself to recognize when I should act that way. I keep making this effort, and over time, I improve.

Some have described me as being "tone-deaf," and that is fair. With my difficulty in understanding social cues, that tends to happen. For instance, I defended Professor Minsky on an M.I.T. mailing list after someone leaped to the conclusion that he was just guilty as Jeffrey Epstein. To my surprise, some thought my message defended Epstein. As I had stated previously, Epstein is a serial rapist, and rapists should be punished. I wish for his victims and those harmed by him to receive justice.

False accusations -- real or imaginary, against me or against others -- especially anger me. I knew Minsky only distantly, but seeing him unjustly accused made me spring to his defense. I would have done it for anyone. Police brutality makes me angry, but when the cops lie about their victims afterwards, that false accusation is the ultimate outrage for me. I condemn racism and sexism, including their systemic forms, so when people say I don't, that hurts too.

It was right for me to talk about the injustice to Minsky, but it was tone-deaf that I didn't acknowledge as context the injustice that Epstein did to women or the pain that caused.

I've learned something from this about how to be kind to people who have been hurt. In the future, that will help me be kind to people in other situations, which is what I hope to do.

https://www.fsf.org/news/rms-addresses-the-free-software-community

#stallman #rms #fsf #excuse
📡 @nogoolag 📡 @blackbox_archiv
90: Jenny
Darknet Diaries - EP 90: JENNY

Meet Jenny Radcliffe, the People Hacker. She’s a social engineer and physical penetration tester. Which means she gets paid to break into buildings and test their security. In this episode she tells us a few stories of some penetration testing jobs she’s done.

https://darknetdiaries.com/episode/90/

#truecrime #darknetdiaries #podcast
🎙@cRyPtHoN_INFOSEC_FR
🎙
@cRyPtHoN_INFOSEC_EN
🎙
@cRyPtHoN_INFOSEC_DE
🎙
@BlackBox_Archiv
🎙
@NoGoolag
Gmail 'safer than parliament's email system' says Tory MP

Google's email service - Gmail - is “more secure” than parliament's email system, the chair of the Foreign Affairs Select Committee has claimed.

Tom Tugendhat told BBC Radio 4’s Today programme he has repeatedly been the focus of cyber attacks over the past three years.

Hackers have tried to access his account and sent emails impersonating him, he told the BBC.

The Tory MP believes China and Iran were behind some of these attempts.

“I was told by friends at GCHQ that I was better off sticking to Gmail, rather than using the parliamentary system, because it was more secure,” said Mr Tugendhat.

“Frankly, that tells you the level of security and the priority we're giving to democracy in the United Kingdom.”

https://www.bbc.co.uk/news/technology-56733667

#google #gmail #uk #china #iran #cyberattack #tory #thinkabout
📡 @nogoolag 📡 @blackbox_archiv
Update on beta testing payments in Signal

As the world stands today, the future of transaction privacy does not look great. The existing landscape is dominated by traditional credit companies, who over the past decade have been steadily pushing their networks for increased access to user data. They (and their data customers) are on a track to getting SKU level data of every purchase everyone makes everywhere. There are other contenders, such as regional online payments networks (like Venmo in the US), but the data story there is similar.

This is not a future we are particularly excited about. At Signal, we want to help build a different kind of tech – where software is built for you rather than for your data – so these are trends that we watch warily.

https://signal.org/blog/update-on-beta-testing-payments/

#signal #privacy #messaging #cryptocurrency #payment #thinkabout
📡 @nogoolag 📡 @blackbox_archiv
Hypercable Analytics

Hypercable Analytics is a fully featured high performance scalable alternative to Google Analytics, build with timescaledb openresty redis and rails.

💡 Feature list:

*
Selfhost
* Basic Metrics
* Channel Referrer / Campaign Tracking
* Integration with Google Ads
* Ecommerce Analytics
* Event-level raw data
* Custom reporting logic
* No data sampling
* Measurment Protocol

https://github.com/HyperCable/hypercable

#hypercable #google #analytics #alternatives
📡@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
📡
@NoGoolag