Monthly Shaarli

All links of one month in a single page.

November, 2016

https://librerouter.org/home
Ring | Ring vous donne le plein contrôle de vos communications et un niveau de confidentialité inégalé.
Les pilotes graphiques Nvidia décidément bien trop bavards
Signal Downloads Spiked After Election Results | Motherboard - Liens en vrac de sebsauvage
Défense française : portes ouvertes pour la NSA | Grise Bouille
Les réseaux sociaux, meilleurs ennemis des militants - Boîtes noires, le blog d'Olivier Tesquet - Télérama.fr
Ça sent le souffre chez Riseup · Aldarone.fr
Shaft Inc. : Arrêtez (de conseiller) d'utiliser Google Public DNS

Certes Google Public DNS, pour rester sur le plus connu, est fiable (il ne ment pas et ne tombe pas souvent en panne) mais, Google étant Google, c'est leur donner accès à l'intégralité des requêtes DNS partant de vos machines, soit à peu prêt toute votre activité sur le net. Ces derniers nous disent qu'ils ne font pas grand chose des données collectées, notamment qu'ils ne croisent pas les données qu'ils possèdent via votre compte Google. Dans ce domaine, on ne peut que les croire sur parole. De plus, des données sensibles sont tout de même collectées (entre autre : AS - votre FAI grosso modo - et zone géographique). Notons que sur ce point, ça a l'air d'être la fête du slip chez Cisco (si c'est bien le bon document que j'ai trouvé). Bref, regardons ce que donnent de telles métadonnées avec Unbound (en activant l'option log-queries)

The Matrix, Inverted on Vimeo
My fight against CDN libraries - Pepper&Carrot
Tristan Harris : « Des millions d’heures sont juste volées à la vie des gens » - Rue89 - L'Obs
The UK Is About to Legalize Mass Surveillance | Motherboard

The Investigatory Powers Act formally legalizes a number of mass surveillance programs revealed by Edward Snowden. Civil liberties campaigners say it's one of the most extreme surveillance laws in any…

Blogus Librus | Solus sort en version 1.2.1 et MATE arrive !
Don’t Be Fooled: The Mac App Store Is Full of Scams
Google’s AMP is a gilded cage – Terence Eden's Blog

AMP is Google’s attempt to re-fight the transcoding wars of the early 2000s. It is actively dangerous to the web ecosystem, helps disseminate propaganda, and is disliked by many users. If, li…

Le choix de la Xubuntu 16.10 pour les écoles et les associations
newsoft's fun blog: Le gâchis
Cops hate encryption but the NSA loves it when you use PGP • The Register

It lights you up like a Vegas casino, says compsci boffin

I can’t just stand by and watch Mark Zuckerberg destroy the internet.

But financials are just a small part of what makes Facebook so powerful. Here are some ways it dominates human attention:

  • More than one billion people use Facebook each day. 1/4 of all time spent on the internet is spent using Facebook.

  • For many people, Facebook is the internet. It’s the first place most people go to announce weddings, births, deaths, and other major life events.

  • Facebook is increasingly the place where people consume other forms of media.

Uber's New Terms of Use Gives it Unlimited Rights to Sell Customer Data

Uber recently updated its Terms of Use, and it is outright unethical and grossly violates user’s right to their own data. This is what it says: Any User Content provided by you remains your property. However, by providing User Content to Uber, you grant Uber a worldwide, perpetual, irrevocable…

Edward Snowden Demonstrates How Easy It is to Hack a Voting Machine--All for Just $30

"In a few steps they were able to make votes for one candidate count as votes for a rival"...

Facebook développe un outil de censure pour accéder au marché chinois

D'après les sources du New York Times, Facebook planche actuellement sur un outil permettant de bloquer l'apparition de certains contenus sur une base géographique....

Sur les traces de nos données numériques très convoitées - La Croix
De Facebook à la Nsa, tous fichés, tous suspects ?
Un monde sous surveillance : Edward Snowden en 7 émissions
The code I’m still ashamed of : programming
L'histoire du développeur qui aurait dû lire Kant

Des dilemmes moraux qui se logent dans les lignes de code

Conseils d'achat - ordinateur sur mesure avec GNU/Linux - Émancipation informatique pour tous LIBÈRE TON ORDI !
Countries do not control the internet. Companies do.
Shazam Keeps Your Mac’s Microphone Always On, Even When You Turn It Off | Motherboard
Second Chinese Firm in a Week Found Hiding Backdoor in Firmware of Android Devices
Revue de presse de l'April pour la semaine 46 de l'année 2016 | April
Notes de version LibreOffice 5.2 - The Document Foundation Wiki
Panoptinet - La cybersécurité au quotidien

Contraction des mots grecs « tout » et « voir », et du mot anglais « réseau », Panoptinet est un site web qui donne aux particuliers de nombreuses ressources destinées à la sécurisation de leur accès Internet : actualités, fiches théoriques, fiches pratiques, documentation technique, outils, etc. La possession d’un réseau personnel, notamment WiFi, implique quelques connaissances et l’instauration d’un minimum de sécurité. C’est pourquoi la démarche de Panoptinet est axée sur l’information, la pédagogie et la responsabilisation.

Quel niveau de surveillance la démocratie peut-elle endurer ? - Projet GNU - Free Software Foundation
Filelink pour les pièces jointes volumineuses | Assistance de Thunderbird
collaboraonline – Nextcloud
Comment les publicitaires vous espionnent à coups d'ultrasons
iPhones Secretly Send Call History to Apple, Security Firm Says

Your call logs get sent to Apple’s servers whenever iCloud is on — something Apple does not disclose.

WhatsApp cesse le partage de données avec Facebook en Europe

Fin août, WhatsApp faisait savoir que, dorénavant, certaines données de ses utilisateurs seraient partagées avec sa maison mère, nommément Facebook. Deux mois et...

PSA: Google can lock your account, forcing you to abandon your purchases and even obtain a new credit card - Android
Snowden: Stop Relying on Facebook for Your News - Scribblrs

In the wake of one of the most tumultuous election cycles in recent memory, many people are criticizing social media outlets – namely Facebook –...

Microsoft Fortifies Commitment to Open Source, Becomes Linux Foundation Platinum Member | The Linux Foundation
Internet Freedom Wanes As Governments Target Messaging, Social Apps : All Tech Considered : NPR

Apps like WhatsApp and Telegram are the latest to face crackdowns, a new report says. Two-thirds of Internet users live in countries that censor criticism of the government, military or rulers.

How an accused drug dealer revealed JSO’s facial recognition network | Jacksonville News, Sports and Entertainment | jacksonville.com

Earlier this year, an accused crack cocaine dealer wanted to know how he was identified as a suspect in an undercover drug sting on the Northside. Facing a criminal trial, he deposed the detectives on his case and revealed for the first time how a controversial technology is being used by the Jacksonville Sheriff’s Office.

BBC - Capital - Your slow email replies are causing serious anxiety

The uncertainty that weaves its way into your psyche while you wait can cause angst, sleepless nights and worse. Why we’re anxious about email — and what to do about it.

Microsoft Is Now 'Open By Default', Says Xamarin Founder Miguel de Icaza

Microsoft acquired Xamarin in February of 2016 as part of a key strategic move designed (among other things) to help bolster Microsoft ‘Universal Windows Platform’ (UWP) technology and its cross-platform reach. So what’s it like to be acquired by Redmond and does Microsoft really get the theory behind heterogeneous open connections as it claims?

Ring, officially a GNU package
JackDostoevsky comments on Why I won't recommend Signal anymore

Signal is unusual because it combines cutting edge cryptography with consumer friendliness and is actually successful. It's pragmatic, not ideological. Crypto-warriors have a long history of producing secure software that nobody uses and then blaming the general public for not getting it; this sort of blog post is just a continuation of this decades long trend.

Livre surveillance:// : premier bilan - Standblog
En vrac du vendredi 04/11/2016 - Standblog
Google Developers Blog: Here’s to more HTTPS on the web!

News and insights on Google platforms, tools, and events.

Silence | SMS/MMS encryption made easy

SMS/MMS encryption made easy

Android atteint 87,5 % de parts de marché au troisième trimestre 2016

Android n'en finit plus d'écraser la concurrence. Depuis ses débuts, le petit robot vert a grappillé des parts de marché avec un appétit monstre. Au troisième trimestre 2016,...

Me and my Shadow

Take control of your data

Si Google vous ignore, votre projet est en péril – Framablog
À Bercy, un marché de support aux logiciels libres de 30 millions d’euros
GitHub - i-rinat/freshplayerplugin: ppapi2npapi compatibility layer

The main goal of this project is to get PPAPI (Pepper) Flash player working in Firefox.

Flash d’Adobe à l’agonie - LinuxFr.org
PrimTux2, nouvelle version de la distribution GNU/Linux pour écoliers - LinuxFr.org
How to Send Your Linux Desktop Audio to a Chromecast - OMG! Ubuntu!

Do you want to stream the audio from Rhythmbox, VLC or another Linux app to your TV through Chromecast? Well, we've found a nifty little Linux tool that lets you do just that.

You Can Legally Hack Your Own Car, Pacemaker, or Smartphone Now | WIRED

An exemption in a decade-old anti-hacking statute has finally kicked in, and could unleash a new bounty of security research.

System76 brings Ubuntu to $699 laptop with Kaby Lake chips | CIO

If Windows 10 isn't your cup of tea, there's a new Ubuntu laptop from System76 with Intel's new Kaby Lake chip that won't burn your wallet.

Guide : Comment sauvegarder ses pilotes de PC
Au Journal officiel, un fichier biométrique de 60 millions de « gens honnêtes »
WOT Services - Wikipedia - Liens en vrac de sebsauvage
Jolla’s Sailfish OS now certified as Russian government’s first ‘Android alternative’ | TechCrunch

The future for one of the few remaining alternative mobile OS platforms, Jolla's Sailfish OS, looks to be taking clearer shape. Today the Finnish company..

Diaspora* comme alternative à Facebook · Aldarone.fr

Facebook ça fait longtemps que les hacktivistes ont compris les problèmes de Facebook. On sait que la centralisation c’est tout pourri. On sait que le contrôle unilatéral de nos données c’est de la merde. On sait que leur modèle c’est l’exploitation capitaliste des données qu’on leur fourni gratuitement.
Pourtant, on est toujours sur Facebook. Parce qu’on sait pas trop où on irait sinon là bas car ils ont une masse critique qui s’auto-alimente.

"Impressive. Chrome doesn't work at all if it can't access Google services. "Don't be evil" yeah right https://t.co/9KSTrMyJGP" - André Staltz sur Twitter - Liens en vrac de sebsauvage
informatique:logiciels:firefox [pteuz wiki]
Liste d’extensions Firefox
Filtres personnalisés Twitter pour uBlock origin
Is Gravatar a privacy risk? - Meta Stack Exchange
Blocage et filtrage des sites : une étude met au même plan la France, la Turquie et la Russie
France

A collaborative, free and open database of ingredients, nutrition facts and information on food products from around the world

Solus - Le Linux user-friendly qui refuse de devenir une usine à gaz - Korben
Solus Project 1.2 : simple évolution ou version majeure de la distribution ? – Le Weblog de Frederic Bezies
Pourquoi Framasoft n’ira plus prendre le thé au ministère de l’Éducation Nationale – Framablog
Worried about the NSA under Trump? Here's how to protect yourself | Technology | The Guardian
Réglez les paramètres vie privée de Windows 10 (Après installation) | CNIL
Vie privée : 5 outils utilisés et approuvés par Snowden - Les Echos
The Zuckerberg Files

The Zuckerberg Files is an archive of all public utterances of Facebook’s founder and CEO, Mark Zuckerberg. It includes transcripts and bibliographic data of all publicly-available content from 2004-2014 representing the voice and words of Zuckerberg, including blog posts, letters to shareholders, media interviews, public appearances and product presentations, and quotes in other sources.

It’s time to get rid of the Facebook “news feed,” because it’s not news | Ars Technica

Fake news didn’t throw the election. It was a symptom, not a cause.

PSA: Google can lock your account, forcing you to abandon your purchases and even obtain a new credit card - Android
Riot releases end-to-end encryption: get ready to chat securely! – Medium

Today is a big day in the Riot world, finally releasing the very first cross-platform implementation of Matrix’s end-to-end encryption!

NIST’s new password rules – what you need to know – Naked Security

A lot of password rules are there simply “because we’ve always done it that way.” NIST aims to fix that, and here’s how.

France : le fisc réclamerait à Apple plus de 400 millions d'euros

À l'issue du contrôle fiscal lancé il y a deux ans et portant sur les années 2011, 2012 et 2013, Bercy aurait fini par prendre la décision d'imposer à Apple un redressement...

Le numérique et nous (4/4) : Loi Renseignement La Grande Collecte
L'affaire Snowden - Antoine LEFÉBURE - Éditions La Découverte
"Snowden" : les 3 mystères que le film laisse en plan
Toutes les applications - App Store - Nextcloud
Tutoriel - garder Windows stable plus longtemps - Émancipation informatique pour tous LIBÈRE TON ORDI !
Who Will Own Your Data If the Tech Bubble Bursts? - The Atlantic
Comment sécuriser Firefox avec quelques paramètres dans about:config ? - Blog des télécoms
Secret Backdoor in Some Low-Priced Android Phones Sent Data to a Server in China
UK : les données de 133 827 clients de l'opérateur Three compromises

Outre-Manche, l'opérateur Three a officiellement reconnu, en fin de semaine dernière, avoir été victime d'une intrusion dans son système dédié aux renouvellements...

Lifestyle | La France veut créer une "bibliothèque universelle" du logiciel
OsmAnd Topo map style
OsmAnd - Offline Mobile Maps and Navigation
Le FBI pourra désormais surveiller les 500 millions de tweets publiés chaque jour - Politique - Numerama

Le partenariat conclu entre le FBI et l'entreprise Dataminr permet à l'agence gouvernementale d'accéder, en temps réel, aux 500 millions de messages postés quotidiennement sur Twitter.

Rob Graham 🦃 sur Twitter: "1/x: So I bought a surveillance camera https://t.co/HbmPzrZgFK"
CODE updates - Collabora Productivity
Le logiciel libre gagne en popularité chez les grandes entreprises - le Parisien
La liste d'appels des iPhone est automatiquement envoyée sur iCloud

L'entreprise russe ElcomSoft a récemment mis en avant la sauvegarde automatique des historiques d'appels des iPhone sur le compte iCloud auquel ils sont rattachés....

// GNU Health - Freedom and Equity in Healthcare //
Britain has passed the 'most extreme surveillance law ever passed in a democracy' | ZDNet

The law forces UK internet providers to store browsing histories -- including domains visited -- for one year, in case of police investigations.

No One Cares About The Security Of Your Unlocked Android Phone

There’s no way Amazon would co-launch an exclusive flagship product that has a hidden backdoor that secretly sends all of your personal…

Shazam Keeps Your Mac’s Microphone Always On, Even When You Turn It Off | Motherboard

A security researcher has uncovered a potentially creepy feature of the popular app to discover music.

'Trust it': Results of Signal's first formal crypto analysis are in • The Register
Facebook ouvre les vannes de la publicité sur Messenger

Au terme de longs mois dédiés au test de son dispositif, Facebook vient de donner le feu vert aux entreprises pour commencer à envoyer des "messages sponsorisés"...

Surveillance Self-Defense | Tips, Tools and How-tos for Safer Online Communications

Tips, Tools and How-tos for Safer Online Communications

President Obama Should Shut Down the NSA’s Mass Spying Before It’s Too Late | TIME

Modern surveillance programs would be a disaster under President Trump

Reasons not to use Uber
Apple is doubling down on open source - TechRepublic
Un nouveau bios pour installer Linux sur Lenovo Yoga 900 et Ideapad 710s
Google – My Activity | Hacker News
En 2016, le code informatique arrive à l’école
F-Droid – Free and Open Source Android App Repository
Replacing Google with microG [LWN.net]
Let's talk about messaging apps: what do you think is the best app/service for instant messaging? What could be THE replacement for Whatsapp and all our communications needs? : fossdroid
TeutonJon78 comments on Why I won't recommend Signal anymore

Différence entre microG et OpenGApps

Désormais, Google livre vos données personnelles aux publicitaires
BugReplay

Pornhub Bypasses Ad Blockers With WebSockets

*** Links to discussions on Reddit and Hacker News. Also check out BugReplay on Product Hunt :)

TLDR: Watch the BugReplay Recording of Pornhub dodging AdBlock

(NSFW level: medium)

We tried to find the most PG page on MindGeek’s network to use as an example- it wasn’t easy.

When I was building the prototype for BugReplay, I was evaluating different methods of capturing
and analyzing network traffic from Chrome. One of the first things I saw that looked promising was the chrome.webRequest API.

From the docs: “Use the chrome.webRequest API to observe and analyze traffic and to intercept, block, or modify requests in-flight.”

That seemed to be exactly what I needed.

After experimenting with the Chrome webRequest API, I quickly realized there was a big problem. It didn’t allow me to analyze any WebSocket traffic, something I really wanted to support.

As I was searching the web trying to see if I was misreading the documentation or was looking in the wrong spot, I found a relevant bug report from 2012: “chrome.webRequest.onBeforeRequest doesn’t intercept WebSocket requests.”
In the bug report, users were complaining that without the ability to block WebSockets, websites could get around ad blockers fairly easily. If WebSocket data was not visible to Chrome extensions via the webRequest API, they could not be blocked without some heavy duty hacks.

Initially, the risks to ad blockers seemed theoretical; the examples of sites that were employing this technique were very obscure. Then in August 2016, an employee of the company that owns Pornhub.com (MindGeek) started arguing against adding the WebSocket blocking capabilities to the Chrome API. Pornhub is the 63rd most visited site on the Internet according to Alexa. I checked out a few of MindGeek’s sites and sure enough, I could see ads coming through even though I had Adblock Plus on. The ads on Pornhub are marked ‘By Traffic Junky,’ which is an ad network owned by MindGeek.

In the screenshot below, you can see a banner at the top of the page announcing that the site is aware that the user is using an Ad Blocker, with an invitation to subscribe to a premium ads free version of the site. On the right side of the page you can see an advertisement.

How They Do It

When you visit Pornhub.com, it tries to detect if you have an ad blocker. If it detects one, it opens a WebSocket connection that acts as a backup mechanism for delivering ads.

Watching the BugReplay browser recording, you can see a number of network requests triggered that are blocked by AdBlock: They are marked Failed in the network traffic, and if you click one to inspect the detail pane you can see the failed reason is net::ERR_BLOCKED_BY_CLIENT. That is the error reported by Chrome when an asset is blocked from loading.

You can find the WebSocket frames individually in the network panel or just look at the WebSocket create request which has links to all the individual frames. The name of the domain where the WebSocket connects is “ws://ws.adspayformy.site.” A decent joke aimed at ad blockers :)

When the WebSocket loads, the browser sends a frame with a JSON encoded payload for each of the spots it has available for ads.
Checking out one of the WebSocket frames, you can see in the frame data the advertisement data is sent back with:

The zone_id 13, for where the JavaScript should place the ad.

The media_type image, so the page knows what kind of element to create (most of the ads are videos, I picked an image for this post because it was relatively tame).

The Image itself, transmitted base64 encoded so it can be reconstructed using the data uri scheme

An “img_type” (“image/jpeg”) to pass to the data uri.

Ad Blockers primarily work using the webRequest API, so constructing the ad by transmitting the data over the WebSocket as base64 is a pretty clever way of dodging the blocker.

What’s next

On October 25th, 2016, there was some new activity on the Chromium ticket. A contributor wrote a patch adding the ability to block WebSockets using the webRequest api. If it’s accepted, it will eventually wind up in Chrome stable.

When or if that rolls out, the ad blocker extension writers can choose to remove the hacks for users of the latest Chrome, leaving content providers like Pornhub to figure out their next move in the ad blocking war.

Update

Since I started looking into this, AdBlock Plus and uBlock Origin have shipped workarounds to block this technique. AdBlock and others still do not.

For AdBlock Plus, “The wrapper performs a dummy web request before WebSocket messages are sent/received. The extension recognizes these dummy web requests as representing a WebSocket message. It intercepts and blocks them if the corresponding WebSocket message should be blocked. The WebSocket wrapper then allows / blocks the WebSocket message based on whether the dummy web request was blocked or not.” via

For uBlock Origin, they shipped a workaround that has the “ability to foil WebSocket using a CSP directive.”

Le Multidevice arrive sur Ring
Mirai : une variante s'attaque aux routeurs, 900 000 clients Deutsche Telekom touchés
Vie privée - Liens en vrac de sebsauvage

« Prétendre que votre droit à une sphère privée n'est pas important parce que vous n'avez rien à cacher n'est rien d'autre que dire que la liberté d'expression n'est pas essentielle car vous n'avez rien à dire. »
-- E. Snowden

L’application de messagerie sécurisée Signal devient très populaire après les élections américaines | {niKo[piK]}
Autistici
disroot.org

Disroot is a platform providing online services based on principles of freedom, privacy, federation and decentralization.
No tracking, no ads, no profiling, no data mining!

Blog-Libre | La quête - Liens en vrac de sebsauvage
André Staltz sur Twitter : "Impressive. Chrome doesn't work at all if it can't access Google services. "Don't be evil" yeah right https://t.co/9KSTrMyJGP"

Impressive. Chrome doesn't work at all if it can't access Google services. "Don't be evil" yeah right

Arrêtez (de conseiller) d'utiliser Google Public DNS - Shaft Inc. - Liens en vrac de sebsauvage
Textarea Cache : pour ne plus perdre les textes tapés sous Firefox - Hal-9000
The Entire Internet Will Be Archived In Canada to Protect It From Trump | Motherboard
SAIP : quand une « anomalie » rend indiscrète l’application d’alerte des populations
Search results | Farm Hack
Amazon Worker Jumps Off Company Building After E-Mail Note - Bloomberg

An Amazon.com Inc. employee was injured when he leaped off a building at the company’s Seattle headquarters in what police characterized as a suicide attempt.

Home | Solus
DietPi - Lightweight justice for your SBC
Blogus Librus | Quoi de neuf du côté de chez Solus
Google’s Customer Contempt Conundrum – Terence Eden's Blog

Google’s attitude towards its customers is a continuing stain upon its reputation. In an ideal world, no one would ever need to contact customer services. Every step of one’s interactio…

NSA, GCHQ and even Donald Trump are all after your data • The Register
Antivirus DAVFI : l’autre grand gâchis de l’informatique souveraine ? | Silicon
Android Malware Used to Hack and Steal a Tesla Car

By infecting a Tesla owner's phone with Android malware, a car thief can hack and then steal a Tesla car, security researchers have revealed this week.

Germany planning to ′massively′ limit privacy rights | Germany | DW.COM | 25.11.2016

Interior Minister Thomas de Maiziere is planning a major limitation of privacy rights in Germany, say data protection groups. Germans will no longer have the right to know what data about them is being collected.

Android user locked out of Google after moving cities | Hacker News
Riot releases end-to-end encryption: get ready to chat securely | Hacker News
OpenFood | Produits (14396)

OpenFood est une base de données librement accessible sur les produits vendus en Suisse. Elle est maintenue par le laboratoire d'Épidémiologie Numérique de l'EPFL.

Edward Snowden Demonstrates How Easy It Is to Hack a Voting Machine | Hacker News
Personal data for more than 130,000 sailors hacked: U.S. Navy | Reuters

Hackers gained access to sensitive information, including Social Security numbers, for 134,386 current and former U.S. sailors, the U.S. Navy said on Wednesday.

Signal for Beginners – Medium

For some reason, people have gotten pretty interested in mobile security lately. So let’s talk about a secure messaging app called Signal.

Données privées : « Peut-être avons-nous été collectivement laxistes »

La présidente de la CNIL et du G 29, les CNIL européennes, nous a longuement confié son point de vue sur l'évolution de nos informations personnelles.

Code I’m Still Ashamed Of | Hacker News
En vrac du mercredi - Standblog
Nextcloud Apps, Apps, Apps ... - Hagen Graf
How to install Nextcloud client (ubuntu) – rieger::CLOUD
Installer Nextcloud-client sur Ubuntu – Linux Team
Chris Olson sur Twitter: "3 things about this photo of Zuck: Camera covered with tape Mic jack covered with tape Email client is Thunderbird https://t.co/vdQlF7RjQt"

Mark Zuckerberg a mis du scotch sur sa webcam et son microphone, et utilise thunderbird

Un nouveau label pour encourager le logiciel libre dans les collectivités - Localtis.info - Caisse des Dépôts
LibreOffice : de 5.0 à 5.2, un an après - LinuxFr.org
Il est temps de faire quelquechose à propos de Facebook · Aldarone.fr

Mais aujourd’hui, quelqu’un a décidé de faire un peu plus qu’exprimer son désaccord avec G. Quelqu’un a décidé de prévenir Facebook que G. ne jouait pas selon les règles du réseau social. Et aujourd’hui, Facebook a suspendu le compte Facebook de G. la coupant ainsi totalement de bon nombre de ses contacts qui n’avaient que ce moyen de communication pour interagir avec iel au quotidien.

Touch Bar MacBook Pro models have non-upgradeable SSDs, seemingly under-sized batteries | 9to5Mac

The first MacBook Pro with Touch Bar models are arriving, and if you were encouraged by the removable SSD OWC found in the entry-level machine, there’s bad news. Owners who have opened them u…

LibreOffice Online available in Pydio - Collabora Productivity
En vrac du vendredi - Standblog
Mozilla lance Firefox Focus, son navigateur discret pour iOS

En décembre dernier, Mozilla lançait Focus by Firefox, une application de "blocage de contenu" destinée à alléger la navigation avec Safari sur iOS. À peine 11 mois...

Des milliers de smartphones Android chinois affligés par une backdoor

Nouvelle petite secousse dans le monde de la sécurité Android. Une équipe de chercheurs américains a découvert dans de nombreux modèles de téléphone Android un petit...

poisontap/README.md at master · samyk/poisontap · GitHub

poisontap - Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using Raspberry Pi Zero & Node.js.

Ways Your Wi-Fi Router Can Spy on You | Hacker News
Why did ProtonMail vanish from Google search results for months? | TechCrunch

If you're the maker of a popular, zero access encrypted webmail product and suddenly discover your product is no longer featuring in Google search results for..

Signal Messaging App Formal Audit Results Are Good - Darknet
Raccoon - APK downloader | Onyxbits

Download apps directly from Google Play. Raccoon is the only APK Downloader that also supports paid and large apps.

When CSI meets public wifi: Inferring your mobile phone password via wifi signals | the morning paper

When CSI meets public wifi: Inferring your mobile phone password via wifi signals Li et al., CCS 2016 Not that CSI. CSI in this case stands for channel state information, which represents the state…

Facebook admits it must do more to stop the spread of misinformation on its platform | TechCrunch

Facebook has responded to widespread criticism of how its Newsfeed algorithm disseminates and amplifies misinformation in the wake of the Trump victory in the..

About – Cub Linux®
Trump : la première leçon - Standblog
Mozilla and Google remove WOT extension from Store - gHacks Tech News

Méfiez-vous des extensions que vous installez

Le "décret Halloween", le plus impressionnant système de fichage
microG Project
Let's talk about messaging apps: what do you think is the best app/service for instant messaging? What could be THE replacement for Whatsapp and all our communications needs? (x-post /r/fossdroid) : privacytoolsIO
Seeing Yellow
HP, l'informatique de trahison. - LinuxFr.org
Vivre sous surveillance : un autre Internet est possible - Rue89 - L'Obs
“I have nothing to hide. Why should I care about my privacy?” – Medium
Conversations F-Droid
Conversations: the very last word in instant messaging

A free and open source Jabber/XMPP client for Android. Easy to use, reliable, battery friendly. With built-in support for images, group chats and e2e encryption.

[MàJ] Internet : 75 % des connexions seront mobiles dès 2017

D'après un rapport publié par l'agence Zenith et basé sur l'observation d'une soixantaine de marchés de par le monde, les usages franchiront l'année prochaine un...

Un peu d’hygiène numérique – Framablog
"Fontaine, la libérée" : le logiciel libre dans tous ses états | Place Gre'net
14 mois sans Adobe Flash : bilan sur le « long terme ». – Le Weblog de Frederic Bezies
Revue de presse de l'April pour la semaine 43 de l'année 2016 - LinuxFr.org
surveillance:// Entretien avec son auteur Tristan Nitot et 10 livres à gagner - LinuxFr.org
Stealth Cell Tower
The Real Amount of Energy Used to Power the Internet | Electronic Silent Spring
Researchers reveal how to webcam spy without turning on the LED

Turns out you can't trust the LED indicator light on your webcam to tell you if you're being spied upon or not.

System76 brings Ubuntu to $699 laptop with Kaby Lake chips | Hacker News
Julian Assange - Google Is Not What It Seems