Monthly Shaarli

All links of one month in a single page.

May, 2017

EPFL-ENAC | Annuaire EPFL des principaux logiciels libres
Change.org raises new cash from LinkedIn founder Reid Hoffman | Fortune.com

This is Hoffman's largest personal investment to date.

The Human Fabric of the Facebook Pyramid – SHARE LAB
SHARE LAB – Research & Data Investigation Lab
LMP, la start-up qui a aidé Macron à gagner - Capital.fr

Cette start-up française propose aux partis politiques d'utiliser le big data pour gagner de nouveaux électeurs. Emmanuel Macron s'est offert ses services pour la présidentielle de 2017.

fwupd: Updating Firmware in Linux
What is MouseJack! — Bastille

MouseJack is a class of vulnerabilities that affects the vast majority of wireless, non-Bluetooth keyboards and mice. These peripherals are 'connected' to a host computer using a radio transceiver, commonly a small USB dongle. Since the connection is wireless, and mouse movements and keystrokes are sent over the air, it is possible to compromise a victim's computer by transmitting specially-crafted radio signals using a device which costs as little as $15.

An attacker can launch the attack from up to 100 meters away. The attacker is able to take control of the target computer, without physically being in front of it, and type arbitrary text or send scripted commands. It is therefore possible to perform rapidly malicious activities without being detected. The MouseJack exploit centers around injecting unencrypted keystrokes into a target computer. Mouse movements are usually sent unencrypted, and keystrokes are often encrypted (to prevent eavesdropping what is being typed). However the MouseJack vulnerability takes advantage of affected receiver dongles, and their associated software, allowing unencrypted keystrokes transmitted by an attacker to be passed on to the computer's operating system as if the victim had legitimately typed them.

Laure Lucchesi : “Les administrations feront leur mutation quand elles sauront attirer des communautés de contributeurs” - Acteurs publics

Le logiciel libre sera “encouragé” mais pas pour autant “prioritaire” pour équiper les systèmes d’information des administrations. Est-ce suffisant à vos yeux ?

Cette mesure sur l’encouragement des logiciels libres va dans le bon sens. La formulation est peut-être prudente mais elle aura des effets réels. Il ne faudrait pas non plus imposer des logiciels libres dans des administrations qui n’ont pas les moyens de les mettre en œuvre, ce serait inefficace. A Etalab comme à la Dinsic, nous visons l’utilité et l’efficacité. Comment ? En créant une dynamique nouvelle, qui fait que les collectivités ou les administrations attirent à elles des communautés de contributeurs et sortent de la seule logique d’achat d’un logiciel. Le logiciel libre n’est pas forcément la meilleure solution. Cela dépend de la capacité des administrations à contribuer et à maintenir le code source de ce logiciel.

Hackers Make the First-Ever Ransomware for Smart Thermostats - Motherboard

White hat hackers have made the first proof of concept for malware that locks a smart thermostat and demands a ransom.

Not Google specific, but some good reading on this topic came out in January - T... | Hacker News

Not Google specific, but some good reading on this topic came out in January - The Aisles Have Eyes: How Retailers Track Your Shopping, Strip Your Privacy, and Define Your Power

MasterCard and Visa not only make money from each credit card transaction but to... | Hacker News

MasterCard and Visa not only make money from each credit card transaction but to add insult to injury, they make money selling that transaction data as well! That's what I call a ludicrous business.

Facebook self-censorship: What happens to the posts you don’t publish?

A couple of months ago, a friend of mine asked on Facebook: Do you think that facebook tracks the stuff that people type and then erase before hitting ...

Facebook Won’t Say If It Will Use Your Brain Activity for Advertisements

A forthcoming mental-input system from Facebook assumes that if you sent a thought to the speech center of your brain, you want to share it.

New SMB Worm Uses Seven NSA Hacking Tools. WannaCry Used Just Two

Researchers have detected a new worm that is spreading via SMB, but unlike the worm component of the WannaCry ransomware, this one is using seven NSA tools instead of two.

Troy Hunt: Password reuse, credential stuffing and another billion records in Have I been pwned

The short version: I'm loading over 1 billion breached accounts into HIBP. These are from 2 different "combo lists", collections of email addresses and passwords from all sorts of different locations. I've verified their accuracy (including my own record in one of them) and many hundreds of millions of the

Facebook, le Brexit et les voleurs de données – Framablog

Du grand banditisme à une échelle jamais vue. Le résultat : une élection historique volée.

Les suspects sont connus, les cerveaux, les financiers, les hommes de main…

Il y a Nigel Farage, agent de change devenu politicien malgré lui, fondateur du parti politique UKIP contre l'euro, l'Union Européenne et l'immigration.

Il y a Steve Bannon, à la tête de Breitbart News, une plateforme mé ...

WSUS Offline Update - Update Microsoft Windows and Office without an Internet connection
An open-source web platform for the new President of France (Symfony Blog)

The web platform running the winning campaign of the next President of France, Emmanuel Macron, is made with Symfony and is open source.

En vrac avant les vacances - Standblog
Nextcloud 12 Beta Introduces the Next Generation of Secure Collaboration – Nextcloud

Nextcloud is an open source, self-hosted file sync and share and communication app platform. Access & sync your files, contacts, calendars & communicate and collaborate across your devices. You decide what happens with your data, where it is and who can access it!

maru

Maru is a new kind of computing experience. It gives you a single, context-aware device that makes personal computing really simple. And guess what? That device is your smartphone.

Commission Européenne - COMMUNIQUES DE PRESSE - Communiqué de presse - Mergers: Commission fines Facebook €110 million for providing misleading information about WhatsApp takeover

European Commission - Press Release details page - European Commission - Press release Brussels, 18 May 2017 The European Commission has fined Facebook €110 million for providing incorrect or misleading information during the Commission's 2014 investigation under the EU Merger Regulation of Facebook's acquisition of WhatsApp. Commissioner Margrethe Vestager, in charge of competition policy, said: "Today's decision sends

Qwant, aux armes citoyens ! | binaire
En vrac, vers le ministère (ou pas) - Standblog
Enregistrer la page en PDF – La face cachée de Firefox pour Android - Communauté Mozilla francophone
Thunderbird 52, version majeure annuelle - Communauté Mozilla francophone
Au Royal London Hospital, la cyberattaque met les nerfs des Britanniques à rude épreuve

L’attaque informatique du 12 mai a des effets dévastateurs : les radiographies ne peuvent pas être visionnées, les courriers des médecins ne peuvent pas être lus.

La surveillance de masse est toxique pour nos libertés : la preuve ! - News and Useful Resources Around and About Cozy.io

Alors que la surveillance des citoyens est en train de s’imposer (avez vous suivi les dernières révélations de Wikileaks ?), cela suscite un débat autour de la question : en quoi est-il gênant d’avoir de la surveillance de masse ? La réponse est simple : parce quand on se sait surveillé, on se conforme à la norme, on n’ose plus s’exprimer, penser ni agir de peur d’être jugé.

Annuaire des compétences des Entreprises et Prestataires du Numérique Libre - PLOSS-RA
Rançongiciels, une activité qui prospère

La cyberextorsion est un marché lucratif en forte croissance, constate « Le Temps ».

Cyberattaque : « On a l’impression que c’est crapuleux, plus qu’organisé par un Etat »

Le directeur de l’unité de la police chargée de l’enquête sur le « rançongiciel » WannaCry, François-Xavier Masson, estime que d’autres entreprises françaises pourraient être touchées.

Using RTL-SDR to Open Car Doors

Must note that using a jammer within USA is illegal. This post been changed to exclude any infomation on how to **successfully carry out the attack,  it will show the bases used but will not go in-depth. Thank you for understanding. In the years of 2014-2016, “Car Hacking” has been

EUR-Lex - 52013DC0455 - EN - EUR-Lex

COMMUNICATION DE LA COMMISSION AU PARLEMENT EUROPÉEN, AU CONSEIL, AU COMITÉ ÉCONOMIQUE ET SOCIAL EUROPÉEN ET AU COMITÉ DES RÉGIONS Lutter contre l'enfermement propriétaire: des marchés publics fondés sur des normes pour des systèmes TIC ouverts / COM/2013/0455 final /

How to create an Application Whitelist Policy in Windows

In Windows it is possible to configure two different methods that determine whether an application should be allowed to run. The first method, known as blacklisting, is when you allow all applications to run by default except for those you specifically do not allow. The other, and more secure, method is called whitelisting, which blocks every application from running by default, except for those you explicitly allow.

How to Prevent Ransomware Infections | Question Driven

Ransomware is a type of virus that encrypts a users files locally and in files shares. Ransomware encrypts the files using an encryption key only known by the attacker.  Specific file extensions ar…

I spent two weeks delivering for Uber Eats and made $4.4 per hour - Breakit

For two weeks, Breakit’s reporter Erik Wisterberg has secretly infiltrated the much-hyped food delivery services Foodora and Uber Eats. We can now reveal the truth behind the life as a bike courier – and the actual numbers behind it.

An NSA-derived ransomware worm is shutting down computers worldwide | Ars Technica

Wcry uses weapons-grade exploit published by the NSA-leaking Shadow Brokers.

Quand les recommandations YouTube nous font tourner en bourrique… – Framablog

Vous avez déjà perdu une soirée à errer de vidéo en vidéo suivante ? À cliquer play en se disant « OK c'est la dernière… » puis relever les yeux de votre écran 3 heures plus tard… ?

C'est grâce à (ou la faute de, au choix !) l'algorithme des recommandations, une petite recette qui prend plein d'éléments en compte pour vous signaler les vidéos qui peuvent vous intéresser.

Guillaume Ch ...

AV-Comparatives Mobile-Review - AV-Comparatives

AV-Comparatives - Independent Tests of Anti-Virus Software - Unabhängige Vergleichstests von Antiviren-Software

Now Marketers Can Actually Read Your Photos On Instagram And Facebook

So a brand like McDonald’s will know if you’re hungry, eating the competition, and more. Yeah it’s weird, but will it make online ads better?

>> As abused as they are, internet users need to build up some healthy "buyer be... | Hacker News

As abused as they are, internet users need to build up some healthy "buyer beware" instincts around the tradeoffs.

This shouldn't be on the users. The disparity in knowledge between the people running the services and the people using them is huge. The reason a lot of laws (in general) exist is to protect the vulnerable from harm, including harm they don't have the capacity to understand. I think that's an important facet of this debate. It's not just 'free market/free choice' etc. The harm involved in giving up your privacy isn't fully understood by many people so it's up to the law to protect them.

Regulating the internet giants: The world’s most valuable resource is no longer oil, but data | The Economist

Now similar concerns are being raised by the giants that deal in data, the oil of the digital era. These titans—Alphabet (Google’s parent company), Amazon, Apple, Facebook and Microsoft—look unstoppable. They are the five most valuable listed firms in the world. Their profits are surging: they collectively racked up over $25bn in net profit in the first quarter of 2017. Amazon captures half of all dollars spent online in America. Google and Facebook accounted for almost all the revenue growth in digital advertising in America last year.

Open-source chip mimics Linux's path to take on closed x86, ARM CPUs - Computerworld

Tired of the domination of x86, ARM, and other closed chip architectures, researchers created the open-source RISC-V architecture at the University of California, Berkeley, in 2010.

Mirror Download Server Compromised - HandBrake
HandBrake Hacked!
GitHub - westnordost/StreetComplete: Surveyor app for Android
Pawel Kuczynski - // Canvas Collection
Lancement de RadioWiki, la radio des libristes - alterlibriste
30 Ways Your Windows 10 Computer Phones Home to Microsoft
Des nouvelles de notre ami Facebook – mai 2017 – Framablog
Open data : Le dispositif d'accompagnement des collectivités se met en place- Maire-info / AMF

La loi pour une République numérique impose à toutes les collectivités de plus de 3 500 habitants, soit environ 4 000 entités, d’ouvrir leurs données. Le gouvernement a confié à l’association Open Data France la mise en place d’un dispositif d’accompagnement des petites collectivités, baptisé Open Data Locale, reposant sur 9 territoires pilotes (lire Maire info du 12 décembre 2016). Le 27 avril, un premier bilan du dispositif a été présenté à Créteil.

Thunderbird’s Future Home | The Mozilla Thunderbird Blog

Summary The investigations on Thunderbird’s future home have concluded. The Mozilla Foundation has agreed to serve as the legal and fiscal home for the Thunderbird ...

Optimisation fiscale : Google accepte de verser 306 millions en Italie

La fin d'une longue négociation

Réflexion sur la Bureautique libre : migration et accessibilité
Territoires numériques (PDF)
Sharing & Reuse Conference 2017
IMIO presentation at the Sharing & Reuse Conference 2017 (PDF)
Google versera 306 millions d’euros au fisc italien

C’est une nouvelle victoire du fisc italien contre les géants de la « tech ». Dans un communiqué publié jeudi 4 mai, l’administration transalpine a annoncé avoir conclu un accord soldant son contentieux avec Alphabet, la maison mère de Google, en contrepartie du versement par l’entreprise américaine de 306 millions d’euros à l’Etat italien.

Celui-ci reproche à Google de pratiquer l’évasion fiscale, en déclarant en Irlande des revenus générés sur son territoire, où se trouve son siège social européen – et où la fiscalité sur les entreprises est beaucoup plus attrayante (seulement 12,5 % d’imposition sur les bénéfices des sociétés contre 27,5 % en Italie). Outre le paiement de cette compensation, qui porte sur la période 2002-2015, « des accords préventifs sur la taxation correcte à l’avenir en Italie des activités [de Google] » vont être mis en place. Une disposition encore peu précise qui va faire l’objet de discussions entre le groupe californien et Rome.

Hundreds of privacy-invading apps are using ultrasonic sounds to track you | ZDNet

Apps are using ad-tracking audio signals that your phone can hear, but you can't.

corna/me_cleaner · GitHub

me_cleaner is a tool to remove as much code as possible from an Intel ME/TXE/SPS image.

Disabling Intel AMT

Completely and permanently (unless you re-install it) disable Intel Active Management Technology, Intel Small Business Technology, and Intel Standard Manageability on Windows. These are components of the Intel Management Engine firmware.

GitHub - evilsocket/opensnitch: OpenSnitch is a GNU/Linux port of the Little Snitch application firewall.

OpenSnitch is a GNU/Linux port of the Little Snitch application firewall.

Intel Active Management Technology, Intel Small Business Technology, and Intel Standard Manageability Escalation of Privilege
Facebook’s ad platform will know who you are, what you buy, even offline | Ars Technica

Facebook has officially relaunched the advertising platform Atlas in a new incarnation that will allow marketers to track users in new dimensions, according to a blog post from the company. Atlas will offer the ability to not only synthesize information about where users are seeing ads, but also to see how and whether those ad views play out into a purchase, even if it's offline.

Remote security exploit in all 2008+ Intel platforms - SemiAccurate

Every Intel platform from Nehalem to Kaby Lake has a remotely exploitable security hole. SemiAccurate has been begging Intel to fix this issue for literally years and it looks like they finally listened.

Update May 1, 2017 # 3:35pm: Intel just confirmed it, but not to SemiAccurate. You can read their advisory here.

The short version is that every Intel platform with AMT, ISM, and SBT from Nehalem in 2008 to Kaby Lake in 2017 has a remotely exploitable security hole in the ME (Management Engine) not CPU firmware. If this isn’t scary enough news, even if your machine doesn’t have SMT, ISM, or SBT provisioned, it is still vulnerable, just not over the network. For the moment. From what SemiAccurate gathers, there is literally no Intel box made in the last 9+ years that isn’t at risk. This is somewhere between nightmarish and apocalyptic.

Quand Facebook aide des publicitaires à cibler les adolescents mal dans leur peau - Tech - Numerama

En Australie et en Nouvelle-Zélande, Facebook a publié un guide invitant les publicitaires à cibler les adolescents de 14 ans et plus d'annonces ciblées au moment où ceux-ci se sentent le plus vulnérables. Le réseau social a présenté ses excuses après la révélation de ce document.

Facebook reconnaît avoir subi des campagnes de désinformation pendant la présidentielle américaine - Politique - Numerama

Dans ce rapport de 13 pages, les chercheurs estiment que les phénomènes observés vont bien au-delà des simples fake news : ils préfèrent parler de « campagne de désinformations » menée par des gouvernements étrangers et par des agents externes rémunérés à cette fin. Selon eux, ces manœuvres auraient en effet été opérées manuellement plutôt que par des bots.

Open Data : l’État modernise sa Licence Ouverte pour les administrations
“Markets Today Are Radically Different Than What We Believe - We Have the Façade of Competition" -

A Stigler Center panel explores the implications of big data for competition policy and for consumer welfare.     The business model at the heart of the digital economy is a simple one: Internet giants such as Google and Facebook provide consumers with “free” services—free email, free GPS, free instant messaging, free search—and in return consumers consent to hand over vast amounts of their own data, which the companies then use to target advertisers.   This exchange helped make data the “new” oil, creating “new infrastructure, new businesses, new monopolies, new politics and—crucially—new economics,” according to The Economist. To a large degree, …

Amazon's app store compromises Android security | ZDNet
Cloak and Dagger: From Two Permissions to Complete Control of the UI Feedback Loop

Cloak & Dagger is a new class of potential attacks affecting Android devices. These attacks allow a malicious app to completely control the UI feedback loop and take over the device — without giving the user a chance to notice the malicious activity. These attacks only require two permissions that, in case the app is installed from the Play Store, the user does not need to explicitly grant and for which she is not even notified. Our user study indicates that these attacks are practical. These attacks affect all recent versions of Android (including the latest version, Android 7.1.2), and they are yet to be fixed.

CCC | Chaos Computer Clubs breaks iris recognition system of the Samsung Galaxy S8
“I have nothing to hide. Why should I care about my privacy?”

This is why.

Hacked in Translation - from Subtitles to Complete Takeover | Check Point Blog

Check Point researchers revealed a new attack vector which threatens millions of users worldwide – attack by subtitles. By crafting malicious subtitle files, which are then downloaded by a victim’s media player, attackers can take complete control over any type of device via vulnerabilities found in many popular streaming platforms, including VLC, Kodi (XBMC), Popcorn-Time …

Numérique : les grands chantiers du président Macron

Emmanuel Macron pense que les logiciels libres jouent un « rôle essentiel » dans la future « stratégie globale d'achat numérique » de l'État.

Etcher : L'outil d'écriture USB open-source - CitizenZ
Exclusif - Microsoft : menace sur la sécurité de l'Etat

Alors qu'une cyberattaque exploitant une faille de Windows touche des dizaines de milliers d'ordinateurs dans le monde, le ministère de la Défense a reconduit son contrat avec Microsoft. Bill Gates a, quant à lui, été décoré de la Légion d'honneur. Marianne s'est penché sur les liens étroits entre la firme de Redmond et l'Etat français.

WikiLeaks Dump Shows CIA Could Turn Smart TVs into Listening Devices

One revelation from the cache of 8,000 CIA documents: the CIA can turn a voice-recognition feature of some Samsung TVs into a covert listening device.

The book "Chaos Monkeys"[1], while irritating in many ways, has a detailed descr... | Hacker News

The book "Chaos Monkeys"[1], while irritating in many ways, has a detailed description of how Facebook correlates its own advertising data with information from data brokers (such as credit card transaction aggregators). This kind of stuff has been happening for quite some time. (As an extra bonus, the book describes how the author's ad-tech startup got into YC and was bought by Twitter.)

[1] https://www.amazon.com/dp/B019MMUAAQ

Facebook's Advertisers to Hijack Your Status Updates and Use You in Their Ads - CBS News

There's nothing you can do about it either, as Facebook's terms of service give Facebook the right to use anything you post on the social network as if it were Facebook's own.

Google starts tracking offline shopping — what you buy at stores in person - LA Times

Google says it has access to roughly 70% of U.S. credit and debit card transactions through partnerships with companies that track that data. By matching ad clicks with this data, Google says it can automatically inform merchants when their digital ads translate into sales at a physical store.

WannaCry : comment détecter la faille sur vos machines (nmap)
MacKeeper™ Security
500 millions d'identifiants en fuite sur Internet

Un énorme fichier de comptes utilisateurs volés

The great British Brexit robbery: how our democracy was hijacked | Technology | The Guardian

A shadowy operation involving big data, billionaire friends of Trump and the disparate forces of the Leave campaign heavily influenced the result of the EU referendum. Is our electoral process still fit for purpose?

Even when told not to, Windows 10 just can’t stop talking to Microsoft | Ars Technica

It's no wonder that privacy activists are up in arms.

Google veut former 70 000 personnes aux métiers du numérique en France

Aider les TPE/PME à réussir la mutation numérique

Why Do Not Track is worse than a miserable failure | ZDNet

As a consumer, you'd think that the meaning of "Do Not Track" is pretty clear. But the big data-collecting companies that are behind this standard seem intent on making sure it does nothing at all.

Facebook blocks Pulitzer-winning reporter over Malta government exposé | World news | The Guardian

Temporary censorship of Matthew Caruana Galizia – who worked on the Panama Papers – raises concern over Facebook’s power to shape the news

Zomato Blog — Security Notice
Presentator.io
Presentator.io: Une plateforme collaborative Libre pour faire des prototypes
Uber Doesn’t Want You to See This Document About Its Vast Data Surveillance System
While Microsoft griped about NSA exploit stockpiles, it stockpiled patches: Friday's WinXP fix was built in February • The Register

And it took three months to release despite Eternalblue leak

How to Easily Unsubscribe from Bulk Emails in Gmail - Unroll.me Alternative

How to easily unsubscribe your Gmail email address from mailing lists, newsletters, junk and other unsolicited bulk mail that is clogging up your Gmail inbox.

Hundreds of Apps Can Listen for Marketing ‘Beacons’ You Can’t Hear – WIRED | WIRED
Google and Facebook Reap Almost All Digital Ad Growth | Fortune.com

Digital ad revenue in the U.S. grew by more than 20% last year to a record $72.5 billion, according to the Interactive Advertising Bureau. That's the good news.

The bad news—at least for those who dislike duopolies—is that some estimates by other industry experts show that virtually all of growth in digital ad spending went to Google and Facebook, which already account for more than three-quarters of the U.S. digital ad market.

WhatsApp condamnée en Italie pour son partage de données avec Facebook

L’autorité de la concurrence italienne a annoncé, vendredi 12 mai, avoir infligé une amende de 3 millions d’euros à l’application de messagerie.

Le partenariat entre Google DeepMind et les hôpitaux londoniens à nouveau critiqué

L’affaire avait fait grand bruit au printemps dernier : DeepMind, une entreprise d’intelligence artificielle appartenant à Google et basée à Londres, s’était vu transmettre les données de 1,6 million de patients des hôpitaux londoniens du NHS, le service de santé britannique, dans le cadre d’un partenariat. Mais l’une des principales bases légales de cet accord serait « inappropriée », selon le National Data Guardian (NDG), un organisme gouvernemental chargé de veiller sur les données de santé.

Les outils de surveillance de Marine Le Pen ou d'Emmanuel Macron, élu(e) président(e)

C’est dans moins d’une semaine que l’on connaîtra le nom du futur locataire de l’Élysée : Marine Le Pen ou Emmanuel Macron. Les électeurs s’exprimeront démocratiquement dans les urnes dimanche. Une excellente occasion pour revenir sur les pouvoirs de surveillance qui résideront dans ces nouvelles mains.

Derrière le cas Unroll.Me, la question de la revente peu transparente de données personnelles

Le service « gratuit » Unroll.Me est au cœur d'une tourmente, après avoir vendu des informations issues des boites emails de ses utilisateurs. Ce cas souligne la difficulté de connaître l'utilisation concrète de nos données personnelles, anonymisées ou non, alors que la législation se renforce bientôt sur le sujet en Europe.

Locked in by choice: How European governments are handling their Microsoft addiction

Microsoft has built such an empire inside the European public sector that attempts to challenge its dominant position are rarely successful. Nevertheless, some government agencies have managed to migrate to open source alternatives. How have they done it?

Reverse-engineering the Intel Management Engine’s ROMP module – Purism
How to Protect and Harden a Computer against Ransomware

2016 is almost over and it definitely taught us one thing; Ransomware is here to stay and it's only going to get worse. This guide contains tips and steps that every computer user needs to do in order to protect their data from ransomware.

RansomwareDetectionService/README.md at master · prestoncooper/RansomwareDetectionService · GitHub

RansomwareDetectionService - This program detects all present and future ransomware in Windows file shares or local drives for Windows file servers. I created this windows service to aide system a...

GitHub - schollz/howmanypeoplearearound: Count the number of people around you by monitoring wifi signals

howmanypeoplearearound - Count the number of people around you by monitoring wifi signals

Cisco's Talos Intelligence Group Blog: Player 3 Has Entered the Game: Say Hello to 'WannaCry'

A blog about the world class Intelligence Group, Talos, Cisco's Intelligence Group

Snapchat perd de l'argent, mais raille ses concurrents qui le copient

Ainsi, on apprend que chaque utilisateur a rapporté à Snapchat 0,90 $ sur les trois premiers mois de l'année, tandis qu'il aura coûté 0,60 $ au service. Snapchat revendique 166 millions d'utilisateurs échangeant environ 2,5 milliards de snaps par jour.

[EN] Keylogger in Hewlett-Packard Audio Driver | mod%log
Test antivirus software for Android - March 2017 | AV-TEST

The current tests of antivirus software for Android from March 2017 of AV-TEST, the leading international and independent service provider for antivirus software and malware.

The Document Foundation announces LibreOffice 5.3.3 - The Document Foundation Blog
Bugtraq: Multiple Vulnerabilities in ASUS Routers [CVE-2017-5891 and CVE-2017-5892]
OS mobiles : iOS reste fort aux USA, Android ultra dominateur en Chine

Un premier trimestre sans surprise

A new UX 6 years in the making – F-Droid
Holography with the Wi-Fi-router - TUM

Scientists at the Technical University of Munich (TUM) have developed a holographic imaging process that depicts the radiation of a Wi-Fi transmitter to generate three-dimensional images of the surrounding environment. Industrial facility operators could use this to track objects as they move through the production hall.

Leaked document reveals UK plans for wider internet surveillance | ZDNet

The UK government is soliciting feedback from a handful of internet providers, but isn't consulting the tech industry or the public.

There's two things that don't get mentioned much with this issue. 1. There's a ... | Hacker News

There's two things that don't get mentioned much with this issue.

  1. There's a second bug that allows non-root local users to provision AMT. "An unprivileged local attacker could provision manageability features"[1]

  2. Access to AMT allows you to boot a recovery image, mount local drives, and do whatever you like with the included remote KVM.[2][3]

So, even if this is turned off, there are issues to address. If it's on, they have control of the whole machine, remotely. It's as bad as it can get.

Something similar has happened with Transmission's download DMGs being replaced ... | Hacker News

Something similar has happened with Transmission's download DMGs being replaced on their servers [1] (twice! [2]) in recent memory.

Facebook : 700 000 utilisateurs "manipulés" pour une expérience sur la contagion émotionnelle - ZDNet

Publicité ciblée en fonction des statuts et des messages, profils commercialisés, collecte de données... Facebook est connu pour son goût pour vos informations personnelles. Mais cette fois, le roi des réseaux sociaux est-il allé trop loin ?

On apprend en effet que près de 700.000 utilisateurs anglophones de Facebook ont été le sujet d'une expérience scientifique sans le savoir. Pendant une semaine, en janvier 2012, Facebook et des scientifiques des universités Cornell et de Californie à San Francisco ont voulu savoir si les émotions exprimées par les contacts de ces utilisateurs influençaient leur humeur. En somme, quelle est la "contagion émotionnelle" de Facebook.

Mais il ne s'agissait pas d'une simple observation empirique. Les scientifiques ont modifié les flux d'actualité de 689 003 personnes en bougeant le curseur du nombre de messages positifs et négatifs et observer les réactions sur "l'humeur" des cobayes... Concrètement, certains utilisateurs étaient exposés à plus de messages positifs, d'autres à des statuts plutôt négatifs et un dernier groupe à des messages neutres.

More Android phones than ever are covertly listening for inaudible sounds in ads | Ars Technica

In December 2015, a Salesteam from Shazam music recognition app came by our office in Amsterdam to sell ads targeted and synchronized with TV commercials. Earlier that year they had done this with several big US advertisers: iPhones (and/or Android devices, I don't remember but their pitch was specific about the supported platform) with the Shazam app were constantly listening via the phone mic, when they recognised a Pepsi commercial, the app would register this and next time you open Shazam you would see a targeted ad. You had the ability to then target users even in other ad-supported apps and follow them via the Apple Advertising ID.

Open source growth in Bourgogne-Franche-Comté | Joinup
Et si l'Open Hardware démocratisait l'usage d'ordinateurs reconditionnés ? - LinuxFr.org
Et si on achetait des serveurs Open Hardware ? - LinuxFr.org
Facebook fonce sur les 2 milliards d'utilisateurs et bat des records

Les finances au beau fixe

Facebook peut-il aider les annonceurs à cibler les ados vulnérables ?

On y apprend que Facebook est a priori capable d'identifier les changements d'humeur soudains chez ses utilisateurs et de s'en servir à des fins commerciales. Les algorithmes analyseraient pour cela les statuts, réponses et photos postés, et pourraient en déduire si les utilisateurs sont nerveux ou bouleversés par quelque chose. Ils seraient également capables de repérer quand les adolescents "se sentent à l'aise avec leur corps" ou "souhaitent faire du sport pour perdre du poids". Il n'en faut pas plus pour être interloqué, certains imaginant, par exemple, Facebook être en mesure de profiter d'un état dépressif pour vendre des anti-dépresseurs...

Intel & ME, and why we should get rid of ME — Free Software Foundation — working together for free software

If you did not know, built into all modern Intel-based platforms is a small, low-power computer subsystem called the Intel Management Engine (ME). It performs various tasks while the system is in sleep mode, during the boot process, and also when your system is running.

I'm an ex-Facebook exec: don't believe what they tell you about ads | Technology | The Guardian

The ethics of Facebook’s micro-targeted advertising was thrust into the spotlight this week by a report out of Australia. The article, based on a leaked presentation, said that Facebook was able to identify teenagers at their most vulnerable, including when they feel “insecure”, “worthless”, “defeated” and “stressed”.

Facebook claimed the report was misleading, assuring the public that the company does not “offer tools to target people based on their emotional state”. If the intention of Facebook’s public relations spin is to give the impression that such targeting is not even possible on their platform, I’m here to tell you I believe they’re lying through their teeth.

mjg59 | Intel's remote AMT vulnerablity
Facebook se vante auprès d’annonceurs d’être capable de détecter les adolescents vulnérables

Facebook a-t-il tenté de séduire des annonceurs en leur expliquant qu’il pouvait, en temps réel, identifier les adolescents se sentant « vulnérables », « inutiles » et « ayant besoin de regagner confiance en eux » ? C’est en tout cas ce qu’affirme dans un article publié lundi 1er mai le journal The Australian, qui a eu accès à un document interne récent de 23 pages destiné à être présenté à une grande banque australienne.

Un développeur dérobe 40 000 photos sur Tinder pour alimenter les IA de reconnaissance faciale - Tech - Numerama

Un développeur a créé un script permettant de récupérer facilement des photos de profil Tinder pour en faire des outils d'entraînement destinés aux intelligences artificielles de reconnaissance faciale. Les 40 000 photos dérobées, un temps accessibles en téléchargement libre, ont depuis été supprimées.

Revue de presse de l'April pour la semaine 17 de l'année 2017 | April
Information Operations and Facebook [PDF]
Nouveau record des demandes d’infos sur des comptes Facebook par la France - Politique - Numerama

Le dernier rapport de transparence de Facebook ne déroge pas à cette règle, signe à la fois que la plateforme attire de plus en plus de monde et devient chaque jour un peu plus l’un des lieux privilégiés de sa vie numérique. Couvrant la période du second semestre 2016, il montre en effet que les requêtes hexagonales adressées à Facebook sont passées à 4 478 pour 5 195 comptes ou utilisateurs. Six mois auparavant, elles ne concernaient « que » 3 763 requêtes pour 4 045 comptes ou utilisateurs.

Why Google Is Suddenly Obsessed With Your Photos – The Ringer

The next great Google product offers a window into a company reshaping itself around images, AI, and even more of your data

British Airways: Thousands disrupted as flights axed amid IT crash - BBC News

Boss says power cut behind IT problem which saw all flights from Heathrow and Gatwick cancelled.

How Facebook's tentacles reach further than you think - BBC News

Share Lab uses flow charts and data analysis to map one of the greatest forces shaping our world - Facebook.

GitHub - oguzhaninan/Stacer: Linux System Optimizer and Monitoring

Linux System Optimizer and Monitoring

Updating Logitech Hardware on Linux – Technical Blog of Richard Hughes
What I Learned When Facebook Disabled My Account - Optimization Today
Sortie de passbolt v1.5.0, avec “groupes” - LinuxFr.org
Galicia continues promotion of free software | Joinup

The government of the autonomous region of Galicia (Spain) will continue to encourage the use of free and open source software solutions in the public and private sector. This week, the government published the ‘Free Software Plan 2017’, outlining 110 actions.

Judge: It's OK If Best Buy's Geek Squad Nerds Search Your PC for Illegal Content

A judge presiding over a child pornography case that was set in motion in 2012 has ruled that users have no legal expectation of privacy when they hand over their computers to Best Buy's Geek Squad IT technicians.

Barack Obama's team secretly disclosed years of illegal NSA searches spying on Americans | Circa News - Learn. Think. Do.

The National Security Agency under former President Barack Obama routinely violated American privacy protections while scouring through overseas intercepts and failed to disclose the extent of the problems until the final days before Donald Trump was elected president last fall, according to once top-secret documents that chronicle some of the most serious constitutional abuses to date by the U.S. intelligence community.

« Facebook affirme qu’il n’a pas de rôle éditorial, mais les documents attestent du contraire »

Sarah Roberts, chercheuse en sciences de l’information à l’université de Californie de Los Angeles, revient sur le contenu des guides de modération publiés par le « Guardian ».

L’addiction de l’Europe à Microsoft, un énorme risque pour la sécurité – Framablog

L’équipe de journalistes d’Investigate Europe s’est lancée pendant trois mois dans une mission d’exploration pour établir des faits et interviewer des économistes, des responsables informatiques, des experts en sécurité et des politiciens dans douze pays européens, ainsi qu’à la Commission et au Parlement européens. Les résultats sont inquiétants.

La dépendance des États envers Microsoft :

• engendre des coûts en hausse constante et bloque le progrès technique au sein des autorités publiques ;
• contourne systématiquement les lois européennes en matière de passation des marchés et de règles de concurrence ;
• introduit une influence politique étouffante de la part de cette entreprise ;
• crée pour les systèmes informatiques étatiques, ainsi que pour les données de leurs citoyens, un grand risque technique et de sécurité politique.

Facebook Tinkers With Users’ Emotions in News Feed Experiment, Stirring Outcry - NYTimes.com
Facebook Failed to Protect 30 Million Users From Having Their Data Harvested by Trump Campaign Affiliate

Survey participants didn’t know that operatives hired to influence U.S. voters were harvesting “likes” and demographic data from their Facebook profiles.

The Future of Ransomware - Schneier on Security
Get your loved ones off Facebook. - Salim Virani

I originally wrote this for my friends and family in 2015, to explain why the latest Facebook privacy policy is really harmful. It’s since been read by over a million people, and I updated it earlier thise year. External references – and steps to get off properly – at the bottom. Oh, and if you’re interested in a privacy-friendly way to stay in touch with friends, I’m looking into making a simple phone app for easy sharing.

Kill Google AMP before it KILLS the web • The Register

So it's not really about speed. As with anything that eschews standards for its own modified version thereof, it's about lock-in. Tons of pages in Google AMP markup mean tons of pages that are optimized specifically for Google and indexed primarily by Google and shown primarily to Google users. It's Google's attempt to match Facebook's platform. And yes, Facebook is far worse than AMP, but that doesn't make Google AMP a good idea. At least Facebook doesn't try to pretend like it's open.

Mark Burnett sur Twitter : "I have this Win10 Enterprise vm that I was using to test out various privacy settings. Here's some of the stuff I found out so far..."
How to Opt Out of Twitter's New Privacy Settings | Electronic Frontier Foundation

Since Wednesday night, Twitter users have been gre

Twitter abandons 'Do Not Track' privacy protection | ZDNet

Is this the end for 'Do Not Track', the web-tracking privacy service?

Ben Thompson sur Twitter : "Google Home does not work unless you give Google your browser and app history. https://t.co/URtCAGzC5B"

Google Home does not work unless you give Google your browser and app history.

Turn Your Smartphone Into a Laptop | Indiegogo

Simply connect your smartphone to the Mirabook and unleash the power to do more with less | Crowdfunding is a democratic way to support the fundraising needs of your community. Make a contribution today!

1.9 million Bell customer email addresses stolen by 'anonymous hacker' - Technology & Science - CBC News

Bell attributes the leak to "an anonymous hacker" and says it is working with the RCMP.

WannaCrypt : un ransomware pas si rentable et de nouvelles attaques

Et ça continue, encore et encore

Face au numérique, sommes-nous tous des moutons ?

Si les nouvelles technologies sont réellement portées par ces projets de contrôle des masses, quelle marge de manoeuvre nous reste-t-il ? Quelle responsabilité avons-nous encore face aux méandres algorithmiques ?

Cybersecurity for the People: How to Keep Your Chats Truly Private With Signal
WannaCry, l’attaque systémique tant redoutée

Il faut d’abord que vous fassiez la mise à jour de votre système Windows par l’application du patch MS17-010 mis à disposition par l’éditeur dès le 14 mars 2017.

La 2e solution plus radicale est de couper votre service LanmanServer. Votre machine ne pourra plus se faire contaminer par les machines infectées présentes dans votre réseau. La plupart des stations de travail n’ont d’ailleurs pas besoin que les autres ordinateurs du réseau accèdent à leurs fichiers !

Vous pouvez aussi décider de désactiver le protocole SMBv1

Données personnelles : Facebook condamné par la CNIL à 150 000 euros d’amende

L’autorité de protection des données personnelles pointe « de nombreux manquements à la loi Informatique et libertés ». Elle lui reproche notamment d’avoir tracé des internautes « avec ou sans compte ».

Adylkuzz Cryptocurrency Mining Malware Spreading for Weeks Via EternalBlue/DoublePulsar | Proofpoint
SecNum académie
Conseil d'État, 7ème et 2ème sous-sections réunies, 30/09/2011, 350431, Publié au recueil Lebon | Legifrance

Résumé : 39-02-04 Pour l'application du IV de l'article 6 du code des marchés publics, il y a lieu, s'agissant des marchés de services, d'examiner si la spécification technique a ou non pour effet de favoriser ou d'éliminer certains opérateurs économiques puis, dans l'hypothèse seulement d'une telle atteinte à la concurrence, si cette spécification est justifiée par l'objet du marché ou, si tel n'est pas le cas, si une description suffisamment précise et intelligible de l'objet du marché n'est pas possible sans elle.... ...En l'espèce, les prestations faisant l'objet du marché de services consistaient en l'intégration et l'adaptation aux besoins de la collectivité d'une solution logicielle qui, eu égard à son caractère de logiciel libre, était librement et gratuitement accessible et modifiable par l'ensemble des entreprises spécialisées qui étaient ainsi toutes à même de l'adapter aux besoins de la collectivité et de présenter une offre indiquant les modalités de cette adaptation. La spécification par les documents de la consultation d'un logiciel libre ne confère pas d'avantage concurrentiel à une société co-conceptrice et copropriétaire de ce logiciel, alors que toute entreprise spécialisée dans l'installation de logiciels de ce type avait la capacité d'adapter ce logiciel aux besoins spécifiés.

Microsoft outspends world's tech firms with '€5m' EU lobby bill • The Register

Microsoft spends more than any other tech company in the world on lobbying the EU, if you believe the figures in the non-obligatory EU Transparency Register.

A new online tool called LobbyFacts.eu allows data from the register to be automatically sorted, compared, ranked and analysed in ways not possible through the official EU site. It calculates that Microsoft is number three in the lobbying stakes, spending €4.75m per year, behind tobacco giant Philip Morris and petrol company ExxonMobil.

Se protéger des rançongiciels
Blaze's Security Blog: Ransomware Prevention

CryptoLocker, cryptoware, encrypting ransomware, ransomware prevention

Microsoft Issues WanaCrypt Patch for Windows 8, XP — Krebs on Security
WannaCry ransomware used in widespread attacks all over the world - Securelist

Earlier today, our products detected and successfully blocked a large number of ransomware attacks around the world. In these attacks, data is encrypted with

Europe's reliance on Microsoft has governments under a worrying digital 'killswitch'

It’s estimated that Microsoft makes around two billion euros in Europe every year, just from its business with the public sector. In 2012 the European Commission released a report that stated that 1.1 billion euros were unnecessarily lost by the European public sector due to being locked-in in business with IT system providers.

Certains PC HP analysent vos frappes de clavier en douce

Une mise à jour s'impose

Le premier micro-ordinateur mis aux enchères

16 Ko de mémoire vive

Comment déjouer jusqu'à 94% des vulnérabilités critiques découvertes dans Windows et les outils Microsoft ? - Korben

La société Avecto qui fournit des solutions de sécurité, a analysé l'intégralité des patchs fournis par Microsoft en 2016 et a pondu un petit rapport que vous pouvez télécharger ici. Et la conclusion est sans appel : 94% des vulnérabilités critiques découvertes et publiées lors des fameux "Patch Tuesday" peuvent être déjouées en utilisant un > Lire la suite

“Google Is as Close to a Natural Monopoly as the Bell System Was in 1956" -

Media scholar Jonathan Taplin, author of the new book Move Fast and Break Things, on the rent-seeking and regulatory capture of digital platforms.     In 2014, Silicon Valley venture capitalist Peter Thiel famously proclaimed that “competition is for losers” in an essay published in the Wall Street Journal and in his book (also published in 2014) Zero to One. “If you want to create and capture lasting value, look to build a monopoly,” he advised entrepreneurs, expounding on his view that monopolies are good for innovation and, ultimately, for society at large.    Thiel’s proclamation has received a lot …

Exclusive: Uber faces criminal probe over software used to evade authorities | Reuters

The U.S. Department of Justice has begun a criminal investigation into Uber Technologies Inc's use of a software tool that helped its drivers evade local transportation regulators, two sources familiar with the situation said.

The hijacking flaw that lurked in Intel chips is worse than anyone thought | Ars Technica

Patch for severe authentication bypass bug won’t be available until next week.

HiFive1 | SiFive

SiFive is the first fabless semiconductor company to build customized silicon based on the free and open RISC-V instruction set architecture.

Don’t Let Facebook Make You Miserable - NYTimes.com

I have actually spent the past five years peeking into people’s insides. I have been studying aggregate Google search data. Alone with a screen and anonymous, people tend to tell Google things they don’t reveal to social media; they even tell Google things they don’t tell to anybody else. Google offers digital truth serum. The words we type there are more honest than the pictures we present on Facebook or Instagram.

Facebook: Facebook is a surveillance engine, not friend: Richard Stallman, Free Software Foundation - The Economic Times
Windows 10's 'built-in keylogger'? Ha ha, says Microsoft – no, it just monitors your typing • The Register

The Technical Preview also phones home with data about the files you open and "performance or usage information," including what program features you use most often and how long the system takes to respond to clicks.

And then there's this gem, which is the one that got everyone moaning about keyloggers:

[When you] enter text, we may collect typed characters and use them for purposes such as improving autocomplete and spellcheck features.
Don’t Build a Database of Ruin

Companies need to say “no” to privacy-invading innovations.

How Privacy Became a Commodity for the Rich and Powerful - NYTimes.com
Don’t Let Facebook Make You Miserable - NYTimes.com
Something is wrong when the ‘telephone app’ on your phone becomes 3rd party

Since I am not living in my home country, I frequently use two different SIM cards and prefer having a phone with dual-sim support. This limits your choice s...

[1705.01176] How does Docker affect energy consumption? Evaluating workloads in and out of Docker containers
Majority of towns in Wallonia now use open source | Joinup

The majority (75%) of municipalities in the Walloon region of Belgium are now using open source software and services. In the region 261 cities, towns, villages and other public administrations are using 8 open source-based solutions that are centrally managed and maintained by Intercommunale de Mutualisation Informatique et Organisationnelle (IMIO), an IT service provider set up in 2011 by the Walloon government.

Is The GPL Really Declining? | Meshed Insights Ltd

Is the GNU GPL “dying” or is that just the prejudice of those whose open source exploitation would be hampered by its use? At the huge FOSDEM developer meetup in Brussels in early Febru…

Who Is Publishing NSA and CIA Secrets, and Why? - Lawfare

There's something going on inside the intelligence communities in at least two countries, and we have no idea what it is.

CIA, MI5 hacked smart TVs to eavesdrop on private conversations | ZDNet

The malware, developed during a hackathon between British and American spies, turns ordinary smart TVs into listening devices.

How Purism avoids Intel’s Active Management Technology – Purism

With recent chipsets, Intel offers a mechanism called Active Management Technology (Intel AMT, part of the “vPro”* featureset, specifically the Intel Management Engine) which, Intel says,“allows IT or managed service providers to better discover, repair, and protect their networked computing assets”. This means somebody can control devices remotely, even when powered off—what is officially called out-of-band system access.

Reined-In N.S.A. Still Collected 151 Million Phone Records in ’16 - The New York Times

The National Security Agency vacuumed up more than 151 million records about Americans’ phone calls last year via a new system that Congress created to end the agency’s once-secret program that collected domestic calling records in bulk, a report disclosed Tuesday.

Although the number is large on its face, it nonetheless represents a massive reduction from the amount of information the agency gathered previously. Under the old system, it collected potentially “billions of records per day,” according to a 2014 study.

Report: Facebook helped advertisers target teens who feel “worthless” [Updated] | Ars Technica

According to the report, the selling point of this 2017 document is that Facebook's algorithms can determine, and allow advertisers to pinpoint, "moments when young people need a confidence boost." If that phrase isn't clear enough, Facebook's document offers a litany of teen emotional states that the company claims it can estimate based on how teens use the service, including "worthless," "insecure," "defeated," "anxious," "silly," "useless," "stupid," "overwhelmed," "stressed," and "a failure."

The Australian says that the documents also reveal a particular interest in helping advertisers target moments in which young users are interested in "looking good and body confidence” or “working out and losing weight." Another section describes how image-recognition tools are used on both Facebook and Instagram (a wholly owned Facebook subsidiary) to reveal to advertisers "how people visually represent moments such as meal times." And it goes into great detail about how younger Facebook users express themselves: according to Facebook Australia, earlier in the week, teens post more about "anticipatory emotions" and "building confidence," while weekend teen posts contain more "reflective emotions" and "achievement broadcasting."

Quelle distribution Linux légère peut-on utiliser pour ressusciter un vieil ordinateur ? - Tech - Numerama
L'Union européenne et l'épineux problème de la dépendance aux logiciels Microsoft - Tech - Numerama

Cette problématique d’« enfermement propriétaire » est connue de longue date au sein de l’UE. En 2013, elle a publié un guide pour inciter les gouvernements à lutter contre en se tournant vers les logiciels libres. « Les standards ouverts créent de la concurrence, favorisent l’innovation et permettent d’économiser de l’argent » précise alors la commissaire de la concurrence Neelie Kroës. À l’inverse, continuer d’investir dans des services compatibles avec Windows (comme les documents et factures en ligne) ne fait qu’entretenir cette dépendance dont il devient de fait encore plus difficile de sortir.