Monthly Shaarli

All links of one month in a single page.

March, 2020

Marriott discloses new data breach impacting 5.2 million guests - CNET

The hotel group is sending emails to guests affected by the breach.

Zoom Meetings Do Not Support End-to-End Encryption

The video conferencing service can access conversations on its platform.

Mobilisation des GAFA contre la pandémie Covid-19 : business as usual

L’étude des différentes stratégies de communication des géants du web montre comment ils s’adaptent et tirent profit, chacun différement, du confinement qui touche désormais un milliard d’humains.

Pourquoi la position dominante d'Amazon est un désastre | korii.

Sa logistique est indispensable à 64% des boutiques de sa marketplace: la dépendance est totale. Alors que le nombre de pays où la population est placée en quarantaine s'accroît chaque jour un peu plus, les entreprises de livraison sont inondées de commandes et forcées de s'adapter...

« Les mesures de surveillance high-tech contre l'épidémie de Covid-19 survivront au virus et pourront devenir permanentes », prévient Snowden à propos de méthodes comme le traçage de smartphones

Nombreux sont les gouvernements du monde entier qui utilisent déjà des mesures de surveillance high-tech dans le combat contre la pandémie de Covid-19. À Singapour par exemple, les personnes susceptibles d'avoir fait l’objet d’exposition au nouveau coronavirus (en particulier celles qui revenaient de l'étranger) ont été soumises à des périodes d'isolement à domicile de 14 jours. Les patients confirmés pour leur part ont été hospitalisés. Le contrôle du respect des périodes d’isolement prescrites...

zotero-scihub/README.md at master · ethanwillis/zotero-scihub · GitHub

A plugin that will automatically download PDFs of zotero items from sci-hub - ethanwillis/zotero-scihub

Zoom needs to clean up its privacy act

As quarantined millions gather virtually on conferencing platforms, the best of those, Zoom, is doing very well. Hats off. But Zoom is also—correctly—taking a lot of heat for its privacy policy, wh…

Zoom iOS App Sends Data to Facebook Even if You Don’t Have a Facebook Account - VICE

Zoom's privacy policy isn't explicit about the data transfer to Facebook at all.

I Got My File From Clearview AI, and It Freaked Me Out

Here’s how you might be able to get yours

Chrome Phasing out Support for User Agent

Google announced its decision to drop support for the User-Agent string in its Chrome browser. Instead, Chrome will offer a new API called Client Hints that will give the user greater control over which information is shared with websites.

resilience/README.md at master · kaepora/resilience · GitHub

Resilience is an ad blocker for your computer. Contribute to kaepora/resilience development by creating an account on GitHub.

Researchers Say Microsoft Edge's Telemetry Has the Worst Privacy of Any Major Browser - WinBuzzer

A research paper suggests the data Microsoft Edge sends to its back-end servers has a persistent hardware-based identifier which could be used to find a user's identity.

En vrac du mercredi - Standblog
Federal government in talks with tech groups to use phone location data to track coronavirus: report | TheHill

The federal government is in talks with Facebook, Google and other tech companies about ways to use smartphone location data to tackle the coronavirus,

Librem 5 review: The Linux-based smartphone is not close to consumer ready - TechRepublic

There could be a method to Purism's madness, because the Librem 5 mobile device proves one very important thing.

Popular iPhone and iPad Apps Snooping on the Pasteboard | Mysk

By Talal Haj Bakry and Tommy Mysk If you enjoyed this work, you can support us by checking out our apps: Ctrl - The best presentation companion...

This PIN Can Be Easily Guessed

A comprehensive study of user-chosen 4- and 6-digit smartphone unlock PINs.

Google secretly monitors millions of schoolkids, lawsuit alleges - CBS News

New Mexico AG claims the company uses its dominance in educational software to track millions of future customers.

Australia sues Facebook over Cambridge Analytica, fine could scale to $529BN | TechCrunch
The De-Googled Android Fork is Making Good Progress - It's FOSS

Gael Duval, the head of the /e/ mobile OS, shares the progress on his mission to create an open source Android fork that is free from Google.

With apps, Babel Street's Locate X allows US phone tracking - Protocol

Federal agencies have big contracts with Virginia-based Babel Street. Depending on where you've traveled, your movements may be in the company's data.

cpni-notice
The Case for Limiting Your Browser Extensions — Krebs on Security
I don't care about cookies – Get this Extension for 🦊 Firefox Android (en-US)

Download I don't care about cookies for Firefox. Get rid of cookie warnings from almost all websites!

Leaked Document Shows How Big Companies Buy Credit Card Data on Millions of Americans - VICE

Yodlee, America’s largest financial data broker, says the data it sells it is anonymous. A confidential document obtained by Motherboard shows people could be unmasked in the data.

Daring Fireball: Zoom Falsely Claims Its Group Video Can Be End-to-End Encrypted
Confinement : 5 questions sur la probable surveillance par nos smartphones - Le Parisien

Afin de contrôler les déplacements, de nombreux pays mettent en place des applications ou exploitent les données mobiles. Une pratique polém

Zoom, Google Meet, Classroom, Microsoft Teams, Youtube: la crise du coronavirus aggrave notre dépendance aux géants de la tech

Télétravail, relations sociales ou actes citoyens: il est impossible d’échapper aux solutions proposées par les grands acteurs technologiques américains. En temps de crise, cela peut se révéler dangereux

Orange recycle son service de géolocalisation pour la pandémie – La Quadrature du Net

Depuis des années, Orange cherche à commercialiser la mine d'or que sont nos données de géolocalisation (la liste des antennes-relais auxquelles nos téléphones se connectent au fil la journée). La pandémie semble être pour l'entreprise une bonne occasion d'ouvrir son marché.

Flux Vision

En 201

Poland is making quarantined citizens use a selfie app to prove they're staying inside - CBS News

App users will get a random request for a selfie and they have 20 minutes to upload it or else the police will pay them a visit

Comment un VPN espion a permis à Facebook de s'offrir WhatsApp | korii.

Une app israélienne transformée en mouchard servait à observer la croissance du service de messagerie. Quand Facebook a déboursé 19 milliards de dollars (17,5 milliards d'euros) pour acheter WhatsApp en février 2014, beaucoup se sont demandés si Mark Zuckerberg n'avait pas perdu...

Zoom and Houseparty: Video Calling at Your Own (Privacy) Risk | VPNoverview.com

Now that a lot of people are working from home because of the corona crisis, many companies organize their meetings through video calling. Apps such as Google Hangouts, Skype and Zoom are very popular services right now. However, Zoom might not be the best option for your privacy. Many people are also using similar apps …

The FBI is promoting an at-home exercise app that also tracks your phone's location and data

The FBI suggested that people stuck indoors during the coronavirus pandemic download its workout app, but users questioned why it collected so much data.

https://news.northeastern.edu/2014/10/23/ecommerce-study/ The actual paper: htt... | Hacker News

https://news.northeastern.edu/2014/10/23/ecommerce-study/

The actual paper: http://www.ccs.neu.edu/home/cbw/static/pdf/imc151-hannak.pdf...

"As shown in Figure 11, Travelocity alters hotel search results for users who browse from iOS devices." (In particular, alters the prices shown to the user).

Tom Slee sur Twitter : "Turns out the claims Airbnb was taking houses out of the rental market were right after all. https://t.co/AqVBUr9GDU" / Twitter
En vrac sur le numérique - Standblog
Yahoo!, AOL, OneSearch results biased in favor of parent company Verizon Media’s websites | Ctrl blog

Verizon Media’s search engines promises “unbiased” search results, but serves results clearly favoring the parent company’s media websites.

Coronavirus economics could tilt the scales in favor of Amazon — permanently

As people are staying home to help prevent the spread of the coronavirus, Amazon is seeing an increase in demand as small businesses suffer.

Apple fined $1.2 billion by French competition authorities

The French competition authority said Apple and two wholesalers agreed not to compete on prices and distribution, "thereby sterilizing the wholesale market for Apple products."

New flaw in Intel chips lets attackers slip their own data into secure enclave | TechCrunch
Who’s Allowed to Track My Kids Online? – The Markup

What the United States’ children’s privacy law does and doesn’t do

Hackers Can Clone Millions of Toyota, Hyundai, and Kia Keys | WIRED

Encryption flaws in a common anti-theft feature expose vehicles from major manufacturers.

Errata Security: Huawei backdoors explanation, explained

Today Huawei published a video explaining the concept of "backdoors" in telco equipment. Many are criticizing the video for being tone deaf....

HiddenVM/README.md at master · aforensics/HiddenVM · GitHub

HiddenVM — Use any desktop OS without leaving a trace. - aforensics/HiddenVM

Uncovering The CIA's Audacious Operation That Gave Them Access To State Secrets : NPR
The "Junk Mail" Men: Selling Your Data for over a Century | The Saturday Evening Post

The mailing list brokers of the mid-century spawned political junk mail and today’s Big Brother digital marketing.

bypass-paywalls-firefox-clean/README.md at master · magnolia1234/bypass-paywalls-firefox-clean · GitHub

Bypass Paywalls Clean for Firefox (lot of updates and bug-fixes) - magnolia1234/bypass-paywalls-firefox-clean

Felix sur Twitter : "Ever wondered how the @zoom_us macOS installer does it’s job without you ever clicking install? Turns out they (ab)use preinstallation scripts, manually unpack the app using a bundled 7zip and install it to /Applications if the curren…
Surprise, l'application Zoom transmet des données à Facebook (...même si vous n'avez pas de compte)

L'application de visioconférence Zoom transmet automatiquement certaines de vos données personnelles à Facebook. Quelles informations sont concernées ?

Données mobiles : l’Inserm assure qu’il ne s'agit pas de suivre à la trace les Français - Société - Numerama

Avec l'aide d'Orange, le principal opérateur de téléphonie mobile français, l'Inserm entend conduire une étude statistique basée sur la géolocalisation des smartphones. Un projet qui a soulevé des inquiétudes, que l'institut public entend lever.

As Coronavirus Surveillance Escalates, Personal Privacy Plummets - The New York Times

Tracking entire populations to combat the pandemic now could open the doors to more invasive forms of government snooping later.

Coronavirus : à Moscou, la reconnaissance faciale vidéosurveille les confinés - Next INpact
maza-ad-blocking/README.md at master · tanrax/maza-ad-blocking · GitHub

Local ad blocker. Like Pi-hole but local and using your operating system. - tanrax/maza-ad-blocking

Yelp to stop auto-creating fundraisers after outrage from business owners - The Verge

Yelp faced backlash from those it was trying to help

John Battelle's Search Blog Will The Coronavirus Save Big Tech?

Who’s Really Behind That “Death of the Techlash” Narrative?   One of my least favorite kinds of journalism is the easy win. It’s the kind of story that just lands in yo…

Snowden warns new surveillance measures will outlast the coronavirus

Governments around the world are using high-tech coronavirus surveillance measures to combat the outbreak. But are they worth it?

Apple just killed Offline Web Apps while purporting to protect your privacy: why that’s A Bad Thing and why you should care – Aral Balkan

Apple will delete your data if you don’t use an app for seven days. This effectively kills offline web apps.

Why Don’t We Just Ban Targeted Advertising? | WIRED

From protecting privacy to saving the free press, it may be the single best way to fix the internet.

Locked-Down Lawyers Warned Alexa Is Hearing Confidential Calls - Bloomberg

Hey Alexa, stop listening to my client’s information.

Google Says It Doesn’t 'Sell' Your Data. Here’s How the Company Shares, Monetizes, and Exploits It. | Electronic Frontier Foundation

"Google will never sell any personal information to third parties; and you get to decide how your information is used." - Sundar Pichai Sound familiar? Although big tech companies like Google keep the lights on by harvesting and monetizing your personal data, they can be quick to mince words and deny the strawman scenario of exchanging hard drives full of your data for a suitcase of money. Now California law has given them another reason to deny and deflect.

Formal GDPR complaint against Google’s internal data free-for-all

Brave has filed a GDPR complaint v Google for infringing the GDPR “purpose limitation” principle. Enforcement would be tantamount to a functional separation of Google’s business.

Europe Wants a ‘Right to Repair’ Smartphones and Gadgets - The New York Times

The European Union is seeking to help consumers fix or upgrade devices, rather than replace them, as part of a 30-year push to reduce greenhouse gas emissions.

The opt-out illusion - Technology - TLS

Katrina Gulliver considers how we have acquiesced to losing our privacy

Google tracked his bike ride past a burglarized home. That made him a suspect.

"I was using an app to see how many miles I rode my bike and now it was putting me at the scene of the crime," the man said.

Watch six decade-long disinformation operations unfold in six minutes

Here’s a bird’s eye view of six state-backed information operations on Twitter, and how they evolved over the last decade. This research…

One billion Android devices at risk of hacking - BBC News

Watchdog Which? wants Google to be more transparent about security updates for old phones

Linux-ready, made-in-Germany "Volla Phone" succeeds on Kickstarter

Some months after a failed Kickstarter campaign with an ambitious €350k goal, German startup Volla has managed to raise more than €20k in a new campaign (still open for the next few hours) for their first Volla Phone. Volla Phone in German woods.This new smartphone aims at several niches,

Firefox is showing the way back to a world that’s private by default - The Verge

If Amazon Go cameras seem squiggy, shouldn’t online tracking be too?

Top Economists Study What Happens When You Stop Using Facebook - Study Hacks - Cal Newport

In the most recent issue of the prestigious American Economic Review, a group of well-known economists published a paper titled "The Welfare Effects of Social