Monthly Shaarli

All links of one month in a single page.

August, 2020

Chinese-Made Smartphones Are Secretly Stealing Money From People Around The World
🎓 Dr. Freemo :jpf: 🇳🇱 : "Holy crap, google is apparently taking down all/m…" - Qoto Mastodon

Attached: 1 image

Holy crap, google is apparently taking down all/most fediverse apps from google play on the grounds that that some servers in the fediverse engage in hate speech. At least three apps I know of anyway and I'd imagine the others will follow soon under the exact same reasoning.} Seems to be the case with Husky, Fedilab, and "subway" tooter.

this is a scary precedent if google play is going to ban any apps that can in any way be used to access content with hate speech. So what about a forum client, do they take that down just because there is a forum somewhere on the internet posting hate speech?

This is particularly worrisome because for most people Google Play is the only way they understand to install apps at all.

Picture attached of one of the notices received by fedilab.

https://toot.fedilab.app/@fedilab/104761140268193772

https://mastodon.social/@Gargron/104763960269049818

@fedilab @tateisu #fediverse #mastoadmin #freespeech #censorship

degoogle | A huge list of alternatives to Google products. Privacy tips, tricks, and links.

A huge list of alternatives to Google products. Privacy tips, tricks, and links.

Microsoft Put Off Fixing Zero Day for 2 Years — Krebs on Security

A security flaw in the way Microsoft Windows guards users against malicious files was actively exploited in malware attacks for two years before last week, when Microsoft finally issued a software update to correct the problem.

Why You Should Stop Using Telegram Right Now

Telegram, the supposedly secure messaging app, has over 100 million users. You might even be one of them. If you are, you should probably stop using it right now. Here’s the unfortunate truth about Telegram: it’s not as secure as the company’s marketing campaigns might lead you to believe.

The US Senate Is Using Signal - Schneier on Security
Wegen Vorratsdatenspeicherung: Threema prüft Wegzug aus der Schweiz | heise online
CSS Exfil Protection – Get this Extension for 🦊 Firefox (en-US)

Download CSS Exfil Protection for Firefox. Guard your browser against CSS Exfil attacks!

CSS Exfil is a method attackers can use to steal data from web pages using Cascading Style Sheets (CSS). This plugin sanitizes and blocks any CSS rules which may be designed to steal data.

Instagram could face up to $500 billion in fines in class-action lawsuit alleging it illegally harvested biometric data

...

Is This New Signal Feature Enough To Make You Ditch WhatsApp?

Could this smart new Signal feature be enough to make you ditch WhatsApp?

What are the features of a secure and private communication service – Telegraph

Last update: May 22, 2020
Español - Italiano
Introduction
This article analyses the security and confidentiality features of the most commonly used communication services or applications.
Note: the comparison is made between WhatsApp (the most widespread 1.6 billion users), Telegram (the most secure and widespread 400 million users), Signal and Wire (the most secure and confidential) according to world statistics. A comparison in terms of functionality is available at this address.
Remark: for any communication…

Delisting Wire from PrivacyTools.io

It has recently come to the attention of the PrivacyTools team that Wire, the popular end-to-end encryption messaging platform had been sold or moved to a US company. After a week of questioning, Wire finally confirmed they had changed holding companies and would now be a US based company in

Threema, l’app suisse qui rivalise avec WhatsApp et Telegram - Le Temps

L’application helvétique vient de s’enrichir d’un service d’appels vidéo. Ses développeurs affirment que Threema est plus sûre que tous ses concurrents, dont Telegram et Signal

Google Home smart speakers enabled to listen in to everyday house sounds | The Independent

Users have received notifications when their Google Home speakers hear smoke alarms or breaking glass

GitHub - iamadamdev/bypass-paywalls-chrome: Bypass Paywalls web browser extension for Chrome and Firefox.

Bypass Paywalls web browser extension for Chrome and Firefox. - iamadamdev/bypass-paywalls-chrome

Instagram kept deleted photos and messages on its servers for more than a year - The Verge

Just because you deleted it, doesn’t mean the company did

Apple just kicked Fortnite off the App Store - The Verge

Apple says Epic is violating its App Store guidelines.

To Head Off Regulators, Google Makes Certain Words Taboo – The Markup

The Markup obtained internal documents that coach new employees to avoid creating “very real legal risks” in using words like “market” and “network effects”

Apple Takes Legal Action Against This Small Company's Pear Logo [Update] | iPhone in Canada Blog

Apple says the Prepear logo resembles the Apple logo and has taken legal action against the small business.

Smartphone Hardening non-root Guide 2.0 (for normal people) - Lemmy

Lemmy

Doctolib : le site de prise de RDV médicaux frappé par un vol de données
More Than 1,000 Companies Boycotted Facebook. Did It Work? - The New York Times

Major advertisers on Facebook reduced their spending by millions of dollars in July, but not enough to significantly damage the platform’s revenue.

ProtonMail founder: Apple uses monopoly to “hold all of us hostage” | Ars Technica

ProtonMail CEO argues Apple fails to meet "minimum moral responsibility."

Historical programming-language groups disappearing from Google [LWN.net]

As Alex McDonald notes in this
support request, Google has recently banned the old Usenet groups
comp.lang.forth and comp.lang.lisp from the Google Groups system.
"Of specific concern is the archive. These are some of the oldest
groups on Usenet, and the depth & breadth of the historical material that
has just disappeared from the internet, on two seminal programming
languages, is huge and highly damaging. These are the history and
collective memories of two communities that are being expunged, and it's
not great, since there is no other comprehensive archive after Google's
purchase of Dejanews around 20 years ago."
Perhaps Google can be convinced to restore the content, but it also seems
that some of this material could benefit from a more stable archive.

Does Facebook Still Sell Discriminatory Ads? – The Markup

We found discriminatory ads can still appear, despite Facebook's efforts

How Facebook quietly pressures its independent fact-checkers

As Facebook struggles with waves of misinformation, the company’s political and business concerns are influencing its fact-checking policies.

ThreatSpike Blog: Zoom still don't understand GDPR
Even Google engineers are confused about Google’s privacy settings - The Verge

"The current UI feels like it is designed to make things possible, yet difficult enough that people won’t figure it out."

Bridgefy, the messenger promoted for mass protests, is a privacy disaster | Ars Technica

Researchers notified the company in April of serious flaws that have yet to be fixed.

Kindle Collects a Surprisingly Large Amount of Data

Reading a book on a Kindle sends Amazon a lot of data about reading habits. How fast pages are turned, font sizes and views, and device details.

AndroidHardening project renamed to GrapheneOS
Comment la CIA parvient à lire les messages de WhatsApp - Le Temps
This smartphone has physical kill switches for its cameras, microphone, data, Bluetooth, and Wi-Fi

A common complaint with modern smartphones is that they are black boxes. Android and iOS are complicated pieces of software, each with hundreds (if not

Goodbye Whatsapp: All of Bundesbern relies on Threema Work
Comparing Messaging Apps - Schneier on Security
La Commission européenne adopte Signal, sauf pour les discussions très sensibles

Bruxelles recommande à son personnel d'utiliser la messagerie Signal pour discuter avec des personnes extérieures à l'institution, afin de relever le niveau de sécurité des communications. Les échanges très sensibles en revanche continuent de passer par des canaux dédiés.

Protect yourself against a pure CSS data stealing attack called Exfil - gHacks Tech News
GitHub - gorhill/uBO-Extra: A companion extension to uBlock Origin

A companion extension to uBlock Origin. Contribute to gorhill/uBO-Extra development by creating an account on GitHub.

Signal >> Government Requests >> Grand jury subpoena for Signal user data, Eastern District of Virginia

We’ve designed the Signal service to minimize the data we retain about Signal users, so the only information we can produce in response to a request like this is the date and time a user registered with Signal and the last date of a user’s connectivity to the Signal service.

Notably, things we don’t have stored include anything about a user’s contacts (such as the contacts themselves, a hash of the contacts, any other derivative contact information), anything about a user’s groups (such as how many groups a user is in, which groups a user is in, the membership lists of a user’s groups), or any records of who a user has been communicating with.

All message contents are end-to-end encrypted, so we don’t have that information either.

Two hackers told us which is the safest messaging app

WhatsApp, Signal e Telegram promettono tutte la stessa cosa: comunicazioni sicure. Ma ci possiamo fidare?

Métadonnées : Signal a trouvé un moyen de mieux protéger ses utilisateurs

Open Whispers System, qui édite Signal, teste une nouvelle approche qui permet d'étendre encore plus la confidentialité de sa communauté. Comment ? En intervenant au niveau des métadonnées.

It's fine, but you should know that pretty much everything Moxie and Signal talk... | Hacker News

It's fine, but you should know that pretty much everything Moxie and Signal talk about contrast sharply with Wire. For instance: last I checked, Wire stores your entire social graph on their servers in a database --- effectively forever, Wire stores a plaintext log of everyone you've communicated with.

Unpaywall

Legally get full text of scholarly articles as you browse.

Nano Defender
Mozilla signs fresh Google search deal worth mega-millions as 25% staff cut hits Servo, MDN, security teams • The Register

$2.5m-a-year CEO set to take a pay cut, so that's all right, then

The Subtle Tricks Shopping Sites Use to Make You Spend More | WIRED

Through deceptive designs known as “dark patterns,” online retailers try to nudge you toward purchases you wouldn’t otherwise make.

dorking (how to find anything on the Internet) - for your information

tl;dr: Use advanced Google Search to find any webpage, emails, info, or secrets cost: $0 time: 2 minutes Software engineers have long joked about how much of their job is simply Googling things Now you can do the same, but for free Below, I'll cover dorking, the use of …

Google’s artificial intelligence ethics won't curb war by algorithm | WIRED UK

New ethical principles restrict the work of Google's AI scientists on military projects, but key questions about the technology industry and the future of war remain unanswered

Journalists’ Twitter use shows them talking within smaller bubbles | Illinois

Washington, D.C., journalists are clustering not in one “Beltway bubble,” but in “microbubbles,” says an Illinois study of their Twitter use.

What Are Stingrays and Dirtboxes?

A guide to stingray surveillance technology, which may have been deployed at recent protests.

Facebook hate-speech boycott had little effect on revenue - Axios

Since Facebook relies on millions of small advertisers, so far the boycott effort has been more about image than profits.

Zoom Security Exploit - Cracking private meeting passwords - Tom Anthony
Powell’s says it won’t sell books on Amazon anymore: ‘We must take a stand’ - oregonlive.com

Powell's Books announces a change. “For too long, we have watched the detrimental impact of Amazon’s business on our communities and the independent bookselling world."

Ventoy

Ventoy is an open source tool to create bootable USB drive for ISO files. With ventoy, you don't need to format the disk again and again, you just need to copy the iso file to the USB drive and boot it.

Facebook Says Apple’s New iPhone Update Will Disrupt Online Advertising - WSJ

Facebook says privacy changes that Apple has made to its newest operating system will cripple the social-media giant’s ability to serve targeted ads to iPhone users while they use outside apps.

The Bias in the Machine - Issue 89: The Dark Side - Nautilus

In January, Robert Williams, an African-American man, was wrongfully arrested due to an inaccurate facial recognition algorithm, a…

Redirect AMP to HTML – Get this Extension for 🦊 Firefox (en-US)
2.5 Million Medical Records Leaked By AI Company

Secure Thoughts collaborated with Cyber Security Expert Jeremiah Fowler to expose an AI company which leaked millions of patient medical records online

How was Jeff Bezos’s iPhone hacked? - The Washington Post
εxodus
εxodus
Battle of the Secure Messaging Apps: How Signal Beats WhatsApp

Both Signal and WhatsApp are encrypted, but Signal takes extra steps to keep your chats private.

Feds secretly subpoenaed the encrypted chat app Signal earlier this year - The Verge

Earlier this year, Open Whisper Systems was served with a federal subpoena for records on its users, according to documents published today. Prosecutors were seeking data on two suspects who used...

Signal patches (minor) approximate location disclosure flaw | The Daily Swig

WebRTC DNS lookups exploited in clever hack

Threema: Instant messaging service from Switzerland - Messenger Part 2 ⋆ Kuketz IT security blog

Threema ist ein auf Datenschutz und Sicherheit bedachter Messenger - unabhängig überprüfbar ist dies allerdings nicht.

Lawsuit: Zoom Lied About Security Measures, End-to-End Encryption - Legal Reader

Zoom is facing another lawsuit alleging that the video communications company has deceived consumers by making false claims about its privacy measures.

Signal secure messaging can now identify you without a phone number – Naked Security

Signal decouples its secure messaging service from your phone number – a bit.

Signal's pin feature shows why putting privacy first is hard

The privacy-first messaging app recently rolled out an opt-out feature that was criticized by security experts and panned by users.

Secure Messaging App Wire Stores Everyone You've Ever Contacted in Plain Text

The decision is seemingly a trade-off for usability across multiple devices.

More is Less: On the End-to-End Security of Group Chats in Signal, WhatsApp, and Threema
Choosing the Right Messenger
Threema - Wikipedia
Signal (software) - Wikipedia
Telegram Founder on WhatsApp Hacks: Backdoors Are Camouflaged as Security Flaws

Pavel Durov criticized WhatsApp in new blog post

Signal compromised? - signal

If you need top level privacy protection do some or all of the following

Beware of find-my-phone, Wi-Fi, and Bluetooth, NSA tells mobile users | Ars Technica

And don't forget to limit ad tracking. Advisory contains a host of recommendations.

Instacart shoppers besieged by bots that snatch lucrative orders | The Seattle Times
Facebook abandons broken drilling equipment under Oregon coast seafloor - oregonlive.com

“The delay in notification eliminated any potential options for recovery of the equipment.”

Google resumes its attack on the URL bar, hides full addresses on Chrome 86
thinkst Thoughts...: If the NSA has been hacking everything, how has nobody seen them coming?

As the Snowden leaks continue to dribble out, it has become increasingly obvious that most nations  planning for "cyber-war" have been mer...

Browser Extensions I Can't Live Without

A list of browser extensions that took minutes to add, but made my browsing experience immeasurably better.

BlueLeaks Reveals What TikTok Shares with U.S. Authorities

A glimpse at what the social media platform does in the U.S. underscores that data privacy issues extend beyond China.

Cops Tap Smart Streetlights Sparking Controversy and Legislation - IEEE Spectrum
Cluster of 295 Chrome extensions caught hijacking Google and Bing search results | ZDNet

The malicious Chrome extensions have been installed by more than 80 million users.

pkg.go.dev is more concerned with Google’s interests than good engineering | Drew DeVault’s Blog

pkg.go.dev sucks. It’s certainly prettier than godoc.org, but under the covers, it’s a failure of engineering characteristic of the Google approach.

Google starts testing its replacement for third-party cookies | Engadget

Google is letting developers test trust tokens, its replacement for ad cookies.

Opinion | Data isn’t just being collected from your phone. It’s being used to score you. - The Washington Post