@jsrailton@mastodon.social
@jsrailton@mastodon.social avatar

jsrailton

@jsrailton@mastodon.social

Chasing online badness. Senior Researcher at Citizen Lab. Views mine.

Also, I like tracking stuck boats.

This profile is from a federated server and may be incomplete. Browse more on the original instance.

jsrailton, (edited ) to Health
@jsrailton@mastodon.social avatar

Even for cancer and transplant patients.

We are speeding into idiocracy.

#cancer #transplantation #immunocompromised #health #healthcare #masks #northcarolina

jsrailton, to infosec
@jsrailton@mastodon.social avatar

FINALLY: a 🇺🇸US official speaks the truth security researchers keep warning about...

Americans' movements being tracked with well-known weaknesses that US telcos aren't fixing.

It's remarkable how bad the problem with #SS7 & #Diameter is.

Must-read story by @josephcox
https://www.404media.co/cyber-official-speaks-out-reveals-mobile-network-attacks-in-u-s/

#infosec #cybersecurity #hacking #intelligence #surveillance #espionage

jsrailton, (edited ) to psychology
@jsrailton@mastodon.social avatar

I can confidently diagnose as sociopaths.

Promised therapy customers privacy...then gave their mental health info to advertisers.

Victims get less than ten bucks each.

Company made billion+ in revenue last year alone.

In a just society with good privacy laws, they'd face existential civil & criminal consequences.

https://www.wcnc.com/article/news/nation-world/betterhelp-therapy-class-action-settlement-refund/507-b4ef5e0f-c722-4562-95e9-c3cdd7738d1a

jsrailton,
@jsrailton@mastodon.social avatar

@eccentric_econ Interesting, thanks for sharing your perspective.

jsrailton, to egypt
@jsrailton@mastodon.social avatar

All shipping traffic stopped on the Strait.

Channel connects Black Sea & Mediterranean is busiest in the world.

Why? Bulk carrier is grounded across northbound shipping lane.

Headed to from .

Turkish maritime authorities say on Twitter that they suspect mechanical failure.

image/png
image/png
image/png

jsrailton,
@jsrailton@mastodon.social avatar

UPDATE: Movement!

Watching ship tracking live it appears the hardworking tugs freed bulk carrier & the party is now heading South as some of the Tugs break off.

image/png

jsrailton, to Toronto
@jsrailton@mastodon.social avatar

My colleague Mitchell & partner just escorted a family of lost geese to the lake.

Safely navigating 2km of downtown took 2 hours.

At one point, police stepped in to block traffic.

Strangers jumped in to help too.

He jokes: at @citizenlab we don't just help humans!

image/png
image/png
image/png

jsrailton, (edited ) to infosec
@jsrailton@mastodon.social avatar

Big #VPN companies are churning out bullshit "security advice" on an industrial scale.

It's a marketing funnel that targets those seeking help.

And then misinforms them.

I wish it stopped there

The nonsense makes its way to victims of spyware, where misinformation can have life, death and liberty impacting consequences.

#infosec #cybersecurity #malware #IT #pegasus #predator #spyware #malware

jsrailton,
@jsrailton@mastodon.social avatar

@gunther Each article is bad in different ways :)

But one area where it's easy to see issues is in the advice they give.

The consensus correct advice to someone targeted with Pegasus et. al. would be : seek out expert support, and here are the resources XYZ that can provide it to you.

If you don't make that your main piece of top advice, you are doing it wrong.

Which none of these articles does...

jsrailton, (edited ) to hacking
@jsrailton@mastodon.social avatar

BREAKING: private investigator arrested for cyberespionage on behalf of American PR firm.

Caught by UK under from 🇺🇸US while boarding a flight.

BIG TWIST in a wild case that began w/our @citizenlab investigation into indian hack-for-hire group

Sound familiar?

Because Amit Forlit is the second PI from arrested in similar way for this case.

First = convicted.

https://www.reuters.com/world/israeli-private-eye-arrested-uk-over-alleged-hacking-us-pr-firm-2024-05-02/

jsrailton, (edited )
@jsrailton@mastodon.social avatar

There's a disgraceful ecosystem of public relations & lobbying firms using hackers for hire.

Sometimes they are used to silence critics & advocacy groups.

Like US nonprofits doing climate advocacy.

Our investigation into a group we christened uncovered a sprawling -based hack-for-hire operation.

They enabled US corporations to outsource lawbreaking.

https://citizenlab.ca/2020/06/dark-basin-uncovering-a-massive-hack-for-hire-operation/

jsrailton, (edited )
@jsrailton@mastodon.social avatar

I'd bet my bottom dollar that this "unnamed...PR and lobbying firm" knows exactly who they are...

...and are no doubt experiencing an afternoon of the purest panic.

Using the offshore hack-for-hire ecosystem has been largely consequence-free for the middlemen & the ultimate beneficiaries of stolen information.

The tide may be turning & this latest arrest suggests that more consequences may be inbound.

jsrailton, to poland
@jsrailton@mastodon.social avatar

NEW: "shocking and depressing"

"...even in this room I am speaking to people who were victims of this system"

's prosecutor general testifies to 🇵🇱 parliament about hacking of 100s with spyware.

Story: https://apnews.com/article/poland-spyware-pegasus-nso-group-israel-413bb3cb27daac011d52b524c6d16160

image/png

jsrailton, (edited ) to ai
@jsrailton@mastodon.social avatar

AI-drafted police reports will absolutely result in mistakes enshrined as facts.

This will permanently impact peoples' lives & freedom.

Story: https://www.forbes.com/sites/thomasbrewster/2024/04/23/axon-ai-police-reports-/?sh=7bdefd5b476b

jsrailton, to infosec
@jsrailton@mastodon.social avatar

BREAKING: US imposes visa restrictions on 13 mercenary spyware proliferators / immediate family.

First known application of policy rolled out in Feb.

A lot of shady players are surely having a little panic.

...wondering if their name is or will be on a list.

jsrailton, to random
@jsrailton@mastodon.social avatar

Russian on the street speaks his mind to journalist.

5 year community service sentence.

No doubt without apology it would have been worse.

Story by @meduza_en
https://meduza.io/en/news/2024/04/22/moscow-man-convicted-of-spreading-disinformation-in-street-interview-with-rfe-rl

jsrailton, to poland
@jsrailton@mastodon.social avatar

NEW: female army officers that reported sexual harassment... were hacked with .

Official confirmations from 's AG keep shedding light on more apparent spyware abuses by past gov.

Link [in PL]: https://wiadomosci.onet.pl/kraj/zglosily-molestowanie-w-zandarmerii-wojskowej-byly-inwigilowane-pegasusem/dylyrsv

jsrailton, to privacy
@jsrailton@mastodon.social avatar

"Citizen, leave a copy of your home keys at the police station."

Hmm, people won't like that.

How about, "home-builders have a social responsibility ...[and must give police copies of all house keys]"

Much better.

taking another stab at the encryption fight.

jsrailton, (edited ) to Finland
@jsrailton@mastodon.social avatar

deleted_by_author

  • Loading...
  • jsrailton,
    @jsrailton@mastodon.social avatar

    @klefstadmyr Hi yes there is, here's the list:

    🇦🇺#Australia 🇨🇦#Canada 🇨🇷#CostaRica 🇩🇰#Denmark 🇫🇮#Finland🇫🇷#France 🇩🇪#Germany🇮🇪#Ireland🇯🇵#Japan🇳🇿#NewZealand 🇳🇴#Norway 🇵🇱#Poland🇰🇷#SouthKorea🇸🇪#Sweden 🇨🇭#Switzerland 🇬🇧#UK 🇺🇸#US

    jsrailton, (edited ) to poland
    @jsrailton@mastodon.social avatar

    BREAKING: spyware abused in 🇵🇱 under previous PiS-party government, confirms the new PM Donald Tusk

    "Very, very long" victim list.

    Vindication.

    When we @citizenlab first confirmed the hacking in 2021 both we & victims were targeted w/extensive harassment & disinformation.

    REPORT: https://apnews.com/article/poland-government-pegasus-spyware-tusk-duda-78420fc7099401926d28b5be98669192

    jsrailton, to random
    @jsrailton@mastodon.social avatar

    NEW: heard about ? Something about ?

    Or the waxing paranoid about ?

    What does it all mean?

    Well, my @citizenlab colleague Bill Marczak has an deliciously spicy take on the unfolding saga.

    Plus some tips for defenders.

    https://medium.com/@billmarczak/triangulation-did-the-nsa-fail-to-learn-the-lessons-of-nso-5f36d251d02e

    jsrailton, to random
    @jsrailton@mastodon.social avatar

    NEW: I found 1000s of shady PDFs hosted on .gov websites of states, universities, defense contractors, etc.

    It was a clever SEO spam operation, but the access could have been exploited for more nefarious things. 1/

    @lorenzofb has the writeup

    https://techcrunch.com/2023/06/02/scammers-publish-ads-for-hacking-services-on-government-websites/

    image/png
    image/png
    image/png

    jsrailton,
    @jsrailton@mastodon.social avatar

    2/ SEO operations like this are a bit like opportunistic infections for Content Management Systems.

    They show up when there are bugs, misconfigurations & permissions issues.

    rapidly pushed out notifications to affected orgs & the content is coming down all over.

    jsrailton,
    @jsrailton@mastodon.social avatar

    3/ The PDF spam is still all over. Including many gov sites.

    Want to help?

    1️⃣ Google search:

    "site:[pick a top-level domain e.g. .gov.au .gov.uk etc.] instagram hack followers filetype:pdf"

    2️⃣mix in terms e.g. "Tiktok" & "fans."

    3️⃣ Cry

    4️⃣Gently notify administrators

    jsrailton, to random
    @jsrailton@mastodon.social avatar

    Remember Tara Reade?

    The one-time #Biden accuser is live on 🇷🇺Russian State TV announcing that she's defected.

    Sitting with Maria Butina whom she refers to as a friend.

    #Russia #Propaganda #disinformation

    image/png

  • All
  • Subscribed
  • Moderated
  • Favorites
  • provamag3
  • InstantRegret
  • magazineikmin
  • modclub
  • khanakhh
  • Youngstown
  • rosin
  • mdbf
  • slotface
  • Durango
  • ngwrru68w68
  • thenastyranch
  • kavyap
  • DreamBathrooms
  • JUstTest
  • cubers
  • osvaldo12
  • Leos
  • anitta
  • everett
  • ethstaker
  • GTA5RPClips
  • tester
  • cisconetworking
  • megavids
  • tacticalgear
  • normalnudes
  • lostlight
  • All magazines