seav, to infosec
@seav@en.osm.town avatar

The security of the worldwide information technology infrastructure sadly rests on tons of unpaid open source developers. 😦

https://www.theverge.com/2024/4/2/24119342/xz-utils-linux-backdoor-attempt

#XZUtils #backdoors #exploits #infosec

remixtures, to Cybersecurity Portuguese
@remixtures@tldr.nettime.org avatar

: "Researchers have found a malicious backdoor in a compression tool that made its way into widely used Linux distributions, including those from Red Hat and Debian.

The compression utility, known as xz Utils, introduced the malicious code in versions ​​5.6.0 and 5.6.1, according to Andres Freund, the developer who discovered it. There are no known reports of those versions being incorporated into any production releases for major Linux distributions, but both Red Hat and Debian reported that recently published beta releases used at least one of the backdoored versions—specifically, in Fedora Rawhide and Debian testing, unstable and experimental distributions. A stable release of Arch Linux is also affected. That distribution, however, isn't used in production systems.

Because the backdoor was discovered before the malicious versions of xz Utils were added to production versions of Linux, “it's not really affecting anyone in the real world,” Will Dormann, a senior vulnerability analyst at security firm Analygence, said in an online interview. “BUT that's only because it was discovered early due to bad actor sloppiness. Had it not been discovered, it would have been catastrophic to the world.”

Several people, including two Ars readers, reported that the multiple apps included in the HomeBrew package manager for macOS rely on the backdoored 5.6.1 version of xz Utils. HomeBrew has now rolled back the utility to version 5.4.6. Maintainers have more details available here." https://arstechnica.com/security/2024/03/backdoor-found-in-widely-used-linux-utility-breaks-encrypted-ssh-connections/

alecm, to apple

Operation Triangulation: The last (hardware) mystery | …if this turns out to be an NSA-enabling backdoor, Apple’s security reputation will be toast

Our guess is that this unknown hardware feature was most likely intended to be used for debugging or testing purposes by Apple engineers or the factory, or that it was included by mistake. Because this feature is not used by the firmware, we have no idea how attackers would know how to use it.

https://securelist.com/operation-triangulation-the-last-hardware-mystery/111669/

https://www.addtoany.com/add_to/copy_link?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F108745&linkname=Operation%20Triangulation%3A%20The%20last%20%28hardware%29%20mystery%20%7C%20%E2%80%A6if%20this%20turns%20out%20to%20be%20an%20NSA-enabling%20backdoor%2C%20Apple%E2%80%99s%20security%20reputation%20will%20be%20toasthttps://www.addtoany.com/add_to/threads?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F108745&linkname=Operation%20Triangulation%3A%20The%20last%20%28hardware%29%20mystery%20%7C%20%E2%80%A6if%20this%20turns%20out%20to%20be%20an%20NSA-enabling%20backdoor%2C%20Apple%E2%80%99s%20security%20reputation%20will%20be%20toasthttps://www.addtoany.com/add_to/facebook?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F108745&linkname=Operation%20Triangulation%3A%20The%20last%20%28hardware%29%20mystery%20%7C%20%E2%80%A6if%20this%20turns%20out%20to%20be%20an%20NSA-enabling%20backdoor%2C%20Apple%E2%80%99s%20security%20reputation%20will%20be%20toasthttps://www.addtoany.com/add_to/mastodon?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F108745&linkname=Operation%20Triangulation%3A%20The%20last%20%28hardware%29%20mystery%20%7C%20%E2%80%A6if%20this%20turns%20out%20to%20be%20an%20NSA-enabling%20backdoor%2C%20Apple%E2%80%99s%20security%20reputation%20will%20be%20toasthttps://www.addtoany.com/add_to/hacker_news?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F108745&linkname=Operation%20Triangulation%3A%20The%20last%20%28hardware%29%20mystery%20%7C%20%E2%80%A6if%20this%20turns%20out%20to%20be%20an%20NSA-enabling%20backdoor%2C%20Apple%E2%80%99s%20security%20reputation%20will%20be%20toasthttps://www.addtoany.com/add_to/email?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F108745&linkname=Operation%20Triangulation%3A%20The%20last%20%28hardware%29%20mystery%20%7C%20%E2%80%A6if%20this%20turns%20out%20to%20be%20an%20NSA-enabling%20backdoor%2C%20Apple%E2%80%99s%20security%20reputation%20will%20be%20toasthttps://www.addtoany.com/add_to/linkedin?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F108745&linkname=Operation%20Triangulation%3A%20The%20last%20%28hardware%29%20mystery%20%7C%20%E2%80%A6if%20this%20turns%20out%20to%20be%20an%20NSA-enabling%20backdoor%2C%20Apple%E2%80%99s%20security%20reputation%20will%20be%20toasthttps://www.addtoany.com/add_to/twitter?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F108745&linkname=Operation%20Triangulation%3A%20The%20last%20%28hardware%29%20mystery%20%7C%20%E2%80%A6if%20this%20turns%20out%20to%20be%20an%20NSA-enabling%20backdoor%2C%20Apple%E2%80%99s%20security%20reputation%20will%20be%20toasthttps://www.addtoany.com/share

https://alecmuffett.com/article/108745

snazzyq, to random
@snazzyq@mas.to avatar

The last I’ll say on Beeper/Apple/iMessage debacle:

I think it’s within Beeper’s right to attempt at reverse engineering iMessage, but not Apple’s responsibility to be forced or even expected to host Beeper customers. It’s clear Apple doesn’t want to and I don’t blame them. If this ever went to court, Apple would obliterate Beeper—even if they switched lawyers. It’s not Beeper’s right to push the burden and expense of hosting on Apple.

kkarhan,
@kkarhan@mstdn.social avatar

@snazzyq considering how basically every standardization group - regardless if or - introduce in their , I'd not count on any GSMA standard to come out of this.

Their attempt to replace witha (remember ) failed so hard that I don't have any devices that support it!

cjerrington, to Powershell
@cjerrington@mstdn.social avatar

Today I learned: I can SSH from to my machines effortlessly. This is a game changer!

kkarhan,
@kkarhan@mstdn.social avatar

@dataelemental @13reak @cjerrington Personally I wasted 15 years of my life with and I do regret not having made the switch to 5-10+ years earlier, because Windows to this day doesn't have a good / nor absolute basics like a to keep stuff updated, so every application has to DIY it's own updates like some Caveman-made Ghettohack of a program...

Not to mention the mess re: and it's ...

Polynomial_C, to random Catalan
@Polynomial_C@mastodon.social avatar

Micro$hit Teams vs

kkarhan,
@kkarhan@mstdn.social avatar
bfdi, to random German
@bfdi@social.bund.de avatar

Die Meldungen über ein vermutetes Datensammeln von MS über Outlook sind alarmierend. Wir werden am Dienstag beim Treffen der europäischen Datenschutzaufsichtsbehörden die rechtlich dafür federführenden irischen Datenschutzbeauftragten um einen Bericht bitten

kkarhan,
@kkarhan@mstdn.social avatar

@thierolfOrg @RalfOltmanns @bfdi +9001%

Ein ist überfällig!

Allein schon wegen illegaler ( % )...

Von & in oder ganz uu schweigen...
https://mstdn.social/@kkarhan/111388093200373611

glynmoody, to random
@glynmoody@mastodon.social avatar

EU-wide digital wallet: MEPs reach deal with Council - https://www.europarl.europa.eu/news/en/press-room/20231106IPR09006/eu-wide-digital-wallet-meps-reach-deal-with-council this is an absolute disgrace, it will open up everyone in EU to invisible, unstoppable government surveillance. shame on @EU_Commission and @Europarl_EN details: https://www.techdirt.com/2023/11/03/eu-tries-to-slip-in-new-powers-to-intercept-encrypted-web-traffic-without-anyone-noticing/

kkarhan,
@kkarhan@mstdn.social avatar

@KatS @quincy @glynmoody well, we see how and such attemots get cockblocked by the - or does noone else remember ?

and flat-out refused to even consider it and @mozilla was at least willing to work on that regard.

In the meantime we see in that are so obvious it's flabnerghasting why this binary trash isn't illegal like a submachine gun because it certainly harms way more than one...
https://github.com/kkarhan/windows-ca-backdoor-fix

kkarhan,
@kkarhan@mstdn.social avatar

@quincy @KatS @glynmoody +9001%

Thevproblem is not tjat those propsing the shit don't know of the harm they do with it - they know that damn well.

It's that doing such harm - and that includes even proposing such & - isn't penalized at all!

CarolaSieling, to Cybersecurity German

🤗 BSI veröffentlicht den
Bericht zur "Lage der IT-Sicherheit in Deutschland 2023" !

⚡ Fazit: Die Bedrohung im Cyberraum ist so hoch wie nie zuvor.

https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/Lageberichte/Lagebericht2023.html

Hilfreich auch die Broschüre "Cybersicherheit für KMU"

https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/Broschueren/Cyber-Sicherheit_KMU.html

kkarhan,
@kkarhan@mstdn.social avatar

@CarolaSieling was nicht nur in Teilen daran liegt dass das @bsi weder in vorschreibt noch voller verbietet!

Sollte das aber...

tallship, to random
@tallship@social.sdf.org avatar
gi124, to privacy
@gi124@mastodon.social avatar
publicvoit, to politics
@publicvoit@graz.social avatar

"The Westminster Declaration"

"We write as journalists, artists, authors, activists, technologists, and academics to warn of increasing international that threatens to erode centuries-old democratic norms. [...]"

https://westminsterdeclaration.org/

enno, to random German
@enno@nafo.army avatar

Ich suche eine App, welche meine Ergüsse Parallel auf Twitter, Mastodon, Post, Bluesky und Threads postet und die Antworten sortiert. Und dann bitte einen Messanger für WA, Signal, Telegram, iMessage, Threema, ...

kkarhan,
@kkarhan@mstdn.social avatar

@floe @enno Ich bezweigle dass Firmen dazu complien werden, weil dann müssten.diese ja die entsprechende Krypto FLOSS-lizensieren, und dann dürfte klar sein, wieviele - haben, weil sonst illegal...

kkarhan,
@kkarhan@mstdn.social avatar

@floe @enno Bezweifle ich...

Die "V.R." China haben die.meisten auch aufgegeben.wegen geforderter - und |er Kackshice:

Nur & haben die eigenen *innen direkt aufm Silbertablett serviert!
https://www.youtube.com/watch?v=Ev9_oDHNf-4

publicvoit, to microsoft
@publicvoit@graz.social avatar

After basically the whole cloud was hacked (see list of related sources on https://karl-voit.at/cloud/ ), the first follow-up incidents went public caused by missing containment actions:

60,000 emails were stolen from 10 accounts
https://www.reuters.com/world/us/chinese-hackers-stole-60000-emails-us-state-department-microsoft-hack-senate-2023-09-27/

If you didn't understand until now: basically EVERYTHING at Microsoft got hacked and Microsoft can't (or won't) get rid of the intruders. Everything authenticated by Microsoft is tainted. Even auth.

publicvoit,
@publicvoit@graz.social avatar

@yaeunerd Sure.

In simple words: lost one of their master keys to unlock very important parts of their cloud. This connects to all MS services that do authenticate by MS which includes most setups as well.

This happened long time ago, some people think it was the Chinese.

They were able to implant , self-made keys, ... all over the place.

In order to fix that, MS would need to kill all their connected hosts and start from scratch. It's obvious why they don't.

itnewsbot, to security
@itnewsbot@schleuss.online avatar

China state hackers are camping out in Cisco routers, US and Japan warn - Enlarge (credit: Getty Images)

Hackers backed by the Chinese g... - https://arstechnica.com/?p=1971587 &it

edri, to random
@edri@eupolicy.social avatar

1/2 🚨Today, we’re welcoming in Brussels @signalapp's @Mer__edith, @CommissionerHR @dunja_mijatovic & @epfl's @carmelatroncoso among other experts & policymakers to discuss #encryption & privacy.

We're also pleased to have @cdteurope's Iverna McGowan moderate the discussion 🌟 & to hear from Noémie Levain, Legal Expert at @LaQuadrature, Beatriz Ramalho da Silva, Investigative Journalist at @lhreports & Bart Staszewski LGBTI+ activist, founder and chairman of Basta Fundacja 🤩

kkarhan,
@kkarhan@mstdn.social avatar

@grin @edri @euronews @signalapp @fdroidorg
If "just use " was a working strategy, it would be illegal around the globe and would've gotten hacked like ...

Oh wait, means they'll already have to integrate and means they can't "export" secure .

Mer__edith, to random
@Mer__edith@mastodon.world avatar

Apple's statement is the death knell for the idea that it's possible to scan everyone's comms AND preserve privacy.

Apple has many of the best cryptographers + software eng on earth + infinite $.

If they can't, no one can. (They can't. No one can.)

https://www.wired.com/story/apple-csam-scanning-heat-initiative-letter/

kkarhan,
@kkarhan@mstdn.social avatar

@Mer__edith is totally able and willing to integrate , as they've evidenced woth the chinese ...

Needless to say that I think any " Scanners" and generally .tech are inherently wrong and to be rejected out of principle.

BrodieOnLinux, to linux
@BrodieOnLinux@linuxrocks.online avatar

Github REQUIRES 2FA: What This Means For You? https://youtu.be/WnO3uaatquc

kkarhan,
@kkarhan@mstdn.social avatar

@thatguyoverthere @BrodieOnLinux interesting...

Reminds me of the long compromized by [ ] RSA ...

gamingonlinux, to random
@gamingonlinux@mastodon.social avatar

omg so slow zzz

kkarhan,
@kkarhan@mstdn.social avatar

@bison - ( & ) would be my decison since there are a shitload of accessible servers AND it's fully since you're doing of the !

So even if the maintainers of said servers and/or FLOSS'd clients get held at gunpoint, they can't do ...
https://github.com/greyhat-academy/lists.d/blob/main/xmpp.servers.list.tsv

MeineKehrseite, to Software German

Je mehr rollende auf den Straßen unterwegs sind, um so mehr mache ich mir Sorgen über in den .
Ich finde tatsächlich die von in einem Fahrzeug/Flugzeug/Schiff/Pottwal(😂) bedenklich.

amueller, to random German

deleted_by_author

  • Loading...
  • kkarhan,
    @kkarhan@mstdn.social avatar

    @amueller einfach keine der nutzen?

    Dass nicht nur -Teilnehmer ist.sondern auch wie integrierte sollte diese schon disqualifizieren...

    Genauso wie mangelnde - & -Compliance...

    jmcrookston, to random
    @jmcrookston@mastodon.social avatar

    intentionally baked into secret secure radio standard.

    https://www.wired.com/story/tetra-radio-encryption-backdoor/

    autonomysolidarity, to random German
    @autonomysolidarity@todon.eu avatar

    1/2
    Das 40,00€ teurer gewordene Nachfolgeticket zum 9-Euro-Ticket soll Daten melken. Zwar solle das Ticket übergangsweise nicht nur für Smartphones erhältlich sein sondern auch auf Chip-Karten und kurzzeitig auf Papier mit QR-Code, aber wichtig scheint es den Regierenden vor allem anderen, dass mit dem 49€-Ticket Echtzeit-Verkehrsdaten erhoben werden können.

    Positiv klingt zunächst: "Es werde nicht gespeichert, wer von A nach B fährt, sondern nur, wie stark die Verkehrsmittel ausgelastet sind. Für die Fahrgäste könnte das ein Nutzen sein, weil die Verkehrsunternehmen so für ausreichend Kapazitäten sorgen könnten."

    Allerdings: Das Ticket wird wohl nur als Abo personalisiert erworben werden können, so dass darüber anfallende Personendaten zukünftig schnell integriert werden könnten. Mit Hinblick auf den aktuellen massiven Ausbau des Überwachungsstaats und der Kontrollgesellschaft in Deutschland und der EU (digitale Personenkennziffer/RegMod, Chatkontrolle, Identifizierungspflicht, Biometrie, eIDAS uvm) ist es doch auch gar nicht die Frage ob, sondern nur wann und mit welchem Vorwand (Anschläge, Pandemie, Jugendschutz, Wahlkampf) personalisierte Datenerfassung und Polizeizugriffe kommen werden, sobald die digitale Kontrollinfrastruktur erst einmal errichtet wurde.

    kkarhan,
    @kkarhan@mstdn.social avatar

    @wanderspieler @autonomysolidarity @torproject

    Ja doch, weil es nicht möglich ist ohne - und die sind bei nicht undedektoeirbar möglich...

    Und selbst wenn: funktioniert!

    https://github.com/KBtechnologies/PocketCrypto

  • All
  • Subscribed
  • Moderated
  • Favorites
  • anitta
  • kavyap
  • cisconetworking
  • thenastyranch
  • magazineikmin
  • hgfsjryuu7
  • DreamBathrooms
  • InstantRegret
  • Youngstown
  • slotface
  • PowerRangers
  • Durango
  • everett
  • rosin
  • normalnudes
  • vwfavf
  • modclub
  • ethstaker
  • khanakhh
  • tacticalgear
  • ngwrru68w68
  • osvaldo12
  • mdbf
  • tester
  • cubers
  • Leos
  • GTA5RPClips
  • provamag3
  • All magazines