@CosicBe@mastodon.social
@CosicBe@mastodon.social avatar

CosicBe

@CosicBe@mastodon.social

COSIC provides a broad expertise in digital security and strives for innovative security solutions.
COSIC is headed by Bart Preneel.

Computer Security and Industrial Cryptography group
https://www.esat.kuleuven.be/cosic/

This profile is from a federated server and may be incomplete. Browse more on the original instance.

Piratenpartij, to random Dutch
@Piratenpartij@social.globalpirates.net avatar

270 wetenschappers uit 33 landen maken gehakt van de laatste voorstellen van de Raad van de EU voor en waarschuwen voor "catastrofale gevolgen":
▶️ ondermijnt communicatie en systeemveiligheid
▶️ ongekende toezichts- en controlemogelijkheden
▶️ Miljoenen valse alarmen te verwachten
▶️ is techno-oplossingsgericht en zal kindermisbruik nauwelijks tegengaan

https://nce.mpi-sp.org/index.php/s/eqjiKaAw9yYQF87

jsrailton, (edited ) to hacking
@jsrailton@mastodon.social avatar

BREAKING: private investigator arrested for cyberespionage on behalf of American PR firm.

Caught by UK under from 🇺🇸US while boarding a flight.

BIG TWIST in a wild case that began w/our @citizenlab investigation into indian hack-for-hire group

Sound familiar?

Because Amit Forlit is the second PI from arrested in similar way for this case.

First = convicted.

https://www.reuters.com/world/israeli-private-eye-arrested-uk-over-alleged-hacking-us-pr-firm-2024-05-02/

glynmoody, to random
@glynmoody@mastodon.social avatar

EU plan to force messaging apps to scan for risks millions of false positives, experts warn - https://techcrunch.com/2024/05/02/eu-csam-scanning-council-proposal-flaws/ of course, as we have been saying for years...

restofworld, to random
@restofworld@restof.social avatar

As the Indian government expands its powers over online speech, the threat of a full-scale WhatsApp ban is closer than it’s been in years

https://restofworld.org/2024/exporter-whatsapp-encryption-india/?utm_source=mast

tjmcintyre, to random
@tjmcintyre@mastodon.social avatar

A new open letter signed by more than 270 scientists from 33 countries warning for the risks of the modified CSAM (child sexual abuse) regulation proposed by the Belgian presidency.
http://csa-scientist-open-letter.org

I've co-signed and can answer media inquiries for Ireland

wabrandsma, to random
@wabrandsma@mastodon.social avatar

'Autofabrikanten breken belofte over delen locatiegegevens met politie' https://www.security.nl/posting/840010/'Autofabrikanten+breken+belofte+over+delen+locatiegegevens+met+politie'
De autofabrikanten hadden aangegeven dat ze locatiegegevens van de voertuigen van hun klanten alleen na een gerechtelijk bevel met opsporingsdiensten zouden delen, maar dat blijkt in de praktijk niet te gebeuren.

TheConversationUS, (edited ) to TikTok
@TheConversationUS@newsie.social avatar

Forcing a Chinese company to sell TikTok won’t solve the biggest problem with : the fact that so people get their “” from platforms that are designed to hijack attention for commercial gain, not to deliver reliable information.

If China wants information on Americans, it can buy data from companies since there are no effective laws.

And American-owned Facebook and X have shown themselves to be as bad or worse as TikTok at spreading .

https://theconversation.com/tiktok-fears-point-to-larger-problem-poor-media-literacy-in-the-social-media-age-226667

campuscodi, to random
@campuscodi@mastodon.social avatar

A team of academics has looked at several ways to identify residential IP (RESIP) traffic.

The research comes as threat actors are building more and more RESIP botnets and renting access to these proxy networks to other threat actors to disguise the origin of malicious traffic.

https://chasesecurity.github.io/bandwidth_sharing/

tdp_org, to random
@tdp_org@mastodon.social avatar

@tomatospy isn't pulling any punches (and is absolutely correct, IMO) on today's Risky Biz newsletter.

https://news.risky.biz/corporate-freeloading-makes-open-source-vulnerable/

fhe, to random
@fhe@ioc.exchange avatar

Join us for welcoming returning presenter Sergi Rovira, with Axel Mertens, from Universitat Pompeu Fabra (UPF) and @CosicBe respectively, presenting Convolution-friendly Image Compression in FHE, Apr 25th, 2024 @ 4PM CEST.

Don't miss it!

🗓️ https://fhe.org/meetups/049

#fhe #cryptography

jmaris, to opensource
@jmaris@eupolicy.social avatar

This week, the Parliament signed off on the budget of the institutions, and it was a great week for : the sign-offs praise institutions for using Open Source software, encourage the adoption of , and push for the generalisation of the use of Open Source in EU institutions.

campuscodi, to random
@campuscodi@mastodon.social avatar

Threat actors are using fake stars and automated updates to manipulate GitHub search results and promote malware-infected projects.

The repos are Visual Studio projects that install malware on a developer's system when they build the app.

According to Checkmarx, the malicious code installs a version of Keyzetsu, a malware strain that can manipulate the Windows clipboard.

https://checkmarx.com/blog/new-technique-to-trick-developers-detected-in-an-open-source-supply-chain-attack/

campuscodi, to random
@campuscodi@mastodon.social avatar

Apple sent threat notifications to iPhone users in 92 countries on Wednesday, warning them that may have been targeted by mercenary spyware attacks.

https://techcrunch.com/2024/04/10/apple-warning-mercenary-spyware-attacks/

campuscodi, to random
@campuscodi@mastodon.social avatar

"The Solution of the Zodiac Killer’s 340-Character Cipher"

https://arxiv.org/abs/2403.17350

echo_pbreyer, to random German
@echo_pbreyer@digitalcourage.social avatar

🇩🇪Die Grundrechtsexperten von EDRi nehmen den neuesten Rats-Vorstoß zur auseinander. Ihr Ergebnis: Weder verhältnismäßig, noch wird Verschlüsselung geschützt.

Die Analyse (englisch): https://edri.org/our-work/rearranging-deck-chairs-on-the-titanic-belgiums-latest-move-doesnt-solve-critical-issues-with-eu-csa-regulation/

Jetzt gilt es Druck zu machen!

echo_pbreyer,
@echo_pbreyer@digitalcourage.social avatar

🇬🇧EDRi's fundamental rights experts analyse the latest Council proposal on . Their conclusion: Neither proportionate, nor does it protect encryption.

Read the analysis: https://edri.org/our-work/rearranging-deck-chairs-on-the-titanic-belgiums-latest-move-doesnt-solve-critical-issues-with-eu-csa-regulation/

Now is the time to put pressure on our governments!

ilumium, to security
@ilumium@eupolicy.social avatar

"The biggest source of conflict was an amendment ... that would prohibit from selling consumer data to and would require a warrant to access Americans’ information... National hawks in and local law enforcement groups joined forces to kill the amendment, with the National Sheriffs’ Association claiming it would “kneecap law enforcement” in a letter to Congress..."

https://www.theverge.com/2024/4/5/24122079/data-brokers-fisa-extension-nsa-section-702-surveillance-lexis-nexis

eff, to random
@eff@mastodon.social avatar

“This is the clearest picture that we’ve gotten of how cell-site simulators are operated, installed, and sold to police in years,” EFF’s @cooperq told @HorizonMass. “There absolutely needs to be case law requiring a warrant for a simulator.”
https://horizonmass.news/2024/04/03/feature-follow-up-surreptitious-simulation/

epicenter_works, to random German
@epicenter_works@chaos.social avatar

EU governments have to recognise: The Council’s “new” #chatcontrol proposal is merely a repackaging & still crosses red lines that many Member States have already expressed. We call on them to reject a proposal that would clearly violate fundamental rights.https://edri.org/our-work/rearranging-deck-chairs-on-the-titanic-belgiums-latest-move-doesnt-solve-critical-issues-with-eu-csa-regulation/

hanse_mina, to Ukraine
@hanse_mina@mastodon.social avatar

Nr. 2 of @afd European Parliament election list audio-taped receiving Russian intelligence bribe.

Czech counter-intelligence agendy @biscz have audio recording of German Member of Bundestag @PetrBystronAfD receiving money from Russian espionage. Bystroň is also foreign policy spokesperson of the Bundestag fraction of Russian Alternative for Germany.

https://threadreaderapp.com/thread/1775206482956398690.html

https://denikn.cz/1391766/dukazem-maji-byt-zvukove-nahravky-co-rekl-koudelka-vlade-o-proruske-siti-a-nemeckem-politiku-bystronovi/

campuscodi, to random
@campuscodi@mastodon.social avatar

Newsletter: https://news.risky.biz/risky-biz-news-supply-chain-attack-in-linuxland/
Podcast: https://risky.biz/RBNEWS269/

-Supply chain attack in Linuxland
-AT&T confirms 2019 data breach
-Canonical switches to manual reviews after flood of scam crypto apps
-HP leaves Russia
-Prisma Finance for $12mil
-NSA/Cybercom to keep election security group leaders anonymous
-250 Indians repatriated from Cambodia scam centers
-Fortra, TeamCity, and Splunk security updates
-Unconfirmed Signal zero-day
-Hot Topic discloses cred-stuffing attack

jbaert, to random
@jbaert@mastodon.social avatar

Finally banned from computer vision / image processing papers: the "Lena" playboy image that was used since 1972

https://arstechnica.com/information-technology/2024/03/playboy-image-from-1972-gets-ban-from-ieee-computer-journals/

eff, to random
@eff@mastodon.social avatar

Almost all of us rely on Wi-Fi outside of our homes. That access should be protected against government surveillance. https://www.eff.org/deeplinks/2024/03/eff-asks-oregon-supreme-court-not-limit-fourth-amendemtn-rights-based-terms

eff, to random
@eff@mastodon.social avatar

Face recognition technology has been plagued by bias because early models were “trained” mostly on white, male faces, @kashhill tells EFF’s Cindy Cohn & @jgkelley on the new episode of “How to Fix the Internet.” https://www.eff.org/deeplinks/2024/03/podcast-episode-about-face-recognition

PrivacyDigest, to privacy
@PrivacyDigest@mas.to avatar

AT&T says leaked data set affects about 73 million current, former account holders

Telecom company AT&T said on Saturday that a data set released on the "dark web" about two weeks ago has impacted approximately 7.6 million current account holders and 65.4 million former account holders, based on the company's preliminary analysis of the incident.
#att #privacy #security #leak

https://finance.yahoo.com/news/1-t-says-leaked-data-143508014.html

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

HT to @wdormann here - somebody has backdoored the open source project XZ which has downstream impacts.

For example, although OpenSSH doesn’t use XZ, Debian patch OpenSSH and introduced a dependency which translates as the XZ changes introducing a sshd authentication bypass backdoor it appears.

One dude bothered to investigate in his free time about why ssh was running slow, so it was caught fairly early - i.e. hopefully before distros started bundling it.

https://www.openwall.com/lists/oss-security/2024/03/29/4

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Really good timeline of what is known to have happened so far. It looks like the rogue developer deliberately introduced a vulnerability in other package, too - I haven’t seen anybody else mention this.

Reading the dev’s GitHub history, they’ve been making changes to other open source projects too around compression. It also appears they/somebody involved has other accounts, too.

https://boehs.org/node/everything-i-know-about-the-xz-backdoor

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • kavyap
  • thenastyranch
  • ethstaker
  • osvaldo12
  • mdbf
  • DreamBathrooms
  • InstantRegret
  • magazineikmin
  • Youngstown
  • ngwrru68w68
  • slotface
  • GTA5RPClips
  • rosin
  • megavids
  • cubers
  • everett
  • cisconetworking
  • tacticalgear
  • anitta
  • khanakhh
  • normalnudes
  • Durango
  • modclub
  • tester
  • provamag3
  • Leos
  • lostlight
  • All magazines