Posts

This profile is from a federated server and may be incomplete. Browse more on the original instance.

jsrailton, to poland
@jsrailton@mastodon.social avatar

NEW: second judge in #Poland reportedly confirmed as #Pegasus spyware victim.

Appeals court judge told reporter her responsibilities included classified cases where wiretapping was used.

Poland's spyware reckoning continues.

[PL, machine trans.]
Story: https://oko.press/wiemy-o-drugim-polskim-sedzi-inwigilowanym-pegasusem-to-sedzia-apelacyjna-z-krakowa-news-oko-press

#spyware #infosec #cybersecurity #polska #malware #security #intelligence #surveillance

jsrailton, (edited ) to environment
@jsrailton@mastodon.social avatar

Reading this🧵? Your blood probably contains some amount of toxic made by

Enough to spike your risk of cancers & illnesses?

Without a blood test, you have no idea.

Why is their toxin running in your veins?

Well, 3M & kept the harms secret even as their toxins were incorporated into...everything.

From french fry bags to chairs.

They gaslit their own scientists.

& regularly dumped, creating toxic zones. 1/

https://www.propublica.org/article/3m-forever-chemicals-pfas-pfos-inside-story

jsrailton,
@jsrailton@mastodon.social avatar

2/ Risks from #foreverchemicals include Diabetes, obesity, testicular #cancer, developmental delays...

Some researchers think that anyone exposed to these chemicals will have an elevated cancer risk.

At ANY concentration.

Since scientists estimate that we ALL have at least one of these forever chemicals in our blood...

That would be all of us.

#environment #endocrine #immunesystem

jsrailton,
@jsrailton@mastodon.social avatar

3/ If the "we are all at risk of cancer" from #foreverchemicals framing for some reason doesn't bug you, consider the taxpayer costs.

Numbers are staggering.

$64 billion in estimated increased disease burden in a single year.

Meanwhile #3M makes $1.5 billion a year from making the stuff.

And 16,000 of 3M's products still contain the chemical.

While company pledges to wind down manufacture. They haven't stopped.

To date, 3m has not admitted wrongdoing and faced no criminal liability

jsrailton, (edited ) to Health
@jsrailton@mastodon.social avatar

Even for cancer and transplant patients.

We are speeding into idiocracy.

bouriquet,
@bouriquet@mastodon.social avatar

@jsrailton Just another state I can put on my list to never set foot in or spend another cent in again.

CindyWeinstein,
@CindyWeinstein@zirk.us avatar

@jsrailton.

Is it also illegal to say, "I have my reasons"? Has that free speech also been banned?

jsrailton, to infosec
@jsrailton@mastodon.social avatar

FINALLY: a 🇺🇸US official speaks the truth security researchers keep warning about...

Americans' movements being tracked with well-known weaknesses that US telcos aren't fixing.

It's remarkable how bad the problem with & is.

Must-read story by @josephcox
https://www.404media.co/cyber-official-speaks-out-reveals-mobile-network-attacks-in-u-s/

jsrailton, (edited ) to psychology
@jsrailton@mastodon.social avatar

I can confidently diagnose as sociopaths.

Promised therapy customers privacy...then gave their mental health info to advertisers.

Victims get less than ten bucks each.

Company made billion+ in revenue last year alone.

In a just society with good privacy laws, they'd face existential civil & criminal consequences.

https://www.wcnc.com/article/news/nation-world/betterhelp-therapy-class-action-settlement-refund/507-b4ef5e0f-c722-4562-95e9-c3cdd7738d1a

jsrailton,
@jsrailton@mastodon.social avatar

@eccentric_econ Interesting, thanks for sharing your perspective.

jamieb,
@jamieb@mastodon.social avatar

@jsrailton Hopefully the start of that will be all the YouTube channels refusing sponsorship. Remember the kerfuffle with Established Titles? Since then I’ve not seen a single sponsor from them, and hopefully something similar will happen with Better Help.

It might not put them under but hopefully it will put a dent in their bottom line and make them think twice before doing something like this again.

jsrailton, to egypt
@jsrailton@mastodon.social avatar

All shipping traffic stopped on the Strait.

Channel connects Black Sea & Mediterranean is busiest in the world.

Why? Bulk carrier is grounded across northbound shipping lane.

Headed to from .

Turkish maritime authorities say on Twitter that they suspect mechanical failure.

image/png
image/png
image/png

jsrailton,
@jsrailton@mastodon.social avatar

UPDATE: Movement!

Watching ship tracking live it appears the hardworking tugs freed bulk carrier & the party is now heading South as some of the Tugs break off.

image/png

martijn_grooten,
@martijn_grooten@mastodon.social avatar

@jsrailton Evergreen toot.

jsrailton, to Toronto
@jsrailton@mastodon.social avatar

My colleague Mitchell & partner just escorted a family of lost geese to the lake.

Safely navigating 2km of downtown took 2 hours.

At one point, police stepped in to block traffic.

Strangers jumped in to help too.

He jokes: at @citizenlab we don't just help humans!

image/png
image/png
image/png

Nonilex,
@Nonilex@masto.ai avatar

@jsrailton @citizenlab just lovely

rinske,
@rinske@mastodon.social avatar
jsrailton, (edited ) to infosec
@jsrailton@mastodon.social avatar

Big companies are churning out bullshit "security advice" on an industrial scale.

It's a marketing funnel that targets those seeking help.

And then misinforms them.

I wish it stopped there

The nonsense makes its way to victims of spyware, where misinformation can have life, death and liberty impacting consequences.

gunther,
@gunther@fosstodon.org avatar

@jsrailton The article certainly looks like clickbait, but can you clarify what exactly about it is misinformation?

jsrailton,
@jsrailton@mastodon.social avatar

@gunther Each article is bad in different ways :)

But one area where it's easy to see issues is in the advice they give.

The consensus correct advice to someone targeted with Pegasus et. al. would be : seek out expert support, and here are the resources XYZ that can provide it to you.

If you don't make that your main piece of top advice, you are doing it wrong.

Which none of these articles does...

jsrailton, (edited ) to hacking
@jsrailton@mastodon.social avatar

BREAKING: private investigator arrested for cyberespionage on behalf of American PR firm.

Caught by UK under from 🇺🇸US while boarding a flight.

BIG TWIST in a wild case that began w/our @citizenlab investigation into indian hack-for-hire group

Sound familiar?

Because Amit Forlit is the second PI from arrested in similar way for this case.

First = convicted.

https://www.reuters.com/world/israeli-private-eye-arrested-uk-over-alleged-hacking-us-pr-firm-2024-05-02/

jsrailton, (edited )
@jsrailton@mastodon.social avatar

There's a disgraceful ecosystem of public relations & lobbying firms using hackers for hire.

Sometimes they are used to silence critics & advocacy groups.

Like US nonprofits doing climate advocacy.

Our investigation into a group we christened #DarkBasin uncovered a sprawling #India-based hack-for-hire operation.

They enabled US corporations to outsource lawbreaking.

https://citizenlab.ca/2020/06/dark-basin-uncovering-a-massive-hack-for-hire-operation/
#infosec #cybersecurity #malware #hacking #climatechange #climatecrisis #exxon #phishing

jsrailton, (edited )
@jsrailton@mastodon.social avatar

I'd bet my bottom dollar that this "unnamed...PR and lobbying firm" knows exactly who they are...

...and are no doubt experiencing an afternoon of the purest panic.

Using the offshore hack-for-hire ecosystem has been largely consequence-free for the middlemen & the ultimate beneficiaries of stolen information.

The tide may be turning & this latest arrest suggests that more consequences may be inbound.

jsrailton, to poland
@jsrailton@mastodon.social avatar

NEW: "shocking and depressing"

"...even in this room I am speaking to people who were victims of this system"

's prosecutor general testifies to 🇵🇱 parliament about hacking of 100s with spyware.

Story: https://apnews.com/article/poland-spyware-pegasus-nso-group-israel-413bb3cb27daac011d52b524c6d16160

image/png

jsrailton, (edited ) to poland
@jsrailton@mastodon.social avatar

BREAKING: spyware abused in 🇵🇱 under previous PiS-party government, confirms the new PM Donald Tusk

"Very, very long" victim list.

Vindication.

When we @citizenlab first confirmed the hacking in 2021 both we & victims were targeted w/extensive harassment & disinformation.

REPORT: https://apnews.com/article/poland-government-pegasus-spyware-tusk-duda-78420fc7099401926d28b5be98669192

Awoke,
@Awoke@mastodon.social avatar

@jsrailton @citizenlab


MAKES ZERO SENSE Netanyahu, had this spyware tool & wasn’t prepared 4 OCT 7th Attack❓
The crime matches TRUMP’S Jan 6th INSURRECTION.

image/png
image/jpeg

wonka,
@wonka@chaos.social avatar

To the absolute surprise of... nearly no one.

@jsrailton @citizenlab

jsrailton, to random
@jsrailton@mastodon.social avatar

NEW: heard about ? Something about ?

Or the waxing paranoid about ?

What does it all mean?

Well, my @citizenlab colleague Bill Marczak has an deliciously spicy take on the unfolding saga.

Plus some tips for defenders.

https://medium.com/@billmarczak/triangulation-did-the-nsa-fail-to-learn-the-lessons-of-nso-5f36d251d02e

jfmezei,
@jfmezei@mstdn.ca avatar

@jsrailton @citizenlab Big advantage IF NSA got Apple's cooperation is distributing a signed version of IOS to users in Russia that contains the modified BackupAgent. While each App has its own rooted file system and can't normally touch/see another app's files (unless you grant permission), the backup process (either to iCloud or to a Mac/PC with iTunes/Finder has access to all App's files.

starchturrets,

@jfmezei @jsrailton @citizenlab While wholesale cooperation would make this moot, apps can choose to exclude themselves from backups. It’s long been a complaint, for example, that Signal on iOS has literally no way of backing up messages.

jsrailton, to random
@jsrailton@mastodon.social avatar

NEW: I found 1000s of shady PDFs hosted on .gov websites of states, universities, defense contractors, etc.

It was a clever SEO spam operation, but the access could have been exploited for more nefarious things. 1/

@lorenzofb has the writeup

https://techcrunch.com/2023/06/02/scammers-publish-ads-for-hacking-services-on-government-websites/

image/png
image/png
image/png

jsrailton,
@jsrailton@mastodon.social avatar

2/ SEO operations like this are a bit like opportunistic infections for Content Management Systems.

They show up when there are bugs, misconfigurations & permissions issues.

rapidly pushed out notifications to affected orgs & the content is coming down all over.

jsrailton,
@jsrailton@mastodon.social avatar

3/ The PDF spam is still all over. Including many gov sites.

Want to help?

1️⃣ Google search:

"site:[pick a top-level domain e.g. .gov.au .gov.uk etc.] instagram hack followers filetype:pdf"

2️⃣mix in terms e.g. "Tiktok" & "fans."

3️⃣ Cry

4️⃣Gently notify administrators

jsrailton, to random
@jsrailton@mastodon.social avatar

Remember Tara Reade?

The one-time accuser is live on 🇷🇺Russian State TV announcing that she's defected.

Sitting with Maria Butina whom she refers to as a friend.

image/png

jbaggs,

@jsrailton That's...lovely.

jsrailton, to random
@jsrailton@mastodon.social avatar

Notice how fast alleged medical concern for youth became... smash rainbow displays at Target?

This is a playbook.

It must be forcefully resisted.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • tester
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • osvaldo12
  • ethstaker
  • Youngstown
  • mdbf
  • slotface
  • rosin
  • ngwrru68w68
  • kavyap
  • GTA5RPClips
  • provamag3
  • cisconetworking
  • InstantRegret
  • khanakhh
  • cubers
  • everett
  • Durango
  • tacticalgear
  • Leos
  • modclub
  • normalnudes
  • megavids
  • anitta
  • lostlight
  • All magazines