Vulnerabilities

Our city has had 3 attacks since Thursday. One, on our water utility, will probably mess up the paychecks of some of the hardest-working employees on the island. The attacks on the bus have made bus passes inoperable. The “Handi-Van” is a lifeline transportation service for disabled residents. Both of the latter seem to be back running after the first round of attacks, but with no real-time location data.

I don’t know if it is occurring to anyone to detach critical systems from the fucking internet.

4 Likes

And one week after…

4 Likes

YouTube-Mobile-App-Translate

So much safer.

7 Likes

ann b davis alice nelson GIF by HULU

3 Likes

It just gets worse.

Also, I love this project:

Exploiting the exploit to patch it.

6 Likes
4 Likes

I’m thinking “critical systems” might include “nervous systems.”

Back on topic, in related news:

https://www.cnn.com/2021/12/14/politics/maryland-health-department-hack-covid-19-data/index.html

This is how our county’s schools have closed until mid-Jan., in spite of ostensibly not having a high transmission rate.

(Narrator: We do.)

5 Likes

Via Bruce Schneier’s blog.

Cytrox was reported to be part of Intellexa, the so-called “Star Alliance of spyware,” which was formed to compete with NSO Group, and which describes itself as “EU-based and regulated, with six sites and R&D labs throughout Europe.”

2 Likes

The United Kingdom’s National Crime Agency and National Cyber Crime Unit have uncovered a colossal trove of stolen passwords.

We know this because Troy Hunt, of Have I Been Pwned (HIBP) fame, yesterday announced the agency has handed them over to his service, which lets anyone conduct a secure search of stolen passwords to check if their credentials have been exposed.

The NCA shared 585,570,857 with HIBP, and Hunt said 225,665,425 were passwords that he hasn’t seen before in the 613 million credentials HIBP already stored before the NCA handed over this new batch.

[…]

Maybe someone could cross-post this in the Public service announcements for happy mutants! thread? I’m currently frustrated by the no-more-than-two-consecutive-posts rule.

3 Likes
7 Likes

Is this just for Wireless customers? If this setting exists for FiOS, I can’t find it…

1 Like
6 Likes

I’m sure that Stingray-type boxes have more tricks, but this blocks a basic one.

7 Likes
1 Like
4 Likes
4 Likes
2 Likes

Hm. I didn’t realize that they were using a different (old and failed for its original purpose) technology for those.

Presumably there’s a generic UWB API to inventory the devices in range like Bluetooth. Check the GPS to see if you’ve moved at least 100’, then inventory again. Any devices still there are probably traveling with you.

That would just need a phone or device with UWB or a USB dongle.

Serious pet peeve of mine… Harvesting data should be right up there with slavery as a banned practice.

They missed a couple of other tricks, but it’s always more work to do this:

  • Get a (cheap or free) throw-away email from a separate ISP or mail provider for each streaming service. If you have a domain for something, they often come with email. Make it hard for them to collate data. Got separate credit cards? Use them for billing.
  • They cost more, because they are not monetizing your data, but get a commercial display or hotel TV (e.g. CDW has them). At least then you control what’s running the video.
  • Get an antenna. Here in Mississauga :canada: we can pull in about 30 channels, including all the major networks (but not Fox News, and that is good for my blood pressure). It’s higher data rate than cable too, the picture can be a lot better.
  • If you really feel like doing a bit of work: throw chaff. Program your box to stream random selections day and night. It’s not like Netflix’s recommendations are going to get much worse…

Smart home things can be done also in ways that leave you in control… if you’re so inclined.

Training the the monkey children to do tasks for you is challenging, rewarding, and can work. I’ve automated the vacuum cleaning, garbage, coffee grinding and lawn mowing that way. Arguably not cost effective, though. It’s trickier with the cats, but they’ll take care of mice, rats and rabbits. :thinking:

6 Likes
1 Like