Vulnerabilities

7 Likes

Trans criminals approve.

2 Likes

TikTok Parent ByteDance Planned To Use TikTok To Monitor The Physical Location Of Specific American Citizens

Cross post

5 Likes
3 Likes
5 Likes
6 Likes

Shine a light right up their assholes.

2 Likes

In addition to TrustCor’s certificate power, the firm offers what purports to be end-to-end encrypted email, MsgSafe.io. But researchers said the email is not encrypted and can be read by the company, which has pitched it to a variety of groups worried about surveillance.

As ever, games are being played. Cross posting to Spies, Lies and Realpolitik

5 Likes

Cory has a long piece about this as well.

https://pluralistic.net/2022/11/09/infosec-blackpill/#on-trusting-trust

4 Likes
6 Likes
4 Likes

With mandated spyware downloads to tens of thousands of surveillance cameras equipped with facial-recognition technology, the World Cup in Qatar next month is looking more like a data security and privacy nightmare than a celebration of the beautiful game.

Football fans and others visiting Qatar must download two apps: Ehteraz, a Covid-19 tracker, and Hayya, which allows ticket holders entry into the stadiums and access to free metro and bus transportation services.

Qatar’s Ehteraz contact tracking scheme came under scrutiny even before its World Cup use because it allows remote access to users’ pictures and videos, and can make unprompted calls.

Additionally, Ehteraz requires background location services to always be on and it gives the app the ability to read and write to the file system.

[…]

4 Likes

Timely advice. (I tend to avoid that sort of security-chaining when I can.)

8 Likes
4 Likes
3 Likes
8 Likes
5 Likes
4 Likes

Sure Elon, waste time throwing tantrums over public data about your plane.

6 Likes
7 Likes