712 karma · joined March 12, 2014
You mention Dmitry Sklyarov but more recently Marcus Hutchins (MalwareTech) has been also arrested by the FBI following its appearance at Blackhat or Defcon
I don't think it is economically viable to maintain two sets of power distribution (electricity and petrol) at the same time so countries will probably "push out" traditionnal petrol stations once they think EV distribution is okay enough
And honestly it was the European's fault to believe in this pipe dream.
Same thing with corporate internet, you accept to use the corp proxy DNS and firewall (which all logs infos) to browse the internet instead of using a separate GSM endpoint to circumvent the company's surveillance.
It means for example being systematically in cc for mail exchanged and being in every teams discord channel. The new social contract when working remotely is "you (the manager) can't look over my shoulder to see if I'm working correctly so I (the employee) need to show proofs of communication instead".
I've seen too many juniors working remotely that just don't communicate on their day-to-day work, and completely blindside their manager/coworkers which understandably freaks out.
Then you need remote "telemetry", meaning access either to chat messages, email, tickets, etc. and a way to process it at scale (without reading everything) in order to defuse sticky situations based on partial infos or misunderstandings. Such tools can be panopticon-y so you need to explicitly specify which convos "spaces" are private and which are subject to management interference.
This project is fine for the author's self-improvement on how SSH is implemented, but personally I advise against using it in a production environment.
The fact that the attacker has almost a full-chain but no persistence screams to me "second fiddle", probably a nation state that have access to 0-days brokers but no in-house engineering.
No way any reputable OS vendor would agree to enable, for example, Dutch intelligence services spying on Russian citizens living in the UK.
- "le fait de ne pas communiquer les codes de déverrouillage de l'appareil ou de ne pas répondre aux forces de l'ordre en cas d'interpellation ; " // to not unlock your phone when police ask for it during an arrest
- "le fait de laisser son téléphone mobile allumé à son domicile ou de le mettre en « mode avion » en arrivant sur les lieux de la manifestation pour éviter le bornage, " // leaving your phone at home and go protesting in order to prevent from being geotagged
Not it won't. Facebook removed the chronological feed 10 years ago, they won't reintroduce it in Threads.
"Curated" feeds is how they get announcers to pay for visibility since the user has no control over what it is displayed at a given time
the DRM industry gets away with it since consumers don't care about openness or libre, they just want to watch videos in hi definition.
You can be chummy all you want with the people you are hiring for, but the relation will never be as equals and you have to be cognizant of that.
Windows did try to incite devs to use the windows store but it did not catch on. Restraining third-party installation only from the Store is a good way to remove adwares and co.
Honestly Microsoft did shat the bed with their app store, it has no right to be as difficult to use (both as user and developer) as it is.
They even joke about having to learn portuguese if you want to work in construction due to the massive number of portuguese tradesmen across Europe
However, there is an ongoing discussion about offensive security tools such as Flipper Zero, IMSI-catchers, phishing frameworks, meterpreter lookalikes, etc. and their consequences on the overall security landscape. It used to be that tools were just tools, but now legislators and the general public ask for more responsibility from tools vendors. For example publishing a complete n-day exploit for a major vulnerability (windows/Linux RCE, O365 RCE, etc.) is becoming more and more frown upon since it primarily enables attackers.
Youtube is since ~2016 primarly a platform for music clips, a sorta MTV for millenials and GenZ. They absolutely do not give a fuck anymore for content creator and hobbyists.
The faster people will understand that, the less they will be enraged about ContentID/DMCA
Since Google and P0 are so worried about the safety of theirs users's ecosystem, they should issue CVEs for internally found bugs in Chrome so that CEF, Electron, and every chrome-like projects maintainers can verify if they have backported the correct fix. They even complained about downstreamers leaving a patch gap for attackers recently :)
Unfortunately, nowadays CVEs are a commodity (perhaps a currency in the future ?) where the less you have the more "secure" your system is, which is utter bullshit.
That being said, they way he has been treated is absolutely infuriating and probably illegal in numerous countries which are not the USA.
ssf and other tunneling techno are already abused by a lot of threat actors ...
Since GDPR, PII (Personal Identifiable Information) data has become radioactive, the less you touch it easier your life is.
But the remark still stand, and I hope OP has been correctly credited for it.