RE: https://me.dm/@bayo/116270059395367077

Data Mesh without product thinking is just decentralized chaos with better slide decks. 📊

Most teams distributed ownership. Nobody followed with accountability.

The teams winning? They treat data contracts as the API boundary, not a catalog entry.
Schema. SLA. Lineage. Enforced at write time. Not discovered at incident time.

Mesh vs marketplace. The difference is one enforced contract. 🏗️

#DataMesh #DataProducts #DataEngineering #EvilTwin #EvilMaid #Amazon

RE: https://infosec.exchange/@briankrebs/116280575943263005

Workplace bullying doesn't always look like yelling. 😔

Sometimes it's subtle. Death by a thousand cuts.

If it's costing you your peace every single day, that's not a "tough job." That's a toxic one. 💙

No role is worth leaving your dignity at the door.

#WorkplaceBullying #EvilTwin #EvilMaid

I designed and built Tripwire: A new solution for anti evil maid defense: https://github.com/fr33-sh/Tripwire

If you have heard of Haven (https://github.com/guardianproject/haven), then Tripwire fills in the void for a robust anti evil maid solution after Haven went dormant.

Tripwire's GitHub repo describes both the concept and the setup process in great details. For a quick overview, read up to the demo video.

There is also a presentation of Tripwire available on the Counter Surveil podcast: https://www.youtube.com/watch?v=s-wPrOTm5qo

@eff @hackaday @QubesOS @guardianproject

#privacy #privacytools #security #evilmaid #tamperEvident #opensource #raspberrypi #selfhosted

GitHub - fr33-sh/Tripwire

Contribute to fr33-sh/Tripwire development by creating an account on GitHub.

GitHub
@gerowen #SecureBoot is a placebo anyway, designed only to strengthen #Microsoft's #monopoly and to prevent installation of #FOSS OS. I for one deactivate it routinely. The protecting affect for an end user is: nought, nil, zero. Ok, if you are a company that must fear #EvilMaid attacks, your mileage may vary.
Now that #Bitlocker with external #tpm are proven to be unsafe (simplified #evilmaid attack, you just need the laptop, if no tpm pin is used), should tpm pin-less encryption with discrete tpms still be considered encryption for #gdpr legal purposes?
#Billionaires Are A #Security Threat
There’s a #vulnerability known as #evilmaid attack whereby an untrusted party gains physical access to hardware. The “evil billionaire attack” the weapon is money where you won’t have enough of it to make a difference
https://bit.ly/3hHhMKo
Billionaires Are A Security Threat

Elon Musk’s Twitter takeover is a case study in destruction. It doesn’t have to be this way.

WIRED
Our text about 'Random Mosaic - Detecting unauthorized physical access with beans, lentils and colored rice' has received an update and expanded a few words about the app Blink Comparison from @proninyaroslav
. https://dys2p.com/en/2021-12-tamper-evident-protection.html
#privacy #security #evilmaid #hardwaresecurity
dys2p › Random Mosaic – Detecting unauthorized physical access with beans, lentils and colored rice

strengthening digital self-defense | research and development | providing privacy-focused goods and services

Random Mosaic - Detecting unauthorized physical access with beans, lentils and colored rice https://dys2p.com/en/2021-12-tamper-evident-protection.html #privacy #security #evilmaid #hardwaresecurity
dys2p › Random Mosaic – Detecting unauthorized physical access with beans, lentils and colored rice

strengthening digital self-defense | research and development | providing privacy-focused goods and services

#Encryption is one of the last bastions of #privacy. Alternative access routes: catch suspects by surprise w/disk unlocked, #0day, #evilmaid, #phishing, push seeded updates to device.. Many alternatives. *But*.. w/out backdoors you can't mass scan all #encrypted messengers. 🤔