RE: https://me.dm/@bayo/116270059395367077

Data Mesh without product thinking is just decentralized chaos with better slide decks. πŸ“Š

Most teams distributed ownership. Nobody followed with accountability.

The teams winning? They treat data contracts as the API boundary, not a catalog entry.
Schema. SLA. Lineage. Enforced at write time. Not discovered at incident time.

Mesh vs marketplace. The difference is one enforced contract. πŸ—οΈ

#DataMesh #DataProducts #DataEngineering #EvilTwin #EvilMaid #Amazon

RE: https://infosec.exchange/@briankrebs/116280575943263005

Workplace bullying doesn't always look like yelling. πŸ˜”

Sometimes it's subtle. Death by a thousand cuts.

If it's costing you your peace every single day, that's not a "tough job." That's a toxic one. πŸ’™

No role is worth leaving your dignity at the door.

#WorkplaceBullying #EvilTwin #EvilMaid

I designed and built Tripwire: A new solution for anti evil maid defense: https://github.com/fr33-sh/Tripwire

If you have heard of Haven (https://github.com/guardianproject/haven), then Tripwire fills in the void for a robust anti evil maid solution after Haven went dormant.

Tripwire's GitHub repo describes both the concept and the setup process in great details. For a quick overview, read up to the demo video.

There is also a presentation of Tripwire available on the Counter Surveil podcast: https://www.youtube.com/watch?v=s-wPrOTm5qo

@eff @hackaday @QubesOS @guardianproject

#privacy #privacytools #security #evilmaid #tamperEvident #opensource #raspberrypi #selfhosted

GitHub - fr33-sh/Tripwire

Contribute to fr33-sh/Tripwire development by creating an account on GitHub.

GitHub
@gerowen #SecureBoot is a placebo anyway, designed only to strengthen #Microsoft's #monopoly and to prevent installation of #FOSS OS. I for one deactivate it routinely. The protecting affect for an end user is: nought, nil, zero. Ok, if you are a company that must fear #EvilMaid attacks, your mileage may vary.
Now that #Bitlocker with external #tpm are proven to be unsafe (simplified #evilmaid attack, you just need the laptop, if no tpm pin is used), should tpm pin-less encryption with discrete tpms still be considered encryption for #gdpr legal purposes?
#Billionaires Are A #Security Threat
There’s a #vulnerability known as #evilmaid attack whereby an untrusted party gains physical access to hardware. The β€œevil billionaire attack” the weapon is money where you won’t have enough of it to make a difference
https://bit.ly/3hHhMKo
Billionaires Are A Security Threat

Elon Musk’s Twitter takeover is a case study in destruction. It doesn’t have to be this way.

WIRED
Our text about 'Random Mosaic - Detecting unauthorized physical access with beans, lentils and colored rice' has received an update and expanded a few words about the app Blink Comparison from @proninyaroslav
. https://dys2p.com/en/2021-12-tamper-evident-protection.html
#privacy #security #evilmaid #hardwaresecurity
dys2p β€Ί Random Mosaic – Detecting unauthorized physical access with beans, lentils and colored rice

strengthening digital self-defense | research and development | providing privacy-focused goods and services

Random Mosaic - Detecting unauthorized physical access with beans, lentils and colored rice https://dys2p.com/en/2021-12-tamper-evident-protection.html #privacy #security #evilmaid #hardwaresecurity
dys2p β€Ί Random Mosaic – Detecting unauthorized physical access with beans, lentils and colored rice

strengthening digital self-defense | research and development | providing privacy-focused goods and services

#Encryption is one of the last bastions of #privacy. Alternative access routes: catch suspects by surprise w/disk unlocked, #0day, #evilmaid, #phishing, push seeded updates to device.. Many alternatives. *But*.. w/out backdoors you can't mass scan all #encrypted messengers. πŸ€”