Manuel D'Orso

186 Followers
106 Following
727 Posts
Ⓐ INTJ metalhead • DevSecOps enthusiast
He/him, Italy
Signalcirku.17
A.B. 1043’s Internet Age Gates Hurt Everyone

EFF has long warned against age-gating the internet. Such mandates strike at the foundation of the free and open internet. They create unnecessary and unconstitutional barriers for adults and young people to access information and express themselves online. They hurt small and open-source...

Electronic Frontier Foundation
Critical N8n Vulnerabilities Allowed Server Takeover

Two critical-severity n8n vulnerabilities could have led to unauthenticated remote code execution, sandbox escape, and credential theft.

SecurityWeek

RE: https://mastodon.social/@sovtechfund/116158681333088146

Final call, the survey closes on Monday!

Interesting new project from #Tor #SecureDrop - that’s essentially digitally signed web pages that are client-verified to prevent any server-side covert injection or backdooring. Sounds a bit like SRI (Subresource Integrity) but for the whole page and using digital signature not just server-delegated hash. Obviously, it won’t work for a typical ‘modern’ mash-up website that changes every minute, but sounds perfect for high-integrity and largely static pages such as SecureDrop.

WEBCAT helps protect users from malicious or unexpected changes to the client-side code of a web application. When a user visits a site that has enrolled in WEBCAT, the WEBCAT browser extension verifies the application’s served assets against a signed manifest before any content is executed. If verification fails, WEBCAT blocks the page from loading and shows a warning.

https://securedrop.org/news/webcat-alpha/

#infosec

Help us test WEBCAT alpha

Web applications are only as trustworthy as the servers that serve them, and servers can get hacked. So, last year, we introduced WEBCAT (Web-Based Code Assurance and Transparency), a project designed to enable verifiable in-browser code for web applications. We wrote extensively about WEBCAT’s requirements, constraints, and goals.Today, we’re excited to announce the alpha release of WEBCAT. In particular, we invite community participation in a new, decentralized enrollment infrastructure.

SecureDrop
At Mobile World Congress (MWC) in Barcelona, Motorola (a Lenovo company) announced a partnership with the GrapheneOS Foundation to deliver GrapheneOS, a privacy-focused Android fork, on future Motorola smartphones starting in 2027. https://www.zdnet.com/article/motorola-to-preinstall-grapheneos-on-2027-phones-mwc-2026/
I can't wait for Motorola's GrapheneOS phones: Why they're a win for privacy and open source

At Mobile World Congress, Motorola reveals plans to preinstall GrapheneOS, a privacy-focused Android fork, on smartphones starting next year.

ZDNET
Fips: Free Internetworking Peering System - Nostr mesh routing protocol
https://github.com/jmcorgan/fips
GitHub - jmcorgan/fips: Free Internetworking Peering System - mesh routing protocol

Free Internetworking Peering System - mesh routing protocol - jmcorgan/fips

GitHub
Across the US, people are dismantling and destroying Flock surveillance cameras

Anger over ICE connections and privacy violations is fueling the sabotage. PLUS: 10,000 drivers call on Uber to repay stolen wages, a man is arrested at a public hearing about a data center and more.

Blood in the Machine

🏙️ We are supporting the creation of the Democratic Tech Fund! 🪙

Yesterday, we gathered at the @internetarchiveeurope to shape a new consortium made to distribute funding for value-aligned projects 🌱

The next key moment will be a general assembly at #DWebCamp!

https://democratictech.fund

@commonsnetwork @mike_hales @d1 @SocialCoop

RE: https://infosec.exchange/@metacurity/116063250776966440

Se a qualcuno nel quotidiano? Probabilmente no. Possono collezionare dati per farci poi prodotti bellici? Assolutamente sì.