Ins0mniak

@ins0miak
4 Followers
107 Following
29 Posts
I never get bored

SecureDrop 2.9.0 is scheduled to be released on June 27. This release will include new defenses against network attacks for the Source Interface, support for HTTP range requests, and an updated signing key with a 3-year expiration date.

https://securedrop.org/news/securedrop-2_9_0-pre-release-announcement/

SecureDrop 2.9.0: Pre-Release Announcement

SecureDrop 2.9.0 is scheduled to be released on June 27, 2024. We will send out another notification through this blog, Mastodon, X, and the support portal when the release is live. Changes that journalists and administrators should be aware of are summarized in this blog post. A complete list of changes can be found on GitHub.

SecureDrop
as cryptographers we are steadily running out of dr who references, i suggest we switch to star trek
job alert! my org at Brave is hiring a support engineer: https://brave.com/careers/?gh_jid=5476028.
Join us to Change the Web Together | Brave

Brave offers a new way of thinking and experiencing how the web should work. We're on a mission to fix the web by giving users a faster, safer and better browsing experience while supporting content creators through an ecosytem of rewards. It's so much more than your typical browser. Join the Brave revolution.

Brave

This is a great piece by @micahflee about the significance of supporting ephemeral usernames in @signalapp and the challenges #Signal faces developing the gold standard of private messaging apps.

https://theintercept.com/2024/03/04/signal-app-username-phone-number-privacy/

#privacy #security #encryption #signal

Signal’s New Usernames Help Keep the Cops Out of Your Data

Ephemeral usernames instead of phone numbers safeguard privacy — and makes the Signal messenger app even harder to subpoena.

The Intercept

Mozilla, please go back providing a good browser and stop doing all the other shit. I need a browser from you and the developer Network - that’s it. Why do you pivot to AI and advertising? There is no ethical advertising and the moment you provide targeting there is no privacy friendly advertising.

Sincerely, a user

My data protection assessment of Privacy Sandbox's Protected Audience API. I analyse it through the lens of #GDPR and #ePrivacy. It can be used in line with EU Data Protection, and may even help solving the cookie-consent fatigue. My LL.M. dissertation. https://blog.lukaszolejnik.com/data-protection-assessment-of-privacy-sandboxs-protected-audience-api/

The full content of my LL.M. dissertation at University of Edinburgh Law School The University of Edinburgh https://lukaszolejnik.com/stuff/PrivacySandbox_PAAPI_LLM_LO.pdf
#privacy #dataprotection #dataprotectionlaw #privacysandbox #web #webbrowser #standards

Data Protection assessment of Privacy Sandbox's Protected Audience API

Data protection assessment of Privacy Sandbox's Protected Audience API. It can be deployed and designed in compliance with GDPR.

Security, Privacy & Tech Inquiries

The ShinyHunters hackers who stole Ticketmaster data from Snowflake account appear to have accessed the data through a contractor named EPAM Systems. EPAM has workers in Belarus, Ukraine and, before the war, Russia. Hacker told me they breached an EPAM worker in Ukraine. EPAM says it found no evidence that the hackers used one of their systems, but data leaked online indicates an EPAM worker in Ukraine was infected with an infostealer, which grabbed credentials for the worker's Ticketmaster Snowflake account. EPAM manages Snowflake accounts for customers. My latest story for WIRED:

https://www.wired.com/story/epam-snowflake-ticketmaster-breach-shinyhunters/

Hackers Detail How They Allegedly Stole Ticketmaster Data From Snowflake

A ShinyHunters hacker tells WIRED that they gained access to Ticketmaster’s Snowflake cloud account—and others—by first breaching a third-party contractor.

WIRED
For data brokers dealing with our personal information, our data can either be useful for their profit-making or truly anonymous, but not both. Our privacy rights online must not be sacrificed so corporations can fill their pockets. https://www.eff.org/deeplinks/2023/11/debunking-myth-anonymous-data
Debunking the Myth of “Anonymous” Data

Today, almost everything about our lives is digitally recorded and stored somewhere. Each credit card purchase, personal medical diagnosis, and preference about music and books is recorded and then used to predict what we like and dislike, and—ultimately—who we are. This often happens without our...

Electronic Frontier Foundation

The BlackSuit ransomware gang is behind CDK Global's massive IT outage and disruption to car dealerships across North America, according to multiple sources familiar with the matter.

https://www.bleepingcomputer.com/news/security/cdk-global-outage-caused-by-blacksuit-ransomware-attack/

CDK Global outage caused by BlackSuit ransomware attack

The BlackSuit ransomware gang is behind CDK Global's massive IT outage and disruption to car dealerships across North America, according to multiple sources familiar with the matter.

BleepingComputer