269 Followers
799 Following
2K Posts
random clueless person from the internet
occasional accidental poet
fool with a keyboard
goes by kyrievo in some places
#noarchive #nobot #nobridge #noindex #noml
Accept-Languagede, en
Accept-Pronounshe/him
LocationLeipzig, Germany
Keyoxidehttps://keyoxide.org/7287c01a721c8432e525865a12b4df8abcf3f024
Websitehttps://mkhl.codeberg.page
Header-Byhttps://cohost.org/forSyn/post/5386177-was-requested-i-post
@ireneista love the description đŸ˜»
@ariadne maybe nuttail, as a humorous misread of Nuttall and in reference to the mountain cottontail?
I didn't realize the facebook execs Mozilla acqui-hired last year have been promoted! I was assuming they were still just heading the ads division of Mozilla, but oh boy, I fucking wish.

Now the
former Senior VP of Marketing of facebook (2008-2022, the finest years of facebook) is the CHIEF FINANCIAL OFFICER of the entire Mozilla.

And the
former VP of Ads in Facebook (2012-2022), is now the Senior VP of Product of Mozilla.

Let me repeat this:

The guy who used to lead the facebook team that was literally "
advertising to teenagers based on their emotional state" is now the guy who decides the direction of Firefox as a product. But hey, let's keep giving Mozilla the benefit of the doubt uh? I'm sure these people-who-should-be-on-trial-in-the-hague are going to do great things for the community!



edit: Bradwood has been promoted to Chief Business Officer of the Mozilla Corporation, not Chief Financial Officer, my bad

edit2: as
@[email protected] pointed out, even if Graham Mudd's title is "SVP of Product", the bio in his page talks about him as the SVP of Product for the Mozilla Ads division specifically. So it may be the case that he hasn't been promoted and he's just on top of the ad division. That being said, Mozilla doesn't have a Chief Product Officer anymore, and that makes Mudd the most senior product person in the entire Mozilla organization, outranking the VP that seems to be org-wide.
Mozilla Leadership

Mozilla

Your task for today:
Opt out of #Copilot, because #Microslop forces you into it soon otherwise.

https://github.com/settings/copilot/features

Chaos Communication Congress 2024:

"Do not obey in advance"
https://media.ccc.de/v/38c3-opening-ceremony#t=1347

#systemd: hold my beer.
https://github.com/systemd/systemd/pull/40954
"as required by recent laws"

Merged 4 days ago.

If German communication infrastructure providers had obeyed in advance like that, privacy violating data retention would be a reality in Germany now.

#38c3 #ccc

38C3: Opening Ceremony

media.ccc.de

Firefox updated their Terms of Use? Let's see!

As you type a search query within Firefox, Firefox offers search suggestions to provide you with faster and more direct access to what you’re looking for. Some of the search suggestions come from your search provider (“Search Suggestions”). Others come from Firefox, and are based on information stored on your local device (including recent search terms, open tabs, and previously visited URLs), or content from Mozilla and Mozilla’s partners, including paid sponsors and internet resources like Wikipedia (“Suggestions from Firefox”).

Here chat. Here. This is where Firefox dies.

"information stored in your local device" and "content from mozilla's parners" and "paid sponsors".

This is a very convoluted way of saying "we use your personal data to segment you into something we can sell to advertisers".

This is EXACTLY what chrome does, this is exactly why a lot of us stopped using Chrome and moved back to Firefox.
In some circumstances Mozilla’s partners will receive de-identified search and interaction data, in order to serve relevant suggestions and measure user engagement with suggested content.This is making me really mad. THIS IS JUST CORPO-SPEAK TO DESCRIBE HOW THE ENTIRE INTERNET ADVERTISEMENT INDUSTRY WORKS. This is HOW FACEBOOK WORK. This is how GOOGLE WORK. This is how the entire programmatic advertisement industry work. This is what we call "sell your personal data". No, no one sells your address, no one sells your name. BECAUSE IT'S ILLEGAL IN A SIGNIFICANT PART OF THE WORLD.
We also work with advertising providers to deliver relevant sponsored content using programmatic technologies. To support this, we may share limited, non-identifying information — such as device type, IP-derived location information, and category of content viewed — to help determine which ads to display. We don’t share any information that identifies you. You can turn off sponsored content in your New Tab settings at any time.Oh it's so nice of you Mozilla, to do THE MINIMUM LEGAL REQUIREMENTS when selling our data. You don't share information that identify me? so nice of you! you know how else does that? Meta! Google! Tiktok! Somehow big tech mega corporations are willing to comply with the minimum legal requirements as you do, mozilla!In some cases, we may share or publish aggregated and anonymized data to facilitate research or as part of the lawful business purposes outlined above (such as sharing aggregated insights with advertising partners).This is called "advertisement segmentation" and it's what it paid for Zuckenberg fortress in Hawaii!! Going places, Moz, you are operating exactly as how Facebook used to do in 2016!To provide our services as described above, we may disclose personal data to: Partners, service providers, suppliers and contractors"We never disclose your personal data!!! well, unless it's one of our partners who pays us for it, of course!"

oh wait! they include a table of what kind of data they share with partners!
Technical dataLocationLanguage preferenceSettings dataUnique identifiersSystem performance dataInteraction dataSearch dataBrowsing dataThe SHARE FUCKING EVERYTHING. THEY ARE SELLING EVERYTHING. "Unique identifiers" is the closest to personal identifiable data they can sell. That's what advertisers can use to make a profile of you: They may not know your name, but they will know everything else about you.

This is the same information that google collects and sells from you. THE SAME.

Fucking ghouls. This is where Firefox died, folks.

Firefox Privacy Notice

Mozilla
FOUND IT
Warum ist das nicht in den Schlagzeilen: In Offenbach a.M. hat die AfD ihr Ergebnis HALBIERT. Wenn sofort "AfD stÀrkste Kraft!" kommt, wenn sie in einem Wahlkreis knapp mit 25 % auf Platz 1 liegt, warum werden ihre Niederlagen verschwiegen? Warum sind es nur News, wenn die AfD gewinnt? https://www.volksverpetzer.de/analyse/kommunalwahl-ergebnis-ioffenbach-halbiert/?utm_source=mstdn

Static + dynamic analysis of Signal's APK. The good news first: Signal is genuinely exceptional.

Rust core (libsignal_jni.so), post-quantum hybrid Double Ratchet (Kyber-1024 + X25519), Direct ByteBuffers with immediate zeroing after PIN/username hashing, Intel SGX attestation for SVR — MREnclave verification means even a compromised Signal server can't extract your PIN hash.

But two things stood out:

1. Firebase is always there. Google receives IP + notification timestamps regardless of message content. If you need metadata privacy, Signal still leaks presence data to Google's infrastructure.

2. Certificate revocation endpoints hit http://g.symcd.com in plaintext. An ISP or state-level observer can fingerprint Signal usage from DNS queries and HTTP traffic to those CAs — without touching message content.

Conclusion: strongest crypto engineering in consumer messaging. The attack surface isn't the cryptography. It's the operational dependencies.

Soon the full analysis

#infosec #AndroidSecurity #Signal #privacy #ReverseEngineering #postquantum #mobileforensics

heard "be the elephant you want to see in the room" earlier and gosh if that hasn't stuck with me