mwguy

@mwguy@infosec.exchange
18 Followers
86 Following
750 Posts
Location of ICE thugs arresting and harassing people in Camarillo, CA, Ventura Co.
@georgetakei
Good luck Texas, the majority of census growth here is from immigrants
@randahl I'm not buying his act - I suspect this is more about pulling Tesla out of the dumpster than anything else.

🧵2/2

...Mars was one of russia’s largest revenue generators and top taxpayers in both 2022 and 2023. In 2023, the company made $2.9 billion in revenue in russia and paid $99 million in profit tax alone.

The company claims it’s focused on its “essential role in feeding the russian people and pets” — because, apparently, Russians just can’t be left to suffer without M&M’s and Snickers. 🤷‍♂️

B4Ukraine repeatedly reached out to Mars to initiate a dialogue, but received no response.

#SponsorsOfWar

🧵1/2

US company Mars (owner of brands such as Snickers, Twix, Mars, M&M’s, Skittles, Orbit, Pedigree, Royal Canin, and Whiskas) has leased over 40,000 sq m in a logistics complex under construction in moscow due to business growth, Forbes reports.

Consultants say this is one of the largest recent warehouse real estate deals in russia.

The American company announced in March 2022 that it would cease new investments and halt advertising in russia.

Despite this... ⤵️

Back in the day, Twitter used to be really good if I set up a thread to connect freelancers with clients. Let's see if Mastodon can do it.

Clients: if you're looking for freelancers/contractors, get in the comments

Freelancers/contractors: get in the comments

Everyone else: boosts appreciated.

The market is *dead* for freelancers and a big part of that (in my opinion) is fragmentation. Let's get that network effect *back*.

#FediHire

So the UK Met Office is inviting people to suggest up to 5 names for storms. And apparently lots of people have been suggesting "Storm Bigoil", along with BP, Equinor, Exxon & Shell... This is obviously appalling & definitely not to be emulated via this link:

https://www.metoffice.gov.uk/forms/name-our-storms-call-for-names

Execs are giddy with anticipation about all the humans (they think) they can replace with AI. Short-sighted on their part, in my opinion, and demoralizing for all of us hearing the giddy at every meeting.

Update 3: You can find my PostMortem here: https://infosec.exchange/@masek/114721620930871030

Update 2: As far as I can tell, the servers that caused the leak belonged to the DOJ in Montana. We reached them in two ways:

  • Through this post we got contact to the vendor of the software. With the Serial# (in the extraction reports) they could identify whom to call.
  • A friend had a contact in one of the affected police department and they reached out to the DOJ.

Thanks to this community I was also able to get a contact within the FBI. Furthermore some media contacted me and a lot of Mastodon users provided me with additional contacts.

Event though I contacted the AG in Monatana and one PD, no one has reached out to me from the DOJ side.

Update 1: Leak is closed. Will write more tomorrow. Thank you to everyone who helped.

Phone forensics

Usually law enforcement is very secretive about them analyzing the phones of suspects.

But a forensic lab in #montana is extremely transparent about it. They put the dump of every phone on a public share. Everyone with Internet access can access those dumps.

While I am usually a proponent of government transparency, this takes it a bit too far even for my taste.

Every phone dump is one directory and some case names can be easily connected to crime & death headline news in the U.S.

So for one case I am pretty sure, that I can even say which Sheriff is responsible for that one of the investigations.

I sent that Sheriff an email, i sent him a text message and I even spoke on his voicebox. I even sent him the extraction report from Graykey.

It is really frustrating that I get no response at all. The leak is still open.

The security researcher that found the leak also tried some contacts but had as little success as I do.

I personally believe that this leaks even constitutes a federal crime. Some cases have names ending on CSAM. The security researcher stayed away from any of those and I did not access the files on that server at all.

So does anybody know someone within the #fbi that would give a shit about that. I am getting very tired.

#graykey #cellebrite #forensics

Martin Seeger (@masek@infosec.exchange)

## PostMortem: Assumed DOJ Montana Leak of Phone Dumps ### Type of leak Highly confidential information on a public SMB share without authentication ### Threats from the leak I see the following threats: - Integrity and Confidentiality of investigations into serious crimes compromised - Privacy of U.S. citizens compromised (very likely to contain most intimate data) - Providing 3rd parties hostile to the U.S. with blackmail material 1/4

Infosec Exchange