Stefan Gast

223 Followers
322 Following
1,029 Posts

PhD Candidate in the CoreSec group at #TUGraz, focusing on side-channel security. Apart from that, I also post #Linux and #privacy related stuff.

Opinions posted here are my own and do not necessarily reflect those of my employer.

Websitehttps://stefangast.eu

https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/

So, it turns out the German implementation of eIDAS (electronic ID wallet for e.g. age attestation) will require an Apple/Google account to function

Absolutely pathetic

Mobile Device Vulnerability Management Concept - German National EUDI Wallet: Architecture Documentation

Ohne Google/Apple = Keine EUDI-Wallet

Die Wallet soll EU-Bürger*innen unabhängiger machen - doch sie vertraut blind den gleichen Tech-Giganten, die wir mit DMA & Datenschutzklagen bekämpfen.

Die Wallet prüft via Play Integrity (Android) & App Attest (iOS), ob euer Gerät sicher ist. Gerootet/Jailbroken? Kein Zugang. Veraltete Sicherheitsupdates? Blockiert.

Wie souverän ist eine digitale ID, wenn zwei US-Konzerne über ihre Nutzung bestimmen? Und was passiert, wenn Google/Apple die Attestierung einfach abschalten? Oder meinen Account sperren? Ich soll doch in der EUDI-Wallet zukünftig alles vom Personalausweis bis zum Mietvertrag speichern, wenn ich das recht verstanden habe.

via HackerNews

https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/#motivation

#DigitalSouveränität #eIDAS #EUDI #Privacy #BigTech

Mobile Device Vulnerability Management Concept - German National EUDI Wallet: Architecture Documentation

right now the astronauts are calling houston because the computer on the spaceship is running two instances of microsoft outlook and they can't figure out why. nasa is about to remote into the computer
#nasa #artemis #outlook #microsoft #microslop

🎉 Congratulations, Martin! 🎉

Martin Heckel (@lunkw1ll) successfully defended his #PhD thesis “Real-World Rowhammer: Understanding and Addressing the Challenges to Rowhammer Attacks” yesterday. 🥳
We wish him the best in his future endeavors!

since that browsergate site about LinkedIn seems to be gaining traction I figure I should mention:

  • yes, LinkedIn does do what's being claimed (though, it's that it probes for specific extensions you're running, using features in chrome's API - it doesn't "search your computer")
  • it does seem to have been doing this since at least as far back as 2017, and there has been intermittent reporting on it over the years
  • I'm fairly confident the copy on the site was generated by (or at least went through) an LLM, so idk that this site is the best way to spread the issue around

edit: and as someone else noted in the replies, looking through the list of extensions of scans for... they're pretty much all "AI"/scraper/automation plugins. so, should LinkedIn be doing this, or even able to do this in Chrome? no! but also, it does seem like the stuff they're scanning for is all extensions that shouldn't exist to begin with tbh

edit 2: please see this follow-up post which proves this is just a shitty campaign by people who made an addon called "Teamfluence" that got blocked by LinkedIn

GitHub - dandrews/nefarious-linkedin: :shipit: A look at how LinkedIn spies on its users.

:shipit: A look at how LinkedIn spies on its users. - dandrews/nefarious-linkedin

GitHub

Apparently #LinkedIn runs a silent browser scan on every #Chrome user who visits the site.

6.222 extensions.
~405 million users affected.
No consent, no disclosure, no mention in their privacy policy.

Read the full technical breakdown, legal analysis and searchable database of every scanned extension: https://browsergate.eu/

#BrowserGate #enshittification #microsoft

LinkedIn Is Illegally Searching Your Computer

Microsoft is running one of the largest corporate espionage operations in modern history. Every time any of LinkedIn’s one billion users visits linkedin.com, hidden code searches their computer for installed software, collects the results, and transmits them to LinkedIn’s servers and to third-party companies including an American-Israeli cybersecurity firm. The user is never asked. Never told. LinkedIn’s privacy policy does not mention it. Because LinkedIn knows each user’s real name, employer, and job title, it is not searching anonymous visitors. It is searching identified people at identified companies. Millions of companies. Every day. All over the world.

BrowserGate

More closed-door discussions with the Trump administration won’t strengthen cooperation, they will undermine trust, transparency, and in the worst case even the EU’s ability to enforce its own rules.

Together with other civil society organisations, we call on the @EUCommission to halt this “dialogue” and focus on stronger, faster, and more transparent enforcement of Europe’s digital laws.

Read our statement ⤵️
https://edri.org/our-work/europes-digital-laws-are-not-bargaining-chips/

Europe’s digital laws are not bargaining chips - European Digital Rights (EDRi)

In reaction to the recent plan to “open a formal dialogue” with the US government on EU tech rules, EDRi and other civil society organisations urge the Commission to halt this plan that risks giving Big Tech a back door to weaken the EU digital rulebook and its enforcement.

European Digital Rights (EDRi)
Donald Trump poltert bei jeder Gelegenheit gegen die EU und ihre Digitalregeln. Künftig soll ein neues Gremium der US-Regierung offenbar Mitsprache einräumen, berichtet das Handelsblatt. Im Gegenzug soll es Zollerleichterungen geben. https://netzpolitik.org/2026/neues-gremium-geplant-eu-will-trump-bei-digitalgesetzen-entgegenkommen/
Neues Gremium geplant: EU will Trump bei Digitalgesetzen entgegenkommen

Donald Trump poltert bei jeder Gelegenheit gegen die EU und ihre Digitalregeln. Künftig soll ein neues Gremium der US-Regierung offenbar Mitsprache einräumen, berichtet das Handelsblatt. Im Gegenzug soll es Zollerleichterungen geben.

netzpolitik.org
Posting this link here, as I always have to dig every few years when I need it: https://cdecl.org/ a C -> English translator for those "fun" const pointer to const array issues that you have to work out every so often...
cdecl: C gibberish ↔ English

RE: https://infosec.exchange/@mttaggart/116320350237766467

It's so funny that no one even wants to own the word "ad" anymore. They're "tips." For your own good. Gotcha.