Roberto Selbach 🇨🇦

103 Followers
879 Following
136 Posts

 🇨🇦🇧🇷👨‍💻🛰️🪐👾

Admin mast.quebec

Software engineer in Québec 🇨🇦, mostly doing cloud and identity (#IAM) stuff.

Je parle #français , I also speak #English 🇨🇦, falo #português 🇧🇷, hablo castellano 🇦🇷 und kann ich ein bisschen Deutsch 🇩🇪



#golang #lego #comics #space #cloud #identity #quebec #socialAnxiety

Websitehttps://roberto.selbach.ca
Languages🇨🇦🇧🇷🇦🇷:flagqc:🇩🇪
Pronounshe/him il/lui
GitHubhttps://github.com/rselbach

Not going to lie, Twitter killing off free API access hits me in the feels. I remember with great affection the flood of creativity that happened after we opened up the API, and it's heartbreaking to see that unceremoniously strangled.

I'm relieved that we've got better alternatives, though. While this is perhaps the final straw for many bots on Twitter, it's been a long time coming and the API has long been hobbled compared to the early days. Open protocols or bust. ✊

You don't have to be a Harvard professor to do the math on this one... #JoanDonovan's pathbreaking work on #disinformation and #SocialMedia is a liability for a university that gets half a billion dollars from the owner of the greatest disinformation machine ever built. #commodon @commodon @communicationscholars @ICAHDQ @HigherEdLabor #academic @academicchatter

Please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please please stop #crossposting #twitter.

It monetizes #fascists.

Thank you in advance.

#twittermigration

This thread is very worth a read until the end. What a clusterfork

From: @SecurityWriter
https://infosec.exchange/@SecurityWriter/109777576538835360

Security Writer :verified: :donor: (@[email protected])

We have one client which we manage an Azure tenant for. They require, and have specified, a zero-tolerance for device non-compliance. In roughly two hours, 1647 devices are about to be locked out of access to organisation resources, wiped, and removed from Intune permanently. 4 meetings, 124 emails, and two phone calls a day for the last 14 days have warned them of this. We’ve been *very* clear about what is about to happen for the last 13 months. Their internal management have *acknowledged* what is about to happen. But still, time marches on. Death by middle-management. 🍿

Infosec Exchange

If you configured your iPhone to never allow an app to access your location, you may have been tracked anyway. Release notes for iOS 16.3 make mention of CVE-2023-23503, which Apple says may allow an app to bypass your privacy settings.

A blogger reports that an app from a Brazilian company iFood was able to track users' location even when they restricted the app's access. I haven't confirmed the report, but the screenshot seems convincing.

I wonder how long this vulnerability was in effect. There may have been massive amounts of location data that was collected without users suspecting a thing.

I'd ask Apple for details, but the company would never answer.

https://notes.ghed.in/posts/2023/ifood-bypassing-ios-privacy-location/

Was this Brazilian major app bypassing Apple's location privacy on iOS? · Notes

One of the biggest Brazilian apps/startups, iFood, was peeking at iOS users location when it should’ve not. A reader of Manual do Usuário (my Portuguese-written blog) noticed the glitch/bug while using iOS 16.2. iFood, Brazilian largest food delivering app evaluated at USD 5.4 billion, was accessing his location when not open/in use, bypassing an iOS setting that restrict an app’s access to certain phone’s features. Even when the reader completely denied location access to it, iFood’s app continued to access his phone’s location.

Notes

Thinking about how TWO devices that I own are “obsolete"—not because the hardware has kicked the bucket—but because Google simply doesn’t want to provide security updates for them.

And now that I think about it, it’s all so wasteful.

Here’s a strange thought for you. I own a Sony Walkman that was made decades ago. It still plays NEW cassettes sold on Bandcamp. The device is probably ~30-years-old.

None of these Android phones will be usable in 30 years.

Verification, check. Time for our #introduction:

Founded by @dave and @roustem in 2005, we’re now a team of 800+ who share the same vision: to make the online world a safer place for everyone. Our culture values simplicity, honesty and a human-centric approach to solving problems.

We have a small gang hanging out on Mastodon and we’d love to get to know our new community. Share your own #introduction with us and what brought you to #1Password. 👋😊

starship won't start
We can rebuild him; we have the technology.
Success! 😅