#Cultura#Bitcoin nasce sotto forma di Newsletter e Podcast per divulgare brevi e semplici caratteristiche legate alla comprensione del protocollo Bitcoin, partendo anche da aspetti che poco centrano con esso.
Spotify: https://t.co/35BBdaukBf YouTube: https://t.co/wWG761YwSj
We've paused Blink services while we investigate a security incident.
An attacker accessed a limited number of custodial accounts and withdrew funds.
The large majority of funds are secure.
Non-custodial wallets are not affected.
/e/ is a highly problematic fork of LineageOS very poor privacy and atrocious security. People would be far better off using standard LineageOS one of the better supported devices. An iPhone is far more private and drastically more secure than Murena products.
/e/ lacks crucial standard privacy and security patches. It has many months and even years of delays to provide those. Nearly all the devices they support lack most Linux kernel, driver and firmware updates. They don't keep up with those for any devices. They don't keep up with Android, Chromium or Linux security updates anywhere either. Many severe patched privacy and security vulnerabilities are left wide open for months and even years with /e/. They heavily mislead their users about what's patched and how long they take to ship it.
/e/ also doesn't provide important standard privacy or security protections. It lags years behind on providing the current generation protections and disables many of the most important ones. An operating system failing to protect against known privacy weaknesses does not have reasonable privacy.
/e/ includes their own privacy invasive services and sends user data to third parties. They spent years sending user speech data to OpenAI without obtaining consent and falsely claimed the data was anonymized when challenged over it. Despite how it's marketed, it includes many Google services with privileged integration into the OS. They have their own privacy invasive services including user tracking with unique identifiers in their update client.
Their own supposed privacy features are incredibly flawed and do not provide what they claim. A small list of blocked domains omitting everything used for useful functionality does not stop tracking by apps or services. It leaves the most privacy invasive behavior of apps and services intact and is trivially bypassed in multiple ways even for what it does cover. Apps and services only need to use the same domains for functionality as tracking to avoid it which is already largely what they do. Apps and services also already widely deploy bypasses for this naive domain-based filtering even for domains dedicated to tracking. /e/ would have you believe that a DNS blocklist is a game changing approach. There are better implementations including RethinkDNS available for use elsewhere.
More information:
https://t.co/I7DVZds9cD
https://t.co/4ntrvMGkFA
https://t.co/zEdqfnCH36
https://t.co/uWVPGoiEUs
/e/ and their for-profit company Murena have repeatedly pushed anti-privacy talking points from authoritarians claiming devices with strong privacy and security are for criminals and pedophiles. Here are 2 examples where Gaël Duval says that himself about privacy/security hardened devices in general:
https://t.co/tknnMLauok
https://t.co/QmrgmbRyVa
/e/ and Murena many of the same anti-privacy talking points as France's current government and national law enforcement. They've aligned themselves with authoritarians in the country where they're based instead of opposing it. There are dozens of examples where they falsely claim GrapheneOS is mainly useful to criminals and mainly used by criminals. That's more extreme than the claims by France's national law enforcement cracking down on secure devices. They've gone so far to align themselves with anti-privacy authoritarians that they're ahead of them.
Murena is a for-profit company with the founders and owners of it being the same people who run /e/. /e/ includes for-profit paid Murena services and is built for Murena to sell devices with it. Despite being made for profit, /e/ receives millions of euros in government funding from governments which have spent years cracking down on legitimate privacy products:
> The European Union has subsidized us to the tune of several million for this project.
https://t.co/KjNyCtTytQ
/e/ makes it far easier to remotely take over devices, violate user privacy from apps and bypass encryption to extract all the data from a device. These are exactly the kinds of devices authoritarians opposed to privacy and security want people to be using. These devices are much less private and drastically less secure than iPhones but are duping people into paying them for it with false marketing. They're regressing privacy and security instead of advancing it.
@st3b1t Si spererebbe di trovare in un hacker un individuo attento alla privacy ed alla proprietà
O per lo meno qualcuno capace di leggere un paper e applicare conseguente deduzione logica con l'approfondimento
Evidentemente i congitivamente dissociati non mancano nemmeno lì
We are aware of a security incident on @Liquid_BTC. Purported white-hat hackers have withdrawn ~4,000 BTC (~$320 million) from the Liquid Federation wallet. The @Blockstream team is working on contacting them on-chain with a signed message.
What we know so far is that the funds were withdrawn via the SideSwap PAK (Peg-out Authorization Key), but that key was not compromised, nor were any others.
Exchanges have been notified and have already paused (or will pause) LBTC deposits and withdrawals. Other Liquid assets such as USDT, DePix, and RWAs are unaffected by this security incident.
Bridge nodes have been temporarily disabled, so no new transactions can be submitted to the network. Effectively, the Liquid sidechain is paused until this issue is resolved.
Liquid wallets will be impacted, and we're sorry for any inconvenience. Federation members are actively working on resolving this so we can restore normal network activity.
You can monitor the situation via @mempool's https://t.co/M46Zhn8nlY site below:
https://t.co/B8j9u4j6i4
We've developed a secure paste feature replacing traditional clipboard APIs. Users will be able to take away clipboard access from apps to use this instead. It integrates into the standard selection toolbar, input methods, accessibility services and keyboard shortcuts. We plan to get it merged soon.
A small subset of apps including those written in Flutter implement their own text selection toolbar. We've worked around this by adding a Paste button to the default keyboard. We'll be replacing AOSP Keyboard with a much better keyboard and will carry over adding this feature to the new one too.
Android only permits the currently focused app and keyboard to read the clipboard. However, sensitive data often lingers around in the clipboard for a while and privacy invasive apps can read it. Android shows a notice for apps reading clipboard content set by other apps but by then it's too late.
Our approach is replacing the inherently problematic API-based clipboard access approach used by both desktop and mobile operating systems. It's another overhaul of the privacy model for apps similar to our Contact Scopes and Storage Scopes features. We have many of these privacy features planned.
Our approach still allows apps to read the clipboard if they set the current content themselves. It only takes away the ability to read content set by other apps. It preserves usability as much as possible by only blocking the most problematic part of the API and replacing it with an alternative.
We are long, long, long overdue to reduce the amount of KYC we do as a society.
It doesn’t stop crime. It enables mass surveillance of the innocent by the tyrannical. And, perhaps most of all, it enriches hackers with troves of intimate personal data.
https://t.co/udoChrOMnZ
Soon enough, they may impose capital controls to mobilize savings for Europe’s war economy or to prevent savers from escaping a collapsing sovereign debt system.
Classic socialist death-spiral playbook.
Buy Bitcoin.