For the tl;dr, I wrote a summary of my analysis of the GPS Special Message “number station”, including entropy measurement, duplicated strings, a mysterious new “TEXT” prefix, and the system’s relationship with military key distribution. https://t.co/BKQp9GYQJo
(Un)forced Errors: Analysis of Proposed Surveillance Law Expansion under Bill C-22, An Act respecting lawful access - The Citizen Lab https://t.co/crt0RdwPSi
⚠️ Multiple @ redhat-cloud-services npm packages were found carrying malicious payloads that fire via a preinstall hook on every npm install. All packages were published via GitHub Actions OIDC, indicating the CI/CD pipeline was compromised.
The payload targets GitHub Actions secrets, AWS, GCP, Azure, Kubernetes, HashiCorp Vault, npm and CircleCI tokens. It reads /proc/mem to bypass log masking, self-propagates via harvested npm tokens bypassing 2FA, and persists on developer devices via Claude Code and VS Code injection.
UI flows that force a user to hard-close the app just to escape a marketing upsell are textbook deceptive patterns. A mandatory promotional screen with zero exit paths is hostile UX, Duolingo.
Simply amazing interview of @AnnaBower by @MicahLoewinger here: "Trump Sued Himself … and ‘Settled’ for a $1.8 Billion Fund" WNYC Studios https://t.co/Xkd7CkdQUQ
If you'll be at USENIX Security this year and would be interested in meeting up any of our NDSS fellows that may be there, drop me a line? They are the best: https://t.co/QzTGOPcGYw
The Bill C-22 hearing yesterday featuring the Privacy Commissioner of Canada, Apple, Google and others was a mess. But the message was clear. Bill C-22 represents a serious risk to the privacy and security of millions of Canadians.
https://t.co/XYp5Hm9wGn