Apple spent the entire summer telling the public that they were confident they could resist government pressure, when defending their CSAM scanning system. Today they’re pulling voting guides from the Russian App Store. What changed in a month?
Everyone- please stop discussing the Facebook DB leak. It was fixed in 2019.
All 533m were notified and all 533m changed their first name, last name, address, and telephone number.
That's how it works, right?
Forcing companies to collect & store sensitive customer data in a centralized database is a massive & unacceptable risk in the internet era. The benefits do not outweigh the costs. The challenge of our time is to find ways for law enforcement to do its job without requiring KYC.
Apparent KYC database leak from MobiKwik in India:
- Database is 8.2 TB and contains 36099759 files. Nearly 3.5 million users' full KYC details. Along with 99224559 user phone numbers, emails, hashed passwords, addresses, bank accounts & card details e… https://t.co/51t68SQBma
I love how the US has managed to screw up privacy so badly that even the government just buys your exact location off the shelf. https://t.co/vegskfDArL
Today's outages in Russia appears to have been caused by a bad substring match by @roscomnadzor.
Intending to block Twitter's link shortener t[.]co, Russia blocked all domains containing t[.]co, for example
Microsoft[.]com and Reddit[.]com.
(H/T @GregoryKhodyrev)
@Fiskantes "when being withdrawn from the system, BNTs are locked for a pre-set time (default 24 hr) to prevent panic liquidation" -- https://t.co/iGPA2387wA
OMG. A person whose last name is "True" has been locked out of iCloud for 6 months because the code got confused between the last name and the boolean value!
@maddiestone Let’s make a really complex parser. Let’s let it generate code. Let’s put that code in the same address space as secrets. Lets make it remote accessible. Let’s sell access to via advertisement to anybody. Also, let’s make sure that the system of selling advertisement is opaque.
I put together this handy BINGO CARD for people playing along when reading any new cyber policy paper or attending a talk where bad ideas are likely to be proposed as solutions to all our problems. :)
"So tell me precisely how you would process this technical task in [insert programming language here]?"
"Well, I would pull up the documentation for [library X] to review..."
"You don't have access to the internet."
"I'm sorry, am I doing this work from a fallout shelter???"
The root cause of all of the insecurity you are seeing in large enterprise products is that nobody is allowed to test them and publish the results. Hence quality is usually very low.
I couldn’t tweet a better description than the headline for this piece: After SolarWinds breach, lawmakers ask NSA for help in cracking Juniper cold case. https://t.co/Q1apNypM1j