It's fact that it's possible, the question is just if Google is doing it. I know some apps that have been proven to track mouse movement to identify users and prevent botting. They want to identify users because it's against ToS to have multiple accounts and also to prevent banned users from making new accounts. Tracking mouse movement is extremely accurate way to uniquely identify users. Google would have no problems doing this if they wanted to, the question is just if they are doing that. I think it would be coping to say they aren't but that's my opinion based on my perspective on big tech and google.
HN user
PrimaryAlibi
Freedom
Everyone reading this should start to contact websites/companies who use cloudflare and tell them in simple and few words that it's a problem and link them to a video or article that explains more, maybe even to this HN topic. We are not many, maybe 1-2% of their users/customers I keep reading people saying but I have in the past been able to get big tech companies to change to a friendlier tech. You would be surprised how effective it is to contact them about it. Maybe they have a tech support who already has same opinion as you but they can't make any change until a customer makes a complaint about it, then they happily see it as their opporunity to finally make a change.
That's same for almost all surveillance/tracking tech. It's always trivial for criminals/abusers to bypass. The surveillance is just about controlling the sheep.
To become a freelancer you first need to be a professional with a lot of work experience. Then you can start doing some freelance on the side and make it grow. It's very difficult to start your career as freelance.
To find part time job you first need to be able to find a job at all.
Basically no matter what, it all begins with getting work experience, probably full time, then after that you can start looking for part time or freelance.
So the charger won't work without the data wire and it could destroy the laptop. It's so crazy because I've seen in these tech communities people saying it's recommended to cut the data wires and everyone is upvoting it. I guess that's another popular misconception going around that it's generally fine to cut a data wire.
But my questions aren't extremely general, i even asked very specifically if you are supposed to attach an external programmer to the component like keyboard or cam etc but you can't even answer that. You can't even give one example. Are you saying there is nothing at all in common with different device models like camera model b and camera model c? You don't physically manipulate with them in any way? Don't attach anything or what? Or do you shine a light on one model and breath on another? When you can't even make one example that makes it hard to believe you. You are just constantly deflecting and refusing to explain. It just seems like you are spreading FUD when you say it can be done but wont explain how. I'm not even asking for full step by step instruction, just a simple overview of what kind of process it is in general.
These are the type of vague answers i said i didn't want because they are not helpful. How do i know if you really know what you are talking about? No explanations or links to sources. "depends on the device" is almost not an answer at all.
BIOS password does help if they need to be able to boot from usb drive to flash firmware. Or do you know another way? Again, not talking about boot rom.
How would it be done externally? Is it done same way as flashing the boot rom? You just need to know where the chip is for the other components? No 0-days needed? Or do you need a 0-day to do this? Is that why you think only foreign intelligence agencies are the ones who can do this? Also assume that the bios is password protected and it's configured in bios to not boot from a USB drive.
I asked about 0-day because I dont think anyone would use that on me. So if I know that it can only be done with a 0-day then I would practically be secure.
The first paragraph you made doesn't sound so convincing though with mostly "probably" and no source or explanation other than intel has put a lot of effort into protecting the boot rom and EC. If you or someone could elaborate further that would be great.
good answer, I will read more about uefi bootkits and blacklotus. It also reminds me that recently bootkitty uefi bootkit was in news. i saw a video about it a couple days ago.
Is it just from userspace you flash these firmware (other than boot rom)? Or can you flash externally as well if you have physical access?
This also means that just like you avoid a lot of malware by going to linux instead of windows which is what all hackers build their malware for, you can probably also avoid a lot of these firmware bootkits by flashing coreboot instead of having UEFI.
I think most people already know that air pollution is bad for health. The question is how big part in all these deaths did the air pollution have. Are those face masks people use to "protect" themselves from covid effective at protecting from air pollution? I don't even know if asking these questions is worth it when there is so much censorship.
I have been making youtube videos for a long time on many different accounts. I don't know what else to say except try to choose topics that youtube won't give you trouble over so avoid things like privacy, crypto, politics. Then you just keep making videos and one day you win the lottery when the algorithm finally shines the light on you.
I think you have the same problem either way. NSA (most likely) recently was caught for putting backdoor in IOS. It doesn't matter how big the brand is.
Unfortunately it comes down to just needing to learn how to verify the hardware. If you only trust then you have lost.
Yeah I didn't know it was possible because some laptops have the TPM in a seperate chipset than the one that has intel me. I thought they only set the hap bit to neutralize but I learned here that they can also disable it on laptops that have TPM on a 2nd chipset.
Maybe I misunderstand you what you mean with a clone of the computer. Do you mean take my entire computer and replace it with a completely different computer that is the same model? Because if that is what you mean then they can't clone the tamper evident container because then it wouldn't be tamper evident. Glitter nail polish for example couldn't be cloned because the pattern would be different on the second computer which is the clone.
Or do you mean to do everything on my computer without having access to any hardware/firmware? You would just simply boot up the computer and somehow hack it? How?
I don't think there is any best place but if there was then it would be on an .onion site because without anonymity there will be censorship and people can go to prison. I wouldn't be surprised if UK soon begins searching for people who have supported Telegram CEO and then sending them to prison just like they are calling twitter users terrorists who retweet ongoing protests. Even Elon Musk is a terrorist according to UK. You better make sure your posts commenting on Telegram's CEO arrest can't be traced back to you.
Do you mean to use VNC to access your data? Because that sounds very difficult to secure and also do maintenance when you are never onsite. The host computer that has your data would have same problems as what this topic is about but now you can't even check for tamper evidence because you are not onsite.
Or do you mean to encrypt your data and upload to the cloud? Then download the data when you need to use it? And how are you managing all the passwords and encryption keys? I think you would need to keep quite a bit of sensitive data on that travel computer so you would need tamper evidence on it as well.
Or I think I must be completely missing out on something here what you are saying. Maybe you can elaborate a bit? It sounds interesting.
I made a mistake when I wrote the post mixing up disable and neutralized but I hoped everyone would understand I'm talking about disabling it.
They first have to get through the glitter nail polish protection without evidence. That's the point of the glitter nail polish, tamper evidence.
If we have a container that is tamper evident then they can't do all those computer modifications you mentioned without we finding out the computer has been tampered with.
I don't think it's such an rare adversary to have. Organized crime can easily have several experienced hackers in their "organization". It's common knowledge that gangs actually do monitor peoples routines who are inside their territory and they do it for several reasons, one of them being to rob your apartment or do an evil maid attack on your computer.
It's also common knowledge that all adversaries view people who have higher security than the average person as a person of interest or a mark. If they are spies they think you don't need privacy if you have nothing to hide and if you are trying to hard to hide then you must have something important to hide. Criminals think if you have security then you must have something valuable to protect.
Also some of the methods described her this thread seem impractical and extreme but one you go down this rabbit hole of security and privacy, you become used to gradually putting in a little more extra effort for better security and privacy. Normal users can't understand how someone can survive with having to toggle scripts on/off with the noscripts extension but for most people who are interested in security and privacy that is easy and effortless like breathing air.
I think its more useful to define requirements of an "elegant" website. FOSS is getting attacked a lot by governments these days so if you care about privacy or not doesnt matter, you need opsec or you could end up in prison.
Thats why a good open source website should be made elegant and usable by browsers with JS disabled and also other web features disabled. Website should be simple, don't make it unnecessary advanced using Javascript for something you can do with CSS.
so you are saying you dont care about your privacy but i dont understand how that is relevant
Great question but I'm not experienced enough developer to give the best answer. I don't know if it's possible to make this happen in the near enough future but the best would be if we could build the distro ourselves "reproducible builds". Then we can know for certain there are no added malicious modules added by the person signing the image.
Otherwise I think whatever the solution is, it must be a decentralized and censorship resistant solution, which means there must also be anonymity for the devs otherwise they can be forced to do bad things or even put in prison for working on a freedom software.
I think we can probably learn a lot from Monero's developers. I think the best solution is probably a fair launch DAO where everyone can vote on who should be allowed to be a developer, who will do the signing, which features we want, etc.
I think others can give better and more detailed answers than me. I will look into what hydra is that you mentioned.
I looked into nixos. First of all it has same problem as all other distros where you need to trust a signed image file.
Secondly, on the page https://nix.dev/contributing/how-to-contribute they say "Currently the focus is on funding in-person events to share knowledge and grow the community of developers proficient with Nix. With enough budget, it would be possible to pay for ongoing maintenance and development of critical infrastructure and code – demanding work that we cannot expect to be done by volunteers indefinitely." So that means they want a centralized team.
Third there's an active topic there which shows clearly that the team behind nixos is centralized and corrupt and politically driven: https://discourse.nixos.org/t/why-was-jon-ringer-banned-from...
This whole project smells like a honey pot. Centralized = bad.
You only send 1 application per month? I've read it's normal to send over 60 applications before you get a job. Are you sure there are no more websites you can use to look for more job ads? I also read that more than 70% of job hires happen on LinkedIn.