signal did everything right on their end. encrypted push, content only shown if the user opts in. the weak link is iOS caching decrypted notification content in an unencrypted sqlite database that survives app deletion. the 'e2e' in e2e encryption ends at the os, not the app.
HN user
_slih
same threat group hit filezilla last month with a fake domain. this time they didn't even need a fake domain, they compromised the real one's api layer. the attack is evolving from 'trick users into visiting the wrong site' to 'make the right site serve the wrong file.'
flock says customers own their data and control access. but their national lookup tool means 5,000+ agencies can search your city's cameras without your city's permission. 'customer-owned data' that anyone in the network can query isn't customer-owned in any meaningful sense.
5,000 flock networks searched per query. cities that approved cameras for local burglary investigations are now having their data searched for immigration enforcement by fish and wildlife cops in florida. nobody voted for that.
yo, livekit acts as independent controller for call detail records under their own dpa. that means proton's privacy constraints don't even apply to that data. livekit can hand call records to us law enforcement without notifying proton
palantir is a US company subject to the cloud act. patient data from 123 hospital trusts is now one mlat request away from us law enforcement regardless of where the servers sit.
the attestation is a real step forward for silicon provenance. the problem is your board, firmware, bmc, and nic still come through the same opaque supply chain as before. the processor is rarely where a hardware implant goes.
rpki adoption is the new ipv6 adoption. it looks great until you realize it only validates who owns the prefix, not the path to get there lol
the privacy manifest declares no data collected while the app sends your device model, ip address, session count, and a persistent tracking id to onesignal on every launch. false attestation anyone?
I think everyone's glossing over that this extends to anyone who knows the password. Your sysadmin, your business partner, your spouse. Hong Kong just turned your company's entire key management chain into a legal liability.
Forget the Iran attribution for a second. The FBI director's personal email was already in leaked credential databases from prior breaches.
FBI director was asked point blank if he'd commit to not buying Americans' location data. he said no.
two verdicts in two days, $375m in new mexico and $6m in LA. meta's insurance company already got cleared of covering these claims. if even ten more states follow, meta is paying out of pocket at a scale that actually shows up on the balance sheet.
the fine is 0.6% of last year's profit. the lobbying budget probably costs more.
cloud providers design for software failures and network partitions. they do not design for drone strikes. the redundancy model assumes your availability zones won't get hit by the same military operation.
the ban covers all foreign-made consumer routers but practically every router is manufactured abroad, even the ones sold by American companies. the only domestic exception is Starlink, iirc
hack back assumes you know who hit you. attribution in cyber is hard enough for the NSA
second breach in a month from the same initial credential compromise. the first rotation didn't fully revoke access. the attacker walked right back in. no persistence needed.
telling users on a cybersecurity website to click past certificate warnings is training them to do the exact thing every security awareness program says never to do. DISA runs the security standards that every defense contractor has to comply with...
the supply chain for offensive tooling is now indistinguishable from the supply chain for malware. take care of your security team!
the product got deployed across the government while the security review was still in progress. then fedramp approved it because it was already everywhere. seem like i saw a lobbyist or two with a broom sweeping something under a rug...
Thanks for the heads up. The links are in the text body. Demo dashboards here: https://awsight.com/demo.html and main site: https://awsight.com. I posted as a text submission so I could include context.
A few technical details: checks run via scheduled API queries across your services. No agents or collectors run in your account. The cross-account role is scoped to read/list calls only. Findings are stored historically so you can see when issues appeared and when they were resolved.
three states passing the same template bill in three months isn't organic legislation
the infrastructure outlasts whoever is in office. that's the part that doesn't get repealed.
the post getting mass-reported off reddit twice is the best evidence that the research is accurate lol
the timeline for all of this is not a coincidence. meta spent millions lobbying for age verification laws that require content scanning. hard to scan content that's encrypted.
"no actual age verification" is doing a lot of work in these defenses
every age verification mandate creates another one of these databases. billion records, no password, plain text.
a school district is a customer of the same ALPR data broker network that sells to law enforcement, repo companies, and federal agencies. the data doesn't care who's buying.