"For some reason VStarcam really wants to have access to their customer’s passwords."
HN user
supermatou
Excellent article about Telegram's encryption from Matt Green (cryptographer, for those who haven't heard of him):
https://blog.cryptographyengineering.com/2024/08/25/telegram...
mysterious life form on a docked ship
black goo
Hey, I've watched this X-Files episode before!
No, I don't have it anymore. I kept it around for 3 or 4 years, trying various methods to revive it, then threw it away when I took a job in New Zealand, hoping to move there for good. Well, that didn't work out and I came back after a few years, but the drive (and many other things) were lost in the process.
Also: the drive was absolutely dead, it wouldn't power up. I even tried to change its controller - I took it off another Conner drive, installed it on the deceased one - and nothing happened. On that occasion I realized that, even though they were the same model/capacity, Conner had used different electronics for different batches.
Ironically, the drive was built like a tank: never again I saw a hard-drive with a casing that thick (looked like cast iron).
Same here. Thirty years later, I'm still reeling from the loss of an inestimable trove of software created between the late Seventies and the early Nineties (many now-defunct operating systems, extremely rare programs and so on). All that on a 800MB Conner drive, which I had installed as a secondary (non-boot) drive in my system. The drive died on me with absolutely no warning signs, something that was unusual even for that period of time - it simply disappeared from the OS/BIOS, less that a year after I bought it.
Original article, with the technical analysis of the bootkit:
https://www.welivesecurity.com/en/eset-research/bootkitty-an...
Original article:
https://www.axios.com/2024/11/15/iran-israel-destroyed-activ...
But wait: it gets even funnier(?):
which uses Google maps/location services, places me in my correct location. Asking Google Search "what is my current location", places me in Eastern Europe.
Go figure.
You're right, a new IP from their pool should take care of this issue. Thing is, I'd like to know what could've possibly made Google think my current IP is in EE? what did I do to make Google Search - and ONLY Google Search think that?
Again, it's a major ISP, and I've been with them for the past 20 years. They've been using the same allocated IPs since the early Nineties - and EVERY detection services correctly assigns those IPs to my ISP, in my region.
any chance your traffic has recently seen a major change,
from Google's PoV? Especially, might one of your devices have
become a TOR entry/exit node, part of a VPN, or something similar?
Absolutely not. I'm not even using a VPN or any other method of tunneling into some remote server.
I found on the internet a few similar complaints, like someone in the Netherlands who was suddenly detected as being in Israel; he couldn't find any remedy, but mentioned that "the situation returned to normal in a month or so". But, as I already said, for me it's become more than a curiosity and a minor annoyance, as it's now interfering with my ability to shop online.
Forgot to mention: asking Google "what's my IP" shows my correct IP, but the bottom of the page places it in Eastern Europe. Every other service linked on the results page locates me correctly i.e. in Canada.
Also: in my Google account, "Where you're signed in" shows my Air, my iPhone, my Pixel and my Chromebook in the correct location (Canada, $MyCity).
I'm not qualified to decide whether this is scientifically valid or some kind of quackery. Please chime in if you're in related fields of research.
Unpaywalled version:
Zero competency in cryptography, so your explanations are much appreciated.
Q: Does this mean that encrypted data (stored files, communications via messengers etc) can be scanned for keywords, without the need to decrypt the entire file/message?
If so, isn't this a huge privacy problem?
It's a pretty comprehensive article, with proofs-of-concept for several browsers, don't know why you got the impression it's junk.
Actual title is "“EchoSpoofing” — A Massive Phishing Campaign Exploiting Proofpoint’s Email Protection to Dispatch Millions of Perfectly Spoofed Emails", but HN rejected it for some reason.
For those unable to bypass FT's paywall:
Very informative answer, thank you!
Much better resolution:
https://video-images.vice.com/articles/593594e8c270a8484d1d1...
[Copy/paste from their web site]
What is JShelter?
JShelter is a browser extension to give back control over what your browser is doing. A JavaScript-enabled web page can access much of the browser's functionality, with little control over this process available to the user: malicious websites can uniquely identify you through fingerprinting and use other tactics for tracking your activity. JShelter aims to improve the privacy and security of your web browsing.
How does it work?
Like a firewall that controls network connections, JShelter controls the APIs provided by the browser, restricting the data that they gather and send out to websites. JShelter adds a safety layer that allows the user to choose if a certain action should be forbidden on a site, or if it should be allowed with restrictions, such as reducing the precision of geolocation to the city area. This layer can also aid as a countermeasure against attacks targeting the browser, operating system or hardware.
Please see the FAQ (https://jshelter.org/faq/) and our blog (https://jshelter.org/blog/) for more information about the extension.
What is the threat model?
See https://jshelter.org/threatmodel/
Do you have a paper that explains the extension?
Yes, see https://arxiv.org/abs/2204.01392
a company is large and influential enough, with an entrenched market position, it does not get to "do whatever they want" because of the harm that causes to the economy overall.
I'm not sure I understand: this would be applicable if Apple was the only provider of phone/mobile OS. But... Apple is just one of the players; if I was adamant that Firefox - which, again, I've been using for the past 20 years - is the only browser I want to use on mobile, I'd simply give up on iPhones and buy something else. So, again, as long as I have a choice, where is the problem?
Firefox hardcore user here -- and someone not at all versed in anti-monopoly laws.
Could someone explain why the EU forced Apple to allow alternative browser engines in their own eco-system ("walled garden")? It's theirs, shouldn't they do whatever they want with it? It's not like there aren't any alternatives to iOS - Android is excellent and you can use many different browsers on Android. So... where's the problem?
Here's a tip re. a nice built-in function:
about:memory
You can reclaim quite a lot of memory there when your Firefox seems laggy.
I think the idea is that we willingly plug them in to critical systems, or everything really but including important infrastructure
Oh, OK. So an evil AI would conceal its capabilities and would play nice until it's put in charge of critical systems. I hadn't thought of that.
A more technical question for those of you working in AI: right now, are there any methods of - surveillance? - capable of monitoring/detecting emerging characteristic within an AI? how would you detect "evilness"? or "generosity"? or any other emotion/moral traits inside an AI?
some very smart people seem to spend a lot of time worrying about it
That's what puzzles me, as someone who has nothing to do with AI research; in my (layman's) mind, the problem seems ridiculously obvious (just flip that switch!); the fact that, as you say, some very smart people keep worrying about it, makes me think the problem is much more serious -- and I'd really, really like some AI guru to ELI5 how the machine could bypass the switch-off solution.
Sorry for asking a very basic question, but could anyone explain how are machines supposed to intervene in the real world and threaten our very existence?
In Star Trek, one of the most eye-roll-inducing plots is the "the holodeck is misbehaving, it has become evil, and we cannot shut it down!".
Suppose a machine achieves superhuman intelligence; how is it going to access the physical world, in a way that's *physically* threatening to us? how would such a machine - from inside a laboratory, within an isolated network - gain access to the electric grid, the dams, the nukes, etc? How would such a machine prevent its shutdown - by simply flipping a power switch?