BlackBox (Security) Archiv
3.94K subscribers
183 photos
393 videos
167 files
2.67K links
👉🏼 Latest viruses and malware threats
👉🏼 Latest patches, tips and tricks
👉🏼 Threats to security/privacy/democracy on the Internet

👉🏼 Find us on Matrix: https://matrix.to/#/!wNywwUkYshTVAFCAzw:matrix.org
Download Telegram
Manchester United are being held to RANSOM for millions of pounds by cyberhackers who targeted club computer systems and are demanding cash not to release sensitive data

Manchester United are being held to ransom for millions of pounds by cyber criminals who have crippled the club's systems, Sportsmail can reveal.

United have brought in a team of technical experts to contain the potentially 'disastrous' attack that was launched more than a week ago.

But it's understood the hackers still have United in their grip after the National Cyber Security Centre on Thursday night confirmed they are helping the club to resolve the crisis.

👀 👉🏼 https://www.dailymail.co.uk/sport/sportsnews/article-8989881/Manchester-United-held-RANSOM-cyberhackers-control-computers.html

#cybercriminals #manchesterunited #ransomware
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
EU anti-terrorism commissioner warns against video games and pleads for backdoors

According to Gilles de Keroche, terrorists use video games for attack preparation and communication. Platform operators should therefore hand over the plain text of encrypted messages to law enforcement agencies.

In an interview with the news agency AFP, the EU anti-terrorism commissioner demands stronger regulation of computer games. Terrorists could use them to prepare attacks and as a means of communication. Combat games are suitable for testing attack scenarios.

The Belgian emphasizes that extremists already abuse video games for propaganda purposes. Right-wing extremists in Germany in particular have developed titles in which one could shoot at Arabs, the Jewish billionaire George Soros or the German Chancellor. In addition, the politician points out the danger of money laundering via game currencies. The games sector is not problematic as a whole, he said, but from the point of view of counter-terrorism there is too little regulation.

👀 👉🏼 Translated with DeepL:
https://t3n.de/news/anti-terrorbeauftragter-eu-computerspiele-videospiele-warnung-anschlaege-hintertueren-verschluesselung-1341260

#eu #antiterrorism #videogames #encryption #backdoors #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
This media is not supported in your browser
VIEW IN TELEGRAM
You've Got Spam: With this tool you send back your spam mails

You get unwanted emails every day, no matter how often you unsubscribe from mailing lists? With this tool, e-mail revenge is yours.

💡 👉🏼 https://youvegotspam.mschfmag.com

#youvegotspam #email #spam #tool #gmail
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Crypto Wars: Green light for contested EU declaration on decryption

Diplomats have approved the EU Council resolution on encryption drafted by the German government. IT companies should help with decryption.

🇬🇧 EU: Council set to adopt declaration against encryption
https://www.statewatch.org/news/2020/november/eu-council-set-to-adopt-declaration-against-encryption/

👀 👉🏼 🇩🇪 https://data.consilium.europa.eu/doc/document/ST-13245-2020-INIT/de/pdf

#eu #encryption #declaration #cryptowars #netpolitics #thinkabout #pdf
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Most Americans Object to Government Tracking of Their Activities Through Cellphones

A new survey found widespread concern among Americans about government tracking of their whereabouts through their digital devices, with an overwhelming majority saying that a warrant should be required to obtain such data.

A new Harris Poll survey indicated that 55% of American adults are worried that government agencies are tracking them through location data generated from their cellphones and other digital devices. The poll also found that 77% of Americans believe the government should get a warrant to buy the kind of detailed location information that is frequently purchased and sold on the commercial market by data brokers.

The Wall Street Journal has reported that several U.S. law-enforcement agencies are buying geolocation data from brokers for criminal-law enforcement and border-security purposes without any court oversight.

Federal agencies have concluded that they don’t require a warrant because the location data is available for purchase on the open market. The U.S. Supreme Court ruled in 2018 that a warrant is required to compel cellphone carriers to turn over location data to law enforcement, but it hasn’t addressed whether consumers have any expectation of privacy or due process in data generated from apps rather than carriers.

Modern mobile-phone applications like weather forecasts, maps, games and social networks often ask consumers permission to record the phone’s location. That data is then packaged and resold by brokers. Computers, tablets, cars, wearable fitness tech and many other internet-enabled devices also have the potential to generate location information that is collected by companies.

The buying and selling of the location data drawn from modern technology have become a multibillion-dollar business—frequently used by corporations for targeted advertising, personalized marketing and behavioral profiling. Wall Street firms, real-estate developers and many other corporations use such information to guide decisions on investments, developments and planning.

👀 👉🏼 https://telegra.ph/Most-Americans-Object-to-Government-Tracking-of-Their-Activities-Through-Cellphones-11-28-2

#usa #gov #tracking #cellphones #mobilephone #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Second Swiss firm allegedly sold encrypted spying devices

Swiss public television, SRF, has found a second company besides Crypto AG was involved in manufacturing manipulated devices allegedly used for spying by foreign intelligence.

According to SRF sources, the Swiss company Omnisec AG had ties to US intelligence services. This follows revelations in February by SRF, German television ZDF and The Washington Post that Zug-based firm Crypto AG was at the heart of a huge international spying operation led by the CIA, and to a lesser extent by the German BND spy agency. Omnisec was one of the largest competitors of Crypto AG.

Swiss cryptologist and professor Ueli Maurer was a consultant for Omnisec for years and told SRF that in 1989 US intelligence services (National Security Agency) contacted Omnisec through him.

Of concern are the OC-500 series devices. Devices were sold to several Swiss federal agencies. However, Swiss authorities only noticed the devices weren't secure in the mid-2000s.

Several Swiss companies also received manipulated devices from Omnisec, including Switzerland’s largest bank, UBS. It is unclear whether the authorities informed UBS about the weak devices in the mid-2000s. UBS told SRF that it does not comment on security matters but that it had no indications that sensitive data were exposed at the time.

👀 👉🏼 https://www.swissinfo.ch/eng/second-swiss-firm-allegedly-sold-encrypted-spying-devices/46186432

#swiss #usa #nsa #spy #spionage #omnisec #cryptoag
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Five-Eyes intelligence services to help Europe circumvent encryption

Strongly secured chats annoy secret services and prosecutors worldwide. On this sensitive issue, the EU states are now to coordinate with the powerful Anglo-Saxon secret service alliance.

In future, the EU states are to work closely with the Anglo-Saxon secret service alliance of the "Five Eyes" to circumvent secure encryption in digital communications. This can be seen from documents sent to the member states by the German EU Council Presidency and available to the Süddeutsche Zeitung. As "Five Eyes", the secret services of the USA, Great Britain, Australia, New Zealand and Canada are cooperating with each other.

A report by the Austrian radio station ORF had already pointed out two weeks ago the similarity of the wording in the draft EU paper with a statement by the secret service alliance "Five Eyes" as well as India and Japan on October 11, which also demanded "lawful access to encrypted communication". Another paper from the EU Council of Ministers now substantiates this suspicion: The document called "Recommendations for the future handling of the encryption issue" is dated November 16 and has been submitted to the SZ.

The document is addressed to the EU member states and is a kind of handout. Point six states that governments should engage in a close dialogue on the topic with the initiators of the paper "End-to-End-Encryption and Public Safety". This is the declaration of the Five Eyes countries, as well as India and Japan, in which they call on companies such as Facebook to allow states access to encrypted content.

👀 👉🏼 Translated with DeepL
https://www.sueddeutsche.de/digital/geheimdienste-verschluesselung-crypto-wars-messenger-1.5131084

#fiveeyes #intelligence #eu #encryption #messenger #cryptowars #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Threema boss: Master key for secret services "not possible at all

The head of the messenger service Threema has sharply criticized demands for access to private chat messages for state security authorities. "These demands for a master key testify to the inexperience of the authorities," Martin Blatter told Welt am Sonntag. Technically, he said, it was not even possible. "We don't have a master key that we could deposit. The encryption is done by the users and not by us.

"Criminals almost always already known to the authorities"

In mid-November, alleged plans by EU countries to ban the secure encryption of messages on channels such as WhatsApp caused a great stir. The German EU Council Presidency had drafted a resolution on the subject. However, the paper was vaguely formulated and did not go into detail about how security authorities should be able to decrypt encrypted messages. Nevertheless, civil rights activists and data protectionists strongly criticized the initiative.

Blatter also emphasized that in the case of terrorist attacks, the perpetrators were almost always already known to the authorities and on file. "This means that politicians have not managed to protect citizens". In the newspaper interview, he also spoke of U.S. secret services having forced manufacturers of routers to install back doors, which in the end were also used by China.

👀 👉🏼 Translated with DeepL
https://telegra.ph/Threema-Chef-Generalschl%C3%BCssel-f%C3%BCr-Geheimdienste-gar-nicht-m%C3%B6glich-11-29

via www.heise.de

#fiveeyes #intelligence #eu #encryption #messenger #threema #cryptowars #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
EP 79: Dark Basin.mp3
46.6 MB
Darknet Diaries - EP 79: Dark Basin

What do you do when you find yourself the target of a massive hacking campaign, and you are getting thousands of phishing emails and someone keeps following you in your car? You might turn to Citizen Lab who has the ability to research who is behind this and help bring the hackers to justice.

🎙 https://darknetdiaries.com/episode/79/

#darknetdiaries #truecrime #podcast
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
The Hitchhiker’s Guide to Online Anonymity

Making a social media account with a pseudonym or artist/brand name is easy. And it’s enough is most use cases to protect your identity as the next George Orwell. There are plenty of people using pseudonyms all over Facebook/Instagram/Twitter/Linkedin/TikTok/Snapchat/Reddit/… But the vast majority of those are anything but anonymous and can easily be traced to their real identity by your local cops, random people within the OSINT1 (Open-Source Intelligence) community and trolls on 4chan2.

This is a good thing as most criminals/trolls are not really tech savvy and will be identified with ease. But this is also a bad thing as most political dissidents, human rights activists and whistleblowers can also be tracked rather easily.

This updated guide aims to provide introduction to various tracking techniques, id verification techniques and guidance to creating and maintaining anonymous identities online including social media accounts safely.

Will this guide help you protect yourself from the NSA, the FSB, Mark Zuckerberg or the Mossad if they’re out to find you? Probably not … Mossad will be doing “Mossad things” 3 and will probably find you no matter how hard to try to hide4.

You have to consider your threat model5 before going further.

Will this guide help you protect your privacy from OSINT researchers like Belingcat6 , Doxing7 trolls on 4chan and others that have no access to the NSA toolbox? More likely. Tho I wouldn’t be so sure about 4chan.

It’s also important to understand this guide is the humble result of years of experience and testing from a single individual (myself) and that many of those systems that aim to prevent anonymity are opaque closed-source systems. Most of those guidelines are guessed based on experience. These experiences take a lot of time and resources and are unfortunately far from being scientific. Your mileage may vary.

👀 👉🏼 https://anonymousplanet.github.io/thgtoa/guide.html

#guide #online #anonymity #anonymousplanet
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Facebook to Buy Kustomer, Startup Valued at $1 Billion

Facebook Inc. said it would buy Kustomer, a startup that specializes in customer-service platforms and chatbots, part of an effort by the social-media giant to help companies use its platforms to do business.

Facebook announced the deal in a posting Monday, confirming an earlier report by The Wall Street Journal. Though terms weren’t disclosed, people familiar with the matter said it would value New York-based Kustomer at a little over $1 billion.

Closely held Kustomer, whose technology takes conversations from different channels and puts them on a single screen, was valued at $710 million in a private funding round roughly a year ago, according to PitchBook.

Increasingly, customers are communicating with companies by messaging instead of calling. Facebook said more than 175 million people reach out every day to businesses using its WhatsApp messaging service.

Kustomer already has a relationship with Facebook. Its offerings allow companies to aggregate and respond to customer inquiries that come in through Facebook Messenger. In October, Kustomer said it also began integrating with Facebook’s Instagram messaging.

👀 👉🏼 http://telegra.ph/WSJ-News-Exclusive--Facebook-to-Buy-Kustomer-Startup-Valued-at-1-Billion-11-30

via www.wsj.com

#DeleteFacebook #fb #kustomer #startup
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
BlackBox (Security) Archiv pinned «The Hitchhiker’s Guide to Online Anonymity Making a social media account with a pseudonym or artist/brand name is easy. And it’s enough is most use cases to protect your identity as the next George Orwell. There are plenty of people using pseudonyms all over…»
Senator Wyden to introduce legislation to stop the IRS from spying on Americans

The Internal Revenue Service (IRS) has been in hot water and under investigation by its oversight body for buying location information on American citizens without a warrant. Motherboard has seen the contract between Venntel and the IRS that confirms how the IRS was spying on American citizens. Now, Senator Wyden has unveiled plans to introduce legislation that will stop the IRS from buying location data from third party companies like Venntel.

This data is gathered by Venntel through agreements with mobile applications which siphon your personal information for advertising purposes. The thing is, the government is also utilizing this data – which they obviously aren’t allowed by the Constitution to collect by themselves. Besides the IRS, US Customs Border Protection (CBP) has also been revealed to have a Venntel contract. It seems that many three letter agencies, certainly not just limited to the IRS, have been using this tactic to spy on Americans and it’s high time that legislation was introduced to stop this widespread privacy violating practice.

Because the information comes directly from your mobile phone, it can provide accurate location data even if your phone is spoofing GPS coordinates and changing its IP address. The document between the IRS and Venntel highlights why the IRS would want to use this technology and what for:

This allows tracing and pattern-of-life analysis on locations of interesting criminal investigations, allowing investigators to trace locations of mobile devices even if a target is using anonymizing technologies like a proxy server, which is common in cyber investigations.

👀 👉🏼 https://www.privateinternetaccess.com/blog/senator-wyden-to-introduce-legislation-to-stop-the-irs-from-spying-on-americans/

#usa #wyden #legislation #irs #spying
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Privacy / Interviews - Tutanota wants to file a complaint at the BGH (Federal Supreme Court)

Because of the court decision by the Regional Court of Cologne, the anonymous e-mail service Tutanota wants to bring about a decision by the highest court.

The anonymous e-mail service Tutanota wants to bring about a decision by the supreme court in response to the court ruling by the Cologne Regional Court. The company does not agree that they must provide the LKA NRW with access to unencrypted messages for individual users. However, the judgement does not indicate that the company has had a major impact on the German market to date.

The Regional Court of Cologne is forcing the cryptology service Tutanota to rebuild its technical infrastructure again. Once again, the company from Hanover is to guarantee the investigators access to individual accounts. The public prosecutor's office wants direct access to non-encrypted messages of an extortionist. Despite our current interview, we have again followed up on the incident with press spokeswoman Hanna Bozakov.

👀 👉🏼 Translated with DeepL
https://tarnkappe.info/tutanota-will-beschwerde-vor-dem-bgh-vorbringen/

#tutanota #bgh #encryption #email #backdoors #lka #interview #privacy
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Spain's Biggest Union Is Suing Amazon for Spying on Striking Workers

The union alleges that Amazon hired the Pinkertons, which subcontracted with a local firm, to surveil workers planning an October strike in Barcelona.

More evidence of Amazon's widespread worker surveillance program and the company's use of the Pinkerton spy agency has emerged in Spain.

El Diario reported on Monday that Amazon spied on workers planning an October 30, 2019 strike at its BCN1 warehouse in Barcelona. To spy on workers, the outlet reported, Amazon called on the Pinkertons, who subcontracted the job in Catalonia to a local firm named Castor & Polux. A retired police officer, Antonio Giménez Raso, was named as a "police liaison" between Castor & Polux and the Catalonia police force, Mossos d'Esquadra.

The Barcelona strike took place days before another strike in Poland that Motherboard reported was infiltrated by Pinkerton operatives working for Amazon.

Castor & Polux’s report on the BCN1 warehouse, obtained by El Diario, is a detailed 51-page document featuring secretly-taken photographs of the strikers and their faces, as well as extensive comments collected from trade unionists, workers, and journalists reporting on the strike. The document also mentions a reporter who interviewed workers, prompting the agents to search for her vehicle, record the license plate and model, and take photographs of it.

Amazon did not immediately respond to Motherboard’s request for comment. A spokesperson told el Diario that Amazon did not direct the Pinkertons or its affiliates to spy on the strike.

👀 👉🏼 https://www.vice.com/en/article/wx8x8z/spains-biggest-union-is-suing-amazon-for-spying-on-striking-workers

👀 👉🏼 https://www.businessinsider.com/amazon-pinkerton-agency-spies-union-strike-spain-ccoo-legal-action-2020-12

#DeleteAmazon #amazon #spying #strikes #pinkertons #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Forwarded from /r/latestagecapitalism
This is the biggest general strike in history. Solidarity to the people of India
https://redd.it/k5js26
@r_latestagecapitalism
NIST.IR.8331.pdf
29.6 MB
Face mask no longer helps against face recognition

The developers of biometric face recognition have adapted their software to the pandemic. While the algorithms still had great difficulty with masked faces in the summer, five months later the situation looks completely different, a new study shows.

Face recognition is becoming more and more accurate, even if the monitored persons wear a facemask. This is the result of a study published on Tuesday by the US National Institute of Standards and Technology (NIST), which tested 152 different face recognition algorithms.

👀 👉🏼 (PDF)
https://nvlpubs.nist.gov/nistpubs/ir/2020/NIST.IR.8331.pdf

#biometric #facerecognition #study #pdf
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
No, the Darknet is not the stronghold of all evil!

The anonymization service Tor can be used for good and bad, a study examines what outweighs. However, this goes a long way wrong.

To obtain information about the usage patterns of the Tor network, scientists Eric Jardine (Virginia Tech/USA), Andrew Lindner (Skidmore College/USA) and Gareth Owenson (University of Portsmouth/UK) operated about 1 percent of the Tor entry nodes for about seven months between December 31, 2018, and August 18, 2019, and studied the connections that were made there.

👀 👉🏼 https://www.pnas.org/content/early/2020/11/24/2011893117

#tor #darknet #study #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
More than 400 lawmakers from 34 countries back 'Make Amazon Pay' campaign

LONDON (Reuters) - More than 400 lawmakers from 34 countries have signed a letter to
Amazon.com Inc boss Jeff Bezos backing a campaign that claims the tech giant has “dodged and dismissed … debts to workers, societies, and the planet,” organisers said.

The “Make Amazon Pay” campaign was launched on Nov. 27 - the annual Black Friday shopping bonanza - by a coalition of over 50 organisations, with demands including improvements to working conditions and full tax transparency.

The letter’s signatories include U.S. Congresswomen Ilhan Omar and Rashida Tlaib, former UK Labour Party leader Jeremy Corbyn and Vice President of the European Parliament Heidi Hautala, co-convenors Progressive International and UNI Global Union said.

“We urge you to act decisively to change your policies and priorities to do right by your workers, their communities, and our planet,” the letter said.

“We stand ready to act in our respective legislatures to support the movement that is growing around the world to Make Amazon Pay.”

👀 👉🏼 https://telegra.ph/More-than-400-lawmakers-from-34-countries-back-Make-Amazon-Pay-campaign-12-03

via www.reuters.com

#DeleteAmazon #amazon #makeamazonpay
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Justice Department Files Lawsuit Against Facebook for Discriminating Against U.S. Workers

Lawsuit Alleges Facebook Favors H-1B Visa Workers and Other Temporary Visa Holders over U.S. Workers

The Department of Justice announced today that it filed a lawsuit against Facebook Inc. for discriminating against U.S. workers.

The lawsuit alleges that Facebook refused to recruit, consider, or hire qualified and available U.S. workers for over 2,600 positions that Facebook, instead, reserved for temporary visa holders it sponsored for permanent work authorization (or “green cards”) in connection with the permanent labor certification process (PERM). The positions that were the subject of Facebook’s alleged discrimination against U.S. workers offered an average salary of approximately $156,000. According to the lawsuit, and based on the department’s nearly two-year investigation, Facebook intentionally created a hiring system in which it denied qualified U.S. workers a fair opportunity to learn about and apply for jobs that Facebook instead sought to channel to temporary visa holders Facebook wanted to sponsor for green cards.

“The Department of Justice’s lawsuit alleges that Facebook engaged in intentional and widespread violations of the law, by setting aside positions for temporary visa holders instead of considering interested and qualified U.S. workers,” said Assistant Attorney General Eric S. Dreiband of the Civil Rights Division. “This lawsuit follows a nearly two-year investigation into Facebook’s practices and a ‘reasonable cause’ determination by the Justice Department’s Civil Rights Division. Our message to workers is clear: if companies deny employment opportunities by illegally preferring temporary visa holders, the Department of Justice will hold them accountable. Our message to all employers — including those in the technology sector — is clear: you cannot illegally prefer to recruit, consider, or hire temporary visa holders over U.S. workers.”

👀 👉🏼 http://telegra.ph/Justice-Department-Files-Lawsuit-Against-Facebook-for-Discriminating-Against-US-Workers-12-03-2

via www.justice.gov

#DeleteFacebook #fb #facebook #doj #lawsuit #discrimination
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Zippyshare - known filehoster currently with problems

If you are currently trying to load something from Zippyshare, you may have already noticed. There is something wrong. The reason for the errors might be a certificate that expired yesterday. But there are also more and more virus warnings on the site.

Whether the expired certificate is also responsible for the slowly increasing number of virus warnings on Zippyshare, we do not know at this time. However, the first virus tests were negative.

👀 👉🏼 https://www.virustotal.com/gui/domain/www18.zippyshare.com/detection

#zippyshare #certificate #viruswarning
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag