Privacy Not A Crime
668 subscribers
196 photos
20 videos
234 links
๐Ÿ” Take control of your digital freedom.

Curated tools and expert insights on Privacy, Cybersecurity and OSINT. Actionable guides to protect your data and communications.

Defend your rights online. ๐Ÿ”ฐ
Download Telegram
๐Ÿ“„ Archive.ph: Your digital time capsule for web pages

How many times have you shared a link only to find out later that the content was edited or simply disappeared? We've all been there. Archive.ph solves exactly that problem by taking a permanent snapshot of any webpage, preserving both its text and visual layout exactly as it appeared at a given moment. No edits, no deletions, no surprises.

โš™๏ธ How does it actually work

The concept is simple but powerful. When you paste a URL into Archive.ph, the service downloads the page content along with a graphical copy for maximum accuracy. What makes it especially useful is that it strips out all active scripts, pop-ups, and interactive elements from the saved version.

This means the archived page is not only permanent but also completely safe to open, since there's no hidden malware or trackers lurking behind it. You get a short, clean link to an unalterable record.

๐Ÿฅฐ Why privacy folks love it

Here's where things get interesting. When you view a page through Archive.ph, you never actually connect to the original server. The content lives on their infrastructure, which means the target site can't log your IP, track your behavior, or plant cookies on you. For anyone who cares about digital privacy, that's a big deal. You can access content that might be geoblocked in your region without revealing your real location, and since all dynamic scripts are removed, there's no risk of client-side exploits running in the background.

๐ŸŒ Real-world scenarios where it shines

Think about a journalist needing to preserve a politician's tweet before it gets deleted under pressure. Or a lawyer capturing terms of service right before a company quietly rewrites them. Even in everyday life, it comes handy more than you'd expect: saving a job listing before it's taken down, archiving a rental ad that seems too good to be true, or keeping a record of a forum post that could vanish overnight.

๐Ÿ›ก Staying safe while using it

Even though Archive.ph gives you a script-free, sanitized view of any page, common sense still applies. Always double-check the URL before archiving to make sure you're capturing the right content. Keep in mind that the original site remains untouched, so don't let your guard down if you later visit the live version. And for extra privacy, consider pairing it with a VPN so not even your connection to the archive itself can be traced back to you.

๐Ÿ’ธ Two domains are available:

๐Ÿ–ฅ https://archive.ph
๐Ÿ–ฅ https://archive.today

๐Ÿ˜Š If you enjoyed the article share it with your friends and follow us.

#Cybersecurity #DigitalPrivacy #WebArchives #InfoSec #OnlineSafety

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
โœ6๐Ÿ‘€321
๐Ÿ‡บ๐Ÿ‡ธ US declares emergency after cyberattack hits police systems

The United States has officially declared a state of emergency following a severe cyberattack targeting local police infrastructure. The incident has disrupted critical communication channels and forced authorities to revert to manual operations while security teams work to isolate the breach.

โš ๏ธ FBI steps in urgently

In response to the escalating situation, the city council has formally requested immediate intervention from the Federal Bureau of Investigation (FBI).
Federal agents are now leading the forensic analysis to identify the threat actors and determine the extent of the compromise.

This move underscores the growing reliance on federal resources when local digital defenses are overwhelmed.

๐ŸŸช Risks of centralized digital dependency

This event highlights a critical vulnerability in modern municipal governance: when essential city services depend on a single digital infrastructure, a failure in one component can cascade rapidly beyond just computers. From dispatch systems to evidence databases, the interconnected nature of these networks means that a localized malware infection can paralyze an entire department's ability to respond to public safety needs. Experts warn that without redundant, air-gapped backup systems, such attacks pose a direct threat to community safety.

๐Ÿ˜Š Follow us to stay informed about the latest threats and protect yourself.

#CyberEmergency #PoliceHack #DigitalSafety #FBIInvestigation #Critical

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿค”5๐Ÿ˜22
๐Ÿ“ฑ Android security bypassed via malicious SIM card commands

Think the SIM card in your phone is just for your carrier? Think again. Behind that small chip lies a miniature computer capable of sending commands directly to your device's modem.

In the wrong hands, this can lead to serious trouble, even on a locked Android phone.

๐Ÿ’ฉ An 80s standard with modern consequences

The issue stems from the AT command protocol, a system originally designed in the 1980s for dial-up modems. Decades later, millions of smartphones still rely on this legacy infrastructure. Security researchers have discovered how a maliciously crafted SIM can exploit this inherent trust, injecting commands that bypass Android's lock screen protections. The implications are severe: unauthorized access to messages, location tracking, and network manipulation can occur without ever needing your passcode.

โ˜ ๏ธ What makes the attack possible

The vulnerability lies within the SIM Application Toolkit, a legitimate feature intended to allow your SIM to interact with phone menus for tasks like checking your balance. However, when developers fail to properly validate these interactions, the toolkit transforms into a backdoor.

Since most modems are designed to inherently trust commands originating from the SIM, a compromised card can execute harmful operations immediately. This means anyone with physical access to your device or someone who convinces you to swap in a fake SIM could gain unexpected control over your communications.

โค๏ธ Protecting yourself without panic

Fortunately, manufacturers are gradually rolling out patches, though the vast number of affected devices means many remain exposed. You can significantly reduce your risk by obtaining SIM cards exclusively from official carriers and avoiding unknown sources.

Keeping your firmware updated is crucial, particularly regarding modem security. If your phone supports eSIM, switching to it eliminates the physical slot entirely, effectively cutting off this attack vector. Additionally, if you notice unusual behavior such as random network disconnections or suspicious text activity, investigate immediately.

๐Ÿ˜Š Follow us to stay informed about the latest threats and protect yourself.

#AndroidSecurity #SIMVulnerability #MobilePrivacy #CyberThreats #TechSafety

@PrivacyNotACrime๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘Œ7๐Ÿ‘€31
๐Ÿ‡ช๐Ÿ‡ธ Spanish hacker Gil exposes NATO and SBU intelligence data

Enrique Arias Gil, also known as "Desinformador Ruso", is a Spanish IT specialist currently residing in Russia, claims to have uncovered the personal data of 400 intelligence officers from Ukraine and Spain, many of whom are linked to NATO, the CIA, and the SBU. This revelation sends shockwaves through western security circles, highlighting vulnerabilities in how sensitive personnel information is stored and protected.

๐ŸŒŸ A three-month operation with global implications

According to Gil, the data collection effort took approximately three months of dedicated work. The compromised information includes high-ranking officials such as brigadier generals, colonels, and lieutenant colonels. One particularly symbolic figure mentioned is a lieutenant colonel from the Spanish Armed Forces Intelligence Center, reportedly connected to NATO operations, Ukraine, and cognitive warfare initiatives. Beyond military ranks, Gil also obtained photographs and personal details of over 1,000 Spanish police officers.

๐ŸŽ‰ The geopolitical chessboard

Gil received political asylum in Russia in February and has since integrated into the Russian academic sector, teaching at two higher education institutions. He currently holds a temporary visa but aims to secure permanent residency within five to six months, eventually seeking citizenship. His case illustrates a growing trend where nations actively recruit foreign cybersecurity experts, regardless of their controversial backgrounds or legal status elsewhere.

๐Ÿ‘ฎโ€โ™‚๏ธ Charges and international pursuit

Spanish authorities have accused Gil of espionage, sabotage, cyberterrorism, and data theft in the interest of Russia. He claims to be the most wanted person by Europol. While his actions have sparked outrage in Madrid, his asylum in Moscow underscores the complex intersection of cybersecurity, geopolitics, and intellectual talent migration.

๐Ÿ˜Š Follow us to stay informed about the latest threats and protect yourself.

#CyberEspionage #DataLeak #NATO #Europol #InfoSec

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘€12โœ10๐Ÿค”9๐Ÿ™ˆ5๐Ÿ˜4๐Ÿ‘Œ31
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿ‡ฎ๐Ÿ‡ฑ Mossad sends data instead of stealing it: a real espionage success?

Imagine you're a spy agency with billions in budget, fancy surveillance tools, and decades of operational experience. Now imagine you try to hack a lawyer's phone and somehow manage to send him your entire contact list instead of stealing anything. Welcome to the world of modern cyberespionage, where sometimes the biggest threat to national security is a simple misconfigured script.

โš ๏ธ The operation that backfired harder than expected

The story comes from Juan Branco, one of only twelve lawyers in France representing Palestinian victims. According to him, Mossad's attempt to extract data from his phone resulted in the exact opposite: a massive push of sensitive information onto his device. And not just any contacts. We're talking phone numbers for Elon Musk, Sam Altman, and essentially every top political, judicial, and intelligence figure in Israel.

It's like trying to rob a house and accidentally leaving your wallet full of addresses and passwords on the doorstep. The irony here is almost too perfect: a lawyer defending people who've been surveilled ends up receiving the surveillance database itself. Bravo, truly professional work.

โ” Questions nobody asked but everyone should

This blunder raises more questions than answers. How does a sophisticated operation designed for covert extraction flip into a mass data delivery system? What kind of quality control exists before deploying tools that could accidentally expose an entire intelligence network to its enemies?.

For Branco, the situation is legally messy. Possessing classified Israeli contacts could complicate his cases or endanger sources. For the individuals whose numbers were leaked, including tech giants and government officials, the risks of doxxing and harassment are real. And for Mossad? Well, let's just say their reputation took a hit that no amount of denials will fully fix.

๐Ÿ˜Š Follow us to stay informed about the latest threats and protect yourself.

#Mossad #SpyBlunder #DataLeak #CyberSecurity #IntelOps

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿคฃ10๐Ÿ‘€5๐Ÿ˜3
๐ŸŒ FirewallFalcon Manager: When free VPN tools hide a dangerous secret

Over 650 servers caught in a coordinated campaign, all traced back to a single open-source utility that thousands trusted blindly.

FirewallFalcon Manager presented itself as a handy, community-driven solution for managing VPN servers on Linux and here is the worst part: it actually worked. It delivered every feature it promised. But behind that polished functionality lurked a quietly modified component that turned it into a remote control for attackers.

๐ŸŒŸ A supply chain attack disguised as convenience

The malicious operation was elegant in its simplicity. Perpetrators took the legitimate tool and surgically replaced its subscription verification mechanism with a rogue module granting them administrative authority over every deployment. Instead of authenticating users, the tampered code opened a hidden channel allowing attackers to intercept, redirect, and manipulate all client traffic flowing through affected servers. Since the rest of the application continued performing exactly as advertised, administrators had almost no visible clue that something was terribly wrong underneath.

โ„น๏ธ What makes this case particularly troubling

This is not the typical scenario where a shady tool tricks inexperienced users into installing malware.

FirewallFalcon Manager looked legitimate, felt legitimate, and behaved legitimately. That is precisely what supply chain attacks thrive on. By poisoning a trusted distribution channel, operators managed to compromise a vast network of servers without exploiting a single vulnerability in the traditional sense. The 650-plus infected nodes represent a massive surveillance infrastructure built on borrowed trust.

๐Ÿ˜Š If you enjoyed the article share it with your friends and follow us.

#FirewallFalcon #SupplyChain #VPNThreats #LinuxSecurity #Backdoor

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
21
๐Ÿ” Tools for source code search

Open-source intelligence operations increasingly depend on examining publicly available code repositories. Security researchers and penetration testers need efficient methods to discover exposed credentials, API keys, and sensitive configuration files that developers accidentally commit to version control systems.

This guide presents five essential tools designed to streamline the process of searching through GitHub and uncovering potential security exposures.

๐Ÿ”— Gitrob โ€“ Repository history scanner

Gitrob clones repositories and scans their entire commit history to find suspicious files containing secrets. It highlights matches using known patterns for sensitive data like passwords and API keys. Findings display through an intuitive web interface for easy review. Ideal for auditing your own projects or assessing third-party codebases before deployment.

๐Ÿ“ฑ Github Dorks โ€“ Automated search queries

This Python utility automates advanced GitHub searches using specialized dork syntax. Users can target specific file types, paths, or keywords without learning complex search operators. The tool gracefully handles API rate limits while exporting results in clean formats. Perfect for rapid reconnaissance during security assessments.

๐ŸŸช GitGraber โ€“ Real-time credential hunter

gitGraber monitors GitHub continuously for credentials targeting services like AWS, Google, PayPal, Facebook, Twitter, and Stripe. Its predefined patterns reduce false positives while delivering actionable results. Run it in the background for instant alerts when new secrets appear. Essential for incident response and proactive exposure monitoring.

๐Ÿ‘จโ€๐Ÿ’ป GitHub Search โ€“ Command-line investigation suite

A modular collection of CLI tools for systematic GitHub investigations. Script searches, parse results programmatically, and integrate into larger security pipelines. Supports JSON and CSV output for downstream analysis. Handles authentication tokens securely to prevent accidental exposure during execution.

๐Ÿ’ง TheScrapper โ€“ Contact information extractor

TheScrapper extracts email addresses and social media accounts from website source code and repositories. Parses HTML, JavaScript, and text files to locate personal identifiers. Useful during reconnaissance to identify contributors or build communication vectors. Respects rate limits to avoid triggering security controls while crawling.

๐Ÿ›ก Protection tips for developers

To prevent your code from leaking sensitive data, implement pre-commit hooks before pushing, rotate API keys regularly, use environment variables instead of hardcoding credentials, and deploy continuous monitoring services like GitGuardian or TruffleHog.

๐Ÿ˜Š If you enjoyed the article share it with your friends and follow us.

#OSINT #CodeSearch #GitHub #SecurityTools #BugBounty

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
3
๐Ÿ‡ท๐Ÿ‡บ What is the FIRST.org website

If you work in cybersecurity, particularly in SOC operations, incident response, or vulnerability management, you have probably encountered FIRST. This organization is fundamental to how the global security community collaborates during critical situations.

FIRST stands for Forum of Incident Response and Security Teams. It operates as an international association focused on enabling collaboration and experience sharing between security teams, CSIRTs, CERTs, and PSIRTs worldwide.

โžก๏ธ Why FIRST.org matters for professionals

The platform delivers several essential resources that shape industry practices and operational standards.
First and foremost, FIRST develops and maintains the Common Vulnerability Scoring System, commonly known as CVSS. This framework represents one of the most important global standards for measuring vulnerability severity, allowing organizations to prioritize remediation efforts based on consistent risk assessment.

Beyond scoring systems, the site offers comprehensive incident response frameworks. These resources guide teams through identifying, analyzing, and containing security breaches efficiently. For those building or managing CSIRT and PSIRT teams, specialized documentation covers team design, operations, and best practices.

๐Ÿ’ฌ Community and specialization

FIRST functions as a vast network where security practitioners across borders share intelligence and coordinate responses. This collaborative approach proves essential when adversaries operate internationally.

The organization also runs Special Interest Groups focusing on targeted areas like threat intelligence, automation, artificial intelligence security, and evolving CVSS methodologies. These SIGs drive innovation within specific security domains.

๐Ÿ‘ฅ Practical advice for security teams

To maximize the value of FIRST resources, integrate CVSS scoring into your vulnerability management workflow from the start.

Participating in regional FIRST conferences helps establish personal connections that prove invaluable during active incidents.

For anyone working in Blue Team operations, SOC analysis, incident response, or vulnerability lifecycle management, FIRST.org deserves a permanent spot in your professional bookmarks.

๐Ÿ“ƒ Official Website:

https://www.first.org/

๐Ÿ˜Š If you enjoyed the article share it with your friends and follow us.

#Cybersecurity #FIRST #IncidentResponse #CVSS #BlueTeam

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
32๐Ÿ‘Œ1
Buy us a coffee โ˜•
Has our content helped you today? Buy us a coffee to help us keep this space active, updated, and ad-free. Every contribution counts!

Thank you for your support! ๐Ÿ™
๐Ÿฆ  Malware detection made accessible with XGBoost

Ever wonder if analyzing suspicious files really requires expensive enterprise tools or deep technical skills? A new open source project proves otherwise. It shows how modern machine learning can bring malware analysis within reach of security enthusiasts and small teams who want to identify threats without breaking the bank.

๐Ÿ”‚ A modern approach to an old problem

Called Malware-Detector-XGBoost, this is a web based system that classifies Windows executable files as malicious or benign. Developed by I Ketut Widiyane as a Final Year Project, it uses the XGBoost algorithm to examine Portable Executable metadata. Traditional signature based scanners often miss zero day threats, but this system detects patterns and anomalies in file structures instead, providing a proactive defense layer.

The tech stack combines a Python backend using FastAPI for fast inference with a Next.js frontend that keeps the interface clean and responsive. Users upload files through a simple form, get instant analysis results, and can even download detailed PDF reports or export their scan history as CSV. The system handles exe, dll, sys, scr, and ocx files, which covers the most common Windows malware vectors.

๐Ÿ”ฌ Under the hood

Feature extraction happens in the extractor.py module, which pulls PE metadata like header details, section characteristics, and import tables. These features feed into a trained XGBoost model, while predictor.py delivers the binary classification result. It is not magic, just solid machine learning applied thoughtfully to a real world security challenge.

User management includes two roles: regular users and admins. Regular accounts let you register, upload files, and review your scan history. Admins access global statistics and can manage other users through a dedicated dashboard. This multi user setup works well for universities or security labs that want to share one analysis tool across a team.

๐Ÿ”ฌ Setting up your own detection lab

You will need Python, Node.js, and MySQL to get started. The documentation walks you through cloning the repo, configuring database credentials in the environment files, and spinning up both backend and frontend services.

Once everything is running, the backend offers a complete API for authentication, file uploads, and analytics, plus interactive docs to explore endpoints.
Running locally means files never leave your infrastructure.

For organizations dealing with sensitive data that cannot go to third party cloud scanners, this privacy preservation is essential.

๐Ÿง  Smart security practices to complement detection tools

Having a detection tool helps, but layered security matters more. Keep your operating system and antivirus definitions current to catch what automated tools might miss. Download executables only from verified sources since highly obfuscated malware can fool even advanced detectors. Test suspicious files in isolated virtual machines before touching your main system to avoid accidental compromise. Watch your network traffic too, because some malware communicates externally even when static analysis passes it.

๐Ÿฑ Check the tool at GitHub

๐Ÿ˜Š If you enjoyed the article share it with your friends and follow us.

#MachineLearning #CyberSecurity #OpenSource #MalwareAnalysis #TechTools

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘Œ5โœ3๐Ÿ‘€221
๐Ÿ›œ Check your router for hidden vulnerabilities

Think your home network is secure just because you set a strong Wi-Fi password? Maybe not. The router itself, the brain of your connection, might be running outdated firmware with known security holes that hackers can exploit silently. A new open-source project is here to help you discover exactly which risks are lurking behind your gateway.

๐Ÿšจ A practical tool for proactive defense

Security researcher Mikhail Artamonov has released router-cve-audit, a utility designed to scan your router's firmware and cross-reference it against a massive database of known Common Vulnerabilities and Exposures. Unlike generic scanners, this tool focuses specifically on identifying whether your device is running versions vulnerable to publicly documented exploits, giving you a clear picture of your exposure without requiring deep technical expertise.

The project leverages the growing transparency of vulnerability databases to empower regular users. By analyzing the firmware version and model of your router, it can instantly flag issues ranging from remote code execution flaws to weak default credentials that haven't been patched in years. This matters because many routers sit untouched for months or even years, becoming easy targets for botnets and unauthorized access.

๐Ÿง Why this matters for your privacy

Routers often represent the weakest link in home cybersecurity. A compromised router can lead to traffic interception, DNS hijacking, or even full control over your connected devices. With thousands of CVEs affecting popular brands like TP-Link, ASUS, Netgear, and others, assuming it works fine is no longer sufficient. This audit tool bridges the gap between complex security data and actionable insights for everyday users.

๐ŸŒŸ How to protect yourself

Start by downloading the tool from the official repository and running a quick scan against your router's firmware details. If vulnerabilities surface, update your router's firmware immediately using the latest version from the manufacturer.

If no updates exist for your specific model, seriously consider replacing it with a newer device that receives regular security patches.

For advanced users, enabling automatic updates if available, disabling remote management features, and changing default admin credentials remain essential habits. If you suspect compromise, perform a factory reset followed by a firmware flash where possible.

๐Ÿฑ Check this awesome tool at GitHub

๐Ÿ‘ If you enjoyed the article share it with your friends and follow us.

#RouterSecurity #CVEAudit #NetworkPrivacy #FirmwareUpdate #OpenSource

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘Œ7๐Ÿ‘€5โœ21
๐Ÿ’ป Windows 0-day exploited by Lazarus to gain SYSTEM privileges

A newly discovered zero-day vulnerability in Windows has been weaponized by the North Korean hacking group Lazarus as part of their ongoing Operation Dream Job campaign. This sophisticated threat targets defense and aviation sector employees with enticing job offers, only to infect their systems through fake PDF viewer software.

๐Ÿ—ก The mechanics of the attack

At the heart of this operation lies CVE-2026-68820, a previously unknown vulnerability in the Windows Ancillary Function Driver (AFD.sys) with a severity rating of 7.0. This flaw allows attackers to escalate privileges directly to the highest system level, SYSTEM, granting them complete control over the compromised machine.

Microsoft acknowledged the issue on July 31 and released a patch on August 11 as part of their scheduled security updates.

The latest iteration of this campaign involves victims being lured to install a counterfeit application called SecurityPDF, distributed through fraudulent websites impersonating the legitimate company Enveil. Once a specially crafted document is opened within this fake viewer, a new backdoor named Troy is deployed. This malicious tool supports 17 distinct commands, enabling extensive remote control capabilities.

๐Ÿ˜ƒ Why continuing with Windows or MacOS may be a mistake

Individuals and organizations that continue relying on Windows or MacOS as primary work tools are increasingly making a risky choice. The reality is stark. Windows vulnerabilities show no signs of ending. Some security experts argue that certain flaws are intentionally embedded to enable law enforcement investigative capabilities, yet these same backdoors inevitably become weapons for cybercriminals once discovered or leaked.

Companies still tied to proprietary operating systems face an endless cycle of patches and emergency fixes.

Meanwhile, open-source alternatives like Linux offer transparency and community-driven security audits that significantly reduce hidden vulnerabilities. For privacy-focused users and businesses handling sensitive data, migrating to Linux is not just advisable. It is becoming essential for long-term digital sovereignty.

๐Ÿ’ก Practical migration path to Linux

Transitioning does not mean abandoning your workflow entirely. Many professional applications have Linux-compatible alternatives or run through containers. Start with a dual-boot setup to test compatibility with your daily tools. Distributions like Ubuntu, Fedora, or Debian provide enterprise-grade stability while maintaining full control over your system.

๐Ÿ˜Š If you enjoyed the article share it with your friends and follow us.

#LazarusGroup #ZeroDay #WindowsSecurity #LinuxMigration #DigitalSovereignty

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
โœ9๐Ÿ‘€7๐Ÿ˜3๐Ÿค”3๐Ÿ‘Œ31
๐ŸŽฎ Twitch using streams to train Amazon AI by default

Are your Twitch broadcasts truly private? Unfortunately, they are not. Your face, voice, chat interactions, clips, and content are currently feeding Amazon's artificial intelligence systems without your knowledge. This process runs silently in the background, enabled automatically from day one.

๐Ÿ’ต Default opt-out reveals troubling priorities

Amazon and Twitch explained their reasoning quite bluntly: if participation required active consent, virtually nobody would agree. This straightforward admission shows how creator privacy ranks below data collection objectives. The platform's documentation confirms that user content trains models capable of generating text, audio, images, and video.

๐Ÿ”Ž What data is vulnerable

Without manual intervention, Amazon accesses your entire footprint on the platform. Live broadcasts, archived videos, fan-made clips, and real-time chat messages all become potential training material.
Every image and word displayed on your channel enters this extensive pool, turning personal broadcasts into corporate assets without asking permission.

โ“ Uncertainty about past harvesting

Questions about previously collected data receive no clear answers. When asked whether specific content had already been used, Twitch leadership admitted they could not confirm what Amazon processed historically. Statements from 2024 acknowledged Amazon was pulling Twitch content for AI purposes, yet creators stay uninformed about how much has disappeared into training systems. Once absorbed into these pipelines, removing your data becomes practically impossible.

๐Ÿ›ก Protecting yourself step by step

You can stop future data collection through simple settings adjustments. Navigate to your profile picture โ†’ settings โ†’ security and privacy. Scroll down until you find the "Generative AI Training" option and turn it off completely. Pay attention because some users report this switch toggling back on unexpectedly, demanding regular checks.

Two important caveats deserve attention. Opting out protects only your own channel content. When you join chat rooms on other streamers' broadcasts, their settings control your visibility regardless of your preferences. Furthermore, this action prevents only incoming training sessions. No mechanism exists to recover or identify what has already been consumed by Amazon's systems.

๐Ÿ˜Š If you enjoyed the article share it with your friends and follow us.

#TwitchAI #DataPrivacy #CreatorRights #AmazonAI #DigitalSecurity

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
โœ7๐Ÿ‘Œ4๐Ÿ‘€2๐Ÿคทโ€โ™‚1๐Ÿ˜1๐Ÿค”11
๐Ÿค– Strix brings AI-powered pentesting to open source

Think penetration testing requires weeks of manual work and expensive security consultants? Strix challenges that assumption by combining artificial intelligence with the same offensive security tools professional ethical hackers use.

This open-source platform empowers developers and security teams to identify and fix vulnerabilities faster than traditional methods allow.

โš™๏ธ Agentic pentesting meets real-world tools

Strix agents deploy a comprehensive security toolkit directly into your development workflow. From HTTP interception proxies with full request manipulation to automated browser exploitation for XSS and CSRF testing, the platform mirrors what human pentesters accomplish manually. The shell execution environment enables interactive exploit development while the custom Python sandbox validates proof-of-concept exploits safely. Reconnaissance capabilities automatically map attack surfaces through subdomain enumeration and fingerprinting without human intervention.

๐Ÿ“Ž Static analysis finally catches context

Unlike conventional scanners drowning teams in false positives, Strix combines SAST and DAST capabilities with vulnerability intelligence. Each finding includes CVSS scoring and OWASP classification with structured details and reproduction steps. The dashboard displays live agent activity, severity breakdowns, and allows mid-scan steering instructions through the browser interface. Teams can browse historical runs and generate shareable reports emailed directly to stakeholders.

๐ŸŒ Enterprise features without vendor lock-in

The platform scales from individual developers to organizations needing compliance-ready documentation. SOC 2, ISO 27001, and PCI DSS reporting comes standard alongside SSO integration via SAML or OIDC.

Custom deployment options include VPC hosting and self-hosted configurations with bring-your-own-key model support. Security teams maintain full control while benefiting from dedicated SLA-backed support channels.

๐Ÿฑ Check this tool at GitHub

๐Ÿ˜Š If you enjoyed the article share it with your friends and follow us.

#AIsecurity #Pentesting #DevSecOps #OpenSource #AppSec

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘€8๐Ÿ‘Œ5โœ3๐Ÿ˜21
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿ“ธ FLOCK: The AI surveillance network watching America

A private company based in Atlanta has quietly built one of the most expansive surveillance networks ever seen on US soil. Flock Safety, founded in 2017, has deployed roughly 120,000 automated license plate reader cameras across 49 states, capturing vehicle data in real time and building a permanent record of citizen movement.

Marketed as a public safety tool, the system has sparked fierce opposition from privacy advocates and civil liberties organizations who warn that it effectively eliminates anonymity in public spaces.

โš™๏ธ How FLOCK cameras operate

These devices are self-contained units powered by solar panels or LTE connections, mounted on traffic poles, lampposts, and other public fixtures. Each camera captures not only license plates but also vehicle make, model, color, and what the company calls a "vehicle signature." The AI processes this data instantly and cross-references it against databases of stolen vehicles, Amber Alerts, and custom watchlists created by local law enforcement.

What makes this particularly alarming is the retroactive search capability. Officers can look back weeks or even months to reconstruct the movement history of any vehicle, without needing prior suspicion of a crime. This turns ordinary traffic into a searchable database of human behavior, where every trip to the store, a doctor's appointment, or a protest becomes a data point permanently stored and queryable by more than 5,000 law enforcement agencies nationwide.

๐Ÿšจ Threats to privacy and civil liberties

The ACLU and other organizations have raised serious concerns about the indefinite storage of data belonging to innocent citizens. Reports have emerged of this information being accessed by federal agencies such as ICE for immigration enforcement, expanding the system's reach far beyond its original public safety purpose.

Without federal regulation, data retention policies vary wildly between jurisdictions. Some areas keep records indefinitely, creating an ever-growing database of personal movement patterns. Critics have drawn parallels to dystopian literature, noting that constant surveillance produces a chilling effect on free speech and peaceful assembly. People have reportedly avoided attending protests, political meetings, or medical facilities out of fear of being tracked and catalogued.

There are also documented cases of security vulnerabilities. Researcher Benn Jordan discovered that some Flock cameras were left live-streaming to the open internet, and that company executives had accessed live feeds from cameras near schools and gymnastics facilities. The company's CEO even sent emails to police department customers claiming that Flock and law enforcement were "under attack" by YouTube videos exposing these issues.

๐ŸŒ Practical steps to reduce your exposure

While completely avoiding cameras in urban environments is nearly impossible, there are meaningful actions you can take. Community mapping tools like DeFlock allow you to identify known ALPR locations near you and plan routes that minimize exposure. Supporting local legislation that limits data retention periods and requires warrants for retrospective searches is another powerful way to push back. Organizations like the EFF and ACLU actively monitor surveillance deployments and provide resources for community advocacy. You can also demand transparency from your local government regarding contracts with surveillance companies and how your data is handled.

๐Ÿ” Find where cameras are installed near you:

https://deflock.org
https://maps.deflock.org

๐Ÿ˜Š If you enjoyed the article share it with your friends and follow us.

#MassSurveillance #PrivacyRights #FlockSafety #CivilLiberties #ALPR

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘€6๐Ÿค”4โœ3๐Ÿ‘Œ2๐Ÿ˜1
๐Ÿค– Nodriver: Advanced automation and web scraping

Collecting web data today means dealing with serious anti-bot defenses. That's where nodriver comes in. As the successor to Undetected-Chromedriver, this library handles asynchronous web automation and scraping while slipping past detection systems like Captcha and CloudFlare. For developers who need reliable access to web data, it's built to work when other tools fail.

๐Ÿ–ฅ Core features and ease of use

Unlike Selenium-heavy solutions, nodriver runs light and fast. You can start a browser session with literally one line of code. Each execution automatically cleans up user profiles afterward, which helps avoid fingerprinting issues. The element search and selection methods are also more advanced than what you get with traditional libraries, saving time on complex interactions.

โ–ถ๏ธ Performance and resilience benefits

Speed is noticeably better thanks to the async architecture. Data collection happens faster, but the real win is how it holds up against WAFs and bot mitigation systems. I've seen scrapers that normally block within minutes keep running for hours with nodriver. For both quick prototypes and production setups, that reliability makes a difference.

๐Ÿ‘จโ€๐Ÿ’ป Ideal use cases

If your project involves scraping sites known for blocking automation, or you need to navigate flows that aggressively detect bots, this tool gives you the flexibility to stay under the radar. It's particularly useful when you're tired of constantly tweaking scripts just to get through basic pages.

๐Ÿ›ก Protection tips for ethical scraping

Powerful tools come with responsibility. Here's how to use them without causing issues:

โ–ซ๏ธ Check robots.txt first โ€” respect what sites allow you to scrape.

โ–ซ๏ธ Add delays between requests so servers don't get overwhelmed.

โ–ซ๏ธ Read Terms of Service before automating access to any site.

โ–ซ๏ธ Watch out for personal data โ€” GDPR and similar regulations still apply.

๐Ÿฑ For those wanting to dive into the code or documentation, check out the official repository

๐Ÿ˜Š If you enjoyed the article share it with your friends and follow us.

#Python #WebScraping #Automation #CyberSecurity #OpenSource

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
โœ6๐Ÿ‘Œ5๐Ÿ˜2๐Ÿค”1๐Ÿ‘€111
๐Ÿ– Discover 100 private services: Free alternatives to leading platforms

Big tech giants like Google, ChatGPT, and Midjourney profit from your data. Every click, message, and upload can end up in advertisers hands. But you don't have to accept this trade-off anymore.

๐Ÿ”› Practical replacements that work

This collection curates 100 tools that put you in control. Swap out mainstream services for private file managers, discreet app stores, local AI models, encrypted cloud storage, and keyboards built for privacy. Each option keeps your information local or encrypts it before it ever touches a server.

๐Ÿ” Simple steps to protect yourself

Make security a habit: enable end-to-end encryption on everything you can, choose open-source software whenever possible, limit what you store in the cloud, and remember that free services usually monetize through your data. Small changes add up to real protection.

๐Ÿฑ Check the full toolkit at Github

๐Ÿ˜Š If you enjoyed the article share it with your friends and follow us.

#Privacy #OpenSource #CyberSecurity #DataProtection #DigitalRights

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ˜6โœ4๐Ÿค”3๐Ÿ‘€2111
๐Ÿ—ฝ The ten commandments of Privacy Not A Crime

This is who we are. This is what we believe. Ten principles that guide everything we share.

๐Ÿ”ข Information must be free and accessible to everyone, at all times

Knowledge should never sit behind paywalls or borders. The moment we accept only those who can afford it deserve to be informed, we lose something fundamental. Security awareness, threat intelligence, defensive techniques, all of it should flow freely.

๐Ÿ”ข Never pay for information, except in rare exceptions

Core security knowledge should not become a luxury item. When protecting yourself online comes with a price tag, something has gone wrong. Exceptions exist, but openness is always the default.

๐Ÿ”ข Economic contributions must always be voluntary

Support should come from conviction, never pressure. No forced subscriptions, no hidden fees, no holding content hostage. Support grows organically when people truly believe in what you do.

๐Ÿ”ข Physical and digital freedom is the number one priority

Your right to walk down a street without tracking and browse without profiling are the same fight. Both matter equally. Freedom is not a setting you toggle, it is a baseline.

๐Ÿ”ข Use learned knowledge to do good and for a just and ethical cause

Skills are tools. Vulnerability disclosure can save millions or get sold to exploit them. The difference lies in the hands that hold the knowledge. We choose protection, always.

๐Ÿ”ข Transparency is the antidote to abuse

Secret algorithms shape what you see. Hidden data collection profiles who you are. None of this survives public scrutiny intact, which is why scrutiny matters. Openness is the foundation of security.

๐Ÿ”ข Security is a human right, not a luxury product

Being safe online should not depend on affording premium software. Basic digital hygiene, encrypted communication, strong authentication, these are not perks for the privileged. They are minimum standards everyone deserves.

๐Ÿ”ข Anonymity is a shield for the vulnerable

Anonymity protects journalists, activists, survivors, and ordinary citizens who do not want every move catalogued. It is not about hiding wrongdoing, it is about surviving.

๐Ÿ”ข Education empowers resistance

You cannot defend what you do not understand. Knowing how tracking works, why apps want your location, what permissions mean, this is survival literacy for the digital age. We break down complex concepts into language anyone can follow.

๐Ÿ”ค Privacy is not a crime, it is a fundamental right

Wanting a private life does not make you suspicious. Encrypting messages does not make you a target. Refusing to share personal data means you understand your life belongs to you, not a corporation or algorithm.

Privacy Not A Crime. It never was. And it never should be.

These ten commandments are who we are. If they resonate with you, you are already one of us.

๐Ÿ˜Š Follow us to stay informed about the latest threats and protect yourself.

#PrivacyNotACrime
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿฅฐ22๐Ÿ‘Œ17โœ7๐Ÿ‘€4๐Ÿค”2๐Ÿ˜1
๐Ÿ’ฌ A follower asks us the following question in Spanish:

Which operating system is most vulnerable to these attacks: GrapheneOS, iOS, or standard Android? Which one is more secure in preventing real-time remote access by government spyware and zero-click attacks where the user doesnโ€™t have to do anything, but simply by inserting the SIM card and connecting to the network, the phone becomes infected and is accessed remotely?


๐Ÿ™ First of all, thank you for asking.

๐Ÿ”นThe most vulnerable and exploitable operating systems are those that are closed-source, the ones that the community cannot audit and does not know what lies behind them. That is why we always recommend using the latest version of Android with the latest security patches applied. Note: we mean โ€˜open-sourceโ€™ Android, without proprietary services such as those from Google.

๐Ÿ”นTo prevent remote access to your smartphone, you need to take certain basic security measures; the most important ones are as follows:

โ–ซ๏ธ Manually update your operating system to the latest version and ensure it has the latest security patches. By โ€˜manuallyโ€™, we mean that you should download the update from the providerโ€™s official website and install it from a PC; never update automatically, as this is a common vector for compromise. Always be wary of automatic updates.

โ–ซ๏ธ Never accept automatic updates for any type of app.

โ–ซ๏ธ Never click on any links that are sent to you, no matter how harmless they may seem. Even if they're sent by someone you trust. Just don't do it.

โ–ซ๏ธ Always keep your web browser and apps updated to the latest version, although there are exceptions depending on each person's situation.

โ–ซ๏ธ Do not use proprietary services from companies such as Google, Microsoft, Facebook (Meta), X, YouTube, WhatsApp, etc.

โ–ซ๏ธ Of course, don't install apps from unknown sources unless you know what you're doing.

๐Ÿ”นDisable the network operatorโ€™s services and uninstall apps such as โ€˜SIM Toolkitโ€™, as this is a commonly used attack vector.

๐Ÿ”นAlways opt for an eSIM rather than a physical SIM card to reduce the attack surface.

๐Ÿ”นUse a good, community-maintained smartphone firewall that is regularly updated, and a good VPN that does not keep logs

๐Ÿ”นBlock all private IP addresses on the firewall, but particularly those of the service provider (100.64.0.0/10). The service provider may intercept your traffic and reroute it through that range in order to spy on your communications.

๐Ÿ”นAlways prioritise 5G NR over any other mobile network. Do not confuse this with 5G NR NSA, as NR NSA uses 4G LTE for the control channel and 5G NR for the data channel. This offers no additional security benefits and creates attack vectors such as man-in-the-middle attacks.

๐Ÿ”นUninstall any certificate from the root system unless you fully trust it and know what it is for. If you do not know why it is there, it is best to remove it.

โ• But itโ€™s not all down to the software; the hardware is also very important, and, paradoxically, using a less popular smartphone will help to reduce the attack surface. Most exploits are designed for Samsung and Apple.

๐Ÿ”– These are just a few tips for reducing your attack surface. However, youโ€™ll also need to learn how to identify indicators of compromise so you know when your device might be compromised. But weโ€™ll cover that in another article if our followers show their support.

๐Ÿ‘‹ If youโ€™ve enjoyed this new section, please let us know.

@PrivacyNotACrime ๐Ÿ—ฝ โŒจ๏ธ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿฅฐ15โœ11
๐Ÿฅฐ532๐Ÿ‘Œ11