Privacy + Secure Tech Corner Channel 🛡️
90 subscribers
6.65K photos
578 videos
497 files
16.1K links
Here you can find all about GSI's, ROM's, GKI Kernel's, Tech NEWS, Updates, Root methods, Magisk Module, Overlay's, Hacker things, FLOSS, FOSS, Privacy + Secure Stuff and many more!
Download Telegram
Forwarded from cKure
■■□□□ News circulating online.

Cloudflare just blocked the largest DDOS attack of all time at 11.5 Tbps. The attack was a UDP flood that came from Google Cloud.
Russia To Mandate Preinstallation Of State Messaging App Max And Rustore On All Smartphones And Tablets

https://github.com/KARENKING112/max-deep-analysis-of-the-messenger

Here's a deep analysis of it.

General report on the analysis of the application "Max"
General information about the "Max" app: The Max application is positioned as a fast and easy messenger for communication. High-quality calls, animated stickers, sending files up to 4 GB, as well as the presence of chatbots and mini-applications are declared. It is distributed on various platforms: Android (via Google Play, RuStore, AppGallery, iOS (via the App Store) and desktop versions. The application package - ru.oneme.app(According to Android Manifest.xml).
Code obfuscation: A significant part of the application code, especially in the module com.my.tracker.obfuscated, subjected to obfuscation. Names of classes (e0, c1, y2, b3, f1etc.), methods (a(), b(), c()) and variables in these osted files are meaningless and short, which makes the analysis of the logic of the application extremely difficult without debfusion. Oceanscape is often used to difficulty in reverse designing and hiding the true functions of code.
Data collected (MyTracker module): Module com.my.tracker(Judges by MyTracker.java, MyTrackerConfig.java, MyTrackerParams.java) is responsible for the extensive collection of user data and events.
The main categories of data collected:
User events :
Promotional events (trackAdEvent): Information about interaction with advertising.
Events of purchases (trackAppGalleryPurchaseEvent, trackPurchaseEvent): Details of purchases, including product ID, prices, currency, and additional parameters.
General user events (trackEvent): Universal collection of arbitrary events with customizable parameters (e.g. event name, category, value).
Events of invitations (trackInviteEvent): Tracking User invitations.
Start of applications (trackLaunchManually): Fixing each manual application start.
Level Events (trackLevelEvent): User progress by level.
Entrance Events (trackLoginEvent): User input information, including ID and login method.
Events of mini-applications (trackMiniAppEvent): User activity in mini-applications.
Events of registration (trackRegistrationEvent): Details about the user registration process.
Time spent in the annex/event (incrementEventTimeSpent, startAnytimeTimeSpent, stopAnytimeTimeSpent, startForegroundTimeSpent, stopForegroundTimeSpent): Detailed statistics of application use.
Personal data of the user :
Age (getAge, setAge)
Paul (getGender, setGender)
User ID (getCustomUserId/getCustomUserIds, setCustomUserId/setCustomUserIds)
Email Addresses (getEmail/getEmails, setEmail/setEmails)
ID from messengers and social networks: ICQ ID (getIcqIdOK.ru ID (getOkId), VK Connect ID (getVkConnectId), VK ID (getVkId)
Phone numbers (getPhone/getPhones, setPhone/setPhones)
Interface language (getLang, setLang)
Special IDs associated with MRGS (getMrgsAppId, getMrgsId, getMrgsUserId)
Arbitrary custom parameters (getCustomParam, setCustomParam): Allow developers to collect any additional information.
Attribution data :
Diplinki ( getDeeplinkFrom MyTrackerAttribution: Sources of user transfer to the application (e.g., from advertising campaigns or external links).
Data and system with it (Android Manifest.xml): File AndroidManifest.xmldescribes the requested permissions and components that allow the application to interact with the operating system and collect system data.
The main requested permissions:
Access to the network and location:
android.permission.INTERNET: Full access to the network.
android.permission.ACCESS_WIFI_STATE, android.permission.ACCESS_NETWORK_STATE, android.permission.CHANGE_NETWORK_STATE, android.permission.CHANGE_WIFI_STATE: Access to the state of Wi-Fi and cellular network, the ability to change their condition.
Forwarded from cKure Red
🖼The One-Man APT, Part I: A Picture That Can Execute Code on the Target.

https://hackers-arise.com/the-one-man-apt-part-i-a-picture-that-can-execute-code-on-the-target/
Please open Telegram to view this post
VIEW IN TELEGRAM
Media is too big
VIEW IN TELEGRAM
⚡️FCC to Shut Down 1,000+ VoIP Companies

Do you use a VoIP service? On August 28, over 1,000 U.S. VoIP providers were forced to stop service under a new FCC order.

The reason: companies didn’t meet the latest Robocall Mitigation Database requirements under the TRACED Act. That means within 2 business days, all other carriers must block traffic from these providers.

This isn’t just about robocalls. It’s also about surveillance — with call lookups, timestamps, calling parties, and more stored for months at a time.

Check if your provider is on the list here:
📄 https://web.archive.org/web/20250826200157/https://docs.fcc.gov/public/attachments/DA-25-737A1.pdf

📖Read the full article on Substack


🫶 @takebackourtech
📩 WEBSITE & NEWSLETTER | 🎥 VIDEOS| XMPP | SUBSTACK
#Microsoft swats down reports of #SSD failures in #Windows
Company says recent update didn't cause storage failures

https://xcancel.com/pirat_nation/status/1962668041830912305
The Unique Personal Registry Code (biometric CURP) project in Mexico, which requires the compulsory submission of face, fingerprints and iris biometrics, is not going ahead as planned in some parts of the country following court injunctions.

The new personal identification system, which was made mandatory in July, has been halted by at least three tribunals after a barrage of criticisms and legal challenges over data security and privacy, Yucatán Magazine reports.

One of the suspensions follows a decision from the Collegiate Tribunal for Criminal and Administrative Matters in Yucatán, when it ruled on the filing of a complaint by an individual.

Similar decisions to suspend the mandatory biometric collection have also been granted by tribunals in Mexico City and Querétaro. https://www.biometricupdate.com/202509/mexico-courts-pause-biometric-curp-project-over-data-privacy-concerns
Boostify

Boostify is a modern, Xposed module that supercharges WhatsApp with smart extras, adding advanced features and fine-grained customization and privacy. — inspired by WaEnhancer and MdgWa. It focuses on a clean, preference-first UX, safe guards for power actions, and tools that respect your device.

🔗 Links:
- Download
- Screenshot
- Features
- Source code
Developer: wizdom13

🫂 Special thanks to @magiskrootport for post

❤️ Support the Project

If this project makes your life easier, here are a few quick ways to show some love:

Star the repo/app
Buy a coffee for the developer
🛠 Contribute code, issues, or pull-requests

🏷 Tags:  #Android #Root #XPosed #Modules
📱 Above Phone — Easy to Use, Hard to Track

More than a phone — it’s your complete shield against mobile surveillance.
Zero Big Tech connections by default
Worldwide service — just pop in a SIM
Modern updates & features through 2031

Above Phone gives you more freedom:
• Disable 5G, stick to secure 4G/LTE
• Create encrypted “phones” inside your phone
• Use multiple numbers on one device
• Encrypted calls, texts & apps

Every phone comes with a free 45-min onboarding call + guides, video courses, and monthly webinars.

👉 Discover Above Phone
Unix Co-Creator Brian Kernighan on Rust, Distros and NixOS

Kernighan shared his thoughts on what he thinks of the world today — with its push away from C to more memory-safe programming languages, its hundreds of distributions of Linux — and with descendants of Unix powering nearly every cellphone.
https://thenewstack.io/unix-co-creator-brian-kernighan-on-rust-distros-and-nixos/