Daily Shaarli

All links of one day in a single page.

June 25, 2018

Messageries, moteurs de recherche... comment se passer de Google, Facebook ou Twitter
Potent malware that hid for six years spread through routers | Ars Technica

Nation-sponsored Slingshot is one of the most advanced attack platforms ever.

LocationSmart API Vulnerability – Robert Xiao

On May 16th, I found a vulnerability in the LocationSmart website which allowed anyone, with no prior authentication or consent, to obtain the realtime location of any cellphone in the US to within…

MixedContentHunter - Modules pour Firefox
Ad-Blocker Ghostery Just Went Open Source—And Has a New Business Model - firefox

While we're at it, might as well include the links of the other privacy suggested addons collected here:

I originally sourced from this comment

HTTPS Everywhere, Cookie AutoDelete, Don't touch my tabs, Link Cleaner, CanvasBlocker and MixedContentHunter. Edit: Links for uBlock Origin, Decentraleyes, privacy badger

Don't touch my tabs! (rel=noopener) - Modules pour Firefox
Ghostery is now Open Source - Android

If you are concerned about privacy, then ghostery still isn't ideal, as it still seems to collect data on the user and has an 'opt-in' ad service which will put adds in.

As others have recommended, for android other browsers are better. As for extensions, there are better ones as well (privacy badger + ublock origins will do what it does, but better).

Another severe flaw in Signal desktop app lets hackers steal your chats in plaintext

Another critical code injection vulnerability found in Signal Desktop app lets remote hackers steal your chats in plaintext