Daily Shaarli

All links of one day in a single page.

18 août 2020

2.5 Million Medical Records Leaked By AI Company

Secure Thoughts collaborated with Cyber Security Expert Jeremiah Fowler to expose an AI company which leaked millions of patient medical records online

εxodus
εxodus
Battle of the Secure Messaging Apps: How Signal Beats WhatsApp

Both Signal and WhatsApp are encrypted, but Signal takes extra steps to keep your chats private.

Why You Should Stop Using Telegram Right Now

Telegram, the supposedly secure messaging app, has over 100 million users. You might even be one of them. If you are, you should probably stop using it right now. Here’s the unfortunate truth about Telegram: it’s not as secure as the company’s marketing campaigns might lead you to believe.

The US Senate Is Using Signal - Schneier on Security
Wegen Vorratsdatenspeicherung: Threema prüft Wegzug aus der Schweiz | heise online
CSS Exfil Protection – Get this Extension for 🦊 Firefox (en-US)

Download CSS Exfil Protection for Firefox. Guard your browser against CSS Exfil attacks!

CSS Exfil is a method attackers can use to steal data from web pages using Cascading Style Sheets (CSS). This plugin sanitizes and blocks any CSS rules which may be designed to steal data.

Instagram could face up to $500 billion in fines in class-action lawsuit alleging it illegally harvested biometric data

...

Is This New Signal Feature Enough To Make You Ditch WhatsApp?

Could this smart new Signal feature be enough to make you ditch WhatsApp?

What are the features of a secure and private communication service – Telegraph

Last update: May 22, 2020
Español - Italiano
Introduction
This article analyses the security and confidentiality features of the most commonly used communication services or applications.
Note: the comparison is made between WhatsApp (the most widespread 1.6 billion users), Telegram (the most secure and widespread 400 million users), Signal and Wire (the most secure and confidential) according to world statistics. A comparison in terms of functionality is available at this address.
Remark: for any communication…

Choosing the Right Messenger
Threema - Wikipedia
Signal (software) - Wikipedia
Telegram Founder on WhatsApp Hacks: Backdoors Are Camouflaged as Security Flaws

Pavel Durov criticized WhatsApp in new blog post

Signal compromised? - signal

If you need top level privacy protection do some or all of the following

AndroidHardening project renamed to GrapheneOS
How was Jeff Bezos’s iPhone hacked? - The Washington Post
This smartphone has physical kill switches for its cameras, microphone, data, Bluetooth, and Wi-Fi

A common complaint with modern smartphones is that they are black boxes. Android and iOS are complicated pieces of software, each with hundreds (if not

Goodbye Whatsapp: All of Bundesbern relies on Threema Work
Comparing Messaging Apps - Schneier on Security
La Commission européenne adopte Signal, sauf pour les discussions très sensibles

Bruxelles recommande à son personnel d'utiliser la messagerie Signal pour discuter avec des personnes extérieures à l'institution, afin de relever le niveau de sécurité des communications. Les échanges très sensibles en revanche continuent de passer par des canaux dédiés.

Protect yourself against a pure CSS data stealing attack called Exfil - gHacks Tech News
Lawsuit: Zoom Lied About Security Measures, End-to-End Encryption - Legal Reader

Zoom is facing another lawsuit alleging that the video communications company has deceived consumers by making false claims about its privacy measures.

Signal secure messaging can now identify you without a phone number – Naked Security

Signal decouples its secure messaging service from your phone number – a bit.

Signal's pin feature shows why putting privacy first is hard

The privacy-first messaging app recently rolled out an opt-out feature that was criticized by security experts and panned by users.

Secure Messaging App Wire Stores Everyone You've Ever Contacted in Plain Text

The decision is seemingly a trade-off for usability across multiple devices.

More is Less: On the End-to-End Security of Group Chats in Signal, WhatsApp, and Threema
Delisting Wire from PrivacyTools.io

It has recently come to the attention of the PrivacyTools team that Wire, the popular end-to-end encryption messaging platform had been sold or moved to a US company. After a week of questioning, Wire finally confirmed they had changed holding companies and would now be a US based company in

Threema, l’app suisse qui rivalise avec WhatsApp et Telegram - Le Temps

L’application helvétique vient de s’enrichir d’un service d’appels vidéo. Ses développeurs affirment que Threema est plus sûre que tous ses concurrents, dont Telegram et Signal

Comment la CIA parvient à lire les messages de WhatsApp - Le Temps
Microsoft Put Off Fixing Zero Day for 2 Years — Krebs on Security

A security flaw in the way Microsoft Windows guards users against malicious files was actively exploited in malware attacks for two years before last week, when Microsoft finally issued a software update to correct the problem.

Feds secretly subpoenaed the encrypted chat app Signal earlier this year - The Verge

Earlier this year, Open Whisper Systems was served with a federal subpoena for records on its users, according to documents published today. Prosecutors were seeking data on two suspects who used...

Signal patches (minor) approximate location disclosure flaw | The Daily Swig

WebRTC DNS lookups exploited in clever hack

Threema: Instant messaging service from Switzerland - Messenger Part 2 ⋆ Kuketz IT security blog

Threema ist ein auf Datenschutz und Sicherheit bedachter Messenger - unabhängig überprüfbar ist dies allerdings nicht.

GitHub - gorhill/uBO-Extra: A companion extension to uBlock Origin

A companion extension to uBlock Origin. Contribute to gorhill/uBO-Extra development by creating an account on GitHub.

Signal >> Government Requests >> Grand jury subpoena for Signal user data, Eastern District of Virginia

We’ve designed the Signal service to minimize the data we retain about Signal users, so the only information we can produce in response to a request like this is the date and time a user registered with Signal and the last date of a user’s connectivity to the Signal service.

Notably, things we don’t have stored include anything about a user’s contacts (such as the contacts themselves, a hash of the contacts, any other derivative contact information), anything about a user’s groups (such as how many groups a user is in, which groups a user is in, the membership lists of a user’s groups), or any records of who a user has been communicating with.

All message contents are end-to-end encrypted, so we don’t have that information either.

Two hackers told us which is the safest messaging app

WhatsApp, Signal e Telegram promettono tutte la stessa cosa: comunicazioni sicure. Ma ci possiamo fidare?

Métadonnées : Signal a trouvé un moyen de mieux protéger ses utilisateurs

Open Whispers System, qui édite Signal, teste une nouvelle approche qui permet d'étendre encore plus la confidentialité de sa communauté. Comment ? En intervenant au niveau des métadonnées.