pouet.chapril.org est l'un des nombreux serveurs Mastodon indépendants que vous pouvez utiliser pour participer au fédiverse.
Chapril https://www.chapril.org est un projet de l'April https://www.april.org

Administré par :

Statistiques du serveur :

1,1K
comptes actifs

#identification

0 message0 participant0 message aujourd’hui
Chuck Darwin<p>For decades, the right has targeted the protections of the 1965 Voting Rights Act, </p><p>most visibly via court decisions, <br>as well as spurious voter roll <a href="https://c.im/tags/purges" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>purges</span></a> and <a href="https://c.im/tags/gerrymandering" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>gerrymandering</span></a> efforts, <br>which warp territorial districting law to divide opponents and consolidate supporters.</p><p>One of the most reliable methods of suppression, though, <br>is to tighten <a href="https://c.im/tags/voter" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>voter</span></a> <a href="https://c.im/tags/identification" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>identification</span></a> rules. </p><p>Requiring <a href="https://c.im/tags/citizenship" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>citizenship</span></a> <a href="https://c.im/tags/paperwork" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>paperwork</span></a>, which many (fully eligible) citizens do not possess, <br>leads to the emergence of a racially inflected pattern of <a href="https://c.im/tags/vote" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>vote</span></a> <a href="https://c.im/tags/suppression" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>suppression</span></a>. </p><p>If you make voting as inconvenient and costly as possible, <br>by default, some percentage of those who are short on money and time <br>— people of color, students, low-income workers and others who juggle lots of obligations with few resources <br>— will decide that getting to the polls just isn’t worth it. </p><p>Maximizing this effect is the primary motive driving the rampant right-wing infringements on democratic participation, <br>Trump’s latest order included.</p><p>To justify these measures, the executive order <br>👉purports to combat large-scale voter fraud: <br>⚠️the familiar right-wing myth that millions of illicit votes are cast in the U.S., in numbers that could throw a presidential election. </p><p>(The real nationwide illegal vote count is a few hundred, at most</p><p>-- of those, quite a few were Trump voters.) </p><p>The type of voter fraud claimed by the right is so vanishingly rare as to be an utterly negligible force in U.S. politics. </p><p>If anything can be said to constitute actual substantive electoral fraud, <br>it is the right’s systematic and wildly successful campaign to <a href="https://c.im/tags/obstruct" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>obstruct</span></a> voting rights.</p><p>Trump’s order, <br>while perhaps the most aggressive foray into voter suppression of late, <br>is far from the only effort to impair democracy. </p><p>🔥Right now the SAVE Act is making its way through Congress; </p><p>the Republican-sponsored legislation would alter registration procedures <br>and demand proof of citizenship documents like <br>a passport, birth certificate or naturalization certification. </p><p>(As NPR reported, researchers have found that<br>👉 1 in 10 voting-eligible Americans don’t possess these documents.)❗️</p><p>There’s notable overlap between the two efforts <br>— the administration seems to be hedging its bets. </p><p>“A lot of [the executive order] tracks pretty closely with what’s in the SAVE Act,” <br>said Diaz. </p><p>Should the SAVE Act fail, the executive order may<br> allow “the White House to get around the congressional lawmaking process<br> -- and do whatever they want.”</p><p><a href="https://truthout.org/articles/trump-assumes-unheard-of-powers-in-ordering-federal-overhaul-of-elections/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">truthout.org/articles/trump-as</span><span class="invisible">sumes-unheard-of-powers-in-ordering-federal-overhaul-of-elections/</span></a></p>
PrivacyDigest<p><a href="https://mas.to/tags/Apple" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Apple</span></a> launches 'age assurance' tech as US states mull social media laws | Reuters</p><p>Feb 27 (Reuters) - Apple Thursday said it will introduce a way for parents to share the age of a <a href="https://mas.to/tags/child" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>child</span></a> with app developers without revealing sensitive information such as <a href="https://mas.to/tags/birthdays" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>birthdays</span></a> or government <a href="https://mas.to/tags/identification" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>identification</span></a> numbers<br><a href="https://mas.to/tags/privacy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>privacy</span></a> <a href="https://mas.to/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://mas.to/tags/ageverification" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ageverification</span></a> <a href="https://mas.to/tags/socialmedia" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>socialmedia</span></a> </p><p><a href="https://www.reuters.com/technology/apple-launches-age-assurance-tech-us-states-mull-social-media-laws-2025-02-27/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">reuters.com/technology/apple-l</span><span class="invisible">aunches-age-assurance-tech-us-states-mull-social-media-laws-2025-02-27/</span></a></p>
Jenny Mathiasson<p>What a week! </p><p>It's been a teaching/speaking heavy one for me as I delivered some training on the identification and care of wood in collections yesterday (which I'd like to think turned out well enough), and spoke to conservation students at Lincoln University about podcasting today. 🪵🎙️</p><p>Speaking of which, we're recording some new podcast material soon as well!</p><p><a href="https://glammr.us/tags/collections" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>collections</span></a> <a href="https://glammr.us/tags/museums" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>museums</span></a> <a href="https://glammr.us/tags/wood" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>wood</span></a> <a href="https://glammr.us/tags/identification" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>identification</span></a> <a href="https://glammr.us/tags/events" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>events</span></a> <a href="https://glammr.us/tags/training" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>training</span></a> <a href="https://glammr.us/tags/workshops" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>workshops</span></a> <a href="https://glammr.us/tags/talks" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>talks</span></a> <a href="https://glammr.us/tags/wooden" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>wooden</span></a> <a href="https://glammr.us/tags/conservation" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>conservation</span></a> <a href="https://glammr.us/tags/CollectionsCare" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CollectionsCare</span></a></p>
Ryan Hodnett<p>Does anyone know what this is? It was in shallow water in a pond in Norway.</p><p><a href="https://mastodon.world/tags/Unidentified" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Unidentified</span></a> <a href="https://mastodon.world/tags/Identification" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Identification</span></a> <a href="https://mastodon.world/tags/ArtWithOpenSource" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ArtWithOpenSource</span></a> <a href="https://mastodon.world/tags/Darktable" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Darktable</span></a> <a href="https://mastodon.world/tags/CCBYSA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CCBYSA</span></a> <a href="https://mastodon.world/tags/Nature" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Nature</span></a> <a href="https://mastodon.world/tags/NaturePhotography" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NaturePhotography</span></a> <a href="https://mastodon.world/tags/Photography" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Photography</span></a></p>
Anthony<p>Si un·e naturaliste peut m'identifier ce cri d'oiseau à (environ 1s / 7s puis 17s). Entendu ce matin vers 10h dans un massif du Gard (essentiellement de chênes verts). L'appli me dit qu'il y a des geais des chênes (ça ok, j'ai bien entendu) mais j'ai un doute pour ce cri qui se répète à intervalle plus longue.</p><p>Une idée <span class="h-card" translate="no"><a href="https://cirtensis.net/channel/lautfille" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>lautfille</span></a></span> ?</p><p><a href="https://piaille.fr/tags/identification" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>identification</span></a> <a href="https://piaille.fr/tags/oiseau" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>oiseau</span></a> <a href="https://piaille.fr/tags/bird" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>bird</span></a> <a href="https://piaille.fr/tags/faune" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>faune</span></a> <a href="https://piaille.fr/tags/Gard" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Gard</span></a> <a href="https://piaille.fr/tags/Occitanie" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Occitanie</span></a></p>
Erik van Straten<p><span class="h-card" translate="no"><a href="https://mastodon.social/@dianasusanti" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>dianasusanti</span></a></span> : very good! It would help if more people did that.</p><p>Of course "avast-pdq dot com" sounds weird, but these scammers also had: (or still have, I'm not sure):</p><p> avast-antivirus dot com</p><p>(see <a href="https://www.virustotal.com/gui/domain/avast-antivirus.com/summary" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">virustotal.com/gui/domain/avas</span><span class="invisible">t-antivirus.com/summary</span></a>).</p><p>HOWEVER: it is too hard for most people and simply insufficient. There are a lot of fake webshops, of whom you don't know the domain name in advance.</p><p>A domain name is a *unique* identification (good!) but it does *not* identify (bad!) who is responsible for a website.</p><p>Certificates *used* to provide that information, but Big Tech insisted on "simpler", in fact anonymous, certificates - as can be seen below. There is *no* information regarding the owner of the website, including their country of jurisdiction.</p><p>We were used to visit shops in streets. It is extremely hard to run a fake physical shop (or bank with a counter and employees), while it is incredibly easy to create an anonymous website that may mimic everything the scammers want.</p><p>Perhaps there were more scammers on pasars (markets) because a new salesperson can appear any day - possibly without permits. Doing that in an actual building is harder.</p><p>P.S. a site to look up certificates is <a href="https://crt.sh" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">crt.sh</span><span class="invisible"></span></a> (example: <a href="https://crt.sh/?q=google-ivi.com" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">crt.sh/?q=google-ivi.com</span><span class="invisible"></span></a>).</p><p><a href="https://infosec.exchange/tags/DVCerts" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DVCerts</span></a> <a href="https://infosec.exchange/tags/DomainValidated" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DomainValidated</span></a> <a href="https://infosec.exchange/tags/Certificates" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Certificates</span></a> <a href="https://infosec.exchange/tags/Identification" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Identification</span></a> <a href="https://infosec.exchange/tags/Authentication" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Authentication</span></a> <a href="https://infosec.exchange/tags/Impersonation" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Impersonation</span></a></p>
Gen_G ⏚<p><a href="https://mamot.fr/tags/Activit%C3%A9PhysiqueQuotidienne" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ActivitéPhysiqueQuotidienne</span></a> (ou presque) <a href="https://mamot.fr/tags/Marche" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Marche</span></a><br><a href="https://mamot.fr/tags/PaysHorloger" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PaysHorloger</span></a>&nbsp;<a href="https://mamot.fr/tags/Doubs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Doubs</span></a> <a href="https://mamot.fr/tags/Paysage" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Paysage</span></a><br>Lundi j'ai passé mon tour, mais hier j'ai fait une balade sympa sur les hauteurs, entre pâturages et forêt et sur un long de sentier de crête.</p><p>Si quelqu'un s'y connaît en <a href="https://mamot.fr/tags/identification" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>identification</span></a> de fèces en plusieurs sections, je suis preneuse.<br>Canidé ou félidé ?</p>
Y⃒̸̷̝̜̙ͥͥͥngmar<p>SOLVED: See bottom of thread.</p><p>It's about 30cm wide, has two independently rotating ceramic rollers with electrical heating spirals inside. But the routing of the wires restricts the turning of the rollers severely, so they can only rotate about 30°.</p><p>There's some elaborate ceramic covers on the wires and a metal tray for catching something between the legs.</p><p>It's clean, doesn't look like it was used for food. Maybe <a href="https://social.tchncs.de/tags/sewing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sewing</span></a>? I have absolutely no idea!</p><p><a href="https://social.tchncs.de/tags/WhatIsThis" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WhatIsThis</span></a> <a href="https://social.tchncs.de/tags/Mystery" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Mystery</span></a> <a href="https://social.tchncs.de/tags/Identification" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Identification</span></a></p>
Schneier on Security RSS<p>Google Is Allowing Device Fingerprinting</p><p>Lukasz Olejnik writes about device fingerprinting, and why Google’s policy change to allow it in 2025 is a majo... <a href="https://www.schneier.com/blog/archives/2025/01/google-is-allowing-device-fingerprinting.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">schneier.com/blog/archives/202</span><span class="invisible">5/01/google-is-allowing-device-fingerprinting.html</span></a></p><p> <a href="https://burn.capital/tags/datacollection" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>datacollection</span></a> <a href="https://burn.capital/tags/identification" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>identification</span></a> <a href="https://burn.capital/tags/Uncategorized" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Uncategorized</span></a> <a href="https://burn.capital/tags/fingerprints" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fingerprints</span></a> <a href="https://burn.capital/tags/tracking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tracking</span></a> <a href="https://burn.capital/tags/privacy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>privacy</span></a> <a href="https://burn.capital/tags/Google" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Google</span></a></p>
PrivacyDigest<p>New year, new ID? Here's the deadline to get the <a href="https://mas.to/tags/RealID" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RealID</span></a> and why you need one </p><p>The federal Real ID Act will take effect May 7, meaning a standard state-issued driver's license or <a href="https://mas.to/tags/identification" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>identification</span></a> card will no longer get people through airport <a href="https://mas.to/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> or into federal buildings.<br><a href="https://mas.to/tags/id" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>id</span></a> <a href="https://mas.to/tags/driverslicense" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>driverslicense</span></a></p><p>Los Angeles Times: <a href="https://apple.news/ASzzT4I9_TdWml7Ol6GRBAA" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">apple.news/ASzzT4I9_TdWml7Ol6G</span><span class="invisible">RBAA</span></a></p>
Apokrif<p><a href="https://pouet.chapril.org/tags/Identification" class="mention hashtag" rel="tag">#<span>Identification</span></a> <a href="https://pouet.chapril.org/tags/morts" class="mention hashtag" rel="tag">#<span>morts</span></a> <a href="https://pouet.chapril.org/tags/Syrie" class="mention hashtag" rel="tag">#<span>Syrie</span></a><br /><a href="https://www.francetvinfo.fr/monde/syrie/chute-de-bachar-al-assad/document-franceinfo-comment-voulez-vous-les-reconnaitre-ils-ont-des-trous-a-la-place-des-yeux-dans-l-enfer-des-morgues-de-damas-ou-les-syriens-tentent-d-identifier-leurs-proches-disparus_6961235.html" target="_blank" rel="nofollow noopener noreferrer" translate="no"><span class="invisible">https://www.</span><span class="ellipsis">francetvinfo.fr/monde/syrie/ch</span><span class="invisible">ute-de-bachar-al-assad/document-franceinfo-comment-voulez-vous-les-reconnaitre-ils-ont-des-trous-a-la-place-des-yeux-dans-l-enfer-des-morgues-de-damas-ou-les-syriens-tentent-d-identifier-leurs-proches-disparus_6961235.html</span></a></p>
loganer<p><a href="https://mastodon.social/tags/Bug" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Bug</span></a> <a href="https://mastodon.social/tags/Canada" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Canada</span></a> <a href="https://mastodon.social/tags/Aylmer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Aylmer</span></a> <a href="https://mastodon.social/tags/Ontario" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Ontario</span></a> <a href="https://mastodon.social/tags/Identification" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Identification</span></a> </p><p>I have never seen anything like this before.<br>some kind of spider/stick bug hybrid?</p>
tala<p>Drôle de mouche à tête jaune presque de la taille d&#39;une abeille charpentière. Visiblement une tachina grossa ?<br /><a href="https://pouet.chapril.org/tags/insects" class="mention hashtag" rel="tag">#<span>insects</span></a> <a href="https://pouet.chapril.org/tags/insectes" class="mention hashtag" rel="tag">#<span>insectes</span></a> <a href="https://pouet.chapril.org/tags/identification" class="mention hashtag" rel="tag">#<span>identification</span></a></p>
Erik van Straten<p>🌘DV-CERT MIS-ISSUANCE INCIDENTS🌒<br>🧵#3/3</p><p>Note: this list (in reverse chronological order) is probably incomplete; please respond if you know of additional incidents!</p><p>2024-07-31 "Sitting Ducks" attacks/DNS hijacks: mis-issued certificates for possibly more than 35.000 domains by Let’s Encrypt and DigiCert: <a href="https://blogs.infoblox.com/threat-intelligence/who-knew-domain-hijacking-is-so-easy/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">blogs.infoblox.com/threat-inte</span><span class="invisible">lligence/who-knew-domain-hijacking-is-so-easy/</span></a> (src: <a href="https://www.bleepingcomputer.com/news/security/sitting-ducks-dns-attacks-let-hackers-hijack-over-35-000-domains/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/sitting-ducks-dns-attacks-let-hackers-hijack-over-35-000-domains/</span></a>)</p><p>2024-07-23 Let's Encrypt mis-issued 34 certificates,revokes 27 for dydx.exchange: see 🧵#2/3 in this series of toots</p><p>2023-11-03 jabber.ru MitMed/AitMed in German hosting center <a href="https://notes.valdikss.org.ru/jabber.ru-mitm/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">notes.valdikss.org.ru/jabber.r</span><span class="invisible">u-mitm/</span></a></p><p>2023-11-01 KlaySwap en Celer Bridge BGP-hijacks described <a href="https://www.certik.com/resources/blog/1NHvPnvZ8EUjVVs4KZ4L8h-bgp-hijacking-how-hackers-circumvent-internet-routing-security-to-tear-the" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">certik.com/resources/blog/1NHv</span><span class="invisible">PnvZ8EUjVVs4KZ4L8h-bgp-hijacking-how-hackers-circumvent-internet-routing-security-to-tear-the</span></a></p><p>2023-09-01 Biggest BGP Incidents/BGP-hijacks/BGP hijacks <a href="https://blog.lacnic.net/en/routing/a-brief-history-of-the-internets-biggest-bgp-incidents" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">blog.lacnic.net/en/routing/a-b</span><span class="invisible">rief-history-of-the-internets-biggest-bgp-incidents</span></a></p><p>2022-09-22 BGP-hijack mis-issued GoGetSSL DV certificate <a href="https://arstechnica.com/information-technology/2022/09/how-3-hours-of-inaction-from-amazon-cost-cryptocurrency-holders-235000/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">arstechnica.com/information-te</span><span class="invisible">chnology/2022/09/how-3-hours-of-inaction-from-amazon-cost-cryptocurrency-holders-235000/</span></a></p><p>2022-09-09 Celer Bridge incident analysis <a href="https://www.coinbase.com/en-nl/blog/celer-bridge-incident-analysis" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">coinbase.com/en-nl/blog/celer-</span><span class="invisible">bridge-incident-analysis</span></a></p><p>2022-02-16 Crypto Exchange KLAYswap Loses $1.9M After BGP Hijack <a href="https://www.bankinfosecurity.com/crypto-exchange-klayswap-loses-19m-after-bgp-hijack-a-18518" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bankinfosecurity.com/crypto-ex</span><span class="invisible">change-klayswap-loses-19m-after-bgp-hijack-a-18518</span></a></p><p>🌘BACKGROUND INFO🌒<br>2024-08-01 "Cloudflare once again comes under pressure for enabling abusive sites<br>(Dan Goodin - Aug 1, 2024) <a href="https://arstechnica.com/security/2024/07/cloudflare-once-again-comes-under-pressure-for-enabling-abusive-sites/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">arstechnica.com/security/2024/</span><span class="invisible">07/cloudflare-once-again-comes-under-pressure-for-enabling-abusive-sites/</span></a></p><p>2018-08-15 Usenix-18: "Bamboozling Certificate Authorities with BGP" <a href="https://www.usenix.org/conference/usenixsecurity18/presentation/birge-lee" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">usenix.org/conference/usenixse</span><span class="invisible">curity18/presentation/birge-lee</span></a></p><p>Edited 2024-09-05 14:19 UTC: corrected the link for the "jabber.ru" incident.</p><p><a href="https://infosec.exchange/tags/DV" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DV</span></a> <a href="https://infosec.exchange/tags/LE" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LE</span></a> <a href="https://infosec.exchange/tags/LetsEncrypt" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LetsEncrypt</span></a> <a href="https://infosec.exchange/tags/Certificates" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Certificates</span></a> <a href="https://infosec.exchange/tags/Certs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Certs</span></a> <a href="https://infosec.exchange/tags/Misissuance" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Misissuance</span></a> <a href="https://infosec.exchange/tags/Mis_issuance" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Mis_issuance</span></a> <a href="https://infosec.exchange/tags/Revocation" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Revocation</span></a> <a href="https://infosec.exchange/tags/Revoked" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Revoked</span></a> <a href="https://infosec.exchange/tags/Weaknessess" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Weaknessess</span></a> <a href="https://infosec.exchange/tags/WeakCertificates" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WeakCertificates</span></a> <a href="https://infosec.exchange/tags/WeakAuthentication" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WeakAuthentication</span></a> <a href="https://infosec.exchange/tags/Authentication" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Authentication</span></a> <a href="https://infosec.exchange/tags/Impersonation" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Impersonation</span></a> <a href="https://infosec.exchange/tags/Identification" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Identification</span></a> <a href="https://infosec.exchange/tags/Infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Infosec</span></a> <a href="https://infosec.exchange/tags/DNS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DNS</span></a> <a href="https://infosec.exchange/tags/DNSHijacks" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DNSHijacks</span></a> <a href="https://infosec.exchange/tags/SquareSpace" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SquareSpace</span></a> <a href="https://infosec.exchange/tags/Authorization" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Authorization</span></a> <a href="https://infosec.exchange/tags/UnauthorizedChanges" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>UnauthorizedChanges</span></a> <a href="https://infosec.exchange/tags/UnauthorizedModifications" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>UnauthorizedModifications</span></a> <a href="https://infosec.exchange/tags/DeFi" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DeFi</span></a> <a href="https://infosec.exchange/tags/dydx_exchange" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dydx_exchange</span></a> <a href="https://infosec.exchange/tags/CryptoCoins" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CryptoCoins</span></a></p>
Erik van Straten<p>🌘DV-CERT MIS-ISSUANCES &amp; OCSP ENDING🌒<br>🧵#1/3</p><p>On Jul 23, 2024, Josh Aas of Let's Encrypt wrote, while his nose was growing rapidly:</p><p>&lt;&lt;&lt; Intent to End OCSP Service<br>[...]<br>We plan to end support for OCSP primarily because it represents a considerable risk to privacy on the Internet.<br>[...]<br>CRLs do not have this issue. &gt;&gt;&gt;<br><a href="https://letsencrypt.org/2024/07/23/replacing-ocsp-with-crls.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">letsencrypt.org/2024/07/23/rep</span><span class="invisible">lacing-ocsp-with-crls.html</span></a></p><p>🚨 On THAT SAME DAY, Jul 23, 2024, LE (Let's Encrypt) issued at least 34 certs (certificates) for [*.]dydx.exchange to cybercriminals, of which LE revoked 27 mis-issued certs approximately 6.5 hours later.</p><p>Note that falsified DNS records may instruct DNS caching servers to retain entries for a long time; therefore speedy revocation helps reducing the number of victims.</p><p>Apart from this mis-issuance *blunder*, CRL's have HUGE issues that Josh does not mention: they are SSSLLLOOOWWW and files are potentially huge - while OCSP is instantaneous and uses little bandwith.</p><p>🌘NO OCSP INCREASES INTERNET RISKS🌒<br>If LE quits OCSP support, the average risk of using the internet will *increase*.</p><p>🌘LIES🌒<br>Furthermore, the privacy argument is mostly moot, as nearly every website makes people's browsers connect to domains owned by Google (and even let's those browsers execute Javascript from third party servers, allowing nearly unlimited espionage). In addition, IP-addresses are sent in the plain anyway (📎).</p><p>(📎 When using a VPN, source and destination IP-addresses *within the tunnel* are not visible for anyone with access to the *outside* of the tunnel - but they are sent in the plain between the end of the tunnel and the actual server.)</p><p>Worse, the remote endpoint of your E2EE https connection increasingly often is *not* the actual server (that website was moved to sombody else's server in the cloud anyway), but a CDN proxy server which has the ability to monitor everything you do (unencrypting your data: three letter agencies love it, FISA section 702 grants them unlimmited access - without anyone informing you).</p><p>🤷 LE may try to blame others for their mis-issuance blunder, but *THEY* chose to use old, notoriously untrustworthy, internet protocols (BGP and DNS, including database records - that DNSSEC will never protect) as the basis for authentication. By making that choice, LE and other DV cert suppliers were simply ASKING for trouble.</p><p>🔓 In fact, the promise that Let's Encrypt would make the internet safer was misleading from the start: domain names are mostly meaningless to users, 100% fault intolerant, unpredictable and easily forgotten. If your browser is communicating with a malicious server, encryption is pointless.</p><p>Josh, stop lying to us; your motives are purely economical.</p><p>🌘CORRUPT: BIG TECH FACILITATES CRIME🌒<br>DV-certs were heavily promoted by Google (not for phun but for profit) after their researchers "proved" that it was possible to show misleasing identification information in the browser's address bar after certificate mis-issuance (the "Stripe, Inc" incident, <a href="https://arstechnica.com/information-technology/2017/12/nope-this-isnt-the-https-validated-stripe-website-you-think-it-is/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">arstechnica.com/information-te</span><span class="invisible">chnology/2017/12/nope-this-isnt-the-https-validated-stripe-website-you-think-it-is/</span></a>).</p><p>This message was repeated by many specialists (e.g. <a href="https://www.troyhunt.com/paypals-beautiful-demonstration-of-extended-validation-fud/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">troyhunt.com/paypals-beautiful</span><span class="invisible">-demonstration-of-extended-validation-fud/</span></a>) with stupid arguments: certificates do NOT directly warrant reliable websites.</p><p>OV and EV certificates, and QWAC's, more or less reliably, warrant *WHO OWNS* a domain name. That means that users know *who* they're doing business with, can depend on their reputation and can sue them if they violate laws.</p><p>"Of course" Google recently lost trust in Entrust for mis-issuing certificates (<a href="https://security.googleblog.com/2024/06/sustaining-digital-certificate-security.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">security.googleblog.com/2024/0</span><span class="invisible">6/sustaining-digital-certificate-security.html</span></a>).</p><p>Meanwhile the internet has become a corrupt and criminal mess; its users get to see misleading identification info in their browser's address bar WAY MORE OFTEN, e.g. https:⁄⁄us–usps–ny.com (for loads of examples see <a href="https://www.virustotal.com/gui/ip-address/188.114.96.0/relations" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">virustotal.com/gui/ip-address/</span><span class="invisible">188.114.96.0/relations</span></a>; tap ••• a couple of times).</p><p>Supporting DN's like "ing–movil.com" and "m–santander.de" *is* facilitating cybercrime, by repeatedly mis-issuing certs for them (see <a href="https://crt.sh/?q=ing-movil.com" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">crt.sh/?q=ing-movil.com</span><span class="invisible"></span></a> and <a href="https://crt.sh/?q=m-santander.de" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">crt.sh/?q=m-santander.de</span><span class="invisible"></span></a>) and by letting them hide behind a CDN (see <a href="https://www.virustotal.com/gui/domain/ing-movil.com/details" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">virustotal.com/gui/domain/ing-</span><span class="invisible">movil.com/details</span></a> and <a href="https://www.virustotal.com/gui/domain/m-santander.de/details" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">virustotal.com/gui/domain/m-sa</span><span class="invisible">ntander.de/details</span></a>).</p><p>In addition, *thousands* of DV-certs have been mis-issued - without *their* issuers getting distrusted by Google, Microsoft, Apple and Mozilla.</p><p>People have their bank accounts drained and companies get slammed with ransomware because of this.</p><p>But no Big Tech company (including the likes of Cloudflare) takes ANY responsibility; they make Big Money by facilitating cybercrime. Not by issuing "free" DV-certs, but by selling domain names, server space and CDN functionality, and by letting browsers no longer distinguish between useful and useless certs. They've deliberately made the internet insecure *FOR PROFIT*.</p><p>🌘CERT MIS-ISSUANCE ROOT CAUSE🌒<br>The mis-issuance of LE certs was caused by the unauthorized modification of customer DNS records managed by SquareSpace; this incident was further described in <a href="https://www.bleepingcomputer.com/news/security/defi-exchange-dydx-v3-website-hacked-in-dns-hijack-attack/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/defi-exchange-dydx-v3-website-hacked-in-dns-hijack-attack/</span></a>.</p><p>Note that a similar attack, also affecting SquareSpace customers, occurred on July 11, 2024 (see <a href="https://www.bleepingcomputer.com/news/security/dns-hijacks-target-crypto-platforms-registered-with-squarespace/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/dns-hijacks-target-crypto-platforms-registered-with-squarespace/</span></a>). Even if it *looks like* that no certs were mis-issued during the July 11 incident, because (AFAIK) none of them have been revoked, this does not warrant that none of them were mis-issued; such certs can still be abused by attackers, albeit on a smaller scale.</p><p>🌘MORE INFO🌒<br>Please find additional information in two followups of this toot:</p><p>🧵#2/3 Extensive details regarding Mis-issued dydx.exchange certs on 2024-07-23;</p><p>🧵#3/3 Links to descriptions of multiple other DV-cert mis-issuance issues.</p><p>🌘DISCLAIMER🌒<br>I am not (and have never been) associated with any certificate supplier. My goal is to obtain a safer internet, in particular for users who are not forensic experts. It is *way* too hard for ordinary internet users to destinguish between 'fake' and 'authentic' on the internet. Something that, IMO, can an must significantly improve ASAP.</p><p>Edited 08:16 UTC to add people:<br><span class="h-card" translate="no"><a href="https://infosec.exchange/@troyhunt" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>troyhunt</span></a></span> <br><span class="h-card" translate="no"><a href="https://infosec.exchange/@dangoodin" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>dangoodin</span></a></span> <br><span class="h-card" translate="no"><a href="https://infosec.exchange/@BleepingComputer" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>BleepingComputer</span></a></span> <br><span class="h-card" translate="no"><a href="https://infosec.exchange/@agl" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>agl</span></a></span> </p><p><a href="https://infosec.exchange/tags/DV" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DV</span></a> <a href="https://infosec.exchange/tags/LE" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LE</span></a> <a href="https://infosec.exchange/tags/LetsEncrypt" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LetsEncrypt</span></a> <a href="https://infosec.exchange/tags/Certificates" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Certificates</span></a> <a href="https://infosec.exchange/tags/Certs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Certs</span></a> <a href="https://infosec.exchange/tags/Misissuance" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Misissuance</span></a> <a href="https://infosec.exchange/tags/Mis_issuance" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Mis_issuance</span></a> <a href="https://infosec.exchange/tags/Revocation" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Revocation</span></a> <a href="https://infosec.exchange/tags/Revoked" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Revoked</span></a> <a href="https://infosec.exchange/tags/Weaknessess" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Weaknessess</span></a> <a href="https://infosec.exchange/tags/WeakCertificates" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WeakCertificates</span></a> <a href="https://infosec.exchange/tags/WeakAuthentication" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WeakAuthentication</span></a> <a href="https://infosec.exchange/tags/Authentication" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Authentication</span></a> <a href="https://infosec.exchange/tags/Impersonation" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Impersonation</span></a> <a href="https://infosec.exchange/tags/Identification" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Identification</span></a> <a href="https://infosec.exchange/tags/Infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Infosec</span></a> <a href="https://infosec.exchange/tags/DNS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DNS</span></a> <a href="https://infosec.exchange/tags/DNSHijacks" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DNSHijacks</span></a> <a href="https://infosec.exchange/tags/SquareSpace" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SquareSpace</span></a> <a href="https://infosec.exchange/tags/Authorization" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Authorization</span></a> <a href="https://infosec.exchange/tags/UnauthorizedChanges" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>UnauthorizedChanges</span></a> <a href="https://infosec.exchange/tags/UnauthorizedModifications" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>UnauthorizedModifications</span></a> <a href="https://infosec.exchange/tags/DeFi" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DeFi</span></a> <a href="https://infosec.exchange/tags/dydx_exchange" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dydx_exchange</span></a> <a href="https://infosec.exchange/tags/CryptoCoins" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CryptoCoins</span></a></p>
Eric Maugendre<p><a href="https://social.coop/tags/work" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>work</span></a> <a href="https://social.coop/tags/workPlace" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>workPlace</span></a> <a href="https://social.coop/tags/safety" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>safety</span></a> <a href="https://social.coop/tags/workCulture" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>workCulture</span></a> <a href="https://social.coop/tags/platforming" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>platforming</span></a> <a href="https://social.coop/tags/workQuality" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>workQuality</span></a> <a href="https://social.coop/tags/mentalHealth" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>mentalHealth</span></a> <a href="https://social.coop/tags/capabilities" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>capabilities</span></a> <a href="https://social.coop/tags/career" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>career</span></a> <a href="https://social.coop/tags/organisations" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>organisations</span></a> <a href="https://social.coop/tags/status" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>status</span></a> <a href="https://social.coop/tags/recognition" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>recognition</span></a> <a href="https://social.coop/tags/anger" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>anger</span></a> <a href="https://social.coop/tags/frustration" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>frustration</span></a> <a href="https://social.coop/tags/meaning" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>meaning</span></a> <a href="https://social.coop/tags/identification" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>identification</span></a> <a href="https://social.coop/tags/disappointment" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>disappointment</span></a> <a href="https://social.coop/tags/needs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>needs</span></a> <a href="https://social.coop/tags/personal" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>personal</span></a></p>