101010.pl is one of the many independent Mastodon servers you can use to participate in the fediverse.
101010.pl czyli najstarszy polski serwer Mastodon. Posiadamy wpisy do 2048 znaków.

Server stats:

567
active users

#signature

0 posts0 participants0 posts today

Die Signatur-Problematik bei F-Droid ist offenbar noch immer nicht gelöst: "We find it concerning that F-Droid constantly chooses to move the goalposts and continues to rely on a fundamentally broken approach for certificate pinning, merely patching [15] known vulnerabilities without ever addressing the underlying cause." 😵👇

github.com/obfusk/fdroid-fakes

GitHubGitHub - obfusk/fdroid-fakesigner-poc: F-Droid Fake Signer PoCF-Droid Fake Signer PoC. Contribute to obfusk/fdroid-fakesigner-poc development by creating an account on GitHub.

@bedast My problem is that these people refuse to take the correct consequences and migrate away from garbage:

  1. You just don't install such garbage on #Unix-esque Systems like #Linux!

  2. #CrowdStrike is just yet another #Scareware #Scam.

  3. The entire business model of #AntiVirus and other Scareware shouldn't exist to begin with.

  4. 3rd party #BinaryBlobs on a non-#FLOSS'd kernel are just bad!

  5. It should be #Microsoft's sole tesponsibility to just not allow #Rootkits / #Bootkits like that to exist eith their blessing aka. #Signature on.

  6. #Windows & #WindowsServer are unbelieveably #cursed and unmaintainable mess that'll make even #Solaris 7 look clean and sleek.

  7. The diversity of Linux and Unix-esque distros like #BSD's make it basically impossible to bmhave such a giant and direct effect.

  8. The whole issue should've been avoided throug extensive testing because it's certainly so rampant that it would've been picked up by #QA testers.

  9. The fuckedup-ness of #CensorBoot aka. "#SecureBoot" (which is insecure af - see #GoldenKeyBoot!) is the reason why this results in such catastrophic failures, whereas on #Linux one just uses #LUKS and can easily recover files.

  10. Most Windows users & -#sysadmins neglect #Backups of Windows machines because there is no good way to backup them!

  11. 3rd party kernel binaryblobs are #malware, regardless if "Anti-Malware" or "#AntiCheat" is the claimed functionality.

  12. If I don't trust #WindowsDefender then I don't trust Windows or rather Microsoft and thus have to cease using it!

  13. This shit would not have been possible under Linux!

Nondeterministic ComputerMatthew Garrett (@mjg59@nondeterministic.computer)"Linux would have prevented this!" literally true because my former colleague KP Singh wrote a kernel security module that lets EDR implementations load ebpf into the kernel to monitor and act on security hooks and Crowdstrike now uses that rather than requiring its own kernel module that would otherwise absolutely have allowed this to happen, so everyone please say thank you to him
Replied in thread

@Framasoft
Je me souviens être passé par DocuSign* la dernière fois que j’ai signé un contrat.
Ça me proposait de signer « à la main » certains champs.
Ça ne me dérangerait pas de signer numériquement à l’aide d’une clef PGP mais ce n’est pas populaire comme pratique.

* docusign.com/

www.docusign.comDocusign | #1 in Electronic Signature and Intelligent Agreement ManagementCreate, commit to, and manage your agreements all in one platform with Docusign IAM. Electronically sign for free.
Continued thread

The most dangerous tendency of all:

These massive surveillance AI companies are moving to become defense contractors,
providing weapons and surveillance infrastructures to militaries and governments they choose to arm and cooperate with.

We are all familiar with being shown ads in our feeds for yoga pants (even though you don’t do yoga)
or a scooter (even if you just bought one),
or whatever else.

We see these because the surveillance company running the ad market or social platform has determined that these are things
“people like us” are assumed to want or be attracted to,
based on a model of behavior built using surveillance data.

Since other people with data patterns that look like yours bought a scooter, the logic goes,
you will likely buy a scooter
(or at least click on an ad for one).

And so you’re shown an ad.

We know how inaccurate and whimsical such targeting is.

And when it’s an ad it’s not a crisis when it’s mistargeted.

But when it’s more serious, it’s a different story.

We can trace this story to the post-9/11 US drone war,
with the concept of the #Signature #Strike.

A signature strike uses the logic of ad targeting,
determining targets for death based not on knowledge of the target
or certainty about their culpability,
but based on data patterns and surveillance of behavior that the US,
in this case, assumes to be associated with terrorist activity.

Signature strikes kill people based on their data profiles.

And AI, and the large scale surveillance platforms that feed AI systems,
are supercharging this capability in incredibly perilous ways.

We know of one shocking example thanks to investigative work from the Israeli publication 972,
which reported that the Israeli Army, following the Oct 7th attacks,
is currently using an AI system named #Lavender in Gaza,
alongside a number of others.

Lavender applies the logic of the pattern recognition-driven signature strikes popularized by the United States,
combined with the mass surveillance infrastructures and techniques of AI targeting.

Instead of serving ads, Lavender automatically puts people on a kill list
based on the likeness of their surveillance data patterns to the data patterns of purported militants
– a process that we know, as experts, is hugely inaccurate.

Here we have the AI-driven logic of ad targeting,
but for killing.

According to 972’s reporting, once a person is on the Lavender kill list,
it’s not just them who’s targeted,
but the building they
(and their family, neighbors, pets, whoever else)
live is subsequently marked for bombing,
generally at night when they (and those who live there)
are sure to be home.

This is something that should alarm us all.

(4/8)

‘Secret’ iPhone feature lets you easily sign online documents for free, with no scanning, printing, or app installing

In the age of digital communication, needing to sign important documents online has become increasingly common, but it’s not necessarily the easiest process.

For an iPhone you can just use the standard Photos app to open it, hit Edit, click the M ...continues

See gadgeteer.co.za/secret-iphone-

GadgeteerZA · ‘Secret’ iPhone feature lets you easily sign online documents for free, with no scanning, printing, or app installingIn the age of digital communication, needing to sign important documents online has become increasingly common, but it’s not necessarily the easiest process.
Replied in thread

5/4 Update: looks like more devs should read that latest toot of this thread. Since I'm checking #signatures in my repo, there's not a week where not AT LEAST one app comes in with a different #signature 😱 So here's what to specifically be aware of:

* disk crashes (or entire PCs giving up)
* accidentally deleting the directory where the "important stuff" is in
* signing was done by a team member that left

All 3 cases can be covered by good #backups – just sayin'. Off-device, ideally.

Any clues on to how I can view the #signature of a #PDF file on linux?

A family member has set their system up to sign with a government-signed certificate, and I want to check that the signature they've attached (and the chain) is valid.

Looking for something simple, it's a one-time okay-to-do-manually kind of thing.

Elizabeth Warren: "it’s critical that those responsible not be rewarded. #SBV and #Signature shareholders will be wiped out, but their executives must also be held accountable. ... Congress should empower regulators to recover pay and bonuses. Prosecutors and regulators should investigate whether any executives engaged in insider trading ‌or broke other civil or criminal laws." nytimes.com/2023/03/13/opinion

The New York TimesOpinion | Elizabeth Warren: We Can Prevent More Bank FailuresBy Elizabeth Warren