• 2 Posts
  • 181 Comments
Joined 3 years ago
cake
Cake day: July 3rd, 2023

help-circle















  • Every major OS can be secured to the highest security standards

    Has Android added E2EE to their cloud backups yet like Apple has?

    Apple is no friend to any of us, but Google openly and shamelessly scrapes every piece of data you put on their phones. Apple is absolutely the lesser of these two evils with out of the box functionality. I say this as a lifelong Android fan and Apple hater that entered the cybersecurity space and am only interested in the most private option I can get out of the box.

    Like an Android can be more secure and private than an IPhone, but afaik that involves owning a Pixel specifically and installing an entirely different OS on it, one that Google a Is also out to get.


  • The NYPD beat cops aren’t really trained to look for or discover cyber security threats. Additionally, the secret service agents that discovered these were not from Washington but from the local NYC field office, and it was most likely due to heightened security measures surrounding the UNGA visit specifically.

    They weren’t jammers either, they were just sim farms, commonly used for spam calling and other general mid-level cybercrime like that. Think of them as “A bunch of phones”

    The thing is, the importance of this whole event is just being exaggerated, likely to make the Trump admin look good. Like they said these could “take down NYCs cell infrastructure” but they said they only found 100,000 SIM cards total. If every one of those turned on at the same time and tried to overload local infrastructure, it would result in a 1% increase in cell network utilization inside NYC.



  • Server costs? I mean for a media serving website at this scale you need the servers, storage, people to run the servers, people to development the website, fix bugs, keep on top of security. If you had a very talented team that was very lean, and each member of which can wear multiple hats to reduce headcount, you’re talking $400-$600,000 a year just in salaries. Thats before you consider taxes, benefits, etc.

    Do you think bandcamp is run by like one guy renting bargain bin shared cpu servers from AWS?


  • That doesn’t make any logical sense. You cant tie legal authorization to an unsaid implicit assumption, especially when that is in turn based on what you do with the content you’ve retrieved from a system after you’ve accessed and retrieved it.

    When you access a system, are you authorized to do so, or aren’t you? If you are, that authorization can’t be retroactively revoked. If that were the case, you could be arrested for having used a computer at a job, once you’ve quit. Because even though you were authorized to use it and your corporate network while you worked there, now that you’ve quit and are no longer authorized that would apply retroactively back to when you DID work there.


  • If I put a banner on my site that says “by visiting my site you agree not to modify the scripts or ads displayed on the site,” does that make my visit with an ad blocker “unauthorized” under the CFAA?

    How would you “authorize” a user to access assets served by your systems based on what they do with them after they’ve accessed them? That doesn’t logically follow so no, that would not make an ad blocker unauthorized under the CFAA. Especially because you’re not actually taking any steps to deny these people access either.

    AI scrapers on the other hand are a type of users that you’re not authorizing to begin with, and if you’re using CloudFlares bot protection you’re putting into place a system to deny them access. To purposefully circumvent that access would be considered unauthorized.