7 Matching Annotations
  1. Dec 2024
    1. From DEF CON 32, August 8-11, 2024

      https://defcon.org/html/defcon-32/dc-32-speakers.html#54469

      Abstract

      Pawning countries at top level domain by just buying one specific domain name ‘wpad.tld’, come hear about this more the 25+ years old issue and the research from running eight different wpad.tld domains for more than one year that turn into more the 1+ billion DNS request and more then 600+GB of Apache log data with leaked information from the clients.

      This is the story about how easy it is to just buying one domain and then many hundreds of thousands of Internet clients will get auto pwned without knowing it and start sending traffic to this man-in-the-middle setup there is bypassing encryption and can change content with the ability to get the clients to download harmful content and execute it.

      The talk will explain the technical behind this issue and showcase why and how clients will be trick into this Man-in-the-middle trap.

  2. Jun 2022
    1. The goal is to gain “digital sovereignty.”

      the age of borderless data is ending. What we're seeing is a move to digital sovereignty

  3. Nov 2021
  4. Nov 2020
  5. May 2020
  6. Jan 2017
    1. Almost half of eight- to 11-year-olds have agreed impenetrable terms and conditions to give social media giants such as Facebook and Instagram control over their data, without any accountability, according to the commissioner’s Growing Up Digital taskforce. The year-long study found children regularly signed up to terms including waiving privacy rights and allowing the content they posted to be sold around the world, without reading or understanding their implications.
  7. Sep 2016
    1. A recent Hewlett-Packard printer software update changed the printers so they would not work with third-party ink cartridges. Worse, the change was made as part of a security update.

      https://act.eff.org/action/tell-hp-say-no-to-drm Petition HP to fix this wrongdoing, and promise not to repeat it. They are also being asked to promise not to invoke the DMCA against security researchers who find vulnerabilities in their products.