1
00:00:00,020 --> 00:00:03,920
This week's surveillance report covers a brutal stretch of Microsoft's vulnerabilities,

2
00:00:04,440 --> 00:00:08,880
so all of you Linux users who've tuned in the last couple weeks can rejoice because it's Microsoft's turn.

3
00:00:09,400 --> 00:00:12,160
There's a supply chain attack wave on open source software.

4
00:00:12,640 --> 00:00:15,280
Signal has threatened to leave Canada over some encryption stuff.

5
00:00:15,760 --> 00:00:19,160
Meta has this new AI-powered technology that targets underage users.

6
00:00:19,640 --> 00:00:23,140
There's definitely some eyebrow raisers for you Bitwarden users listening to this podcast,

7
00:00:23,480 --> 00:00:26,840
plus our usual data breaches, threats, and FOSS updates.

8
00:00:27,380 --> 00:00:29,820
Welcome, everybody, to the Techlore Surveillance Report.

9
00:00:29,980 --> 00:00:34,800
your essential weekly tech news, delivering deep analysis on the latest threats to security,

10
00:00:35,300 --> 00:00:41,100
privacy, and digital freedom, and empowering you to reclaim control and defend your rights.

11
00:00:41,330 --> 00:00:46,940
Now, before I get into the seven Microsoft stories this week, I know, crazy, just a quick

12
00:00:47,050 --> 00:00:50,360
little announcement. I've done a little bit of fresh branding for surveillance reports,

13
00:00:50,450 --> 00:00:54,440
so you might see some from some different stuff. I think it looks fresh. Let me know what you guys

14
00:00:54,580 --> 00:00:59,120
think. All right, now this has been a crazy week for Microsoft. So I just want to kind of set the

15
00:00:59,140 --> 00:01:04,059
seen here, which is the last couple weeks have been quite difficult on the Linux world because

16
00:01:04,080 --> 00:01:09,240
we've had all of these exploits in the Linux side of things. There's a Microsoft Exchange server

17
00:01:09,960 --> 00:01:14,720
spoofing vulnerability. So this occurs when an improper neutralization of input during web page

18
00:01:14,920 --> 00:01:19,520
generation or a cross-site scripting attack enables an attacker to perform spoofing over the network.

19
00:01:20,100 --> 00:01:24,680
All it takes to exploit this is to send a maliciously crafted email, which when opened in

20
00:01:24,620 --> 00:01:29,500
Outlook Web Access can execute arbitrary JavaScript in the context of the browser.

21
00:01:30,040 --> 00:01:35,060
Now, when this was announced, it was actually a zero day that hadn't been patched yet and didn't

22
00:01:35,260 --> 00:01:40,140
make it into Patch Tuesday. At the time of recording, Microsoft has put forward an emergency

23
00:01:40,480 --> 00:01:44,900
mitigation process that they recommend for this critical vulnerability. Now, if that was it for

24
00:01:45,100 --> 00:01:49,500
Microsoft, this wouldn't be the highlight story. So we have a lot more, and these all tie together.

25
00:01:49,780 --> 00:01:57,660
Because last week we talked about how there is a disgruntled security researcher, hacker, zero-day finder.

26
00:01:58,020 --> 00:02:01,940
I don't know what their formal classification is.

27
00:02:02,640 --> 00:02:08,160
But this is chaotic eclipse or nightmare eclipse, again, depending on the time of day.

28
00:02:09,500 --> 00:02:12,620
They delivered on their promise when we talked about this last week.

29
00:02:12,740 --> 00:02:18,960
Because last week they put forward some zero days and they were quite disgruntled about how Microsoft was handling their bug report process.

30
00:02:19,080 --> 00:02:20,920
and they felt like they were wronged by Microsoft.

31
00:02:21,060 --> 00:02:21,660
And so they said,

32
00:02:21,660 --> 00:02:23,740
we're going to keep finding zero days and publishing them.

33
00:02:23,920 --> 00:02:24,960
So this is called Mini Plasma

34
00:02:25,000 --> 00:02:27,040
and it lets attackers gain system privileges

35
00:02:27,320 --> 00:02:29,320
on fully patched Windows systems.

36
00:02:29,700 --> 00:02:31,380
I don't know if they can fully claim

37
00:02:31,760 --> 00:02:35,680
that they were the discoverer slash original author of this

38
00:02:36,260 --> 00:02:38,040
because it's the same exact issue

39
00:02:38,180 --> 00:02:42,320
that was reported to Microsoft by Google Project Zero in 2020,

40
00:02:42,900 --> 00:02:44,440
which is still present unpatched.

41
00:02:44,960 --> 00:02:47,400
In fact, the original proof of concept by Google

42
00:02:47,400 --> 00:02:51,320
worked without any changes, they said. So I think they might have made some changes beyond that

43
00:02:51,500 --> 00:02:55,940
original proof of concept. But the reality is the original proof of concept also still worked from

44
00:02:56,060 --> 00:03:00,220
Google. So Google actually reported this to Microsoft originally, and Microsoft just chose

45
00:03:00,220 --> 00:03:05,120
to ignore it for six years. Now, if you are curious on prevention tips, as always, all of these sources

46
00:03:05,360 --> 00:03:09,260
are in the description. And as you can see on screen, or if you're an audio listener, you can

47
00:03:09,300 --> 00:03:14,200
click into the show notes. There are ways that you can check to see and detect if you've been

48
00:03:14,180 --> 00:03:18,720
exploited by this. But really, all of this is a Trojan horse for the story behind this individual,

49
00:03:19,000 --> 00:03:24,440
right? Like, even Bleeping Computer, I think the lead leads into what's actually going on here,

50
00:03:24,480 --> 00:03:29,340
which is this person, you know, they had Blue Hammer, they had Red Sun, they had Undefend,

51
00:03:29,360 --> 00:03:33,820
they had Yellow Key and Green Plasma, which we covered last week, which was the BitLocker

52
00:03:33,960 --> 00:03:38,920
bypass that we talked about. And now we have Chaotic Eclipse, you know, putting out this

53
00:03:39,120 --> 00:03:42,640
brand new one. And they said, quote, normally, I would go through the process of begging them to

54
00:03:42,640 --> 00:03:47,400
fix a bug. But to summarize, I was told personally by them that they will ruin my life, and they did.

55
00:03:47,680 --> 00:03:52,180
They mopped the floor with me and pulled every childish game they could. It was so bad at some

56
00:03:52,300 --> 00:03:56,300
point. I was wondering if I was dealing with a massive corporation or someone who was just having

57
00:03:56,520 --> 00:04:02,740
fun seeing me suffer. But it seems to be a collective decision. So yeah, I guess this is

58
00:04:03,000 --> 00:04:08,199
very interesting. Personally, on my end, I would love to see kind of like what these communications

59
00:04:08,200 --> 00:04:12,880
looked like and why and how they felt they were wrong. I would be curious to look at it. But yeah,

60
00:04:12,940 --> 00:04:18,140
this person's upset. But that's not even it. Because this last week, there is a very major

61
00:04:18,459 --> 00:04:22,560
event that happens, I believe annually, which is called Pwn2Own, which happens in Berlin.

62
00:04:22,850 --> 00:04:27,240
Pretty much a ton of researchers and hackers get together, and they just try to break things.

63
00:04:27,700 --> 00:04:32,220
And as you could expect, there were a lot of exploits for just common pieces of software.

64
00:04:32,560 --> 00:04:36,440
We have Apple Safari was in here, Red Hat Enterprise Linux for Workstation,

65
00:04:36,760 --> 00:04:41,460
LM Studio, OpenAI Codex, Anthropic Cloud Code, Mozilla Firefox even.

66
00:04:42,060 --> 00:04:46,880
But of course, on that list was Microsoft SharePoint, Microsoft Exchange, Windows 11.

67
00:04:47,160 --> 00:04:51,780
But yeah, that's just one more thing this week that put Microsoft on the map for these vulnerabilities

68
00:04:52,340 --> 00:04:55,220
and potentially some issues in how they're dealing with them.

69
00:04:55,500 --> 00:04:59,100
But that's not all, because yesterday there is a report put out.

70
00:04:59,400 --> 00:05:01,460
It is a sponsored piece from Bleeping Computer.

71
00:05:01,500 --> 00:05:03,400
It's from this company called Beyond Trust.

72
00:05:03,720 --> 00:05:04,600
They did this little report.

73
00:05:04,800 --> 00:05:07,760
pretty much found that Microsoft's vulnerabilities actually fell last year.

74
00:05:08,120 --> 00:05:12,680
The previous year, which I believe is 2024, would have been 1,360 vulnerabilities.

75
00:05:13,040 --> 00:05:15,860
But last year, it was 1,273 vulnerabilities.

76
00:05:16,140 --> 00:05:17,160
So it actually went down.

77
00:05:17,600 --> 00:05:21,100
But the nuance to this is actually the critical vulnerabilities went up.

78
00:05:21,200 --> 00:05:22,660
In 2024, it was 78.

79
00:05:22,940 --> 00:05:25,240
And last year is 157, which is double.

80
00:05:25,620 --> 00:05:27,060
But that's not all.

81
00:05:27,420 --> 00:05:32,700
Because there's another kind of questionable situation that's hard to make sense of.

82
00:05:32,780 --> 00:05:35,500
It's hard to know who's telling the truth or what's going on.

83
00:05:35,720 --> 00:05:39,460
But there was a Microsoft Azure vulnerability that came out.

84
00:05:39,920 --> 00:05:43,160
And a security researcher claims they quietly fixed this,

85
00:05:44,560 --> 00:05:47,700
but they said they never cared and they didn't want to fix it.

86
00:05:47,800 --> 00:05:50,000
So pretty much, this is a bit confusing,

87
00:05:50,380 --> 00:05:52,140
but there was this vulnerability with Microsoft Azure.

88
00:05:52,250 --> 00:05:55,060
This person came forward and they reported the vulnerability.

89
00:05:55,220 --> 00:05:57,340
Microsoft said, this isn't a vulnerability.

90
00:05:57,810 --> 00:05:59,320
We're not going to make any changes to this.

91
00:05:59,690 --> 00:06:01,140
But the researcher came forward and said,

92
00:06:01,320 --> 00:06:03,880
hey, now this requires trusted access to be manually configured,

93
00:06:04,210 --> 00:06:07,700
and this actually fixes the original problem that I put forward.

94
00:06:08,260 --> 00:06:10,040
So the vulnerability appears to have been fixed,

95
00:06:10,200 --> 00:06:12,860
but Microsoft didn't issue a public advisory,

96
00:06:13,200 --> 00:06:14,880
nor did they notify their customers about it.

97
00:06:15,060 --> 00:06:17,640
This one seems a little bit more of a structural problem.

98
00:06:17,810 --> 00:06:20,020
In fact, Bleeping Computer at the end talks about how,

99
00:06:20,210 --> 00:06:22,520
because this didn't get a CVE or an advisory,

100
00:06:23,040 --> 00:06:25,080
there's very little visibility into the exposure window,

101
00:06:25,410 --> 00:06:28,120
and so it's really difficult to actually make sense of these things

102
00:06:28,260 --> 00:06:29,440
and going back and forth with them.

103
00:06:29,580 --> 00:06:36,620
People are complaining and saying that maybe this has to do with AI spamming these bug and security research programs.

104
00:06:36,760 --> 00:06:39,100
And so it's making it harder for companies to keep up with this.

105
00:06:39,220 --> 00:06:48,700
It's really hard to know what's going on, but there does seem to be this overwhelming pattern of companies maybe having shorter fuses for security researchers, which is a problem.

106
00:06:49,160 --> 00:06:52,700
Now, before I get into the takeaways, I did want to say it wasn't all bad news for Microsoft.

107
00:06:52,880 --> 00:06:55,680
This is actually an update from a story we covered a few weeks ago in the podcast,

108
00:06:56,320 --> 00:07:00,040
because we covered how Microsoft Edge is the only Chromium-based browser

109
00:07:00,480 --> 00:07:03,740
that loaded your passwords into your RAM in plain text,

110
00:07:04,080 --> 00:07:06,260
so any other piece of software could have accessed it.

111
00:07:06,360 --> 00:07:10,800
In fact, I even called this directly kind of a lack of care for defense in depth

112
00:07:10,960 --> 00:07:15,800
and thinking about security outside of just what you're maybe responsible for at the bare minimum.

113
00:07:16,340 --> 00:07:19,000
Well, it's kind of cool because Microsoft actually patched this.

114
00:07:19,200 --> 00:07:21,460
I mean, it should have never been an issue in the first place, but they did patch it,

115
00:07:21,540 --> 00:07:22,060
and they said, quote,

116
00:07:22,480 --> 00:07:27,580
This defense and depth change will come to every supported version of Edge, including stable, beta, dev, canary.

117
00:07:27,910 --> 00:07:31,980
With the extended stable channel, our enterprise customers run, and we're prioritizing the rollout.

118
00:07:32,070 --> 00:07:36,420
So they are getting that issue fixed, which is good because, again, I think it was just sloppy and lazy.

119
00:07:36,920 --> 00:07:38,420
And I'm glad they changed their mind on it.

120
00:07:38,600 --> 00:07:41,120
And yeah, they backpedaled, but in a good way.

121
00:07:41,400 --> 00:07:42,900
So there's a lot of stuff going on here, right?

122
00:07:43,000 --> 00:07:44,340
We've been covering these Linux vulnerabilities.

123
00:07:44,800 --> 00:07:51,439
And, you know, just to start off, I think the issue with the Linux vulnerabilities in general is that there's so much just messiness

124
00:07:51,460 --> 00:07:53,460
because you have all these different Linux distributions.

125
00:07:53,740 --> 00:07:55,280
You have the Linux kernel itself,

126
00:07:55,640 --> 00:07:57,920
which has tons of different people who are managing it.

127
00:07:57,920 --> 00:08:00,200
It's not like one person controls the Linux kernel.

128
00:08:00,620 --> 00:08:02,940
And so you have these natural downstream effects

129
00:08:03,040 --> 00:08:04,520
when we get these exploits.

130
00:08:04,600 --> 00:08:06,400
And you have these families of exploits

131
00:08:06,520 --> 00:08:08,280
that are all quite similar in nature,

132
00:08:08,480 --> 00:08:09,620
but they work slightly differently.

133
00:08:09,980 --> 00:08:13,120
And then you have to try to track which distro does what.

134
00:08:13,240 --> 00:08:14,560
And I'm really sorry for you all

135
00:08:14,780 --> 00:08:16,420
because I got some comments.

136
00:08:16,780 --> 00:08:17,540
Some people were like,

137
00:08:17,560 --> 00:08:19,980
Arch hasn't had any public communication about this.

138
00:08:19,980 --> 00:08:21,160
They haven't fixed any of these issues.

139
00:08:21,360 --> 00:08:28,400
But then when I checked their site and I looked for the CV reports on Arch's website, they actually had one or two of them fixed, but maybe not the third one.

140
00:08:28,450 --> 00:08:40,979
And so this puts so much burden on all of you who are just trying to use Linux individually to have to know if you're on patched or unpatched software, which I don't think it should be your responsibility to do that.

141
00:08:41,419 --> 00:08:43,860
And so that is kind of the Linux side of things.

142
00:08:43,969 --> 00:08:48,800
But I think that is, for most people, a fair tradeoff maybe for getting that open ecosystem.

143
00:08:48,820 --> 00:08:56,040
You're running open software, run by people, run by a community, and you don't have to deal with a company that doesn't care about you.

144
00:08:56,050 --> 00:09:05,840
Now, Microsoft is quite unique here because you're actually still getting a lot of that experience, but through a centralized company that should know what the hell they're doing.

145
00:09:06,779 --> 00:09:08,080
Microsoft is coming forward.

146
00:09:08,320 --> 00:09:12,240
They're backpedaling on what they're considering a security issue and what's not a security issue.

147
00:09:12,980 --> 00:09:14,440
They're pissing off researchers.

148
00:09:15,050 --> 00:09:17,620
They are getting caught with all these vulnerabilities left and right.

149
00:09:17,700 --> 00:09:25,300
It seems unclear and it doesn't seem like they internally have a clear process on what they're deciding to prioritize and fix first over something else.

150
00:09:26,140 --> 00:09:27,500
It just seems like a mess back there.

151
00:09:27,820 --> 00:09:39,800
Honestly, you're getting kind of the worst of all worlds right now with Microsoft because I don't think they're really handling these situations in a way that really showcases leadership, that showcases care for users, care for the user experience.

152
00:09:40,300 --> 00:09:44,320
Not that we'd expect anything different given Microsoft's history these last few years.

153
00:09:44,560 --> 00:09:46,700
I mean, everything they do seems to be anti-user.

154
00:09:47,000 --> 00:10:00,880
So this is tough, man. It's really tough to back this up. It's really tough to not look at these situations and make me go, I don't know why someone would put faith in Microsoft right now for this kind of stuff unless they absolutely needed to use Windows operating system.

155
00:10:00,980 --> 00:10:18,160
So that's Microsoft's week. And just to top it off, a couple days ago, there were actually install issues for the security update. Like people were getting errors like insufficient free space, errors 0x70. So even if you have been on top of your updates, apparently people were still having issues installing those security updates.

156
00:10:18,300 --> 00:10:22,820
It's like everything Microsoft has neglected the last five years is finally coming to a

157
00:10:22,980 --> 00:10:23,580
peak right now.

158
00:10:23,710 --> 00:10:29,020
Like all the resources they poured into AI slop that nobody cares about that could have been

159
00:10:29,180 --> 00:10:32,760
directed towards a more polished user experience, fixing update issues, fixing bugs.

160
00:10:33,110 --> 00:10:34,020
They refuse to do.

161
00:10:34,110 --> 00:10:36,440
And now we're kind of seeing what this actually looks like.

162
00:10:36,580 --> 00:10:41,480
And the pieces of duct tape holding this operating system together and everything on top of it

163
00:10:41,820 --> 00:10:43,140
is kind of falling down a little bit.

164
00:10:43,440 --> 00:10:46,860
And it's nice that we can get Linux out of the spotlight and we can put Microsoft back

165
00:10:46,970 --> 00:10:47,620
in that spotlight.

166
00:10:53,880 --> 00:10:57,180
All right, enough about Microsoft for now. I think we have another couple stories about them later,

167
00:10:57,440 --> 00:11:02,880
but let's move on. So we actually have something quite fascinating here, which is a supply chain

168
00:11:03,120 --> 00:11:09,460
campaign. It's a lot of work to break into a piece of software. And that's a lot of time and

169
00:11:09,720 --> 00:11:14,300
investment. And if you're an attacker, you have to put a lot of resources into figuring out an

170
00:11:14,300 --> 00:11:18,380
exploit for something, figuring out the best way to mass exploit it if you're trying to

171
00:11:18,940 --> 00:11:23,620
reach a lot of people. And you have to do that per piece of software. But sometimes we get these

172
00:11:23,820 --> 00:11:26,760
attacks that are a little bit more interesting because what they're going to be doing is they

173
00:11:26,920 --> 00:11:30,880
target the supply chain. So in this case, libraries for charting, graph visualization,

174
00:11:31,260 --> 00:11:35,660
building flowcharts, and mapping. But popular packages outside of that have also been compromised.

175
00:11:35,840 --> 00:11:41,960
So this is called Shai Halud. I don't know how to say that. So it's S-H-A-I-H-U-L-D,

176
00:11:42,920 --> 00:11:46,360
pretty much they've published 639 malicious versions

177
00:11:46,660 --> 00:11:49,660
across 333 packages in about one hour.

178
00:11:50,240 --> 00:11:53,840
So this compromised the NPM account called Atool,

179
00:11:54,160 --> 00:11:55,420
A-T-O-O-L,

180
00:11:55,760 --> 00:11:58,440
which publishes packages in the AntV namespace.

181
00:11:58,700 --> 00:12:02,400
So impacted libraries are things like G2, G6, X6, L7,

182
00:12:02,600 --> 00:12:07,700
G2 Plot, Graphen, TimeAgo.js, SizeSensor, CanvasNest.js,

183
00:12:08,340 --> 00:12:09,900
and it's probably a lot of other random things

184
00:12:10,060 --> 00:12:11,960
that just sound like random mumbo-jumbo.

185
00:12:12,020 --> 00:12:13,760
But I'll talk about why this matters in a second.

186
00:12:14,160 --> 00:12:16,840
So it's targeting developers and their development workflows.

187
00:12:17,400 --> 00:12:22,640
And it's going after things like SSH credentials, database credentials, Docker, vaults, etc.

188
00:12:23,260 --> 00:12:26,600
Now, the good news is that this probably doesn't impact most of you out there.

189
00:12:26,740 --> 00:12:34,900
But if you're a developer, this is something you really should take a look at because you could just accidentally be using this and you don't even know it.

190
00:12:35,100 --> 00:12:41,860
So if you downloaded any of these infected NPM packages, you should remove or downgrade to a known good version before May 18th.

191
00:12:41,940 --> 00:12:44,720
and then revoke and rotate all exposed credentials

192
00:12:44,960 --> 00:12:48,120
because things like SSH keys, et cetera, could be jeopardized.

193
00:12:48,240 --> 00:12:51,780
Now, there is one takeaway that I think does apply to all of you out there.

194
00:12:52,220 --> 00:12:56,220
And I think Bleeping Computer maybe kind of hinted at this,

195
00:12:56,400 --> 00:12:57,900
but TechCrunch was a bit more direct.

196
00:12:58,240 --> 00:13:00,240
Hackers took over the account of one developer

197
00:13:00,320 --> 00:13:01,960
and released all of these packages, right?

198
00:13:02,260 --> 00:13:07,160
So this is just my reminder that regardless of where you get software from,

199
00:13:07,680 --> 00:13:13,960
you typically always have to trust that whoever published the update authorized that update.

200
00:13:14,110 --> 00:13:17,340
So even if you're getting your software from GitHub or even from somebody's website,

201
00:13:18,020 --> 00:13:22,780
there's always that small, slim possibility that maybe their device,

202
00:13:23,000 --> 00:13:29,180
the developer who publishes your software's device was compromised to put out a bad update.

203
00:13:29,250 --> 00:13:33,440
Or maybe they just had weak credentials on their account and somebody logged into their account

204
00:13:33,440 --> 00:13:35,160
and figured out a way to break into their account.

205
00:13:35,480 --> 00:13:40,540
Now, this isn't to just create fear and panic, but it's something that I think everybody should be intentional about and think about.

206
00:13:40,580 --> 00:13:51,480
And I think this is where you might see a place for some kind of middle person to help be an additional point of reference and, you know, someone to validate the update and nothing crazy in it.

207
00:13:51,480 --> 00:14:01,520
Right. This is where we see FDroid's approval process actually really work in favor of you as the user, because when you get crazy things, I think a good example of this is Simple Mobile Tools.

208
00:14:01,640 --> 00:14:08,000
Simple Mobile Tools was this Android ecosystem that's meant to replace the stock apps with open source apps.

209
00:14:08,180 --> 00:14:10,020
And it was very popular on F-Droid.

210
00:14:10,680 --> 00:14:16,420
But they got bought out and they pushed out updates that started including ad and trackers and all these crazy things in there.

211
00:14:16,800 --> 00:14:23,620
And it never made it to the F-Droid store because F-Droid actually takes all the packages, analyzes them, makes sure that they're not doing anything shady.

212
00:14:24,420 --> 00:14:26,140
And then it puts it on the store for you.

213
00:14:26,400 --> 00:14:31,620
This is all to say when you're getting things direct from a developer, there are lots of freedom benefits that come along with that.

214
00:14:31,690 --> 00:14:34,580
And I also get a lot of my software directly from developers as well.

215
00:14:34,900 --> 00:14:39,340
I don't think it's a common issue, but I know some of you might be more sensitive to this kind of stuff.

216
00:14:39,480 --> 00:14:41,740
So I just wanted to shine a light on it.

217
00:14:47,860 --> 00:14:52,760
All right, coming soon, we have Meta to use AI visual analysis to detect underage users.

218
00:14:52,920 --> 00:14:57,060
and we have Bitwarden quietly changing some things that are worrying a lot of people.

219
00:14:57,520 --> 00:15:02,740
But before we get there, I had to just do some digging to find a non-paywalled version of this

220
00:15:02,940 --> 00:15:07,540
article. So you're going to find an archived version in the show notes for this. But Signal

221
00:15:07,740 --> 00:15:12,140
is threatening to pull out of Canada. Now Signal's an open source and an encrypted messenger.

222
00:15:12,600 --> 00:15:17,620
And you might be wondering what the hell's going on. I thought that this is a safe platform. What's

223
00:15:17,760 --> 00:15:22,780
happening? And so let's talk about it. So pretty much Canada has put forward a bill called Bill

224
00:15:22,780 --> 00:15:29,120
22. Now this is being proposed as something called lawful access legislation, which if you listen to

225
00:15:29,160 --> 00:15:35,380
this podcast, you know is a very subtle way of saying we want to access things that are encrypted.

226
00:15:35,670 --> 00:15:39,400
So Signal's vice president pretty much said we would rather pull out of the country than be

227
00:15:39,660 --> 00:15:43,500
compelled to compromise on the privacy promises we have made to our users. Pretty much they're

228
00:15:43,500 --> 00:15:47,260
saying this could threaten encryption. It could also make private messaging services a potential

229
00:15:47,480 --> 00:15:51,640
target for cyber attacks. So this is something that can impact your security as well. When your

230
00:15:51,660 --> 00:15:56,420
encryption is at stake there and there's a way to break it, it makes it possible to break for

231
00:15:56,640 --> 00:16:00,620
everybody. There's no way to selectively break encryption for just one or two people. But it

232
00:16:00,760 --> 00:16:04,500
doesn't just impact messengers because this bill requires telecom providers, internet companies,

233
00:16:04,680 --> 00:16:08,460
and other electronic service providers to make changes to their systems to give surveillance

234
00:16:08,660 --> 00:16:12,580
capabilities to police and the Canadian Security Intelligence Service to combat threats and

235
00:16:12,730 --> 00:16:17,760
criminal activity. I think what's quite interesting about this is these providers specifically like

236
00:16:17,780 --> 00:16:22,860
telecom providers, internet companies, they already collect so much data. And it's already,

237
00:16:23,260 --> 00:16:27,300
based on my understanding, quite easy to access. So I think it's quite interesting how they're

238
00:16:27,360 --> 00:16:31,140
trying to get more. This is one of those situations where sometimes the companies

239
00:16:31,240 --> 00:16:37,200
are on the right side of things, even gasp meta. But Apple and meta have also spoken publicly about

240
00:16:37,360 --> 00:16:42,260
Bill C-22. And they also are saying this is not something we agree with. This could be really bad

241
00:16:42,360 --> 00:16:47,740
for encryption, not just for Canada, but broadly, right? This is forced metadata collection for

242
00:16:47,740 --> 00:16:53,080
messaging apps and could put encryption services in jeopardy because this is, and this is,

243
00:16:53,080 --> 00:16:57,080
they say it right here, encrypted communication systems are a lifeline for human rights defenders,

244
00:16:57,780 --> 00:16:59,480
journalists, and dissidents around the world.

245
00:17:00,200 --> 00:17:01,860
So this is very important stuff.

246
00:17:01,960 --> 00:17:02,940
It's not just about Signal.

247
00:17:02,950 --> 00:17:03,940
It's not just about WhatsApp.

248
00:17:04,069 --> 00:17:04,900
It's not just about this.

249
00:17:05,060 --> 00:17:09,520
It's about your basic right to be able to communicate privately in the digital age,

250
00:17:09,620 --> 00:17:11,380
which still is possible right now, right?

251
00:17:11,560 --> 00:17:15,160
Like when you're using any of these end-to-end encrypted messengers, something like Signal

252
00:17:15,160 --> 00:17:20,600
session, SimpleX, etc. You are actually trying your best to recreate what a private conversation

253
00:17:20,680 --> 00:17:24,839
in your home with your family looks like in the digital era. And the fact that we have developed

254
00:17:24,980 --> 00:17:28,780
that technology is incredible. And the fact that they're trying to poke holes in that,

255
00:17:29,200 --> 00:17:34,460
so that, oh yeah, we'll just poke holes in your door so at any point we can kind of try to listen

256
00:17:34,640 --> 00:17:39,960
in. That's not reassuring. That still makes it less safe. That means anybody can go and try to

257
00:17:40,100 --> 00:17:44,580
listen into your conversations if you have a hole in your wall. And so we need to be very careful

258
00:17:44,580 --> 00:17:48,740
with this. We've seen lots of countries try to come forward and propose these kind of,

259
00:17:49,240 --> 00:17:53,240
they say it's encryption neutral. That's a direct quote from one of the politicians in Canada.

260
00:17:53,240 --> 00:17:59,460
This is encryption neutral. But again, we've talked about this concept that data about data,

261
00:18:00,000 --> 00:18:04,880
aka metadata, is just as important as the encryption itself. So whether or not this

262
00:18:05,060 --> 00:18:09,780
actually targets encryption natively, if it starts requiring more metadata collection from these

263
00:18:09,780 --> 00:18:15,040
services, it's still a huge problem for users. Right now, all Signal collects about its users

264
00:18:15,320 --> 00:18:19,840
is when they first created their account and when they last logged in. And so if now they're forced

265
00:18:19,920 --> 00:18:25,360
to start collecting who's talking to who all the time, at what time, on which devices, from which

266
00:18:25,520 --> 00:18:31,400
IP addresses, now it's really easy to see exactly what's going on inside of this network. And the

267
00:18:31,500 --> 00:18:35,420
bigger kind of global picture of this, if you're not based out of Canada, is that if this starts

268
00:18:35,440 --> 00:18:40,580
getting passed in Canada, it's going to leak into other countries. This is why so many people are

269
00:18:40,720 --> 00:18:45,100
coming forward and going, we need to stop this right now. We just cannot have this become a thing,

270
00:18:45,360 --> 00:18:51,080
right? Like if a big massive, if a major country pushes this forward, gets it through and they get

271
00:18:51,220 --> 00:18:56,000
away with it, now they've set precedent for other countries to follow. And so even if you're not

272
00:18:56,200 --> 00:18:59,960
Canadian, this is a fight that you should still be a part of. Share this around with people you know,

273
00:19:00,280 --> 00:19:03,460
talk about it because a lot of people don't understand the way that these bills are put

274
00:19:03,500 --> 00:19:08,920
forward sound really noble and they sound like they make a lot of sense and it's they they they

275
00:19:09,020 --> 00:19:14,060
cover issues that everybody can get behind like keeping children safe stopping criminals but there

276
00:19:14,120 --> 00:19:21,760
are some very nasty uh side effects that these politicians do or don't intentionally have as part

277
00:19:21,840 --> 00:19:28,000
of those of those bills and those laws all right coming up in just a second we have meta who is

278
00:19:28,180 --> 00:19:33,440
trying to analyze underage people using ai and we also have some questionable things out of bitward

279
00:19:33,460 --> 00:19:51,620
But I quickly wanted to showcase our sponsor. If you've ever looked yourself up on people searching sites and you've seen your home address sitting there for anyone to grab, that is the data broker industry happening behind the scenes. And today's sponsor is really one of the few, if not the only removal service that I actually trust to do something about it. And it's what I personally use, Easy Optouts.

280
00:19:51,820 --> 00:20:20,180
Here's the thing. There's a lot of these services out there that claim to do this, but they are actually consumer reports verified. They ran a four-month study across 13 services, most of them drastically underperformed and really overmarketed what their services can provide. But Easy Optouts tied essentially with Optory, but Easy Optouts does it for an honest price for only $20 a year. For some services, that's what they charge per month. They're a small transparent team. There's no VC backing. The founder is reachable. They don't have a data side hustle funding the cheap pricing.

281
00:20:20,340 --> 00:20:21,860
And they also have business plans.

282
00:20:22,140 --> 00:20:23,320
They're really wonderful to work with.

283
00:20:23,480 --> 00:20:25,380
I genuinely don't have a better recommendation

284
00:20:25,640 --> 00:20:27,320
when people in my life ask me

285
00:20:27,380 --> 00:20:28,520
what they can do about these services

286
00:20:28,720 --> 00:20:29,580
in an automated way

287
00:20:29,600 --> 00:20:31,060
and they don't want to go through the manual route,

288
00:20:31,140 --> 00:20:32,620
which takes a lot of work and maintenance.

289
00:20:33,080 --> 00:20:34,200
I always tell them easy opt-outs.

290
00:20:34,360 --> 00:20:35,460
That's genuinely what I recommend

291
00:20:35,600 --> 00:20:36,360
to my friends and family.

292
00:20:36,640 --> 00:20:37,680
And so if you've been putting off

293
00:20:37,800 --> 00:20:38,640
that data broker cleanup

294
00:20:38,940 --> 00:20:40,220
because the services were too expensive

295
00:20:40,460 --> 00:20:41,280
or too sketchy,

296
00:20:41,360 --> 00:20:43,380
easy opt-out solves kind of both of those issues.

297
00:20:43,720 --> 00:20:44,900
Links are in the show notes

298
00:20:45,000 --> 00:20:45,920
if you want to check them out.

299
00:20:46,200 --> 00:20:47,160
They are a wonderful service

300
00:20:47,340 --> 00:20:48,640
and I wholeheartedly recommend them.

301
00:20:54,620 --> 00:21:01,580
and now back to the show we're going to talk about meta who is continually doing interesting things so

302
00:21:02,140 --> 00:21:06,960
meta is on a mission this is from tudor to ramp up its underage enforcement measures now the way

303
00:21:06,960 --> 00:21:12,420
this works is it analyzes photos and it tries to calculate bone structure height visual cues etc

304
00:21:12,500 --> 00:21:16,280
of every single photo that's published on the platform but they come forward and say this is

305
00:21:16,220 --> 00:21:23,260
not facial recognition. Our AI looks at general themes and visual cues of your face to recognize

306
00:21:23,680 --> 00:21:27,920
what age you might be, but it's not facial recognition. And now, you know, in Meta's defense,

307
00:21:28,020 --> 00:21:32,860
this is actually a downstream impact of something broader, which is age verification, right? We see

308
00:21:32,860 --> 00:21:37,120
this age verification technology put forward by these politicians. We've been covering it nonstop

309
00:21:37,140 --> 00:21:41,920
the last year. It's happening all around the world. And all of these platforms are having to respond

310
00:21:41,920 --> 00:21:45,020
in some way, shape, or form to try to deal with this problem.

311
00:21:45,420 --> 00:21:46,060
And here's the thing.

312
00:21:46,480 --> 00:21:48,200
This is what politicians created.

313
00:21:48,480 --> 00:21:51,820
If I was meta and there is now laws being passed

314
00:21:51,850 --> 00:21:53,540
that would hold me personally liable

315
00:21:53,720 --> 00:21:55,400
if I allowed teens on my platform

316
00:21:55,540 --> 00:21:57,320
that bypassed the age verification checks,

317
00:21:57,460 --> 00:22:00,420
which were also mandated by those same exact politicians,

318
00:22:01,080 --> 00:22:03,320
I would be probably throwing everything I can

319
00:22:03,620 --> 00:22:05,520
to try to make sure that there wasn't a situation

320
00:22:05,760 --> 00:22:06,820
where a kid bypassed it.

321
00:22:06,850 --> 00:22:08,160
And then if something happened to that kid

322
00:22:08,190 --> 00:22:09,420
as a result of my own platform,

323
00:22:09,980 --> 00:22:11,900
now I'm being held legally liable

324
00:22:11,920 --> 00:22:16,580
could be sued for millions of dollars. So I actually see this as a failure of, yes, meta

325
00:22:17,340 --> 00:22:21,660
is being meta. We don't have high expectations for meta. This is just what we'd expect them to do.

326
00:22:22,010 --> 00:22:28,360
But I actually think this is a direct downstream effect, a direct result of what these politicians

327
00:22:28,540 --> 00:22:32,900
have been putting forward as what's designed to keep children safe. They're now introducing more

328
00:22:33,100 --> 00:22:37,900
surveillance technology and they're trying to solve this problem with more technology instead

329
00:22:37,920 --> 00:22:42,180
of just treating it like an actual human problem that it's actually designed to be.

330
00:22:42,500 --> 00:22:47,960
I have serious issues with how we have these kind of ideas of how to keep children safe

331
00:22:48,260 --> 00:22:52,600
online when really what we need to do is create safer environments for children to exist where

332
00:22:52,680 --> 00:22:53,480
they've always existed.

333
00:22:53,590 --> 00:22:57,000
I don't think that this idea of keeping children away from social media platforms is going

334
00:22:57,000 --> 00:22:57,260
to work.

335
00:22:57,380 --> 00:22:58,120
It's where kids are.

336
00:22:58,220 --> 00:22:59,580
It's where we now socialize.

337
00:22:59,640 --> 00:23:00,540
It's where technology is.

338
00:23:00,620 --> 00:23:02,020
This is how we communicate as humans.

339
00:23:02,430 --> 00:23:03,520
And we're penalizing kids.

340
00:23:03,530 --> 00:23:07,880
We're penalizing adults by implementing all these new surveillance technologies when really

341
00:23:07,900 --> 00:23:10,500
What we need to do is tell Meta they can't have addictive platforms.

342
00:23:10,900 --> 00:23:12,240
We need to reel in these algorithms.

343
00:23:12,400 --> 00:23:16,700
We need to actually have real accountability for these companies that know full well that

344
00:23:16,760 --> 00:23:17,420
they're harming children.

345
00:23:17,520 --> 00:23:22,360
We have actual court cases where it's been proven and demonstrated and Meta literally

346
00:23:22,660 --> 00:23:24,080
lost, as well as other big tech companies.

347
00:23:24,660 --> 00:23:28,420
These cases that show that they were exploitive and addictive to kids.

348
00:23:28,780 --> 00:23:33,140
So why we're not regulating that and instead we're just trying to keep children off the

349
00:23:33,280 --> 00:23:36,660
platform and then we're just letting adults join these platforms anyway, which have been

350
00:23:36,660 --> 00:23:37,340
shown to be dangerous?

351
00:23:37,780 --> 00:23:42,560
I don't know. This makes no sense to me. And so yes, Meta is doing this. Meta, of course,

352
00:23:42,660 --> 00:23:46,740
is doing it in a privacy invasive way because they don't care about privacy. But I actually

353
00:23:46,880 --> 00:23:50,040
don't think this is fully their fault. I think the politicians are putting them in a position

354
00:23:50,040 --> 00:23:53,220
where they're like, well, I guess we got to roll out more surveillance technology to deal with

355
00:23:53,230 --> 00:23:57,740
this problem. And I'm convinced the people who are going to actually suffer from all of this

356
00:23:57,960 --> 00:24:01,720
legislation that's being passed, which I think is lazy legislation all around the world, which is

357
00:24:01,720 --> 00:24:05,860
this age assurance technology and this age assurance push, the people who are going to suffer are

358
00:24:05,880 --> 00:24:09,320
going to be you and me and the kids, right? Like we're going to have to deal with all this new

359
00:24:09,420 --> 00:24:12,500
surveillance technology. We're going to have to deal with uploading our ID to these platforms and

360
00:24:12,700 --> 00:24:16,020
trusting that they're going to be handling that safely. We're going to have to deal with this

361
00:24:16,180 --> 00:24:20,400
internet now where you can't just access information and you have to upload your identity in order to

362
00:24:20,640 --> 00:24:24,460
access things. And things aren't just open and public. We're going to have to deal with a world

363
00:24:24,540 --> 00:24:28,040
where if you have children, they're going to have to bug you every 10 minutes just to be able to

364
00:24:28,220 --> 00:24:31,880
tinker online and be able to break things and build things and become engineers someday.

365
00:24:32,540 --> 00:24:38,980
Like, this is the world that we're going to move towards if these politicians don't actually try to fix things from a systemic level.

366
00:24:45,240 --> 00:24:50,080
All right, we have one more story before we get into the data breaches, threats, and the open source updates.

367
00:24:50,330 --> 00:24:56,920
And I guess technically this one's kind of an open source update, but it's a major enough story that I wanted to put it here in the major story section.

368
00:24:57,400 --> 00:24:58,860
But many of you probably use Bitwarden.

369
00:24:58,980 --> 00:24:59,600
It's open source.

370
00:24:59,740 --> 00:25:00,020
It's free.

371
00:25:00,240 --> 00:25:01,020
It's a password manager.

372
00:25:01,360 --> 00:25:02,060
I like them a lot.

373
00:25:02,180 --> 00:25:03,320
Our community likes them a lot.

374
00:25:03,520 --> 00:25:04,600
They're in our resources.

375
00:25:04,780 --> 00:25:08,960
I just had one of their team members on for an interview not that long ago on Techlore Talks,

376
00:25:09,010 --> 00:25:09,980
which is our sister podcast.

377
00:25:10,290 --> 00:25:11,840
If you want to check out that podcast, check it out.

378
00:25:11,850 --> 00:25:13,300
I interview tons of people in the space.

379
00:25:14,240 --> 00:25:16,520
And so this caught a lot of people off guard, including myself.

380
00:25:16,730 --> 00:25:20,200
But there are some interesting flags going up right now from Bitwarden.

381
00:25:20,580 --> 00:25:23,260
First is they've had a quiet shift in leadership and messaging.

382
00:25:23,470 --> 00:25:27,400
Their longtime CEO and CFO stepped down and the company removed,

383
00:25:27,770 --> 00:25:30,380
always free from their prominent password manager page

384
00:25:30,400 --> 00:25:34,420
and replaced inclusion and transparency with innovation and trust.

385
00:25:34,760 --> 00:25:37,260
I think this is really bad timing when all this is happening

386
00:25:37,560 --> 00:25:40,380
because we just had OnePassword do some pricing changes.

387
00:25:40,640 --> 00:25:43,280
OnePassword is a proprietary, very popular password manager,

388
00:25:43,740 --> 00:25:45,560
and they changed all their prices around, right?

389
00:25:46,460 --> 00:25:48,920
And it got a lot of people worked up looking for alternatives,

390
00:25:49,320 --> 00:25:51,220
which were things like Bitwarden.

391
00:25:51,960 --> 00:25:54,600
And so a lot of people, they just inherited this whole community

392
00:25:54,620 --> 00:25:58,220
of people looking to them as kind of this leader

393
00:25:58,220 --> 00:26:01,020
of good quality personal password managers.

394
00:26:01,720 --> 00:26:05,280
And I think this is setting off some alarms, right?

395
00:26:05,520 --> 00:26:07,080
For the record, nothing has happened yet.

396
00:26:07,200 --> 00:26:08,500
No pricing changes have happened.

397
00:26:08,780 --> 00:26:11,900
I don't want us to rush ahead with the speculation,

398
00:26:12,360 --> 00:26:14,320
but I think these are legitimate signals.

399
00:26:14,440 --> 00:26:15,460
They're things to look at.

400
00:26:15,460 --> 00:26:16,640
They're things to watch out for.

401
00:26:16,640 --> 00:26:17,720
For the last several years,

402
00:26:17,900 --> 00:26:19,160
they brought on some VC funding

403
00:26:19,500 --> 00:26:21,320
and people expressed some concern.

404
00:26:22,160 --> 00:26:25,200
And now we kind of see more of those downstream concerns

405
00:26:25,520 --> 00:26:27,340
maybe sprouting, right?

406
00:26:27,400 --> 00:26:33,320
The seeds of doubt have maybe begun to sprout just a little bit, and we can start to see what the direction of this company looks like in the future.

407
00:26:33,620 --> 00:26:35,040
So I'm curious to watch.

408
00:26:35,080 --> 00:26:38,560
I really hope that they still stay very pro end user.

409
00:26:38,920 --> 00:26:40,040
They still keep their free plan.

410
00:26:40,120 --> 00:26:41,480
They still remain a good option.

411
00:26:41,640 --> 00:26:44,940
We need to have accessible free password managers for people, right?

412
00:26:45,440 --> 00:26:52,920
Otherwise, people are just going to stay with Apple passwords or their browser's password manager, and we're going to run out of options for people to get started and dip their toes into password management.

413
00:26:52,980 --> 00:26:57,340
I don't think everybody should just be using the Bitwarden free plan, but I think the Bitwarden

414
00:26:57,480 --> 00:27:01,580
free plan was a really, really good entryway for a lot of people to start using their first

415
00:27:01,700 --> 00:27:05,680
password manager, realize, oh, I actually want some more of the paid features. And then now

416
00:27:05,690 --> 00:27:09,340
they're using password managers. And down the road, they might use KeyPass, they might use ProtonPass,

417
00:27:09,500 --> 00:27:14,580
whatever. And so if this goes a negative direction, this could be a big loss. So I'm going to be

418
00:27:14,760 --> 00:27:18,500
watching this closely. I'm really curious for your guys' thoughts, especially if you're Bitwarden

419
00:27:18,680 --> 00:27:22,480
users. I know a lot of you listening to this podcast use Bitwarden. So let me know what you

420
00:27:22,460 --> 00:27:27,020
think in the comments, whether that's on Spotify or YouTube or wherever you can leave comments

421
00:27:27,240 --> 00:27:38,120
nowadays. And we can dive into the defense bulletin. Again, last week, we started a new system

422
00:27:38,570 --> 00:27:42,840
where the defense bulletin has three sections. We have the data breaches, we have the threats,

423
00:27:43,040 --> 00:27:47,420
and then we have the open source updates, the open source, the FOSS section, which you all asked for.

424
00:27:47,480 --> 00:27:54,280
So I will say too, being back here, I got a lot of comments from the last several months

425
00:27:54,940 --> 00:27:56,860
that people wanted the FOSS section back.

426
00:27:56,920 --> 00:28:00,100
And so when I added it back, I was like, man, people are going to be really excited for this.

427
00:28:00,100 --> 00:28:01,700
I don't think I saw a single comment about it.

428
00:28:01,940 --> 00:28:03,100
And so that made me a little sad.

429
00:28:03,320 --> 00:28:05,820
It's also helpful to know if you guys actually liked something too,

430
00:28:06,000 --> 00:28:06,960
because then I know if it worked.

431
00:28:07,220 --> 00:28:11,400
Otherwise, I'm like, was it just three people complaining for a few months and no one actually cares?

432
00:28:11,700 --> 00:28:12,560
So let me know.

433
00:28:12,800 --> 00:28:14,600
I'd be curious if you guys actually liked the new system.

434
00:28:15,140 --> 00:28:23,200
Now, we're going to start with New York City Health and Hospitals that say that hackers stole medical data and fingerprints during a breach affecting at least 1.8 million people.

435
00:28:23,800 --> 00:28:33,700
And so if you're part of this NYCHHC, which is a public health system in the U.S., make sure to look into this to see if you were impacted and what your next steps are.

436
00:28:34,240 --> 00:28:39,760
We also had a hotel check-in system that left a million passports and driver's licenses open for anyone to see.

437
00:28:40,080 --> 00:28:43,600
This is through a company called Tabiq, T-A-B-I-Q.

438
00:28:43,920 --> 00:28:45,240
It's a Japan-based tech startup.

439
00:28:45,640 --> 00:28:49,360
And pretty much they found that any hotel using this system was exposed.

440
00:28:49,600 --> 00:28:51,280
And we actually haven't seen this in a long time,

441
00:28:51,340 --> 00:28:55,060
but it's because it was a publicly available Amazon storage bucket.

442
00:28:55,360 --> 00:28:57,560
So this used to be a common joke on the podcast.

443
00:28:57,780 --> 00:29:00,800
When Nate was on the podcast, we would do this whole thing of like take a shot

444
00:29:01,120 --> 00:29:03,860
because these were like three times a week types of stories

445
00:29:04,060 --> 00:29:06,760
where it was an Amazon storage bucket that was publicly exposed.

446
00:29:06,980 --> 00:29:08,260
So I haven't seen one of these in a while,

447
00:29:08,420 --> 00:29:11,220
But it's good to have a little throwback to the good old days.

448
00:29:11,600 --> 00:29:15,080
All right, 7-Eleven has confirmed a data breach claimed by the Shiny Hunters gang.

449
00:29:15,600 --> 00:29:18,780
This is a convenience store here, at least in the U.S.

450
00:29:19,080 --> 00:29:21,840
Oh, but it says 86,000 stores globally, so it's not just the U.S.

451
00:29:22,060 --> 00:29:25,280
Now, they sent breach notifications to affected individuals on May 1st.

452
00:29:25,360 --> 00:29:28,060
And so you probably already heard about this if it happened to you.

453
00:29:28,300 --> 00:29:31,240
And if you do think you might be caught in this breach, definitely check out the show notes.

454
00:29:31,540 --> 00:29:32,400
We have three more data breaches.

455
00:29:32,540 --> 00:29:36,200
The first is from West Pharmaceutical Services that disclosed it was a target of a cyber attack

456
00:29:36,220 --> 00:29:38,780
that resulted in data exfiltration and system encryption.

457
00:29:39,170 --> 00:29:40,040
It was on May 4th.

458
00:29:40,100 --> 00:29:42,360
And there's actually very little information about this so far.

459
00:29:42,520 --> 00:29:45,280
They're currently doing investigations and stuff.

460
00:29:45,330 --> 00:29:47,740
So make sure to stay subscribed and we might have updates for you.

461
00:29:48,080 --> 00:29:49,860
This next story was interesting.

462
00:29:50,660 --> 00:29:54,120
I'm trying my best to make sense of it.

463
00:29:54,570 --> 00:29:57,420
But there's an open source tool called Grafana Labs.

464
00:29:57,640 --> 00:29:59,480
Grafana Labs. Grafana Labs.

465
00:29:59,840 --> 00:30:00,740
I'm going to say Grafana Labs.

466
00:30:01,080 --> 00:30:02,000
It's an open source tool.

467
00:30:02,380 --> 00:30:06,000
But apparently some attacker attempted to blackmail them.

468
00:30:06,920 --> 00:30:09,640
demanding payment to prevent the release of their code base.

469
00:30:10,900 --> 00:30:11,860
But again, they're open source.

470
00:30:12,070 --> 00:30:13,620
So the code is open source and public.

471
00:30:13,980 --> 00:30:16,220
They compromise their GitHub environment.

472
00:30:16,470 --> 00:30:19,420
And so I'm a little bit lost on the downstream impacts of this.

473
00:30:20,200 --> 00:30:21,740
The company said they invalidated a token,

474
00:30:22,110 --> 00:30:24,560
added additional security measures, and I think that's it.

475
00:30:24,720 --> 00:30:26,420
So this was kind of a silly thing, I think,

476
00:30:26,520 --> 00:30:27,600
for maybe the attacker as a target,

477
00:30:27,670 --> 00:30:30,100
or maybe they did something silly once they broke into it.

478
00:30:30,220 --> 00:30:31,960
But I just thought it was an interesting story

479
00:30:32,010 --> 00:30:33,060
and I wanted to share it along.

480
00:30:33,420 --> 00:30:37,920
And up next, this is the headline from Ars Technica, not from me, but it's called,

481
00:30:38,050 --> 00:30:43,060
In Stunning Display of Stupid, Secret Siza Credentials Found in Public GitHub Repo.

482
00:30:43,420 --> 00:30:48,780
This repo is called Private Siza, which included plain text passwords, SSH private keys, tokens,

483
00:30:49,020 --> 00:30:50,920
and other sensitive Siza assets.

484
00:30:51,480 --> 00:30:53,500
And it was just available publicly.

485
00:30:54,020 --> 00:30:56,340
And they pretty much said it's not the first time Siza screwed up.

486
00:30:56,680 --> 00:30:58,180
It's not even the first time this year.

487
00:30:58,700 --> 00:31:01,720
And they cover a lot of your other stories from Siza messing up.

488
00:31:01,800 --> 00:31:03,500
So pretty embarrassing, actually.

489
00:31:03,670 --> 00:31:05,440
I would be quite embarrassed if I was Siza right now.

490
00:31:05,660 --> 00:31:07,340
If you use WordPress, there's a new plugin.

491
00:31:07,600 --> 00:31:11,600
We see these quite frequently, but it's called Burst Statistics, and there's a vulnerability

492
00:31:11,940 --> 00:31:12,020
there.

493
00:31:12,050 --> 00:31:15,500
So if you're using it on your WordPress site, make sure to look into this.

494
00:31:16,080 --> 00:31:20,220
We also have a plugin called Funnel Builder, which is also a WordPress thing, and that also

495
00:31:20,360 --> 00:31:22,660
had a vulnerability that you should try to patch up.

496
00:31:23,200 --> 00:31:28,260
But that's not at all, because we have a third one called Avada Builder, which is also a

497
00:31:28,480 --> 00:31:31,400
plugin for WordPress, and that is something else that you should look into.

498
00:31:31,520 --> 00:31:36,780
Earlier in the podcast, I talked about how there's a lot of trust in the software that's pushed to your devices.

499
00:31:37,280 --> 00:31:40,280
And at any point, someone could jeopardize a developer's account.

500
00:31:40,900 --> 00:31:42,500
Well, here's a good example of that.

501
00:31:42,640 --> 00:31:44,440
Because there's the Wii U emulator called Simu.

502
00:31:44,840 --> 00:31:46,540
And they hit version 2.6.

503
00:31:46,860 --> 00:31:52,000
But the Linux version was compromised by a Russian threat actor for literally a whole week.

504
00:31:52,320 --> 00:31:54,820
This was their AppImage and Ubuntu zip assets.

505
00:31:55,160 --> 00:32:00,260
And any of you who ran these Linux binaries between May 6th and May 12th,

506
00:32:00,300 --> 00:32:03,000
They literally recommend a clean operating system install.

507
00:32:03,210 --> 00:32:08,760
At minimum, delete the compromised binaries and reset all passwords, GitHub tokens, SSH keys, and any other credentials.

508
00:32:08,950 --> 00:32:12,380
But honestly, you should just reinstall your operating system.

509
00:32:12,820 --> 00:32:15,980
There are some more instructions here on mitigations, but this is really bad.

510
00:32:15,980 --> 00:32:19,200
And again, it's a reminder that you really need to trust where you're getting your software from.

511
00:32:19,560 --> 00:32:23,920
There was another vulnerability in NGINX, which pretty much allowed a DOS attack.

512
00:32:24,050 --> 00:32:25,540
And it's a potential RCE.

513
00:32:25,760 --> 00:32:28,240
It's a remote code execution from a very old vulnerability.

514
00:32:28,900 --> 00:32:30,760
So if you want to learn more about that, check out the show notes.

515
00:32:31,220 --> 00:32:33,440
This is a quick signal boost for a story from Wired,

516
00:32:33,560 --> 00:32:35,880
which talks about this underground ecosystem

517
00:32:36,220 --> 00:32:38,720
where criminals are trying to break into iPhones

518
00:32:39,180 --> 00:32:41,640
and then they do phishing attacks against the people's contacts

519
00:32:41,960 --> 00:32:45,320
from those unlocked devices to get access to bank accounts, more, etc.

520
00:32:45,900 --> 00:32:47,340
And so this has to do with stolen iPhones.

521
00:32:47,560 --> 00:32:50,520
This is more of a real-world attack where your device gets stolen

522
00:32:51,400 --> 00:32:52,920
and then bad things happen.

523
00:32:53,000 --> 00:32:54,380
And so if you want to learn more about this,

524
00:32:54,700 --> 00:32:56,940
it didn't quite make a major story this week,

525
00:32:57,020 --> 00:32:58,760
but I wanted to still call attention to it.

526
00:32:58,860 --> 00:33:00,200
So you can find more in the show notes.

527
00:33:00,800 --> 00:33:04,960
Interpol had Operation Rams, which has seized 53 malware and phishing servers.

528
00:33:05,320 --> 00:33:07,920
This also included 200 individuals who were arrested.

529
00:33:08,010 --> 00:33:12,640
And so if you want to keep up with more of the law enforcement side of things, check out the show notes.

530
00:33:13,420 --> 00:33:18,900
FBI is now seeking $36 million for nationwide access to automated license plate reader data.

531
00:33:19,260 --> 00:33:23,980
It seems like they're very much targeting Flock or similar companies here for that kind of technology.

532
00:33:24,110 --> 00:33:26,960
So it's more of a signal boost for that what's going on.

533
00:33:27,100 --> 00:33:32,560
And these last three stories in the threat section before we get into the open source section actually has to do with macOS.

534
00:33:33,140 --> 00:33:38,580
So the first one is from Anthropics Mythos, which has helped build a working macOS exploit in five days.

535
00:33:39,020 --> 00:33:43,580
Now, this vulnerability runs a command as a standard user to gain root administrator access to the machine.

536
00:33:43,810 --> 00:33:49,440
There isn't that much information on this attack because they're waiting for Apple to ship the fix for this first.

537
00:33:49,820 --> 00:33:52,340
So maybe we're going to learn more as that comes out.

538
00:33:52,420 --> 00:33:57,740
But that wasn't the only thing because there was a macOS Info Stealer variant, which spoofs Apple security updates.

539
00:33:58,240 --> 00:34:06,360
Pretty much there's a malicious Apple script you download, you run it, and then it tries to pretty much fake you out into downloading an update that you don't need that is malicious.

540
00:34:06,540 --> 00:34:09,340
And so if you want to learn more about this, check out the show notes.

541
00:34:09,500 --> 00:34:14,060
This is something you have to intentionally install, but some people might accidentally do it.

542
00:34:14,139 --> 00:34:14,879
That's what they're counting on.

543
00:34:15,159 --> 00:34:19,760
And the last thread of the week, which also impacts macOS, comes from Misk, who does a lot of security research.

544
00:34:20,120 --> 00:34:21,580
and this is a critical vulnerability.

545
00:34:21,970 --> 00:34:24,940
And they actually break macOS app sandboxing data containers

546
00:34:25,980 --> 00:34:27,220
using archive utility.

547
00:34:27,740 --> 00:34:28,419
For those who don't know,

548
00:34:28,580 --> 00:34:30,860
this is the default compression utility in macOS.

549
00:34:30,940 --> 00:34:31,720
If you ever click compress

550
00:34:31,970 --> 00:34:33,659
or you uncompress something in macOS,

551
00:34:33,720 --> 00:34:34,659
you are actually using this.

552
00:34:34,710 --> 00:34:36,740
So a lot of people don't even realize they're using it.

553
00:34:36,879 --> 00:34:38,840
The summary that they put here for non-technical readers,

554
00:34:39,020 --> 00:34:40,220
which I'm just going to read out,

555
00:34:40,340 --> 00:34:41,760
and it's a really nice feature of this,

556
00:34:41,889 --> 00:34:42,600
the way they wrote this.

557
00:34:42,610 --> 00:34:43,639
I wish more people did that.

558
00:34:43,980 --> 00:34:46,480
They found a security issue in macOS 26.4.

559
00:34:47,080 --> 00:34:48,579
If they trick you into running their code

560
00:34:48,600 --> 00:34:50,300
and dragging and dropping one specific file.

561
00:34:50,330 --> 00:34:51,620
They can read private app data,

562
00:34:52,220 --> 00:34:54,020
including notes, messages, WhatsApp, or Safari.

563
00:34:54,220 --> 00:34:56,379
They can access files in place you expect to be private,

564
00:34:56,560 --> 00:34:58,720
such as your desktop, documents, folders, etc.

565
00:34:59,400 --> 00:35:01,060
And they can secretly replace trusted apps

566
00:35:01,090 --> 00:35:02,960
you already have installed with malicious versions.

567
00:35:03,460 --> 00:35:05,200
All this can happen without your Mac's password

568
00:35:05,230 --> 00:35:06,180
or any special approval.

569
00:35:06,590 --> 00:35:08,880
The attack bypasses macOS security protections

570
00:35:08,970 --> 00:35:10,280
by taking advantage of a bug

571
00:35:10,350 --> 00:35:11,940
in the macOS built-in archive utility.

572
00:35:12,460 --> 00:35:13,980
So if you want to learn more about how this works,

573
00:35:14,050 --> 00:35:17,240
the app sandbox, how this works under the hood,

574
00:35:17,720 --> 00:35:21,440
definitely check out the show notes. We couldn't really cover it with the time restrictions today,

575
00:35:21,880 --> 00:35:26,100
but it's a really interesting attack. Okay, without further ado, we are in the open source

576
00:35:26,620 --> 00:35:31,160
section. So let's talk about it. I want to start by showcasing the Free Software Foundation of

577
00:35:31,250 --> 00:35:34,920
Europe. They just put out an article about the DMA, which is the Digital Markets Act.

578
00:35:35,240 --> 00:35:40,200
This is pretty much them going after these big tech providers who are trying to control the

579
00:35:40,370 --> 00:35:44,439
internet. They are now intervening against Apple before European Court of Justice for the second

580
00:35:44,440 --> 00:35:49,060
time, pretty much trying to say, hey, Apple isn't actually complying with the DMA. They are still

581
00:35:49,400 --> 00:35:53,720
challenging interoperability. And they're saying, quote, this case is one of the major judicial tests

582
00:35:53,810 --> 00:35:58,880
of the EU's interoperability obligations under the DMA. This law aims at preventing large technology

583
00:35:59,020 --> 00:36:02,880
companies from unfairly locking out competitors. The Free Software Foundation of Europe seeks to

584
00:36:03,100 --> 00:36:08,160
enforce the DMA in a free software developer friendly way. But the idea here is Europe wants

585
00:36:08,440 --> 00:36:12,299
small players to be able to compete against big tech players because Apple does things like not

586
00:36:12,320 --> 00:36:16,480
letting people use third-party app stores. Apple does things like not allowing you to use a third-party

587
00:36:16,660 --> 00:36:21,380
browser engine. Apple does things like making everybody use the Lightning port. It's all of

588
00:36:21,500 --> 00:36:25,620
these things that Europe tried to push on and say, hey, you can't do that. We need to be using standards

589
00:36:26,140 --> 00:36:30,400
and we need to actually allow things to be properly competitive. The problem is that Apple isn't

590
00:36:30,600 --> 00:36:34,640
actually complying with these in a way that the Free Software Foundation of Europe thinks is

591
00:36:35,180 --> 00:36:38,220
actually complying. They don't think they're complying with the law. If you want to learn

592
00:36:38,260 --> 00:36:42,280
more about this, I've actually had three different people from the Free Software Foundation of Europe

593
00:36:42,300 --> 00:36:44,340
on Techlore Talks, again, our sister podcast.

594
00:36:44,830 --> 00:36:47,100
So if you want to learn more about this whole saga specifically,

595
00:36:47,370 --> 00:36:49,480
they cover a lot more of this in those interviews.

596
00:36:50,480 --> 00:36:54,120
Up next, Tor Browser released version 15.0.14.

597
00:36:54,820 --> 00:36:58,300
It includes some bug fixes and some basic updates, nothing too major.

598
00:36:58,900 --> 00:37:01,880
But Firefox itself had a pretty big week.

599
00:37:01,930 --> 00:37:05,780
So Firefox 151 includes VPN location selection.

600
00:37:05,990 --> 00:37:09,640
So when I did my review, which I'll leave a card here and also in a description,

601
00:37:10,300 --> 00:37:12,180
I did a review of Firefox's new VPN.

602
00:37:12,390 --> 00:37:13,680
And one of the things I even talked about

603
00:37:13,820 --> 00:37:15,400
is it doesn't even tell you which location you're in.

604
00:37:15,740 --> 00:37:17,960
So now they actually let you choose a VPN location

605
00:37:18,400 --> 00:37:20,040
by country, it looks like, which is incredible.

606
00:37:20,340 --> 00:37:22,820
And you can see it, which is also great.

607
00:37:23,320 --> 00:37:24,580
You also have your AI controls

608
00:37:24,650 --> 00:37:25,740
that are going to be in mobile now.

609
00:37:25,750 --> 00:37:27,420
If you don't want to deal with AI at all,

610
00:37:27,470 --> 00:37:28,920
you can just toggle them all off

611
00:37:29,040 --> 00:37:30,920
or you can enable the specific things you want.

612
00:37:31,360 --> 00:37:34,700
They're also getting Shake to summarize on Android devices,

613
00:37:35,020 --> 00:37:36,400
which they say is a favorite feature.

614
00:37:36,610 --> 00:37:37,560
Pretty much if you're on a page,

615
00:37:37,560 --> 00:37:39,720
you just shake your phone and it summarizes the page.

616
00:37:40,220 --> 00:37:41,940
and they're bringing that to Android devices.

617
00:37:42,450 --> 00:37:45,900
And apparently Nightly includes a redesign of the settings page.

618
00:37:46,110 --> 00:37:48,080
So that is pretty exciting stuff.

619
00:37:48,500 --> 00:37:51,360
Then when we move over to Discord, this is not open source news.

620
00:37:51,470 --> 00:37:54,280
Again, I said open source and like open source adjacent.

621
00:37:55,000 --> 00:37:57,080
Discord is not open source at all.

622
00:37:57,590 --> 00:38:01,400
But I did still think that a lot of people in the open source community are on Discord.

623
00:38:01,720 --> 00:38:04,760
In fact, lots of open source projects host their communities on Discord.

624
00:38:04,830 --> 00:38:06,240
So I still wanted to showcase this.

625
00:38:06,660 --> 00:38:10,400
but they are rolling out end-to-end encryption by default for all voice and video calls.

626
00:38:10,710 --> 00:38:14,680
I think this is a really good move forward for just a basic privacy, basic security for users.

627
00:38:15,160 --> 00:38:16,140
I'm a big fan of this.

628
00:38:16,500 --> 00:38:17,700
No, it's not going to be signal.

629
00:38:17,830 --> 00:38:18,840
No, it's not going to be session.

630
00:38:19,140 --> 00:38:20,800
No, it's not going to be absolute privacy.

631
00:38:21,170 --> 00:38:24,480
But this is one step forward, and it also helps normalize encryption,

632
00:38:24,960 --> 00:38:28,460
which is really important when we zoom out at all these legal attacks against encryption.

633
00:38:28,880 --> 00:38:33,620
We also had a stunning, I guess, alternative to the highlight story this week,

634
00:38:33,720 --> 00:38:37,600
which is Microsoft is doing its first server Linux distribution

635
00:38:38,580 --> 00:38:40,280
called Azure Linux 4.0.

636
00:38:41,040 --> 00:38:43,620
It's immutable, and they are...

637
00:38:45,000 --> 00:38:46,100
Yeah, that's it.

638
00:38:46,130 --> 00:38:47,260
If you want to learn more about it,

639
00:38:47,660 --> 00:38:48,960
it's actually based on Fedora Linux,

640
00:38:49,420 --> 00:38:51,400
and it's an open distribution on GitHub.

641
00:38:51,570 --> 00:38:53,700
You can literally see it on the screen

642
00:38:53,870 --> 00:38:54,960
after it's done loading here.

643
00:38:55,480 --> 00:38:58,000
But yes, Microsoft has a GitHub repo,

644
00:38:58,360 --> 00:38:59,500
and it's called Azure Linux,

645
00:39:00,340 --> 00:39:01,360
and they have a Linux distribution.

646
00:39:01,720 --> 00:39:03,560
So if you want to learn more about this, check it out.

647
00:39:03,680 --> 00:39:04,440
It's quite fascinating.

648
00:39:04,800 --> 00:39:07,240
All right, this next update actually has me really excited

649
00:39:07,380 --> 00:39:10,080
because it addresses what I've been kind of alluding to

650
00:39:10,700 --> 00:39:12,680
in the last couple of Surveillance Supports episodes,

651
00:39:13,040 --> 00:39:14,820
which is, and even earlier in this one,

652
00:39:14,900 --> 00:39:17,900
which is it's very hard to consistently patch things

653
00:39:18,060 --> 00:39:19,400
on the Linux side of things, right?

654
00:39:19,460 --> 00:39:21,540
You have every distro doing its own thing.

655
00:39:21,760 --> 00:39:24,040
And I really appreciate this leadership from Rocky Linux.

656
00:39:24,280 --> 00:39:25,520
So Rocky Linux came forward

657
00:39:26,120 --> 00:39:28,060
and now they introduced a security repository.

658
00:39:28,840 --> 00:39:31,420
And they specifically cite copyfail and dirtyfrag

659
00:39:31,440 --> 00:39:33,780
as reasons for why they did this.

660
00:39:33,920 --> 00:39:36,780
So that is directly in this article here on their website.

661
00:39:37,150 --> 00:39:39,440
These were serious local privilege escalation vulnerabilities

662
00:39:39,860 --> 00:39:42,420
with public proof-of-concept exploits already in the wild.

663
00:39:42,920 --> 00:39:45,880
Both arrived upstream, which had fixes broadly available,

664
00:39:46,360 --> 00:39:50,660
and both put Rocky Linux administrators in a position no one wants to be in,

665
00:39:50,820 --> 00:39:53,740
which is they're aware of the risk, aware of the exploit, and just waiting.

666
00:39:54,180 --> 00:39:57,240
And that is exactly kind of the predicament that a lot of you communicated

667
00:39:57,310 --> 00:39:59,300
in the comments from these last few videos.

668
00:39:59,540 --> 00:40:03,620
Now, this does target more developers, people running servers, not necessarily end users,

669
00:40:03,860 --> 00:40:06,060
but the next vulnerability could be an end user.

670
00:40:06,400 --> 00:40:11,600
They have launched the Rocky Linux Security Repository, which is an optional opt-in repository

671
00:40:11,860 --> 00:40:18,500
that gives them a path to ship urgent security fixes ahead of upstream when circumstances genuinely demand it.

672
00:40:18,860 --> 00:40:24,880
This changes nothing if you don't opt into it, but if you do opt into it, you can actually receive these updates a lot quicker.

673
00:40:25,260 --> 00:40:26,760
And they actually already cite that this worked.

674
00:40:27,140 --> 00:40:29,100
they already pushed out some of these updates

675
00:40:29,480 --> 00:40:31,700
and they were able to bridge the gap

676
00:40:31,940 --> 00:40:33,440
while Upstream got their fix out.

677
00:40:33,580 --> 00:40:37,300
And so if you are a developer, administrator, et cetera,

678
00:40:37,620 --> 00:40:38,560
this is something to look into.

679
00:40:38,680 --> 00:40:41,860
And actually, I would love to see more of this.

680
00:40:42,040 --> 00:40:43,600
I just love that they put this forward.

681
00:40:44,060 --> 00:40:46,540
All right, the last story of the week is from Organic Maps.

682
00:40:46,680 --> 00:40:48,200
They have brought transit line highlights,

683
00:40:48,800 --> 00:40:50,960
cleaner bookmark labels, and a more legible map.

684
00:40:50,980 --> 00:40:52,640
And so if you are an Organic Maps user

685
00:40:52,840 --> 00:40:54,400
and you're trying to get away from Google or Apple,

686
00:40:55,340 --> 00:40:56,620
this is an update for you all.

687
00:40:56,940 --> 00:40:58,460
That is going to conclude the week.

688
00:40:58,780 --> 00:41:00,420
If this analysis helped you reclaim control,

689
00:41:00,860 --> 00:41:02,640
become a Techlorian by visiting the show notes

690
00:41:02,710 --> 00:41:03,280
in the description.

691
00:41:03,460 --> 00:41:04,500
It's a great way to support us.

692
00:41:04,500 --> 00:41:06,040
You get access to our private signal group.

693
00:41:06,090 --> 00:41:07,960
You get access to my private RSS feed

694
00:41:07,970 --> 00:41:09,380
so you can keep up with all these stories

695
00:41:09,660 --> 00:41:12,160
as they happen throughout the week in your RSS.

696
00:41:12,540 --> 00:41:13,660
You can also join the newsletter

697
00:41:13,710 --> 00:41:15,760
and get a written version of this surveillance support.

698
00:41:15,860 --> 00:41:16,660
It's completely free.

699
00:41:16,900 --> 00:41:17,760
There's no spam or anything.

700
00:41:18,040 --> 00:41:20,340
It's just a weekly written version if you prefer that.

701
00:41:20,580 --> 00:41:21,060
Other than that,

702
00:41:21,070 --> 00:41:23,140
I would really like to ask everybody to leave a rating,

703
00:41:23,500 --> 00:41:25,080
support this podcast in any way they can.

704
00:41:25,090 --> 00:41:26,240
It doesn't have to be financial.

705
00:41:26,720 --> 00:41:29,240
I see all your Apple podcast reviews and they mean a lot.

706
00:41:29,270 --> 00:41:30,460
And so if you're listening to Apple,

707
00:41:30,810 --> 00:41:32,760
it takes about five seconds to just scroll down

708
00:41:32,790 --> 00:41:33,960
and leave a rating on a podcast

709
00:41:34,150 --> 00:41:35,640
and it makes a big difference for Discovery.

710
00:41:36,160 --> 00:41:37,400
You can do the same thing on Spotify.

711
00:41:37,790 --> 00:41:38,720
You can share the episode.

712
00:41:39,300 --> 00:41:42,000
You can really just keep tuning in as well.

713
00:41:42,140 --> 00:41:44,240
Like whatever you can do to give back to this podcast

714
00:41:44,540 --> 00:41:45,480
is really appreciated.

715
00:41:46,020 --> 00:41:46,700
Thank you all for listening

716
00:41:46,850 --> 00:41:48,880
and I'll see you in the next episode of Surveillance Report.

717
00:41:49,240 --> 00:41:50,080
Stay safe out there.