GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Orca? | ??️‍⚧️ (orca@nya.one)'s status on Tuesday, 25-Feb-2025 22:58:14 JST Orca? | ??️‍⚧️ Orca? | ??️‍⚧️

    公民实验室审计了一下 #小红书 的 app 。
    发现他们在用明文 http 传递用户发布的内容。
    意味着,你连接的 WiFi 热点管理员(比如星巴克)、中国电信、国安国保、入侵网络的攻击者、NSA 不但知道你在刷小红书,还知道你在看的是哪条帖子。
    https://citizenlab.ca/2025/02/network-security-issues-in-rednote/
    https://www.eff.org/deeplinks/2025/02/crimson-memo-analyzing-privacy-impact-xianghongshu-aka-red-note

    5202年了啊,爷,还明文http,你小红书是真的牛逼 :blobcatfrowning::blobcatfrowning::blobcatfrowning:

    RE: https://mastodon.social/users/eff/statuses/114027750205976229

    In conversation Tuesday, 25-Feb-2025 22:58:14 JST from nya.one permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.eff.org
      Crimson Memo: Analyzing the Privacy Impact of Xianghongshu AKA Red Note
      from Cooper Quintin
      Early in January 2025 it seemed like TikTok was on the verge of being banned by the U.S. government. In reaction to this imminent ban, several million people in the United States signed up for a different China-based social network known in the U.S. as RedNote, and in China as Xianghongshu (小红书/...
    2. Domain not in remote thumbnail source whitelist: citizenlab.ca
      Network Security Issues in RedNote
      from Mona Wang
      Our first network security analysis of the popular Chinese social media platform, RedNote, revealed numerous issues with the Android and iOS versions of the app. Most notably, we found that both the Android and iOS versions of RedNote fetch viewed images and videos without any encryption, which enables network eavesdroppers to learn exactly what content users are browsing. We also found a vulnerability in the Android version that enables network attackers to learn the contents of files on users’ devices. We disclosed the vulnerability issues to RedNote, and its vendors NEXTDATA, and MobTech, but did not receive a response from any party. This report underscores the importance of using well-supported encryption implementations, such as transport layer security (TLS). We recommend that users who are highly concerned about network surveillance from any party refrain from using RedNote until these security issues are resolved.
    3. No result found on File_thumbnail lookup.
      Electronic Frontier Foundation (@eff@mastodon.social)
      from Electronic Frontier Foundation
      Citizen Lab released a report that highlights three serious security issues in the RedNote app, including that the app retrieves uploaded user content in a way that allows anyone else on your network, at your ISP, or organizations like the NSA, to see everything you look at and upload to RedNote. https://www.eff.org/deeplinks/2025/02/crimson-memo-analyzing-privacy-impact-xianghongshu-aka-red-note

    Feeds

    • Activity Streams
    • RSS 2.0
    • Atom
    • Help
    • About
    • FAQ
    • TOS
    • Privacy
    • Source
    • Version
    • Contact

    GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

    Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.