TIL #Discord effectively does traffic amplification when users post an image. They crawl the image URL using a Discordbot User-Agent, but in the same second request the same URL with a spoofed Mac OS browser User-Agent that can't be identified as a Discord request.
Both request are required for the image to render in Discord chat. Absolutely great!
You use your real name to post online? You use the same phone number, or the same email address to sign up to different accounts? You use the same, or a similar sounding username on your online accounts? You use the same profile picture on your accounts?
Anything that is publicly available is being scraped and indexed by archivists, officials, and private companies.
Do you really think there are no automated tools that connect the dots, let alone investigators being able to manually do this?
Everything you share publicly on the internet is publicly available and will not be forgotten. That includes government agencies, [and] your worst enemies.
This shouldn't be a surprise to anyone, but it repeatedly is. The latest source of outcry is #ShadowDragon, which seems to be a simple #OSINT tool that just collects public posts and makes them available to the feds. Some call this mass surveillance.
Hackers from TU Berlin managed to jailbreak #Tesla cars, unlocking software-locked features worth up to $15,000 🪓🪓🪓
They used a known (unpatchable) voltage fault injection attack against the AMD Secure Processor to glitch the boot process, got root, and retrieved the car's RSA private key 👌
"You can decide for yourself whether downstream rebuilds are valuable for you and it’s your call to make it easy, or not.
Simply rebuilding code, without adding value or changing it in any way, represents a real threat to open source companies everywhere. This is a real threat to open source, and one that has the potential to revert open source back into a hobbyist- and hackers-only activity." #redhat#centos#opensource