soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin email
social@octade.net

Search results for tag #security

[?]Freezenet » 🌐
@freezenet@noc.social

History Repeats Itself: UK Age Verification Law Fails

Under age teens are once again circumventing the age gates on a massive scale, causing the UK age verification laws to catastrophically fail.

freezenet.ca/history-repeats-i

    [?]PrivacyDigest » 🌐
    @PrivacyDigest@mas.to

    It's official: is the U.S. state closest to - Yahoo Tech

    When Utah's Senate Bill 73 goes into force on May 6, websites subject to the state's age verification law will be legally barred from explaining how to use a to get around age . They'll also be liable for enforcing age for any user within Utah's physical borders — regardless of their apparent virtual location.

    tech.yahoo.com/vpn/article/its

      [?]PrivacyDigest » 🌐
      @PrivacyDigest@mas.to

      [?]PrivacyDigest » 🌐
      @PrivacyDigest@mas.to

      Shut Down Turnkey

      William Binney, the architect-turned-whistleblower, called it the "turnkey state." Whoever sits in power gains access to a boundless surveillance empire that scorns and crushes . Politicians will come and go, but you can help us claw the tools of oppression out of government hands.

      eff.org/deeplinks/2026/04/claw

        [?]Jesus Michał von Gentoo 🏔 (he) » 🌐
        @mgorny@social.treehouse.systems

        library (yes, the one that criticizes everything and everyone) is now vibecoded. Our future is truly bright!

        Noticed because apparently "Claude" wrote a test that OOM-ed my system. But hey, protects against memory errors, so it's fine to vibecode your security critical components.

        github.com/pyca/cryptography/p

          [?]knoppix » 🌐
          @knoppix95@mastodon.social

          iOS 26.5 adds default end-to-end encryption for RCS messages between Apple and Android, now in beta with supported carriers and a lock icon in chats 🔐
          The update follows GSMA changes, improving cross-platform privacy but remaining tied to proprietary apps and carrier support, limiting user control and transparency 📱

          🔗 engadget.com/2164303/ios-26-5-

            [?]Dawid Wiktor » 🌐
            @dawid@vebinet.com

            RE: vebinet.com/@kristin/116517777

            Reminder: If someone is claiming to be Signal Support, or your organization's/company's support on Signal, and asking you to provide your PIN or authentication code, then you can be sure it's phishing.

            Never accept contact requests and never ever give your PIN or authentication code.

            Encryption protects you, but the moment you give these 2, it cannot do so anymore. You can imagine it as walls of the castle. They will protect you, but if you open the gates, then walls have no use anymore.

            And as @kristin mentioned, if you use other apps and services, it's smart advice to apply these rules too.

              OCTADE boosted

              [?]Freezenet » 🌐
              @freezenet@noc.social

              Utah’s VPN Ban Law Goes Into Effect in Age Verification Escalation

              Utah is attempting to cover up the failures of their age verification law by effectively banning VPNs.

              freezenet.ca/utahs-vpn-ban-law

                [?]CosicBe » 🌐
                @CosicBe@mastodon.social

                Newly appointed COSIC professor Yunwen Liu gave her inaugural lecture today on “Security and Privacy Challenges in Distributed Ledger Technologies.”
                We’re delighted to officially welcome Yunwen to the COSIC team!

                  muddle boosted

                  [?]ProPublica » 🌐
                  @ProPublica@newsie.social

                  I Reached Out to the White House Counterterrorism Czar for Comment. He Lashed Out on X.
                  ---

                  Sebastian Gorka accused a ProPublica reporter of writing a “putrid piece of hackery” about him. Here’s how basic beat reporting led to a broader story about the state of the U.S. counterterrorism mission at a critical moment.
                  propublica.org/article/sebasti

                    [?]knoppix » 🌐
                    @knoppix95@mastodon.social

                    Signal is developing a standalone desktop app without requiring a smartphone for setup or use, based on recent open-source code changes. 🖥️
                    The update adds more desktop controls while keeping end-to-end encryption, improving device independence with a privacy-first design. 🔐

                    @signalapp

                    🔗 aboutsignal.com/news/signal-de

                      [?]knoppix » 🌐
                      @knoppix95@mastodon.social

                      Greece plans to require social media users to verify real identities, limiting anonymity to curb abuse and misinformation, raising privacy risks ⚖️
                      Officials say pseudonyms may remain but tied to real identities, highlighting tensions between state oversight, platform control, and user anonymity 🔐

                      🔗 euractiv.com/news/greece-to-ba

                        [?]knoppix » 🌐
                        @knoppix95@mastodon.social

                        Turkey plans to ban unlicensed VPNs and require approved providers to log user activity and share data with authorities, restricting anonymous access. 🚫
                        VPN signups surged as users seek privacy tools amid blocks, highlighting tensions between state control, surveillance risks, and user autonomy online. 🔐

                        🔗 reclaimthenet.org/turkey-to-ba

                        [?]knoppix » 🌐
                        @knoppix95@mastodon.social

                        Ubuntu will add opt-in AI features via Snaps in 26.10, including speech tools and automation, without a global disable switch, raising user control concerns. 🤖
                        Canonical says AI Snaps can be removed, but some users want AI-free builds or may switch to Linux Mint or Pop!_OS, citing privacy and autonomy risks. 🔐

                        🔗 theverge.com/tech/920723/linux

                          [?]Teh AnKorage ☑️ » 🌐
                          @ankorage@fe.disroot.org

                          "This Bill is So Good It Will Never Pass | Weekly News Roundup" 👀👏🌻

                          All hail the Van Panther

                          Click on, "Show More" or "Read More" to get the links.

                          DESCRIPTION of the content found at the links, below - "The Supreme Court hears case on Geofence warrants while congress introduces the Surveillance Accountability Act. This bill is so good it will never pass."

                          ==========

                          NOTE - This post is best viewed on a PC. Switched To Linux is, “written by a broad spectrum computer consultant to help people learn more about the Linux platform.” This account is a supporter of Switched To Linux and provides convenience posts of thumbnails art, videos and streams.

                          #SwitchedToLinux #Linux #Windows #Mac #Technology #Tech #AltTech #Privacy #Private #Security #Secure #FOSS #FreeAndOpenSource #FreeAndOpenSourceSoftware #FreeOpenSourceSoftware #YouTube #Odysee #Rumble #BitChute #Locals #Patreon #DLive #Twitch #AltTech #FactCheckTrue #Fediverse #SocialMedia #geofence #surveillance #bigdata

                          ==========

                          After viewing the content located at the below links, Tell us what you think by filling out a "SATISFACTION SURVEY or ABUSE/SPAM REPORT" form from Teh AnKorage

                          https://cryptpad.disroot.org/form/#/2/form/view/elsOVQUrXAmGuer4kd75JhA3mNELuCj8cTjEUynrZZo/

                          \*Videos and podcasts may take a considerable amount of time to post. If it is not present, it will be, soon(tm).

                          MATRIX! Join our Matrix community where you can chat about Linux and general tech topics. Also, direct video links are provided for our Matrix community members! Don't miss out!
                          https://matrix.to/#/#switchedtolinux:matrix.org

                          #YouTube -
                          https://www.youtube.com/@SwitchedtoLinux/videos

                          #Odysee -
                          https://odysee.com/@switchedtolinux:0?view=content

                          #Rumble -
                          https://rumble.com/c/SwitchedToLinux/videos

                          #Bitchute -
                          https://www.bitchute.com/channel/uf9hzD216LX0

                          ==========

                          Keep an eye out for a possible podcast!

                          PODCAST: https://podcast.switchedtolinux.com

                            [?]WIRED - The Latest in Technology, Science, Culture and Business [Unofficial] » 🌐
                            @wired.com@web.brid.gy

                            Disneyland Now Uses Face Recognition on Visitors

                            Plus: The NSA tests Anthropic’s Mythos Preview to find vulnerabilities, a Finnish teen is charged over the Scattered Spider hacking spree, and more.

                            Disneyland Now Uses Face Recognition on Visitors

                            Alt...Disneyland Now Uses Face Recognition on Visitors

                            [?]Jesus Michał von Gentoo 🏔 (he) » 🌐
                            @mgorny@social.treehouse.systems

                            Greg Kroah-Hartman: "If you look there are thousands of unfixed CVEs in the older LTS kernels right now, and if distros or users that rely on those older branches wish to see those resolved, they need to provide working backports to us to apply, as our first attempt did not work (which is why they are unfixed in those branches.)"

                            Really asking for a "Pray tell us", given that nobody actually bothered disclosing the problem to downstreams and that the commit message was hiding it.

                            Either way, apparently the great LLM-backed patch backporting process that is so proud of doesn't really work. Upstream doesn't really care about branches, and they should be considered insecure by default.

                            lore.kernel.org/stable/2026050

                              [?]Freezenet » 🌐
                              @freezenet@noc.social

                              Government Shuts Down Debate on Political Party Surveillance Bill

                              Nothing restores confidence in a surveillance bill quite like the government telling everyone to shut up about it.

                              freezenet.ca/government-shuts-

                                [?]Teh AnKorage ☑️ » 🌐
                                @ankorage@fe.disroot.org

                                "This Bill is So Good It Will Never Pass | Weekly News Roundup" 👀👏🌻

                                STREAMING at 8:00 PM EASTERN

                                All hail the van panther

                                Click on, "Show More" or "Read More" to get the links!

                                DESCRIPTION of the content found at the links, below - "The Supreme Court hears case on Geofence warrants while congress introduces the Surveillance Accountability Act. We also look at why we need parental digital neglect laws."

                                ==========

                                NOTE - This post is best viewed on a PC. Switched To Linux is, “written by a broad spectrum computer consultant to help people learn more about the Linux platform.” This account is a supporter of Switched To Linux and provides convenience posts of thumbnails art, videos and streams.

                                #SwitchedToLinux #Linux #Windows #Mac #Technology #Tech #AltTech #Privacy #Private #Security #Secure #FOSS #FreeAndOpenSource #FreeAndOpenSourceSoftware #FreeOpenSourceSoftware #YouTube #Odysee #Rumble #BitChute #Locals #Patreon #DLive #Twitch #AltTech #FactCheckTrue #Fediverse #SocialMedia #WeeklyNewsRoundup #geofence #smartphones

                                ==========

                                After viewing the content located at the below links, Tell us what you think by filling out a "SATISFACTION SURVEY or ABUSE/SPAM REPORT" form from Teh AnKorage

                                https://cryptpad.disroot.org/form/#/2/form/view/elsOVQUrXAmGuer4kd75JhA3mNELuCj8cTjEUynrZZo/

                                ==========

                                MATRIX - Join our Matrix community where you can chat about Linux and general tech topics. Also, direct video links are provided for our Matrix community members! Don't miss out!
                                https://matrix.to/#/#switchedtolinux:matrix.org

                                #YouTube:
                                https://www.youtube.com/@SwitchedtoLinux/streams

                                #Odysee:
                                https://odysee.com/@switchedtolinux:0

                                #Rumble:
                                https://rumble.com/c/SwitchedToLinux/livestreams

                                For folks on DLive and Twitch, you may also watch the stream, there...

                                #DLive - https://dlive.tv/switchedtolinux

                                #Twitch - https://twitch.tv/search?term=switchedtolinux

                                Keep an eye out for the podcast

                                https://podcast.switchedtolinux.com

                                  [?]Steele Fortress » 🌐
                                  @steelefortress@infosec.exchange

                                  The Illinois Biometric Information Privacy Act (BIPA) creates a private right of action with statutory damages for the unauthorized collection of biometric identifiers, including facial geometry captured by drone-mounted cameras, potentially exposing individuals to $1,000 per negligent violation or $5,000 per intentional or reckless violation.

                                  Where would forget what youve heard about drones and personal sp... break first in your environment?

                                  Read more: steelefortress.com/fortress-fe

                                  CyberSecurity

                                  🎥 Watch Teaser: steelefortress.com/ayxthd

                                    [?]PrivacyDigest » 🌐
                                    @PrivacyDigest@mas.to

                                    Utah’s New Law Targeting VPNs Goes Into Effect Next Week

                                    Instead of realizing that mass and age gates aren't exactly crowd favorites, lawmakers have decided that VPNs themselves are the real issue.

                                    Next week, on May 6, 2026, Utah will become, to EFF’s knowledge, the first state in the nation to target the use of VPNs to avoid legally mandated age-verification gates.

                                    eff.org/deeplinks/2026/04/utah

                                      [?]knoppix » 🌐
                                      @knoppix95@mastodon.social

                                      EU-funded programs and institutions are financing spyware firms like Intellexa and Paragon, despite use against journalists and activists in Europe. 🕵️‍♂️
                                      Reports cite weak oversight and transparency, raising risks to privacy, encryption, and democratic rights. 🚨

                                      🔗 edri.org/our-work/its-not-just

                                        [?]knoppix » 🌐
                                        @knoppix95@mastodon.social

                                        Proton CEO Andy Yen warns global age-verification laws could end anonymity via ID or biometric checks and centralized databases. 🔐
                                        He calls for open-source, on-device, encrypted checks, warning they could expand controls, reducing user control and enabling tracking. ⚠️

                                        @protonprivacy

                                        🔗 techradar.com/vpn/vpn-privacy-

                                          bruh/a1ba boosted

                                          [?]Jesus Michał von Gentoo 🏔 (he) » 🌐
                                          @mgorny@social.treehouse.systems

                                          So you read about , and are like… owww, shit. But then you see that it was responsibly disclosed after being fixed in main, we had releases since, they went stable in (over other fixes), so we should be good, right?

                                          Except that it turns out that after it has been fixed in mainline, nobody bothered actually backporting the fix to all the LTS branches. And it doesn't apply cleanly (social.treehouse.systems/@thes). What a shitshow!

                                          (And we've been only talking how 5.x don't get vulnerability fixes in time — but it turns out that anything but the latest is insecure to use!)

                                          [?]sam » 🌐
                                          @thesamesam@social.treehouse.systems

                                          Very unfortunate that the fix for CVE-2026-31431 isn't easily backportable, with a new API being added, and then its implementation details changing, since the last LTS (6.12 vs 6.18).

                                            [?]Sudo » 🌐
                                            @ImpracticalPrivacy@mastodon.social

                                            Ever notice how physical parking meters are disappearing? Replaced by QR codes and mandatory app downloads?

                                            That's not just modernization. It's coerced consent.

                                            When a city outsources parking to private vendors, they're outsourcing surveillance. You're handing over location data, device IDs, and payment info just to occupy public space.

                                            We cover the risks, breaches, and how to protect yourself without getting towed.

                                            Listen: ImpracticalPrivacy.com

                                              [?]Steele Fortress » 🌐
                                              @steelefortress@infosec.exchange

                                              Deploying ambient computing systems without embedded privacy architecture is a recipe for catastrophic financial losses, with estimated annual costs ranging from $150,000 to $432,000 and a risk-adjusted value of avoidance between $75,000 and $250,000 due to regulatory penalties.

                                              Where would the invisible threat lurking in your daily interacti... break first in your environment?

                                              Read more: steelefortress.com/fortress-fe

                                              CyberSecurity

                                              🎥 Watch Teaser: steelefortress.com/09o6mj

                                                [?]Olly 👾 » 🌐
                                                @Olly42@nerdculture.de

                                                :androidalt: Google blocks 8.3B Policy-Violating Ads in 2025, launches Android 17 Privacy Overhaul.

                                                The new policy updates relate to contact and location permissions in Android, allowing third-party apps to access the contact lists and a user's location in a more privacy-friendly manner. This includes a new Contact Picker, which offers a standardized, secure, and searchable interface for contact selection.

                                                "This feature allows users to grant apps access only to the specific contacts they choose, aligning with Android's commitment to data transparency and minimized permission footprints," Google said.

                                                android-developers.googleblog.

                                                ⁉️To comply with this update, developers are being urged to review their apps location usage to ensure that they are requesting the minimum amount of location data necessary for them to function.⁉️

                                                ⁉️"If your app targets Android 17 and above and uses precise location for discrete, temporary actions, implement the location button by adding the onlyForLocationButton flag in your manifest," the tech giant said. "If your app requires persistent, precise location to function, you will need to submit a Play Developer Declaration in Play Console to show why the new button or coarse location isn't sufficient for your app's core features."⁉️

The declaration form is expected to be available before October 2026, with pre-review checks in the Play Console to go live starting October 27 to identify potential contacts or location permissions policy issues.

👾Google is also implementing a secure way for businesses to transfer ownership of their apps through a native account transfer feature built into Play Console so as to stay protected against fraud. The company is recommending that app developers handle account ownership changes through this feature starting May 27, 2026.👾

"That means that unofficial transfers (like sharing login credentials or buying and selling accounts on third-party marketplaces), which leave your business vulnerable, are not permitted," it said.

                                                Alt...⁉️"If your app targets Android 17 and above and uses precise location for discrete, temporary actions, implement the location button by adding the onlyForLocationButton flag in your manifest," the tech giant said. "If your app requires persistent, precise location to function, you will need to submit a Play Developer Declaration in Play Console to show why the new button or coarse location isn't sufficient for your app's core features."⁉️ The declaration form is expected to be available before October 2026, with pre-review checks in the Play Console to go live starting October 27 to identify potential contacts or location permissions policy issues. 👾Google is also implementing a secure way for businesses to transfer ownership of their apps through a native account transfer feature built into Play Console so as to stay protected against fraud. The company is recommending that app developers handle account ownership changes through this feature starting May 27, 2026.👾 "That means that unofficial transfers (like sharing login credentials or buying and selling accounts on third-party marketplaces), which leave your business vulnerable, are not permitted," it said.

                                                👾Previously, apps requiring access to a specific user's contacts relied on READ_CONTACTS, an overly broad permission that granted apps the ability to access all contacts and their associated information. With the latest change introduced in Android 17, apps can specify which fields from a contact they need, such as phone numbers or email addresses, as opposed to reading the entire record.👾

The updated policy will require all applicable apps to use the picker [or the Android Sharesheet] as the main way to access users' contacts, with READ_CONTACTS now reserved only for apps that can't function without it. It's advised to entirely remove the READ_CONTACTS permission from the app manifest declaration if it's targeting Android versions 17 [currently in beta] and later.

<https://developer.android.com/training/sharing/send>

⁉️The second policy change revolves around a streamlined location button that Google has introduced in Android 17 that enables apps to request one-time access to a user's precise location. In doing so, it allows the user to make a better choice about how much information they want to share and for what duration. What's more, a persistent indicator will appear to alert a user every time a non-system app accesses their location.⁉️

<https://android-developers.googleblog.com/2026/03/location-privacy.html>

                                                Alt...👾Previously, apps requiring access to a specific user's contacts relied on READ_CONTACTS, an overly broad permission that granted apps the ability to access all contacts and their associated information. With the latest change introduced in Android 17, apps can specify which fields from a contact they need, such as phone numbers or email addresses, as opposed to reading the entire record.👾 The updated policy will require all applicable apps to use the picker [or the Android Sharesheet] as the main way to access users' contacts, with READ_CONTACTS now reserved only for apps that can't function without it. It's advised to entirely remove the READ_CONTACTS permission from the app manifest declaration if it's targeting Android versions 17 [currently in beta] and later. <https://developer.android.com/training/sharing/send> ⁉️The second policy change revolves around a streamlined location button that Google has introduced in Android 17 that enables apps to request one-time access to a user's precise location. In doing so, it allows the user to make a better choice about how much information they want to share and for what duration. What's more, a persistent indicator will appear to alert a user every time a non-system app accesses their location.⁉️ <https://android-developers.googleblog.com/2026/03/location-privacy.html>

                                                  [?]The New Oil » 🤖 🌐
                                                  @thenewoil@mastodon.thenewoil.org

                                                  [?]Tom Sellers » 🌐
                                                  @TomSellers@infosec.exchange

                                                  The articles about AI ganking production make me think of an altered version of Lucius Fox's comments in The Dark Knight:

                                                  "Let me get this straight.. you wired up SuperAutocomplete to a Magic 8-Ball for an RNG and your plan is to give this thing access to production operations and your backups? Good luck."

                                                  I'm sure using TheNonDeterministic Engine without guardrails is consistent with contractual and regulatory requirements for data governance and privacy..

                                                  TNDE: Makes changes including opening all S3 buckets to public access
                                                  User: Yay, prod isn't a smoking ruin so it probably did what I asked.

                                                  The original scene is amazing btw.
                                                  youtu.be/1z6o1GIEsQE?t=49

                                                    [?]ResearchBuzz: Firehose » 🌐
                                                    @researchbuzz_firehose@rbfirehose.com

                                                    The Register: Scotland Yard can keep using live facial recognition on people in London, say judges. “London’s Metropolitan Police Service (MPS) has survived a legal challenge that attempted to curb its rollout of live facial recognition (LFR) technology across the capital. The challenge was brought against the Met by civil liberties organization Big Brother Watch, which was representing Shaun […]

                                                    https://rbfirehose.com/2026/04/28/the-register-scotland-yard-can-keep-using-live-facial-recognition-on-people-in-london-say-judges/

                                                    [?]knoppix » 🌐
                                                    @knoppix95@mastodon.social

                                                    Proton analyzed 54k profiles using 2025 ad auction data, estimating US user value at $1,605/year, ranging from $31 to $17,929 by age, device, and behavior. 📊
                                                    Desktop users generate ~4.9× more value than Android users, and the top 10% of profiles account for 43% of total advertiser value. 🔒

                                                    @protonprivacy

                                                    🔗 proton.me/blog/what-is-your-da

                                                      [?]PrivacyDigest » 🌐
                                                      @PrivacyDigest@mas.to

                                                      [?]knoppix » 🌐
                                                      @knoppix95@mastodon.social

                                                      FTC reports $2.1B lost to social media scams in 2025, up 8× since 2020, with Facebook driving most losses via targeting, account abuse, and ads 🔐
                                                      Meta added scam warnings, detection tools, and takedowns, but centralized platforms still expose user data at scale, raising privacy and transparency risks ⚠️

                                                      🔗 bleepingcomputer.com/news/secu

                                                        [?]Frankie ✅ » 🌐
                                                        @Some_Emo_Chick@mastodon.social

                                                        Lightfighter boosted

                                                        [?]Frankie ✅ » 🌐
                                                        @Some_Emo_Chick@mastodon.social

                                                        [?]ResearchBuzz: Firehose » 🌐
                                                        @researchbuzz_firehose@rbfirehose.com

                                                        CalMatters: Websites break California privacy law at ‘industrial scale,’ survey finds. “A new audit has found that websites across the internet may be failing to abide by California privacy law, ignoring a requirement to not track visitors who set a privacy control.”

                                                        https://rbfirehose.com/2026/04/27/calmatters-websites-break-california-privacy-law-at-industrial-scale-survey-finds/

                                                        Back to top - More...