soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin email
social@octade.net

Search results for tag #media

[?]Olly 👾 » 🌐
@Olly42@nerdculture.de

Discord rolls out End-to-End Encryption on Voice, Video Calls.

The implementation was completed in March. Extensive at-scale testing has given Discord the confidence to formally announce the E2EE deployment now, and to start removing client code that supports unencrypted fallback. “End-to-end Encryption is now standard for every voice and video call on Discord, outside of stage channels. No opt-in required.” - Discord

discord.com/blog/every-voice-a

⁉️The migration to E2EE was achieved by extending the open-source encryption protocol DAVE to support all platforms where Discord clients run, including desktop, mobile, web browsers, PlayStation, Xbox and Discord SDKs.⁉️

github.com/discord/libdave

👾The encryption layer now covers DMs, group DMs, voice channels and Go Live streams. Stage channels remain the only exception because they are designed for large public broadcasts rather than private conversations.👾

The protocol leverages WebRTC encoded transforms, Messaging Layer Security [MLS] for scalable group key exchanges, and ephemeral identity keys to enhance privacy while minimizing call disruptions and latency when participants join or leave sessions.

⁉️Discord underlines the technical challenges of extending DAVE availability to all supported platforms and achieving low-latency levels that should make the migration unnoticeable for users.⁉️

• One example highlighted in the report is a compatibility issue with Firefox. Instead of implementing a workaround or limiting browser support, Discord engineers worked with Mozilla to resolve the problem.

Alt...👾The encryption layer now covers DMs, group DMs, voice channels and Go Live streams. Stage channels remain the only exception because they are designed for large public broadcasts rather than private conversations.👾 The protocol leverages WebRTC encoded transforms, Messaging Layer Security [MLS] for scalable group key exchanges, and ephemeral identity keys to enhance privacy while minimizing call disruptions and latency when participants join or leave sessions. ⁉️Discord underlines the technical challenges of extending DAVE availability to all supported platforms and achieving low-latency levels that should make the migration unnoticeable for users.⁉️ • One example highlighted in the report is a compatibility issue with Firefox. Instead of implementing a workaround or limiting browser support, Discord engineers worked with Mozilla to resolve the problem.

    [?]Emeritus Prof Christopher May » 🌐
    @ChrisMayLA6@zirk.us

    As Nesrine Malik argues, whatever other problems there are with AI & its associated technologies, in the end one of its most corrosive aspects may be its destruction of trust in what people write;

    the widening suspicion that AI has been used to write all sorts of things (previously penned/typed by humans) is leading to a decline in trust in communication more generally.... with who knows what long-term consequences?

    theguardian.com/commentisfree/

      [?]Philosophics » 🌐
      @microglyphics@mastodon.social

      In this essay, I investigate the ideas of Stuart Hall in light of my own. Hall and I have many commonalities in the operation of language, but my enterprise is broader and deeper, as his was ostensibly limited to media.

      open.substack.com/pub/brywilli

        [?]The-14 » 🌐
        @The14@mastodon.world

        [?]Olly 👾 » 🌐
        @Olly42@nerdculture.de

        College Student hacks Taiwan High-Speed Rail Line with Software defined Radios, stopping four Trains.

        [19 years without crypto key rotation ends in predictable result as hacker sails through 7 layers of protection.]

        Techies and trains have always had a fairly close relationship, but some people seem to take that relationship to toxic levels. About a month ago, a 23-year-old Taiwanese student "hacked" the country's high-speed rail line using an SDR [Software-Defined Radio] filter and radios, remotely broadcasting a General Alarm sign and triggering a manual emergency braking procedure.

        ⁉️The event brought four trains to a standstill for 48 minutes until the situation was verified as a false alarm, with reportedly no hard stops executed. Lin, the mind behind the operation, sailed through "seven verification layers" thanks to the fact that the TETRA [Terrestrial Trunked Radio] system in use hadn't had its cryptographic keys rotated in 19 years.⁉️

        taipeitimes.com/News/taiwan/ar

        Democratic Progressive Party Legislator Ho Shin-chun clearly stated, "If a college student could hack into a system as sophisticated as that of the high-speed rail system, what would happen if the same thing happened with the Taiwan Railway Corp’s system?"

👾As for Lin, he's using the Looney Tunes defense that it was an accidental press of a button on the radio he had in his pocket. It would have been easy for him to conduct himself better and take the ethical route by disclosing the vulnerability to the relevant authorities, as Taiwan appears to have a highly progressive attitude towards civil hacking in all forms.👾

<https://www.rtl-sdr.com/student-arrested-in-taiwan-for-using-sdr-and-handheld-radios-to-halt-four-high-speed-trains-with-tetra-hack/>

⁉️This is exemplified by the g0v initiative, which calls for open and transparent operations from regular citizens, an ethos that has official government support and was most useful during the COVID-19 pandemic. There's a yearly Presidential Hackathon, too, and Taiwan's National Institute of Cyber Security recently awarded $17,000 for 20 reported vulnerabilities across a range of products.⁉️

<https://focustaiwan.tw/politics/202512140012>

<https://www.rti.org.tw/en/news?uid=3&pid=205156>

        Alt...Democratic Progressive Party Legislator Ho Shin-chun clearly stated, "If a college student could hack into a system as sophisticated as that of the high-speed rail system, what would happen if the same thing happened with the Taiwan Railway Corp’s system?" 👾As for Lin, he's using the Looney Tunes defense that it was an accidental press of a button on the radio he had in his pocket. It would have been easy for him to conduct himself better and take the ethical route by disclosing the vulnerability to the relevant authorities, as Taiwan appears to have a highly progressive attitude towards civil hacking in all forms.👾 <https://www.rtl-sdr.com/student-arrested-in-taiwan-for-using-sdr-and-handheld-radios-to-halt-four-high-speed-trains-with-tetra-hack/> ⁉️This is exemplified by the g0v initiative, which calls for open and transparent operations from regular citizens, an ethos that has official government support and was most useful during the COVID-19 pandemic. There's a yearly Presidential Hackathon, too, and Taiwan's National Institute of Cyber Security recently awarded $17,000 for 20 reported vulnerabilities across a range of products.⁉️ <https://focustaiwan.tw/politics/202512140012> <https://www.rti.org.tw/en/news?uid=3&pid=205156>

        [ImageSource: Getty Images]

The extracurricular activity was quickly traced back to Lin, who seemingly answered the radio in an awkward manner and hung up. This prompted the train network to immediately review all beacons in use, followed by its CCTV footage. Working with the police, they followed the trail to Lin's home in Taichung. There, they found a laptop alongside several radios. Lin is now out on $3,200 bail while waiting for a trial and a judgment that could have him behind bars for 10 years.

👾Despite Lin's apparent lack of forethought, the "hack" didn't take much effort, as any radio system that goes 19 years without key rotation easily falls to a low-grade cloning attack. RTL-SDR speculates that the system in question used now-broken TEA1 encryption. However, we believe that since key rotation in TETRA needs to be configured and scheduled at installation, the likely answer is that it just wasn't implemented.👾

<https://www.rtl-sdr.com/student-arrested-in-taiwan-for-using-sdr-and-handheld-radios-to-halt-four-high-speed-trains-with-tetra-hack/>

⁉️Lin reportedly also had information on how to access the comms of the New Taipei Fire City Department and the Taoyuan International Airport MRT Line. The incident triggered a round of political ping-pong to assess responsibilities for the weak security and a formal review of all aforementioned radio systems.⁉️

        Alt...[ImageSource: Getty Images] The extracurricular activity was quickly traced back to Lin, who seemingly answered the radio in an awkward manner and hung up. This prompted the train network to immediately review all beacons in use, followed by its CCTV footage. Working with the police, they followed the trail to Lin's home in Taichung. There, they found a laptop alongside several radios. Lin is now out on $3,200 bail while waiting for a trial and a judgment that could have him behind bars for 10 years. 👾Despite Lin's apparent lack of forethought, the "hack" didn't take much effort, as any radio system that goes 19 years without key rotation easily falls to a low-grade cloning attack. RTL-SDR speculates that the system in question used now-broken TEA1 encryption. However, we believe that since key rotation in TETRA needs to be configured and scheduled at installation, the likely answer is that it just wasn't implemented.👾 <https://www.rtl-sdr.com/student-arrested-in-taiwan-for-using-sdr-and-handheld-radios-to-halt-four-high-speed-trains-with-tetra-hack/> ⁉️Lin reportedly also had information on how to access the comms of the New Taipei Fire City Department and the Taoyuan International Airport MRT Line. The incident triggered a round of political ping-pong to assess responsibilities for the weak security and a formal review of all aforementioned radio systems.⁉️

          [?]Paria sans portefeuille » 🌐
          @PariaSansPortefeuille@jasette.facil.services

          Owen Jones welcomes , author of : The 's Complicity in the Destruction of (all royalties from which go to Middle East Children's Alliance)

          youtube.com/watch?v=ETJv8ggAFA0

          @bookstodon

            [?]Scary Austin » 🌐
            @MaryAustinBooks@mstdn.social

            Leading cause of vaginal dryness Ben Shapiro has just laid off half the staff of the Daily Wire due to reduced engagement and revenue. 🥳 🎉 :catmoji_tears:

            No word on whether their Appeal to Heaven flags will fly at half staff too.

            rawstory.com/daily-wire-267684

              muddle boosted

              [?]Alexander Karn » 🌐
              @xankarn@mastodon.online

              Big ups to the legions of Mastodonians linking to their vetted sources.

              Protect and nourish our information ecosystems!

                [?]Olly 👾 » 🌐
                @Olly42@nerdculture.de

                :androidalt: Google blocks 8.3B Policy-Violating Ads in 2025, launches Android 17 Privacy Overhaul.

                The new policy updates relate to contact and location permissions in Android, allowing third-party apps to access the contact lists and a user's location in a more privacy-friendly manner. This includes a new Contact Picker, which offers a standardized, secure, and searchable interface for contact selection.

                "This feature allows users to grant apps access only to the specific contacts they choose, aligning with Android's commitment to data transparency and minimized permission footprints," Google said.

                android-developers.googleblog.

                ⁉️To comply with this update, developers are being urged to review their apps location usage to ensure that they are requesting the minimum amount of location data necessary for them to function.⁉️

                ⁉️"If your app targets Android 17 and above and uses precise location for discrete, temporary actions, implement the location button by adding the onlyForLocationButton flag in your manifest," the tech giant said. "If your app requires persistent, precise location to function, you will need to submit a Play Developer Declaration in Play Console to show why the new button or coarse location isn't sufficient for your app's core features."⁉️

The declaration form is expected to be available before October 2026, with pre-review checks in the Play Console to go live starting October 27 to identify potential contacts or location permissions policy issues.

👾Google is also implementing a secure way for businesses to transfer ownership of their apps through a native account transfer feature built into Play Console so as to stay protected against fraud. The company is recommending that app developers handle account ownership changes through this feature starting May 27, 2026.👾

"That means that unofficial transfers (like sharing login credentials or buying and selling accounts on third-party marketplaces), which leave your business vulnerable, are not permitted," it said.

                Alt...⁉️"If your app targets Android 17 and above and uses precise location for discrete, temporary actions, implement the location button by adding the onlyForLocationButton flag in your manifest," the tech giant said. "If your app requires persistent, precise location to function, you will need to submit a Play Developer Declaration in Play Console to show why the new button or coarse location isn't sufficient for your app's core features."⁉️ The declaration form is expected to be available before October 2026, with pre-review checks in the Play Console to go live starting October 27 to identify potential contacts or location permissions policy issues. 👾Google is also implementing a secure way for businesses to transfer ownership of their apps through a native account transfer feature built into Play Console so as to stay protected against fraud. The company is recommending that app developers handle account ownership changes through this feature starting May 27, 2026.👾 "That means that unofficial transfers (like sharing login credentials or buying and selling accounts on third-party marketplaces), which leave your business vulnerable, are not permitted," it said.

                👾Previously, apps requiring access to a specific user's contacts relied on READ_CONTACTS, an overly broad permission that granted apps the ability to access all contacts and their associated information. With the latest change introduced in Android 17, apps can specify which fields from a contact they need, such as phone numbers or email addresses, as opposed to reading the entire record.👾

The updated policy will require all applicable apps to use the picker [or the Android Sharesheet] as the main way to access users' contacts, with READ_CONTACTS now reserved only for apps that can't function without it. It's advised to entirely remove the READ_CONTACTS permission from the app manifest declaration if it's targeting Android versions 17 [currently in beta] and later.

<https://developer.android.com/training/sharing/send>

⁉️The second policy change revolves around a streamlined location button that Google has introduced in Android 17 that enables apps to request one-time access to a user's precise location. In doing so, it allows the user to make a better choice about how much information they want to share and for what duration. What's more, a persistent indicator will appear to alert a user every time a non-system app accesses their location.⁉️

<https://android-developers.googleblog.com/2026/03/location-privacy.html>

                Alt...👾Previously, apps requiring access to a specific user's contacts relied on READ_CONTACTS, an overly broad permission that granted apps the ability to access all contacts and their associated information. With the latest change introduced in Android 17, apps can specify which fields from a contact they need, such as phone numbers or email addresses, as opposed to reading the entire record.👾 The updated policy will require all applicable apps to use the picker [or the Android Sharesheet] as the main way to access users' contacts, with READ_CONTACTS now reserved only for apps that can't function without it. It's advised to entirely remove the READ_CONTACTS permission from the app manifest declaration if it's targeting Android versions 17 [currently in beta] and later. <https://developer.android.com/training/sharing/send> ⁉️The second policy change revolves around a streamlined location button that Google has introduced in Android 17 that enables apps to request one-time access to a user's precise location. In doing so, it allows the user to make a better choice about how much information they want to share and for what duration. What's more, a persistent indicator will appear to alert a user every time a non-system app accesses their location.⁉️ <https://android-developers.googleblog.com/2026/03/location-privacy.html>

                  [?]Jacob Urlich 🌍 » 🌐
                  @experimentmapass@social.trom.tf

                  I DO NOT STRUGGLE WITH IT, BECAUSE I DO.NOT USE IT?

                  bbc.co.uk/reel/playlist/katty-…





                    muddle boosted

                    [?]Warner Crocker » 🌐
                    @WarnerCrocker@mastodon.social

                    A bit of good news.

                    The Onion says it has struck a deal to take over Infowars motherjones.com/politics/2026/

                    And the announcement on The Onion’s site is hysterical.

                    theonion.info

                      [?]Olly 👾 » 🌐
                      @Olly42@nerdculture.de

                      Google rolls out Gmail end-to-end Encryption on Mobile Devices.

                      The company says Gmail end-to-end encryption [E2EE] is now available on all Android and iOS devices, allowing enterprise users to read and compose emails without additional tools.

                      ⁉️Recipients who don't have the Gmail mobile app and use other email services can read them in a web browser, regardless of the device and service they're using.⁉️

                      workspaceupdates.googleblog.co

                      👾Gmail's end-to-end encryption [E2EE] feature is powered by the client-side encryption [CSE] technical control, which allows Google Workspace organizations to use encryption keys they control and are stored outside Google's servers to protect sensitive documents and emails.👾

<https://support.google.com/a/answer/10741897>

This way, the messages and attachments are encrypted on the client before being sent to Google's servers, which helps meet regulatory requirements such as data sovereignty, HIPAA, and export controls by ensuring that Google and third parties can't read any of the data.

⁉️Gmail CSE was introduced in Gmail on the web in December 2022 as a beta test, following an initial beta rollout to Google Drive, Google Docs, Sheets, Slides, Google Meet and Google Calendar, and it reached general availability for Google Workspace Enterprise Plus, Education Plus and Education Standard customers in February 2023.⁉️

                      Alt...👾Gmail's end-to-end encryption [E2EE] feature is powered by the client-side encryption [CSE] technical control, which allows Google Workspace organizations to use encryption keys they control and are stored outside Google's servers to protect sensitive documents and emails.👾 <https://support.google.com/a/answer/10741897> This way, the messages and attachments are encrypted on the client before being sent to Google's servers, which helps meet regulatory requirements such as data sovereignty, HIPAA, and export controls by ensuring that Google and third parties can't read any of the data. ⁉️Gmail CSE was introduced in Gmail on the web in December 2022 as a beta test, following an initial beta rollout to Google Drive, Google Docs, Sheets, Slides, Google Meet and Google Calendar, and it reached general availability for Google Workspace Enterprise Plus, Education Plus and Education Standard customers in February 2023.⁉️

                      [ImageSource: Google]

Writing E2EE messages and reading them without the app.

⁉️"For the first time, users can compose and read these E2EE messages natively within the Gmail app on Android and iOS. No need to download extra apps or use mail portals. Users with a Gmail E2EE license can send an encrypted message to any recipient, regardless of what email address the recipient has," Google announced.⁉️

"This launch combines the highest level of privacy and data encryption with a user-friendly experience for all users, enabling simple encrypted email for all customers from small businesses to enterprises and public sector."

👾This feature is now available for all client-side encryption [CSE] users with Enterprise Plus licenses and the Assured Controls or Assured Controls Plus add-on after admins enable the Android and iOS clients in the CSE admin interface via the Admin Console.👾

<https://knowledge.workspace.google.com/admin/security/client-side-encryption-setup-overview>

⚠️To send an end-to-end encrypted message, Gmail users have to turn on the "Additional encryption" option by clicking the Lock icon when writing the message.⚠️

                      Alt...[ImageSource: Google] Writing E2EE messages and reading them without the app. ⁉️"For the first time, users can compose and read these E2EE messages natively within the Gmail app on Android and iOS. No need to download extra apps or use mail portals. Users with a Gmail E2EE license can send an encrypted message to any recipient, regardless of what email address the recipient has," Google announced.⁉️ "This launch combines the highest level of privacy and data encryption with a user-friendly experience for all users, enabling simple encrypted email for all customers from small businesses to enterprises and public sector." 👾This feature is now available for all client-side encryption [CSE] users with Enterprise Plus licenses and the Assured Controls or Assured Controls Plus add-on after admins enable the Android and iOS clients in the CSE admin interface via the Admin Console.👾 <https://knowledge.workspace.google.com/admin/security/client-side-encryption-setup-overview> ⚠️To send an end-to-end encrypted message, Gmail users have to turn on the "Additional encryption" option by clicking the Lock icon when writing the message.⚠️

                        muddle boosted

                        [?]Texas Observer » 🌐
                        @TexasObserver@texasobserver.social

                        “Until a journalist is actually able to bring a civil rights lawsuit to trial against the government for violating their First Amendment rights, it’s open season on anyone doing , and especially those without an in-house lawyer handy.” texasobserver.org/la-gordiloca

                          [?]Paria sans portefeuille » 🌐
                          @PariaSansPortefeuille@jasette.facil.services

                          welcomes to discuss his book (all royalties from which go to Middle East Children's Alliance)

                          "We talk about how the whitewashed Israeli lies, erased Palestinian voices, and contrived a way to make a political settlement seem impossible, and war crimes not only acceptable, but also inevitable."

                          speakingoutofplace.buzzsprout.

                          @bookstodon

                            [?]Flipboard » 🌐
                            @Flipboard@flipboard.social

                            A new startup, Objection, aims to use AI to judge the "truth" of journalism. @Techcrunch's Rebecca Ballard talked to founder Aron D'Souza, who also co-created the Enhanced Games, about the Peter Thiel-backed venture.

                            flip.it/npOOPv

                             

                              [?]Scary Austin » 🌐
                              @MaryAustinBooks@mstdn.social

                              Cartoonist Rob Rogers was fired from the Pittsburgh Post-Gazette in 2018 for the cartoon below. While he seems to have done all right for himself, it's just one episode of many showing the rank cowardice of the media that contributed to this disaster.

                              Social media exchange from 2018 posted as a reminder
Rob Rogers says "Sad to report this update: Today, after 25 years as the editorial cartoonist for the Pittsburgh Post-Gazette, I was fired."
Ted St Godard says "This got the cartoonist fired. Share it." He posts Rogers' cartoon which shows a road sign saying "CAUTION" with silhouettes of a family running away from Trump's outline. The parents run ahead and a little girl can't keep up. Trump is grabbing her as she reaches out to her parents."

                              Alt...Social media exchange from 2018 posted as a reminder Rob Rogers says "Sad to report this update: Today, after 25 years as the editorial cartoonist for the Pittsburgh Post-Gazette, I was fired." Ted St Godard says "This got the cartoonist fired. Share it." He posts Rogers' cartoon which shows a road sign saying "CAUTION" with silhouettes of a family running away from Trump's outline. The parents run ahead and a little girl can't keep up. Trump is grabbing her as she reaches out to her parents."

                                [?]Scary Austin » 🌐
                                @MaryAustinBooks@mstdn.social

                                When you know your audience is a bunch of pedophiles:

                                "Marc Siegel: The problem is teens and young adults. From ages 15-19 the fertility rate is down 7% and it's down 70% over the last two decades, meaning we're telling people that are young not to have babies.”

                                mediamatters.org/fox-news/fox-

                                  [?]Project Gutenberg » 🌐
                                  @gutenberg_org@mastodon.social

                                  When Satirical Magazines Confront Real Crises

                                  In Chile and Argentina, satirical publications used humor to expose political crises overlooked by the mainstream press.

                                  By: Livia Gershon

                                  daily.jstor.org/when-satirical

                                    [?]Olly 👾 » 🌐
                                    @Olly42@nerdculture.de

                                    :firefox: Firefox 149 will offer a Free built-in VPN, split Views, Tab Notes and optional AI Windows.

                                    Mozilla has announced several major updates coming to Firefox. Starting with Firefox 149, users in the United States, France, Germany, and the United Kingdom will be able to access a free built-in virtual private network [VPN] with a 50-gigabyte monthly data limit. The VPN will route browser traffic through a proxy, masking users IP addresses and locations for increased privacy without needing extra downloads.

                                    blog.mozilla.org/en/firefox/fi

                                    ⁉️Also Firefox is the first browser to ship Sanitizer API, a new web security standard that blocks attacks before they reach you [for untrusted HTML XSS vulnerabilities].⁉️

                                    hacks.mozilla.org/2026/02/good

                                    🖇️Check my Image Description🖇️

                                    👾Alongside the VPN, Firefox 149 will introduce split view, allowing two webpages to be displayed side by side in a single window. This enables easier comparison, copying, and multitasking without constantly switching tabs.👾

Also in this release, the Smart Window feature [formerly AI Window] will offer an optional browsing assistant. Using artificial intelligence, it will provide quick definitions, article summaries, or product comparisons directly within the browser interface. Users can choose to enable or disable this feature.

Firefox 149 will introduce Tab Notes, letting users attach notes to any tab to aid with multitasking and organization.

<https://connect.mozilla.org/t5/discussions/new-in-nightly-tab-notes-feedback-wanted/td-p/117040>

⁉️These updates are complemented by broader usability improvements. The redesigned settings section now offers clearer navigation and an improved search function, making customization simpler.⁉️

<https://support.mozilla.org/en-US/kb/firefox-labs-explore-experimental-features-firefox>

Additionally, Firefox is debuting refreshed themes, icons and visual refinements throughout its interface. Users may also notice the appearance of Firefox’s new mascot, Kit 🦊.

<https://youtu.be/AtuzapfqF1M>

                                    Alt...👾Alongside the VPN, Firefox 149 will introduce split view, allowing two webpages to be displayed side by side in a single window. This enables easier comparison, copying, and multitasking without constantly switching tabs.👾 Also in this release, the Smart Window feature [formerly AI Window] will offer an optional browsing assistant. Using artificial intelligence, it will provide quick definitions, article summaries, or product comparisons directly within the browser interface. Users can choose to enable or disable this feature. Firefox 149 will introduce Tab Notes, letting users attach notes to any tab to aid with multitasking and organization. <https://connect.mozilla.org/t5/discussions/new-in-nightly-tab-notes-feedback-wanted/td-p/117040> ⁉️These updates are complemented by broader usability improvements. The redesigned settings section now offers clearer navigation and an improved search function, making customization simpler.⁉️ <https://support.mozilla.org/en-US/kb/firefox-labs-explore-experimental-features-firefox> Additionally, Firefox is debuting refreshed themes, icons and visual refinements throughout its interface. Users may also notice the appearance of Firefox’s new mascot, Kit 🦊. <https://youtu.be/AtuzapfqF1M>

                                      Guy boosted

                                      [?]JuneSim63 💚 » 🌐
                                      @junesim63@mstdn.social

                                      Media coverage of net zero is more than twice as likely to be negative than public attitudes and is driving a false perception that net zero policies are unpopular with voters, according to an analysis that identifies rightwing media narratives as fuelling a false backlash against climate action.

                                      theguardian.com/environment/20

                                        [?]Flipboard » 🌐
                                        @Flipboard@flipboard.social

                                        Small publishers (1,000-10,000 daily page views) are experiencing the worst traffic declines in the AI era, Axios reports, based on data from Chartbeat. Our managing editor @csullivan writes about how Flipboard is working with independent and worker-owned publications to drive people to their sites. At the second link, find @AxiosNews's story on the latest traffic stats.

                                        about.flipboard.com/inside-fli
                                        flip.it/uhVLNO

                                          [?]Olly 👾 » 🌐
                                          @Olly42@nerdculture.de

                                          :apple_inc: Predator Spyware hooks iOS SpringBoard to hide Mic & Camera Activity.

                                          The malware does not exploit any iOS vulnerability but leverages previously obtained kernel-level access to hijack system indicators that would otherwise expose its surveillance operation.

                                          ⁉️Researchers at mobile device management company Jamf analyzed Predator samples and documented the process of hiding the privacy-related indicators.⁉️

                                          jamf.com/blog/predator-spyware

                                          Alt...👾According to Jamf, Predator hides all recording indicators on iOS 14 by using a single hook function (‘HiddenDot::setupHook()’) inside SpringBoard, invoking the method whenever sensor activity changes [upon camera or microphone activation].👾 By intercepting it, Predator prevents sensor activity updates from ever reaching the UI layer, so the green or red dot never lights up. ⁉️“The target method _handleNewDomainData: is called by iOS whenever sensor activity changes - camera turns on, microphone activates, etc.,” Jamf researchers explain. “By hooking this single method, Predator intercepts ALL sensor status updates before they reach the indicator display system.”⁉️

                                          [ImageSource: Jamf]

Function targeting the SBSensorActivityDataProvider.

⁉️The hook works by nullifying the object responsible for sensor updates [SBSensorActivityDataProvider in SpringBoard]. In Objective-C, calls to a null object are silently ignored, so SpringBoard never processes the camera or microphone activation, and no indicator appears.⁉️

Because SBSensorActivityDataProvider aggregates all sensor activity, this single hook disables both the camera and the microphone indicators.

👾The researchers also found “dead code” that attempted to hook ‘SBRecordingIndicatorManager’ directly. However, it doesn’t execute, and is likely an earlier development path that was abandoned in favor of the better approach that intercepts sensor data upstream.👾

In the case of VoIP recordings, which Predator also supports, the module responsible lacks an indicator-suppression mechanism, so it relies on the HiddenDot function for stealth.

                                          Alt...[ImageSource: Jamf] Function targeting the SBSensorActivityDataProvider. ⁉️The hook works by nullifying the object responsible for sensor updates [SBSensorActivityDataProvider in SpringBoard]. In Objective-C, calls to a null object are silently ignored, so SpringBoard never processes the camera or microphone activation, and no indicator appears.⁉️ Because SBSensorActivityDataProvider aggregates all sensor activity, this single hook disables both the camera and the microphone indicators. 👾The researchers also found “dead code” that attempted to hook ‘SBRecordingIndicatorManager’ directly. However, it doesn’t execute, and is likely an earlier development path that was abandoned in favor of the better approach that intercepts sensor data upstream.👾 In the case of VoIP recordings, which Predator also supports, the module responsible lacks an indicator-suppression mechanism, so it relies on the HiddenDot function for stealth.

                                          [ImageSource: Jamf]

iPhone cam/mic activation indicators.

Apple introduced recording indicators on the status bar in iOS 14 to alert users when the camera or microphone is in use, displaying a green or an orange dot, respectively.

While its ability to suppress camera and microphone activity indicators is well known, it was unclear how the mechanism worked.

👾Jamf further explains that camera access is enabled through a separate module that locates internal camera functions using ARM64 instruction pattern matching and Pointer Authentication Code [PAC] redirection to bypass camera permission checks.👾

Without indicators lighting up on the status bar, the spyware activity remains completely hidden to the regular user.

⁉️Jamf notes that technical analysis reveals the signs of the malicious processes, such as unexpected memory mappings or exception ports in SpringBoard and mediaserverd, breakpoint-based hooks, and audio files written by mediaserverd to unusual paths.⁉️

                                          Alt...[ImageSource: Jamf] iPhone cam/mic activation indicators. Apple introduced recording indicators on the status bar in iOS 14 to alert users when the camera or microphone is in use, displaying a green or an orange dot, respectively. While its ability to suppress camera and microphone activity indicators is well known, it was unclear how the mechanism worked. 👾Jamf further explains that camera access is enabled through a separate module that locates internal camera functions using ARM64 instruction pattern matching and Pointer Authentication Code [PAC] redirection to bypass camera permission checks.👾 Without indicators lighting up on the status bar, the spyware activity remains completely hidden to the regular user. ⁉️Jamf notes that technical analysis reveals the signs of the malicious processes, such as unexpected memory mappings or exception ports in SpringBoard and mediaserverd, breakpoint-based hooks, and audio files written by mediaserverd to unusual paths.⁉️

                                            🗳

                                            [?]Flipboard » 🌐
                                            @Flipboard@flipboard.social

                                            3.46 million people subscribe to journalist/documentarian/creator Andrew Callaghan's YouTube series, Channel 5. Sophie Culpepper, a NiemanLab journalist, attended his "carnival" event to see what the fuss was about. Here's what she thought. We want to know, as social and video networks overtake TV as a news source, where do you get your news (choose as many as you like)?

                                            flip.it/zNHIpG

                                            Television:0
                                            Print newspapers and magazines:0
                                            Aggregators/apps like Flipboard:0
                                            Newsletters:0
                                            Mainstream social media:0
                                            Open social media:0
                                            YouTube/other video platforms:0
                                            Somewhere else (explain in the comments):0

                                              [?]SetSideB » 🌐
                                              @setsideb@wrestling.social

                                              The History of Game Player’s Magazines
                                              The Video Game History Foundation has a breezy 3½ minute video about one of the less-remembered magazines of the NES-through-Playstation era, Game Player's, with the apostrophe-S at the end. But it wasn't just one magazine. Over ten years they put out magazines under thirteen different titles, and s
                                              setsideb.com/the-history-of-ga

                                                [?]ᴮᵉⁿ ᴿᵒʸᶜᵉVOTE IN THE PRIMARIES » 🌐
                                                @benroyce@mastodon.social

                                                @mastodonmigration @ikuturso

                                                the play is easy

                                                genuinely likes their audience

                                                but.. are finances

                                                the goons who control the purse strings lick their chops with very goon-based dreams, replace the leadership, and then fucking ruin it

                                                just like

                                                just like traditional ( , , etc)

                                                so a warning for all:

                                                enjoy bluesky

                                                but its days are numbered

                                                it will become a cesspool like twitter eventually

                                                with certainty

                                                  [?]Nonilex » 🌐
                                                  @Nonilex@masto.ai

                                                  The lawsuit was filed in the US Court of Appeals for the District of Columbia by ​the Public Integrity Project on behalf of two retail US investors in rival firms. It aims to require a renegotiation of the deal "that doesn't put ⁠administration allies in a position to on one of the world's most ​popular platforms."

                                                    [?]Olly 👾 » 🌐
                                                    @Olly42@nerdculture.de

                                                    New WhatsApp Lockdown Feature protects High-Risk Users from Attackers.

                                                    Meta has started rolling out a new WhatsApp lockdown-style security feature designed to protect journalists, public figures and other high-risk individuals from sophisticated threats, including spyware attacks.

                                                    ⁉️Known as "Strict Account Settings," this new feature builds on already existing end-to-end encryption by adding extreme safeguards for users who require heightened protection beyond standard security measures.⁉️

                                                    ⚠️Users can enable these new extreme privacy and security controls only from their primary device by toggling on the "Strict account settings" option under Settings > Privacy > Advanced.⚠️

                                                    blog.whatsapp.com/whatsapps-la

                                                    👾Once enabled, it will apply the most restrictive privacy controls, automatically turning on two-step verification, blocking media and attachments from unknown senders, silencing calls from unknown people, turning off link previews, locking access to the users last seen and online information, profile photo, About details and profile links, and limiting other features that could expose users to attacks.👾

"We will always defend that right to privacy for everyone, starting with default end-to-end encryption. But we also know that a few of our users – like journalists or public-facing figures – may need extreme safeguards against rare and highly-sophisticated cyber attacks," WhatsApp said in a blog post.

"This feature is built for the very few users who may be the target of such attacks. Therefore, you should only turn this on if you think you may be a target of a sophisticated cyber campaign. Most people are not targeted by such attacks," it added in a separate support document.

<https://faq.whatsapp.com/846698564598022/>

⁉️WhatsApp said that the feature it's also slowly migrating to the Rust programming language behind the scenes to boost protection against spyware targeting photos, videos and messages.⁉️

                                                    Alt...👾Once enabled, it will apply the most restrictive privacy controls, automatically turning on two-step verification, blocking media and attachments from unknown senders, silencing calls from unknown people, turning off link previews, locking access to the users last seen and online information, profile photo, About details and profile links, and limiting other features that could expose users to attacks.👾 "We will always defend that right to privacy for everyone, starting with default end-to-end encryption. But we also know that a few of our users – like journalists or public-facing figures – may need extreme safeguards against rare and highly-sophisticated cyber attacks," WhatsApp said in a blog post. "This feature is built for the very few users who may be the target of such attacks. Therefore, you should only turn this on if you think you may be a target of a sophisticated cyber campaign. Most people are not targeted by such attacks," it added in a separate support document. <https://faq.whatsapp.com/846698564598022/> ⁉️WhatsApp said that the feature it's also slowly migrating to the Rust programming language behind the scenes to boost protection against spyware targeting photos, videos and messages.⁉️

                                                      Back to top - More...