-
US Gov’t Signal-clone with backdoor for message retention, hacked, messages leaked | …I really hope #Ofcom are watching re: the impact of proposed client side scanning
Data includes fragments of live communications, including sensitive discussions about pending crypto legislation. Thread: https://x.com/mattjay/status/1919457030793732281 Source: https://www.404media.co/the-signal-clone-the-trump-admin-uses-was-hacked/
Fediverse reactions
-
ICYMI: “Every TWINSCAN EUV ships with ~45 million lines of code […] Bugfixes and features start out as *word documents* sent to a series of review boards…”
Remember, kids: all this security nightmare can be fixed through the simple act of regulators demanding that security be implemented “by design”. Or not. Because “security by design” doesn’t mean anything. These are the machines which fabricate all the world’s major CPUs:
-
Mike Waltz Accidentally Reveals Obscure App the Government Is Using to Archive Signal Messages | Sigh, but at least I suppose they are shooting in the right direction…
A photograph of Trump administration official Mike Waltz’s phone shows him using an unofficial version of Signal designed to archive messages during a cabinet meeting. https://www.404media.co/mike-waltz-accidentally-reveals-obscure-app-the-government-is-using-to-archive-signal-messages/
Fediverse reactions
-
How a 20 year old bug in GTA San Andreas surfaced in Windows 11 24H2 | Silent’s Blog
A fascinating delve into an old “uninitialised variables on stack because of inadequate input validation”-bug, which managed to survive two decades in the wild before detection. https://cookieplmonster.github.io/2025/04/23/gta-san-andreas-win11-24h2-bug/
Fediverse reactions
-
Baby food pouches low in key nutrients, lab testing finds | BBC News | …READ THIS ARTICLE if you are interested in AI or Cybersecurity, because …
…it’s a microcosm of every clickbait techlash article of the past 20 years: https://www.bbc.com/news/articles/c62j0l0gg4go
-
“Signal is better than most other commercial apps, but it’s not military-grade encryption” | …and we are all grateful for that small mercy
Fears grow that Signal leaks make Pete Hegseth top espionage target | Signal group chat leak | The Guardian https://www.theguardian.com/us-news/2025/apr/23/pete-hegseth-pentagon-espionage
Fediverse reactions
-
Proposal to Update Indicator 9B of the DPG Standard: Inappropriate & Illegal Content | …whyyyy do social-good activists still do stuff like this?
[Any…] system as-described can be trivially repurposed … to identify content pertaining to LGBTQ community, sexual health, abortion rights, political activism, democracy campaigns and resistance to foreign invasion. There is no such thing as a … system which can be permanently technologically limited to a narrow, politically defined “duty of care” scope, so there is
Fediverse reactions
-
My delightful discovery of the day is that not only does the word ‘pudding’ derive (roughly) from French blood sausage, but also there is a Korean blood sausage called ‘sundae’
You can’t make this stuff up: https://en.wikipedia.org/wiki/Sundae_%28sausage%29 See also the history of “black pudding” and “boudin noir”.
Fediverse reactions
-
“Processing an audio stream in a maliciously crafted media file may result in code execution”
About the security content of iOS 18.4.1 and iPadOS 18.4.1 – Apple Support Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS. https://support.apple.com/en-us/122282
Fediverse reactions
-
London Security Engineering Meetup: Alec Muffett “End to End Encryption: Why You Should Implement It” (May 08, 1800h)
Join us for the May edition of the London Security Engineering meetup at Wise’s London offices! We are thrilled to host Alec Muffett, a distinguished technologist and security consultant with over 30 years of experience in cryptography and security. https://www.meetup.com/london-security-engineering-group/events/307320393/ I’m going to try something a little more experimental with this presentation, aiming avoid slides and
Fediverse reactions
-
MITRE / CVE is being killed by the Trump Government
This is incalculable harm to coordination of infosec response; via Brian Krebs: MITRE has announced that its funding for the Common Vulnerabilities and Exposures (CVE) program and related programs, including the Common Weakness Enumeration Program, will expire on April 16. The CVE database is critical for anyone doing vulnerability management or security research, and for
Fediverse reactions
-
Google rolling out auto-restart security feature to Android phones | One of the things I really love…
…about companies attempting to copy and outdo each other in terms of individual privacy protection, is that this bar-raising exercise is very much in the spirit of improving security for everybody, in spite of what various government might think is in their own narrow best interest: https://9to5google.com/2025/04/14/android-auto-restart-security/
Fediverse reactions