Skip Navigation
Rep. Jamaal Bowman loses New York primary to pro-Israel George Latimer, most expensive primary race ever
  • "Fine, if you're not going to vote Biden, at least vote down ballot. Primaries and local offices are the next wave of politicians."

    [Funds into primaries to remove progressives from office, backs conservatives because of "electability".]

    "Oh uh, sorry. By the way this is you, the pleb's fault, not the rich we gladly accept. Maybe next year we won't pull the football out of the way when someone pays us to?"

  • Windows 11 is now automatically enabling OneDrive folder backup without asking permission
  • If Recall went through, so much for "it's all localized and offline."

    I understand its (currently) not happening, but if Microsoft was able to deflect the criticism long enough, and since no company makes a change like this overnight (The time to approve of the privacy policies, shifting of storage for it, the increased traffic on their servers needing to be accommodated), can you imagine just having it still installed and enabled by default?

  • Blaming Trump for 'combustible atmosphere,' prosecutors to push for gag order in classified docs case - ABC News
  • We only got Al Capone due to tax evasion, and even Trump gets around that! The fucking mafia committing crimes has to worry about the IRS more than dipshit orange fuck Trump.

    Again, can we call ourselves a democracy when one of the "only" choices is a convicted felon who tried to coup the government? Because there's a word for when the "the worst, least qualified, or most unscrupulous citizens" run the joint, it's Kakistocracy.

  • Prosecutors say gag order is needed to keep Trump from inviting 'violent act' on law enforcement - ABC News
  • Jesus Christ can we just lock him away? Why does he get to run for office, get more money for being a charged criminal, while us plebs have to worry about cops shooting first and asking questions later?

    Gag him, but it won't do dick when he's already been gagged and violated it, and courts take forever for the richest and most corrupt fuckers on the planet. He needs to be in jail for his crimes. (Yes I know you can run for office from jail, Eugene V. Debs did it when he was arrested for protesting the draft of WW1.)

  • Prosecutors say gag order is needed to keep Trump from inviting 'violent act' on law enforcement - ABC News
  • Rape jokes aren't cool even if its prisoners or male on male. Jesus Christ.

  • Pentagon ran secret anti-vax campaign to undermine China during pandemic
  • “I don’t think it’s defensible,” said Daniel Lucey, an infectious disease specialist at Dartmouth’s Geisel School of Medicine. “I’m extremely dismayed, disappointed and disillusioned to hear that the U.S. government would do that,” said Lucey, a former military physician who assisted in the response to the 2001 anthrax attacks.

    In 2019, Trump authorized the Central Intelligence Agency to launch a clandestine campaign on Chinese social media aimed at turning public opinion in China against its government, Reuters reported in March. As part of that effort, a small group of operatives used bogus online identities to spread disparaging narratives about Xi Jinping’s government.

    U.S. military leaders feared that China’s COVID diplomacy and propaganda could draw other Southeast Asian countries, such as Cambodia and Malaysia, closer to Beijing, furthering its regional ambitions.

    A senior U.S. military commander responsible for Southeast Asia, Special Operations Command Pacific General Jonathan Braga, pressed his bosses in Washington to fight back in the so-called information space, according to three former Pentagon officials.

    By summer 2020, the military’s propaganda campaign moved into new territory and darker messaging, ultimately drawing the attention of social media executives.

    In regions beyond Southeast Asia, senior officers in the U.S. Central Command, which oversees military operations across the Middle East and Central Asia, launched their own version of the COVID psyop, three former military officials told Reuters.

    Although the Chinese vaccines were still months from release, controversy roiled the Muslim world over whether the vaccines contained pork gelatin and could be considered “haram,” or forbidden under Islamic law. Sinovac has said that the vaccine was “manufactured free of porcine materials.” Many Islamic religious authorities maintained that even if the vaccines did contain pork gelatin, they were still permissible since the treatments were being used to save human life.

    The Pentagon campaign sought to intensify fears about injecting a pig derivative. As part of an internal investigation at X, the social media company used IP addresses and browser data to identify more than 150 phony accounts that were operated from Tampa by U.S. Central Command and its contractors, according to an internal X document reviewed by Reuters.

    Facebook executives had first approached the Pentagon in the summer of 2020, warning the military that Facebook workers had easily identified the military’s phony accounts, according to three former U.S. officials and another person familiar with the matter. The government, Facebook argued, was violating Facebook’s policies by operating the bogus accounts and by spreading COVID misinformation.

    The military argued that many of its fake accounts were being used for counterterrorism and asked Facebook not to take down the content, according to two people familiar with the exchange. The Pentagon pledged to stop spreading COVID-related propaganda, and some of the accounts continued to remain active on Facebook.

    Nonetheless, the anti-vax campaign continued into 2021 as Biden took office.

    Angered that military officials had ignored their warning, Facebook officials arranged a Zoom meeting with Biden’s new National Security Council shortly after the inauguration, Reuters learned. The discussion quickly became tense.

    “It was terrible,” said a senior administration official describing the reaction after learning of the campaign’s pig-related posts. “I was shocked. The administration was pro-vaccine and our concern was this could affect vaccine hesitancy, especially in developing countries.”

  • Good = Boring = No Corporate News Story
    • Freeing Mexican citizens locked in cages at the border, but has in fact increased the numbers according to the ACLU, and now limiting the numbers of who can come in like fascist Trump wanted
    • The COVID pandemic is still ongoing, we're just ignoring it while I've had friends die from it after it was "over" according to the CDC. Also removing the 14 day expected leave for it to improve companies fucking over sick and healthy workers alike the economy
    • Roe v Wade being reinstated, for the party that "cares about women's rights".
    • Minimum Wage increases (Yes Congress is in charge of the purse, but can he say "please fucking do it so everyone has better income?")
    • Ran on trying to stop cops from shooting innocent civilians, but in his first State of the Union said "We don't need to defund the police, we need to fund the police!" to bipartisan roaring applause. I know he has a fucking cop as a VP, but god damn.
    • And he's not doing anything to stop Project 2025 from getting into place if Trump wins.
    • Could maybe consider giving new arms to Ukraine and stop funding explicit genocide in Palestine.
    • Didn't help the unions during the rail strikes give into the demands for better worker safety and benefits, blocking it like how Reagan blocked the FAA from striking for safety and benefits
    • Still allows Trump-era expansions of spying agencies, that was made public under "constitutional lawyer and defender" Obama, and instated under Dubya.

    But we don't have the President saying stupid shit on Twitter every day, so I guess that means we're back to a sane normal, or whatever white cishet liberals need to say to sleep well at night. Ignore the bloodshed of BIPOC and queers, women and their doctors fleeing red states over being arrested for bodily autonomy, and that white nationalists just goosestep freely because its not respectable to tell fascists to fuck off and die, it doesn't impact you, so it's all sane politics and electable!

  • "Criticizing the President is criticizing America, and criticizing America is criticizing me!" Conservatives in 2004, Liberals in 2024

    If you confuse criticism of citizens as criticism of the government, you're probably some kind of racist. You can just call out the government and not say it's the fault of the citizens directly.

    If you confuse criticism of your government with criticism of yourself as a person, and it's a personal attack, you're a nationalist. If your leader said a bad take where people call it out and you consider it as if you personally said it, maybe stop being a form of parasocial weirdo for a politician who doesn't know your name beyond "dipshit voter who will defend his actions"

    You can mock my government, it's not mocking me. You can mock me, it's not mocking my government. You can mock both.

    When the person I voted for does a bad thing, I consider it a moral failing on them and a lesson for me to do better research on who I support.

    I don't understand why that's such an issue.

    4
    Good = Boring = No Corporate News Story
  • Sure, I agree that it should be brought up more, and that Trump gets endless free airtime even from liberal news outlets. But it's just wild to go "No one remembers or talks about these, the media ignores it!" while we're talking about it and the good it has done.

  • Good = Boring = No Corporate News Story
  • But they did make headlines, that's how we know about these. The FTC and FCC doing their job more is good and makes headlines.

    It's good, don't get me wrong. But man it feels like table scraps compared to a lot on what Biden ran on in 2020.

  • From an unironic liberal tumblr blog, "yes he sucks and broke every promise, but come on, youre not going to vote trump, so dont worry"
  • And I'd just like a president who doesn't break promises, protects women's rights, fights against a corrupt court, didn't lock up more Mexicans at the border, raised the minimum wage, protected the EPA, didn't claim COVID is over while people are still dying...

    "But that's Congress' job!" And yeah sure it is, but has he ever fucking asked Congress to do these things? Has he been vocal consistently about it like progressives want him to? Nope. He won't be.

    When you vote for lesser evil, you get evil.

  • From an unironic liberal tumblr blog, "yes he sucks and broke every promise, but come on, youre not going to vote trump, so dont worry"

    Yeah because I'm not going to vote for Orange Dipshit doesn't mean Biden lying and breaking promises is somehow valid and cool and good. Blue MAGA is awesome!

    12
    Biden campaign picks right-side podium for CNN debate, Trump will have the last word - ABC News
  • "He's murdered people and failed to protect the rights of Americans."

    "Uhh... so?"

    God do you people just like to sound like dismissive pricks to bloodshed or is it second nature to selling your soul to a party?

  • Coke—and Dozens of Others—Pledged to Quit Russia. They’re Still There.
  • Can't buy products if the products aren't for sale. That's why they keep doing it. It lets people blame the Russian government and people on buying it and the American government and people for failing prohibiting the sale of it.

    When the simple solution is: Don't allow companies to sell products to your enemies when it's war.

  • The Supreme Court has a lot of work to do — and little time to do it
  • Dred Scott is considered what directly lead to the Civil War. But god this one is close to that much of a fuck up.

  • Far-Right Militias Are Back
  • Of course they're back, they've been back since the 1960s, or 1910s if you wanna go back slightly further.

    And as a reminder: Modern gun control laws were started because the Black Panthers also trained and learned to defend themselves from far right militias to express the right to vote and free speech. We didn't start doing anything when the KKK locked and loaded, only when people started defending themselves from the KKK.

  • Biden campaign picks right-side podium for CNN debate, Trump will have the last word - ABC News
  • 2024: "Not Trump"

    2020: "Not Trump"

    2016: "Not Trump"

    God I'm tired of it. I know its the better option, lesser of two evils, I'm going to vote for Biden if I live to November, but we act shocked when we get evil when we vote for lesser evil.

  • US sues Adobe for ‘deceiving’ subscriptions that are too hard to cancel | The Justice Department alleges that Adobe hid early cancellation fees and trapped consumers in pricey subscriptions
  • It doesn't help Adobe has software patents for their products, so anyone who makes a similar program has to either live in a country that doesn't recognize the "right" to claim you invented math, or be risk being sued.

  • Comrades, is mocking conservative bumpster stickers the same as being a liberal in 1930s Germany?

    "Sometimes, someone posts an angry response to some terrible opinion I've never heard before, and it's a weird indirect way to learn how awful their other friends must be."

    14
    Did you know: If you criticize Biden you're not American, and if your Mastodon ends in .eu you're not allowed to have an opinion?

    What made them mad:

    > "Man I'm not happy with Biden winning the nomination. I wish I was Bernie."

    > "Well we can get Trump out of office and then you can push him to the left."

    > "Fair enough, a moldy ham sandwich is better than Trump. Biden can string words together so that's possible."

    > [One presidential election and mid-term later.]

    > "So Biden hasn't pushed Congress on most of his campaign promises, and he's enabled racist policies Trump wanted to try and win moderates. No abortion, no DREAMers, no minimum wage increases, no queer protection, but they can find time to ban hoodies in Congress. Not to mention ignoring voters who care about Ukraine and Palestine. It feels like Biden isn't great for Americans, he's just slightly better than Trump."

    > "Why are you so anti-Biden? Are you some kind of fake leftist or a Russian agent pretending to be American?"

    > "No? I'm trying to push him left. I'm saying he's not doing things for most of the people who voted for him to be better. His biggest actions are done by appointments, by him to the FTC and FCC. Not a lot of bills passed."

    > "I think you just hate what Democracy is, he's not a king."

    > "Right. But Republicans can pass without issue, and Democrats want to work with them instead of getting progressive voters."

    > "You're biased and nitpicking, so I win."

    11
    Ukraine says hackers abuse SyncThing tool to steal data
    www.bleepingcomputer.com Ukraine says hackers abuse SyncThing tool to steal data

    The Computer Emergency Response Team of Ukraine (CERT-UA) reports about a new campaign dubbed "SickSync," launched by the UAC-0020 (Vermin) hacking group in attacks on the Ukrainian defense forces.

    Ukraine says hackers abuse SyncThing tool to steal data
    27
    The California McDonald's rumor is coming from a digital ghost - The writer boosting McDonald's misinformation probably doesn't exist.

    You probably haven’t heard the name Tony Bonnani, but he’s one of the most prolific writers on the internet. He publishes several articles a day, often churning out pieces within minutes of each other. Compared to most journalists, Tony Bonnani writes at a superhuman pace.

    There’s one other interesting thing about Bonnani: He probably doesn’t exist. His name, face and stories appear to be the products of a content farm headquartered at a Connecticut shopping center. And one of his stories may have convinced thousands of people that they’d never be able to eat a Big Mac in California ever again.

    The culture war comes for the Big Mac

    In recent weeks, misinformation about chain restaurant closures has proliferated on social media. Rumors that Chili’s and Fuddruckers were going out of business gained enough traction to prompt both chains to issue responses.

    But perhaps most perplexing of all is the rumor that McDonald’s is shutting down its California locations. The Google search term “McDonald’s leaving California” began trending two days ago. This morning, it briefly eclipsed “Giants” and “Warriors” as search terms. A quick Google search of the phrase yields a flurry of YouTube videos speculating about the chain’s exodus.

    “MCDONALD’S TO SHUTDOWN IN CALIFORNIA……. (SHOCKING)” reads the title of one video with 50,000 views, uploaded two days ago.

    Another video, with more than 400,000 views, takes a more moderate approach: “Another Scandal Hits California While McDonald’s Considers Leaving the State.”

    On Google News, searching the term dredges up a few recent articles about individual franchisees struggling to manage costs with the state’s minimum wage increase. But only one article, which was picked up by MSN, has a headline suggesting that the chain is actually leaving the state: “McDonald’s on the verge of CLOSING in California After $20 Minimum Wage.”

    Although the link still pops up on Google, the webpage for the article no longer exists. MSN, which is Microsoft’s news aggregator, likely took it down. MSN does not produce content of its own, but recirculates articles submitted by its content partners, which have syndication agreements with the service.

    SFGATE traced that article back to an outlet called UnitedLiberty, which has more than 20,000 followers on MSN. The website churns out formulaic articles with a conservative slant, populated by short paragraphs and generic photos. Most list a single YouTube video for a source, like the story “9 Self-Defense Tactics Against Violent Mobs That Won’t Land You In Jail,” which cites a video by a channel called Armed Attorneys.

    Some headlines, like “3 Supreme Court Justices Recuse Themselves From Election Case,” are blatant misinformation. Others, like the McDonald’s headline, are misleading. Many are simply incendiary: “RFK Jr OPPOSES Gun Ban, Argues Guns ARE NOT To Blame For Violence.”

    The McDonald’s closure story cites a video from a YouTube channel called Market Gains, which is likely the source of the rumor. (SFGATE reached out to McDonald’s for comment, but did not receive a response in time for publication.) The video was posted seven days ago, and although its title suggests that the franchise is closing its California locations (“McDonald’s Is Suddenly CLOSING In California After $20 Minimum Wage”), the video is actually a summary of several news articles discussing individual franchisees’ struggles to balance costs, like this piece from Fox Business.

    The text of UnitedLiberty’s article is different from the Market Gains video, but the titles are nearly identical. The article’s text, unlike its headline, does not suggest that the chain is on the verge of leaving the state, but given the panic that has ensued, many people didn’t read beyond the headline.

    The talented Mr. Bonnani

    Most of the site’s articles, including the McDonald’s closure piece, are written by an author named Tony Bonnani. Yesterday, 12 articles were published under his name, several within the span of a minute. The previous day, Bonnani “wrote” five articles, and about 10 more the day before that.

    For such a prolific writer, Bonnani is a digital ghost. Searching his name yielded only links to his articles, nothing more. His author photo appears nowhere else on the web. TrueMedia, a tool for fighting A.I.-manipulated content, rated Bonnani’s headshot as “highly suspicious” for use of generative AI.

    Using fake human authors to push out AI-generated is not a new phenomenon. Last year, Sports Illustrated deleted the profiles of several fake writers after it was caught publishing AI-generated articles.

    On its own, this steady churn of garbage content would be banal, if a tad depressing. But UnitedLiberty is not an isolated node in the information ecosystem. MSN has a wide readership, showing up by default on Microsoft web browsers and products.

    Although UnitedLiberty’s article did not spawn the rumor, it played a role in circulating it. UnitedLiberty helped the rumor cross over from YouTube to digital news, accelerating its spread. This created a feedback loop of sorts; the aforementioned 400,000-view YouTube video cites Bonnani’s article, and includes several screenshots of the article on MSN before it was taken down.

    David Harris, a lecturer on AI ethics and social media at UC Berkeley and former misinformation researcher at Meta, referred to the proliferation of this type of low-grade content as the “ens—ttification of the internet,” a term coined by journalist Cory Doctorow to describe the decay of internet platforms.

    “The internet is filling up with s—t, and it’s really bad for our societies,” Harris told SFGATE. “It’s not just a minor irritation, like the junk mail flyers that I still seem to get every week in my actual mailbox. It’s a major, major threat to our information environment and our democracy.”

    In his research, Harris said he’s noticed many fake news websites similar to UnitedLiberty that produce content at “inhuman rates.” Some even include summaries of his own published articles, scraped without his permission.

    It’s unclear how this sort of content arrived on a publisher like MSN, though it’s not the first time MSN has published misinformation. In October, MSN disseminated a false story that San Francisco Supervisor Dean Preston had resigned after a fight with Elon Musk.

    SFGATE reached out to MSN to find out how stories like UnitedLiberty’s end up on its site but did not receive a response by the time of publication. However, we did hear back from Bonnani’s boss.

    ‘Good writers are VERY hard to find’

    UnitedLiberty is part of a company called Get Media, LLC, headquartered in a Connecticut shopping center. Public records obtained by SFGATE list a Connecticut man named Kris Lippi as the principal of Get Media, LLC.

    UnitedLiberty also shares an IP address with three other websites: Boomers Remember, ISoldMyHouse and Circle Squared. All three websites also feature writing by authors who churn out articles at astonishing rates. All three are run by LLCs that list Lippi as their principal. And in public records, all three list their headquarters in the same shopping center, within a stone’s throw of a dentist’s office and a Thai restaurant.

    Like UnitedLiberty, ISoldMyHouse has a syndication agreement with MSN. While some ISoldMyHouse and UnitedLiberty articles draw little engagement on the platform, others draw thousands of likes and comments.

    Article continues below this ad In recent weeks, misinformation about chain restaurant closures has proliferated on social media. Rumors that Chili’s and Fuddruckers were going out of business gained enough traction to prompt both chains to issue responses.

    In recent weeks, misinformation about chain restaurant closures has proliferated on social media. Rumors that Chili’s and Fuddruckers were going out of business gained enough traction to prompt both chains to issue responses. Photos via Getty; Illustration by SFGATE

    Tony Bonnani published a second article about McDonald’s leaving California on May 27. That article was picked up by MSN on May 30, and remains on the site as of publication.

    The article cites a YouTube video, titled “80% of American’s Can’t Afford Fast Food | McDonalds Leaving CA,” as its only source. And that video cites Bonnani’s original article multiple times.

    The snake is eating its own tail. Lippi’s articles scrape YouTube videos. YouTubers then cite those articles, and new articles scrape those videos for new content. This ens—ttification feedback loop amplifies misinformation, creating an echo chamber loud enough to influence Google Trends.

    When SFGATE reached out for comment, Lippi denied that AI was involved in the production of the articles. He referred to Bonnani and the other prolific authors on his sites as “freelance writers.”

    “I’m not sure how you would do a news story with AI because it’s my understanding the knowledge is only current to a certain date in the past,” he wrote in an email to SFGATE.

    SFGATE asked twice to be put in touch with Bonnani. Both times, Lippi declined.

    When pressed on the rapid clip of Bonnani’s output, Lippi replied that the multiple articles published within the span of a minute were pre-written and scheduled for simultaneous publication. Then, he extended a job offer.

    “I must say, I do appreciate your hustle, and if you would like to freelance for me, let me know and maybe we could work something out,” he added. “Good writers are VERY hard to find.”

    May 31, 2024

    19
    Portable workspace, what is the best solution?

    Here's the basics of my set up for what I can bring around:

    • A Crucial 1TB M.2 Drive
    • A M.2 Drive Enclosure that has USB 3.1 Gen 2 output So with these together are desktop performance in a small thing. It is not a flash drive that just gets ruined in like 3 months of constant use.

    And with these, I use a Ventoy set up called Medicat. I love it, and there's no issue with it for me, besides that Medicat/Microsoft requires NTFS for Windows stuff. Aside from standard NTFS bullshit, it's wonderful.

    Since I have so much space, I had the idea of storing a Linux set up for on the go use on any laptop/computer without needing to sign into 10 websites for one time use. Here's my two methods of how to do it:

    • Make a persistent data block for Fedora/Ubuntu/etc. and make a Live ISO point to it, then boot from Ventoy into the ISO, which then handles mounting the "drive".
    • Clear a space on the drive, install a distro like Fedora/Debian and encrypt it, allowing me to just run apt upgrade and move on like a normal PC.

    Here's the upsides and downsides to both that I can see, just thinking about it.

    Persistence:

    • ✅ Don't need to fuck with partitions of NTFS, last time I tried to shrink the drive NTFS had a breakdown and I couldn't fix it.
    • ✅ Can expand the persistence as time goes on
    • ❌ NTFS constantly has issues with me, where I can cleanly eject the drive but I need to run ntfsfix to make it work again, and I don't know when that will happen in the future.
    • ❓ Not sure how it will go with Arch Linux, but that might be a bad choice for a drive I boot into for fun/infrequently.

    Partition and full install:

    • ✅ Easier to just get going, point an ISO to install there and good to go.
    • ✅ Easier to upgrade to new packages/editions, instead of downloading new ISOs and pointing it each time. I'm unsure if it would let me use a .dat file from Fedora 36 for Fedora 40, for example.
    • ✅ I can encrypt it so I don't need to worry about people nabbing it and messing with personal files.
    • ✅ I can use something like ext4 or btrfs, so I don't need to rely on NTFS.
    • ❌ Trying to resize NTFS was really fucky, and felt like I was breaking something. I did break it, and had to reinstall Medicat/Ventoy.
    • ❓ I'm unsure of how to boot from it and keep Medicat/Ventoy as the main option. Maybe create a file on Ventoy to boot the distro? Maybe it varies from BIOS to BIOS?

    Wanting to hear the thoughts from people smarter than me, maybe have done this before. I just want to make it clear It's not a USB flash drive, this won't break randomly from one too many R/Ws.

    17
    How to use a portable SSD for a travel OS with Linux?

    Hello! The TL;DR is:

    I have an m.2 drive that is in a sturdy enclosure that has 1 TB. I have Ventoy with Medicat on there, with some backups of important data.

    I still have a lot of room left on there, so I was thinking what else I could do, and the idea of basically installing a Linux Distro to a chunk of free space on there. Maybe Debian/Fedora or Arch.

    Is there anything I should be aware of to help not break that system or rapidly kill the drive? It's not a USB flash drive, it's a M.2 drive that's put on a small board that then allows it to talk via USB C/Thunderbolt.

    EDIT: Just to be sure, if I use Ventoy's EFI, do I need to be worried about a conflict with the bootloader of the Linux install?

    14
    LogoFAIL - A malicious attack that uses the company branding on boot to run deep code that Secure Boot and Operating Systems can't detect
    www.securityweek.com Enterprise, Consumer Devices Exposed to Attacks via Malicious UEFI Logo Images

    LogoFAIL is an UEFI image parser attack allowing hackers to compromise consumer and enterprise devices using malicious logo images.

    Enterprise, Consumer Devices Exposed to Attacks via Malicious UEFI Logo Images

    Firmware security company Binarly on Wednesday disclosed the details of an attack method that can be used to compromise many consumer and enterprise devices by leveraging malicious UEFI logo images.

    The attack method, dubbed LogoFAIL, exploits vulnerabilities in the image parsers used by the UEFI firmware to display logos during the boot process or in the BIOS setup. Getting the affected parsers to process a specially crafted image can enable the attacker to hijack the execution flow and run arbitrary code.

    Hackers can use the LogoFAIL attack to compromise the entire system and bypass security measures such as Secure Boot.

    “These vulnerabilities can compromise the entire system’s security, rendering ‘below-the-OS’ security measures like any shade of Secure Boot ineffective, including Intel Boot Guard. This level of compromise means attackers can gain deep control over the affected systems,” Binarly explained.

    Binarly’s analysis showed that UEFI vendors use various types of parsers for BMP, PNG, JPEG, GIF and other types of images. The security firm’s research targeted firmware from Insyde, AMI and Phoenix and led to the discovery of two dozen vulnerabilities, more than half of which have been assigned a ‘high severity’ rating.

    The impacted firmware is shipped with hundreds of consumer and enterprise computer models — including x86 and ARM-based devices — made by companies such as Acer, Dell, Framework, Fujitsu, Gigabyte, HP, Intel, Lenovo, MSI, Samsung, and Supermicro. This means millions of devices worldwide could be exposed to attacks.

    A LogoFAIL attack can be launched by abusing the firmware update procedure to replace the legitimate logo with a malicious version. Attacks through physical access may also be possible, using an SPI flash programmer, assuming that the logo is not protected by hardware verified boot technologies.

    Some vendors — this includes Intel, Acer and Lenovo — offer features that enable users to customize the logos displayed during boot, which can make it possible to launch LogoFAIL attacks from the OS, without the need for physical access to the device.

    It’s important to note that while image parser vulnerabilities have been found in devices from all of the aforementioned vendors, they cannot always be exploited. In Dell’s case, for instance, the logo is protected by Intel Boot Guard, which prevents its replacement even if the attacker has physical access to the targeted system. In addition, Dell does not offer any logo customization features.

    Details of the attack were presented by Binarly at the Black Hat Europe conference on Wednesday, and the company has published a technical blog post describing its findings.

    The security firm has published a video showing a proof-of-concept (PoC) LogoFAIL exploit in action, demonstrating how an attacker who has admin permissions on the operating system can escalate privileges to the firmware level.

    The vulnerabilities were reported to impacted vendors through CERT/CC several months ago, but it can take a lot of time for patches for these types of security holes to reach end devices, even if vendors create the fixes.

    8
    New Outlook update sends passwords and mails on private servers to MS. Ulrich Kelber, TheCommissioner for Data Protection of Germany plans to submit inquires on Tuesday
    www.heise.de Microsoft lays hands on login data: Beware of the new Outlook

    The free new Outlook replaces Mail in Windows, and later also the classic Outlook. It sends secret credentials to Microsoft servers.

    Microsoft lays hands on login data: Beware of the new Outlook

    Microsoft is singing the praises of the new Outlook and wants to persuade users to switch. But beware: if you try out the new Outlook, you risk transferring your IMAP and SMTP credentials of mail accounts and all your emails to Microsoft servers. Although Microsoft explains that it is possible to switch back to the previous apps at any time, the data will already be stored by the company. This allows Microsoft to read the emails. Start menu shows new Outlook as recommended app

    The new Outlook now appears as a recommended app in the Windows Start menu of Windows 11 devices with the 2023 update. The Outlook client itself also offers to test the new Outlook version with a "The new Outlook" switch. This is still under development, but is set to replace the mail program and the calendar included in Windows in 2024. In a recent tech community article, Microsoft employee Caitlin Hart also explains that it will also replace the classic Outlook. However, unlike the Windows Mail and Calendar apps, the timetable for this has not yet been set.

    When adding a mail account in the new Outlook that is not hosted by Microsoft but is located on company mail servers, for example, the program displays a message. It links to a support article that simply states that non-Microsoft accounts are synchronized with the Microsoft cloud, whereby Gmail, Yahoo, iCloud and IMAP accounts are currently supported. The new Outlook also does this in the versions for Android, iOS and Mac. This means that copies "of your email, calendar, and contacts will be synchronized between your email provider and Microsoft data center". This gives the company full access to all emails and allows it to read and analyze them. Microsoft wants to provide functions that way that Gmail and IMAP do not offer. Warning message of the new Outlook version when adding a non-Microsoft account

    The note makes you wonder: What does Microsoft transfer where? When creating an IMAP account, c't was able to sniff the traffic between new Outlook and the Microsoft servers. It contained the target server, log-in name and password which were sent to those Servers of Microsoft. Although TLS-protected, the data is sent to Microsoft in plain text within the tunnel. Without informing or inquiring about this, Microsoft grants itself access to the IMAP and SMTP login data of users of the new Outlook.

    When switching from the old Outlook to the new one, it is installed the new software in parallel. Previously set up IMAP accounts are not automatically transferred, but the account stored in Windows is. During the test with Google accounts, authentication with OAuth2 was used. Users receive an authentication request and Microsoft does not receive any specific access data, but only an access token that users can revoke again.

    An answer to our request for a statement from Microsoft is still pending. At this point in time, however, we must warn against trying out the new Outlook without thinking. In addition to all the emails, some credentials may even end up with Microsoft.

    Microsoft already attracted attention with such data redirections at the beginning of the year. After Office updates were applied on Mac computers, Outlook redirected the data to Microsoft's cloud servers without any user notification. At that time, the remedy was to delete IMAP accounts and set them up again. However, this is obviously no longer helpful with the new Outlook.

    The Federal Commissioner for Data Protection and Freedom of Information of Germany, Professor Ulrich Kelber, is alarmed by the data detour in Microsoft's new Outlook. He posted on Mastodon that he wants to ask for a report from the Irish Data Protection Commissioner, who is responsible for companies like Microsoft, during a meeting of the European data protection supervisory authorities on Tuesday of the coming week.

    17
    Is there a Linux based OS for public computers, such as at a library or a PC cafe?

    Title. Mainly asking for the library side, but PC cafe is also interesting to ask about.

    Mainly since Windows 11 is 64-bit only, and it seems Windows 12 is going to subscription based on top of that, neither of which public libraries can afford tossing out computers and paying more in subscription fees than they make with overdue books.

    My local library is only open for 2 days a week, due to a lack of funds for hiring more staff in the area. They use older Dell all in ones, and that just makes me think if they don't have the money for being open 5 days a week, they don't have the money to buy 4 new computers for the space.

    Not even getting into the bigger libraries part of that system or the ones nearby. Some have 8 computers in groups, with 4 stations of groups.

    So I was just wondering, if anyone has started or is aware of a Library/Public Computer focused linux-based OS? Perhaps one that allows immutable systems, and the library card system backed most use to enable end user access. Perhaps that's a config file tucked away somewhere.

    And I guess the PC cafe OS is interesting, simply due to the fact that Linux gaming has been making huge strides, and PC cafes are still popular in Japan, Korea, and China.

    EDIT: I am not in control or assistance to the library, just looking if there's a potential solution to libraries like mine. If I could give links to a library computer manager, or if I could give upstream bug reports to people making such software.

    114
    queue Queue @lemmy.blahaj.zone

    Thoughts intrusive, ass protrusive, trans inclusive

    Things people have claimed I work for, on the payroll, or are some kind of propaganda agent.

    Russian bot: 11

    Chinese Communist Party: 6

    Central Intelligence Agency: 11

    Democrat Party/DNC: 6

    Republican Party: 6

    Bernie Bro: 9

    Posts 12
    Comments 379