Jump to content

David H. Lipman

Experts
  • Posts

    21,141
  • Joined

  • Days Won

    255

Everything posted by David H. Lipman

  1. WHAT? No underwater Photography?
  2. Strava heatmap loophole may reveal users' home addresses Strava told the researchers that heat map data isn’t shared unless several users are active in any given area, but the researchers still managed to identify the home addresses of some users via the heatmap. These locations were confirmed using voter registration data. Note that depending on which country you live in, voter data may not be available to use in this manner (or even be available in the first place). While this may all sound very straightforward to do, the actual process involved is fairly involved. As Bleeping Computer highlights, the process is as follows: Collect data on your chosen location for a period of roughly a month. Overlay OpenStreetMaps (an open geographic database maintained by volunteers) at a zoom level which allows for singling out residence addresses. Compare heatmap endpoints and user data accessible from search to establish connections between “high activity points” and home addresses. This, combined with public profiles displaying real names, photographs, and data related to specific activities means that singling out certain users was achievable. A word of caution: the success rate for this kind of needle in a haystack activity is not fantastic. The study mentions that more active users will be potentially easier to track down, but for “average” users of the app the likelihood of being discovered is 37.5%. The paper highlights a few of the ways Strava users can reduce the possibility of falling victim to this attack, but a lot depends on the app developers implementing them or the randomness of your personal circumstances. For example, living in a heavily populated area will go a long way toward blending you into the crowd. Another is large exclusion zones around your home area, to make it impossible to figure out which specific location you’re exiting and entering. You can set your Strava profile to private, and also disable the heatmap feature if you don’t need any of the social features available to you. If you use another form of fitness tracking app, this is the ideal moment to see what data you may be sharing and lock down as needed. Reference: https://anupamdas.org/paper/CONPRO2023.pdf
  3. Please see: Multiple Vulnerabilities in Apple Products ...
  4. Multiple Vulnerabilities in Apple Products Could Allow for Arbitrary Code Execution MS-ISAC ADVISORY NUMBER: 2023-066 DATE(S) ISSUED: 06/21/2023
  5. It looks looks more like a malicious advertisement (aka; malvertisement) because they desire to get control of the account and not already have compromised it.
  6. The important take-away is the use of Dark Patterns. It is this Social Engineering ploy that was at the heart of the Amazon scheme. References: https://en.wikipedia.org/wiki/Dark_pattern https://www.deceptive.design/ https://www.vox.com/recode/22351108/dark-patterns-ui-web-design-privacy https://www.ftc.gov/news-events/news/press-releases/2022/09/ftc-report-shows-rise-sophisticated-dark-patterns-designed-trick-trap-consumers https://www.uxdesigninstitute.com/blog/what-are-dark-patterns-in-ux/ https://pudding.cool/2023/05/dark-patterns/
  7. And... May it be a relatively wet one for the West Coast and South West as well......
  8. FTC Takes Action Against Amazon for Enrolling Consumers in Amazon Prime Without Consent and Sabotaging Their Attempts to Cancel
  9. Maybe but make sure it is secured. It could be a 2cnd choice. If it had not been already enabled, it may be best to be disabled upon your leaving. https://support.microsoft.com/en-us/windows/use-your-windows-pc-as-a-mobile-hotspot-c89b0fad-72d5-41e8-f7ea-406ad9036b85
  10. Asked and answered - no. Why would Malwarebytes sell or give-away the source code for their software which could be used to undermine the efficacy of the anti malware capabilities. Furthermore Malwarebytes' already suffered harm when a competitor stole their signature detection database.
  11. Anybody can buy the Malwarebytes' software.
  12. You may be drawing inferences and faux conclusions. There are many reasons why there are antennae on the roof and in a 13 floor high rise they may implement Verizon VDSL or other technology. You may presume that in an urban setting and within a 13 floor high rise, and on an upper floor, that your cellular reception would be good.
  13. @AdvancedSetup does NOT kid-around when it comes to Scripting.
  14. It doesn't. Notepad is just an Editor. When the file extension is CMD it is supposed that the contents are a series of commands to be interpreted by the Command Processor CMD.EXE and when the file extension is BAT it is supposed that the contents are a series of commands to be interpreted by the Command Processor COMMAND.COM . Thus when you "run" a CMD or BAT file it is considered to be a BATch of interpreted commands. Some are "native" to the particular Command Processor (aka; interpreter) and some are external files. These are external commands known as utilities. Where WMIC and NET are WMIC.EXE and NET.EXE and what follows them are command line options unique to each utility. wmic useraccount where Name="%USERNAME%" set PasswordExpires=false wmic UserAccount set PasswordExpires=False net accounts /FORCELOGOFF:NO net accounts /minpwlen:0 net accounts /maxpwage:unlimited This is an Internal command (native) used in both CMD.EXE and COMMAND.COM pause References: https://en.wikipedia.org/wiki/Interpreter_(computing) https://en.wikipedia.org/wiki/Cmd.exe https://en.wikipedia.org/wiki/COMMAND.COM https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/pause
  15. Edited above. Now create/edit your copy and Run as Administrator again and you'll see how "pause" works in a BAT or CMD process. wmic useraccount where Name="%USERNAME%" set PasswordExpires=false wmic UserAccount set PasswordExpires=False net accounts /FORCELOGOFF:NO net accounts /minpwlen:0 net accounts /maxpwage:unlimited pause
  16. FTC Will Require Microsoft to Pay $20 million over Charges it Illegally Collected Personal Information from Children without Their Parents’ Consent
  17. It worked IFF you ran it as an Administrator.
  18. Create a BAT file with the following and run it as an Administrator wmic useraccount where Name="%USERNAME%" set PasswordExpires=false wmic UserAccount set PasswordExpires=False net accounts /FORCELOGOFF:NO net accounts /minpwlen:0 net accounts /maxpwage:unlimited
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.