TheZero

Security Researcher & Pentester @ShielderSec@infosec.exchange
~ Curiosity-driven ~ Hate the indifferent.
Tweets are my own

TheZero boosted:
End Israeli ApartheidEndIsraeliApartheid
2025-06-10

A Palestinian photojournalist was killed in an Israeli attack in Gaza, taking the death toll of journalists since October 2023 to 227.

Momen Abu Alof, was killed along with three ambulance workers by Israeli fire during a humanitarian mission in eastern Gaza City.

The office strongly condemned “the systematic targeting, killing, and assassination of Palestinian journalists by the Israeli occupation.”

aa.com.tr/en/middle-east/pales

🕎 🇵🇸 ☮️

TheZero boosted:
2025-06-10

Dear USA

Deploying troops against civilians will not go well.

Yours
Great Britain and Northern Ireland

TheZero boosted:
Osservatorio Nessuno0n_odv@mastodon.cisti.org
2025-06-09

Il rapporto del COPASIR sul caso Graphite solleva nuove domande.
Il trattamento che è stato riservato a giornalisti e attivisti è inaccettabile in uno stato democratico.
Chiediamo trasparenza, responsabilità e risposte concrete al problema della sorveglianza di stato.

osservatorionessuno.org/it/blo

TheZero boosted:
2025-05-16
TheZero boosted:
2025-05-16

Thanks for the find [1], @privacyguides !

Seems that using #GrapheneOS isn't a bad idea.

> #Cellebrite, as far as we know, publishes a support matrix for Android-based and iOS-based devices monthly or at least multiple times a year. The latest version available at time of writing is version 7.73.1 released on February 2025.

Secondary source: Osservatorio Nessuno [2]

[1]: discuss.privacyguides.net/t/up
[2]: osservatorionessuno.org/blog/2

#Cellebrite #GrapheneOS #Android #Encryption #E2EE #DataPrivacy

Cellebrite report: Android OS access matrix for Googgle Pixel devices from Pixel 6 to Pixel 9:
BFU: Before First Unlock
AFU: Afer First Unlock
FFS: Full File System Extraction
BF: Brute Force
SPL: Security Patch Level
TheZero boosted:
2025-05-16

> Pixel devices remain quite a solid choice if kept updated. While it seems that for the standard Google ROM there are working exploits available to perform the FFS extraction in AFU state, on the contrary GrapheneOS additional hardening and protections are effective, and have been so since 2022 [1].

[1]: osservatorionessuno.org/blog/2

#Cellebrite #GrapheneOS #GooglePixel #Encryption #DataPrivacy #Android

TheZero boosted:
Peter Rileypeterjriley2024
2025-05-16

Digital Prison
Serbian authoritarians deploy technology and digital repression tactics as instruments of wider state control directed against civil society. NSO Group’s with Android & UFED mobile forensics tools against environmental activists and protest organisers.
amnesty.org/en/documents/eur70

TheZero boosted:
Jan de Mooijjandem
2025-05-15

We found an Apple Silicon CPU issue with FJCVTZS, the "JS-compatible double-to-int32 conversion" instruction that was added to ARMv8.3.

If the Flush-to-Zero flag is set in the FPCR register and FJCVTZS is used with a denormal, my M1 sets the Zero flag to 1 and M2-M4 CPUs set it to 0. This flag indicates whether the conversion was exact. I believe M1 is correct?

Test case: gist.github.com/jandem/e6b5660

TheZero boosted:
2025-01-16

🚨 New Open Source Audit Alert! 🚨

Shielder, with @OSTIF & @cloudnativefdn, audited @karmada_io:
🔍 6 issues found (1 high, 1 medium, 2 low, 2 info)
✔️ Most fixed, others planned.
🗣️ to @suidpit and @thezero

Full details in the blog post!

shielder.com/blog/2025/01/karm

TheZero boosted:
2025-01-12

*Someone* seems keen to delete Wikipedia's article on Appin, the cyber mercenary firm we wrote about last year:

en.wikipedia.org/wiki/Wikipedi

TheZero boosted:
2025-01-12

The second edition of TumpiCon is here!
📅 June 27-28, 2025
📍 Somewhere near Turin, Italy
🔒 Invite-only

No flashy stages. No fluff. Just raw, technical, and unfiltered hacking.
More details? If you know, you know.
Follow the trail: tumpicon.org

TheZero boosted:

@munin

For those who must use Windows 11 - here is how to disable Recall:

- Open a command prompt as Administrator (Local Admin should do)
- Type: Dism /Online /Disable-Feature /FeatureName:Recall

Disclaimer
Do understand and Please Read - This may hinder some features of the new file explorer. Because Microsoft never learns.

For those who must use Windows 11 - here is how to disable Recall:

- Open a command prompt as Administrator (Local Admin should do)
- Type: Dism /Online /Disable-Feature /FeatureName:Recall

Disclaimer
Do understand and Please Read - This may hinder some features of the new file explorer. Because Microsoft never learns.
TheZero boosted:
2024-09-18

Backdooring thousands of pagers with explosives and then mass detonating those devices indiscriminately to injure often random humans does not feel like something any nation should be doing, supporting or celebrating. bbc.co.uk/news/live/cwyl9048gx

TheZero boosted:
Seasons of Jason 🎒killyourfm@layer8.space
2024-09-18

One of the weirdest disconnects happened a few months ago when I received a Mozilla Foundation newsletter about the evils of big corporations building unethical AI. It was a donation appeal so they could gear up to "fight" against companies like OpenAI.

This doesn't seem strange until you consider that Mozilla is currently paying a ChatGPT Enterprise license for all ~1000 of its employees. And encouraging them to use it for productivity, brainstorming, & code.

Yea, it didn't sit well. At all.

TheZero boosted:
Zhuowei Zhangzhuowei@notnow.dev
2024-09-08

Amazon’s $1,600 Astro robot has FOUR CPUs running Linux?!!!

Amazon lists four CPUs in the specs (“2x Qualcomm QCS605, 1x Qualcomm SDA660, 1x processor with Amazon AZ1 Neural Edge”)

iFixit’s teardown shows the Snapdragon 660 (a smartphone CPU) and the Mediatek MT8512 (the CPU from the Echo Show 10)… apparently just to run the tablet at the front!

On another board, there’s the pair of QCS605 octa-core CPUs (likely for image processing).

https://www.ifixit.com/News/70384/amazon-astro-teardown

https://www.amazon.com/Introducing-Amazon-Astro/dp/B078NSDFSB

This is truly Amazon’s Juicero.

TheZero boosted:
q3k :blobcatcoffee:q3k@hackerspace.pl
2024-08-26

Just two days left until the first hearing in Newag's lawsuit against us (Dragon Sector members) and SPS. It will take place on 28.08.2024 at 10:00. In case you've missed it, we're being accused of infringing upon Newag's intellectual property and unfair competition. This is, of course, bullshit and a great example of a SLAPP case.

comic sans, blue: newag
comic sans, black: we sue researchers
TheZero boosted:
Esra'aalshafei
2024-08-26

Pleased to announce the launch of Surveillance Watch, an interactive map and resource that documents the hidden connections within the opaque surveillance industry: surveillancewatch.io/

By mapping out the intricate web of surveillance companies, their subsidiaries, partners, and financial backers, we hope to expose the enablers fueling this industry's extensive rights violations, ensuring they cannot evade accountability for being complicit in this abuse.

TheZero boosted:
Aaron Toponce ⚛️:debian:atoponce@fosstodon.org
2024-08-23

#Bitwarden native mobile apps are finally getting rolled out.

New users will get the native app when first installed from your app store.

Existing users will get gradually rolled out in the coming weeks.

Android users must be on Android 10 or higher. iOS must be on iOS 15.0 or higher.

Older mobile OSes will keep using the existing app, just won't get the new native refresh.

#passwords

TheZero boosted:
2024-05-22

Back in December 2023 our researchers @thezero, @suidpit, and @mindlaess_ performed an audit sponsored by @awscloud and facilitated by @ostifofficial on boost.
It resulted in 7 findings and 15 new fuzzers.
The report is now public, check the details here: shielder.com/blog/2024/05/boos

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst