#AllowListing

Kevin Karhan :verified:kkarhan@infosec.space
2025-07-15

@stman @Sempf @LaF0rge yes.

Because physical SIMs, like any "cryptographic chipcard" (i.e. @nitrokey ) did all that fancy public/private crypto on silicon and unless that was compromizeable (which AFAICT always necessistated physical access to the #SIM, espechally in pre-#OMAPI devices) the SIM wasn't 'cloneable' and the weakest link always had been the #MNO /.#MVNO issueing (may it be through #SocialHacking employees into #SimSwapping or LEAs showng up with a warrant and demanding "#LawfulInterception"):

Add to that the regression in flexibility:

Unlike a #SimCard which was designed as a vendor-independent, #MultiVendor, #MultiProvider, device agnostic unit to facilitate the the #authentification and #encryption in #GSM (and successor standards), #eSIMs act to restrict #DeviceFreedom and #ConsumerChoice, which with shit like #KYC per #IMEI (i.e. #Turkey demands it after 90 days of roaming per year) und #lMEI-based #Allowlisting (see #Australia's shitty #VoLTE + #2G & #3G shutdown!) are just acts to clamp down on #privacy and #security.

  • And with #EID being unique per #eSIM (like the #IMEI on top!) there's nothing stopping #cyberfacist regimes like "P.R." #China, #Russia, #Iran, ... from banning "#eSIMcards" (#eSIM in SIM card form factor) or entire device prefixes (i.e. all phones that are supported by @GrapheneOS ), as M(V)NOs see the EID used to deploy/activate a profile (obviously they don't want people to activate eSIMs more than once, unless explicitly allowed otherwise.

"[…] [Technologies] must always be evaluated for their ability to oppress. […]

  • Dan Olson

And now you know why I consider a #smartphone with eSIM instead of two SIM slots not as a real #DualSIM device because it restricts my ability to freely move devices.

  • And whilst German Courts reaffirmed §77 TKG (Telco Law)'s mandate to letting people choose their devices freely, (by declarong #fees for reissue of eSIMs illegal) that is only enforceable towards M(V)NOs who are in #Germany, so 'good luck' trying to enforce that against some overseas roaming provider.

Thus #Impersonation attacks in GSM-based networks are easier than ever before which in the age of more skilled than ever #Cybercriminals and #Cyberterrorists (i.e. #NSA & #Roskomnadnozr) puts espechally the average #TechIlliterate User at risk.

  • I mean, anyone else remember the #Kiddies that fucked around with #CIA director #Brennan? Those were just using their "weapons-grade #boredom", not being effective, for-profit cyber criminals!

And then think about those who don't have privilegued access to protection by their government, but rather "privilegued access" to prosecution by the state because their very existance is criminalized...

The only advantage eSIMs broight in contrast is 'logistical' convenience because it's mostly a #QRcode and that's just a way to avoid typos on a cryptic #LocalProfileAgent link.

Kevin Karhan :verified:kkarhan@infosec.space
2025-05-05

@n_dimension @shaknais @maxleibman what kind of facist policestate has it become?

  • Oh nevermind, having an encrypted phone or using secure communications is also illegal, I guess... [1 - 5]

And to enshure "criminals" can't just order something on ShitExpress, they now have an #IMEI-#Allowlisting / #Firewall in place that makes the #Turkish Registration Demands look chill in comparison, [6 - 10] cuz they only yeet devices after 90 days and not preemtively block them from any network!

  • This wouldn't be such a proplem if Australia was like Germany where the furthest doctor away is 1hr by bike and the worst one could get is a bite from a rabid fox and having to get some post-exposure shots. So yeah tourists are not gonna be able to call for help in down under...

Seriously, whoever came up with these ideas needs to touch grass, preferablzyin the outback on foot!

1 2 3 4 5 6 7 8 9 10

Kevin Karhan :verified:kkarhan@infosec.space
2025-01-21

And don't even get me started on #VoLTE support...

Also most #VoLTE / #Vo5G - devices *explicitly use #2G / #3G for #EmergencyCalls!

  • Which is #funfuckingtastic in a place like Australia where basically everything in nature conspires to hurt or kill humans!

#DownUnder #AUSpol #AUpol #tech #2Gshutdown #3Gshutdown #EmergencyCalling

Kevin Karhan :verified:kkarhan@infosec.space
2025-01-19
Kevin Karhan :verified:kkarhan@infosec.space
2024-08-08

@feld @Suiseiseki @hj @mirabilos why would anyone do that?

Also just switch to #Pubkey-based #allowlisting instead...

Kevin Karhan :verified:kkarhan@infosec.space
2024-07-23

@CppGuy @frameworkcomputer In terms if #avoid I'd sadly say #Lenovo (espechally outside the #ThinkPad line) and any cheap/craptastic no-name brand...

Tho personally, Lenovo, #Intel, #Fibocom and @ubuntu / #Canonical ruined my experience with the ThinkPad #P15v because despite being "#UbuntuCertified" the #WWAN module (an Intel #XMM7360 rebadged as Fibocom #850GL) didn't work and neither of the aformentioned parties felt responsible to fix it!

  • And thanks to #PCIe - #AllowListing of #WWAN cards I couldn't just plop a known working M.2 card in there, but that applies also to #hp, #Dell and any other "Business Notebook"...
Kevin Karhan :verified:kkarhan@infosec.space
2024-07-08

@Laberpferd @Natanox

Besonders #WebBrowser sind die Angriffsfläche Nummer eins weil sowas wie #CryptoJacking ist so dermaßen gängig, ich nutze #TorBrowser standardmäßig und wenn ich nen anderen [z.B. #Firefox] nutzen muss, dann nur mit #NoScript scharf und reines #AllowListing...

  • Ist halt kacke dass es soweit gekommen ist...

youtube.com/watch?v=vMIZKtVruH

2024-06-07

and won't this be detrimental to #letsencrypt themselves?
Because many companies use #geoblocking as policy, they will resort to #allowlisting #letsencrypt ip's. So people Will start exchanging and publishing the ip's of the #letsencrypt servers. These will become relatively easy prey for ddos attack?
So won't #letsencrypt become less stable as a service by this #geoblocking ban?
Why not use local servers (in the same region) and only fall back to other regio's or something?
#infosec #tls #linux #opensource

Kevin Karhan :verified:kkarhan@infosec.space
2024-02-28

@fuchsiii @walsonde FIBOCOM GL830...

Die #GL850 ist ein verkorkstes #Intel #XMM7360 was noch schlechter unter #Linux funzt als der #GMA500-Chipsatz!

Weder #Lenovo noch #Fibocom noch #Intel fühlen sich zuständig dieses Drecksteil zu fixen.

Ich persönlich würde einfach ne Sierra Wireless MC7700 oder was anderes reinstopfen wenn nicht nen shice #AllowListing bei den #ThinkPad|s der Standard wäre...

Leider hat @frameworkcomputer nich kein Mainboard mit zusätzlichem M.2 A+E bzw. B-Key - Slot für #LTE bzw. #5G-Modems samt #SIM-Slot im Angebot...

Sonst könnte mensch einfach nen #Quectel #RM500Q-GL draufknatschen, auch wenn die €300 fürnen 5G-Modem happig sind [Danke #Qualcomm, ihr Gierschlunde!]

Kevin Karhan :verified:kkarhan@mstdn.social
2023-11-05

@mar I do think that #Allowlisting - like #Blocklisting should be supported...

I'd gladly add an #AllowList in addition to the existing #DenyList I have here:
github.com/greyhat-academy/lis

Feel free to open up an issue and suggest it...
github.com/greyhat-academy/lis

Kevin Karhan :verified:kkarhan@mstdn.social
2023-06-24
Kevin Karhan :verified:kkarhan@mstdn.social
2022-12-22

@kuketzblog +9001%

Ohne #pfBlockerNG, #uBlockOrigin & #AdAway sowie #NoScript & #YesScript inkl. #JavaScript auf reines #Allowlisting beschränkt ist das #Internet unbenutzbar.

Ich blockiere aus Prinzip alle #Cookies & #Popups sowie #Werbung, denn dafür ist mir mein Traffic zu schade!

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst