#Backdoored

Kevin Karhan :verified:kkarhan@infosec.space
2025-05-20

@DeltaWye @kfh I'd say @torproject / #TorBrowser as it's #Firefox but without #tracking, #adware and #analytics!

But if you're using #Govware like #Windows, any #Browser that doesn't use the #backdoored #CryptoAPI (i.e. all #Chromium-Forks do use it!) is better...

Kevin Karhan :verified:kkarhan@infosec.space
2025-05-07

@alice isn't that one of those #TSA-#backdoored #locks?

Kevin Karhan :verified:kkarhan@infosec.space
2025-05-03

@cryptrz add to that the fact that the #CryptoAPI is #backdoored and that said #backdoor can be triggered with a simple #HTTPS request in any #Browser [except #Firefox & #TorBrowser as they use #NSS instead!] (or #PowerShell's horrible wget implementation)...

And we have sufficient proof thaf #Windows is a #Govware that noone should use and that should be banned across the globe.

github.com/kkarhan/windows-ca-

2025-01-31

Sellers of Anom, the FBI's Secret #Backdoored Phone, Plead Guilty

The court records released as part of the plea deals also provide new insight into how some of the phone sellers discussed drug #trafficking on their #Anom devices as well.
#privacy #security #backdoor

404media.co/sellers-of-anom-th

Kevin Karhan :verified:kkarhan@infosec.space
2024-12-01

@puppygirlhornypost2 @navi yeah, but that's a common problem based off #TechIlliteracy and lack of proper explaination!

Bonus points if #TPM bs prevents #DataRecovery.

  • My biggest problem with #FDE/ #FullDiskEncryption is that is mandates direct access to a system to authenticate, thus one needs to manually mount stuff on servers post-boot instead.
Kevin Karhan :verified:kkarhan@infosec.space
2024-11-27

@tokyo_0 Well, #VeraCrypt does get audited from time to time, and it's so far the only #CrossPlatform #FullDiskEncryption solution there is that isn't a #proprietary "#TrustMeBroWare" or flatout #backdoored.

There are numerous reasons why #TrueCrypt got forked into VeraCrypt and I'm shure the #Wikipedia articles mention why...

Kevin Karhan :verified:kkarhan@infosec.space
2024-11-27

@tokyo_0 #TrueCrypt is #abandonware with serious security issues.

  • DO NOT USE TRUECRYPT FFS!!!

Use #VeraCrypt or even better: migrate machines to #Linux and use #LUKS / #dmcrypt instead, as it's the best option at hand.

github.com/kkarhan/windows-ca-

Kevin Karhan :verified:kkarhan@infosec.space
2024-10-21

@frederic meanwhile hat #Apple alle #iOS & #macOS-Versionen für die "V.R." #China #backdoored...

Kevin Karhan :verified:kkarhan@infosec.space
2024-10-15

@phlogiston because #GSM (and it's successor standards!) was #backdoored with #Govware like #SS7 so hard it can't be secure under any circumstances!

Kevin Karhan :verified:kkarhan@infosec.space
2024-09-16

@mysk that's because #Apple has introduced varios #Govware - #Backdoors in their products.

2024-09-14

1.3 million #Android -based #TV boxes #backdoored; researchers still don’t know how
#backdoor #security #privacy

arstechnica.com/?p=2049773

Kevin Karhan :verified:kkarhan@infosec.space
2024-08-19

@bojkotiMalbona @diebarschlampe @lmorchard @vkc nodds in agreement

I hate the #GAFAM-driven #Enshittification and the #Microsoft tech stack.

  • I can accept it when someone needs something specific, but every single time I asked people who claimed they need i.e. #Excel they refused to tell me what they use it for or what function they need #LibreOffice doesn't offer them.

I get hired and paid to prevent #LockIn effects and to enshure #ITsec is up to code, but that necessitates not surrendering to #PRISM-Collaborators and #Govware integrators...

Kevin Karhan :verified:kkarhan@infosec.space
2024-07-31

@frumble alle #GSMA-Standards sind #Govware-#backdoored seit #GSM...

Da gibt's nix zu fixen!

Meanwhile #Cisco, #Juniper & Co. integrierten #Govware wie #DUAL_EC_DRBG und hben sich bis heute dafür nicht entschuldigt!

Kevin Karhan :verified:kkarhan@infosec.space
2024-07-04

@GossiTheDog OFC there is - Microsoft still keeps their own #CryptoAPI #backdoored to this day...

Not shure if a fix even works anymore amd since I'm 100% #Windows-free I'd rather drink a bottle of vinegar or snort a line of soda than ever touching that cursed #Govware ever again in my life...

Kevin Karhan :verified:kkarhan@infosec.space
2024-06-26

@wravoc IMHO, #TPM & #UEFI are both #Scams and neither can be trusted due to being #backdoored and #Bloatware respectably.

Personally, I want a machine that is purposefully #incompatible with #CensorBoot by #Microsoft (and thus #Windows11) by using #LinuxBoot / #NERF and no TPM at all!

Sadly I guess that means I've to use the #RISCv version of the @frameworkcomputer mainboard for that...

The fact that UEFI has more code than the #Linux #Kernel with all it's drivers yet less than 100 contributors makes it inacceptable!

Kevin Karhan :verified:kkarhan@infosec.space
2024-05-21

@nuintari I think people should get firednfor buying #backdoored Networkibg gear like #Cisco since they didn't even apologize for the #DUAL_ED_DRBG #Govware in their products...

Kevin Karhan :verified:kkarhan@infosec.space
2024-05-07

@jsrailton #Govware like #Pegasus isn't something that can be fixed outside of extensive #ITsec, #InfoSec, #OpSec & #ComSec workups.

In fact it's easier to bootstrap an entirely new identity than trying to uninstall such persistent shite!

That being said, #VPN providers are just the newest #DigitalSnakeoil sales reps and everything against them applies to #Antivirus as well...

So sad that @tomscott was just naively debunking them years ago...

The constant #disinfo sown by VPN and #AV providers is so rampant that I'd not be surprised if one day both would finally be made illegal for all the right reasons:

Kevin Karhan :verified:kkarhan@infosec.space
2024-04-23

@technodad @mattblaze Another #FunFact: Due to the #backdoored #CryptoAG #ciphermachines and thus insight into all communications, the #US was able to influence #UN founding members to locate in #NYC instead of #Switzerland like the #LeagueOfNations before or any other #neutral country for that matter...

Kevin Karhan :verified:kkarhan@infosec.space
2024-04-22

@voltrina because it's #backdoored if not #Govware...

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst