#PII

Dave MasonDaveMasonDotMe
2025-05-27

Data harvesting, data brokers, and the like are out of control in the U. S.

Other than you and me, there's very little standing in their way.




Dave MasonDaveMasonDotMe
2025-05-27

At the doctor's office today. (To be clear, the patient is me. )

They asked for my wife's birthdate. I asked why they wanted that info. They said they needed it because she's on my insurance plan.

I told them they were wrong--they most certainly do not 'need' it. I refused to give them the info.

The response was predictable. They acted like I was the unreasonable one.




Chum1ng0 - Security Research :verified:chum1ng0@infosec.exchange
2025-05-26

#Ecuador: The group claims to have negotiated with an agent. However, we cannot confirm the veracity of this claim, as these groups often lie to gain some benefit.

More details:

security-chu.com/2025/05/ranso

#ciberseguridad #government #cybersecurity #cyberattack #ransomware #Qilin #LATAM #dataprotection #PII #news #noticias

Chum1ng0 - Security Research :verified:chum1ng0@infosec.exchange
2025-05-24

#Ecuador:The Qilin ransomware group claims to have stolen 100GB of data from the Savings and Credit Cooperative of Public Servants of the Ministry of Education and Culture.

There is no information available regarding whether the members of the Savings and Credit Cooperative of Public Servants of the Ministry of Education and Culture of Ecuador (CACSPMEC) have been notified about the theft of personal data that allegedly occurred in this incident.

More details:

security-chu.com/2025/05/ranso

#ciberseguridad #government #cyberattack #ransomware #Qilin #LATAM #ciberseguridad #dataprotection #PII #cybersecurity #news #noticias

Kevin Karhan :verified:kkarhan@infosec.space
2025-05-23

@silhouette @richi @signalapp @torproject

1. You completely miss the points! There is no "#TechnicalNecessity" to demand #PII like a #PhoneNumber - espechally for a "#privacy"-focussed messenger!

2. & 3. #Signal is able and willing to comply with #Cyberfacism and pushing a #Shitcoin (#MobileCoin) makes it trivial to criminalize the App for "illegal & unregilated banking". If #Moxie or @Mer__edith cared they'd yeet that thing (or didn't even integrate it to begin with!) to avoid the attention. And yes Signal does restrict the App functionality when using a phone number from #Russia & #Iran (among other nations), thus affecting not only those in need of safe comms but by sending a verification code to them, earmarking them for police & intelligence. Which bings.me to the 1st agrument.

4. #Tor has a stellar record in terms of stability, integrity and censorship circumvention. DIY'ing something instead if following almost two decades of solid progress is absurd and violates "don't roll your own crypto" as a rule!

5. Only with #SelfCustody can you protect your own data. Or do you really expect Staff from Signal to not talk when facing lifetime in jail? If they have the keys, they can decrypt it, thus their #E2EE is just a "#TrustMeBro!" concept. I mean, what prevents them from being forced into backdooring all comms to @icij as per #NSL? Any "guarantee" without self-custody is worthless by virtue of being unenforceable!

Signal pushing #TechPopulism instead of teaching folks that their #ComSec is worth diddly-piss wothout.#OpSec, #InfoSec & #ITsec is dangerous!

  • And yes claiming "JuSt UsE sIgNaL!" is dangerous in the era of #Trump's #cyberfacist regime acting as it does (like with the #ICC)!

Not to mention there are better options that don't do that shite (i.e. demand PII) and just work. @monocles / #monoclesChat & @delta / #deltaChat for example can adapt way better to said risks and ain't run by a #VCmoneyBurningParty!

Dawiscodawisco
2025-05-23

Well... so this is happening

"...will include information deemed by the ODNI as highly sensitive, that which can be “misused to cause substantial harm, embarrassment, and inconvenience to U.S. persons.”

theintercept.com/2025/05/22/in

Kevin Karhan :verified:kkarhan@infosec.space
2025-05-22

@richi Except @signalapp is not "#Privacy-first" cuz if #Signal did, they'd not.demand #PII (#PhoneNumber) nor remain in the #USA (#CloudAct) nor peddle #Shitcoin-#Scams (#MobileCoin) and put their tech on @torproject / #Tor and fully #decentralized.with 100% #SelfCustody of all the keys!

Kevin Karhan :verified:kkarhan@infosec.space
2025-05-22

@GossiTheDog @signalapp it merely prevents #Screenshots by claiming it's #DRM'd content.

The correct solution for #Signal would be to alert all their users and specifically block #Windows in general or at least #Windows11 simply because it is a #Govware and empirically cannot be made private or secure.

But that would require them to actually give a shit, which thed don't, cuz otherwise they would've stopped demanding #PII like a #PhoneNumber and moved out of juristiction of #CloudAct.

  • I mean, what's gonna prevent the #Trump-Regime from threatening @Mer__edith et. al. with lifetime in jail for not kicking the #ICC (or anyone else he and his fans dislike) from #Signal's infrastructure?

Since they are highly centralized.they certainly are capable to comply with "#Sanctions" (or whatever bs he'll claim!)...

Kevin Karhan :verified:kkarhan@infosec.space
2025-05-22

@Arios The Problem is #Windows.

Don't expect the "#DRMflag" to work when it's being used by @signalapp (which in and of itself is problematic for demanding #PII like #PhoneNumbers and shilling a #Shitcoin-#Scam named #MobileCoin!) because like the #API to signal to Windows "I'm an #Antivirus product, disable defender!" this will be abused.

If you are actually concerned re: #privacy you'd yert signal, educate others and use #XMPP+#OMEMO (i.e. @monocles / #monoclesChat & @gajim ) or #PGP/MIME (i.e. @delta / #deltaChat & @thunderbird ) over @torproject / #Tor instead.

  • It does take a bit of setup, but in return you get extreme gains in #privacy beyond what any #VPN provider can offer - legally and technically!

Not to mention #Signal falls under #CloudAct, so your privacy there is already nonexistant!

  • Otherwise @Mer__edith would've been in jail for the rest of her life already due to the statistic inevitability of it's abuse!
2025-05-21

For the last few weeks, I've been getting frequent #ThreeRings tech support calls to my personal mobile number. We don't offer phone-based tech support, so this was a bit of a surprise, and although I don't mind the odd one, this seemed like a significant ramping-up.

So I asked one of them where they found my number, and they said it came up when they did a #Google search for "Three Rings login".

Turns out they were right. Google had the phone number I gave them... four years ago?... for identity verification. But then a few weeks ago they randomly started serving it to people who searched for Three Rings!

I was able to remove it from #GoogleBusinessProfile, where they admitted that they modified it, but I'm yet to receive any kind of explanation.

🔗 Full story: danq.me/2025/05/21/google-shar

#privacy #gdpr #pii

Google Search results page for 'Three Rings CIC', showing a sidebar with information about the company and including... my personal mobile number (faked and blurred in this screenshot) and a 'Call' button that calls it!
Chum1ng0 - Security Research :verified:chum1ng0@infosec.exchange
2025-05-17

On April 24, the mining company Kolpa was listed on the website of the SafePay ransomware group.

🇵🇪 The cybercriminal group claimed in its description that it had stolen 108 GB of data from the company.

The SafePay group leaked information on a page where it compiles all the documentation belonging to this company.

Some documents titled "Constancia de Alta del Personal en Formación" contain employee identification data, such as ID number (DNI), date of birth, nationality, full name, gender, marital status, phone number, email, and address.

Another document called "Data Entrega de Tarjetas Hijos."

This file exposes personal data of workers, such as ID number (DNI), names, job title, and department, as well as information about their family members, including full names of children, ID numbers, dates of birth, age, and gender.

#PII #dataleak #databreach #dataprotection #privacy #ransomware #cyberattack #Peru #cybersecurity #ciberseguridad

If you ever worked for this company, your data may be leaked on the dark web.

In Peru, the Personal Data Protection Law (Law No. 29733) requires companies to protect personal data and notify affected individuals in case of data breaches.

More details:

security-chu.com/2025/05/Miner

2025-05-15

#CFPB Quietly Kills Rule to Shield Americans From #DataBrokers

#RussellVought , acting director of the Consumer Financial Protection Bureau, has canceled plans to more tightly regulate the sale of Americans’ sensitive personal data.
#pii #privacy #trump #maga

wired.com/story/cfpb-quietly-k

2025-05-13

It's almost time! ⌚ See #Grayog at #apidays NYC this week. Join us there tomorrow for a great preso (at 4:05 pm ET) by Jeff Zemerick and #Graylog's Rob Dickinson 👉 Catching the Quiet Thief: Detecting Low-and-Slow #API Data Exfiltrations in Real Time. 🔍 ⏱️

Jeff and Rob will talk about:
🐌 “Low and slow” API data exfiltrations
😈 Attackers exploiting #APIs for long-term data theft
🕵️‍♀️ How runtime monitoring with full payload visibility helps detect and block attackers
🔍 PII-aware detection, risk scoring, and real-time response uncovering threats hiding in plain sight
➕ And more

apidays.global/new-york/ #cybersecurity #infosec #PII #APIsecurity

Bisafansbisafans
2025-05-12

Schlummertags-Event im Mai 2025 gestartet

Neue Schlafposen erhalten in den nächsten Tagen eine höhere Chance, aufzutauchen.

Zur News: news.bisafans.de/11609

Kevin Karhan :verified:kkarhan@infosec.space
2025-05-11

@kuketzblog da widerspreche ich vehement.

Es gibt #proprietär|e #Silos welche qua #SingleVendor & #SingleProvider-Aufbau als #InformationBlackhole agieren (u.a. #WhatsApp, #Signal, #Threema, #Session, #Telegram, #discord, …)

und es gibt #OffeneStandards die #Wahlfreiheit zwischen #Clients, #Plattformen, #Servern und #Providern ermöglichen (u.a. #IRC, #Zulip, #RocketChat, ...) und echte #E2EE mit #SelfCustody aller Schlüssel ermöglichen (u.a. #XMPP+#OMEMO & #PGP/MIME)...

Natürlich steht es Menschen frei irgendeinen großen, zentralisierten Anbieter zu nutzen, nur wird dieser am ehesten zur #Enshittification neigen und mit #PII wie #Telefonnummern entsprechende Begierlichkeiten wecken!

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst