the grugq's newsletter

Subscribe
Archives
May 9, 2023

May 9, 2023

May 9, 2023

⛓️Diving deeper into MSI leak, it has been discovered that one of the leaked keys (bxt_dbg_priv_key.pem) is associated with Intel Orange or OEM Unlocked.

🔥Based on Intel documentation, it appears to be more powerful in comparison to Boot Guard keys.https://t.co/mtABZNgalM pic.twitter.com/oX0L9b49UK

— Alex Matrosov (@matrosov) May 9, 2023

Bellingcat: "The Bellingcat team has put together a useful gui…" - Mastodon 🐘

The Bellingcat team has put together a useful guide on how to chronolocate with a few more examples from our own investigations and training back catalogue. Read it here: https://www.bellingcat.com/resources/2023/05/08/chronolocation-determining-when-a-photo-was-taken-using-facebook-google-street-view-and-assorted-tiny-details/


GitHub code search is generally available | The GitHub Blog

Restricting network access using Linux Network Namespaces

Our last blog post on Linux mount namespaces explored ways to restrict access to the file system. In this post we'll show how to restrict access to the network.



Not gonna lie, I'm betting on the team that is physically fit and well fed.

Whatever happens,
We have got,
The world's only air-mobile Burger King,
and they have not. https://t.co/dOQDMfHR1T

— Bret Devereaux (@BretDevereaux) May 8, 2023

And to be clear, I am not joking: https://t.co/RhdxbGjnjp

— Bret Devereaux (@BretDevereaux) May 8, 2023

China's soft power deficit is really stunning....and on a related note, it turns out you need to invest in the Humanities if you want to churn out effective national propaganda.

— Dr. Michael J. Taylor (@DrMichaelJTayl1) May 8, 2023

🚀‼️Commissioned by ESA, #Clearspace1 is the world's first mission to remove an existing piece of #SpaceDebris from orbit.

It will demonstrate the technologies needed for debris removal, and is a first step to establishing a new and sustainable commercial sector in space.🛰️🗑️💙 https://t.co/Nkk2NS798z pic.twitter.com/bORWleuUws

— ESA Operations (@esaoperations) May 9, 2023

Really curious to see how CVS-223-32233 for #linux #netfilter nf_tables https://t.co/L42C8sfIXl can be exploted fom "unprivileged local users". AFAICT, nf_tables_api goes through nfnetlink, and nfnetlink_rcv() checks for CAP_NET_ADMIN way before the code in nf_tables_api.

— LaForge - @LaF0rge@chaos.social (@LaF0rge) May 9, 2023

❗️@EP_PegaInquiry press release: “spyware use in 🇬🇷 does not seem to be part of an integral authoritarian strategy, but rather a tool used on an ad hoc basis for political and financial gains.” https://t.co/ZH2q4rRVAk pic.twitter.com/0SrpHWT9OJ

— Vas Panagiotopoulos (@criticalvas) May 8, 2023

Spyware: MEPs sound alarm on threat to democracy and demand reforms @EP_PegaInquiry committee has adopted its final report and recommendations, condemning spyware abuses in several EU member states and setting out a way forward.

Details ⤵️https://t.co/dCaS6VICI4

— EP PressService (@EuroParlPress) May 8, 2023

This is problematic:

EU Tech Lab and a boost to vulnerability research

To help uncover illicit surveillance, MEPs propose the creation of an EU Tech Lab, an independent research institute with powers to investigate surveillance, provide legal and technological support including device screening, and perform forensic research. They also want new laws to regulate the discovery, sharing, resolution and exploitation of vulnerabilities.

(Emphasis added)

If you have not read the EU Council Legal Service opinion on the EU's #ChatControl proposal — their version of the #OnlineSafetyBill spyware clauses — you really should.

It is *damning* about EU/UK state anti-encryption proposals:

Extracts below; src: https://t.co/aYbfLqnKBo pic.twitter.com/oa9fk6GlVc

— Alec Muffett (@AlecMuffett) May 8, 2023

https://t.co/eQTn82Nafn

— Dr. Dan Lomas (@Sandbagger_01) May 9, 2023

https://t.co/Bz0HpTE5fz

— Dr. Dan Lomas (@Sandbagger_01) May 9, 2023

Life goals fully achieved https://t.co/rrzQOX42Ts

— Ciaran Martin (@ciaranmartinoxf) May 9, 2023

You can have only one headline, which one would you choose!? 😏 pic.twitter.com/jJrrT1FdSO

— @goconnor@infosec.exchange 🇺🇦🔶️ (@GPEOConnor) May 9, 2023

♫ Wait 'til we get our Hanes on you ♫

(via @JHTatum) pic.twitter.com/i8BYziPm4m

— Science Diagrams that Look Like Shitposts (@scienceshitpost) May 9, 2023

pic.twitter.com/pXDtE9naYm

— Classical Studies Memes for Hellenistic Teens (@CSMFHT) May 9, 2023

I've always assumed that towns in the middle of nowhere were founded by settlers who got tired of walking and said "fuck it, this is home"

— Melvin of York (@MelvinofYork) October 5, 2017
Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X