Hacker Newsnew | past | comments | ask | show | jobs | submit | v4n4d1s's commentslogin

In a recent press release [1] the USDT said "According to the Department of Justice, LockBit has targeted over 2,500 victims worldwide". Now finding 7k decryption keys gives us a more realistic view on the insane problem ransomware has become and how many companies pay without publicy declaring a security incident.

[1] https://home.treasury.gov/news/press-releases/jy2326


Try Xrdp https://en.wikipedia.org/wiki/Xrdp

I use it on a bunch of Ubuntu 18.04 systems, works out of the box with apache guacamole.


Switch to freerdp 2.0 and swiss german keyboard layout are my highlights.



My Bank has a password character limit of 32, which actually is a 31 character limit and I was the first person to notice.


Ha, bet somebody wrote < 32 instead of <=32


Just ordered two 4GB variants. They're getting strong enough to replace my 3 node proxmox cluster at home for most of my services.

Not happy with micro-HDMI though.


I have a Nokia 3 and a Nokia 7.0 Plus, both had a bunch of com.evenwell.* packages installed.

I think all HMD devices have those packages.


Would love to speak to you about this. Can you send me an email? henrik.lied [at] nrk.no


Send you a mail from a newly created mail account.


This has to be fixed by HMD and I hope for an official investigation as most other manufacturers are probably doing the same.

In the meantime, I recommend the following:

1. Remove any unnecessary packages through ADB (https://www.xda-developers.com/uninstall-carrier-oem-bloatwa...)

2. Use Shelter (https://f-droid.org/en/packages/net.typeblog.shelter/)

3. Use a VPN-Firewall such as NetGuard (https://f-droid.org/en/packages/eu.faircode.netguard/) or NoRoot Firewall (https://play.google.com/store/apps/details?id=app.greyshirts...).


This should be fixed at an even higher level, and have Google force manufacturers to not add or alter the base OS for any data-gathering reasons in Android One and deny them from using the Android One brand if they do, or people will lose faith about the Android One program.


That, my friend, would be abusing their monopoly position.

Google hoovers up all the data and tells their partners they can't do this too? The antitrust regulators would have a field day.


According to the statement HMD Global gave to NRK, they have already rolled out a software update to fix this issue. Of course there is almost guaranteed to be other spyware on the phone serving the curiosity of the same and different masters, like Google.


Google should revoke their use of the AndroidOne trademark over these shenanigans.


Thank you for linking Shelter, I had no idea that was possible and that easy software for it existed!


You suggest installing userspace apps to control system software that might run in a privileged context. NoRoot Firewall, for example, doesn't control iptables, it just pretends to be a VPN server and privileged software, I assume, can bypass it.


Yes, I'm fully aware of this. There's also the problem of having a closed source baseband processor in pretty much every device.

But bypassing these mechanisms is a decision they had to make. If they're just lazy or incompetent, these userspace apps should be sufficient as a mitigation.

Check this out for a more sophisticated way: https://privacyinternational.org/node/2732


According to the explanation about permissions within NoRoot Firewall itself, any app with the 'Internet' permission can create connections to bypass the VPN. This is how NoRoot Firewall itself works (else the filtered traffic would never escape the app/vpn).


I used to run a Microsoft Exchange Server for my family, just switched to Mailcow-Dockerized, which is really awesome.

https://mailcow.email/


Thanks for developing easymorph! Free version helped me through my bachelors degree. It's my go-to tool to introduce people to ETL and similar concepts.


You're welcome! Great to hear it happened to be of help :)


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: