norden.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Moin! Dies ist die Mastodon-Instanz für Nordlichter, Schnacker und alles dazwischen. Folge dem Leuchtturm.

Administered by:

Server stats:

3.5K
active users

#cryptoapi

0 posts0 participants0 posts today
Replied in thread

@gborn @MichaelD @Bundesligatrainer @Ihazchaos nein, eben nicht.

Dass #Windows10 [und besonders #Windows11] nicht #DSGVO- & #BDSG-konform sein können ist evidenzierte Tatsache und ich habe noch keine*n Anwält*in gesehen die etwas anderes behaupten und dafür im Zweifelsfalle auch die #Haftung übernehmen würden.

  • Wohingegen ich mir sicher bin dass @SUSE & @ubuntu mir im Zweifelsfalle sogar ne #Versicherung der #Compliance ab Werk anbieten würden, was #Microsoft aufgrund von #CloudAct inhärent nicht kann!

  • Außerdem verbietet sich das Procurement von Anbietern die in "illegaler Agententätigkeit" [u.a. #PRISM] involviert sind (!!!) schon aus oberflächlicher due diligence...

Von einfach ausnutzbaren #Govware - #Backdoors in der #CryptoAPI unter #Windows hab ich noch garnicht angefangen!

Replied in thread

@bojkotiMalbona @diebarschlampe @lmorchard @vkc nodds in agreement

I hate the #GAFAM-driven #Enshittification and the #Microsoft tech stack.

  • I can accept it when someone needs something specific, but every single time I asked people who claimed they need i.e. #Excel they refused to tell me what they use it for or what function they need #LibreOffice doesn't offer them.

I get hired and paid to prevent #LockIn effects and to enshure #ITsec is up to code, but that necessitates not surrendering to #PRISM-Collaborators and #Govware integrators...

GitHubGitHub - kkarhan/windows-ca-backdoor-fix: Fixes a critical backdoor in Windows' CryptoAPI, which allows to unconsenting Update of CA Certificates in the background. See https://www.heise.de/ct/ausgabe/2013-17-Zweifelhafte-Updates-gefaehrden-SSL-Verschluesselung-2317589.htmlFixes a critical backdoor in Windows' CryptoAPI, which allows to unconsenting Update of CA Certificates in the background. See https://www.heise.de/ct/ausgabe/2013-17-Zweifelhafte-Updates-gefae...
#ibm#redhat#rhel
Replied in thread

@happygeek Morpheus Voice "What if I told you it *never*was safe to begin with?

Cuz #Microsoft not only is a #PRISM collaborator but also knowingly leaves #Govware #Backdoors open and refuses to fix known issues.

And the only "fix" isn't even persistent but easy to backroll by #WindowsUpdate or it's subsystem...

It doesn't even require elevated privilegues on the machine to exploit, just malformed / hijacked #DNS as Microsoft doesn't check it's #SSL #Certificate updates for #integrity or #signatures at all...

www.heise.deZweifelhafte Updates gefährden SSL-VerschlüsselungWas macht Windows, wenn es auf ein Verschlüsselungszertifikat trifft, dessen Echtheit es nicht überprüfen kann? Es schlägt nicht etwa Alarm, sondern fragt bei Microsoft nach, ob man dort zufällig jemanden kennt, der das Zertifikat für echt erklären möchte.
Replied in thread

@Quinnypig the sheer fact that #Microsoft and #Windows11 ain't banned across the #EU to this day is an indictment to the #TechIlliteracy of politicans in the @EUCommission & @europarl_en despite

and now

And since @GossiTheDog managed to get it running on a system w/o "#AI" acceleration aka. "#NPU" it's safe to assume that it'll be perfectly possible to retroactively shove it down everyones' throats without recourse!

  • Actually there are options for recourse besides "#ThoughtsAndPrayers" that regulators like @bsi would actually take this seriously:

Like: Stop using #Windows and get some help migrating away from it to a good #Linux distro!

GitHubGitHub - kkarhan/windows-ca-backdoor-fix: Fixes a critical backdoor in Windows' CryptoAPI, which allows to unconsenting Update of CA Certificates in the background. See https://www.heise.de/ct/ausgabe/2013-17-Zweifelhafte-Updates-gefaehrden-SSL-Verschluesselung-2317589.htmlFixes a critical backdoor in Windows' CryptoAPI, which allows to unconsenting Update of CA Certificates in the background. See https://www.heise.de/ct/ausgabe/2013-17-Zweifelhafte-Updates-gefae...
Replied in thread

@arrrg I tend to disagee...

Shure you can make the argument towards #TechIlliterates that they don't know better, but it's our failure as #TechLiterates to not just #preach and #demand #RepairableTech, but oftentimes people don't follow up their demands with actual purchase decisions.

  • OFC if one only has like $100 and they can only get an unrepairable & barely working shitPhone 4 SE from 2016 that's not to blame them, because #UseLonger & #ReUse is better than #Recycle or #BuyANewOne...

In #capitalism, the #users and #consumers do have #choices and they can decide to #unionize and collectively #refuse to buy or use garbage.

#WhatYouAllowIsWhatWillContinue applies to everything and this we need to demand and force change by all means necessary to do so.

OFC please do go ahead and choose #UnauthorizedRepair to keep your gear up and running as long as feasible anyway - just like I'll not toss out my still working #X230Tablet for a #Framework13 unless I literally have no other choice...

GitHubGitHub - kkarhan/windows-ca-backdoor-fix: Fixes a critical backdoor in Windows' CryptoAPI, which allows to unconsenting Update of CA Certificates in the background. See https://www.heise.de/ct/ausgabe/2013-17-Zweifelhafte-Updates-gefaehrden-SSL-Verschluesselung-2317589.htmlFixes a critical backdoor in Windows' CryptoAPI, which allows to unconsenting Update of CA Certificates in the background. See https://www.heise.de/ct/ausgabe/2013-17-Zweifelhafte-Updates-gefae...