Showing posts with label Internet Scams. Show all posts
Showing posts with label Internet Scams. Show all posts

11 June 2026

'Telstra' scam email - Governments and corporations failing to keep us ‘safe’.

MANY people, especially those that are victims of a corrupt legal/judicial system, will say that “the system is broken”, but that is far from the truth.

The system is deliberately ‘broken’, unless of course you owe an alleged debt to state authorities or the taxation department.

Make no mistake that the system is not broken, but rather it’s functioning quite perfectly, the way they have intended it to.

A global deception that is going around at the moment in the ‘online’ world is something called ‘age-verification’ where the authorities allege that it’s in place so that the children (of the cannon fodder) are protected.

The uncomfortable reality is that governments do not care about the children of the slaves, but rather about controlling and monitoring society with this latest farce.

With regards to internet traffic, Australia has all sorts of DNS filters, firewalls, etc which moderate what content people can see or comes into Australia.

You may not be able to 'consume' content under DMCA (Digital Millennium Copyright Act, US law), but corporations are allowed to 'steal' your (copyrighted) content.

Phishing emails like the one shown below can also be stopped with a simple ban of the domain name within the email.


So why isn't it done?

Because realistically, the people in government do not give a stuff about the serf's trials and tribulations.

As long as the people in government are looked after, is all that matters at the end of the business day.

Livin' the life in a (penal) colony.  

28 November 2025

What is the WhatsApp OTP codes to hijack scam, and how to stay safe?

The new scam involves cybercriminals asking users to send over OTPs (One-Time Passcodes), to hijack their accounts


If you receive any unexpected or unwanted OTPs, ignore them and do not click on any links or download any media included with them [File] | Photo Credit: REUTERS

Social media users are reporting a new WhatsApp scam that logs out a person from the messaging service and makes them lose all access to their accounts, including messages, contacts, media, and files stored. Once the perpetrators gain control of the victim’s WhatsApp account, they repeat the process with the victim’s contacts.

How does the scam work?

Multiple users on X described receiving normal WhatsApp texts from friends, family members, or acquaintances they had already added as contacts.

The WhatsApp message from their seemingly trusted contact asked the user to check their messages for an OTP or verification code that was sent to them by mistake, and then share the details over WhatsApp.

Users would naturally look for the OTP and share the security credentials without thinking about it too much, since the request was coming from a trusted sender.

Later, however, the user would be logged out of all their WhatsApp accounts - across devices - and would struggle to regain access to the hijacked account.

What is actually happening?

Several possibilities could be at play here, but signs point to a phishing scam. Many users do not realise that the OTP sharing request from their so-called trusted contact was actually a malicious user who had seized control of the sender’s WhatsApp account already.

Now, with access to a platter of potential victims and their phone numbers and other sensitive details, the attacker tries to take over the next victim’s WhatsApp account. Using the phone number, they generate an OTP to verify the user’s identity, change their login credentials, or log them out of all devices. This OTP is obviously sent to the victim’s device. The attacker would lie to the victim and pretend the OTP was generated for another purpose, before asking them to share it.

The victim would likely share the OTP without realising that the malicious user is taking control of their own account. By the time the hacked victim is able to contact Meta or report the incident to the police, the hacker might have gone on to scam multiple other people this way.

How can you keep yourself safe?

First and foremost, never share OTP messages or personal verification codes with others, even if you trust them fully. OTPs are for your private use alone. When they are shared with others, you may end up being exploited, hijacked, or hacked, even if the OTP is only being shared between trusted contacts.

When in doubt about the security of an OTP message, it is better to let the time limit run out so that the OTP becomes useless. The OTP can be generated again later, in a more secure environment.If friends, relatives, acquaintances, or other known contacts suddenly ask you to share OTP numbers they claim were sent to you by mistake, do not engage with such messages or get into a conversation with the user, as they may have already been hacked. Report the incident to Meta and reach out to your contact directly, if possible.

If you receive any unexpected or unwanted OTPs, ignore them and do not click on any links or download any media included with them.

Source:supplied

24 November 2025

Understanding risks of One-Time Passcode (OTP) authentication

Governments and corporations worldwide are now 'forcing' people under a false narrative, to have a newly created digital identification.

The databases where YOUR personal identification (or rather private and confidential) documents are stored, will now be the target of cybercrime, more than ever before in the history of the internet.

Authorities and corporations, will lie to you that 'your' data is safe.

Authentication will now be more imprtant than ever before, but are you being informed of all the risks involved?

Your research can start with this article of the following content:

Since the early 2000s, One-Time Passcodes (OTPs) have been a popular way to verify online transactions. Banks, fintechs, and financial services used OTPs to add extra security beyond traditional passwords. By generating a unique code for each transaction or login, OTPs introduced a second layer of protection - usually through two-factor authentication (2FA).

OTPs were also convenient. Users could quickly verify their identity without complicated steps. However, as cyber threats have become more advanced, OTPs - especially SMS-based OTPs - are no longer as secure as they once seemed.

In fact, SIM-swapping attacks have doubled in just a few years. Complaints to the FCC increased from 275 cases in 2020 to 550 cases in 2023. This rising threat highlights the growing risks of relying on OTPs in sensitive industries like finance and banking.

In this article, we’ll break down the risks of OTPs and explain why more businesses are moving to stronger alternatives like biometric authentication. Let’s start with the basics.

What Is OTP Authentication?

OTP stands for One-Time Passcode. It’s a security method that verifies a user’s identity by sending a temporary code. The user enters this code to complete a login or transaction.

Usually, OTPs are paired with a password for two-factor authentication. Once used, the code expires, making it harder for hackers to reuse it.

How Are OTPs Delivered?

SMS-based OTPs: Sent to the user’s mobile number. Easy to use but vulnerable to SIM swap attacks and mobile network vulnerabilities.

Email-based OTPs: Delivered to a user’s email inbox. Convenient, but risky if the email account is compromised.

App-based OTPs: Generated by apps like Google Authenticator. More secure, but requires users to set up an app in advance.

Why OTPs Are Becoming Risky

Despite their convenience, OTPs are now a major target for cybercriminals. Common attack methods include:

SIM Swap Attacks: Fraudsters trick mobile carriers into transferring a victim’s number to a new SIM card, intercepting OTPs.

SS7 Protocol Flaws: Outdated telecom systems can be exploited to intercept SMS messages, including OTPs.

Phishing and Social Engineering: Users are tricked into entering OTPs on fake websites or sharing them with attackers.



The Problems with SMS-Based OTPs

Weakened Security: SMS OTPs are now easily intercepted or bypassed by modern hackers.

Delivery Issues: Messages can be delayed or lost due to poor signal, roaming, or carrier errors.

High Costs: Sending millions of OTPs per month generates large operational expenses for banks and fintechs.

Better Alternatives to OTP Authentication

To stay ahead of attackers, businesses are moving toward stronger, more reliable authentication methods:

1. Biometric Authentication with Liveness Detection

Biometric authentication uses fingerprints, facial recognition, or iris scans. Advanced systems integrate liveness detection, ensuring that a real, live person is present - not just a photo or video. This makes it extremely difficult for fraudsters to spoof the system.

2. Passwordless Authentication

Passwordless systems remove the need for both passwords and OTPs. Instead, users authenticate with biometrics, security keys, or device-bound links. Benefits include:

Stronger protection against phishing and SIM swapping.

A smoother user experience with fewer login barriers.

Lower operational costs by eliminating SMS fees and password resets.

Why Moving Beyond OTPs Matters for Finance and Banking

Financial institutions face increasing pressure to secure customer accounts and protect sensitive data. Today’s leaders are adopting:

Biometric Authentication: Enhanced with liveness detection to stop spoofing.

Passwordless Solutions: Faster, safer, and more convenient for users.

Adaptive MFA: Dynamic authentication based on user behavior and device security.

Privacy is also critical. That’s why new solutions like Keyless’ Zero-Knowledge Biometrics (ZKB) ensure that no biometric data is ever stored or shared, helping banks stay compliant with regulations like GDPR.

Conclusion: OTPs Are No Longer Enough

While OTPs once served as a valuable security tool, today’s digital landscape demands stronger protection. The risks of SIM swapping, protocol flaws, and phishing make OTPs an increasingly unreliable method.

Forward-looking organizations are upgrading to privacy-first, biometric-based authentication solutions. By doing so, they’re not just protecting transactions - they’re building trust and delivering safer digital experiences.

Source:keyless.io

09 November 2025

Facebook SCAMS its users, 15 billion scam ads a day!


Internal documents have revealed that Meta has projected it earns billions from ignoring scam ads that its platforms then targeted to users most likely to click on them.

In a lengthy report, Reuters exposed five years of Meta practices and failures that allowed scammers to take advantage of users of Facebook, Instagram, and WhatsApp.



Documents showed that internally, Meta was hesitant to abruptly remove accounts, even those considered some of the “scammiest scammers,” out of concern that a drop in revenue could diminish resources needed for artificial intelligence growth.

Instead of promptly removing bad actors, Meta allowed “high value accounts” to “accrue more than 500 strikes without Meta shutting them down,” Reuters reported. The more strikes a bad actor accrued, the more Meta could charge to run ads, as Meta’s documents showed the company “penalized” scammers by charging higher ad rates. Meanwhile, Meta acknowledged in documents that its systems helped scammers target users most likely to click on their ads.

“Users who click on scam ads are likely to see more of them because of Meta’s ad-personalization system, which tries to deliver ads based on a user’s interests,” Reuters reported.

Internally, Meta estimates that users across its apps in total encounter 15 billion “high risk” scam ads a day. That’s on top of 22 billion organic scam attempts that Meta users are exposed to daily, a 2024 document showed. Last year, the company projected that about $16 billion, which represents about 10 percent of its revenue, would come from scam ads.

“High risk” scam ads strive to sell users on fake products or investment schemes, Reuters noted. Some common scams in this category that mislead users include selling banned medical products, or promoting sketchy entities, like linking to illegal online casinos. However, Meta is most concerned about “imposter” ads, which impersonate celebrities or big brands that Meta fears may halt advertising or engagement on its apps if such scams aren’t quickly stopped.

“Hey it’s me,” one scam advertisement using Elon Musk’s photo read. “I have a gift for you text me.” Another using Donald Trump’s photo claimed the US president was offering $710 to every American as “tariff relief.” Perhaps most depressingly, a third posed as a real law firm, offering advice on how to avoid falling victim to online scams.

Meta removed these particular ads after Reuters flagged them, but in 2024, Meta earned about $7 billion from “high risk” ads like these alone, Reuters reported.

Sandeep Abraham, a former Meta safety investigator who now runs consultancy firm Risky Business Solutions as a fraud examiner, told Reuters that regulators should intervene.

“If regulators wouldn’t tolerate banks profiting from fraud, they shouldn’t tolerate it in tech,” Abraham said.

Meta won’t disclose how much it made off scam ads

Meta spokesperson Andy Stone told Reuters that its collection of documents—which were created between 2021 and 2025 by Meta’s finance, lobbying, engineering, and safety divisions—“present a selective view that distorts Meta’s approach to fraud and scams.”

Stone claimed that Meta’s estimate that it would earn 10 percent of its 2024 revenue from scam ads was “rough and overly-inclusive.” He suggested the actual amount Meta earned was much lower but declined to specify the true amount. He also said that Meta’s most recent investor disclosures note that scam ads “adversely affect” Meta’s revenue.

“We aggressively fight fraud and scams because people on our platforms don’t want this content, legitimate advertisers don’t want it, and we don’t want it either,” Stone said.

Despite those efforts, this spring, Meta’s safety team “estimated that the company’s platforms were involved in a third of all successful scams in the US,” Reuters reported. In other internal documents around the same time, Meta staff concluded that “it is easier to advertise scams on Meta platforms than Google,” acknowledging that Meta’s rivals were better at “weeding out fraud.”

As Meta tells it, though seemingly dismal, these documents came amid vast improvements in its fraud protections. Stone told Reuters that “over the past 18 months, we have reduced user reports of scam ads globally by 58 percent and, so far in 2025, we’ve removed more than 134 million pieces of scam ad content,” Stone said.

According to Reuters, the problem may be the pace Meta sets in combating scammers. In 2023, Meta laid off “everyone who worked on the team handling advertiser concerns about brand-rights issues,” then ordered safety staffers to limit use of computing resources to devote more resources to virtual reality and AI. A 2024 document showed Meta recommended a “moderate” approach to enforcement, plotting to reduce revenue “attributable to scams, illegal gambling and prohibited goods” by 1–3 percentage points each year since 2024, supposedly slashing it in half by 2027. More recently, a 2025 document showed Meta continues to weigh how “abrupt reductions of scam advertising revenue could affect its business projections.”

Eventually, Meta “substantially expanded” its teams that track scam ads, Stone told Reuters. But Meta also took steps to ensure they didn’t take too hard a hit while needing vast resources—$72 billion—to invest in AI, Reuters reported.

For example, in February, Meta told “the team responsible for vetting questionable advertisers” that they weren’t “allowed to take actions that could cost Meta more than 0.15 percent of the company’s total revenue,” Reuters reported. That’s any scam account worth about $135 million, Reuters noted. Stone pushed back, saying that the team was never given “a hard limit” on what the manager described as “specific revenue guardrails.”

“Let’s be cautious,” the team’s manager wrote, warning that Meta didn’t want to lose revenue by blocking “benign” ads mistakenly swept up in enforcement.

Meta should donate scam ad profits, ex-exec says

Documents showed that Meta prioritized taking action when it risked regulatory fines, although revenue from scam ads was worth roughly three times the highest fines it could face. Possibly, Meta most feared that officials would require disgorgement of ill-gotten gains, rather than fines.

Meta appeared to be less likely to ramp up enforcement from police requests. Documents showed that police in Singapore flagged “146 examples of scams targeting that country’s users last fall,” Reuters reported. Only 23 percent violated Meta’s policies, while the rest only “violate the spirit of the policy, but not the letter,” a Meta presentation said.

Scams that Meta failed to flag offered promotions like crypto scams, fake concert tickets, or deals “too good to be true,” like 80 percent off a desirable item from a high-fashion brand. Meta also looked past fake job ads that claimed to be hiring for Big Tech companies.

Rob Leathern previously led Meta’s business integrity unit that worked to prevent scam ads but left in 2020. He told Wired that it’s hard to “know how bad it’s gotten or what the current state is” since Meta and other social media platforms don’t provide outside researchers access to large random samples of ads.

With such access, researchers like Leathern and Rob Goldman, Meta’s former vice president of ads, could provide “scorecards” showing how well different platforms work to combat scams. Together, Leathern and Goldman launched a nonprofit called CollectiveMetrics.org in hopes of “bringing more transparency to digital advertising in order to fight deceptive ads,” Wired reported.

“I want there to be more transparency. I want third parties, researchers, academics, nonprofits, whoever, to be able to actually assess how good of a job these platforms are doing at stopping scams and fraud,” Leathern told Wired. “We’d like to move to actual measurement of the problem and help foster an understanding.”

Another meaningful step that Leathern thinks companies like Meta should take to protect users would be to notify users when Meta discovers that they clicked on a scam ad—rather than targeting them with more scam ads, as Reuters suggested was Meta’s practice.

“These scammers aren’t getting people’s money on day one, typically. So there’s a window to take action,” he said, recommending that platforms donate ill-gotten gains from running scam ads to “fund nonprofits to educate people about how to recognize these kinds of scams or problems.”

“There’s lots that could be done with funds that come from these bad guys,” Leathern said.

Source:arstechnica

23 July 2025

Next Level of fake videos - Veo 3

A.I. is increasing in leaps and bounds in what can be done with it.

As usual humans find ways to use technology for nefarious purposes.

Here is a benign example of a 'video' created totally by A.I.


This now at a new level, where can you truly tust what you see in 'social media' clips or even YouTube?

Source: László Gaál

03 February 2025

Lex Fridman another internet fraud?

There are too many people nowadays who are not what they portray to be.


It's too easy today to forge a fraudulent identity online where people pretend to be what they're not.

From 'social media's' 'influencers' to to finance and business 'gurus' (e.g. Robert Kiyosaki, of Rich Dad Poor Dad fame) to so called professionals in academia.

This can all come crashing to an end when some people start doing a 'deep dive' into who you really are.

Let's take a closer look at Lex Fridman, where a Wikipedia post says the following at the time of this writing:

Lex Fridman (/ˈfrdmən/; born 15 August 1983) is an American computer scientist and podcaster. Since 2018, he has hosted the Lex Fridman Podcast, where he interviews notable figures from various fields such as science, technology, sports, and politics.

Fridman rose to prominence in 2019 after Elon Musk praised a study Fridman authored at MIT, which concluded that drivers remained focused while using Tesla's semi-autonomous driving system. The study was criticized by AI experts and was not peer-reviewed.[4][5] That year Fridman transitioned to an unpaid role at MIT AgeLab,[4] and since 2023 has worked as a research scientist at the MIT Laboratory for Information and Decision Systems (LIDS).[6]

Early life and education

Alexey Alexandrovich Fridman was born in Chkalovsk, Tajik Soviet Socialist Republic and grew up in Moscow.[7][4] He is Jewish.[8] His father, Alexander Fridman, is a plasma physicist and professor at Drexel University. His brother Gregory was also a professor at Drexel.[4]

When he was about 11, soon after the collapse of the Soviet Union, Fridman's family moved from Russia to the Chicago area.[4][9] He attended Neuqua Valley High School in Naperville, Illinois.[10] He then went on to obtain B.S. and M.S. degrees in computer science at Drexel University in 2010,[11] and completed his Ph.D. in electrical and computer engineering at Drexel in 2014.[12] His PhD dissertation, Learning of Identity from Behavioral Biometrics for Active Authentication, was completed under the advisement of engineering educators Moshe Kam and Steven Weber and sought to "investigate the problem of active authentication on desktop computers and mobile devices".[13]

Career

MIT

In 2014, Fridman was hired by Google to continue his dissertation work on the use of AI for identity authentication, but left the company after only six months stating that he prefers the "chaos of research and the academic environment".[12] In 2015, he moved to MIT's AgeLab to work on "psychology and big-data analytics to understand driver behavior."[4]

In 2019, Fridman published a non-peer-reviewed study about Tesla Autopilot finding that drivers using semi-autonomous vehicles stayed focused, contrasting with established research on how humans interact with automated systems. Following his Tesla Autopilot study, Fridman was flown to Tesla offices for an interview with Elon Musk. Fridman's study on Tesla Autopilot was criticized for its methodology by Missy Cummings, a professor at Duke University and advisor for the National Highway Traffic Safety Administration, who described it as "deeply flawed". AI researcher Anima Anandkumar suggested Fridman should submit his study for peer review before seeking press coverage.[4][5] Following the interview with Musk, viewings of his podcast episodes increased significantly. The study was later removed from MIT's website.[4]

Following the publication of the study, he left AgeLab and took up an unpaid role in MIT's Department of Aeronautics and Astronautics.[4] As of 2023, he is a research scientist at the MIT Laboratory for Information and Decision Systems (LIDS).[6][14]

____________________________

But is is true what the wikipedia article states?

Some people even threathen to sue Wikipedia, if the truth is 'unflattering' to them, or maybe if it just hurts their feelings.

Telstra's CEO Solomon Trujillo, threatened to sue Wikipedia, where someone public the truth redarding his business dealings in the United States before he 'fled' to Australia to become head of a Telecom's giant. 

See article: https://solomontrujillo.blogspot.com/ which is different from today's Wikipedia page on "Sol Trujillo", where there is no 'Controversies' section, how convenient.

Let's see what a couple of people have to say about Mr. Fridman.

Is Lex Fridman a FRAUD?: (12m19s)


The Dangerous Truth of Lex Fridman: (14m08s)


17 December 2024

Mandiant Demonstrats a Unique QR Code Technique to Bypass Browser Isolation Defenses


Cybersecurity firm Mandiant has unveiled a groundbreaking discovery that demonstrates how threat actors could potentially bypass browser isolation technologies using QR codes as a covert command-and-control (C2) communication channel. The research, disclosed on December 8, 2024, raises significant concerns about the effectiveness of current browser isolation security measures.

The novel technique, developed by Mandiant's Red Team, leverages machine-readable QR codes embedded within web pages to establish unauthorized communication channels. This method proves effective against all major types of browser isolation solutions, including remote, on-premises, and local implementations, potentially compromising organizations' security infrastructure.

"The discovery highlights a critical weakness in what many organizations consider a robust security measure," explained a senior researcher at Mandiant. "By utilizing QR codes as a transmission medium, attackers can effectively circumvent traditional browser isolation protections that are designed to separate user browsing activity from the corporate network."

The proof-of-concept implementation demonstrated by Mandiant researchers utilizes Google Chrome in headless mode, integrated with Cobalt Strike's External C2 feature. The malicious implant operates by rendering web pages in a headless browser, capturing screenshots of embedded QR codes, and subsequently decoding them to extract command data.


However, the technique does come with notable limitations. The researchers found that the QR code-based C2 method is constrained by a maximum data capacity of 2,189 bytes, primarily due to streaming quality issues. Additionally, the communication process experiences significant latency, with each request taking approximately five seconds to complete, making high-throughput operations like SOCKS proxying impractical.

"While the current implementation may not be optimal for large-scale data exfiltration, it proves the concept that browser isolation can be circumvented through creative means," stated a Mandiant Research Team. "This should serve as a wake-up call for organizations relying solely on browser isolation as their primary defense mechanism.

"In response to these findings, Mandiant has issued several recommendations for organizations to strengthen their security posture. These include implementing comprehensive traffic inspection mechanisms to detect anomalous patterns indicative of QR code-based C2 activity, conducting regular domain reputation checks, and deploying advanced URL scanning solutions.

Security experts emphasize the importance of adopting a multi-layered "defense in depth" strategy rather than depending on a single security solution. "Organizations need to understand that no single security measure is foolproof," noted a cybersecurity analyst familiar with the research. "This discovery reinforces the need for comprehensive security strategies that combine multiple protective layers."

The revelation has prompted increased attention from the cybersecurity community, with several organizations already beginning to evaluate their browser isolation implementations in light of this new threat vector. Security vendors are also expected to develop countermeasures to detect and prevent such QR code-based bypass attempts.

As organizations continue to rely on browser isolation technologies as part of their security infrastructure, Mandiant's discovery serves as a crucial reminder of the ever-evolving nature of cyber threats and the importance of maintaining robust, multi-layered security defenses.

Found this article interesting? Keep visit thesecmaster.com, and our social media page on FacebookLinkedInTwitterTelegramTumblrMedium, and Instagram and subscribe to receive tips like this. 

Source:thesecmaster.com

See also other articles on QR Codes:

http://web.archive.org/web/20201126001729/https://www.cyber.gov.au/acsc/view-all-content/publications/quick-response-codes-covid-19-environment

24 November 2024

Meta illegally promoting scams and harmful websites

Meta’s ‘asset’ illegally, at least in Australia, promotes ponzi schemes, gambling and phishing sites that will cause (financial) harm to people who click on those links.

If you’re running a dodgy business, wanting to defraud people of their hard earned cash, all you have to do is pay Meta the relevant ‘advertising’ fee and they will promote your post.




This has been going on for quite some time and the ‘Australian Government’ (Pty Ltd, LLC, etc etc) has been doing nothing about it.

What's also concerning, is that Australia's governments (state and federal) have also used taxpayer funds to falsely promote a trial drug as a so called 'vaccine' for a few years on this advertising forum referred to as Facebook, is also swept under the rug.

NO inquiry on that matter, thank you very much!

Forget the proposed 'Misinformation and Disinformation' law, legally referred to as the Communications Legislation Amendment (Combatting Misinformation and Disinformation) Bill 2024, this is plane Jane fraud 'supported' by Mark Zuckerberg.

Will the Australian Government truly put it's foot down on one of the resources it uses against people?

You can’t really trust the government to protect you now can you, as this is not the first job of government!

See what the first job of government is, in the post:

What is the first job of a government?

See also:

Facebook Knows Instagram Is Toxic for Teen Girls, Company Documents Show

09 September 2024

Google falsifying smartphone reviews

Google had a motto “Don’t be evil”, where it’s not a ‘normal’ company value.

This value is no longer current, why?

Is it because that goal has already been breached?

Google is one of the world’s largest advertising corporations and supplier of data to the FiveEyes global surveillance network, and as a result its (alleged) illegal actions, such as breach of copyright or monopolistic behaviour have long been overlooked by governments worldwide.

Depending on one’s interests ‘influencers’ such as the Kardashians, Khabane Lame, Mr Beast, PewDiePie etc, in fact all of them even collectively, pale in comparison to how Google can ‘influence’ people.

Google ‘falsifies’ search results, in one example based on a person’s login, where the internet history is used to profile the user’s religious, political and sexual beliefs, compared to another person’s different internet useage history rather than the metrics on hand of the topic concerned.

Google even removes topics from its search pool, see post from 14 years ago:

Youtube censoring Wikileaks

AS mentioned before Google is the world’s largest copyright breacher, where nothing has been done about it for decades, where now it allows the theft of creator’s content on its YouTube platform to be used for A.I. as an example.

So what’s the point of copyright law, if it’s not being enforced?

Is it only enforced if a kid downloaded a song for 'free'?

To make matters even worse, people coming to YouTube to obtain an honest review of a phone from a ‘content creator’ cannot even trust that source, as that source is ‘influenced’ by Google.



Google gets its creators on YouTube to falsify product reviews under a program called ‘Brand Love’ where the creator MUST agree to the following:

By opting into this program, do you acknowledge that you are expected to feature the Google Pixel device in place of any competitor mobile devices? Please note that if it appears other brands are being preferred over the Pixel, we will need to cease the relationship between the brand and the creator”

  • Therefore, can you a potential customer of a product, trust ANY reviewer’s so called ‘review’?

  • Will that reviewer give you FULL DISCLOSURE of any terms and conditions they are bound by?

  • Will the reviewer be bound to a NDA (Non Disclosure Agreement) that covers up illegal or deceptive conduct?

  • Which other corporations conduct business in such manner?


Google should be charged at the very least with false, deceptive and misleading conduct in relation to this matter.

Will the legal system business take this course of action?

The answer would be, probably not!

24 August 2024

Two Factor Authentication (2FA) The SCAM of the Century - Defensive Strategy

MANY people may think that companies, or internet data hoovering corporations wrapping themselves up as 'social media' platforms require you to use 2FA (Two Factor Authentication) for your 'security', but that is a farce, where it's all about tying your number to your 'person'.

In any event your number can be 'spoofed' or hijacked / hacked.

Realistically this action is part of the Nanny State agenda.

For a more in-depth explanation see the following:



04 July 2024

AI Generated low quality content, the new normal?

We’ve come to a new age, where A.I. generated ‘content’ will saturate the internet.

The worst part about it that it’s absolute garbage, low quality and low value to the user.

It's bad enough that Google has screwed the internet, where approximately 60% of one's traffic now is 'advertising' material, we the 'consumers' or products (if the service is 'free') have to contend with technologies to reduce that amount of unwanted/unnecessary advertising material that bombards our daily lives, and now we have to deal with this new 'fake news' like material.

The problem there is that this type of content will not be moderated, whereas conversely MANY people's posts are deleted if not in line with a political or medical agenda in play.


See the above 'content' within the link: https://www.youtube.com/watch?v=D1jqj5B_4GA

Too bad, so sad, 'we' (the 'consumers') lose, again!

02 June 2024

Global Surveillance Network: 5 Eyes, 9 Eyes, 14 Eyes


When it comes to picking the right VPN provider, jurisdiction is important.

By jurisdiction, that means where the company providing a VPN is actually based, and not where its servers are located, but that matters too.

This is crucial for a number of reasons, but the major issue is state surveillance

You may not be aware of it, but security agencies in most developed nations have the ability to snoop and monitor almost everything you do. And they use these powers to the full, as the NSA scandals showed. 

It would be naïve to think that VPNs are immune to their intrusive activities.


5 Eyes alliance


The full five eyes list includes:

It emerged from the UKUSA security agreement, signed in 1946, and has been updated for the digital age. The idea behind the agreement was to ensure that Cold War allies could share SIGINT (signal intelligence) seamlessly. And the treaty also sought to keep this information sharing under wraps, remaining secret to the public until 2005.

Nowadays, the core aim of the alliance is to monitor their citizens’ online activity. And if certain laws prevent one member from digging into its peoples’ internet escapades, they can just ask another Eye to do the dirty work for them. The UK was found guilty of just that – asking the NSA to provide any data they pulled about United Kingdom residents.

Why was the 5 Eyes agreement kept hidden from the people? Well, we still don’t know the full story and the true scope of information gathering carried out under the terms of the alliance. But the implication is that the USA and its allies were engaged in detailed surveillance and intrusive activities which electorates would find controversial.

It very likely included the use of ECHELON, STONEGHOST, PRISM, and various other surveillance systems, which tapped into electronic communications across the world.

Do the 5 Eyes nations work alone?

If the intrusive operations permitted by the UKUSA treaty were the only global surveillance network, life would be easier for many spying-wary citizens. However, the core alliance doesn’t operate on its own. It has also gathered a series of satellite partners, that supplement its intelligence-gathering capabilities:

Israel operates hand in glove with the US government, providing and requesting security information on individuals of interest. It also has a thriving tech sector where cybersecurity is a major growth area. So users should be cautious about using Israeli VPNs.

Other partners include Asian nations like Singapore, Japan, and South Korea. All of these countries came under the US sphere of influence during the Cold War, and retain intelligence sharing systems with Washington. The same applies to British Overseas Territories like Bermuda or the Cayman Islands.

9 Eyes alliance



Here’s the full 9 Eyes list for reference:

Essentially the 9 Eyes network is an extension of the 5 Eyes group, and there is a debate about how formalized its structures are, and how powerful it is.

The main reason we are having this debate is down to one man: Edward Snowden. When he went public with his revelations about the NSA back in 2013, Snowden lifted the veil from the NSA’s global surveillance structures, confirming the existence of the 5 Eyes list.

What’s notable is that the 9 Eyes, and by extension the 14 Eyes, don’t have the same privileges as the 5 Eyes. Not all information collected by 5 Eyes members is available to the rest of the group, but the core nations are privy to all data gathered by the rest of the alliance countries, including satellite partners.

According to Snowden, the original 5 Eyes are not supposed to target each other. So, there should be no wiretapping by the USA of UK government meetings, and Australian ministers should be free to use the web without their activities being logged by the NSA. But that doesn’t really apply to other members.

14 Eyes alliance


As with the 9 Eyes countries, the 14 Eyes list includes:

This alliance also emerged directly from the Cold War and NATO structures, being christened the “SIGINT Seniors Europe” grouping. But it is much more loosely integrated into the circuits of global intelligence sharing than countries in the core alliance.

In fact, this has led to some friction, with Germany demanding greater access to intelligence data. In 2015, allegations emerged about the NSA spying on German government meetings, so it’s easy to see why they would want the protection from mutual spying that being in the 5 Eyes provides.

However, the core nations have sought to protect their privileges, leading some of the 14 Eyes countries to go their own way. In August 2018, the Germans announced a major new cybersecurity initiative along the lines of America’s DARPA, with the aim of establishing digital independence from the USA/UK.

Recent years have also seen the rise of “Pirate Parties” in nations like Sweden, which prioritize digital freedom and privacy, making governments less inclined to strengthen their ties to bodies like the NSA.

Surveillance systems used by the Eyes alliance

Naturally, this alliance has numerous ways to spy on people. And we only know about a fraction of systems used to monitor and gather citizen information. Here are a few that received media attention, bringing them to light.

ECHELON

This surveillance program was originally created in the 1960s to spy on the Soviet Union and its Eastern Bloc allies by the signatory states to the UKUSA Security Agreement. Now, they are the core 5 Eyes countries, and ECHELON has greatly expanded beyond the original scope.

According to the documents leaked by Snowden, ECHELON’s systems are capable of eavesdropping on telephones, faxes, computers, emails, bank accounts, and so much more. And the computers used for this purpose can store millions of records about individuals.

PRISM

USA-led surveillance program the NSA uses to request user data from technology and telecommunication companies. Such information includes essentially anything that is passed over the company’s network. We’re talking about emails, chat logs, photographs, documents, videos, etc.

The confirmed companies participating in PRISM are:

  • AOL
  • Apple
  • Dropbox
  • Facebook
  • Google, YouTube
  • Microsoft
  • Paltalk
  • Skype
  • Yahoo!

As of today, the true extent of the PRISM program is still unknown.

XKeyscore

Another NSA-led program that allows surveillance in real-time and the agents intercepting your communications don’t require a warrant to do so. With XKeyscore, they can parse through metadata, emails and the content on them, VoIPs, browser history, and any other internet activity associated with a person.

It shouldn’t be surprising that the 5 Eyes countries have access to these surveillance databases.

All eyes on VPN: using VPNs based in alliance member states

How do the 5 Eyes countries relate to VPN users?

In recent years, 5 Eyes governments have passed numerous laws which should concern VPN users.

For instance, the UK’s Investigator Powers Act empowered GCHQ to collect the following:

  • Data on users’ browsing habits
  • How long users spend connected to certain sites
  • Users’ SMS messages

These nations have also beefed up their powers to force Internet Service Providers (ISPs) to hand over data regarding individual users, again using national security as an excuse. And ISPs have tended to comply, adding backdoors when asked which allow security agencies to access the flow of consumer data.

Most importantly, governments have recognized the increasing usage of VPNs and taken steps to neutralize the threat they pose. Experts now generally advise users to avoid companies based in 5 Eyes nations and to exercise caution when using servers located in these nations.

Are worries about the Five Eyes countries exaggerated?

While the intelligence-gathering abilities of Washington and GCHQ are formidable, they are generally focused on specific security threats and interests, not everyday web users.

    • For many of us, government intrusion is less worrisome than the threat of cyber-crime and theft, and your VPN jurisdiction doesn’t matter too much when facing down these threats.
    • Secondly, the 5 Eyes countries haven’t taken direct steps to regulate VPNs. Their efforts are focused more on ISPs and conventional traffic, along with cellphone networks. VPNs currently have very few requirements regarding data retention. If they state that they keep logs (or fail to make it clear that they don’t), that’s their decision, not the state’s.
    • VPNs based in 5 Eyes nations also tend to be transparent about their identity and how to reach them – in keeping with the regulatory environment in places like the UK, Australia or Canada. This needs to be balanced against non-5 Eyes operators, who can sometimes be very hazy about who they are, and how they work.

So there’s room to question how dangerous the 5 Eyes is when choosing a VPN jurisdiction. But bear in mind that we simply don’t know the full scope of how VPNs interact with bodies like the NSA, and given the past history of governments, there’s a decent chance that VPNs in 5 Eyes countries have working relationships with spooks.

Should you worry if your VPN jurisdiction is on the 9 Eyes list?

Here’s another area where things get interesting. On one hand, third parties on the 9 Eyes list tend to have less intrusive surveillance agencies than the 5 Eyes. So they should be more trustworthy as hosts for VPN providers. And plenty of VPNs have set up in these countries, such as GooseVPN (in the Netherlands) or ActiVPN (in France).

However, if you scroll through a list of the world’s most trusted VPNs, you’ll probably notice that many aren’t based in 9 eyes countries. The same security concerns apply to 9 Eyes jurisdictions as to those in the five eyes list. VPNs located in places like Norway or France are liable to be subpoenaed by the FBI or other agencies, forcing them to either release logs or hand over encryption key data.

Of course, you need to bear in mind that the risk is low for everyday users, but if you are using a VPN for sensitive business or political communications, the 9 Eyes alliance is just as perilous as the core 5 Eyes nations. In fact, given that the 5 Eyes nations have an agreement not to spy on each other, there may be a higher probability of VPNs in third party nations being compromised.

As with 5 Eyes nations, this tends to lead experts to advise those in need of the best possible security protection to avoid a VPN jurisdiction in the 9 Eyes network.

Is it dangerous to use a VPN based in 14 Eyes countries?

The answer to this question is exactly the same as with the other alliances. Yes, it tends to be riskier to use VPNs based in 14 Eyes countries than those outside the alliance.

There have been cases of these informal information-sharing networks being used to issue DMCA notices from US-based corporations, targeting file-sharers in other jurisdictions. And anyone in a 14 Eyes nation can expect the same kind of intrusion from state surveillance agencies, making them dangerous for transmitting sensitive information.

In general, 14 Eyes countries will be slightly more autonomous where privacy is concerned than their partners in the core alliances. And for ordinary users, the risks are small.

Should I use a VPN based outside the 14 Eyes list?

By now, you’re probably asking yourself whether you should always look for VPNs based outside the 14 Eyes umbrella. There are certainly plenty of good reasons to do so.

Most importantly, VPNs located outside the core nations will be much more tightly protected against legal challenges and state surveillance originating in the USA. So if you intend to work around geo-blockers or torrent large amounts of data, they could be the right option to go for.

This is especially important if you are worried about protecting personal communications from the eyes of the state. If privacy is your major concern, choosing a VPN jurisdiction outside the 14 Eyes is essential.

So, where should you look? Given that the world now has over 200 nations, there shouldn’t be any lack of contenders. Several things you should pay attention to while picking a VPN provider:

  • Jurisdiction. Ideally, the VPN is based outside the influence of the 14 Eyes alliance, including the satellite nations. Such services won’t be forced to collect or hand over any user data. Furthermore, they aren’t required to comply with data requests dished out by other countries.
  • Audited no-logs policy. Any service can claim to have a no-logs policy they adhere to, but where’s the proof no data collection is happening behind the scenes? Here’s where independent audits done by reputable third parties come into play. And better yet if you can view audit documentation and results yourself.
  • Any past controversies. Many VPNs with “strict no-logs audits” have cooperated with governments in the past, like Riseup, HMA VPN, and such. A little digging around with Google helps reveal services that you shouldn’t trust from the get-go.

Generally, VPNs in countries like Switzerland or Panama will deliver enhanced protection against snoopers, especially if they offer techniques like “multi-hop” transmission. So when choosing your next VPN, take jurisdiction into account. It’s a key part of ensuring online security, so it pays to keep your eyes open and exercise caution.

Other online privacy measures to consider

With so much data and our lives being shared on the web, you should think about minimizing how much you share of yourself online. We recommend:

  • Pseudonyms and anonymous mail. Anonymous mail services encrypt your emails and usually don’t contain any information that could be traced back to you.
  • Privacy-friendly browsers. Most web browsers like Chrome and various others that run on Chromium collect your browsing data for marketing purposes. Switching to a secure browser helps solve this. The most popular choices include Brave and Tor.
  • Encrypted messaging apps. Not all messaging apps that utilize end-to-end encryption protect your metadata or abstain from collecting other identifiable data. (WhatsApp is notorious for this). There are better alternatives, like Telegram or Signal, that do not participate in such practices.
  • Just don’t overshare. While it might be tempting to post the latest vacation photos on Instagram or share life updates on Facebook or Twitter, is it really worth it? Any kind of personal information you put on the internet stays there forever. And it’s easy pickings for any entity (government or not).
What is also important is who owns your VPN.

When it comes to the true ownership of various VPN products and brands, it’s crucial to know which company owns or operates the users’ data. There are two big possible issues to consider.

1. Data privacy

If the parent companies are actually located in Fourteen Eyes countries, which are typically high-surveillance countries, users’ data could be wide open to the governments.

Suppose they are in Russia, China, and other authoritarian or repressive regimes. Then, the governments force them to provide data on a default basis (we discussed this in our Chinese surveillance analysis). The parent company may also be willing to sell user data.

In 2019, US senators planned an investigation into the foreign servers used to redirect traffic when using a VPN. Senators Marco Rubio (R-FL) and Ron Wyden (D-OR) noted the following [pdf]:

“If US intelligence experts believe Beijing and Moscow are leveraging Chinese and Russian-made technology to surveil Americans, surely DHS should also be concerned about Americans sending their web browsing data directly to China and Russia.”

For ultimate safety, a VPN shouldn’t operate in any of the 5, 9, or 14 Eyes alliance countries. A privacy-friendly jurisdiction means there’s no push to collect your data or what you do while the VPN is turned on. As such, locations like Panama, Switzerland, The British Virgin Islands, Romania, and so on, are what you should look for. If you want the best VPN service tucked away from the clutches of the Eyes alliance, we recommend getting NordVPN, now 74% off.

2. Data security

If the owning company is untrustworthy, it could bring up many problems. We’re talking about parent companies with major vulnerabilities or even suspicious add-ons and possible phishing emails with malware. This could lead to stolen data user data or even hacked computers.

This is especially applicable if you’re entrusting yourself to free VPN brands. We understand the appeal, but, ultimately, they aren’t worth it since you’re paying for these services with your data instead. In fact, numerous costless VPN providers have been caught collecting various information about their users.

Let’s take Betternet. They promise utmost privacy and security, yet what’s actually happening behind the scenes couldn’t be further away from it. The company behind it was busted for logging and selling user data to third parties, as well as embedding third-party trackers into its VPN Android app.

Another example is Hola VPN. For them, stealing and reselling your bandwidth is fair game. And the VPN itself isn’t really a private virtual network, but rather a P2P network. Here, the user itself is the endpoint other people connect to, meaning strangers are cloaking themselves in your IP address. If they do something that’s illegal, you’re the one who’s going to get busted for it, not the actual perpetrators.


Whatever VPN you choose, make sure you know it's current place of business and the country's current law with regards to privacy, as changes to the law are getting worse and worse with regards to your privacy.