15 May 2022

21 Million Records of VPN Users Leaked on Telegram


The database containing 10GB worth of user information of three VPN services such as ChatVPN, SuperVPN, and GeckoVPN was leaked in the Telegram Groups.

On May 7th, 2022, the data of 21 million users was leaked, exposing the personal details and login credentials of the users.

The Data Breach:

Telegram uses encryption and offers its users anonymity. It is also easily accessible and doesn’t require any technical skills. This makes it the perfect platform for hackers to post data breaches, even more so if they want more people to have access to them.

The leaked records of users contain the following information:

  • Full names
  • Usernames
  • Country names
  • Billing details
  • Email addresses
  • Randomly generated password strings

“It appears that the passwords were either hashed and salted or random, without collision. This means each password hash is different, making them harder to crack”, say the experts from VPNMentor.

Also, 99.5% of the email addresses were Gmail accounts, which is much higher than the average percentage. This can be understood that the group who shared the dump shared a subset of data and not the entire dump.

 The Possible Impact of the Breach

In this scenario, the experts say the affected users would become a victim of blackmail. The attackers might send phishing messages and scams to exposed users via email, using their full names and other personal details that only the company could know about, such as usernames, countries, or billing details, to build trust.

Hackers can read a password, take control of the user’s account, and take advantage of their premium status.

Also, the exposed database could end up in the hands of a restrictive government in a country where VPN use is banned or access to specific sites is blocked. This would allow the authorities to potentially arrest dissidents and VPN users.

Recommendations for Protection

Experts recommend VPN users change the password with a random combination of upper and lower case letters, numbers, and symbols for utmost security. Also, ignore any suspicious SMS messages and emails and educate yourself about phishing attacks, scams, malware, and other forms of cybercrime.

Source:gbhackers.com


13 May 2022

Your mechanical keyboard isn't just annoying, it's also a security risk

This website is all ears


If noisy mechanical keyboards are the bane of your life at home or in the office then you may have just found the perfect excuse to stop your colleagues or loved one from smashing those keys so loudly - it turns out that hackers can tell almost exactly what you're writing just by listening to you type.

Keytap3 is a software developed by Georgi Gerganov that can detect what keys are being pressed simply by listening at a close range with a half-decent microphone, with Gerganov demonstrating this using a mobile phone's built-in microphone in an 'acoustic eavesdropping' test on their YouTube channel.


This isn't the first version that Gerganov has developed though this is by far the most intuitive, having previously dabbled in projects that required the user to type a series of predetermined words and phrases to 'train' Gerganov’s software into deciphering what keys are being selected. 

Previous versions also required that the position of the microphone used to record the typing remain unchanged between the test and actually running the software, though these restrictions don't exist with Keytap3, which as the name implies, is the third version of the project.

Gerganov explains that it "works by clustering the detected keystrokes based on their sound similarity and then using statistical information about the frequency of the letter n-grams in the supposed language of the text (for example, English)."

We gave it a try using the Razer Huntsman v2 Analog which uses Razer's own Analog key switches, which gave some pretty mixed results so it's fair to say that this isn't 100% accurate just yet. Still, most of what Keytap3 detected from our typing was in fact, what we were writing which means it could detect important data such as passwords and sensitive information in private emails. Scary stuff.

You can give this a try for yourself over on the Keytap3 website by following the instructions below that Gerganov provided to better optimize the experience.

  • Be in a quiet room
  • Open this page on your phone and place it next to the keyboard of interest
  • Alternatively, open the page on your PC and put the mic next to the keyboard
  • Note that the keyboard does not even have to be plugged in during this test
  • Press the Init button below and allow microphone access to the web page
  • Type some English text on the keyboard using only lowercase letters and space
  • Try not to type faster than 250 CPM

Thankfully this only works with mechanical keyboards, and noisy ones at that as the audio needs to be loud enough for a microphone to pick it up. If you're particularly concerned then you could switch out your current key switches to something a little quieter like Cherry MX Silent switches. Even if the risk of hackers listening into your conversations is low, said colleagues may be grateful to you for giving their ears a rest.

Analysis: This isn't a real concern...yet

If this has set you on edge then I have both good and bad news for you. The good news is that while this is fairly creepy, it's unlikely that hackers will be able to break into your private space and place a microphone in close enough proximity to your keyboard without you noticing.

The bad news is that there are plenty of other ways that your keyboard could be giving away your private information. Keystroke capturing dongles exist that can be plugged into a keyboard’s USB cable, and wireless keyboards can be exploited using hardware such as KeySweeper, a device that can record keyboards using the 2.4GHz frequency when placed in the same room.

There are even complex systems that use lasers to detect vibrations or fluctuations in powerlines to record what's being written on a nearby keyboard.

Still, if you're a fan of mechanical keyboards then don't let any of this deter you, especially if you use one at home rather than in a public office environment. It's highly unlikely that you need to take extreme measures in your own home and just about everything comes with a security risk these days. Sometimes it's just better to enjoy the obnoxious tapping than keep yourself up at night worrying about hackers listening into your Facebook messages to your mom.

Source:techradar.com

12 May 2022

Google's Wallet app with digital IDs - The next phase in slavery



In order to accelerate the slavery agenda, Google is now integrating digital identifications in their new Wallet app.

Google now also owns Fitbit, meaning all your bio-metric data will now be 'owned' by Google, where you will have zero control of the data, irrespective of that Google may tell you.

We do not recommend the use or purchase of any Google products.

In fact if you are truly serious about your privacy, we recommend you to 'de-Google' your life and devices, for a start; using hardware which can run AOSP, non spy-ware version of Android.

For example, to purchase a smart watch which does not require the companion app to login to a external server, where some of those watches can use a generic opensource companion app called Gadgetbridge.

See article from gsmarena.com of the headline:

Google announces new Wallet app with support for digital IDs

If there's one thing Google likes to do almost as much as constantly launching new messaging apps, it's killing an app or service and then after a while launching another thing with the same name. So, with that in mind, say hello to the new Google Wallet. This will be available for Android and Wear OS devices in the coming weeks in "over 40 countries".

As you might expect, you can use it to store bank cards for tap to pay, but also any other sort of card you might have, including loyalty ones. But not just that - vaccine certificates? Check! And at some later point, Wallet will even support digital IDs, where you can identify yourself without even giving anyone your phone, through the magic of NFC. This obviously depends on state support, so the rollout might take some time, even in the US, where it's starting.



Digital office and hotel keys will also be supported, and developers can make almost any item into a digital pass. Google has created some templates that are the easiest to use - for boarding passes and event tickets and the likes, but there's also a generic template for more unique things.

To add a boarding pass or Covid vaccine card, you can simply take a screenshot of it and then you'll see an option to add it directly to your Google Wallet. Once it's added, you'll get notifications of delays and gate changes. The same goes for concert tickets - you'll receive a notification reminding you of the gig.

And if you look up directions in Maps to go see a friend, your transit card balance (provided it's added to Wallet) will be shown alongside the route. If you're low on credit/fare, you can tap and add more.

Since Google loves to be confusing with its apps and services sometimes, Google Pay will still be around in the US, India, and Singapore, focusing on sending and receiving payments from friends, but you'll pay for stuff with Google Wallet. See? We told you it was confusing.

10 May 2022

EU could start enforcing Digital Markets Act rules on Apple, Google, Meta in Spring 2023


You may have heard so far that the European Union has been preparing to have a say in how big tech companies like Apple, Google, and Meta operate. We are talking about a legislation dubbed the DMA (Digital Markets Act) which the European Commission has been rigorously preparing for a while. Now, The Verge reports that changes might come as soon as Spring 2023.


Spring 2023 might be the time when we see EU vs Big Tech


The European Commission's executive vice president Margrethe Vestager has set her eyes on controlling (or at least, fining if uncontrollable) tech giants such as Apple, Google, Amazon, Meta, and others with the DMA. Previously, she expected the battle to begin in October, but it seems we are more likely to see some action in the Spring of next year.

The waiting game depends on when the DMA will get implemented. The legislation is currently waiting for approval from the Council and Parliament.

The EU is, however, gearing up for enforcement of the new laws. The legislation focuses on the so-called gatekeeper companies, that, if you've been attentive so far in this article, you might presume refers to those big tech companies we mentioned earlier.

And you would be correct. If you're curious, here's the definition of what companies are considered gatekeepers: the company needs to have a market capitalization (a fancy way of saying the total of its stocks value) of over €75 billion ($82 billion) and own a social platform or app with at least 45 million monthly users.

These companies could face fines of up to 10 percent of their total worldwide turnover (for the preceding year) if they fail to comply with the legislation. For the repeated offenders, the fine can grow to 20 percent, which could help the EU drive its point home.

So, big tech companies will have three months to declare their status to the Commission, and then they'll have to wait for up to two months to receive confirmation from the EU. Indeed, it seems like it could take quite a while for the giant mechanism to start working (you can't expect tech giants and government commissions to fight a fierce Marvel-like battle that's so quick it's hard to see).

And as you might imagine, the EU has a lot more work it needs to do beforehand. Hiring heroes (we mean, staff), preparing the hundreds of monitors and computers to analyze data (and possibly, the 007 coffee for the employees that are working there)... joking aside, it will indeed take some tremendous work to prepare such legislation to be executed. Vestager also mentions that they will need to prepare legal text on various procedures. 

However, when the DMA passes, it will possibly mark an end of an era. In case you haven't heard of it yet, this is the legislation that could force Apple to allow users to download apps from outside the App Store (a possibility that freaks Tim Cook out and has him worried about the iPhone security), as well as require WhatsApp and iMessage to become interoperable with smaller chat apps.

Sideloading (the process of downloading apps on iPhone from outside the App Store) is arguably the biggest change the DMA will force for Apple. Previously, Apple has raised concerns that this will weaken the iPhone's security. By the way, Android users have been able to sideload apps for quite a while now.

On the other hand, an even bigger cause of headache for Apple is that the DMA would make Cupertino allow App Store customers to make in-app payments through alternative payment platforms (you may have heard about the infamous Apple Tax, 30% cut, which Apple takes from developers when payments are made via the App Store).

With all this being said, it will be quite interesting to see the DMA in action and what changes will big tech giants have to implement (and whether they will comply).


07 May 2022

Warrantless seizures accepted by Australian courts

The colony's legal system is corrupt to its foundations.

The ABC 'exposed' that the judiciary, or more specifically magistrates have not been sworn in correctly for 30 years in Tasmania.

Therefore ANY order made, quiet simply put is not valid.

Since people have been 'notified', have legal firms advertised for a class action to occur?

Did any person in Tasmania seek or obtain a remedy from an unlawfully issued court order?

(you can respond in the comments section if you have, including the results)

The mainstream media also noted that since Victoria Police personnel have not been sworn in correctly, their fines in relation to a certain health situation have no legal legs to stand on.

The fact that the police acted under dictation has also been deliberately omitted.

In a court matter when you (the serf) are required to be sworn in or take an oath it MUST be done according to the procedure/rules/regulations, otherwise your information will not be accepted by the court.

To make matters worse, the legal system is covering up the fact that there is no lawfully appointed sheriff and therefore deputies in Victoria.

There must be a lawfully enacted 'instrument' in place, in order to seize property from a 'person', period.

A person's property is seized by a sheriff, and this is where the problems begin, where they are not limited to the following two points:

  1. Currently (and previously), there is no lawfully appointed Sheriff of Victoria,

  2. The warrant, in its original form does not exist.

There is no current lawful appointment for a sheriff, an officer of the Supreme Court of Victoria, by the name of Mr. Warwick Knight.

There was no lawful appointment for the previous so called sheriff Mr. Brendan Facey.

If any person states otherwise, we challenge that person to produce the lawfully enacted paperwork within the comments section of this post.

First and foremost, to act on seizure of property a so called warrant in Victoria must be filled in and presented upon request to the person whose property is being seized.

As an example, if an 'Infringement Notice' arising from alleged road traffic offence is not paid, the fine expiates to what can be referred to as 'sheriff stage' where an alleged 'Infringement Warrant' (Against a Natural Person) is issued.

This warrant appears in the Infringements (Reporting and Prescribed Details and Forms) Regulations 2006, Schedule Forms, Form 1.


See: http://classic.austlii.edu.au/au/legis/vic/num_reg/iapdafr2006n75o2006714/sch1.html

Victoria's corrupt judicature has been obtaining cash from persons even though no warrants can be produced by the Sheriff's Office of Victoria.

This action is across more than one legal jurisdiction.

The courts have left many unsuspecting victims in their wake.

The real problem being though, is that those who have been astute enough to pick up on the fraud are being deceived stifled from obtaining a remedy by the court, where to be more specific it would be more beneficial to name those persons preventing you from obtaining justice be it a judicial registrar or judge, and initiating a judicial review.

One very public matter of a corrupt legal system denying justice to a victim of Victoria Police is that of Ms Corinna Horvath, where ultimately there was no 'real' remedy for her within Australia's legal system, where she had to take it externally culminating in 2014 in the case called 'Horvath v Australia' some 18 years after an assault by eight 'men' employed by Victoria Police.

Did these 'men' lose their jobs or were they 'rewarded' for their efforts?


The pinnacle of a corrupt legal system, where the 'brotherhood' looks after its own.

There are many more victims of the legal system similar in calibre to that of Ms. Horvath where the legal system is abusing them, by denying justice in deliberately not providing a remedy.

Does the legal system take 18 years to obtain cash from an 'Infringement Notice'?

06 May 2022

Scam watch: India a nation of scammers?


Do we hear of Chinese calling people and scamming them out of their hard earned cash?

Do we hear of Russians calling up unsuspecting 'mums and dads' for an anti-virus refund scam?

Do we hear that South Koreans are calling our phones in order to con us?

What we (the people) DO hear is that we are flooded with scams originating from India.

The 'best' part about it is that it's all 'supported' by governments worldwide, under the globalisation banner, because if these actions were not supported then they'd be stopped.

Governments are quick to act, to stop you from obtaining information from websites (e.g. 'working' for Hollywood) with the use of firewalls but allow obvious spam messages through, therefore putting you in financial harms way where in reality this is a deliberate failure of government.

Why?

Because you (the serf) are affected, corporations don't suffer nor do people in government.

If people in government were targeted in the same manner this action would be neutralised.

These people are commuting fraud, they are the scum of the Earth, there are no excuses.

In any event Australia needs to import more of those people for 'human right' reasons, because Scammer Lives Matter too, and for the sake of 'diversity', Australia (the colony) needs to be more diverse, where if we go back to the good ol' days it was once roamed by rascals and outlaws”

Bring back the good ol' days!

See just one example of too many:



05 May 2022

A better alternative for your privacy to Google's Play Store.


Google NEEDS you to use its services in order to build a sellable database, after all it is the world's largest advertising corporation.

In order to entice you to use its programs, Google says it's introducing features with regards to your privacy, something that is contrary to its business model.

Some of the privacy features outlined by phonearena.com are as follows:

"Google's new privacy section shows:
  • Whether and for what reason the developer is gathering data.
  • Whether the app creator is sharing your personal information with other parties.
  • The app's security policies, like whether data is well encrypted if intercepted and whether users can request that their information be deleted completely.
  • Whether or not an app follows Google Play's Families Policy in order to protect children in the Play store.
  • Whether or not the developer's security practices are in line with a global security standard."

We do NOT recommend using Play Store to download apps to your Android phone.

In fact we recommend using as little Google 'services' as possible.

a 'de-Googled' phone would a good start, but that is another topic altogether.

If you must download Android apps from Google's Play Store, then a better alternative would be the Aurora Store.


The Aurora Store obtains the apps from Google's Play Store, where in Anonymous mode, Google does not know that you are obtaining those apps, therefore a better 'privacy feature' for you.

If you must know the new features Google is implementing, then you can still browse the apps via a web browser, rather than the app.

What's better for your privacy is to use as little 'commercial' non-open source apps as possible.

A source for those apps is called f-droid.org.


We also encourage people to support the developers if the app you use is useful to you.

Google is part of the five-eyes 'Nanny State' agenda.

04 May 2022

AEC censored a political party's social media post

AUSTRALIA, we (the people) have a problem!

The Australian Electoral Commission has removed a post made by a candidate of a political party, One Nation.

Democracy is truly dead in this (dictatorial) colony called Australia!

So, let's be clear about this:

Someone or rather a 'person' within the AEC, a 'commission' removed another person's social media post.

The AEC does not have the lawful nor legal authority to take such action.

If any person disputes this fact, then we welcome that person to provide the lawfully enacted instrument that allows such an action to occur, within the comments section of this post.

The person who removed that post, has (allegedly) committed a Commonwealth criminal offence, where this action must be investigated by the authorities.

Now, the real question is, will the general population hear from the mainstream media that an investigation will occur is another story.

To make matters ever more 'precarious' for the AEC, commissions are not courts.

See article from constitutionwatch.com.au of the headline:

Tribunals and Commissions are not Courts.

The High Court's decision Burns v Corbett significantly narrowed the jurisdiction of commissions and tribunals. The High Court held that the Australian Constitution precludes a State tribunal from exercising federal and state jurisdiction, tribunals are not Courts and cannot exercise judicial powers and jurisdiction.  A tribunal or Commission not being a 'court of a State' cannot adjudicate disputes involving any of the matters set out in ss 75 and 76 of the Australian Constitution, even when the dispute involves the application of State legislation. The decision affects all areas of law including anti-discrimination disputes, residential tenancy disputes, and building and construction disputes.

A State law cannot impair or detract from the operation of a Commonwealth law by impairing the Commonwealth law’s ‘conditional and universal’ application, except to the extent that it has a ‘legal operation or practical effect within the universe of the conditional legal operation of the Commonwealth law’. Impairing or detracting from     s 39(2) of the Judiciary Act is to say that the Parliament has made a complete, exhaustive and exclusive statement on federal jurisdiction: ‘It is necessarily to say that the Commonwealth Parliament has not only provided positively for the conditional investiture of federal jurisdiction in State courts but has also stipulated negatively for the non-investiture of any jurisdiction with respect to any of those matters other than in State courts.’  Gageler J noted the difficulty of finding any such ‘negative penumbra’ in the text of s 39(2), and stated that the more fundamental problem lies in finding a source of Commonwealth legislative power: namely that s 77(iii) does not allow Parliament to confer judicial power on a tribunal that is not a State court.

The Industrial Relations Tribunals and tribunals of the State such as VCAT and the Fair Work Commission all fall into the same category, they fail to be courts and cannot provide you with an enforceable judicial decision.

See Burns v Corbett - Perakath:


See Burns v Corbett - AIAL Forum No. 95:





03 May 2022

Tracked by AirTag? Android users can also know


How to know if you're being tracked with Apple's AirTag, even if you haven't got an iPhone.

People have been using Apple's AirTag, (designed as a 'key' finder) for the illegal activity of stalking.

It can be attached in a clandestine manner to the victims belongings, eg. inside a purse, raincoat or to a vehicle in order to track that person.

Since this useage for nefarious purposes Apple has rolled out a software patch for their iPhone devices that will warn users of an attached AirTag.

Since victims may not have an iPhone, those people have been left out, until someone decided to make an app for Android users.



The app is called AirGuard, by Niklas Bittner and is available on the open source Android app store called F-droid within the following link:

https://f-droid.org/en/packages/de.seemoo.at_tracking_detection/

When this invention hit the 'consumer' market Apple stated its was safe and checked all the boxes with regards to privacy.

The problem there is Apple LIED!

This device can also be used to track you in other ways.

See further information with the video:



Action like this by corporations, further promoted the global 'Nanny State' agenda.

01 May 2022

Samsung ceases updates but AOSP doesn't


What good are you to a corporation if you only purchase their product once every four, five or eight years?

They need you purchase their wares every year or two, so that they can rake in the profits, as it's ALL about the profits.

Samsung dictates if your phone is 'eligible'.

Shouldn't it be eligible for the entirely of it's life?

In any event,

if you have a Samsung Galaxy S9 series phone with its original bloat/spyware operating system and you still want to feel 'up to date' with security updates, you can load Android in it's purest form called AOSP, from e Foundation, where the focus of that bare OS is that it's 'de-Googled'.

This may have some limitations for users, but in most cases it's fine.



See the company's website for other smart phones that accept the de-Googled version of Android:

https://doc.e.foundation/devices