14 September 2022

Victoria Police caught issuing fake permits


IMAGINE IF THE VICTORIAN REGISTRY JUST DID WHAT IT WANTED TO DO?

LEADING PRO-SHOOTERS RIGHTS MP and NSC member Tim Quilty MLC, has revealed in Parliament that VicPol’s registry (LRD) have been caught breaking the same laws it administers.

This follows revelations of “missing guns” and allegations of continual misconduct of senior LRD officers.  Now they’re issuing ‘pretend permits’ for their friends.




This the third time Senior Sergeant Armstrong has been named in Parliament.

Tim then went on to detail a long list of misconduct and improper behaviour by LRD, all backed by an overwhelming mountain of evidence.

(To hear what Tim said click here to watch the Parliamentary video footage below.)


source:constitutionwatch.com.au


11 September 2022

ISPs are quitely distributing data that can trace traffic through VPNs

ISPs are quietly distributing "netflow" data that can, among other things, trace traffic through VPNs.


There's something of an open secret in the cybersecurity world: internet service providers quietly give away detailed information about which computer is communicating with another to private businesses, which then sells access to that data to a range of third parties, according to multiple sources in the threat intelligence industry.

The information, known as netflow data, is a useful tool for digital investigators. They can use it to identify servers being used by hackers, or to follow data as it is stolen. But the sale of this information still makes some people nervous because they are concerned about whose hands it may fall into.

"I'm concerned that netflow data being offered for commercial purposes is a path to a dark fucking place," one source familiar with the data told Motherboard. Motherboard granted multiple sources anonymity to speak more candidly about industry issues.

At a high level, netflow data creates a picture of traffic flow and volume across a network. It can show which server communicated with another, information that may ordinarily only be available to the server owner or the ISP carrying the traffic. Crucially, this data can be used for, among other things, tracking traffic through virtual private networks, which are used to mask where someone is connecting to a server from, and by extension, their approximate physical location.

Team Cymru, one threat intelligence firm, works with ISPs to access that netflow data, three sources said. Keith Chu, communications director for the office of Senator Ron Wyden which has been conducting its own investigations into the sale of sensitive data, added that Team Cymru told the office "it obtains netflow data from third parties in exchange for threat intelligence."

Do you work at a company that handles netflow data? Do you work at an ISP distributing that data? Or do you know anything else about the trade of netflow data? We'd love to hear from you. Using a non-work phone or computer, you can contact Joseph Cox securely on Signal on +44 20 8133 5190, Wickr on josephcox, or email joseph.cox@vice.com.

Companies that may source Team Cymru's data include cybersecurity firms hired to respond to data breaches or proactively hunt out hackers. On its website, Team Cymru says it works with both public and private sector teams to "to help identify, track and stop bad actors both in cyber space and on the ground."

"I'm less worried about a bad guy hacker and more worried about a bad guy government or company or politician," one source familiar with the data said. A source in the threat intelligence industry added that they "always thought it was kinda bonkers," referring to Team Cymru's sale of netflow data.

The continued sale of sensitive data could present its own privacy and security concerns, and the news highlights that ISPs are providing this data at scale to third parties likely without the informed consent of their own users. Other companies, such as cybersecurity firm Palo Alto Networks, also have access to netflow data.

"The users almost certainly don't [know]" their data is being provided to Team Cymru, who then sells access to it, the source familiar with the data said.

Team Cymru's customers can probe a dataset, and "effectively run queries against virtually any IP to pull the netflows to and from that IP over a given point in time," one of the sources said. Chu added Team Cymru said it "restricts the amount of data that is returned, so that only a small portion of the netflow data in its database can be accessed by any one client."

In product descriptions, Team Cymru offers users the ability to follow traffic through VPNs, which attackers may use to cover their tracks or ordinary people to browse the internet more privately.

"Trace malicious activity through a dozen or more proxies and VPNs to identify the origin of a cyber threat," one brochure for a Team Cymru product called Pure Signal Recon reads. In essence, access to netflow data lets a security team observe what is happening on the wider internet, and may indicate what is happening to other organizations, beyond the borders of their own network or company. One of the sources said they previously saw traffic from an organization they knew inside Team Cymru's dataset and was spooked by it at the time.

"Visibility and insight are global," the description adds. An image included in the brochure shows Team Cymru's product letting users trace the activity of servers linked to an Iranian hacking group further than other datasets, such as DNS lookups.


A section of Team Cymru's marketing material for its Pure Signal Recon product. Image: Team Cymru.

In a recent research report on an Israeli spyware vendor called Candiru, Citizen Lab thanked Team Cymru.

"Thanks to Team Cymru for providing access to their Pure Signal Recon product. Their tool’s ability to show Internet traffic telemetry from the past three months provided the breakthrough we needed to identify the initial victim from Candiru’s infrastructure," the report reads. Citizen Lab did not respond to multiple requests for comment.

Team Cymru did not respond to multiple requests for comment on which ISPs provide it with the data, what privacy protections are in place around the collection and distribution of such data, and whether the individual ISP users have provided consent for their data to be shared.

"Fundamentally, people have a right to some degree of anonymity, and as a carrier it's not our job to eavesdrop in any form."

For its Cortex Xpanse product, Palo Alto Networks also gains access to netflow data, according to product documentation available online.

"Cortex® Xpanse™ obtains flow data via multiple relationships with Tier 1 ISPs. Through these relationships, Cortex Xpanse has access to a sample of approximately 80% of global flows," one page reads.

Jim Finkle, director of threat communications at Palo Alto Networks, said in an emailed statement that "Palo Alto Networks provides enterprise customers with netflow data to and from their own networks to identify violations of security policies, gaps in security monitoring and other high-risk activity on the customer’s network." Palo Alto Networks declined to name which ISPs it sources data from, or whether it purchases the data outright from the ISPs.

Dave Schaeffer, CEO of ISP Cogent Communications, which he said handles around 22 percent of the world's internet traffic, told Motherboard that as an ISP his company doesn't provide their netflow data to anybody.

"Fundamentally, people have a right to some degree of anonymity, and as a carrier it's not our job to eavesdrop in any form," he said in a phone call. Schaeffer says Cogent generates 96 percent of its traffic from selling to large wholesale customers, such as Vodafone, Cox, Spectrum, and BT. Schaeffer says Cogent provides services to Team Cymru but does not share netflow data with the company.

"I don't know if there's a lot of really useful things people could do with [netflow] data," he added. "There's probably some bad things I could think of if that data was available."

Although multiple sources were concerned about the sale of netflow data, several of them stressed that Team Cymru is a responsible organization.

"It's pretty shadowy but honestly they're a 'good actor,'" one in the threat intelligence industry said. "Very strict protections on who can see it, but still, yeah, it's shady."

The source familiar with the data said they were concerned about the sale of netflow data, but that Team Cymru "also enable security organizations to do some really awesome work. So I'm conflicted about it."

"I'm concerned that netflow data being offered for commercial purposes is a path to a dark fucking place."

In May, Motherboard reported that Senator Wyden's office asked the Department of Defense (DoD), which includes various military and intelligence agencies such as the National Security Agency (NSA) and the Defense Intelligence Agency (DIA), for detailed information on its data purchasing practices. The response showed that the Pentagon is carrying out warrantless surveillance of Americans, according to a subsequent letter written by Wyden and obtained by Motherboard.

Some of the answers the DoD provided were provided in a form meaning that Wyden's office could not legally publish specifics on the surveillance. Wyden's office then asked the DoD to release the information to the public. At the time, Wyden's office declined to provide Motherboard with specifics on one of the answers which was classified, but a Wyden aide said that the question related to the DoD buying internet metadata.

"Are any DoD components buying and using without a court order internet metadata, including 'netflow' and Domain Name System (DNS) records," the question read.

Other cybersecurity firms sell access to controversial datasets. In September, Motherboard reported how one firm called HYAS was sourcing smartphone location data to trace people to their "doorstep." As Motherboard has repeatedly shown, the ordinary apps installed on peoples' phones that gather this information often don't have informed consent to then sell or otherwise provide it to third parties.

Source:vice.com

Corporate fraud by NVIDIA, it plans to manipulate the market. No court action in the US?

Corporate fraud is rampant across ALL industries, it's that all you have to do is catch them out.

At the end of the business day, no one cares until someone takes it to court.

Will NVIDIA (NASDAQ: NVDA) see the inside of a court room?

See more at:



10 September 2022

While the Queen was opening the colony's new Parliament House, a sinister plot was afoot

Queen Elizabeth II, Prime Minister Bob Hawke, artist Michael Nelson Jagamara and the Duke of Edinburgh at the official opening of new Parliament House, Canberra 1988.
Image courtesy of the National Archives of Australia. NAA: A6135, K19/5/88/20

The colony we know as Australia is truly a legal basket case, as laughed at by the motherland's legal eagles, especially since the inception of the unlawful Australia Acts of 1986.

Briefly, Australia's legal bird brains had no idea how to hook the colony's slaves into the Act, so they made a local one and just in case that didn't work had an imperial one made up just in case, but that is a topic for another post.

The so called 'authorities' have been misbehaving on this land at the end of the world since they stepped foot on it.

So much so that the imperial motherland had enough that they had to install an Act in 1865 called the Colonial Laws Validity Act to remind the rascal and outlaws (in power, not the alleged 'free range' ones) that the monarchy rules.


The skullduggery against the Monarchy has never really stopped in Australia.

From the unlawful creation of the 'Queen of Australia' to the sabotage of the Commonwealth of Australia Constistution Act 1900 (UK) in 1988.

Now that Queen Elizabeth the Second is no more, with the anti monarchial vehcile the Labor party enact the dormant Bill to change the Commonwealth of Austrlaia Constitution Act 1900 (UK)?

See article:

Sabotage of the Constitution laying dormant

See documents:

First Report Constitutional Commission 1988 - Vol I


First Report Constitutional Commission 1988 - Vol II


Final Report Constitutional Commission 1988 - Vol I


Final Report Constitutional Commission 1988 - Vol II


Upholding the Australian Constitution_v19-ch9 - The Queen of Australia, Dr. Anne Twomey


See Original Commonwealth Constitution from the convention debates with Notes from '98


08 September 2022

Victoria Police issuing fines illegally against motorists



Victoria Police is not an ‘honourable’ organisation to say the least, where it’s members are involved in criminal actions but that is a whole topic in itself where the mainstream media’s so called ‘journalists’ do not expose the criminal actions, but rather certain selected few individual’s actions.

Victoria Police have been issuing (alleged) speeding infringement notices based on the illegal operations of the measuring equipment.

To put it quite bluntly, the equipment used to capture a motorist’s velocity has not been used in accordance with the law, and the police have been getting away with it for decades.

Have you been a victim of the illegal actions of Victoria Police in relation to alleged road traffic (criminal) offences?

If so, a class action lawsuit could be starting point.

05 September 2022

Is Windows bad?


It’s what we know. Windows is a tool and has evolved over the years while dominating the PC Market since the 90s. So it begs the question, is it bad?

What it does well

There are certain things Windows does better than any other OS. The operating system itself has an amazing assortment of compatibility and gaming.

If you want to play the most software and games that works with all your hardware, Windows is your best bet and that isn’t changing anytime soon.

Why use something else?

Let’s say you don’t mind some software or hardware not working or you want to pick out specific hardware to use on another operating system. What do you gain?

* Better Security - Windows is know to be easily hackable, from the NSA tool leak in 2017, Ransomware, and out dated kernel design. Windows is an absolute security nightmare. Both Mac and Linux offer proper elevation support with a NIX design, while windows does not and relies on the tacked on UAC system.

Better Privacy - Windows has extremely egregious telemetry, but what information does Windows collect?


More Consistency - One of the biggest issues Windows has is the rolling update cycle that tends to mess up computers. There are ways businesses tame this process and I’ve even shown how to have sane windows update settings, but the default configuration will typically land users in an undesirable place more often than not. Mac and Linux typically have much better update cycles and far fewer issues with system updates, and need fewer reboots.

The Microsoft HATE

This all doesn’t sound too bad, most people don’t care about privacy or security as they freely give it away on social media. See this image if you want a good laugh at how bad people are at these practices.


So why do people hate Microsoft and try to get away from Windows? The monopoly and absolute ruthless business model it has built over the past 30 years is something to marvel at.

Government Cooperation

It has grown so influential from its massive government lobby and has even an entire wing dedicated to working with governments. While some of this is bad, not all of it is. Their monitoring has helped stop some cyberattacks, like Ukraine cyber attacks in 2022 and this close partnership even had the NSA and FBI remotely hack into Microsoft exchange servers and patch the system. (source: https://www.enterprisetimes.co.uk/2021/04/14/nsa-and-fbi-move-to-help-microsoft-with-its-exchange-server-vulnerabilities/)

The downside to this is when the NSA tools leaked in 2017 with blatant backdoors that spawned a massive ransomware attack around the world with EternalBlue exploit that then spawned a host of WannaCry ransomware payloads delivered to millions of computers. (source: https://www.wired.com/story/eternalblue-leaked-nsa-spy-tool-hacked-world/)

The Companies Microsoft Killed

“Embrace, extend, and extinguish” (EEE), also known as “embrace, extend, and exterminate”, is a phrase that the U.S. Department of Justice found that was used internally by Microsoft… (source: https://en.wikipedia.org/wiki/Embrace,_extend,_and_extinguish)

They have successfully murdered companies and ruined countless lives while stifling innovation to get to where they are. Examples:

*  Browser incompatibilities: Netscape killed off and why we were plagued by the hellscape of Internet Exploader and ActiveX controls for almost a decade before Chrome came along.

*  Office: They purposely held back the API to make other competitors, like WordPerfect, able to succeed when they launched in Windows 98. With no documentation this ensured Microsoft Office had to be purchased and used by the world killing many competitors. They also did this by making Office documents render improperly in other browsers that weren’t Internet Explorer.

*  Purposely breaking Java programs on other systems so they weren’t cross-platform. They’ve settled with Sun for over 2 billion dollars in a lawsuit they lost back in 2002 and 20 million in 2001.

*  Why email sucks? Microsoft implemented MAPI protocol instead of using many common forms like SMTP, POP, or IMAP. On October 1st of 2022, they disabled the following protocols from Exchange Online: Outlook, EWS, RPS, POP, IMAP, and EAS and even SMTP gets disabled if not used.

So the hate comes from the world that never happened because of Microsoft’s greed. The missed innovations, the companies that were forced to shutdown, and the lives that it destroyed, all to make the Microsoft monopoly.

Walkthrough Video

source:ChrisTitus.com

04 September 2022

Snowy Monaro Regional Council corruption exposed - mainstream media silent

New South Wales' Snowy Monaro Regional Council is corrupt to the core where it should be razed to the ground.

In fact ALL councils in the colony have no lawful standing, as they are not departments of the state as per the Commonwealth of Australia Constitution Act 1900 (UK), but that is another topic altogether.

See post regarding an internal document:


 


01 September 2022

Microsoft Windows keylogger enabled by default - disable it now!



Many Windows 10 users are unknowingly sending the contents of every keystroke they make to Microsoft due to an enabled-by-default keylogger. This function has been around since the beginning of Windows 10, and is a prime example of why you should never go through the default install process on any Operating System. Windows 10 privacy has been a hot button issue since its release years ago. The French government even issued a warning to Microsoft last year, telling them to:

" Stop collecting excessive data and tracking browsing by users without their consent. "

It seems Microsoft only paid attention to the latter half of that warning. While many Windows 10 users may have technically given their consent, most – when informed that this has happened – will want to disable the Windows 10 keylogger ASAP.

How to disable Microsoft keylogger in Windows 10

According to Microsoft FAQ, to disallow Microsoft, and who knows what other entities, from using “your typing and handwriting info to improve typing and writing services”:

" 1. Go to Start, then select Settings > Privacy > General.

2. Turn off Send Microsoft info about how I write to help us improve typing and writing in the future." 

If this was ever on while you used Windows 10, there’s no way for you to know that Microsoft has deleted your information. They promise to disassociate their copy of your keystroke history from your identity, but the info is still out there in their hands and, again, pointedly was not initially anonymized.

More detailed instructions are available here.

Microsoft Windows 10 and Windows 7 still vulnerable to Event Tracing (Windows) ETW keyloggers

Last year, at Ruxcon, the CyberPoint Security Research Team unveiled a Proof of Concept that demonstrated using ETW to keylog USB keyboards. The “good” news is that this technique wouldn’t work on most Windows laptops as their keyboards are usually connected via PS2 instead of USB. However, there is no way to turn off ETW because it is crucial to Windows functionality and this is still an active way that a malicious actor could log your keystrokes.

Keyloggers are a very real privacy and security threat. If you must use Windows 10, make sure to disable the default enabled Microsoft keylogger, but be aware that Microsoft has other holes that make keystroke logging possible still.

source:piablog

It's ALL part of the 'Nanny State' agenda.

30 August 2022

Your mechanical keyboard isn't just annoying, it's also a security risk

This website is all ears


f noisy mechanical keyboards are the bane of your life at home or in the office then you may have just found the perfect excuse to stop your colleagues or loved one from smashing those keys so loudly - it turns out that hackers can tell almost exactly what you're writing just by listening to you type.

Keytap3 is a software developed by Georgi Gerganov that can detect what keys are being pressed simply by listening at a close range with a half-decent microphone, with Gerganov demonstrating this using a mobile phone's built-in microphone in an 'acoustic eavesdropping' test on their YouTube channel.


This isn't the first version that Gerganov has developed though this is by far the most intuitive, having previously dabbled in projects that required the user to type a series of predetermined words and phrases to 'train' Gerganov’s software into deciphering what keys are being selected. 

Previous versions also required that the position of the microphone used to record the typing remain unchanged between the test and actually running the software, though these restrictions don't exist with Keytap3, which as the name implies, is the third version of the project.

Gerganov explains that it "works by clustering the detected keystrokes based on their sound similarity and then using statistical information about the frequency of the letter n-grams in the supposed language of the text (for example, English)."

We gave it a try using the Razer Huntsman v2 Analog which uses Razer's own Analog key switches, which gave some pretty mixed results so it's fair to say that this isn't 100% accurate just yet. Still, most of what Keytap3 detected from our typing was in fact, what we were writing which means it could detect important data such as passwords and sensitive information in private emails. Scary stuff.

You can give this a try for yourself over on the Keytap3 website (opens in new tab) by following the instructions below that Gerganov provided to better optimize the experience.

  • Be in a quiet room
  • Open this page on your phone and place it next to the keyboard of interest
  • Alternatively, open the page on your PC and put the mic next to the keyboard
  • Note that the keyboard does not even have to be plugged in during this test
  • Press the Init button below and allow microphone access to the web page
  • Type some English text on the keyboard using only lowercase letters and space
  • Try not to type faster than 250 CPM

Thankfully this only works with mechanical keyboards, and noisy ones at that as the audio needs to be loud enough for a microphone to pick it up. If you're particularly concerned then you could switch out your current key switches to something a little quieter like Cherry MX Silent switches. Even if the risk of hackers listening into your conversations is low, said colleagues may be grateful to you for giving their ears a rest.


Analysis: This isn't a real concern...yet

If this has set you on edge then I have both good and bad news for you. The good news is that while this is fairly creepy, it's unlikely that hackers will be able to break into your private space and place a microphone in close enough proximity to your keyboard without you noticing.

The bad news is that there are plenty of other ways that your keyboard could be giving away your private information. Keystroke capturing dongles exist that can be plugged into a keyboard’s USB cable, and wireless keyboards can be exploited using hardware such as KeySweeper, a device that can record keyboards using the 2.4GHz frequency when placed in the same room.

There are even complex systems that use lasers to detect vibrations or fluctuations in powerlines to record what's being written on a nearby keyboard.

Still, if you're a fan of mechanical keyboards then don't let any of this deter you, especially if you use one at home rather than in a public office environment. It's highly unlikely that you need to take extreme measures in your own home and just about everything comes with a security risk these days. Sometimes it's just better to enjoy the obnoxious tapping than keep yourself up at night worrying about hackers listening into your Facebook messages to your mom.

Via Gizmodo

Source:techradar.com

FBI interferes with Facebook posts - Joe Rogan

Mark Zuckerberg recently told Joe Rogan that the FBI warned Facebook against 'Russian propaganda' before the Hunter Biden laptop story broke in 2020.


#HunterBiden #JoeBiden #JoeRogan #markzuckerberg