voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #privacy

[?]Linux Easy » 🌐
@linuxeasy@mastodon.uno

La nuova VPN gratuita di Firefox è disponibile anche in Italia e permette di migliorare la privacy online senza installare software aggiuntivi. Scopri come funziona e quali sono i suoi limiti.

linuxeasy.org/firefox-italia-v

    [?]The New Oil » 🤖 🌐
    @thenewoil@mastodon.thenewoil.org

    [?]CyberNetsecIO » 🌐
    @netsecio@mastodon.social

    📰 South Korea Hits E-Commerce Giant Coupang with Record $409M Fine Over Data Breach

    South Korea's privacy regulator has fined e-commerce giant Coupang a record $409 MILLION for a data breach affecting 37.5M people. The cause? Inadequate security safeguards, not a sophisticated hack. 🇰🇷

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/so

      [?]The New Oil » 🤖 🌐
      @thenewoil@mastodon.thenewoil.org

      [?]WIRED - The Latest in Technology, Science, Culture and Business [Unofficial] » 🌐
      @wired.com@web.brid.gy

      Grok Is Still Hosting Sexualized Deepfakes of Famous Women

      A WIRED investigation found dozens of “nudified” deepfake images and videos on Grok's website, including nonconsensual depictions of celebrities and at least one prominent US politician.

      Grok Is Still Hosting Sexualized Deepfakes of Famous Women

      Alt...Grok Is Still Hosting Sexualized Deepfakes of Famous Women

      [?]sanitation » 🌐
      @sanitation@lemmy.today

      [?]Anny is not done growing » 🌐
      @annyr@fidelis.social

      What password manager do y'all use these days?

      I'm in the market for one that plays nice across various devices and can be shared (ie with spouse for family accounts)


        [?]Miguel Afonso Caetano » 🌐
        @remixtures@tldr.nettime.org

        "End-to-end encryption, in which data is encoded so that only users on either “end” of a conversation can decrypt their communications—and not the server that relays that information or any other interloper—has become the standard for modern privacy on the internet. But its very name suggests a kind of simple pipe with two openings. The metaphor, and often the encryption technology that has enabled that model, doesn't fit neatly onto the world of Slack, Discord, Google Docs, and the other multiuser, complex, collaborative software where people now live and work.

        So one group of cryptographers has built what they describe as the foundation for a new generation of end-to-end encrypted apps, with a new metaphor: Instead of a mere pipe, they want to create “spaces” where users can hold group conversations, host information on a server, collectively make changes to it, invite in new collaborators or kick them out, all while maintaining the same strong encryption protections that prevent the server or network eavesdroppers from accessing their data.

        That cryptographer team, including contributors from Harvard, Microsoft Research, and former developers of the end-to-end encrypted messenger Signal, today release a “preview” of Encrypted Spaces, an early version of a set of open-source code libraries, which is part of an architecture they've designed to allow anyone to easily build a rigorously end-to-end encrypted app that nonetheless enables all of the complex collaboration features that users demand from software today."

        wired.com/story/signal-alums-r

          [?]Teh AnKorage ☑️ » 🌐
          @ankorage@fe.disroot.org

          New PODCAST - "Now LibreOffice Takes Swings at Euro-Office | The Office Wars Have Begun" ️ 🎙️ 🔊 🎧 👏

          Have a listen at https://podcast.switchedtolinux.com, via RSS feed or using your preferred method!

          !!! ALL HAIL THE VAN PANTHER !!!

          DESCRIPTION: "We look at the open letter Libreoffice wrote to dispute some claims from Euro-office and raise issue with the file format they are defaulting to."

          !!! NOTE !!! This post is best viewed on a PC. Switched To Linux is, “written by a broad spectrum computer consultant to help people learn more about the Linux platform.” This account is a supporter of Switched To Linux and provides convenience posts of thumbnails art, videos and streams.

          #SwitchedToLinux #Linux #Windows #Mac #Technology #Tech #AltTech #Privacy #Private #Security #Secure #FOSS #FreeAndOpenSource #FreeAndOpenSourceSoftware #FreeOpenSourceSoftware #Podcast #Patreon #Twitch #AltTech #FactCheckTrue #Fediverse #SocialMedia #Podcast #stoptheslop #libreoffice #onlyoffice #microsoft

          !!! Tell us what you think by filling out a "SATISFACTION SURVEY or ABUSE/SPAM REPORT" form from Teh AnKorage !!!

          https://cryptpad.disroot.org/form/#/2/form/view/elsOVQUrXAmGuer4kd75JhA3mNELuCj8cTjEUynrZZo/

            [?]The New Oil » 🤖 🌐
            @thenewoil@mastodon.thenewoil.org

            [?]Olly 👾 » 🌐
            @Olly42@nerdculture.de

            WordPress Malware Campaign hides Payloads in Steam Profiles.

            Nearly 2,000 WordPress websites were infected with malware that relies on Steam Community profile comments to hide command-and-control [C2] data.

            The threat actor’s used invisible Unicode characters to encode a payload that builds a URL to a malicious script. By leveraging Valve's platform, the attacker avoids maintaining a separate C2 infrastructure and evades traditional detection methods.

            ⁉️Since the campaign was first uncovered in July 2025, GoDaddy security engineers have found malware on approximately 1,980 WordPress websites.⁉️

            godaddy.com/resources/news/mal

            Alt...It is unclear how the attackers breach the websites, but researchers assess that the initial infection vector ranges from stolen admin logins or compromised FTP/SFTP credentials to the exploitation of a vulnerable WordPress theme or plugin, or a supply-chain compromise. 👾The first-stage malware planted on a website uses WordPress page loads to reach specific Steam profiles and extract text from benign-looking comments. According to the researchers, the decoded payload is used to build a hello-mywordl[.]info URL serving JavaScript code that is injected into every frontend WordPress page. Based on the file names [e.g., asahi-jquery-min-bundle and lodash.core.min.js], the retrieved malware is disguised as a legitimate JavaScript library.👾 ⁉️The researchers recommend that security teams prioritize restoring from a known good backup before the infection date. If this is not possible, the manual cleaning process should be thorough because "attackers can reinstall removed code through the backdoor if any component remains active."⁉️

            [ImageSource: GoDaddy]

Malicious Steam comment

👾However, the text includes hidden Unicode characters that conceal malicious payloads sometimes disguised as ASCII art. GoDaddy researchers note in a report that the threat actor uses six invisible Unicode characters for the encoded payload:👾

• Zero-width non-joiner [U+200C]
• Zero-width joiner [U+200D]
• Function application [U+2061]
• Invisible times [U+2062]
• Invisible separator [U+2063]
• Invisible plus [U+2064]

The decoder ignores any visible character and maps the invisible ones to a corresponding number; then it converts them to binary representation and reconstructs bytes from the binary stream.

⁉️“This encoding allows binary data to be embedded within normal-looking text. The visible characters serve as camouflage while the invisible characters carry the actual payload,” GoDaddy says.⁉️

            Alt...[ImageSource: GoDaddy] Malicious Steam comment 👾However, the text includes hidden Unicode characters that conceal malicious payloads sometimes disguised as ASCII art. GoDaddy researchers note in a report that the threat actor uses six invisible Unicode characters for the encoded payload:👾 • Zero-width non-joiner [U+200C] • Zero-width joiner [U+200D] • Function application [U+2061] • Invisible times [U+2062] • Invisible separator [U+2063] • Invisible plus [U+2064] The decoder ignores any visible character and maps the invisible ones to a corresponding number; then it converts them to binary representation and reconstructs bytes from the binary stream. ⁉️“This encoding allows binary data to be embedded within normal-looking text. The visible characters serve as camouflage while the invisible characters carry the actual payload,” GoDaddy says.⁉️

            [ImageSource: GoDaddy]

👾The final stage of the attack is implementing a backdoor that responds to specially crafted POST requests that include a specific authentication cookie. If the "tEcaKKXEsb cookie is present, the backdoor accepts base64-encoded PHP code via POST parameter," the researchers explain.👾

GoDaddy describes several evasion mechanisms employed by the malware, including obfuscated strings using octal and hex escapes, randomized function names, fake disabled logging code and the use of standard WordPress APIs, allowing it to blend with normal activity.

⁉️Site owners can defend by checking for references to Steam Community URLs, suspicious external JavaScript injections, outbound connections from WordPress servers to Steam, and unexpected scripts loading from domains such as hello-mywordl[.]info.⁉️

⚠️Other indicators include invisible Unicode characters, suspicious _transient_caption_ cache entries, disabled SSL verification in cURL requests and POST requests containing the malware's authentication cookies or the new_code parameter.⚠️

            Alt...[ImageSource: GoDaddy] 👾The final stage of the attack is implementing a backdoor that responds to specially crafted POST requests that include a specific authentication cookie. If the "tEcaKKXEsb cookie is present, the backdoor accepts base64-encoded PHP code via POST parameter," the researchers explain.👾 GoDaddy describes several evasion mechanisms employed by the malware, including obfuscated strings using octal and hex escapes, randomized function names, fake disabled logging code and the use of standard WordPress APIs, allowing it to blend with normal activity. ⁉️Site owners can defend by checking for references to Steam Community URLs, suspicious external JavaScript injections, outbound connections from WordPress servers to Steam, and unexpected scripts loading from domains such as hello-mywordl[.]info.⁉️ ⚠️Other indicators include invisible Unicode characters, suspicious _transient_caption_ cache entries, disabled SSL verification in cURL requests and POST requests containing the malware's authentication cookies or the new_code parameter.⚠️

              [?]AA » 🌐
              @AAKL@infosec.exchange

              You could always just drop Google and get on with it.

              Computerworld: How to opt out of Google’s new AI training default computerworld.com/article/4183

                [?]The New Oil » 🤖 🌐
                @thenewoil@mastodon.thenewoil.org

                [?]gtbarry » 🌐
                @gtbarry@mastodon.social

                Stockton approved Flock drones. Here’s what the system is — and why it has drawn scrutiny elsewhere

                For outside experts, the problem is not just one camera or one drone. It is the network.

                the central question is not only what the drones can see, but what happens to the data collected by the system already in place.

                stocktonia.org/news/local-gove

                  [?]Metin Seven » 🌐
                  @metin@graphics.social

                  Meme, showing a continuous circle of data breach messages from corporations…

Ahaha you're not gonna believe this but we had a bit of a data breach.

Your data is probably for sale online now.

That means someone could easily impersonate you.

Going forward we're gonna need more of your data to make sure its you.

                  Alt...Meme, showing a continuous circle of data breach messages from corporations… Ahaha you're not gonna believe this but we had a bit of a data breach. Your data is probably for sale online now. That means someone could easily impersonate you. Going forward we're gonna need more of your data to make sure its you.

                    [?]ladyteruki [She/Her] » 🌐
                    @ladyteruki@mastodon.social

                    Youtube seems to be currently implementing the announced change to how shared links work. I know it's possible to clean up a url before sharing it, but since there's also an option... might as well disable it. And yes it's opt out.

                    Screenshot of Youtube's Privacy options (as seen on a smartphone).
The one important here is the last one, "Channel visibility for shared links : Show your channel name, handle, and profile picture to people who open links you share outside Youtube", a simple toggle.

                    Alt...Screenshot of Youtube's Privacy options (as seen on a smartphone). The one important here is the last one, "Channel visibility for shared links : Show your channel name, handle, and profile picture to people who open links you share outside Youtube", a simple toggle.

                      [?]The New Oil » 🤖 🌐
                      @thenewoil@mastodon.thenewoil.org

                      [?]Marcel SIneM(S)US » 🌐
                      @simsus@social.tchncs.de

                      [?]sanitation » 🌐
                      @sanitation@lemmy.today

                      'Nobody Is Safe': FL Man Sues After AI Facial Recognition Wrongly Tags Him Child Luring Suspect in Shocking Police Blunder

                      (https://lemmy.dbzer0.com/c/privacy)

                      [?]AegisLink » 🌐
                      @AegisLink@mastodon.social

                      Building a messenger that knows nothing about you. No phone number. No email. No metadata — not even when you talk or who you talk to.

                      Open source (GPL-3.0/AGPL-3.0), E2EE (X3DH + Double Ratchet, keys never leave your device), built by one person, in public.

                      This account documents the journey.

                        [?]The New Oil » 🤖 🌐
                        @thenewoil@mastodon.thenewoil.org

                        Back to top - More...