Salamander

  • 1 Post
  • 51 Comments
Joined 5 years ago
cake
Cake day: December 19th, 2021

help-circle

  • Definitely, disclosing (either private or publicly) a vulnerability that has been verified is significantly better than passing on the LLM output without verifying it.

    It isn’t my intention to argue one specific case. What I think is that normalizing public disclosure of LLM-inspired vulnerabilities would lead to a wide distribution of cases. We would have some successful cases like yours, and also some cases of the type that I have mentioned. Increase in disclosures will raise the noise floor, and the fact that it is done publicly adds the additional pressure that I mentioned.

    I see your point, but I don’t agree that the benefit of public awareness offsets the increase in noise. This disagreement isn’t rooted in aspects that we can objectively quantify though - we just have a difference of opinion here.


  • And in that world, doing a private disclosure made a lot of sense because you did a lot of hard work to find it, and it wasn’t easy for somebody to replicate. This was valuable and dangerous knowledge that had to be communicated in a responsible fashion.

    Private disclosure still makes sense to me when you add LLMs into the mix. It is possible that an LLM outputs some plausible-sounding story that over-estimates the actual risk and impact of the exploit. If this story is publicly announced to people who use the software but are not capable of assessing these risks themselves, this can easily have a negative unnecessary consequence - for example, people may bring their server down until an expert or developer provides an assessment or fix.

    This is a source of noise, and I don’t agree that this is better than private disclosure. Via public disclosure one is applying a lot of pressure to the developer(s) to prioritize whatever is being disclosed, which may not always be the nicest thing to do, especially if the impact is not as significant as the LLM suggests. This may not have been what happened in your case (I don’t know the details), but I am thinking about the idea of the average person disclosing publicly LLM-discovered vulnerabilities.




  • Thanks a lot for the examples! I have been looking through these, and, as far as I can tell:

    1. In SSL stripping, the site would appear to your client as HTTP, not HTTPS. If that’s the case, I think SSL stripping is blocked when using ‘HTTPS-Only’ mode
    2. For DNS spoofing, the visited site would show up as insecure because they would not be able to generate a valid certificate for the target website

    I still have not had the chance to look into leaky metadata. But, generally, I think metadata issues can in part be addressed by not generating much metadata.

    Probably the biggest vulnerability is the captive portal. There is no way to verify you’re connecting to an official Starbucks router. I think that when connecting to a public router it is wise to assume that it is malicious.





  • Salamander@mander.xyztoPrivacy@lemmy.mlSIM card VS e-SIM
    link
    fedilink
    arrow-up
    3
    ·
    edit-2
    1 year ago

    That’s a very interesting resource!

    Actually, the countries where I have been able to purchase anonymous SIM cards are in the list “As of 2021, the following countries do not have mandatory SIM card registration laws”. So, it appears like I just happen to have been lucky and I should not make this as such a general recommendation…

    Funny, about Mexico it says:

    Countries expected to implement mandatory SIM registration in 2022: Philippines, Mexico.

    I can at least confirm that I was not asked for ID when buying SIM cards last year in Mexico.

    I just looked it up and found the proposed law for Mexico on Wikipedia. It was struck down in 2022 as unconstitutional.

    So, then, I really have no anecdotes to say that it is easy in places where it is formally illegal.


  • I am not sure about France. When I search online, I often find resources stating “Yes, ID is required”, even for the countries where I know that I have bought SIM cards with cash. Well, the SIM is usually free and what I pay for is the top-up code.

    I would imagine (but I’m not sure) that if you try to buy a SIM card at an airport or at an official store from a large telephony provider you are more likely to get asked for an ID. I find them in shops that have signs with the names of smaller MVNOs. Something like what is shown in this image that I found online, where you can see signs of ‘Lyca Mobile’ and ‘Lebara’:

    But, your mileage may vary. Probably some locations are more strict than others.


  • Depending on where you are travelling to and from, you can often get an anonymous prepaid SIM card. That is what I do: buy one with cash, put it into a MiFi router, and only switch it on when I need internet. That way I stay off the records of whoever else is with me and I am not relying on their identity as a shield. I have not found an eSIM provider that gives me the same level of anonymity, so I have avoided those.

    If you really have to register a SIM with your identity, it depends on the situation. For example, if you buy a SIM in the EU, activate roaming, and then use it in Mexico, the Mexican authorities can’t instantly demand your subscriber info from the EU. On the other hand, if you or your family buy local SIMs while showing ID, then travel together and check in to hotels together, it makes little difference whose SIM is whose. For Mexico specifically, you can walk into an OXXO store, pay cash, and get a prepaid SIM with a data package, no ID required. Many countries have similar cash options so you check ahead of time.

    About whether the worry is justified. The type of surveillance you mention, such as stingrays, requires both strong capability and strong motivation. If a government wanted to, they could stop your entire family at the border before you ever left. But from what you describe, you are just a foreigner who might pass by a protest. That is unlikely to trigger the level of targeting you are thinking of.

    Still, I would not call it “in vain.” Building habits that protect privacy and understanding how information flows is always useful. But if you can get a prepaid SIM anonymously with cash, it is usually a cleaner option than tethering from family.


  • I like the idea of PeerTube, but I tried running an instance and was unable to sustain the experiment for too long. I made it very open and it got quickly flooded by pirated TV series and spammy and heavy content.

    After that, I had a difficult time at some point finding an instance to host some videos I wanted to upload - and, having had that failed experiment before hand, I can see why the instances that do survive are often those with more stringent filters and less generous with resources.

    So, I am sorry to “chime in about the shortcomings”, but hosting a PeerTube instance can be a demotivating experience. You set up the infrastructure expecting to contribute to a space reminiscent of the old youtube, and you see it filled with spam. The signal-to-noise ratio is just awful and it is expensive. To avoid this, you can be an aggressive gate keeper - but this makes the platform less friendly to people who are looking to find a space to share their original content. Gate keeping is also an additional effort that you need to make. In the end I chose to just shut it off as it was more of a hassle than fun. By comparison, hosting a Lemmy instance is fun, much much cheaper, and little hassle.

    I still haven’t given up on the idea of Peertube, though… I have some video ideas, and when I finally get to making them I plan to make another instance to host only my channel. Then, I would be able to host my own channel using my own infrastructure via a federated network. This use case would work very well for me, and it can probably work for many others. So that is one way of building the Peertube network.

    General permissive video uploads is something that makes YouTube such a powerful platform though, and that is very difficult to replicate.






  • Salamander@mander.xyzOPtoPrivacy@lemmy.mlThe Pager
    link
    fedilink
    arrow-up
    3
    ·
    1 year ago

    Yeah, as others mentioned, you can get cheaper data plans depending on the monthly data you need.

    However, one of the interesting properties is that, unlike with phones, there is no restriction on the number of pagers that can listen to your assigned RIC. You can use one subscription to communicate with as many pagers as you would like, and each individual pager can be programmed using text filters such that one can implement their own sub-address system.