handmade.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
handmade.social is for all handmade artisans to create accounts for their Etsy and other handmade business shops.

Server stats:

37
active users

#faceid

0 posts0 participants0 posts today
Erik van Straten<p>Passkey/password bug: iOS 18.3.1</p><p>Ook in iOS versie 18.3.1 is de eerder door mij gemelde iCloud KeyChain (*) kwetsbaarheid nog niet gerepareerd (eerder schreef ik hierover, Engelstalig: <a href="https://infosec.exchange/@ErikvanStraten/113821443334366419" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.exchange/@ErikvanStrat</span><span class="invisible">en/113821443334366419</span></a>).</p><p>(*) Tegenwoordig is dat de app genaamd "Wachtwoorden" (of "Passwords").</p><p>De kwetsbaarheid bestaat indien:</p><p>• De eigenaar een "passcode" (pincode of wachtwoord) gebruikt om de iPhone of iPad te ontgrendelen - en er GÉÉN biometrie is geconfigureerd;</p><p>ofwel:</p><p>• De gebruiker wel biometrie kan gebruiken om het scherm te ontgrendelen, doch in 'Instellingen' &gt; 'Touch ID en toegangscode' de instelling "Autom. invullen wachtw." is UITgezet.</p><p>Zie onderstaande screenshots (Engelstalig in <a href="https://infosec.exchange/@ErikvanStraten/113821443334366419" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.exchange/@ErikvanStrat</span><span class="invisible">en/113821443334366419</span></a>). Meer info ziet u door op "Alt" in de plaatjes te drukken.</p><p>Probleem: iedereen met toegang tot de ontgrendelde iPhone of iPad kan dan, *zonder* opnieuw lokaal te hoeven authenticeren:</p><p>1) Op elke website inloggen waarvan het user-ID en wachtwoord in iCloud Keychain zijn opgeslagen;</p><p>2) Met passkeys op enkele specifieke websites inloggen (waaronder <a href="https://account.apple.com" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">account.apple.com</span><span class="invisible"></span></a> en <a href="https://icloud.com" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">icloud.com</span><span class="invisible"></span></a>), namelijk als volgt:</p><p>a) Open de website;<br>b) Druk op "Inloggen";<br>c) Druk op de "x" rechts bovenaan de pop-up die verschijnt (in de onderste schermhelft);<br>d) Druk kort in het veld waar om het e-mailadres gevraagd wordt;<br>e) Druk op de knop "gebruik passkey".</p><p>Risico: uitlenen van een unlocked iDevice (o.a. aan kinderen) maar ook diefstal nadat de passcode is afgekeken. Of als de dief geen passcode heeft, als deze wacht tot de eerstvolgende iOS/iPadOS kwetsbaarheid bekend wordt waarbij de schermontgrendeling omzeild kan worden.</p><p>Als u ze nog niet gezien heeft, bekijk in elk geval de eerste van de volgende twee video's van Joanna Stern (van de Wall Street Journal):<br><a href="https://youtube.com/watch?v=QUYODQB_2wQ" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">youtube.com/watch?v=QUYODQB_2wQ</span><span class="invisible"></span></a><br><a href="https://youtube.com/watch?v=tCfb9Wizq9Q" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">youtube.com/watch?v=tCfb9Wizq9Q</span><span class="invisible"></span></a></p><p><a href="https://infosec.exchange/tags/TouchID" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TouchID</span></a> <a href="https://infosec.exchange/tags/FaceID" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FaceID</span></a> <a href="https://infosec.exchange/tags/Passkeys" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Passkeys</span></a> <a href="https://infosec.exchange/tags/iCloudKeychain" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>iCloudKeychain</span></a> <a href="https://infosec.exchange/tags/Passwords" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Passwords</span></a> <a href="https://infosec.exchange/tags/PadswordsApp" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PadswordsApp</span></a> <a href="https://infosec.exchange/tags/Wachtwoorden" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Wachtwoorden</span></a> <a href="https://infosec.exchange/tags/WachtwoordenApp" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WachtwoordenApp</span></a> <a href="https://infosec.exchange/tags/Biometrie" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Biometrie</span></a> <a href="https://infosec.exchange/tags/Passcode" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Passcode</span></a> <a href="https://infosec.exchange/tags/iOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>iOS</span></a> <a href="https://infosec.exchange/tags/iPadOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>iPadOS</span></a> <a href="https://infosec.exchange/tags/iPhone" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>iPhone</span></a> <a href="https://infosec.exchange/tags/iPad" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>iPad</span></a> <a href="https://infosec.exchange/tags/iDevice" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>iDevice</span></a> <a href="https://infosec.exchange/tags/ScreenLock" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ScreenLock</span></a> <a href="https://infosec.exchange/tags/ScreenUnlock" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ScreenUnlock</span></a> <a href="https://infosec.exchange/tags/SchermVergrendeling" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SchermVergrendeling</span></a> <a href="https://infosec.exchange/tags/SchermOntgrendeling" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SchermOntgrendeling</span></a> <a href="https://infosec.exchange/tags/SchermOntgrendelCode" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SchermOntgrendelCode</span></a> <a href="https://infosec.exchange/tags/PINcode" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PINcode</span></a> <a href="https://infosec.exchange/tags/Kwetsbaarheid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Kwetsbaarheid</span></a> <a href="https://infosec.exchange/tags/Vulnerability" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Vulnerability</span></a> <a href="https://infosec.exchange/tags/OngeautoriseerdeToegang" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OngeautoriseerdeToegang</span></a> <a href="https://infosec.exchange/tags/IdentiteitsFraude" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IdentiteitsFraude</span></a> <a href="https://infosec.exchange/tags/Inloggen" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Inloggen</span></a> <a href="https://infosec.exchange/tags/Stern" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Stern</span></a> <a href="https://infosec.exchange/tags/JoannaStern" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>JoannaStern</span></a> <a href="https://infosec.exchange/tags/WSJ" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WSJ</span></a></p>
Matthew Abbott<p>:boost_requested: <a href="https://oliphaunt.social/tags/PSA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PSA</span></a>: It looks like <a href="https://oliphaunt.social/tags/iOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>iOS</span></a> 18 removed the ability to disable biometrics and USB data with “Hey Siri, whose phone is this?” and similar prompts. Activating the power/SOS screen with physical buttons still works.</p><p><a href="https://oliphaunt.social/tags/Siri" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Siri</span></a> can now shut off or restart your phone *but* you will need time to respond to their confirmation prompt.</p><p>Remember that <a href="https://oliphaunt.social/tags/TouchID" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TouchID</span></a> can be compelled and that <a href="https://oliphaunt.social/tags/FaceID" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FaceID</span></a> requires open eyes</p>
Autonomie und Solidarität<p><a href="https://todon.eu/tags/Clearview" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Clearview</span></a> <a href="https://todon.eu/tags/AI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AI</span></a> used nearly 1m times by US police</p><p>"Facial recognition firm Clearview has run nearly a million searches for US police, its founder has told the BBC.<br>Clearview's system allows a law enforcement customer to upload a photo of a face and find matches in a database of billions of images it has collected.<br>It then provides links to where matching images appear online. It is considered one of the most powerful and accurate facial recognition companies in the world."</p><p><a href="https://www.bbc.com/news/technology-65057011" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bbc.com/news/technology-650570</span><span class="invisible">11</span></a></p><p><a href="https://todon.eu/tags/Surveillance" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Surveillance</span></a> <a href="https://todon.eu/tags/faceID" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>faceID</span></a> <a href="https://todon.eu/tags/%C3%9Cberwachung" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Überwachung</span></a> <a href="https://todon.eu/tags/police" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>police</span></a> <a href="https://todon.eu/tags/netzpolitik" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>netzpolitik</span></a> <a href="https://todon.eu/tags/antireport" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>antireport</span></a> <a href="https://todon.eu/tags/reclaimyourface" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reclaimyourface</span></a></p>
Autonomie und Solidarität<p>Iran installs cameras in public places to identify, penalise unveiled women</p><p>"In a further attempt to rein in the increasing number of women defying Iran's compulsory dress code, authorities are installing cameras in public places and thoroughfares to identify and penalise unveiled women, the police announced on Saturday.<br>After they have been identified, violators will receive “warning text messages as to the consequences”, police said in a statement."</p><p><a href="https://www.reuters.com/world/middle-east/iran-installs-cameras-public-places-identify-penalise-unveiled-women-police-2023-04-08/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">reuters.com/world/middle-east/</span><span class="invisible">iran-installs-cameras-public-places-identify-penalise-unveiled-women-police-2023-04-08/</span></a></p><p><a href="https://todon.eu/tags/Iran" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Iran</span></a> <a href="https://todon.eu/tags/Repression" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Repression</span></a> <a href="https://todon.eu/tags/videosurveillance" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>videosurveillance</span></a> <a href="https://todon.eu/tags/Surveillance" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Surveillance</span></a> <a href="https://todon.eu/tags/socialcontroll" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>socialcontroll</span></a> <a href="https://todon.eu/tags/Biometrie" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Biometrie</span></a> <a href="https://todon.eu/tags/Gesichtserkennung" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Gesichtserkennung</span></a> <a href="https://todon.eu/tags/WomanLifeFreedom" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WomanLifeFreedom</span></a> <a href="https://todon.eu/tags/Antireport" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Antireport</span></a> <a href="https://todon.eu/tags/faceID" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>faceID</span></a> <a href="https://todon.eu/tags/reclaimyourface" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reclaimyourface</span></a></p>
Autonomie und Solidarität<p><a href="https://todon.eu/tags/Clearview" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Clearview</span></a> <a href="https://todon.eu/tags/AI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AI</span></a> used nearly 1m times by US police, it tells the BBC</p><p>"CEO Hoan Ton-That also revealed Clearview now has 30bn images scraped from platforms such as <a href="https://todon.eu/tags/facebook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>facebook</span></a> taken without users' permissions.<br>The company has been repeatedly fined millions of dollars in <a href="https://todon.eu/tags/Europe" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Europe</span></a> and <a href="https://todon.eu/tags/Australia" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Australia</span></a> for breaches of privacy.<br>Critics argue that the police's use of Clearview puts everyone into a "perpetual police line-up".<br>"Whenever they have a photo of a suspect, they will compare it to your face," says Matthew Guariglia from the <span class="h-card" translate="no"><a href="https://mastodon.social/@eff" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>eff</span></a></span> says. "It's far too invasive.""</p><p><a href="https://www.bbc.com/news/technology-65057011" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bbc.com/news/technology-650570</span><span class="invisible">11</span></a></p><p><a href="https://todon.eu/tags/Surveillance" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Surveillance</span></a> <a href="https://todon.eu/tags/faceID" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>faceID</span></a> <a href="https://todon.eu/tags/%C3%9Cberwachung" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Überwachung</span></a> <a href="https://todon.eu/tags/police" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>police</span></a> <a href="https://todon.eu/tags/netzpolitik" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>netzpolitik</span></a> <a href="https://todon.eu/tags/antireport" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>antireport</span></a> <a href="https://todon.eu/tags/reclaimyourface" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reclaimyourface</span></a></p>