Salta al contenuto principale






Two Alleged Pirate IPTV Operators Sent to Prison For Contempt of Court


Two men said to be the operators of SmoothStreams, a pirate IPTV service shut down by entertainment companies over three years ago, have been imprisoned in Canada. Marshall Macciacchera and his father Antonio were both found guilty of contempt and sentenced to an initial term of six months. Marshall's sentence will continue until he complies with a court order to hand over financial information and a laptop password, among other things.

in reply to BrikoX

National security interests would drive the selection of certain companies. But all companies that need a bailout should do it in exchange for privileged stock. I'm tired of companies like ATT getting billions of dollars of free money for shit like "fiber infrastructure" and then just pocketting it. If they want that money, and if it is a matter of law, then they get uncle sam on the board telling them to spend it how it was meant to be spent.
Questa voce è stata modificata (3 settimane fa)
in reply to wetbeardhairs

Bailouts are already conditional by law. Companies just break them and get fined cents for it. So clearly that's not the solution.




Israeli forces kill Palestinian basketball star in Gaza aid centre shooting


Local media report Mohammed Shaalan was killed while attempting to secure food and medicine for his family


Archived version: archive.is/newest/middleeastey…


Disclaimer: The article linked is from a single source with a single perspective. Make sure to cross-check information against multiple sources to get a comprehensive view on the situation.






New Syrian government moves to dismantle Assad’s $5bn narco-state


Syria’s new leadership under President Ahmed Al-Sharaa has launched an aggressive campaign to dismantle the vast captagon drug empire left behind by ousted dictator Bashar Al-Assad, whose regime transformed the country into one of the world’s largest narco-states. The drug trade, valued at over $5 billion annually, became a lifeline for Assad during the civil war, as sanctions and conflict crippled the economy.


Archived version: archive.is/newest/middleeastmo…


Disclaimer: The article linked is from a single source with a single perspective. Make sure to cross-check information against multiple sources to get a comprehensive view on the situation.



Turkey is still ready to deploy peace force in Ukraine


While Ankara may commit itself to sending troops as part of security guarantees, Russia's approval is more important than European plans


Archived version: archive.is/newest/middleeastey…


Disclaimer: The article linked is from a single source with a single perspective. Make sure to cross-check information against multiple sources to get a comprehensive view on the situation.



Microsoft’s Security Plan to Protect U.S. Government Data from Hacking Omits China Operations


The tech giant is required to regularly provide U.S. officials with its plan for keeping government data safe from hacking. Yet a copy of Microsoft’s security plan obtained by ProPublica makes no reference to the company’s China-based operations.


VPN Logging Policies in 2025: Which 'No-Logs' Providers Pass the Test?


From the article:

VPNHQ & Eyes AllianceLatest Independent AuditReal-World TestRetention Verdict*
ExpressVPNBritish Virgin Islands (no data-retention laws)KPMG ISAE 3000 Type I, Feb 2025 (ExpressVPN)Split-tunnelling DNS leak disclosed Feb 2024 (patched)Gold-standard. RAM-only fleet, annual audits, BVI jurisdiction.
NordVPNPanamaDeloitte 5th audit, Dec 2024 (NordVPN)2018 server breach – no logs leakedRegular audits and positive breach outcome.
SurfsharkNetherlands (9-Eyes)Deloitte, Jan 2023 (Surfshark)TunnelCrack Wi-Fi leak (Aug 2023) → patched in <7 days.Strong audit hygiene but concerning jurisdiction.
Proton VPNSwitzerlandSecuritum, Apr 2024 (securitum.com)N/AOpen-source clients + Swiss privacy laws.
MullvadSweden (14-Eyes)Assured AB config audit 2023Swedish police raid Apr 18 2023 left empty-handed (Mullvad VPN)Minimal-data design proven in the wild.
Private Internet AccessUSA (5-Eyes)Deloitte, Apr 2024 (Private Internet Access)Multiple US subpoenas produced no logsPaper-trail-verified despite US HQ.
CyberGhostRomania (EU, outside Eyes)Deloitte, May 2024 (CyberGhost VPN)N/ASecond audit boosts trust.
TunnelBearCanada (5-Eyes)Cure53 7th audit, Dec 2023 (TunnelBear: Secure VPN Service)N/ALongest unbroken audit streak.
WindscribeCanada (5-Eyes)Cure53 server image audit 20222025 Greek/Canadian court case upheld no-logs stance (Tom’s Guide)Policy tested – passed.
Hotspot ShieldUSA (5-Eyes)Performance/security review by AV-Test only; no dedicated no-logs audit (vpnMentor)AV-TEST performance audit only; no no-logs audit to date. (CVE Details)Speed king, privacy laggard.

Archived links:

Questa voce è stata modificata (3 settimane fa)
in reply to barnaclebill

You telling me any of those are not related to israel ? Where they are registred and who truly run them is two different things and I believe a column of who truly is behind is relevant.


Pirating newsletters


Paywalls have become part and parcel of the modern Web it seems. And despite helpful extensions like BPC, there are always many sites where one is constrained to compromise. Many sites also keep stuff like newsletters for subscribers only.

In this specific example, The Verge has launched two new variants and both are behind a paywall. Whilst the site itself works with BPC, is there a way to access the newsletters?

Of course, you might ask why I don't pay. It's because it's exceptionally hard. Ironically for a tech company, Verge took the nonsensical step of NOT having regional specific pricing. So, they are currently more expensive than YouTube, Play Pass and local newspaper subscription combined in my country.

in reply to shnizmuffin

And from there you can anonymously publish the newsletter archives for everyone. I agree there should be some kind of tracker for newsletter piracy though.
in reply to communism

If you do this, have three subscriptions and only publish if two of them are exactly the same.


China wakes to the importance of moving closer to Israel


cross-posted from: lemmy.sdf.org/post/40765971

China’s growing involvement in the Middle East, intensified by the recent escalation of violence in Gaza, is prompting renewed scrutiny of Beijing’s regional strategy, The Jerusalem Post reports. Traditionally focused on securing access to energy resources, safeguarding trade corridors, and expanding infrastructure investments, particularly in the Gulf, China's approach has until recently been marked by strategic ambiguity and a reluctance to take clear sides in regional rivalries.

[...]

Energy security remains central to China’s engagement in the region. As the world’s leading oil importer, China currently sources approximately 40% of its oil from the Middle East; a figure projected to double by 2035. This dependency leaves Beijing vulnerable to disruptions in maritime chokepoints such as the Red Sea and the Strait of Hormuz, which are also vital routes for Chinese trade with Europe and Africa.

[...]

In Israel meanwhile, some have called for a reassessment of relations with China, despite limitations imposed by close ties to Washington. This reassessment could present Israel with an opportunity to strengthen its presence in Asian markets, diversify its regional relationships, while at the same time exploring deeper engagement with countries across the Global South; a region Iran struggles to relate to.

[...]

https://www.intellinews.com/china-wakes-to-the-importance-of-moving-closer-to-israel-395036

in reply to BrikoX

In 2024, China imported goods worth $2.8bn from Israel, while Hong Kong imported an additional $2bn, according to the UN Comtrade database. With the combined $4.8bn, China is worldwide the second-largest buyer of Israeli goods behind the US.

China was, however, the biggest exporter to Israel with $19bn, more than twice the volume of second US with $9.4bn, and Germany with $5.6bn.

That's more than 'ambiguous talk' but has rather long been materializing I would say.

in reply to Hotznplotzn

Considering China's trade power, it's more fair to compare it to the EU bloc which is by far the number one trade partner. Total trade in goods between the EU and Israel in 2024 amounted to €42.6 billion. EU imports from Israel were worth €15.9 billion. The EU’s exports to Israel amounted to €26.7 billion.

And considering China's total exports in 2024 were valued at US$3.58 trillion, it's kind of insignificant in a sense that it signifies a shift in trade policy.

Questa voce è stata modificata (3 settimane fa)



Belarus, Iran sign package of documents on advancing cooperation




96,000 UK Police Bodycam Videos Lost After Data Transfer Mishap


cross-posted from: programming.dev/post/35959876

At the end of each shift, officers’ BWV footage was uploaded and stored to a central hub which could be accessed and managed, along with all of SYP’s digital evidence, via a secure system.

Following an upgrade in May 2023, the secure system began to struggle processing BWV data and a local drive workaround was put in place.

In August 2023 SYP identified that its BWV file storage was very low and further investigation found that 96,174 pieces of original footage had been deleted from its system.

The following month it was found the deletion had taken place on 26 July 2023 and included the loss of data relating to 126 criminal cases, only three of the cases were impacted by the loss. Of those three cases, SYP states one may have progressed to the first court hearing if BWV had been available. However, as there was no additional independent evidence to prove the offence, progression to prosecution stage was already uncertain.

Prior to the deletion, 95,033 pieces of BWV footage had been copied to a new system that SYP was implementing but, due to poor record keeping, SYP remain unable to confirm the exact number of files deleted without copies made.




96,000 UK Police Bodycam Videos Lost After Data Transfer Mishap


At the end of each shift, officers’ BWV footage was uploaded and stored to a central hub which could be accessed and managed, along with all of SYP’s digital evidence, via a secure system.

Following an upgrade in May 2023, the secure system began to struggle processing BWV data and a local drive workaround was put in place.

In August 2023 SYP identified that its BWV file storage was very low and further investigation found that 96,174 pieces of original footage had been deleted from its system.

The following month it was found the deletion had taken place on 26 July 2023 and included the loss of data relating to 126 criminal cases, only three of the cases were impacted by the loss. Of those three cases, SYP states one may have progressed to the first court hearing if BWV had been available. However, as there was no additional independent evidence to prove the offence, progression to prosecution stage was already uncertain.

Prior to the deletion, 95,033 pieces of BWV footage had been copied to a new system that SYP was implementing but, due to poor record keeping, SYP remain unable to confirm the exact number of files deleted without copies made.



in reply to Phoenixz

How can you set up a system like this without having a plan to maintain it and avoid issues like this. It doesnt make sense.


The Document Foundation is proud to release LibreOffice 25.8


The Document Foundation is proud to release LibreOffice 25.8.

LibreOffice is a powerful, free and open source office suite for Linux, MacOS and Microsoft Windows.

No advertising. No data tracking. No subscriptions.

LibreOffice is used by individuals, businesses, schools, hospitals and cities around the world.

blog.documentfoundation.org/bl…

New improvements

Highlights of LibreOffice 25.8 include:

  • Up to 30% faster opening of files in Writer and Calc
  • Support for exporting PDF 2.0
  • Improved user interface: the Welcome/What’s New dialog now offers access to the user interface picker and appearance options
  • Optimized memory management for smoother operation on virtual desktops
  • Improved scrolling through large documents
  • New viewer mode to open all files in read-only mode.
  • Overhauled word hyphenation and spacing
  • New financial functions in Calc
  • Significantly better display of Chinese, Japanese, and Korean DOC/DOCX documents
  • Spell check dictionaries updates for Danish, English, Hindi, Mongolian, Spanish, Thai, and Ukrainian.

The Document Foundation

The Document Foundation is a German non-profit organization.

We believe that Free Software can provide better privacy, quality, reliability, and greater flexibility than corporate alternatives.

Helping

LibreOffice is developed by hundreds of volunteers around the world.

Join us today and help us to make it even better ❤️

👉 libreoffice.org/community/get-…

Thank you to the developers, designers, translators, donors and supporters 🙏 🙏🙏.

Questa voce è stata modificata (3 settimane fa)

Technology reshared this.

in reply to Davriellelouna

Do they have a PDF editor solution?
Questa voce è stata modificata (3 settimane fa)
in reply to ABetterTomorrow

Maybe i got lucky, but i always had good experiences with the pdfs i had to tweak in draw

But most of my modofications are kind of form-filling, alignment font and format was never a reequirement

Questa voce è stata modificata (3 settimane fa)
in reply to ABetterTomorrow

LibreOffice Draw can actually edit PDFs - it's not perfect for complex layouts but works great for basic editing, adding text, and modifing simple elements (tho sometimes formatting gets a bit wonky).
in reply to Davriellelouna

Lots of love for LibreOffice.

Its a great opensource project that just keeps chugging along being great.

My team and I use it exclusively in our consultancy. Complex documents and spreadsheets all day long. LO never gets tired.

Without LO id be beholden to Microsoft.

Apache should really release the rights to the name OpenOffice and let LO have it.



Wednesday, August 20, 2025


[vlog/video] Trump-Zelensky summit was theater, not progress: Landsbergis — Russia resumes stolen grain shipments from occupied Ukrainian territories to Syria — Ukrainian drones hit oil refinery in Russia’s Volgograd Oblast — Security guarantees for Ukrai

Share

The Kyiv Independent [unofficial]


This newsletter is brought to you by Medical Bridges.

Medical Supplies for Ukraine’s Hospitals. Partnering for global health equity.

Russia’s war against Ukraine


Supporters of the Ukraine Solidarity Campaign protest in Parliament Square on August 19, 2025 in London, England. President Zelensky has said today that he is willing to meet President Putin for peace talks to end Russia’s war on Ukraine. (Guy Smallman / Getty Images)

Zelensky, Putin may meet within 2 weeks, German chancellor says. “The American president spoke with the Russian president on the phone and agreed that there would be a meeting between the Russian president and the Ukrainian president within the next two weeks,” German Chancellor Friedrich Merz said.

US troops won’t be sent to Ukraine as part of security guarantees, Trump says. U.S. President Donald Trump said on Aug. 19 that U.S. soldiers will not be on the ground in Ukraine to ensure security guarantees are upheld, deflecting the responsibility to European allies.

NATO military leaders to meet on Aug. 20 to discuss security guarantees for Ukraine. NATO military leaders are scheduled to meet virtually on Aug. 20 to discuss the alliance’s support for Ukraine as European leaders continue negotiations with Kyiv and Washington on security agreements for the embattled country.

‘I want to try to get to heaven,’ Trump cites divine motivation for Ukraine peace. “If I can save 7,000 people a week from being killed, I think that’s a pretty… I want to try to get to heaven if possible, I’m hearing that I’m not doing well,” Trump said on Aug. 19.

Your contribution helps keep the Kyiv Independent going. Become a member today.

Russia resumes stolen grain shipments from occupied Ukrainian territories to Syria. Russia has resumed grain shipments to Syria from within occupied Crimea, transporting stolen grain from Ukraine’s occupied territories, reported Kateryna Yaresko, a journalist with the Ukrainian SeaKrime project that tracks Russia’s illegal shipping activity.

Zelensky outlines $90 billion US arms deal as part of Ukraine’s security guarantees. By tying its defense needs to a major boost for U.S. industry, Ukraine hopes to turn its request into an investment opportunity that appeals directly to American interests. The proposal also includes a separate $50 billion agreement for producing drones with Ukrainian companies.

Ukrainian drones hit oil refinery in Russia’s Volgograd Oblast, governor says.

The refinery is the second-largest owned by Lukoil and a key producer of petroleum products in Russia’s Southern Federal District.

Ukrainian drones destroy 2 Russian ammo depots in Luhansk Oblast, Security Service says. The strikes hit warehouses in the village of Bilokurakyne, located on a key railway line supplying Russian forces on the Pokrovsk front, where Moscow is focusing its primary offensive efforts.

Read our exclusives


Trump walks back from Ukraine ceasefire calls, aligning closer with Russia’s push for peace deal

U.S. President Donald Trump has walked away from his ceasefire demand, saying that he supports its “concept” but can push for a peace deal between Russia and Ukraine without one.

Photo: Andrew Harnik / Getty Images

Learn more

Ukraine war latest: US troops won’t be sent to Ukraine as part of security guarantees, Trump says

Trump said on Aug. 19 that U.S. soldiers will not be on the ground in Ukraine to ensure security guarantees are upheld, deflecting the responsibility to European allies.

Photo: Bonnie Cash /UPI /Bloomberg via Getty Images

Learn more

Did Zelensky wear a suit? President’s outfit at White House meeting sparks fresh debate

All eyes were on President Volodymyr Zelensky’s outfit as he arrived at the White House to meet President Donald Trump, months after his previous Washington visit sparked controversy — in part over what he wore.

Photo: Anna Moneymaker / Getty Images

Learn more

Security guarantees for Ukraine explained: What’s on the table and what’s realistic?

As peace talks to end the war gather speed toward a potential trilateral meeting between the U.S., Ukraine, and Russia, the question of what kind of security guarantees Kyiv might receive continues to loom large.

Photo: Tom Brenner for The Washington Post via Getty Images

Learn more

From Crimea to Donbas, Russia’s “peace” has always meant more war. We’re here in Ukraine to give the world a reality check. Support independent journalism in this critical moment.

BECOME A MEMBER

MAKE A DONATION

Human cost of Russia’s war


Russian strikes killed 21, injured 99 in Ukraine since Trump-Putin summit.

Five people were killed and 11 injured on Aug. 17, followed by eight killed and 35 injured on Aug. 18, and at least eight killed and 53 injured on Aug. 19.

Russia’s Aug. 17 strike on Kharkiv kills 7, injures 24, just hours before Zelensky met with Trump in Washington. Russia launched a wave of missile and drone attacks against Ukrainian cities late on Aug. 17, mere hours before President Volodymyr Zelensky is scheduled to meet for peace talks with U.S. President Donald Trump at the White House.

Ukraine repatriates 1,000 bodies of fallen soldiers from Russia. According to Russian authorities, the remains belong to Ukrainian servicemembers killed in action in Donetsk, Zaporizhzhia, Luhansk, and Kursk regions.

Trump-Zelensky summit was theater, not progress — Landsbergis

International response


Hungary emerges as potential venue for Zelensky-Putin meeting, Reuters reports. Hungarian Prime Minister Viktor Orban has blocked or delayed military aid to Ukraine, maintained ties with Russian President Vladimir Putin, and echoed Kremlin narratives.

EU’s 19th sanctions package against Russia expected to be ready in September, Kallas says. The European Union’s 19th package of sanctions against Russia is expected to be ready in September, top EU diplomat Kaja Kallas announced on Aug. 19, as the EU ramps up its pressure on Moscow in hopes that it will push Russia to end its war in Ukraine.

Trump raises topic of Ukraine’s EU membership with Orban, Bloomberg reports. According to sources cited by Bloomberg, European leaders urged U.S. President Donald Trump to pressure Orban into dropping his opposition to Ukraine’s EU accession talks.

Switzerland ready to give Putin immunity for peace talks. Switzerland is prepared to grant Russian President Vladimir Putin immunity from arrest if he travels to Geneva for peace negotiations, Swiss Foreign Minister Ignazio Cassis said in an interview on Aug. 19.

Around 10 European allies willing to send troops to Ukraine, talks accelerate on security guarantees, Bloomberg reports. Talks among European officials on Aug. 19 reportedly focused on proposals to send troops from the U.K. and France to Ukraine, along with contingents from roughly 10 other countries.

In other news


Border guards detain priest attempting to smuggle draft-age man across Ukrainian border. The priest had concealed the passenger under his robes on the back seat to bypass checkpoints. The passenger turned out to be a 41-year-old resident of Sumy Oblast.

This newsletter is open for sponsorship. Boost your brand’s visibility by reaching thousands of engaged subscribers. Click here for more details.

Today’s Ukraine Daily was brought to you by Oleg Sukhov, Oleksiy Sorokin, Tymur Zadorozhnyy, Dmytro Basmat, Olena Goncharova, and Lucy Pakhnyuk.

If you’re enjoying this newsletter, consider joining our membership program. Start supporting independent journalism today.

Share

#russia #syria #france #germany #uk #washington #hungary #NATO #Trump #england #EuropeanUnion #german #genocide #switzerland #ukrainian #Ukraine #drones #homes #orban #London #european #geneva #Putin #protests #destroy #warcrimes #moscow #Apartments #украина #soldiers #troops #Kyiv #crimea #путин #donetsk #luhansk #zelensky #Sanctions #kharkiv #alaska #Zaporizhzhia #grain #PutinWarCrimes #CrimesAgainstHumanity #RussianWarCrimes #russianwar #dronestrikes #Theft #missiles #terrorists #houses #negotiations #lukoil #Smuggling #FriedrichMerz #ceasefire #Landsbergis #Kursk #petroleum #Киев #геноцид #russianterrorists #russianterrorism #Pokrovsk #RussianAggression #realistic #missileattacks #occupiedterritories #KyivIndependent #oilrefinery #trumpisarussianasset #grainshipments #sumyoblast #warehouses #parliamentsquare #USTroops #OilRefineries #internationallawviolations #borderguards #RailwayLine #villages #armsdeal #trumpputin #ukrainepeace #killingcivilians #peacenegotiations #residentialbuildings #securityguarantees #eumembership #russianstrikes #Russianforces #militaryleaders #ukrainiandrones #occupiedcrimea #americaninterests #UkraineSolidarity #CiviliansTargeted #europeanallies #ComradeKrasnov #diplomatictheater #ukrainiancities #checkpoints #civiliansAttacked #civiliansTortured #LuhanskOblast #Военныепреступления #Преступленияпротивчеловечества #Российскиежертвы #RussianCausalities #residentialAreas #stolenGrain #VolgogradOblast #UkrainianBorder #ammoDepots #Bilokurakyne #deadRussians #divineMotivation #illegalShipping #KremlinNarratives #producingDrones #sanctionsPackages #SeaKrime #SouthernFederalDistrict #TrumpZelenskySummit


in reply to Davriellelouna

This is 'GM in 2008' all over again.

(because a company that's 'too big to fail' has been bailed out by the government before)

Questa voce è stata modificata (2 settimane fa)


CrowdBucks is a new payment system for the Fediverse


This was initially demoed at FediCon 2025, but CrowdBucks is an open source, self-hostable fundraising system that allows people to financially support one another. You use your existing Fediverse account to hold a fundraiser, and can also donate to other people's fundraisers as well. The form factor is kind of similar to Kickstarter or Patreon.


CrowdBucks is a new payment system for the Fediverse


More developments are happening on the front to provide payment and monetization options for the Social Web. Over the past few years, there have been interesting experiments in making this possible. Mitra, notably, pioneered subscription payments by utilizing Monero. Bandwagon has also built on the concept by instead relying on integrations with traditional payment networks, starting with Stripe and PayPal. The short-lived SubClub implemented private feeds for paid access.

Introducing CrowdBucks


CrowdBucks is a new effort developed by Charles Iliya Krempeaux, better known by his online moniker, Reiver. It builds on some of the ideas previous implementations have tried, and aims to make the process as smooth and simple as possible.

“The long-term vision that CrowdBucks is a part of is to create a payments layer for the Fediverse,” Reiver explains, “obviously, it’s not the only part, there will be other projects later.”
CrowdBucks caption saying "All You Have to Do...As a Helper...1. Open a CrowdBucks Page2. Sign In with a Fediverse Account3. Donate"Source: CrowdBucks

Signing Up


Instead of forcing users to create yet another account, CrowdBucks does something really smart: you can just sign in with an existing Fediverse account.

At the moment, sign-in is limited to just Mastodon, but the plan is to gradually support a number of different platforms. Since a lot of Fediverse software implements part of the Mastodon API, I attempted to log in with both Akkoma and WordPress, but neither one seems to work yet. We opted to use a tried-and-true community instance.

After doing the Authorization dance, CrowdBucks directs users to a simple dashboard, where they are prompted to do basic setup for their page. Fediverse integration automatically pulls in profile details, including the username, avatar, header, and handle, although most of the public-facing details can be customized.


Getting Set Up


The first thing to do with your account is to set fundraising goals and donation tiers. The flow feels reminiscent of something like Kickstarter or Patreon, where rewards can be spelled out as something symbolic, something digital, or even something tangible.
You can view our demo account here. Please, don’t actually donate to this.

Donations and Payments


Support tiers can be set up with any monthly denomination, and these get prominently displayed on your CrowdBucks page. Donors can use their CrowdBucks accounts to find a page, select a tier, and support creators and projects easily.

When a person pledges towards a Tier, they’re automatically taken to a checkout page. For the time being, the only supported Payment Processor is Stripe. Reiver has explained that this is because Stripe was easiest to implement, but the team intends to also add support for PayPal and other providers, as well as support for standards such as Web Monetization and OpenPayments.


Quick Demo


CrowdBucks was initially revealed in a brief demo at FediCon a few weeks ago, which was recorded and added alongside the FediCon Talks on PeerTube. It’s a useful insight into where Reiver is coming from, what’s being built, and ideas of what CrowdBucks could be used for.

spectra.video/videos/embed/5bp…

Open Source and Self-Hostable


“Anyone will be able to set up their own CrowdBucks server,” Reiver explains, “just like anyone can set up their own Mastodon server.”

The CrowdBucks project itself is licensed under the GNU AGPL, with source code readily available. The CrowdBucks.fund site is simply operated as a flagship instance, but the goal is to allow anyone to host their own version as part of their operational infrastructure.

“We want CrowdBucks to help pay server bills, to support developers building Fedi software, and to fund creators on the Fediverse. The whole thing is designed to be native to the Fediverse.”

Future Plans


While the project itself is still fairly young, the team is actively thinking about how to improve. One area CrowdBucks is already exploring involves the ability for the app to post to the Fediverse on the behalf of fundraisers, for example, to give credit to supporters. Another possibility might involve collaborating with Emissary to standardize pieces involving payments and private access.

This is an exciting endeavor, and might be one of the most polished attempts yet to make payments possible on the Social Web. Hopefully, existing projects will get involved, and hash out the details on how to make this as open and interoperable as possible.

ShareOpenly logo Share


reshared this

in reply to Sean Tilley

Just curious: would any of this be able to circumvent or prevent this unspeakable crime:

Gofundme cancels accounts of Palestinians:
mastodon.social/@daliamohisen/…


I just received news that crushed me on top of everything I’m already enduring. An email was sent to my cousin
the one who manages our campaign abroad, since we Palestinians from Gaza are not allowed to create accounts or links ourselves. He set it up for us, but unfortunately, we have received only a small amount of donations so far.


How We Exploited CodeRabbit: From a Simple PR to RCE and Write Access on 1M Repositories


Black Hat USA presentation.

::: spoiler Comments
- Hackernews
:::

In this blog post, we explain how we got remote code execution (RCE) on CodeRabbit’s production servers, leaked their API tokens and secrets, how we could have accessed their PostgreSQL database, and how we obtained read and write access to 1 million code repositories, including private ones.
Questa voce è stata modificata (3 settimane fa)



Zero-Day Vulnerability allow attackers to steal users data Found in Password Managers( 1Password, Bitwarden, LastPass, Enpass, iCloud Passwords, and LogMeOnce remain unpatched— still vulnerable)


cross-posted from: programming.dev/post/36006277

Independent verification and publication by Socket Security.

Fixed: NordPass, ProtonPass, RoboForm, Dashlane, Keeper

Still vulnerable: Bitwarden, 1Password, iCloud Passwords, Enpass, LastPass, LogMeOnce

::: spoiler Key Points


  • A new clickjacking technique where a malicious script manipulates UI elements that browser extensions inject into the DOM by making them invisible using javascript.
  • In my research, I selected 11 password managers that are used as browser extensions and the result was that all were vulnerable to "DOM-based Extension Clickjacking". Tens of millions of users could be at risk (~40 million active installations).
  • A single click anywhere on the attacker's website could leak credit card details including security codes (6 out of 9 were vulnerable) or exfiltrate stored personal information (8 out of 10 vulnerable).
  • All password managers filled credentials not only to the "main" domain, but also to all subdomains. An attacker could easily find XSS or other vulnerabilities and steal the user's stored credentials with a single click (10 out of 11), including TOTP (9 out of 11). In some scenarios, passkey authentication could also be exploited (8 out of 11).
  • All vulnerabilities were reported in April 2025 with a notice that public disclosure will be in August 2025. Some vendors have still not fixed described vulnerability: Bitwarden, 1Password, iCloud Passwords, Enpass, LastPass, LogMeOnce. Users of these password managers may still be at risk (~32.7 million active installations).
  • For Chromium-based browser users it is recommended to configure site access to "on click" in extension settings. This configuration allows users to manually control autofill functionality.
  • The described technique is general and I only tested it on 11 password managers. Other DOM-manipulating extensions are probably vulnerable (password managers, crypto wallets, notes etc.).
    :::




Zero-Day Vulnerability allow attackers to steal users data Found in Password Managers( 1Password, Bitwarden, LastPass, Enpass, iCloud Passwords, and LogMeOnce remain unpatched— still vulnerable)

Fixed: NordPass, ProtonPass, RoboForm, Dashlane, Keeper

Still vulnerable: Bitwarden, 1Password, iCloud Passwords, Enpass, LastPass, LogMeOnce

::: spoiler Key Points

  • A new clickjacking technique where a malicious script manipulates UI elements that browser extensions inject into the DOM by making them invisible using javascript.
  • In my research, I selected 11 password managers that are used as browser extensions and the result was that all were vulnerable to "DOM-based Extension Clickjacking". Tens of millions of users could be at risk (~40 million active installations).
  • A single click anywhere on the attacker's website could leak credit card details including security codes (6 out of 9 were vulnerable) or exfiltrate stored personal information (8 out of 10 vulnerable).
  • All password managers filled credentials not only to the "main" domain, but also to all subdomains. An attacker could easily find XSS or other vulnerabilities and steal the user's stored credentials with a single click (10 out of 11), including TOTP (9 out of 11). In some scenarios, passkey authentication could also be exploited (8 out of 11).
  • All vulnerabilities were reported in April 2025 with a notice that public disclosure will be in August 2025. Some vendors have still not fixed described vulnerability: Bitwarden, 1Password, iCloud Passwords, Enpass, LastPass, LogMeOnce. Users of these password managers may still be at risk (~32.7 million active installations).
  • For Chromium-based browser users it is recommended to configure site access to "on click" in extension settings. This configuration allows users to manually control autofill functionality.
  • The described technique is general and I only tested it on 11 password managers. Other DOM-manipulating extensions are probably vulnerable (password managers, crypto wallets, notes etc.).
    :::



https://marektoth.com/blog/dom-based-extension-clickjacking/

Questa voce è stata modificata (3 settimane fa)


Zero-Day Vulnerability allow attackers to steal users data Found in Password Managers( 1Password, Bitwarden, LastPass, Enpass, iCloud Passwords, and LogMeOnce remain unpatched— still vulnerable)


cross-posted from: programming.dev/post/36006277

Independent verification and publication by Socket Security.

Fixed: NordPass, ProtonPass, RoboForm, Dashlane, Keeper

Still vulnerable: Bitwarden, 1Password, iCloud Passwords, Enpass, LastPass, LogMeOnce

::: spoiler Key Points


  • A new clickjacking technique where a malicious script manipulates UI elements that browser extensions inject into the DOM by making them invisible using javascript.
  • In my research, I selected 11 password managers that are used as browser extensions and the result was that all were vulnerable to "DOM-based Extension Clickjacking". Tens of millions of users could be at risk (~40 million active installations).
  • A single click anywhere on the attacker's website could leak credit card details including security codes (6 out of 9 were vulnerable) or exfiltrate stored personal information (8 out of 10 vulnerable).
  • All password managers filled credentials not only to the "main" domain, but also to all subdomains. An attacker could easily find XSS or other vulnerabilities and steal the user's stored credentials with a single click (10 out of 11), including TOTP (9 out of 11). In some scenarios, passkey authentication could also be exploited (8 out of 11).
  • All vulnerabilities were reported in April 2025 with a notice that public disclosure will be in August 2025. Some vendors have still not fixed described vulnerability: Bitwarden, 1Password, iCloud Passwords, Enpass, LastPass, LogMeOnce. Users of these password managers may still be at risk (~32.7 million active installations).
  • For Chromium-based browser users it is recommended to configure site access to "on click" in extension settings. This configuration allows users to manually control autofill functionality.
  • The described technique is general and I only tested it on 11 password managers. Other DOM-manipulating extensions are probably vulnerable (password managers, crypto wallets, notes etc.).
    :::




Zero-Day Vulnerability allow attackers to steal users data Found in Password Managers( 1Password, Bitwarden, LastPass, Enpass, iCloud Passwords, and LogMeOnce remain unpatched— still vulnerable)

Fixed: NordPass, ProtonPass, RoboForm, Dashlane, Keeper

Still vulnerable: Bitwarden, 1Password, iCloud Passwords, Enpass, LastPass, LogMeOnce

::: spoiler Key Points

  • A new clickjacking technique where a malicious script manipulates UI elements that browser extensions inject into the DOM by making them invisible using javascript.
  • In my research, I selected 11 password managers that are used as browser extensions and the result was that all were vulnerable to "DOM-based Extension Clickjacking". Tens of millions of users could be at risk (~40 million active installations).
  • A single click anywhere on the attacker's website could leak credit card details including security codes (6 out of 9 were vulnerable) or exfiltrate stored personal information (8 out of 10 vulnerable).
  • All password managers filled credentials not only to the "main" domain, but also to all subdomains. An attacker could easily find XSS or other vulnerabilities and steal the user's stored credentials with a single click (10 out of 11), including TOTP (9 out of 11). In some scenarios, passkey authentication could also be exploited (8 out of 11).
  • All vulnerabilities were reported in April 2025 with a notice that public disclosure will be in August 2025. Some vendors have still not fixed described vulnerability: Bitwarden, 1Password, iCloud Passwords, Enpass, LastPass, LogMeOnce. Users of these password managers may still be at risk (~32.7 million active installations).
  • For Chromium-based browser users it is recommended to configure site access to "on click" in extension settings. This configuration allows users to manually control autofill functionality.
  • The described technique is general and I only tested it on 11 password managers. Other DOM-manipulating extensions are probably vulnerable (password managers, crypto wallets, notes etc.).
    :::



https://marektoth.com/blog/dom-based-extension-clickjacking/

Questa voce è stata modificata (3 settimane fa)


Zero-Day Vulnerability allow attackers to steal users data Found in Password Managers( 1Password, Bitwarden, LastPass, Enpass, iCloud Passwords, and LogMeOnce remain unpatched— still vulnerable)


Fixed: NordPass, ProtonPass, RoboForm, Dashlane, Keeper

Still vulnerable: Bitwarden, 1Password, iCloud Passwords, Enpass, LastPass, LogMeOnce

::: spoiler Key Points

  • A new clickjacking technique where a malicious script manipulates UI elements that browser extensions inject into the DOM by making them invisible using javascript.
  • In my research, I selected 11 password managers that are used as browser extensions and the result was that all were vulnerable to "DOM-based Extension Clickjacking". Tens of millions of users could be at risk (~40 million active installations).
  • A single click anywhere on the attacker's website could leak credit card details including security codes (6 out of 9 were vulnerable) or exfiltrate stored personal information (8 out of 10 vulnerable).
  • All password managers filled credentials not only to the "main" domain, but also to all subdomains. An attacker could easily find XSS or other vulnerabilities and steal the user's stored credentials with a single click (10 out of 11), including TOTP (9 out of 11). In some scenarios, passkey authentication could also be exploited (8 out of 11).
  • All vulnerabilities were reported in April 2025 with a notice that public disclosure will be in August 2025. Some vendors have still not fixed described vulnerability: Bitwarden, 1Password, iCloud Passwords, Enpass, LastPass, LogMeOnce. Users of these password managers may still be at risk (~32.7 million active installations).
  • For Chromium-based browser users it is recommended to configure site access to "on click" in extension settings. This configuration allows users to manually control autofill functionality.
  • The described technique is general and I only tested it on 11 password managers. Other DOM-manipulating extensions are probably vulnerable (password managers, crypto wallets, notes etc.).
    :::

https://marektoth.com/blog/dom-based-extension-clickjacking/

Questa voce è stata modificata (3 settimane fa)
in reply to Ŝan

Research on only 11 password managers

others DOM-manipulating extensions will be vulnerable (password managers, crypto wallets, notes etc. )





Maneskin, reunion nel 2025: bilanci in calo e Victoria De Angelis batte Damiano da solista


I Maneskin sono pronti a tornare insieme nel 2025. Dopo la pausa che ha segnato la carriera della band romana, i conti economici e i risultati da solisti hanno accelerato la decisione della reunion. Victoria De Angelis si è distinta con un successo superiore rispetto a Damiano David, e la band tornerà a esibirsi dal vivo entro fine 2025, con un tour mondiale già previsto per il 2026.

LEGGI TUTTO 👉 MANESKIN: REUNION NEL 2025

reshared this



Claire Danes, Jim Parsons – „Ein Kind wie Jake“ (2018)

Vor sieben Jahren konnte diese Geschichte vielleicht noch wie ein intimes Indie-Drama aus Brooklyn wirken, aber heute erkennen wir, dass der Film eine Vorwarnung war. Denn längst nicht nur in den USA hat sich seither ein Kulturkampf entfesselt, der gegen jede Form von Förderung von Vielfalt und geschlechtlicher Selbstbestimmung aufmarschieren lässt. Kulturkrieger:innen streichen systematisch Programme, verbannen Bücher aus Schulen, säubern Lehrpläne und selbst das Fernsehen. Zu unserem Glück aber noch nicht bei 3Sat. (3Sat)




AWS chooses Intel again


Amazon Web Services (AWS) has teamed up with Intel to announce the eighth generation of memory-optimized EC2 instances: the R8i and R8i-flex. These new instance types run on specially developed Intel Xeon 6 processors with DDR5 7200 MT/s memory.




Intel ghosts researcher who found web apps spilled 270K staff records


Chipzilla quietly fixed the problems without responding to the person who found them


UK | Labour is paying hospitals to remove patients from waiting lists WITHOUT treating them


Meanwhile, Labour is stripping disabled people of benefits - but claiming the NHS has them covered. This could not be more alarming.


Archived version: archive.is/newest/thecanary.co…


Disclaimer: The article linked is from a single source with a single perspective. Make sure to cross-check information against multiple sources to get a comprehensive view on the situation.