I Replaced Kafka, Redis, and RabbitMQ With One Tool. Here’s What I Learned.
The post’s core idea is that NATS JetStream can replace separate Kafka, Redis, and RabbitMQ setups by covering streaming, queueing, and pub/sub in one system. It argues this can simplify architecture and reduce the operational overhead of running multiple messaging tools for different workloads.
scalebites.substack.com/p/i-re…
I Replaced Kafka, Redis, and RabbitMQ With One Tool. Here’s What I Learned.
The one tool your backend stack has been missingJainal Gosaliya (Scale Bites)
CDN friendica reshared this.
Wolfie Christl
in reply to Wolfie Christl • • •Alongside our report, Hungarian journalist Szabolcs Panyi publishes a VSquare investigation which reveals that Hungarian domestic intelligence has used Webloc since at least 2022, and still does today.
This is the first confirmation of the use of ad-based surveillance technology in Europe:
vsquare.org/orban-spying-toolk…
Orbán’s Spying Kit Revealed: Israeli Surveillance Tool Combined with Hungarian Technology - VSquare.org
Szabolcs Panyi (VSquare.org)reshared this
kravietz 🦇, ☑️ Cath, Disreputable_Craftsman, Clockwork ☃️✒️, Cory Doctorow, Tarnport e Joe Vinegar reshared this.
Wolfie Christl
in reply to Wolfie Christl • • •i and my colleagues at the University of Toronto's Citizen Lab spent months investigating Webloc, its capabilities and customers, based on public records, leaked docs, freedom of information requests and technical analysis.
Webloc is an add-on to the social media and web intelligence system Tangles, both developed by Israeli Cobwebs Technologies and since 2023 sold by US-based vendor Penlink.
Cory Doctorow reshared this.
Wolfie Christl
in reply to Wolfie Christl • • •This screen, from a leaked 2021 document, shows how Webloc tracked a person travelling from Germany via Austria to Hungary.
The system obtains the data from everyday consumer apps installed on phones. The data is tied to mobile device IDs typically used for ad targeting, which identify a phone and its owner.
The systematic misuse of this data for tracking and profiling in digital marketing is already highly problematic. Misusing it for government surveillance is another level of disastrous.
reshared this
GhostOnTheHalfShell, Cory Doctorow, Tarnport, JustME e ffalaschi reshared this.
Wolfie Christl
in reply to Wolfie Christl • • •Another screen from the same 2021 doc shows how Webloc tracked a male person in Abu Dhabi, who has 141 apps installed on his phone, some of which sent 81 GPS location records to the system over the past 5 days.
He was also located based on Wi-Fi access points nearby his phone 110 times.
The activity graph on the right bottom indicates that the system tracked his location up to 12 times a day.
The code shown at the right top is the so-called 'Advertising ID' that identifies his mobile device.
Cory Doctorow reshared this.
Wolfie Christl
in reply to Wolfie Christl • • •Here's how Webloc displayed a targeted person's profile information in 2021, in this example a Hungarian who used a Samsung S8 phone with the language set to English.
The profile also lists “user segments” typically used in digital advertising, which can be much more sensitive than the ones shown here.
reshared this
Disreputable_Craftsman e Cory Doctorow reshared this.
Wolfie Christl
in reply to Wolfie Christl • • •Penlink claims that Webloc doesn't process age, gender & ad targeting categories anymore today but 'merely' location records tied to device identifiers.
Location data can reveal a person's home, workplace, family, friends, habits, interests and more. Misusing it for government surveillance is highly problematic.
Another 2021 screen shows how Webloc displays location records in Street View, all of them possibly associated with a person who was frequently located in front of a certain house.
Cory Doctorow reshared this.
Wolfie Christl
in reply to Wolfie Christl • • •Our research shows that Webloc was used by El Salvador National Civil Police.
In the US, it is or was used by ICE, the US military, Texas Department of Public Safety, DHS West Virginia and several police departments in Los Angeles, Dallas, Baltimore, Tucson, Durham down to smaller cities/counties like City of Elk Grove and Pinal County.
Public records indicate that an even larger number of US federal, state and local agencies bought Tangles. Some of them might also use the Webloc add-on.
Cory Doctorow reshared this.
Wolfie Christl
in reply to Wolfie Christl • • •There might be other Webloc customers.
In Europe and the UK, we sent 96 freedom of information requests to law enforcement agencies in 14 countries and to 6 EU bodies. Many were rejected or received no response.
Some responses are interesting, including those from Europol, the UK Home Office and the Swedish Police Authority.
We believe that further research would also be fruitful with respect to potential Webloc purchases in Italy, Netherlands, Austria, Israel, Mexico, Vietnam and Singapore.
Cory Doctorow reshared this.
Wolfie Christl
in reply to Wolfie Christl • • •We also did some technical research. After receiving a tip from Amnesty Security Lab's @DonnchaC, we identified 219 active servers located in at least 21 countries that we consider to be associated with deployments of Tangles, Webloc or other products developed by Cobwebs Technologies.
Those servers are located in the US, UK, NL, DE, FR, SE, NO, IE, CY, AU, SP, MX, CO, SG, HK, ID, IN, IL, AE, IQ, KE, many of them hosted via MS Azure.
115 of them displayed a Tangles login page in the browser.
Cory Doctorow reshared this.
Wolfie Christl
in reply to Wolfie Christl • • •We briefly investigated two other Cobwebs products:
- Lynx, which helps facilitate undercover ops on the web and manage fake accounts
- Trapdoor, which appears to help trick people into revealing information. Our analysis leads us to believe that it can help facilitate the deployment of malware on devices
We do not know whether Trapdoor and Lynx are still being sold by Penlink.
reshared this
Disreputable_Craftsman e Cory Doctorow reshared this.
Wolfie Christl
in reply to Wolfie Christl • • •Trapdoor has rarely been reported or mentioned anywhere.
We discovered a Vietnamese requirements doc and servers located in Kenya and Indonesia that display Trapdoor login pages, which contain publicly available Javascript code for its admin interface.
The source code and the doc suggest that Trapdoor can help send phishing links that lead to fake web pages, which can open hidden tabs in the browser, extract passwords, access camera and microphone, and even deliver "files or payloads".
reshared this
mORA e Cory Doctorow reshared this.
Wolfie Christl
in reply to Wolfie Christl • • •We also investigate corporate networks.
Cobwebs Technologies, founded in 2015 by former members of IDF special forces and intel units, merged with Penlink in 2023/24.
Cobwebs' founder and long-term president, who now oversees Penlink's global operations, holds an indirect interest in the spyware vendor Quadream.
A former Cobwebs exec and investor is a key investor in Quadream, whose spyware was used to target civil society, journalists and political opposition figures:
citizenlab.ca/research/spyware…
Sweet QuaDreams: A First Look at Spyware Vendor QuaDream’s Exploits, Victims, and Customers - The Citizen Lab
The Citizen LabCory Doctorow reshared this.
mojala
in reply to Wolfie Christl • • •Sebastian
in reply to Wolfie Christl • • •wann wird Ungarn aus der EU geworfen?
@EUCommission
Petr Skála
in reply to Wolfie Christl • • •thriftwicker
in reply to Wolfie Christl • • •