mastodon.world is one of the many independent Mastodon servers you can use to participate in the fediverse.
Generic Mastodon server for anyone to use.

Server stats:

8.1K
active users

Replied in thread

@BackFromTheDud @skinnylatte @minmi

BTW, an interesting POV I learned from Tendayi Bloom, a scholar and editor of the book below (disclosure: of which I am a contributor), is that while #homelessness itself is usually not illegal, the practise of making #natural #human #necessities such as sleeping and excreting waste illegal in public spaces has the same effect as #criminalising being #unhoused.

😡

I am linking the book because there are so many vectors to being treated as non-#citizens that I think it are important to be aware of, even if one is *technically* a citizen, claiming such rights may depend on a number of other systems such as #authenticated #identification to "enjoy" those rights.

Lots of complexity that absolutely could be fixed if policymakers chose to do so. 😡

manchesteruniversitypress.co.u

#criminalisation
#citizenship
#HumanRights
#dignity
#access
#accessibility

Manchester University PressManchester University Press - Statelessness, governance, and the problem of citizenshipStatelessness, governance, and the problem of citizenship - Browse and buy the Hardcover edition of Statelessness, governance, and the problem of citizenship by Tendayi Bloom
Biometric surveillance infrastructure grows as FBI, Leidos deepen partnership In a move that reflects the accelerating convergence of biometric surveillance and national security infrastructure, th...

#Biometrics #News #Government #Services #Law #Enforcement #biometric #database #biometric #identification #biometrics

Origin | Interest | Match
BiometricUpdate.com · Biometric surveillance infrastructure grows as FBI, Leidos deepen partnershipBy Anthony Kimery
Biometric surveillance infrastructure grows as FBI, Leidos deepen partnership In a move that reflects the accelerating convergence of biometric surveillance and national security infrastructure, th...

#Biometrics #News #Government #Services #Law #Enforcement #biometric #database #biometric #identification #biometrics

Origin | Interest | Match
BiometricUpdate.com · Biometric surveillance infrastructure grows as FBI, Leidos deepen partnershipBy Anthony Kimery
Biometric surveillance infrastructure grows as FBI, Leidos deepen partnership In a move that reflects the accelerating convergence of biometric surveillance and national security infrastructure, th...

#Biometrics #News #Government #Services #Law #Enforcement #biometric #database #biometric #identification #biometrics

Origin | Interest | Match
BiometricUpdate.com · Biometric surveillance infrastructure grows as FBI, Leidos deepen partnershipBy Anthony Kimery
Replied in thread

@LukefromDC : it won't be that bad (it will be bad, but in a different way).

ANY website may ask a user to confirm they are 18+ (or whatever age).

There will be a huge amount of AitM (Attacker in the Middle) websites where naive people will be lured to (using fake emails, SMS, chat app messages or falsified QR-codes) and asked to confirm their age.

That AitM website will subsequently obtain a "ticket" (session cookie) from a real "relying party" website (with a potentially very different type of content than the victim is told).

Those "tickets" will be sold (or traded for watching ads and/or paying with privacy).

Reliable authentication requires a trustworthy identity verifier (even if identification is restricted to age+).

@drgroftehauge @fabio @SylvieLorxu

Replied in thread

@jwildeboer : modern certificates are used for authentication only, not for secure connections.

OTOH, if you have no certainty that your software is communicating with the server you intended, a secure connection to it is pointless - but the connection remains secure.

Using TLS v1.3, the connection is even secured before the server is authenticated (if, after encrypting the connection, the authentication of the server fails, then the client should at least warn the user - if not immediately disconnect).

Yes, I know, these are boring details, but they are misunderstood way too often by people who SHOULD know how this works (I know you do, but please don't simplify things too much).

#TLS#https#X509
Replied in thread

@adfichter : I'm trying to warn people for such holes.

Published earlier this month: heise.de/en/news/BSI-and-ANSSI (there of course is a German version as well).

It refers to a recent joint publication (in English) by the German BSI and the French ANSSI titled:

"Remote ldentity Proofing for EUDI Wallet Onboarding: Strengthening Assurance Against Evolving Threats"

(EUDI Wallet = European Digital Identity Wallet aka EDIW aka EUDIW).

It's about the risks of VideoIdent (getting bigger every day, see e.g. theverge.com/report/714402/uk- - not to mention AI).

However, like in their previous publication (PDF: bsi.bund.de/SharedDocs/Downloa) they ignore one HUGE risk: AitM's (Attacker in the Middle).

The unmentioned gaping security hole here are fake websites, where people are being directed to via falsified emails, SMS, chat app messages and possibly QR-codes.

Step 1️⃣:
————
Victim (contacts AitM site as instructed)
|
| "Please give me my EDIW"
v
AitM site: contacts site below and forwards
|
| "Please give me my EDIW"
v
True EDIW identity verification site

Step 2️⃣:
————
Victim
^
| "Please perform VideoIdent"
|
AitM site: forwards
^
| "Please perform VideoIdent"
|
True EDIW identity verification site

Step 3️⃣:
————
Victim
|
| VideoIdent showing victim
v
AitM site: forwards
|
| VideoIdent showing victim
v
True EDIW identity verification site

Step 4️⃣:
————
Victim
^
| "Something went wrong"
|
AitM site: stores victim's EDIW on their device
^
| EDIW
|
True EDIW identity verification site

The same may happen to people who are tricked into *authenticating* using EDIW on AitM websites.

@ellent

heise online · BSI and ANSSI warn against VideoIdent for the EU digital walletBy Stefan Krempl
#EDIW#EUDIW#AitM

Son bec serait plus petit en hiver ? Oui c’est vrai !
Quand il n’est pas en plumage nuptial, le macareux moine présente un bec plus petit et aussi moins coloré…
Pourquoi cette différence ? Il est probable que la taille et la couleur du bec jouent un rôle dans la séduction, un caractère sexuel secondaire favorisant la reproduction. Mais cette théorie, bien que plausible, reste encore à confirmer par les scientifiques…
#macareux #aquarelle #dessinnaturaliste #ornithologie #arctique #illustration #identification #dessin #oiseau #artiste

404Not Found