Food or stomach pain?
Food or stomach pain?
UK Residents Now Creating Fake IDs to Circumvent Age Verification
The protest against the UKs Online Safety Act is only continuing to grow with some now creating fake IDs of MPs to circumvent age verification systems.
https://www.freezenet.ca/uk-residents-now-creating-fake-ids-to-circumvent-age-verification/
Found this cool spiky #caterpillar in southern #Alberta, any one know what it is?
@BackFromTheDud @skinnylatte @minmi
BTW, an interesting POV I learned from Tendayi Bloom, a scholar and editor of the book below (disclosure: of which I am a contributor), is that while #homelessness itself is usually not illegal, the practise of making #natural #human #necessities such as sleeping and excreting waste illegal in public spaces has the same effect as #criminalising being #unhoused.
I am linking the book because there are so many vectors to being treated as non-#citizens that I think it are important to be aware of, even if one is *technically* a citizen, claiming such rights may depend on a number of other systems such as #authenticated #identification to "enjoy" those rights.
Lots of complexity that absolutely could be fixed if policymakers chose to do so.
https://manchesteruniversitypress.co.uk/9781526156419/
#criminalisation
#citizenship
#HumanRights
#dignity
#access
#accessibility
How the Solid Protocol Restores Digital Agency – Source: www.schneier.com https://ciso2ciso.com/how-the-solid-protocol-restores-digital-agency-source-www-schneier-com/ #rssfeedpostgeneratorecho #SchneierOnSecurity #SchneieronSecurity #CyberSecurityNews #identification #Uncategorized #DataBreaches #DataPrivacy #Integrity #privacy
@LukefromDC : it won't be that bad (it will be bad, but in a different way).
ANY website may ask a user to confirm they are 18+ (or whatever age).
There will be a huge amount of AitM (Attacker in the Middle) websites where naive people will be lured to (using fake emails, SMS, chat app messages or falsified QR-codes) and asked to confirm their age.
That AitM website will subsequently obtain a "ticket" (session cookie) from a real "relying party" website (with a potentially very different type of content than the victim is told).
Those "tickets" will be sold (or traded for watching ads and/or paying with privacy).
Reliable authentication requires a trustworthy identity verifier (even if identification is restricted to age+).
@jwildeboer : modern certificates are used for authentication only, not for secure connections.
OTOH, if you have no certainty that your software is communicating with the server you intended, a secure connection to it is pointless - but the connection remains secure.
Using TLS v1.3, the connection is even secured before the server is authenticated (if, after encrypting the connection, the authentication of the server fails, then the client should at least warn the user - if not immediately disconnect).
Yes, I know, these are boring details, but they are misunderstood way too often by people who SHOULD know how this works (I know you do, but please don't simplify things too much).
@adfichter : I'm trying to warn people for such holes.
Published earlier this month: https://www.heise.de/en/news/BSI-and-ANSSI-warn-against-VideoIdent-for-the-EU-digital-wallet-10476045.html (there of course is a German version as well).
It refers to a recent joint publication (in English) by the German BSI and the French ANSSI titled:
"Remote ldentity Proofing for EUDI Wallet Onboarding: Strengthening Assurance Against Evolving Threats"
(EUDI Wallet = European Digital Identity Wallet aka EDIW aka EUDIW).
It's about the risks of VideoIdent (getting bigger every day, see e.g. https://www.theverge.com/report/714402/uk-age-verification-bypass-death-stranding-reddit-discord - not to mention AI).
However, like in their previous publication (PDF: https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/ANSSI-BSI-joint-releases/ANSSI-BSI_joint-release_2023.pdf?__blob=publicationFile&v=3) they ignore one HUGE risk: AitM's (Attacker in the Middle).
The unmentioned gaping security hole here are fake websites, where people are being directed to via falsified emails, SMS, chat app messages and possibly QR-codes.
Step :
————
Victim (contacts AitM site as instructed)
|
| "Please give me my EDIW"
v
AitM site: contacts site below and forwards
|
| "Please give me my EDIW"
v
True EDIW identity verification site
Step :
————
Victim
^
| "Please perform VideoIdent"
|
AitM site: forwards
^
| "Please perform VideoIdent"
|
True EDIW identity verification site
Step :
————
Victim
|
| VideoIdent showing victim
v
AitM site: forwards
|
| VideoIdent showing victim
v
True EDIW identity verification site
Step :
————
Victim
^
| "Something went wrong"
|
AitM site: stores victim's EDIW on their device
^
| EDIW
|
True EDIW identity verification site
The same may happen to people who are tricked into *authenticating* using EDIW on AitM websites.
Never hand over your #identification details to verify your #mastodon #accounts, its a #scam!
@cassini
#papillons #identification
Le meilleur site d'identification des papillons !
Les Carnets du Lépidoptériste
Français
Identifier un papillon - Espèces courantes
How Solid Protocol Restores Digital Agency – Source: www.schneier.com https://ciso2ciso.com/how-solid-protocol-restores-digital-agency-source-www-schneier-com/ #rssfeedpostgeneratorecho #SchneierOnSecurity #SchneieronSecurity #CyberSecurityNews #identification #Uncategorized #DataBreaches #DataPrivacy #privacy
How Solid Protocol Restores Digital Agency https://www.schneier.com/blog/archives/2025/07/how-solid-protocol-restores-digital-agency.html #identification #Uncategorized #databreaches #dataprivacy #privacy
How Solid Protocol Restores Digital Agency
The current state of digital identity is a mess. Your personal information is scattered across hundreds of locations: social media companies, IoT companies, government agencies, websites you have accounts on, and data brokers you’ve never he... https://www.schneier.com/blog/archives/2025/07/how-solid-protocol-restores-digital-agency.html
"Federal immigration agents (#ICE) seeking to detain a Honduran landscaper chased him into a #SouthernCalifornia surgical center and quickly found themselves in a tense #standoff as #clinic #staff demanded to see #identification and a #warrant."
https://apnews.com/article/ice-arrest-california-surgery-center-c827038f1a40227dc05ab1c28b048035
.
Son bec serait plus petit en hiver ? Oui c’est vrai !
Quand il n’est pas en plumage nuptial, le macareux moine présente un bec plus petit et aussi moins coloré…
Pourquoi cette différence ? Il est probable que la taille et la couleur du bec jouent un rôle dans la séduction, un caractère sexuel secondaire favorisant la reproduction. Mais cette théorie, bien que plausible, reste encore à confirmer par les scientifiques…
#macareux #aquarelle #dessinnaturaliste #ornithologie #arctique #illustration #identification #dessin #oiseau #artiste