Posts
2589
Following
623
Followers
1381
"I'm interested in all kinds of astronomy."
repeated

Side note:
Trend Micro THEMSELVES mentioned this happening ITW about 8 years ago.

But I guess it was a slow news day, so PR coerced an invented story to suggest their relevance. 🤷‍♂️

2
2
0
repeated
repeated

Computer History Museum 🇸🇮

🔎 The museum is seeking stories about Slovenians who cracked copy protections on cassette software in the 1980s 🎮💾 (games for Spectrum, Commodore, etc.). Share your experiences in the comments below! ⬇️😊

0
3
0
repeated
Facial Recognition Company Clearview Attempted to Buy Social Security Numbers and Mugshots for its Database
Show content

Controversial facial recognition company Clearview AI attempted to purchase hundreds of millions of arrest records including social security numbers, mugshots, and even email addresses to incorporate into its product, 404 Media has learned. 

For years, Clearview AI has collected billions of photos from social media websites including Facebook, LinkedIn and others and sold access to its facial recognition tool to law enforcement. The collection and sale of user-generated photos by a private surveillance company to police without that person’s knowledge or consent sparked international outcry when it was first revealed by the New York Times in 2020. 

New documents obtained by 404 Media reveal that Clearview AI spent nearly a million dollars in a bid to purchase “690 million arrest records and 390 million arrest photos” from all 50 states from an intelligence firm. The contract further describes the records as including current and former home addresses, dates of birth, arrest photos, social security and cell phone numbers, and email addresses. Clearview attempted to purchase this data from Investigative Consultant, Inc. (ICI) which billed itself as an intelligence company with access to tens of thousands of databases and the ability to create unique data streams for its clients. The contract was signed in mid-2019, at a time when Clearview AI was quietly collecting billions of photos off the internet and was relatively unknown at the time. 

Ultimately, the entire deal fell apart after Clearview and ICI clashed about the utility of the data with each company filing breach of contract claims. The dispute ultimately went into arbitration where it is common for disputes to be settled privately. The arbiter ultimately sided with Clearview AI in 2024 and ordered ICI to return the contract money. To date, ICI has not paid Clearview, with the company now seeking a court order to enforce the arbiter’s ruling. The president of ICI, Donald Berlin, has been previously accused in a lawsuit of fabricating intelligence reports and libel. Clearview currently advertises to customers that its technology “includes the largest known database of 50+ billion facial images sourced from public-only web sources, including news media, mugshot websites, public social media, and many other open sources,” and Clearview has previously told customers that it was “working to acquire all U.S. mugshots nationally from the last 15 years.”

ICI and Clearview did not return to multiple requests for comment. 

These court records show that while Clearview AI was building a database of images it was simultaneously attempting to purchase sensitive information such as social security numbers, email addresses or other data. Both in the US and internationally, Clearview AI has faced scrutiny for collecting images from social media websites with the company claiming it hoped to collect enough images to “ensure 'almost everyone in the world will be identifiable according to an investor deck reviewed by the Washington Post. The same investor report describes Clearview AI spending millions of dollars on data purchases but the court records reviewed by 404 Media do not make it clear if the purchase of social security numbers were part of the same plans. Clearview has contracts with local, state, and federal law enforcement and government agencies. 

Purchasing booking photos for a facial recognition system raises serious privacy risks according to Jeramie Scott, Senior Counsel & Director of EPIC’s Project on Surveillance Oversight. He points to both the algorithmic biases built into facial recognition systems and the potential for human bias by the police who would review the images. Numerous innocent people have been arrested based on facial recognition technology that misidentified them. This has happened almost exclusively to Black people, in part because the technology is less accurate on Black and brown faces.

“If Clearview AI’s search results not only return the data from its web scraping but also connect individuals to their supposed mugshots and related data then that will bias the human reviewers,” Scott told 404 Media. “When looking at Clearview AI search results and seeing multiple hits, the reviewer will likely be biased toward the person with the mugshot, which will disproportionately impact Black and brown people who are over represented in our criminal justice system.”

The purchase of highly personal data such as SSNs and location data has drawn the attention of regulators and Congress. As we’ve previously reported, access to highly personal data can be easily found online with authorities charging some sellers of the data with crimes. The Department of Justice has previously seized websites linked to the purchase of social security numbers and other personal data online and convicted a Ukrainian national of operating the sites

Ultimately, Clearview AI is facing an uncertain future after a barrage of lawsuits against the company and fines from regulators across the globe. It has stated that it expects its business to grow under the second Trump administration, especially with a new CEO at its helm. At the same time, Clearview may be forced to turn over nearly a quarter of its ownership to settle at least one complex class-action biometrics lawsuit. Internationally, regulators have fined it multi-millions of dollars for privacy violations, and Clearview AI has also won cases on appeal. Clearview AI may also never recover the over one million dollars from ICI or its president: instead of wiring the money to an escrow service, Clearview instead deposited it directly into Berlin’s personal checking account. 

Freddy Martinez is the co-executive director of Lucy Parsons Labs where he writes about policing, its harms, public records and abolition.

0
2
0
@GossiTheDog @catc0n Thanks, I wasn't aware of the update! My analysis was published on 11th March, their screenshot is from 12th March, so this "proof" probably means that someone started to play with the PoC I included (before the Python script appeared on GH).
1
0
2
repeated

There are a lot of people who are wrong and have picked something other than Sneakers. I’m very disappointed in y’all

https://bird.makeup/@greynoiseio/1901649140158959889

0
2
0
repeated

WM_WHATSWRONGWITHYOU

0
4
0
repeated
repeated

Do not travel to the US. Under any circumstance. Think you're safe because your paperwork is in order? Fuck you, it does not matter.

https://www.theguardian.com/us-news/2025/mar/19/canadian-detained-us-immigration-jasmine-mooney

1
6
0
@catc0n If by single source you mean Wallarm, that one is factually incorrect at multiple points so IMO it's best to dismiss as FUD:

https://infosec.place/notice/As2Q4VaBioZNySoR6m
2
4
9
repeated

Has anyone actually confirmed real-world compromises from the supposed Apache Tomcat exploitation (CVE-2025-24813) going on? Breathless headlines seem to be quoting a single vague source, and this bug isn't exploitable in anywhere close to a default config https://attackerkb.com/assessments/1a24556d-24fb-4017-be67-e4ab39c76566

2
2
0
repeated

one thing I've learned about teaching over the years is that if I make a negative statement (like “git commits aren't stored as diffs"), it doesn't really work -- often people will just ignore it, especially if it contradicts their current mental model

so I always have to figure out how to make a positive statement, and make it in a way that will convince people whose mental model is different right now

convincing people to adjust their mental models is really hard!

7
4
1
Windows SMB client is basically quantum computing: sometimes it works, but if you look at it the wrong way it isn't.
1
2
8
repeated
Edited 11 days ago

Last year, I had a few weeks between jobs and decided to look at the infrastructure security of random Linux distributions with the good friends at Fenrisk.

We ended up getting code execution on the Fedora Git forge hosting all package sources and on the Open Build Service instance of openSUSE. Nothing technically fancy (the usual silly argument injection bugs), but we could have effectively backdoored all their packages :°)

We finally presented the details last week at @1ns0mn1h4ck: https://fenrisk.com/assets/media/Don't%20let%20Jia%20Tan%20have%20all%20the%20fun_%20hacking%20into%20Fedora%20and%20OpenSUSE.pdf.

Also now available on the blog:
- Our approach: https://fenrisk.com/supply-chain-attacks
- Pagure: https://fenrisk.com/pagure
- OBS: https://fenrisk.com/open-build-service

Big kudos to distro maintainers, this was one of the most efficient disclosures of my life!

(now let's do kernel.org?)

5
9
1
repeated
Edited 16 days ago

The EFF has shit the bed again. This is a stirring cry to encourage startups ... specifically, AI startups. This ain't it chief.

https://www.eff.org/deeplinks/2025/03/californias-ab-412-bill-could-crush-startups-and-cement-big-tech-ai-monopoly

occasionally the EFF reminds us it was founded by a republican libertarian and funded by SV tech cos

8
8
0
This project by @recantha reminded me that old (IBM) ThinkPad keyboards should be remade into external USB keyboards. Found this /r/ thread with some great links:

https://www.reddit.com/r/thinkpad/comments/fgyh0q/transform_internal_keyboard_to_external_usb/

This build seems especially nice:

https://www.thingiverse.com/thing:4169964

RE: https://mastodon.social/@recantha/114184031395472987
0
1
1
repeated

“I’ve just closed the forum of a small classic car club because we don’t have the time or capacity to ensure compliance with only volunteers. Meta will benefit, because we will, reluctantly, move to using a Facebook page”
https://alecmuffett.com/article/112834

0
2
0
@Proteas yea can't sleep with all those fans spinning like crazy :)
0
0
1
repeated

bert hubert 🇺🇦🇪🇺🇺🇦

This is great news not in the least for our American friends where the weather service is being sabotaged. Weather models are oddly enough always global - you can't predict the weather in Berlin a week ahead without also predicting the weather in Austin, Texas. ECMWF has excellent hurricane forecasts also for the US for that reason, and these are also being used in the US already. Wonderful stuff: https://www.ecmwf.int/en/about/media-centre/news/2025/ecmwf-achieve-fully-open-data-status-2025

4
7
1
Show older