New attack eavesdrops on headphone audio from 30 meters away

arxiv.org
preview

cross-posted from: https://piefed.world/c/tech/p/1387483/new-attack-eavesdrops-on-headphone-audio-from-30-meters-away

Electromagnetic (EM) side-channel leakage and injection are typically treated as distinct physical phenomena, threatening data confidentiality and integrity respectively.

This work investigates how EM injection can be used to amplify side-channel leakage that is otherwise infeasible. We introduce a novel framework for Injection-Induced EM Side Channels to enable integrated, closed-loop EM security analysis. Our theoretical modeling and experimental measurements reveal that nonlinear hardware components, such as ubiquitous amplifiers, analog-to-digital converters, and power converters, can modulate secret electrical signals onto an injected EM carrier and thus upconvert low-frequency secrets into measurable EM emissions. By tuning the injection frequency and amplitude, adversaries gain the ability to actively shape the effective spectrum and entropy of the resulting leakage.

We design InjectEave attack and demonstrate eavesdropping on the audio played through wired and wireless headphones from up to 30 m away with accessible RF equipment, as well as in through-wall scenarios, and characterize injection-induced EM leakage of other low-frequency secrets such as power consumption of smart home devices and analog sensor inputs.

Case studies further demonstrate how the proposed techniques enable closed-loop eavesdropping and manipulation of landline-phone conversations. Finally, we analyze the broader security challenges and mitigations.

Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast

theregister Haiku OS rises / Beta 6 sails open web / Virtual winds fly fast
preview

Crossposted from lemmy.dbzer0.com/post/74960425

A great article on Haiku and the overall state of alternative operating systems.

However, the author skipped mentioning that NetBSD has taken an anti-AI stance as well. From developer guidelines:

  1. Do not commit tainted code to the repository. … Code generated by a large language model or similar technology, such as GitHub/Microsoft’s Copilot, OpenAI’s ChatGPT, or Facebook/Meta’s Code Llama, is presumed to be tainted code, and must not be committed without prior written approval by core

The developers’ announcement on Mastodon: mastodon.sdf.org/@netbsd/112446618914747900

The complex corporate web behind a $3.2 billion AI data center

Ars Technica The complex corporate web behind a $3.2 billion AI data center
preview

In early June, a fire broke out in a still-unfinished building at the Lake Mariner data center in Somerset, New York, exposing just how little the local fire department knew about what it was walking into. Firefighters reportedly found no working alarm, no suppression system, and three dead hydrants; the safety documents they’re legally entitled to see reportedly burned up in the blaze.

Steve Matisz, chief of the Barker Fire Department, said his crew went into the building “kind of blind,” facing heavy black smoke from chemicals they couldn’t identify because the safety sheets meant to inform them had apparently burned up. “It’s been a difficult situation,” Matisz said. He wasn’t sure what to think about the claim that the safety sheets had burned in the fire.

It’s a boondoggle run by shell companies and we’ll all pay for the losses.

Flock just hired 3 corporate lobbyists, Bloomberg reports

Flock Adds New Lobbying Muscle Amid Surveillance Camera Backlash
preview

Tripp Baird

How he describes himself:

Tripp Baird is the founder and principal of Off Hill Strategies, LLC, a boutique lobby firm with a commitment to conservative principles and personalized client service and strategy.

`Prior to establishing Off Hill Strategies with his wife, Tripp was instrumental in launching the political arm of The Heritage Foundation where he served as the Director of Government Relations and Senior Legislative Strategist at Heritage Action for America

Baird also worked with Senators and their staff to introduce Heritage-inspired legislation that advanced conservative principles.

Early in his career, Baird was a Floor Assistant for the U.S. Senate Majority Leader

https://www.offhillstrategies.com/team/tripp-baird

Jennifer Baird

How she describes herself:

Jenn Baird serves as Counsel for Off Hill Strategies, a boutique lobbying firm serving high profile clients with inroads to conservative leaders.

Baird launched her career in the office of a U.S. Representative, attended law school and then clerked in the intellectual property unit of the Senate Judiciary Committee before working at the law/lobbying firm of McGuiness and Holch.

https://www.offhillstrategies.com/team/jennifer-baird

Tim Goeglein

How he describes himself:

Tim C. Goeglein is the Director of Government Affairs for Off Hill Strategies. He serves OHS’s client base by shaping and advancing their policy interests and objectives at the federal level primarily by cultivating and managing key relationships on Capitol Hill, the Executive Branch, and outside organizations.

Prior to joining OHS in December 2023, he worked for U.S. Representative Jim Banks (R-IN) for nearly five years.

He was a Common Sense Society Fellow in Budapest, Hungary, in 2023 and a Claremont Institute Speechwriter Fellow in 202

Tim is heavily involved in his church, Immanuel Evangelical-Lutheran Church, in Alexandria, where he leads men’s ministry

https://www.offhillstrategies.com/team/tim-goeglein

audacity is a very versatile program

Screenshot of a Twitter post by @sirocyl: "what's a good hex editor - preferably for windows - for annotating structs and stuff? I'd normally use audacity but I figure there's gotta be something better for this." Attached to the post is a screenshot of Audacity showing two tracks, one of a binary file being interpreted as audio, zoomed-in at the sample level where individual bits can be edited, and a label track with labels such as "IMGDATA_MAGIC", "IMGDATA_FILE_NAME (1)", "Width (1)" and "Height (1)".
preview
alt text

Screenshot of a Twitter post by @sirocyl: “what’s a good hex editor - preferably for windows - for annotating structs and stuff? I’d normally use audacity but I figure there’s gotta be something better for this.” Attached to the post is a screenshot of Audacity showing two tracks, one of a binary file being interpreted as audio, zoomed-in at the sample level where individual bits can be edited, and a label track with labels such as “IMGDATA_MAGIC”, “IMGDATA_FILE_NAME (1)”, “Width (1)” and “Height (1)”.

How to disconnect the wifi and bluetooth module in your LG OLED C-Series

preview

Because of recent news i trust my LG CX Oled even less. It wasnt connected to the internet for years. But that might havent been enough. Also it always annoyed me that i couldnt disable bluetooth via the TV OS at all and it always screamed into the void.

So i followed this 3 minute video guide how to open up the backpanel which should work for most generations of the LG C-Series:
https://www.youtube.com/watch?v=_pgsggpR7-M

The daughter board with all the wireless stuff should be in the right corner. Just unscrew that one screw which holds it at place.
7PXVHYzSjvWx7ev.jpg

Carefully(or not) flip the daughter board over. Open the black tab and pull the cable out. Aside from the cable just put everything back together. liAonxgkTtRnMJ5.jpg

The magic mouse function of the remote wont work anymore. Otherwise its working fine via IR. You will maybe break a plastic tab of the backpanel.

Dont touch the PSU at all, it could kill you in the worst case even if disconnected.

Wifi and bluetooth obviosly wont work anymore. But that was the whole point and took maybe 15 minutes.

There is also a way to root your TV with certain firmware versions and install an homebrew app to disable bluetooth. But i dont even trust LG enough that a software toggle really disables wifi… In my case the only exploit which still works requires a LG developer account and then i would need to connect the TV to the internet and… Yeah, nope.

If you wanted to resell your TV in full “working” condition it would just take 15 minutes again to reseat the cable.

Now i’m going to read up if ethernet over HDMI could be another potential issue. Edit: Probably not.

What do you guys think of the MA apps on fdroid?

preview

I want a good app ecosystem that has basic android replacements. I tried Fossify apps but I dont know I didnt like them. I ve tried some MA apps and so far they look clean enough, I just wanna know if there are any flaws or issues with them that would make me wanna reconsider

Florida bans Flock cameras and other license plate readers from state highways

NBC News Florida bans Flock cameras and other license plate readers from state highways
preview

In stopped clock is right twice a day news, Florida is moving to ban Flocks from state highways.

Aside from Florida, there is a bunch of momentum all around the US now. Some cities just moved to another ALPR vendor like Axon. That sucks ofc. But many have eliminated ALPR entirely too, after citizens spoke out! Some cities had a constant stream of ppl speaking at city council meetings about it, months on end, dozens of ppl in every meeting.

It’s harder to deal with Flocks on private property. Like Home Depot and Lowes. A city gov terminating its own contract, doesn’t stop Home Depot. I dream of a coordinated, nation-wide boycott of co’s that put private Flocks in their lots. And letting them know exactly why.

Let’s keep the anti ALPR momentum going. It’s starting to see results. And don’t fall into the illogic of thinking it’s not perfect, therefore it’s useless.

Desktops are gonna be screwed by this too.

odysee.com
preview

cross-posted from: lemmy.wtf/post/47274322

So, the EU Digital ID is threatening to kill alt Android and Linux phones, but this is also probably gonna screw over desktops too, because going by how it’s laid out by Mental Outlaw here, desktops could start being required to run Win11 with Pluton enforcement to comply with this, which would not only lock out Linux and BSD desktops, but also older desktops in general which can’t run Win11, and even older desktops which can run Win11 but are too old to support Pluton, meaning just like you have to buy a new Google or Apple phone to comply with this, you’d also have to buy a new Win11 desktop or laptop as well.

what am i doing wrong? i feel like i have no privacy or connivence.

preview

cross-posted from: sh.itjust.works/post/65506805

(this is my first post im new) ive noticed something no one seems to have a problem with. do you have this problem to? am i just doing something wrong?

i use a privacy friendly browser plus a privacy friendly os and use fingerprint spoofer/blocker. i watch videos on invidious. i noticed that the “popular” tab shows videos related to videos i watched before. even if i clear my cookies, or change my idenity in (offiscial) tor browser i still get recommended related videos meaning no matter what i do google knows what i watch. whats worse, if i go on invidious on a totally different device with a normal broswer normal os, i get the same videos. meaning websites know what videos i watch across multiple sessions but also multiple devices. im sick of this. it feels like i’ve tried everything, sacrificed so much connivence but no results.

(this isn’t a question spefecifically about youtube google or invindious just how to get webisites to stop knowing everything i do across multiple identities and every device i use)

Things I tried

*Proton vpn+librewolf(max security according to settings)+nosircpt+Ublock(with the filters it comes with)+ officisal recommended invidious instances+Quad9 via settings

*Tails+Tor browser(max security settings apprentaly)+default bridge+no javascirpt+fingerprint spoofing estendsion+bluetooth disabled by tails+all the previous mentioned (exculding vpn i heard its risky)+invidious again (Tails doesn’t work well for me the police are not after me and it takes so long to start and presisent stoarage is annoying)

*Qubes+Whonix vm+Tor browser(max again)+no javascript (I love and hate qubes from my first impression it meets my security needs and you can run any os in a vm on it but i wish it just worked. theres a steep learning curve and my hardware isn’t the best for it)

No results on any of these just slower internet and some websites are broken. Its just like using a normal browser that tracks you but slow as a privacy one. im getting tired of this. i use all this super deep level paranoid overkill stufff and nothing happens. like im burning my house to get rid of a spider but the spider is still there

possible causes -google wireless access point (does qubes/whonix/tor NOT protect against this at all??) (also my family HATES any changes or mild inconveniences) -i logged in to google without a vpn ONCE does this automatically doom you forever even if you change os and browser and device? -hardware is framework laptop

for clairtiy I am not -a criminal -a journalist -a gooner -willing to go off grid in the woods I am -creeped out -tired -about to give up My privacy goals -be able to actually cut ties with my shadow profile and have websites not know everything ive done in my life -control what data brokers and compaines knsw -not have any website at all know every device i use -be able to use any network safely

I feel like giving up on privacy because nothing seems to work. the only results I get is slower more broken internet

Desktops are gonna be screwed by this too.

odysee.com
preview

So, the EU Digital ID is threatening to kill alt Android and Linux phones, but this is also probably gonna screw over desktops too, because going by how it’s laid out by Mental Outlaw here, desktops could start being required to run Win11 with Pluton enforcement to comply with this, which would not only lock out Linux and BSD desktops, but also older desktops in general which can’t run Win11, and even older desktops which can run Win11 but are too old to support Pluton, meaning just like you have to buy a new Google or Apple phone to comply with this, you’d also have to buy a new Win11 desktop or laptop as well.