microblog.at ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
Dies ist die private Mastodon Instanz von Robert Lender

Verwaltet von:

Serverstatistik:

1
aktive Profile

#googleisevil

0 Beiträge0 Beteiligte0 Beiträge heute
Erik van Straten<p><span class="h-card" translate="no"><a href="https://fediverse.thefloatinglab.world/users/FransVeldman" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>FransVeldman</span></a></span> :</p><p>Hopelijk hebben de *meeste* mensen ondertussen hun buik vol van techsolutionisme (ik in elk geval wel).</p><p>PS hieronder een (zojuist gemaakte) screenshot van een nep Google Play Store - voorzien van een certificaat uitgegeven door "Google Trust Services" (go figure).</p><p>Aanvulling 12:22: u moet niet alles vertrouwen wat u op internet leest (de plaatjes hieronder zijn echt, maar leugenaars zeggen dat ook van hun plaatjes, websites en apps). In het kader van "Certificate Transparency" kunt u o.a. hier: <a href="https://crt.sh/?q=google-ivi.com" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">crt.sh/?q=google-ivi.com</span><span class="invisible"></span></a> de voor de nepsite uitgegeven certificaten bekijken - zodra die server weer bereikbaar is (down op dit moment). Als alternatief ziet u in <a href="https://www.virustotal.com/gui/domain/play.google-ivi.com/details" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">virustotal.com/gui/domain/play</span><span class="invisible">.google-ivi.com/details</span></a> het laatste certificaat. Nb. VirusTotal is een dochterbedrijf van Google, en de nepsite verstopt zich nu achter CDN-servers van Cloudflare.</p><p><span class="h-card" translate="no"><a href="https://mastodon.nl/@GrijzeBeamerNL" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>GrijzeBeamerNL</span></a></span> <span class="h-card" translate="no"><a href="https://socialserver.science/@miekeroth" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>miekeroth</span></a></span> </p><p><a href="https://infosec.exchange/tags/OveralEenAppVoor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OveralEenAppVoor</span></a> <a href="https://infosec.exchange/tags/GoogleIsEvil" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GoogleIsEvil</span></a> <a href="https://infosec.exchange/tags/IkWilNietOveralEenAppVoor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IkWilNietOveralEenAppVoor</span></a> <a href="https://infosec.exchange/tags/DV" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DV</span></a> <a href="https://infosec.exchange/tags/BigTechIsEvil" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BigTechIsEvil</span></a> <a href="https://infosec.exchange/tags/WeWantYourPII" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WeWantYourPII</span></a> <a href="https://infosec.exchange/tags/WeWantYourMoney" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WeWantYourMoney</span></a> <a href="https://infosec.exchange/tags/ThenYouDie" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ThenYouDie</span></a></p>
Erik van Straten<p><span class="h-card" translate="no"><a href="https://mastodon.online/@vwbusguy" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>vwbusguy</span></a></span> : non-ACME certs suck big time.</p><p>However, now the internet has turned into a malicious phishing mess.</p><p>People can no longer determine who is responsible for a website, and nobody cares.</p><p>Google hosted fake websites (using ACME certs from Let's Encrypt) on their cloud servers called:<br>• cancel-google[.]com<br>• adsupport-google[.]com<br>• helpdesk-google[.]com</p><p>See (Dutch) <a href="https://infosec.exchange/@ErikvanStraten/113837934294209517" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.exchange/@ErikvanStrat</span><span class="invisible">en/113837934294209517</span></a>.</p><p>Google also doesn't give a fsck about HSTS, see <a href="https://infosec.exchange/@ErikvanStraten/113856108585517842" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.exchange/@ErikvanStrat</span><span class="invisible">en/113856108585517842</span></a>.</p><p>Worse, last year a phishing site with a domain name containing "google" was proxied by Cloudflare - and had a "GOOGLE TRUST SERVICES" DV certificate.</p><p>Did I mention that browsers suck and that Big Tech, making Big Money, is knowingly complicit to cybercrime?</p><p>And did I mention that certificates were not invented to please admins?</p><p><a href="https://infosec.exchange/tags/Phishing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Phishing</span></a> <a href="https://infosec.exchange/tags/DV" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DV</span></a> <a href="https://infosec.exchange/tags/GoogleIsEvil" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GoogleIsEvil</span></a> <a href="https://infosec.exchange/tags/BigTechIsEvil" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BigTechIsEvil</span></a> <a href="https://infosec.exchange/tags/GTS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GTS</span></a> <a href="https://infosec.exchange/tags/BrowsersSuck" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BrowsersSuck</span></a> <a href="https://infosec.exchange/tags/AnonymousWebsites" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AnonymousWebsites</span></a></p>