• 0 Posts
  • 25 Comments
Joined 11 months ago
cake
Cake day: March 21st, 2024

help-circle



  • This isn’t malware, it’s a scam which is harder to detect. No filtering process is ever 100% successful. I’d argue they do a good job at keeping out most of the junk. A quick look at the Playstore confirms this.

    Sideloading is accessible to anyone with 15 minutes to educate themselves on it. I have a torrent client, an ad-free YouTube, and UTM sideloaded on my US iPhone.

    I do not want to download a different app launcher for every app I download. Especially given they won’t be restricted to Apple’s strict privacy policies. Imagine a different launcher for every bank card, none of them supporting Wallet anymore.

    I realize not everyone will agree with this, but I bought an iPhone for easy of use and because I like Apple’s offerings. I knew about the walled garden going in, and if I didn’t want to participate in it, I would just bought a different phone - as anyone is free to do.













  • Was CVE-2024-44133 Already Exploited?

    After concocting their exploit, Microsoft started scanning customer environments for activity that aligned with what they’d found. On one device, lo and behold, they spotted something quite closely resembling what they were looking for.

    It was a program digging into the victim’s Chrome configuration settings, adding approval for microphone and camera access to a specific URL. It also did more: gathering user and device information, laying the groundwork for a second-stage payload.

    I’m not sure if this article is disingenuous or if I’m just confused… but it states when MS scanned their customers’ environments, they discovered malware making changes to the Chrome config. And the Safari CVE was patched in September. So we don’t have proof of this happening in the wild then?

    What’s more, the Safari exploit requires making changes to a protected directory. But no indication of how that is done by just the browser exploit. Did the attackers already have access to the machine? If so, this article is a nothing burger.