a random tech banner

/tech/ - Technology

Buffer overflow


New Thread
X
Max 20 files0 B total
[New Thread]

Page: Prev [1] [2] [3] [4] [5] Next | View | Catalog | Banners | Logs


thumbnail of bread.png
thumbnail of bread.png
bread png
(1.05 MB, 1380x765)



thumbnail of bc060e6776a468ac2b33fce7b81cc9bc_104b8bd526e228b7bf8384f1bfcee8e4-3749132208.jpg
thumbnail of bc060e6776a468ac2b33fce7b81cc9bc_104b8bd526e228b7bf8384f1bfcee8e4-3749132208.jpg
bc060e6776a468ac2b33f... jpg
(57.35 KB, 1200x857)







Hi, I am a long-time cybersecurity researcher and Tor-user. I have also used Linux for a few years, and have studied various topics such as cybersecurity, networking, opsec, and similar topics.

I became made aware of information implicating various rich people and people in government, in criminal activity, and became a whistleblower, using Tor to leak plain-text (non-documents, just text) whistle-blowing information to various entities, in order to safeguard the public. 

I used a brand-new laptop, fully firmware updated, running on Linux, with a firewall, on public wifi, with a "no-log" VPN (paid via Monero).
I ensured my screen wasn't on camera, so the only way I could have been identified, was via a Tor compromise (backdoor, trace such as via big-data analysis via tracking all Tor relay connections and providing correlations via timing analysis using AI/super computers., or both).

So, because my information was non-specific to me, (I wasn't one of a few people aware of the information), and my whistleblowing was done using plain-text (not documents, with metadata), and I also modified my writing style to specifically avoid stylometric analysis, used a decent operating system (linux), with a VPN to add an additional protection for my source (original) IP, on public wifi (rather than connecting from my house), my analysis concludes that the only way to identify me, as the whistleblower, was via a technical Tor compromise, such as a backdoor, (most likely due to a bribe from the rich criminals, bribing a Tor developer), or a deep intelligence agency backed timing correlation, which is also logical because the criminals were both rich civilians, and government agents.

Because of my technical OPSEC, and use of Public wifi, I believe strongly that Tor was, or is currently, deeply compromised, de-anonymizable, and traceable, in some way.

Even using public wifi, I could have been seen on nearby security cameras, coming to or going from the area where I used public wifi, indicating high-level governmental involvement in my survived assassination attempt, (I got poisoned, with a rare toxin, which was confirmed with a 3rd party lab-test, and also dodged two gunmen while taking a nap in my car, in a very low-crime, safe neighborhood.) which tracks with me analysis of the criminally responsible, which I was whistle-blowing on.

Therefore, I henceforth conclude, based upon my experiences, that Tor is compromised, deeply. Direct deanonymization. Thus, in order to fix Tor, if it is possible, we, as a community, must deeply analize Tor's source code, of both the Tor Browser, and Tor Network software code, crypto analysis, etc.

We should also act as if Tor is compromised currently, and use Tor only from public wifi, wifi not linked to our identity, such as Phone data, or home WIFI connection. Be sure your screen ins't on camera, even with reflections. Preferably, turn off your cellphone to prevent keystroke analysis via audio capture.

Together, we can fix Tor, together, we can audit Tor with security analysis, and patch the backdoors, and add additional timing correlation resistances, such as via random timing delays between relay connections. Tor should be considered as fully compromised at this time. Someone, somewhere, was able to trace me exact source IP, from Public WIFI , to a VPN , through Tor, and back). 

I care deeply about every Tor user, as each user, when the network is working correctly, increases the anonymity of Tor. We all have shared values.

Please use caution when using Tor, please audit and re-secure Tor.
I risked my life to try to save others, and nearly got assassinated, that means every Tor user is also vulnerable to the same technical compromise. Please help to re-secure Tor. Start a group-fund to pay a cybersecurity company to audit Tors full source code of browser and relay networking code, audit the code yourself, use caution when using Tor now.

Thank you.








I'm trying to find the Windows version of Newton's Playground, the old physics-based educational game. The original download site has been offline for years, and none of the Wayback Machine snapshots include a working ZIP file. Every mirror I've tried is either broken or missing the file. I'm hoping someone still has the original Windows ZIP saved from when the site was active. If you have a copy in an old downloads folder or backup drive, I'd really appreciate it if you could share it.

More details here:
https://justpaste.it/mkg41


thumbnail of altered-deal.png
thumbnail of altered-deal.png
altered-deal png
(371.5 KB, 1440x1440)
https://keepandroidopen.org/
https://keepandroidopen.org/cta/#consumers

At the time of this thread's creation, there are 125 days left until Google pushes a forced update to all available Android phones which block the use of third party apps by developers who have not verified their app using government ID, and place further restrictions on people's ability to download and use third party applications.

This cannot happen. Open Android stores like F-droid will fundamentally be broken, and Google will completely control the Android application ecosystem. 

I would sincerely appreciate a moment of your time to take one or more of the following actions to change this outcome:

#0 Do not believe you are useless: if you believe that nothing can be done and this is not able to be changed, think positively! Change can happen with action!

#1 Spread the word: let others know this is happening and what they can do to help out, this could be friends, family, social media, onion forums, other boards, anything.

#2 Make a complaint(s): head to https://keepandroidopen.org/cta/#consumers, locate a country, and make one or multiple complaints about this issue. Please be sincere and professional in your responses, and use Alphabet Inc or Google in the target business. Most PII in the form is not required or can be faked if you like.

#3 Download a third party store: visit https://f-droid.org (http://fdroidorg6cooksyluodepej4erfctzk7rrjpjbbr6wx24jh3lqyfwyd.onion/index.html.en) and download the APK, verification instructions are here: https://f-droid.org/docs/Verifying_Downloaded_APK. They have an amazing software suite!

#4 Read and share the open letter: https://keepandroidopen.org/open-letter

If Google gets away with this, it will become the norm. Make your voice heard now. You will be helping yourself and everyone around you who carries an Android phone, and setting a precedent for other handset providers that they cannot follow in Google's footsteps without severe punishment and backlash.




Hello its me, xYt7x.
This is my first post on Dread and i want to present you my new Project called "Xyyly".

A bit of background: I've been coding since 2015 (Fullstack Web, C# Unity, Mobile Modding, and custom Hacking Tools). I got tired of the leaked, backdoored garbage floating around. Everything on Xyyly is 100% self-developed by me.

I just stocked the store with the first wave of premium tools. In the next few days, I will also drop some exclusive free scripts for the community here. So just wait a few days ig.

I am offering 3 Vouch Copies of my premium tools to established, high-rep members. Drop a comment or DM me if you have the stats to review my code.

Stay safe and see ya there,
***xYt7x

Web: http://7fdbrudrvv3rz4r2oeqvhv4l73ugz4hxcvqy3oqsj2ajmy2h6vuvm6qd.onion/






Post(s) action:


Moderation Help
Scope:
Duration: Days

Ban Type:


0 replies | 0 file
Refresh
New Thread
Max 20 files0 B total

Page: Prev [1] [2] [3] [4] [5] Next | View | Catalog | Banners | Logs