c.im is one of the many independent Mastodon servers you can use to participate in the fediverse.
C.IM is a general, mainly English-speaking Mastodon instance.

Server stats:

2.9K
active users

#kyc

5 posts4 participants2 posts today
Replied in thread

@dzwiedziu @fj @signalapp not really, as the #Metadata #FUD cited by #Signal is mitigateable with proper measures.

  • You can't even run Signal over @torproject and even if that point is moot when you're forced to quasi-#KYC by virtue of a #PhoneNumber aka. #PII they have neither legitimate interest nor technical reason to demand in the first place!

Every claim that things like #ITsec, #InfoSec, #OpSec & #ComSec can be solved with "Just use Signal!" is "#TechPopulism" at best if not being a "#UsefulIdiot"!

Replied in thread

@Andromxda @pixelcode How can you claim something you can't evidence?

It makes you look like one of those folks shilling #VPN|s that ain't logless after all...

  • I don't believe in #marketing #lies and #Signal can't (and won't) be able to evidence that they don't log shit.

At least they should be honest about things and not claim bs, cuz demanding a #PhoneNumber is just #KYC with extra steps like demanding any #SSN or other #PII. Makes them look like chinese MMORPGs that demand ID card numbers for account signups, thus #paywalling the ability to use their service anonymously...

Infosec ExchangeAndromxda 🇺🇦🇵🇸🇹🇼 (@Andromxda@infosec.exchange)@kkarhan@infosec.space @pixelcode@social.tchncs.de > thus subject to Cloud Act They literally don't store anything about you, other than the phone number you used to sign up, and the timestamp of the last login. They can't fulfill any kind of subpoena, because they simply don't have the data. This was proven in court: https://signal.org/bigbrother/cd-california-grand-jury/ I don't know what your mission is, any why you're constantly spreading misinformation about a secure communications platform, trying to discourage people from using it, without naming alternatives. It's pretty suspicious at the very least.
Replied in thread

@signalapp It's not #disinfo when one points out that you demand #PII aka. #PhoneNumbers from Users and that is literally a architectural vulnerability, alongside your #proprietary & #Centralized #Infrastructure.

Not to mention the lack of @torproject / #Tor support with an #OnionService or the willingness to fulfill #cyberfacist "Embargoes" or shilling a #Shitcoin #Scam named #MobileCoin!

  • #KYC is the illicit activity!!!

And don't get me started on the #cyberfacism that is #CloudAct.

  • If you were secure, criminals would've used your platform so hard, it would've been shutdown like #EncroChat and #SkyECC.

I may nit have allvthe.evidence yet, but #Signal stenches like #ANØM: #Honeypot-esque!

Replied in thread

@jrredho @walkinglampshade @fj

Don't 'splain me, m8!

Their figleaf exuses are not legitimate and @signalapp's @Mer__edith knows that...

  • After all, @monocles doesn't require any #PII at all and they are in fact sustainable as in not requiring #donations, since they are user-financed (subscription)...

Read criticisms before commenting...
youtube.com/watch?v=tJoO2uWrX1M

Replied in thread

@heiseonline
"Es gibt staatlich geförderte Studien wie den Glücksspielatlas. Da setzen sich Forscher hin, und machen Umfragen. Wenn da, wie beim Glücksspielatlas 2023, herauskommt, dass viele Menschen ein Spielproblem haben, kommt die Industrie und sagt: Die Daten stimmen gar nicht! Der Staat hat aber alle Daten und könnte das verifizieren. Jetzt haben wir aber Daten aus vielen Casinos. Meine Hoffnung ist, dass ich die Daten Wissenschaftlern oder großen Medienhäusern übergeben kann, damit wir eine datenbasierte Debatte über das gesamte Thema Glücksspiel führen können." 🙏👍
heise.de/hintergrund/Man-hat-s

heise online"Man hat sich einen Dreck um die Sicherheit der Daten der Spieler geschert"Lilith Wittmann hat bei Online-Casinos schwere Sicherheitslücken gefunden. Das Gespräch mit ihr dreht sich nicht nur um Technik, sondern auch eine Behörde.
Replied in thread

@expertenkommision_cyberunfall @dideldum @leachimus @EUCommission @BaFin @ecb

Dass dies technisch möglich ist - inkl. Einhaltung von #Identifikationspflichten (#KYC) und #Geldwäscheprävention (#AML) beweisen Zahlungsdienstleister wie #NowPayments regelmäßig!

  • Natürlich sollte hierzu eine öffentliche, kosten- und patentfreie #Europanorm geschaffen werden, welche entsprechende #API|s definiert, inklusiver verpflichtender #Testing-Endpoints.

Und natürlich nicht mit irgendwelchem #Blockchain-Müll, dafür #dezentral, #P2P mit Förderation (vgl. Fediverse)...

  • Dazu dezentrale Architektur mit "Web of Trust" um effektiv Missbrauch und Akteure dessen zu bekämpfen.

Die Technologien dazu existieren...

#ZachXBT is probably world's greatest crypto detective. He's pro-crypto but has busted a *ton* of frauds and scams.

Recently he's been working on tracking #NorthKorea's massive money laundering operation in the wake of the #Bybit hack and seems to have concluded that the entire crypto industry is fucked (which some of us have known all along).

* Telegram link: t.co/7Fi2sk1cqF

Replied in thread

@kuketzblog das größte Problem si d #Zahlungsdienstleister.

  • Wer mit mit "#wero statt #PayPal!" kommt, kauft offensichtlich nirgendwo online ein und außerhalb der #EU ist dies genauso wie #SEPA keine Option, sondern allenfalls lokale Nische alla #AliPay / #WeChatPay und nicht global verfügbar.

Merke: rein regionale oder gar nationale Lösungen sind keine Alternative zum #VISA / #MasterCard / PayPal - #Tripol und sowohl #Stripe als auch #Klarna sind nicht wirklich konkirrenzfähig.

Eher werden wir #Monero als #Zahlungsmittel beim Durchbruch in den globalen Mainstream sehen!

@cryptadamist @KimPerales OFC.

  • I mean I'm pretty shure that wallet is some "cold wallet" (or "paper wallet") they generated to make it basically impossible to seize.

Obviously the ultimate beneficiaries propably need to figure out a way to do the #ShitcoinLaundering over time or find buyers willing to take #filthy #Bitcoin off their hands that'll instantly get flagged by any #Shitcoin - #AML tool there is...

  • I mean, $700M will exceed the liquidity of even the biggest non-#KYC #Exchange site for months if not years to the point that even #NorthKorea would be unable to handle that volume.

Whoever is behind this must have some #Marsallek - Style "Business Network" or is going to spend several years sitting on it and casually siphoning parts for tumbling once it isn't in the immediate focus of #Blockchain #Analytics experts and #LEA|s...

  • Obviously even if the person in control is gonna sell off at 2,5% the value that's enough money to basically buy citizenship anywhere and add a lot of plastic surgery on top for good measure... At 5% they'd not even need to ever work if they don't blow it on luxury cars & overpriced real estate...

Chances are pretty high the one in control is chillin' in #Dubai and speaks Russian...

Replied in thread

@GossiTheDog the sheer fact that #MSPs & #CSPs can access clients' setups without proper #authorization [including #KYC / #KYB, #AuthCode|s and proper authorization via contract] is already sickening.

Such fundamental #ITsec fuckups are reasons alone not to use #Azure or any #Microsoft products & services at all...

  • I mean, it doesn't require #Mitnick-level skills to pull this off, since it doesn't necessitate #Lapsus-Style #SIMswap or other means to gain access...
CyberplaceKevin Beaumont (@GossiTheDog@cyberplace.social)Attached: 3 images This is the partner.microsoft.com portal, it allows CSPs - Cloud Solution Providers - to gain access to their customer's environments. CVE-2024-49035 was around improper privilege management, i.e. being able to access things you shouldn't. It being in CISA KEV says it was being exploited in the wild. That portal allows a huge footprint of access by design.

Acquistare bitcoin in modo anonimo. La Guida completa!

* Piattaforme P2P Decentralizzate: (Bisq, Robosats) – Massimo anonimato
* Piattaforme P2P Centralizzate: (Hodl Hodl) – Più facile da usare, buona privacy
* Exchange Centralizzati Light-KYC: (Pocket Bitcoin) – Bonifico bancario, KYC minimo
* Alternative non-KYC analizzate a fondo
* Consigli per la privacy nel trading P2P

👉 Scopri di più e leggi l'articolo completo:

bitcoinbeer.events/article/17

Good news (at first glance): Silent Connection Ltd and Dolphin 1337 Limited, two UK-based corporations flagged by Spamhaus as being used for bulletproof hosting, were compulsory dissolved on January 28th and January 14th, respectively. 🙌

Unfortunately, their networks (AS215240 and AS215208) remain active...

Silent Connection quickly secured fresh IP blocks on January 26th through ZeXoTeK IT-Services (whose website, zexotek.de, oddly redirects to Google 🤔). Similarly, Dolphin 1337 Limited acquired new IP space on February 4th.

Even after both companies' were dissolved, these IPs are still operational - effectively making them digital no man’s land.

Luckily, Spamhaus DROP users are protected by the following listings:

⬇️ DROP 176.65.134.0/24 -> check.spamhaus.org/results?que

⬇️ DROP 176.65.139.0/24 -> check.spamhaus.org/results?que

⬇️ DROP 176.65.140.0/23 -> check.spamhaus.org/results?que

⬇️ DROP 176.65.142.0/24 -> check.spamhaus.org/results?que

⬇️ DROP 176.65.144.0/24 -> check.spamhaus.org/results?que

⬇️ DROP 176.65.143.0/24 -> check.spamhaus.org/results?que

This incident highlights why robust customer vetting is a necessity. Silent Connection's imminent dissolution was already visible on the UK company register as of November 5th - a clear red flag. 🚩

Spamhaus recommends always vetting new customers, and checking their commercial registry data before providing services. 🕵

Find a link to the DROP Lists in the comments 👇