Well,
Parler has been hacked and user data has been downloaded. The following thread contains information from /u/BlueMountainDace on Reddit:
"so a group of developers latched onto the Press Release that Twilio put out at midnight last night. In that Press Release, Twilio
Well,
Well, then what happened, those user accounts that had Administration rights to the entire platform... The hackers, internet warriors, call it what you will, was able to use the forgot password link to change the password. Why? Because Twilio was no
This group of Internet Warriors then used that account, to create a handful of other ADMINISTRATION accounts, and then created a script that ended up
Now that they had a way of creating admin accounts without interruption, they created a Docker Image (basically a virtual machine) called a Warrior, that anyone could download, and when fired up, would immediately start
Consider it like SETI (Search for Extra-Terrestrial Intelligence) that people used to load up as screen savers when their computers were not being used. Same concept, crowdsourcing.
All of this data, the videos,
And the kicker.. is this: all of this information was thought to be secure and private by individuals who were making the posts. A significant number of those
It means they uploaded a picture of the front and back of their REAL State Driver's License........ Let that sink in for a second.
I am positive the FBI has been actively
And it's how the FBI, DHS, and FAA have been able to immediately and exhaustively create no-fly lists. Every verified attendee of the Capitol riot where
More from Internet
Hackers reportedly slipped malware into prior SolarWinds software updates, which gave them access to a "God-mode" for infected networks, including the Treasury and Commerce departments.
— Wes Wilson (@weswilson4) December 14, 2020
The Pentagon is also a SolarWinds customer.https://t.co/Srcoztssol https://t.co/OgMhAjJqPx
Basically what this means is that SolarWinds itself was exploited. Someone posted an infected update as legitimate (digitally signed), leading customers to download a bad update.
“Multiple trojanized updates were digitally signed from March - May 2020 and posted to the SolarWinds updates website” https://t.co/8e3bMFWXYu
FireEye then explains that infected organizations were approached and exploited. This is a separate Step 2.
At this point, information is already going to “malicious domains” without extra intervention, after the malware does nothing for “up to two weeks”
(should also be useful for Eng, Design, Data Science, Mktg, Ops folks who want to get better at PM work or want to build more empathy for your PM friends ☺️)
(oh, and pls also share *your* favorite resources below)
👇🏾
1/
Product Management - Start Here by @cagan
(hard to go wrong if you start with Marty Cagan’s
2/
Tips for Breaking into PM by @sriramk
(I’ve recommended this thread in my DMs more often than any other thread, by a pretty wide
Breaking into PMing - a \U0001f9f5 // A question folks from eng/design/other functions often have how to become a PM in a tech co.
— Sriram Krishnan (@sriramk) April 14, 2020
It can seem non-obvious and differs with each company but here are some patterns I've seen work. All the below assumes you have no PMing on your resume.
3/
Top 100 Product Management Resources by @sachinrekhi
(well-categorized index so you can focus on whatever’s most useful right
4/
Brief interruption.
It’s important to understand your preferred learning style and go all in on that learning style (vs. struggling / procrastinating as you force a non-preferred learning
There is no One Correct Way\u2122 to learn
— Shreyas Doshi (@shreyas) August 15, 2020
Don\u2019t feel pressured to read 70 books/year just becos Super-Successful Person X does that
Videos, Podcasts, Audiobooks, Discussions\u2014all are fine
What to do:
Understand your preferred learning style
Don't resist it, embrace it
Commit to it
You May Also Like
It's all in French, but if you're up for it you can read:
• Their blog post (lacks the most interesting details): https://t.co/PHkDcOT1hy
• Their high-level legal decision: https://t.co/hwpiEvjodt
• The full notification: https://t.co/QQB7rfynha
I've read it so you needn't!
Vectaury was collecting geolocation data in order to create profiles (eg. people who often go to this or that type of shop) so as to power ad targeting. They operate through embedded SDKs and ad bidding, making them invisible to users.
The @CNIL notes that profiling based off of geolocation presents particular risks since it reveals people's movements and habits. As risky, the processing requires consent — this will be the heart of their assessment.
Interesting point: they justify the decision in part because of how many people COULD be targeted in this way (rather than how many have — though they note that too). Because it's on a phone, and many have phones, it is considered large-scale processing no matter what.