Hang on, when did I confess that?
27.01.2026 21:52 — 👍 0 🔁 0 💬 1 📌 0@lorenzofb.bsky.social
Real-time historian of the late cyber capitalist era @TechCrunch, writing about the intersection of hackers, human rights, and spies. Also writing a book about Hacking Team and the history of government spyware. ☎️ Signal: +1 917 257 1382
Hang on, when did I confess that?
27.01.2026 21:52 — 👍 0 🔁 0 💬 1 📌 0If you take OPSEC advice from Elon Musk and Pavel Durov, good luck, you're basically screwed. I wouldn’t trust those two to make me a coffee with a Nespresso machine, let alone help me stay secure online.
27.01.2026 20:57 — 👍 29 🔁 7 💬 2 📌 0NEW: After Apple launched Lockdown Mode years ago, and Google released its own special security feature for Android last year, WhatsApp now offers a new mode for users at high risk of being targeted with spyware.
It's called Strict Account Settings and enables certain restrictions to protect users.
Vas has tirelessly and constantly followed virtually every story related to government spyware that is developing in any corners of the world. I don't know how he can keep up with everything that's happening in that world, but I am glad he does.
26.01.2026 18:22 — 👍 24 🔁 3 💬 1 📌 2A number of Washington Post journalists asked for tips from government workers last year and posted their personal phone numbers for @signal.org. Please know that Signal allows you to create a username, meaning you can keep your phone number private. signal.org/blog/phone-n...
26.01.2026 16:20 — 👍 24 🔁 10 💬 0 📌 0Martha Root explained their motivations here, but not any technical details, which they promise are coming soon.
"No, this didn’t happen live on stage. And no it wasn’t a moment straight out of a hacker movie. It was mostly timing, a bit of performance and things that were already unfolding."
NEW: Microsoft handed the FBI the recovery keys to decrypt the hard drives of three laptops encrypted with BitLocker.
BitLocker is enabled by default in modern Windows laptops, but Microsoft also prompts users to upload the recovery keys to the company's cloud, which opens up this possibility.
25 days later, White Date is still down.
23.01.2026 15:42 — 👍 78 🔁 13 💬 1 📌 0Spanish judge closes probe into NSO in wake of Pegasus hack of several govt officials, incl the PM. Court says Israel ignored five requests for information and probe can't proceed as a result. NSO has historically been shielded from accountability by the Israeli govt
therecord.media/spanish-judg...
Imho yes
22.01.2026 17:02 — 👍 2 🔁 0 💬 0 📌 0Come for the news, stay for a quick history lesson on the use of government spyware in Europe, something that's been happening since at least 2004.
techcrunch.com/2026/01/22/i...
NEW: Ireland is working on a law to regulate the use of spyware by the police.
There's no details yet, but the Irish government promises to balance the need to fight serious crime with spyware, with the need to respect privacy and human rights.
techcrunch.com/2026/01/22/i...
New, by me: Under Armour says it’s aware of data breach claims after 72M customer records were posted online.
A spox. told me a "small percentage" of customers had sensitive information compromised but wouldn't say what it considers "sensitive," nor provide an accurate figure of affected customers.
So…is the PS5 Pro worth the extra $$$ or should I just get the normal one?
21.01.2026 22:01 — 👍 0 🔁 0 💬 6 📌 0*pinches bridge of nose and sighs heavily*
These utter fuckwits have returned with the *same* phishing campaign on the *same* burned infrastructure and leaking the same data, which leads me to think that it's probably Iranian intelligence after all.
My writeup from last week with more details:
NEW: Two members of Elon Musk’s Department of Government Efficiency (DOGE) who were working at the Social Security Administration may have shared SSNs to help an advocacy group that had the aim "to overturn election results in certain States," according to a court document.
20.01.2026 20:59 — 👍 41 🔁 19 💬 2 📌 2NOTE: The letter says that the company Defense Prime (rebranded as Palm Beach Networks and linked to Head and Tail) develops Pegasus. That is clearly a mistake, given that it's NSO that develops Pegasus.
20.01.2026 18:51 — 👍 3 🔁 0 💬 0 📌 0No, I think that's a mistake on the part of the people who wrote the letter. But let me note that.
20.01.2026 18:49 — 👍 0 🔁 0 💬 0 📌 0The Catalan newspaper Ara covered this recently, with the news peg that there was a closed-door conference where many of these companies were present.
es.ara.cat/sociedad/suc...
This letter came around the time stories us and Haaretz published stories about the presence of several Israeli (and from other countries too) offensive cybersecurity and spyware companies in Barcelona.
techcrunch.com/2025/01/13/h...
www.haaretz.com/israel-news/...
The government answered that the Ministry of Defense has no information at all about the issues raised in the letter.
www.congreso.es/entradap/l15...
Last year, a member of the Spanish parliament sent a letter to the government asking what it thinks about the fact that there are several Israeli offensive cybersecurity folks in Barcelona working on spyware, and whether the government wants to do anything about it.
www.congreso.es/entradap/l15...
One more link: bsky.app/profile/vall...
20.01.2026 16:58 — 👍 5 🔁 0 💬 0 📌 0And here's the New York Times piece that cites "U.S. officials briefed on the operation."
www.nytimes.com/2026/01/15/u...
2) This blog post by @dangoodin.bsky.social
arstechnica.com/security/202...
These are good pieces on the alleged U.S. cyberattack against the Venezuelan power grid. It seems that for now the skepticism is warranted until we get more details and some independent confirmation from threat intelligence/infrastrucure researchers.
1) This Linkedin post by @metacurity.com
In case tone isn't clear: I am joking.
18.01.2026 19:12 — 👍 7 🔁 0 💬 2 📌 0A new this.weekinsecurity.com is out, featuring stories on: FBI raiding WaPo reporter's home; Iran's internet shutdown passes one week; Flock flucked up license plate redactions; millions of headphones at risk of eavesdropping; a ton of max 10.0 bugs; that Venezuela "cyberattack," and much more.
18.01.2026 17:46 — 👍 20 🔁 7 💬 2 📌 0Trying to protect everything from everyone all the time is a good way to drive yourself crazy. This is why we threat model. Here is EFF's Surveillance Self Defense guide to putting together your security plan, also known as threat modeling: ssd.eff.org/module/your-...
16.01.2026 18:47 — 👍 481 🔁 221 💬 6 📌 6NEW: Nicholas Moore, a hacker who broke into the systems of the U.S. Supreme Court and the Department of Veteran Affairs stole the personal data of victims and then posted it online on his @ihackthegovernment Instagram account.
Moore faces a maximum of a year in prison and a fine of up to $100,000.