Avatar

Mirror on the world

@mirrorontheworld

My take on the news from the world.

Dans le contentieux climatique engagé contre TotalÉnergies par une coalition d’associations et de collectivités, le juge de la mise en état du tribunal judiciaire de Paris a jugé l’action en justice irrecevable. Reposant sur une interprétation inquiétante de la loi sur le devoir de vigilance et des dispositions relatives au préjudice écologique, cette décision vient restreindre l’accès à la justice pour les associations et collectivités. Après plusieurs années de procédure, le tribunal refuse d’examiner l’impact des activités de TotalÉnergies sur le dérèglement climatique.  

Des ministres qui rejoignent des multinationales, des députés qui deviennent lobbyistes ou inversement, des hauts fonctionnaires qui se mettent au service d’intérêts économiques qu’ils étaient chargés de réguler… Enquête sur le grand brouillage des frontières entre public et privé.

Le droit au chiffrement est actuellement attaqué par les pouvoirs policiers, judiciaires et législatifs en France, mais aussi dans l’Union européenne, au Royaume-Uni et aux États-Unis. En tant que société, nous devons choisir. Acceptons-nous un futur dans lequel nos communications privées peuvent être interceptées à tout moment et chaque personne considérée comme suspecte ?

La police pourrait désormais déclencher à distance des caméras ou micros de tout objet connecté et obtenir leur géolocalisation précise, à des fins d’enquête criminelle ou antiterroriste, à votre insu. Une technique de surveillance hyper intrusive, dont l’adoption par l’une des deux chambres parlementaires ne suscite pas vraiment de levée de boucliers.

Delphine, agricultrice bio en Bretagne, a découvert que ses terres étaient polluées de pesticides interdits il y a des décennies. Sans soutien de l’État, elle a dû cesser son activité et chercher seule comment réduire les risques pour ses clients.

Le projet de loi justice donne la possibilité aux enquêteurs d’activer à distance les appareils électroniques d’une personne à son insu. Une «surenchère sécuritaire» ainsi qu’une «grave atteinte à l’intimité», alerte la Quadrature du Net.

Selon nos informations, les juges qui enquêtent sur les comptes des campagnes 2017 et 2022 du président de la République s’intéressent aux « livrables » McKinsey « sur l’évolution du métier d’enseignant », payés par l’État en 2020 et dont des propositions figurent dans le dernier programme d’Emmanuel Macron.

Avec sa concentration record de mégaporcheries, la commune du Finistère est un symbole de l’intensification de l’élevage porcin et de ses conséquences. Enquête sur un coin de Bretagne où rien n’échappe aux cochons. Ni l’eau, ni l’air, ni la mairie.

Avatar

I was planning to drop the items from the linked tweet thread onto this post, but there are SO MANY new bills that it became a wall of text - line after line after line of incredible things Minnesota has enacted in a single session.

  • Marijuana will be fully legal starting in August, but the bill also wipes past criminal records and sets up marginalized communities to benefit from the new incoming profits.
  • voting rights are restored immediately after leaving prison, probation is capped, and phone calls for prisoners are free now.
  • there are so many labor rights being added i can't begin to list them. an end to non-compete clauses, paid sick and family medical leave for the WHOLE STATE, unemployment for seasonal education workers, safety regulations for workers in warehouses and nursing, establishment of minimum wages for gig drivers!
  • carbon free electricity by 2040
  • cutting child poverty by 1/3 immediately
  • price caps for high cost pharmaceuticals
  • more funding for public transit, public defense, education, homelessness prevention, and the removal of ALL lead pipes in the state water system
  • roe v wade is codified, conversion therapy is banned, and other state's anti-trans bills are blocked for anyone receiving gender related care here.
  • undocumented immigrants can get drivers licenses and basic healthcare through the state
  • improvements to our already robust voting rights
  • basic gun safety laws, like background checks and red flag laws

I'm.... actually blown away. the political landscape often feels so hopeless, but the DFL pulled themselves together, getting every member on board for these changes - real changes that are going to protect health, keep people out of jail and housed, and improve work conditions massively. this should be a beacon for every other state democratic party - change doesn't have to be incremental. things can get better and they can get better right now. get crackin'.

Des policiers de la CRS 8, une unité spéciale que Gérald Darmanin a créée en 2021 et qu’il utilise à sa main, font l’objet d’une enquête ouverte par le parquet de Rennes pour avoir brutalisé un manifestant. Dans une note interne, le commandant de cette compagnie ne cache pas leur esprit va-t-en-guerre. Interrogés par Mediapart, des préfets s’émeuvent du fonctionnement hyperviolent de cette compagnie.

Le gouvernement publie cet été sa Stratégie nationale pour l’alimentation, la nutrition et le climat. Face aux pressions des lobbies agroalimentaires, un collectif de 84 organisations environnementales, de consommateurs, de santé et de solidarité exige une Stratégie à la hauteur des enjeux écologiques, sociaux et de santé publique.

Avatar

New Things to Beware on the Internet

On May 3rd, Google released 8 new top-level domains (TLDs) -- these are new values like .com, .org, .biz, domain names. These new TLDs were made available for public registration via any domain registrar on May 10th.

Usually, this should be a cool info, move on with your life and largely ignore it moment.

Except a couple of these new domain names are common file type extensions: ".zip" and ".mov".

This means typing out a file name could resolve into a link that takes you to one of these new URLs, whether it's in an email, on your tumblr blog post, a tweet, or in file explorer on your desktop.

What was previously plain text could now resolve as link and go to a malicious website where people are expecting to go to a file and therefore download malware without realizing it.

Folk monitoring these new domain registrations are already seeing some clearly malicious actors registering and setting this up. Some are squatting the domain names trying to point out what a bad idea this was. Some already trying to steal your login in credentials and personal info.

This is what we're seeing only 12 days into the domains being available. Only 5 days being publicly available.

What can you do? For now, be very careful where you type in .zip or .mov, watch what website URLs you're on, don't enable automatic downloads, be very careful when visiting any site on these new domains, and do not type in file names without spaces or other interrupters.

I'm seeing security officers for companies talking about wholesale blocking .zip and .mov domains from within the company's internet, and that's probably wise.

Be cautious out there.

Avatar

I really want to reiterate how this can go wrong frequently and fast, folks.

A malicious actor sets up a page with an auto-downloader squatting on a domain name that matches a common zip file name like photos DOT zip. This website is set up to start an auto downloader upon being visited, downloading a zip file with the same name as the URL which contains malicious software (virus, worm, keylogger, etc).

Scenario.

Someone you know well sends you an email or text with promised photos attached. The email even reads something like this.

Because .zip is now a TLD, that plain text is automatically formatted into a link to malicious actor's website without them having to send you anything.

Folk with family with iPhones or iPads that are sent multiple photos in one go might be familiar with iCloud's tendency to automatically compile them into zip file for the sender and less savvy tech users have trouble NOT doing that.

These same less savvy users, or even just someone just not thinking in the moment, will click that .zip link, not realizing it isn't the the same as clicking on the promised attachment.

They download a file that matches the name they expected. They open it because they were expecting that file and it's from a trusted source. Except the file they downloaded isn't the one that was sent by their trusted source and now they have malware.

Another Scenario.

An IT person tries to send you an email with instructions on how to resolve a problem with a commonly used filename like install-repair DOT zip or to install new software like microsoft-office DOT zip.

The email may start with instructions of where to go get the legitimate file to do the install or repair, but now a line later in the instructions is also has a link to a .zip URL. A user, already frazzled by IT problems, may click it to ensure they have the right file. Again, they download malicious code from a squatting website or it prompts them with a fake login and now the squatting website has stolen their login credentials for a legitimate site. All due to an expected email from a trusted source.

Above you can see microsoft-office DOT zip is already out there with a fake Microsoft login screen waiting to steal your credentials.

These risks are already out there now because the TLD has been activated.

Plain text on old post are already being resolved into links to the new websites.

Here you can see a tweet from 2021, long before .zip was a domain name, now resolves that plan text into a clickable link. You'll start seeing this everywhere, and malicious actors do not have to lift a finger to send it to you.

Yes, a lot of users aren't going to click that, but a lot of folk will. Whomever is squatting on photos DOT zip domain name has made a one time payment to have access to anyone that ever sees that file name typed out.

In an example of an existing squatter site, clientdocs DOT zip is exactly one such pre-setup .zip domain name that initiates an automatic download. This one may be harmless, but the set ups are already out there and waiting to catch folk.

It's an unnecessary and risky can of worms that's been opened up.

Holy Unforced Errors, Batman.

Pour la première fois dans l’histoire de la République, un ancien chef de l’État a été reconnu coupable en appel dans une affaire de corruption. Nicolas Sarkozy a été condamné, mercredi 17 mai, par la cour d’appel de Paris, à trois ans de prison, dont un ferme sous bracelet électronique à domicile.

Le Parquet national financier a demandé, dans un réquisitoire définitif signé le 10 mai, le renvoi devant le tribunal correctionnel de treize personnes, dont l’ancien président de la République et ses ex-ministres Claude Guéant, Brice Hortefeux et Éric Woerth, dans l’affaire des financements libyens, révélée en 2011 par Mediapart.