575: Brent's Busted Builds
11 August 2024
Brent's computer pulls an all-nighter at the worst possible moment, and the hits keep coming for open-source Android distributions and our new 2FA tool.
Episode Links
- ๐ฅ Gets Sats Quick and Easy with Strike
- ๐ป LINUX Unplugged on Fountain.FM
- Toronto Meetup โ Thursday, August 29, 2024 from 6:00 PM to 8:00 PM EDT
- Sacramento LUG Meetup โ Saturday September 7th, 2024 from 10:00 AM to 2:00 PM PDT
- Anker PowerConf S330 USB Speakerphone
- Corsair Void RGB Elite Wireless Premium Gaming Headset
- Loss of popular 2FA tool puts security-minded GrapheneOS in a paradox
- GrapheneOS on X โ Google can either permit GrapheneOS in the Play Integrity API in the near future
- GrapheneOS on X โ If Authy insists on using it, they should use the standard Android hardware attestation API to permit using GrapheneOS too. Banning 250k+ people with the most secure smartphones from using your app is anti-security, not pro-security.
- GrapheneOS on X โ Authy simply delegated checking device integrity to Google. It’s Google choosing to block GrapheneOS users from using Authy. Google chooses to allow using a device with no security patches for the past 8 years but bans using an OS much more secure than the stock Pixel OS.
- Twilio kills off Authy for desktop, forcibly logs out all users
- GrapheneOS on X โ Our latest release with prevention for most VPN app DNS leaks is currently available in our Alpha and Beta channels. We need more feedback from testing VPN apps and services with leak blocking toggled on, which GrapheneOS already enables by default.
- GrapheneOS on X โ Our current approach to DNS leak blocking appears to work well without breaking compatibility. We’ve made progress towards fixing a related issue for some VPN apps where rare connections are made to VPN DNS outside of the tunnel. We can hopefully ship stricter enforcement soon.
- GrapheneOS on X โ We’ve become aware of another company selling devices with GrapheneOS while spreading harmful misinformation about it to promote insecure products. We’re making our usual attempt at resolving things privately. However, we need to quickly address what has been claimed regardless.
- Membership Summer Discount โ Take $1 a month of your membership for a lifetime!
- How You Guys Expect to Beat Me?
- Blue Iris Container
- netbird โ Connect your devices into a secure WireGuardยฎ-based overlay network with SSO, MFA and granular access controls.
- netbird on GitHub
- OpenZiti โ Open Source Zero Trust Networking
- OpenZiti on GitHub
- Collapse OS โ Bootstrap post-collapse technology
- Docker-OSX โ Run macOS VM in a Docker! Run near native OSX-KVM in Docker! X11 Forwarding! CI/CD for OS X Security Research! Docker mac Containers.