Big congratulations to our 45th and now 47th President on an
extraordinary political comeback and decisive victory. No nation
has bigger opportunities. Wishing @realDonaldTrump all success in
leading and uniting the America we all love.
Congratulations to President Trump on a decisive victory. We have
great opportunities ahead of us as a country. Looking forward to
working with you and your administration.
Congratulations to President @realDonaldTrump on his decisive
victory. We are in a golden age of American innovation and are
committed to working with his administration to help bring the
benefits to everyone.
Congratulations President Trump, we’re looking forward to
engaging with you and your administration to drive innovation
forward that creates new growth and opportunity for the United
States and the world.
Congratulations President Trump on your victory! We look forward
to engaging with you and your administration to help make sure the
United States continues to lead with and be fueled by ingenuity,
innovation, and creativity.
I wonder how much Cook dithered over that cheerful-looking exclamation mark. I hope he regrets it. I wonder whether the latter four knowingly made the error of addressing former president and president-elect Trump as “President Trump”. Our nation only has one president at a time, and that president remains Joe Biden. I wonder too, what taste Cheetos-dusted 78-year-old testicles leave in one’s mouth. Whatever the flavor, I hope it lingers.
Someone should tell Gruber that you still use the honorific "President" for any past president. It's still President Carter, and that was 44 years ago.
An anonymous reader writes: Google Maps is testing a new ad format that could cause distractions while driving. It brings up a pop-up notification during navigation that covers the bottom half of the screen with an unnecessary detour suggestion.
Anthony Higman on X (formerly Twitter) recently spotted the new ad format during their commute. According to Higman, the ad popped up while passing a Royal Farms gas station, even though they did not search for a gas station or convenience store while setting their destination. The ad has a Sponsored tag at the top of the card, followed by the name of the location, its review rating, and the estimated arrival time. It also includes two buttons to add it as a stop or cancel the suggestion.
Veruca Salt: Like Captain Ahab, you are defined by an all-absorbing monomaniacal obsession: to find comfortable shoes that aren’t hideous.
Pavement: You spent your twenties watching movies off the Criterion Collection to impress boys, and it actually worked, so now you’re stuck with plotless black-and-white subtitled movies forever.
Smashing Pumpkins: You’ve disowned family members because they weren’t supportive enough of your career (i.e., they stopped buying the rash-inducing makeup and/or piss-scented essential oils from your MLM company).
Nirvana: You could never be one of those stereotypical soccer moms. (Your kids play lacrosse.)
Nine Inch Nails: You’re learning to pretend that gardening is an adequate replacement for the sexual adventures of your youth.
Eve 6: You go to PTA meetings just so you can whisper “critical race theory” into the microphone and then slip out the back door amid the pandemonium.
Jane’s Addiction: You suddenly realize you’ve saved a little money. You can’t decide if you should use it to fix your roof, your vision, your garage door, your feet, your skin, your wet basement, your dry vagina, your broken sidewalk, or your broken mental health. Before you choose, the dentist informs you that your kids need braces.
The Cardigans: In your quest to find comfortable shoes that aren’t hideous, you’ve convinced yourself that, with the right attitude, flats can be sexy. Unfortunately, your attitude is “desperately trying to make flats sexy.”
Neutral Milk Hotel: You vowed you’d never get a minivan. You got an SUV with a third row.
Mazzy Star: You have not yet admitted to yourself that succulents and macrame wall hangings are your generation’s Live Laugh Love decor.
Rage Against the Machine: You use the term “journey” to describe your training for a charity 5K, changes to your skincare routine, your evolving relationship with gluten, the fact that you occasionally take a yoga class, and your secretly failing marriage.
The Cranberries: Because you procrastinated so long on covering your grays, and now people think you’ve chosen to age gracefully, you’ve become a minor feminist icon.
Bikini Kill: You talk about your produce choices way too much, and now your friends’ secret nickname for you is “manic organic dream girl.”
Everclear: After hearing about the resurgence of lower back tattoos, you started an organization to educate young women on the dangers of the Tramp Stamp.
4 Non Blondes: You knit, and you’ve already given everyone you know a scarf. Time to retreat into decades of obscurity until people start having grandkids so you can make them baby blankets and regain some semblance of a purpose in life.
Pearl Jam: You’ve spent an inordinate amount of time on your town’s Facebook page complaining about how your favorite restaurant raised its credit card fees.
Blur: Just try to talk to you about TV without you explaining that the British Office was better than the American Office.
Garbage: You tell yourself you’re microdosing shrooms for creativity and productivity benefits, but in reality it’s the only way you can deal with the other moms at the playground.
Cake: Your entire identity is built around being Karen who is not a Karen.
Ben Folds Five: You know that no amount of glitter, hot glue, and parchment paper will fill the gaping pit of loneliness that is your middle-aged existence, but you’ll be damned if you aren’t going to at least try to craft your way out of this crippling depression.
No Doubt: You’ve finally given up on the quest to find comfortable, non-hideous shoes, but you still pretend your Birkenstocks are part of the “ironically ugly shoes” fashion trend.
Hansen: You’ve lost multiple friends because you say “don’t yuck my yum” too often.
Porno for Pyros: In a misguided attempt to bond, you showed your daughter a YouTube video of yourself flashing Perry Farrell at the original Lollapalooza. (“Look, honey, we have the same boobs!”)
Sixpence None the Richer: You love the Royal Family more than your own.
Hole: You don’t understand what the Bad Art Friend did wrong.
Harvey Danger: You can’t get through a single conversation without mentioning your junior year abroad in Paris.
Stone Temple Pilots: You put a HATEHAS NO HOMEHERE sign in your front yard, and it’s not a lie, because technically hate is not the same thing as smoldering resentment, all-consuming envy, quiet hostility, and vindictive plotting to use subterfuge, fraud, or witchcraft to destroy the life of that stuck-up bitch in the charming Cape Cod across the street.
Letters to Cleo: You’re living a life less ordinary. (You have one kid or three kids instead of two kids.)
Dave Matthews Band: Your regular family is about to leave you because you won’t shut the fuck up about your Cross Fit family.
Radiohead: Every minor challenge of your life has been a warmup for this ongoing crisis: going through perimenopause while your kid is going through puberty.
Virtual private networking (VPN) companies market their services as a way to prevent anyone from snooping on your Internet usage. But new research suggests this is a dangerous assumption when connecting to a VPN via an untrusted network, because attackers on the same network could force a target’s traffic off of the protection provided by their VPN without triggering any alerts to the user.
Image: Shutterstock.
When a device initially tries to connect to a network, it broadcasts a message to the entire local network stating that it is requesting an Internet address. Normally, the only system on the network that notices this request and replies is the router responsible for managing the network to which the user is trying to connect.
The machine on a network responsible for fielding these requests is called a Dynamic Host Configuration Protocol (DHCP) server, which will issue time-based leases for IP addresses. The DHCP server also takes care of setting a specific local address — known as an Internet gateway — that all connecting systems will use as a primary route to the Web.
VPNs work by creating a virtual network interface that serves as an encrypted tunnel for communications. But researchers at Leviathan Security say they’ve discovered it’s possible to abuse an obscure feature built into the DHCP standard so that other users on the local network are forced to connect to a rogue DHCP server.
“Our technique is to run a DHCP server on the same network as a targeted VPN user and to also set our DHCP configuration to use itself as a gateway,” Leviathan researchers Lizzie Moratti and Dani Cronce wrote. “When the traffic hits our gateway, we use traffic forwarding rules on the DHCP server to pass traffic through to a legitimate gateway while we snoop on it.”
The feature being abused here is known as DHCP option 121, and it allows a DHCP server to set a route on the VPN user’s system that is more specific than those used by most VPNs. Abusing this option, Leviathan found, effectively gives an attacker on the local network the ability to set up routing rules that have a higher priority than the routes for the virtual network interface that the target’s VPN creates.
“Pushing a route also means that the network traffic will be sent over the same interface as the DHCP server instead of the virtual network interface,” the Leviathan researchers said. “This is intended functionality that isn’t clearly stated in the RFC [standard]. Therefore, for the routes we push, it is never encrypted by the VPN’s virtual interface but instead transmitted by the network interface that is talking to the DHCP server. As an attacker, we can select which IP addresses go over the tunnel and which addresses go over the network interface talking to our DHCP server.”
Leviathan found they could force VPNs on the local network that already had a connection to arbitrarily request a new one. In this well-documented tactic, known as a DHCP starvation attack, an attacker floods the DHCP server with requests that consume all available IP addresses that can be allocated. Once the network’s legitimate DHCP server is completely tied up, the attacker can then have their rogue DHCP server respond to all pending requests.
“This technique can also be used against an already established VPN connection once the VPN user’s host needs to renew a lease from our DHCP server,” the researchers wrote. “We can artificially create that scenario by setting a short lease time in the DHCP lease, so the user updates their routing table more frequently. In addition, the VPN control channel is still intact because it already uses the physical interface for its communication. In our testing, the VPN always continued to report as connected, and the kill switch was never engaged to drop our VPN connection.”
The researchers say their methods could be used by an attacker who compromises a DHCP server or wireless access point, or by a rogue network administrator who owns the infrastructure themselves and maliciously configures it. Alternatively, an attacker could set up an “evil twin” wireless hotspot that mimics the signal broadcast by a legitimate provider.
ANALYSIS
Bill Woodcock is executive director at Packet Clearing House, a nonprofit based in San Francisco. Woodcock said Option 121 has been included in the DHCP standard since 2002, which means the attack described by Leviathan has technically been possible for the last 22 years.
“They’re realizing now that this can be used to circumvent a VPN in a way that’s really problematic, and they’re right,” Woodcock said.
Woodcock said anyone who might be a target of spear phishing attacks should be very concerned about using VPNs on an untrusted network.
“Anyone who is in a position of authority or maybe even someone who is just a high net worth individual, those are all very reasonable targets of this attack,” he said. “If I were trying to do an attack against someone at a relatively high security company and I knew where they typically get their coffee or sandwich at twice a week, this is a very effective tool in that toolbox. I’d be a little surprised if it wasn’t already being exploited in that way, because again this isn’t rocket science. It’s just thinking a little outside the box.”
Successfully executing this attack on a network likely would not allow an attacker to see all of a target’s traffic or browsing activity. That’s because for the vast majority of the websites visited by the target, the content is encrypted (the site’s address begins with https://). However, an attacker would still be able to see the metadata — such as the source and destination addresses — of any traffic flowing by.
KrebsOnSecurity shared Leviathan’s research with John Kristoff, founder of dataplane.org and a PhD candidate in computer science at the University of Illinois Chicago. Kristoff said practically all user-edge network gear, including WiFi deployments, support some form of rogue DHCP server detection and mitigation, but that it’s unclear how widely deployed those protections are in real-world environments.
“However, and I think this is a key point to emphasize, an untrusted network is an untrusted network, which is why you’re usually employing the VPN in the first place,” Kristoff said. “If [the] local network is inherently hostile and has no qualms about operating a rogue DHCP server, then this is a sneaky technique that could be used to de-cloak some traffic – and if done carefully, I’m sure a user might never notice.”
MITIGATIONS
According to Leviathan, there are several ways to minimize the threat from rogue DHCP servers on an unsecured network. One is using a device powered by the Android operating system, which apparently ignores DHCP option 121.
Relying on a temporary wireless hotspot controlled by a cellular device you own also effectively blocks this attack.
“They create a password-locked LAN with automatic network address translation,” the researchers wrote of cellular hot-spots. “Because this network is completely controlled by the cellular device and requires a password, an attacker should not have local network access.”
Leviathan’s Moratti said another mitigation is to run your VPN from inside of a virtual machine (VM) — like Parallels, VMware or VirtualBox. VPNs run inside of a VM are not vulnerable to this attack, Moratti said, provided they are not run in “bridged mode,” which causes the VM to replicate another node on the network.
In addition, a technology called “deep packet inspection” can be used to deny all in- and outbound traffic from the physical interface except for the DHCP and the VPN server. However, Leviathan says this approach opens up a potential “side channel” attack that could be used to determine the destination of traffic.
“This could be theoretically done by performing traffic analysis on the volume a target user sends when the attacker’s routes are installed compared to the baseline,” they wrote. “In addition, this selective denial-of-service is unique as it could be used to censor specific resources that an attacker doesn’t want a target user to connect to even while they are using the VPN.”
Moratti said Leviathan’s research shows that many VPN providers are currently making promises to their customers that their technology can’t keep.
“VPNs weren’t designed to keep you more secure on your local network, but to keep your traffic more secure on the Internet,” Moratti said. “When you start making assurances that your product protects people from seeing your traffic, there’s an assurance or promise that can’t be met.”
A copy of Leviathan’s research, along with code intended to allow others to duplicate their findings in a lab environment, is available here.
Alexandra Sternlicht, reporting for Fortune (News+):
Evan Turner, who worked at TikTok as a senior data scientist from
April to September in 2022, said TikTok concealed the involvement
of its Chinese owner during his employment. When hired, Turner
initially reported to a ByteDance executive in Beijing. But later
that year, after the company announced a major initiative to store
TikTok’s U.S. user data only in the U.S., Turner was reassigned — on paper, at least — to an American manager in Seattle, he says.
But Turner says a human resources representative revealed during a
video conference call that he would, in reality, continue to work
with the ByteDance executive. The stealth chain of command
contradicted what TikTok’s executives had said about the company’s
independence from ByteDance, Turner says. [...]
Nearly every 14 days, as part of Turner’s job throughout 2022, he
emailed spreadsheets filled with data for hundreds of thousands of
U.S. users to ByteDance workers in Beijing. That data included
names, email addresses, IP addresses, and geographic and
demographic information of TikTok U.S. users, he says. The goal
was to sift through the information to mine for insights like the
geographical regions where users watched the most videos of a
particular genre and decide how the company should invest to
encourage users to be more active. It all took place after the
company had started its initiative to keep sensitive U.S. user
data in the U.S., and only available to U.S. workers.
“I literally worked on a project that gave U.S. data to China,”
Turner says. “They were completely complicit in that. There were
Americans that were working in upper management that were
completely complicit in this.”
Robyn Dixon, David M. Herszenhorn, and Catherine Belton, reporting for The Washington Post:
Russian opposition leader Alexei Navalny, the defiant
anti-corruption crusader and democracy champion who was President
Vladimir Putin’s despised nemesis, died suddenly in an Arctic
Russian prison colony on Friday, penitentiary officials said,
removing the most prominent figure inside Russia willing to
challenge the Kremlin’s rule.
Referring to Navalny as Putin’s “nemesis” — which description the Post also uses in its headline — whitewashes just how despicable his attempted assassination, yearslong imprisonment, and now (presumed) actual assassination were. It’s a dysphemism — the opposite of a euphemism. Navalny was a political rival and staunch proponent of democracy. Putin was Navalny’s nemesis, but not the other way around.
His death — foretold as almost inevitable, including by
Navalny himself — sent shock waves across Russia and was
quickly condemned by global leaders, some of whom joined
Russian opposition figures in calling it a state-sponsored
murder. Navalny, 47, had appeared a court hearing by video link
the day before, seemingly in good health and with his trademark
humor intact.
Navalny’s family and his team, who continued to run his political
operation in exile, had warned that his life was in danger since
his arrest in January 2021, when he returned to Russia after
recovering in Germany from being poisoned with a banned
nerve agent. An investigation led by Navalny and Bellingcat, an
investigative journalism organization, had identified a team of
Russian federal security agents as responsible for the
assassination attempt, and his supporters noted that in prison he
was in the clutches of the very government that had already tried
to kill him several times.