Basically, it really pissed me off that I HAD to use an app for my thermal printer, so I reverse engineered it, and made GhostLabel, in Rust.
It might or might not work for you, I dunno.
More details in the readme.
Sam Bent
Agorist. Counter-economist. Privacy maximalist. Student of OPSEC. Anti-authoritarian. Free speech absolutist. Logician. Ex-Darknet Vendor. Youtuber.
> builds a GRUB replacement in 2016
> spends 5 years breaking GRUB piece by piece
> strips LUKS encryption from /boot "for security"
> proposes to remove: btrfs, xfs, zfs
> keeps SquashFS, two CVEs, one rated 7.8 HIGH
> controls the signing keys for all of it
> Canonical promoted him.
https://www.sambent.com/canonicals-grub-saboteur-has-a-10-year-plan
There's a Linux distro that exists specifically to break California's age verification law.
"Full, knowing, and intentional noncompliance" with AB-1043.
They're mailing $12 RISC-V boards to schools.
Watch:
Anyone with a computer can mine XMR, which is how decentralization was supposed to work.
Proton built Proton Meet to escape the CLOUD Act.
They built it on CLOUD Act infrastructure.
Their website promises "not even government agencies" can access your calls.
The company routing them hands your call records to the government when asked.
https://www.sambent.com/proton-meet-isnt-what-they-told-you/
Monero has survived ten years on donations and volunteer labor while VC-backed "privacy" projects burned through millions building compliance tools,
turns out you don't need a marketing budget when the product actually works.
Dylan, useful idiot with commit access, pushed age verification PRs to systemd, Ubuntu & Arch,
got 2 Microslop employees to merge it, called it 'hilariously pointless' in the PR itself,
then watched Lennart personally block the revert after community outrage.
Unpaid compliance simp.
https://www.sambent.com/the-engineer-who-tried-to-put-age-verification-into-linux-5/
Virtualization security and hypervisor isolation mechanisms.
"Virtual machine monitors must provide strong isolation between guest operating systems."
- 𝗣𝗿𝗼𝘁𝗲𝗰𝘁𝗶𝗼𝗻 𝗠𝗲𝗰𝗵𝗮𝗻𝗶𝘀𝗺𝘀 𝗶𝗻 𝘁𝗵𝗲 𝗩𝗠/𝟯𝟳𝟬 𝗛𝘆𝗽𝗲𝗿𝘃𝗶𝘀𝗼𝗿 by R.J. Creasy (1981)
https://dl.acm.org/doi/10.1145/800217.806615
#OPSEC365 023/365
In 2018, Strava's global heatmap revealed the locations and layouts of secret military bases because soldiers were tracking their runs.
Fitness apps broadcast where you exercise, what routes you take, and what time you're usually there. If your profile is public, anyone can see your patterns.
Strava's default is public. Soldiers exposed military base layouts in 2018 because nobody changed it. Set your fitness profiles to private.
"Tainted coins" is a concept that only exists when your blockchain snitches on transaction history.
Most Tor Docker images are running outdated Tor, no guard protection, and leave telemetry on by default.
HiddenForge v2.0.0 (my creation):
Tor 0.4.9.6 + Vanguards,
every dependency SHA256-pinned,
zero telemetry,
read-only filesystem,
rootless Podman support.
Built for a state-level adversary threat model.
https://github.com/DoingFedTime/HiddenForge
https://hub.docker.com/r/doingfedtime/hiddenforge
axios Got Hijacked and Your Machine May Be Compromised
https://www.sambent.com/axios-got-hijacked-and-your-machine-may-be-compromised/
Monero Research Lab publishes peer-reviewed cryptography papers while other projects publish marketing decks.
The state will always side with the franchise over the independent because the franchise pays lobbyists.
The most dangerous people to authoritarian systems aren't radicals or revolutionaries,
they're ordinary people who simply refuse to comply with illegitimate demands for their financial data.
This is counter-economics and you've been practicing it your whole life without knowing the name.
Mix networks for anonymous communication predating Tor.
"Mixes provide anonymity by reordering and re-encrypting messages."
- 𝗨𝗻𝘁𝗿𝗮𝗰𝗲𝗮𝗯𝗹𝗲 𝗘𝗹𝗲𝗰𝘁𝗿𝗼𝗻𝗶𝗰 𝗠𝗮𝗶𝗹, 𝗥𝗲𝘁𝘂𝗿𝗻 𝗔𝗱𝗱𝗿𝗲𝘀𝘀𝗲𝘀, 𝗮𝗻𝗱 𝗗𝗶𝗴𝗶𝘁𝗮𝗹 𝗣𝘀𝗲𝘂𝗱𝗼𝗻𝘆𝗺𝘀 by David Chaum (1981)
https://www.freehaven.net/anonbib/cache/chaum-mix.pdf
Tracking the spam value chain from click to payment.
"We present the first comprehensive analysis of the spam value chain, from initial email to final product purchase."
- 𝗖𝗹𝗶𝗰𝗸 𝗧𝗿𝗮𝗷𝗲𝗰𝘁𝗼𝗿𝗶𝗲𝘀: 𝗘𝗻𝗱-𝘁𝗼-𝗘𝗻𝗱 𝗔𝗻𝗮𝗹𝘆𝘀𝗶𝘀 𝗼𝗳 𝘁𝗵𝗲 𝗦𝗽𝗮𝗺 𝗩𝗮𝗹𝘂𝗲 𝗖𝗵𝗮𝗶𝗻 by Kirill Levchenko et al. (2011)
https://cseweb.ucsd.edu/~savage/papers/Oakland11.pdf
Renovated DarkwebDaily.Live with a fresher UI. Added a statistics page too. Use the above url or the onion: http://dailydwusclfsu7fzwydc5emidexnesmdlzqmz2dxnx5x4thl42vj4qd.onion/ No JS.
Name one other service where the provider threatens you with prison for refusing to pay.
Finally, an honest warning label about what financial privacy actually threatens.
The White House app ships with a sanctioned Chinese tracking SDK,
the FBI app serves ads,
and FEMA wants 28 permissions to show you weather alerts.
https://www.sambent.com/the-white-house-app-has-huawei-spyware-and-an-ice-tip-line
X but without ID verification, or a subscription.
Download Tor Browser -> Go to Darkwebdaily.live (my link site) -> find Pitch
Make an account, no email or other bs required.
I have a collection of my favorite people on there here: /p/6075dfe2
Europol didn't say "difficult to trace" or "challenging"....
they said can't, and that word choice matters.
Ken Thompson's acceptance speech for the Turing Award on security thinking.
"The moral is obvious. You can't trust code that you did not totally create yourself."
- 𝗖𝗼𝗺𝗽𝘂𝘁𝗲𝗿 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗶𝗻 𝘁𝗵𝗲 𝗥𝗲𝗮𝗹 𝗪𝗼𝗿𝗹𝗱 by Butler Lampson (2004)
https://www.microsoft.com/en-us/research/wp-content/uploads/2004/06/Computer-Security-in-the-Real-World.pdf
#OPSEC365 016/365
The military calls it a Critical Information List. Step one of OPSEC starts with identifying exactly what information, if collected by your adversary, would degrade your ability to operate safely.
Most people skip this step and jump straight to countermeasures they don't actually need.