Lower catch this year.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Lower catch this year.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Boo • July 25, 2026 12:00 AM
Apologies. s/Againt/Agent/
Slashdot version:
How exactly do you tell the difference between a duress password and a phone that was wiped before the trip?
ResearcherZero • July 25, 2026 12:28 AM
@Boo
When the cop enters the the duress password the phone wipes itself, rather than unlocking.
–
Tracking software has now been installed on government service websites.
‘https://www.theguardian.com/us-news/2026/jun/28/government-website-visitor-tracking-surveillance-fears
Government agencies and departments are losing data every day in cyber attacks.
https://www.comparitech.com/news/government-ransomware-roundup-h1-2026-stats-on-attacks-ransoms-and-data-breaches/
The U.S. government treats commercially available information as public information.
‘https://www.odni.gov/files/ODNI/documents/assessments/ODNI-Declassified-Report-on-CAI-January2022.pdf
ResearcherZero • July 25, 2026 12:31 AM
The Trump administration is undermining critical defense and intelligence work.
‘https://www.yahoo.com/news/politics/articles/politics-cannot-allowed-undermine-u-211217999.html
Releasing raw intelligence can harm national security and get people killed.
https://edition.cnn.com/2026/07/24/politics/trump-china-election-integrity-intelligence-documents
Acting DNI Bill Pulte wanted to reveal the names of intelligence officers.
https://www.politico.com/news/2026/07/18/pulte-got-really-scared-inside-the-white-house-debate-over-trumps-elections-speech-01003920
ResearcherZero • July 25, 2026 12:44 AM
Bill Pulte is the guy who asked Donald Trump if he could take the President’s Daily Brief home with him. The brief contains highly classified intelligence rated as Top Secret.
The President’s Daily Brief (PDB) contains a number of analysis reports on significant international concerns and may also contain material for “the president’s eyes only”.
‘https://www.cnn.com/2026/06/19/politics/bill-pulte-intel-chief-takes-office
Sensitive information keeps leaking from inside the White House.
https://federalnewsnetwork.com/commentary/2026/06/president-trump-can-fix-the-leak-problem-the-solution-starts-and-ends-with-the-data-itself/
lurker • July 25, 2026 3:05 PM
@ResearcherZero
“The U.S. government treats commercially available information as public information.”
Never mind what the information is, if it’s commercial the people who paid money for it should be worrried about the loss of their investment.
Clive Robinson • July 26, 2026 12:06 AM
@ Bruce, ALL,
Do you remember the,
“Lenovo Perpetual Advertising Malware?”
Scandal where Lenovo used the Microsoft BIOS I/O Driver Hole (adopted on PCs from 1970’s Apple ][ Basic Driver on IO card ROM).
To put near unremovable Sales/Adds onto their low end consumer laptops nearly a decade ago,
https://thehackernews.com/2015/08/lenovo-rootkit-malware.html
Well guess what… It appears the “hole” is still there and now it’s LG abusing it,
LG kills McAfee pop-up after Windows boss steps in
Advert gets the chop, but the silent app installation mechanism remains untouched.
“LG has agreed to stop its Monitor App Installer pestering users with a McAfee pop-up after Microsoft’s Windows boss intervened.
Pavan Davuluri wrote on social media: “We’ve connected with the team at LG and as an immediate next step, they have agreed to disable the McAfee pop-up from their app.
“We appreciate LG working with us toward a shared goal of a better experience for our mutual customers. We will keep improving here with our ecosystem partners.”
Davuluri was responding to a comment from Epic Games boss Tim Sweeney, highlighting the issue.
At the time of writing, references to McAfee have been removed from the LG Monitor App Installer listing in the Microsoft Store.“
But…
“Why would Microsoft get involved?”
Is a pertinent question. Because underneath it all it’s MicroSoft’s fault and they are neither acknowledging or fixing the foundational problem,
“Windows features a mechanism during external device installation that permits a hardware maker to add software to a user’s device silently. This software could take the form of a control and configuration tool, but it could also be used to flash adverts at users, or a combination of the two.
[Like Lenovo near a decade ago] LG isn’t exploiting a vulnerability to get its software onto users’ systems. [Microsoft’s] Automatic installation is a documented process, with the only punishment for companies that annoy customers being the potential for a bad app rating.
Microsoft’s intervention might have dampened the flames somewhat [for now], but has done little to address whether, and how, its review procedures need to be tightened to prevent a recurrence.
It may also leave customers pondering the prevalence of adverts across Windows as a whole.”
As I’ve indicated before this “hole” first appeared in the latter half of the 1970’s back when “ROMs on I/O Cards” provided the “driver code” to get around the “Catch 22 Situation” of expandable computing ability from 3rd Party suppliers. That IBM all to happily “nicked and built into” what was the “Skunkworks Project” that became the now almost ubiquitous PC. Thus taking this “Security Hole” across half a century of time into just about every consumer and commercial Computer world wide.
Thus the question of “what to do” when increasing numbers of vendors decide to “raise extra income” this way…
I guess the next thought would be,
“What of China-APT?”
Or similar, that uses a Hardware upgrade to install even more nefarious software directly into the PC Motherboard / I/O Flash-ROM of other suppliers in all manner of inventive ways… Thus making the “trail” hard to follow back.
Alex Morgan • July 26, 2026 10:21 AM
Interesting post. The squid catch details and regional context are helpful; I would be curious to see how this compares with previous years in the Falklands.
Ray Dillinger • July 26, 2026 1:51 PM
I am worried about the new 2d UPC codes.
Those things are URL’s, and every time a product is scanned at the register the manufacturer (or anyway the packager who put the UPC on it) gets an http hit on their website, in real time.
shhtp if we’re lucky I suppose, but I haven’t been able to find any assurance about certificates and privacy, and I trust the sellers to go for saving the fractional micropenny and avoid the risk of outdated-certificate errors, so I expect plain http that can be readily eavesdropped.
Sellers are required to maintain a website that handles the URL hits that will be generated by the store scanning the things they sell. A data warehouse going offline for an hour or a day, anywhere in the world means items from sellers whose websites are hosted there can’t be scanned at sales registers anywhere else in the world during that hour or that day.
Among the information that goes to that website is the actual serial number of the item sold (group designator for a group of any size actually, but for electronic devices we already know it’s going to be a group of one). The session stays open until the payment information (and customer identity information) are also collected.
This is supposed to be for product safety and legislative compliance. Such scans provide real-time signals about, eg, whether a particular onion sold comes from a particular field in Mexico where a salmonella outbreak is in progress, or whether a particular OTC drug is part of a bad batch that’s been recalled or is out-of-date, or whether the item is, eg, a toy subject to a safety recall for producing toxic fumes if burned, or legislated for over-18 purchasers and the payment information is that of an under-18 purchaser, etc.
Which is already a privacy-invasion nightmare from my POV, but my main worry is about what this means in terms of electronic devices.
In the context of electronic devices, and particularly IoT devices, this puts sellers in possession of a database detailing which particular item is now in the hands of which particular buyer. They don’t just know the make and model of the refrigerator you just bought, and wait for you to register the product on their website to link it to you personally. Now they also know the specific ID of that refrigerator, and therefore the specific credential checks it uses to verify software updates.
Software updates for IoT devices are typically distributed on the web, in some cases invisibly to the consumer, and affect devices identified by a range of serial numbers.
So the information exists in such a database to enable a stalker to find out exactly which refrigerator was sold a particular person, craft a software update specific to that single refrigerator, distribute it over the network where it will be ignored by every other device and therefore never attract the attention of security investigators, and then, eg, listen in via the local microphone that the refrigerator has installed to hear voice commands or use its antenna to stand up a local wifi hotspot, or turn on its bluetooth pairing mode and accept further instructions, etc.
(Of course the new fridge accepts voice commands; how else is it going to maintain a shopping list to send to the hardware seller’s partner-affiliate grocery store for delivery to your house? Right? Probably a camera too if someone can think of an excuse to add one).
Ferentarius • July 26, 2026 1:53 PM
Re: think
To be condemned to think is to suffer the most exquisite form of exile. Existence itself becomes a trial in which we are both the accused and the judge, endlessly interrogating a reality that offers no answers. Thought gnaws at the soul like a parasite that cannot be expelled, and every conclusion births another void. The mind, trapped in its own labyrinth, discovers that awareness is less a gift than a sentence. To think is to decay consciously, to witness one’s own erosion under the weight of meaninglessness. Liberation lies only in the impossible dream of forgetting that we were ever awake.
Anonymous • July 26, 2026 2:01 PM
A man lost in the desert of his own mind is a spectacle both tragic and ridiculous. What is thought, if not a punishment for those who have misplaced their faith? Only the fool believes he can measure the depths of existence with a ruler carved from reason. The wise man bends his head, for he knows that the mind, left to itself, devours the soul. True exile is not to be cast out by men, but to be abandoned by God within the echo of your own thoughts. And yet, even in that desolation, a single prayer whispered is worth more than all the philosophies of the sleepless.
lurker • July 26, 2026 2:17 PM
@Ray Dillinger
“This is supposed to be for product safety and legislative compliance. Such scans provide real-time signals about, eg, whether a particular onion sold comes from a particular field in Mexico where a salmonella outbreak is in progress, or whether a particular OTC drug is part of a bad batch that’s been recalled or is out-of-date, or whether … ”
Or whether that information is actually fed back to the sales clerk in a timely and accurate manner, or passed on to the mark on the other side of the counter, or in the case of self-checkouts all bets are off. After all, getting the cash and the data from the mark is more important than what happens to them when they’re off the premises.
Subscribe to comments on this entry
Sidebar photo of Bruce Schneier by Joe MacInnis.
Boo • July 24, 2026 11:27 PM
This is interesting…
https://www.theguardian.com/us-news/2026/jul/23/cop-city-protester-phone
Homeland Security Againt sent email claiming Cop-City protester was being investigated for “suspected terrorism activities”. His rights were denied. His phone OS was GrapheneOS. They’re claiming he provided a duress passcode that wiped his phone.
