<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Newsletter from Kushal</title>
    <link>https://news.kushaldas.in/</link>
    <description>Containing random links to read about privacy, security, programming and FOSS in general. Sometimes about life.</description>
    <pubDate>Tue, 07 Apr 2026 15:44:15 +0000</pubDate>
    <item>
      <title>0x19</title>
      <link>https://news.kushaldas.in/0x19?pk_campaign=rss-feed</link>
      <description>&lt;![CDATA[Resuming this after 2 years. A lot of things happened within these 2 days. I never thought much about how much time will it take to settle down in Sweden, but it seems 2 years is not enough :)&#xA;&#xA;For now I want you all to watch this talk from Mike Monteiro, How to fight fascism.&#xA;&#xA;If you want to discuss any of these topics, hop on to the Libera.chat server (IRC), and come to the #learnandteach channel. Or you can find me on fediverse https://toots.dgplug.org/@kushal.]]&gt;</description>
      <content:encoded><![CDATA[<p>Resuming this after 2 years. A lot of things happened within these 2 days. I never thought much about how much time will it take to settle down in Sweden, but it seems 2 years is not enough :)</p>

<p>For now I want you all to watch this talk from <a href="https://www.muledesign.com/">Mike Monteiro</a>, <a href="https://www.youtube.com/watch?v=1Hxs-9kzATU">How to fight fascism</a>.</p>

<p>If you want to discuss any of these topics, hop on to the Libera.chat server (IRC), and come to the <a href="https://news.kushaldas.in/tag:learnandteach" class="hashtag"><span>#</span><span class="p-category">learnandteach</span></a> channel. Or you can find me on fediverse <a href="https://toots.dgplug.org/@kushal">https://toots.dgplug.org/@kushal</a>.</p>
]]></content:encoded>
      <guid>https://news.kushaldas.in/0x19</guid>
      <pubDate>Mon, 15 Jan 2024 19:30:51 +0000</pubDate>
    </item>
    <item>
      <title>0x18</title>
      <link>https://news.kushaldas.in/0x18?pk_campaign=rss-feed</link>
      <description>&lt;![CDATA[Too many times, I was asked why I don&#39;t invest in various crypto coins. Back in the days when we used to have conferences in real life, random strangers often came to me. They told me to use blockchain which will solve all of the security problems in the application (just imagine any application). When I started asking for a patch with full implementation, that trouble went away fast.&#xA;&#xA;Now, a 2 hours long video has all the explanations as required. Watch it with your family, share it with your friends.&#xA;&#xA;Links for the week&#xA;&#xA;System transparency at Mullvad&#xA;How secure are journalists&#39; favorite transcription tools?&#xA;Enforcing the pyramid of open source&#xA;Ola Bini&#39;s trial resumed&#xA;End-to-end encryption protects children&#xA;Mudge &amp; Rinki Sethi are leaving Twitter&#xA;Podcast with ippsec&#xA;Israeli police used Pegasus against officials and family members&#xA;EU wants own DNS service&#xA; Jonathan Leitschuh is the inaugural Dan Kaminsky Fellow&#xA;Tutanota on Google analytics&#xA;Unsafe anywhere: women human rights defenders speak out about Pegasus attacks&#xA;&#xA;Video for the week&#xA;&#xA;Watch Brian Kernighan talking about The early days of Unix at Bell Labs.&#xA;&#xA;If you want to discuss any of these topics, hop on to the Libera.chat server (IRC), and come to the #learnandteach channel. Or you can find me on fediverse https://toots.dgplug.org/@kushal.&#xA;&#xA;Kushal]]&gt;</description>
      <content:encoded><![CDATA[<p>Too many times, I was asked why I don&#39;t invest in various crypto coins. Back in the days when we used to have conferences in real life, random strangers often came to me. They told me to use <strong>blockchain</strong> which will solve all of the security problems in the application (just imagine any application). When I started asking for a patch with full implementation, that trouble went away fast.</p>

<p>Now, a <a href="https://www.youtube.com/watch?v=YQ_xWvX1n9g">2 hours long video</a> has all the explanations as required. Watch it with your family, share it with your friends.</p>

<h2 id="links-for-the-week" id="links-for-the-week">Links for the week</h2>
<ul><li><a href="https://mullvad.net/en/blog/2022/1/12/diskless-infrastructure-beta-system-transparency-stboot/">System transparency at Mullvad</a></li>
<li><a href="https://freedom.press/training/blog/how-secure-are-journalists-favorite-transcription-tools/">How secure are journalists&#39; favorite transcription tools?</a></li>
<li><a href="https://daniel.haxx.se/blog/2022/01/17/enforcing-the-pyramid-of-open-source/">Enforcing the pyramid of open source</a></li>
<li><a href="https://www.eff.org/deeplinks/2021/10/after-years-delays-and-alarmingly-flimsy-evidence-security-expert-ola-binis-trial">Ola Bini&#39;s trial resumed</a></li>
<li><a href="https://www.theguardian.com/technology/2022/jan/21/end-to-end-encryption-protects-children-says-uk-information-watchdog">End-to-end encryption protects children</a></li>
<li><a href="https://www.nytimes.com/2022/01/21/technology/twitter-security-team.html">Mudge &amp; Rinki Sethi are leaving Twitter</a></li>
<li><a href="https://thehackerfactory.simplecast.com/episodes/from-esports-to-ethical-hacker-a-conversation-with-ippsec-the-hacker-factory-with-phillip-wylie-PmqUAZh_">Podcast with ippsec</a></li>
<li><a href="https://twitter.com/jsrailton/status/1485133555860742145?s=20">Israeli police used Pegasus against officials and family members</a></li>
<li><a href="https://therecord.media/eu-wants-to-build-its-own-dns-infrastructure-with-built-in-filtering-capabilities/">EU wants own DNS service</a></li>
<li><a href="https://www.humansecurity.com/blog/our-first-dan-kaminsky-fellow"> Jonathan Leitschuh is the inaugural Dan Kaminsky Fellow</a></li>
<li><a href="https://tutanota.com/blog/posts/google-analytics/">Tutanota on Google analytics</a></li>
<li><a href="https://www.frontlinedefenders.org/sites/default/files/unsafe-anywhere_-women-human-rights-defenders-speak-out-about-pegasus-attacks_en.pdf">Unsafe anywhere: women human rights defenders speak out about Pegasus attacks</a></li></ul>

<h2 id="video-for-the-week" id="video-for-the-week">Video for the week</h2>

<p>Watch Brian Kernighan talking about <a href="https://www.youtube.com/watch?v=ECCr_KFl41E">The early days of Unix at Bell Labs</a>.</p>

<p>If you want to discuss any of these topics, hop on to the Libera.chat server (IRC), and come to the <a href="https://news.kushaldas.in/tag:learnandteach" class="hashtag"><span>#</span><span class="p-category">learnandteach</span></a> channel. Or you can find me on fediverse <a href="https://toots.dgplug.org/@kushal">https://toots.dgplug.org/@kushal</a>.</p>

<p>Kushal</p>
]]></content:encoded>
      <guid>https://news.kushaldas.in/0x18</guid>
      <pubDate>Sun, 23 Jan 2022 07:14:44 +0000</pubDate>
    </item>
    <item>
      <title>0x17</title>
      <link>https://news.kushaldas.in/0x17?pk_campaign=rss-feed</link>
      <description>&lt;![CDATA[Ukraine Govt websites were attacked couple of days. More than anything else, this is direct way to create pressure on Government . The more our lives are entangled with the Internet, the bigger the chances of getting effected in the thinking process. All the different social media sites, and the algorithms they use to show content to us, are very good example of such attacks to our personal space.&#xA;&#xA;Staying in the same topic, The Wire released the 3rd part of their Tek Fog story.&#xA;&#xA;Links to read&#xA;&#xA;Destructive malware targeting Ukrainian organizations &#xA;Mandiant whitepaper on &#34;Proactive Preparation and Hardening to Protect Against Destructive Attacks&#34;&#xA;In Russia, FSB arrested REvil team&#xA;Launching Python, Virtual Environments, and Locking Dependencies With Brett Cannon RealPython podcast&#xA;Chrome will limit access to private network&#xA;Extensive Hacking of Media &amp; Civil Society in El Salvador with Pegasus Spyware&#xA;Rust 1.58.0 released&#xA;Anaconda is getting a new suit&#xA;&#xA;Btw, my workshop in PyCon Sweden 2021 on Writing Python modules using Rust is available on Youtube.&#xA;&#xA;If you want to discuss any of these topics, hop on to the Libera.chat server (IRC), and come to the #learnandteach channel. Or you can find me on fediverse https://toots.dgplug.org/@kushal.&#xA;&#xA;Kushal&#xA;&#xA; ]]&gt;</description>
      <content:encoded><![CDATA[<p>Ukraine Govt websites <a href="https://www.aljazeera.com/news/2022/1/14/be-afraid-cyberattack-in-ukraine-targets-government-websites">were attacked</a> couple of days. More than anything else, this is direct way to create pressure on Government . The more our lives are entangled with the Internet, the bigger the chances of getting effected in the thinking process. All the different social media sites, and the algorithms they use to show content to us, are very good example of such attacks to our personal space.</p>

<p>Staying in the same topic, The Wire released the <a href="https://thewire.in/tekfog/en/3.html">3rd part</a> of their Tek Fog story.</p>

<h2 id="links-to-read" id="links-to-read">Links to read</h2>
<ul><li><a href="https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/">Destructive malware targeting Ukrainian organizations </a></li>
<li><a href="https://www.mandiant.com/resources/protect-against-destructive-attacks">Mandiant whitepaper on “Proactive Preparation and Hardening to Protect Against Destructive Attacks”</a></li>
<li>In Russia, <a href="https://twitter.com/maryilyushina/status/1481980035535888384">FSB arrested REvil team</a></li>
<li><a href="https://realpython.com/podcasts/rpp/93/">Launching Python, Virtual Environments, and Locking Dependencies With Brett Cannon</a> RealPython podcast</li>
<li><a href="https://therecord.media/chrome-will-limit-access-to-private-networks-citing-security-reasons/">Chrome will limit access to private network</a></li>
<li><a href="https://citizenlab.ca/2022/01/project-torogoz-extensive-hacking-media-civil-society-el-salvador-pegasus-spyware/">Extensive Hacking of Media &amp; Civil Society in El Salvador with Pegasus Spyware</a></li>
<li><a href="https://blog.rust-lang.org/2022/01/13/Rust-1.58.0.html">Rust 1.58.0 released</a></li>
<li><a href="https://communityblog.fedoraproject.org/anaconda-is-getting-a-new-suit/">Anaconda is getting a new suit</a></li></ul>

<p>Btw, my workshop in PyCon Sweden 2021 on <a href="https://www.youtube.com/watch?v=BgzIaEzXEBU">Writing Python modules using Rust</a> is available on Youtube.</p>

<p>If you want to discuss any of these topics, hop on to the Libera.chat server (IRC), and come to the <a href="https://news.kushaldas.in/tag:learnandteach" class="hashtag"><span>#</span><span class="p-category">learnandteach</span></a> channel. Or you can find me on fediverse <a href="https://toots.dgplug.org/@kushal">https://toots.dgplug.org/@kushal</a>.</p>

<p>Kushal</p>
]]></content:encoded>
      <guid>https://news.kushaldas.in/0x17</guid>
      <pubDate>Sun, 16 Jan 2022 07:57:25 +0000</pubDate>
    </item>
    <item>
      <title>0x16</title>
      <link>https://news.kushaldas.in/0x16?pk_campaign=rss-feed</link>
      <description>&lt;![CDATA[Resuming this newsletter after 10 months. In between, we had the second wave of COVID in India, the whole family was down with it. And then we managed to move to Sweden. Still settling down.&#xA;&#xA;I kept taking the notes in between for the newsletter but did not send it out. I guess I am in a state now to resume it again.&#xA;&#xA;As a primary story, I would love if you all could take a few minutes and read this story from The Wire and learn how technology (especially big IT companies) is helping the current political party in power to &#xA;&#xA;  artificially inflate the popularity of the party, harass its critics and manipulate public perceptions at scale across major social media platforms.&#xA;&#xA;Part 2 of the story is also out. Please share the links with our friends and family. Most people around the world will never believe that these applications exist, and they can actually affect the mass.&#xA;&#xA;Links to read&#xA;&#xA;Don&#39;t mix URL parsers&#xA;Moxie stepping down from CEO post of Signal&#xA;T-mobile blocking iCloud private relay feature&#xA;AMD made graphics card which is bad for mining&#xA;Tumpa for macOS is released&#xA;Story of Ipinfo&#xA;&#xA;If you want to discuss any of these topics, hop on to the Libera.chat server (IRC), and come to the #learnandteach channel. Or you can find me on fediverse https://toots.dgplug.org/@kushal.&#xA;&#xA;Kushal]]&gt;</description>
      <content:encoded><![CDATA[<p>Resuming this newsletter after 10 months. In between, we had the second wave of COVID in India, the whole family was down with it. And then we managed to move to Sweden. Still settling down.</p>

<p>I kept taking the notes in between for the newsletter but did not send it out. I guess I am in a state now to resume it again.</p>

<p>As a primary story, I would love if you all could take a few minutes and read <a href="https://thewire.in/tekfog/en/1.html">this story</a> from <a href="https://thewire.in">The Wire</a> and learn how technology (especially big IT companies) is helping the current political party in power to</p>

<blockquote><p> artificially inflate the popularity of the party, harass its critics and manipulate public perceptions at scale across major social media platforms.</p></blockquote>

<p><a href="https://thewire.in/tekfog/en/2.html">Part 2 of the story</a> is also out. Please share the links with our friends and family. Most people around the world will never believe that these applications exist, and they can actually affect the mass.</p>

<h2 id="links-to-read" id="links-to-read">Links to read</h2>
<ul><li><a href="https://daniel.haxx.se/blog/2022/01/10/dont-mix-url-parsers/">Don&#39;t mix URL parsers</a></li>
<li><a href="https://signal.org/blog/new-year-new-ceo/">Moxie stepping down from CEO post of Signal</a></li>
<li><a href="https://9to5mac.com/2022/01/10/t-mobile-block-icloud-private-relay/">T-mobile blocking iCloud private relay feature</a></li>
<li><a href="https://arstechnica.com/gadgets/2022/01/amd-says-rx-6500-xt-is-optimized-to-be-good-for-gaming-and-bad-for-mining/">AMD made graphics card which is bad for mining</a></li>
<li><a href="https://kushaldas.in/posts/releasing-tumpa-for-mac.html">Tumpa for macOS is released</a></li>
<li><a href="https://tech.marksblogg.com/where-are-ip-addresses-ipinfo.html">Story of Ipinfo</a></li></ul>

<p>If you want to discuss any of these topics, hop on to the Libera.chat server (IRC), and come to the <a href="https://news.kushaldas.in/tag:learnandteach" class="hashtag"><span>#</span><span class="p-category">learnandteach</span></a> channel. Or you can find me on fediverse <a href="https://toots.dgplug.org/@kushal">https://toots.dgplug.org/@kushal</a>.</p>

<p>Kushal</p>
]]></content:encoded>
      <guid>https://news.kushaldas.in/0x16</guid>
      <pubDate>Tue, 11 Jan 2022 05:41:00 +0000</pubDate>
    </item>
    <item>
      <title>0x15</title>
      <link>https://news.kushaldas.in/0x15?pk_campaign=rss-feed</link>
      <description>&lt;![CDATA[Instead of writing the newsletter, I spent the last few hours figuring how to get back my primary domain.&#xA;The register system did not auto-renew, and I had a few hours of panic to get it back. Finally, it seems things are working once again.&#xA;&#xA;Links to read&#xA;&#xA;Chinese group has broken into too many Microsoft Exchange servers&#xA;A news on iOS security&#xA;German prison intern posted master keys photos online&#xA;German officials want emails to be linked with real world IDs&#xA;Myanmar&#39;s Military using digital tools for crackdown&#xA;Tracking pixels on emails&#xA;Android VPN service breached&#xA;Far right social media platform Gab was breached&#xA;&#xA;Must read guide for iOS users&#xA;&#xA;Device and Data Access when Personal Safety is At Risk is a special guide from Apple. It contains many useful tips which you can regularly use too.&#xA;&#xA;If you want to discuss any of these topics, hop on to the Freenode server (IRC), and come to the #learnandteach channel. Or you can find me on fediverse https://toots.dgplug.org/@kushal.&#xA;&#xA;Kushal&#xA;&#xA;]]&gt;</description>
      <content:encoded><![CDATA[<p>Instead of writing the newsletter, I spent the last few hours figuring how to get back my primary domain.
The register system did not auto-renew, and I had a few hours of panic to get it back. Finally, it seems things are working once again.</p>

<h2 id="links-to-read" id="links-to-read">Links to read</h2>
<ul><li><a href="https://www.wired.com/story/china-microsoft-exchange-server-hack-victims/">Chinese group has broken into too many Microsoft Exchange servers</a></li>
<li><a href="https://www.technologyreview.com/2021/03/01/1020089/apple-walled-garden-hackers-protected/">A news on iOS security</a></li>
<li><a href="https://www.thelocal.de/20210305/intern-at-german-prison-faces-hefty-bill-after-sending-photo-of-master-key-to-friends/">German prison intern posted master keys photos online</a></li>
<li><a href="https://apnews.com/article/germany-email-instant-message-real-identity-3baabc1a3052850a9f63432ec38fcf15">German officials want emails to be linked with real world IDs</a></li>
<li><a href="https://www.nytimes.com/2021/03/01/world/asia/myanmar-coup-military-surveillance.html">Myanmar&#39;s Military using digital tools for crackdown</a></li>
<li><a href="https://www.bbc.com/news/technology-56071437">Tracking pixels on emails</a></li>
<li><a href="https://cybernews.com/security/one-of-the-biggest-android-vpns-hacked-data-of-21-million-users-from-3-android-vpns-put-for-sale-online/">Android VPN service breached</a></li>
<li><a href="https://www.wired.com/story/gab-hack-data-breach-ddosecrets/">Far right social media platform Gab was breached</a></li></ul>

<h2 id="must-read-guide-for-ios-users" id="must-read-guide-for-ios-users">Must read guide for iOS users</h2>

<p><a href="https://manuals.info.apple.com/MANUALS/1000/MA1976/en_US/device-and-data-access-when-personal-safety-is-at-risk.pdf">Device and Data Access when Personal Safety is At Risk</a> is a special guide from Apple. It contains many useful tips which you can regularly use too.</p>

<p>If you want to discuss any of these topics, hop on to the Freenode server (IRC), and come to the <a href="https://news.kushaldas.in/tag:learnandteach" class="hashtag"><span>#</span><span class="p-category">learnandteach</span></a> channel. Or you can find me on fediverse <a href="https://toots.dgplug.org/@kushal">https://toots.dgplug.org/@kushal</a>.</p>

<p>Kushal</p>
]]></content:encoded>
      <guid>https://news.kushaldas.in/0x15</guid>
      <pubDate>Sun, 07 Mar 2021 13:03:19 +0000</pubDate>
    </item>
    <item>
      <title>0x14</title>
      <link>https://news.kushaldas.in/0x14?pk_campaign=rss-feed</link>
      <description>&lt;![CDATA[In the last week&#39;s newsletter, I mentioned the book This Is How They  Tell Me the World Ends: The Cyberweapons Arms Race. I hope a few of you already started reading it. This week we have new information about one of the major stories from the book. Apparently, the Chinese teams managed to get the same exploits from Equation Group 3 years earlier (2013) before the Shadow Broker leak. They were happily using the offensive tools against the USA, where the original exploits were found by the US folks only. This story warns us once again about why we should make responsible disclosures. All of the computer exploits can be used against the creator. You can read the wired story with details, or the Checkpoint report for technical details on how did they identify the exploits.&#xA;&#xA;Links for the week&#xA;&#xA;Unauthorized RCE in VMware vCenter patch your systems regularly&#xA;Vietnamese Human Rights attacked&#xA;Changes in Indian rules for online content, you can also read Access Now story on the same.&#xA;The Saudi Kill Team identified you can also read related backstory from Citizenlab.&#xA;Quickbooks malware&#xA;A rooster was held in Indian police station&#xA;Auth-Bypass in Cisco&#xA;NurseryCam breach&#xA;Matrix/Element exploit&#xA;&#xA;Special read&#xA;&#xA;A story on Gabriel Weinberg and Duckduckgo&#xA;&#xA;Podcast for the week&#xA;&#xA;You should listen to Michael Foord talking to Brian from Test &amp; Code on testing, TDD, and many things more.&#xA;&#xA;If you want to discuss any of these topics, hop on to the Freenode server (IRC), and come to the #learnandteach channel. Or you can find me on fediverse https://toots.dgplug.org/@kushal.&#xA;&#xA;Kushal]]&gt;</description>
      <content:encoded><![CDATA[<p>In the last week&#39;s newsletter, I mentioned the book <code>This Is How They  Tell Me the World Ends: The Cyberweapons Arms Race</code>. I hope a few of you already started reading it. This week we have new information about one of the major stories from the book. Apparently, the Chinese teams managed to get the same exploits from <code>Equation Group</code> 3 years earlier (<code>2013</code>) before the Shadow Broker leak. They were happily using the offensive tools against the USA, where the original exploits were found by the US folks only. This story warns us once again about why we should make responsible disclosures. All of the computer exploits can be used against the creator. You can read the <a href="https://www.wired.com/story/china-nsa-hacking-tool-epme-hijack/">wired</a> story with details, or the <a href="https://research.checkpoint.com/2021/the-story-of-jian/">Checkpoint report</a> for technical details on how did they identify the exploits.</p>

<h2 id="links-for-the-week" id="links-for-the-week">Links for the week</h2>
<ul><li><a href="https://swarm.ptsecurity.com/unauth-rce-vmware/">Unauthorized RCE in VMware vCenter</a> patch your systems regularly</li>
<li><a href="https://www.amnesty.org/en/latest/research/2021/02/click-and-bait-vietnamese-human-rights-defenders-targeted-with-spyware-attacks/">Vietnamese Human Rights attacked</a></li>
<li><a href="https://internetfreedom.in/intermediaries-rules-2021/">Changes in Indian rules for online content</a>, you can also read <a href="https://www.accessnow.org/indian-authorities-tighten-control-over-online-content/">Access Now story</a> on the same.</li>
<li><a href="https://www.nytimes.com/2021/02/26/us/politics/saudi-kill-team-khashoggi.html">The Saudi Kill Team identified</a> you can also read related <a href="https://citizenlab.ca/2018/10/the-kingdom-came-to-canada-how-saudi-linked-digital-espionage-reached-canadian-soil/">backstory</a> from Citizenlab.</li>
<li><a href="https://threatpost.com/tax-quickbooks-data-theft/164253/">Quickbooks malware</a></li>
<li><a href="https://www.aljazeera.com/news/2021/2/28/indian-rooster-kills-owner-during-cockfight">A rooster was held in Indian police station</a></li>
<li><a href="https://threatpost.com/cisco-critical-security-flaw/164255/">Auth-Bypass in Cisco</a></li>
<li><a href="https://www.bbc.com/news/technology-56141093">NurseryCam breach</a></li>
<li><a href="https://twitter.com/GrapheneOS/status/1365881076229488641">Matrix/Element exploit</a></li></ul>

<h2 id="special-read" id="special-read">Special read</h2>

<p><a href="https://www.phillymag.com/news/2021/02/20/duckduckgo-data-privacy-paoli/">A story on Gabriel Weinberg and Duckduckgo</a></p>

<h2 id="podcast-for-the-week" id="podcast-for-the-week">Podcast for the week</h2>

<p>You should listen to Michael Foord talking to Brian from <a href="https://testandcode.com/145">Test &amp; Code</a> on <code>testing, TDD, and many things more</code>.</p>

<p>If you want to discuss any of these topics, hop on to the Freenode server (IRC), and come to the <a href="https://news.kushaldas.in/tag:learnandteach" class="hashtag"><span>#</span><span class="p-category">learnandteach</span></a> channel. Or you can find me on fediverse <a href="https://toots.dgplug.org/@kushal">https://toots.dgplug.org/@kushal</a>.</p>

<p>Kushal</p>
]]></content:encoded>
      <guid>https://news.kushaldas.in/0x14</guid>
      <pubDate>Mon, 01 Mar 2021 04:36:36 +0000</pubDate>
    </item>
    <item>
      <title>0x13</title>
      <link>https://news.kushaldas.in/0x13?pk_campaign=rss-feed</link>
      <description>&lt;![CDATA[At the end of September and the beginning of October, Telegram fixed a couple of vulnerabilities on its client applications. The actual flaws could enable any serious attacker to gain access to secret chats, photos or videos by just sending animated stickers. You can read the detailed story.&#xA;&#xA;Another very exciting news came in the Python world, with the acceptance of PEP 634, aka &#34;Pattern Matching&#34;. Read the tutorial from Guido to see how it will look like. I love pattern matching in Rust, and now in the future, I will use the same in Python.&#xA;&#xA;Links for the week&#xA;&#xA;An example of why building software is political and can decide who will die and who will live Must read.&#xA;Linux powered helicopter on Mars&#xA;Russia&#39;s Sandworm team attacking French systems CentOS, Exim, and direct attacks.&#xA;Firefox 85 and supercookies&#xA;Blog post from Matrix explained how they handled FOSDEM21&#xA;Possible malware attacks via ShareIT android app&#xA;Yandex employee sold access to customer data&#xA;Power outage took out Internet in many states in Mexico&#xA;&#xA;Must read book for the week&#xA;&#xA;This Is How They Tell Me the World Ends: The Cyberweapons Arms Race by Nicole Perlroth. You can read an excerpt from the book here.&#xA;&#xA;If you want to discuss any of these topics, hop on to the Freenode server (IRC), and come to the #learnandteach channel. Or you can find me on fediverse https://toots.dgplug.org/@kushal.&#xA;&#xA;Kushal]]&gt;</description>
      <content:encoded><![CDATA[<p>At the end of September and the beginning of October, Telegram fixed a couple of vulnerabilities on its client applications. The actual flaws could enable any serious attacker to gain access to secret chats, photos or videos by just sending animated stickers. You can read the <a href="https://thehackernews.com/2021/02/a-sticker-sent-on-telegram-could-have.html">detailed story</a>.</p>

<p>Another very exciting news came in the Python world, with the acceptance of PEP 634, aka “Pattern Matching”. Read the <a href="https://github.com/gvanrossum/patma/blob/master/README.md#tutorial">tutorial</a> from Guido to see how it will look like. I love pattern matching in Rust, and now in the future, I will use the same in Python.</p>

<h2 id="links-for-the-week" id="links-for-the-week">Links for the week</h2>
<ul><li><a href="https://www.protocol.com/china/i-built-bytedance-censorship-machine">An example of why building software is political and can decide who will die and who will live</a> Must read.</li>
<li><a href="https://spectrum.ieee.org/automaton/aerospace/robotic-exploration/nasa-designed-perseverance-helicopter-rover-fly-autonomously-mars">Linux powered helicopter on Mars</a></li>
<li><a href="https://www.wired.com/story/sandworm-centreon-russia-hack/">Russia&#39;s Sandworm team attacking French systems</a> CentOS, Exim, and direct attacks.</li>
<li><a href="https://medium.com/zu-development/the-supercookie-d5124133cd41">Firefox 85 and supercookies</a></li>
<li><a href="https://matrix.org/blog/2021/02/15/how-we-hosted-fosdem-2021-on-matrix">Blog post from Matrix explained how they handled FOSDEM21</a></li>
<li><a href="https://thehackernews.com/2021/02/unpatched-shareit-android-app-flaw.html">Possible malware attacks via ShareIT android app</a></li>
<li><a href="https://www.zdnet.com/article/yandex-said-it-caught-an-employee-selling-access-to-users-inboxes/">Yandex employee sold access to customer data</a></li>
<li><a href="https://twitter.com/netblocks/status/1361519617815048192">Power outage took out Internet in many states in Mexico</a></li></ul>

<h2 id="must-read-book-for-the-week" id="must-read-book-for-the-week">Must read book for the week</h2>

<p><a href="https://www.amazon.com/This-They-Tell-World-Ends/dp/1635576059">This Is How They Tell Me the World Ends: The Cyberweapons Arms Race</a> by <a href="https://twitter.com/nicoleperlroth">Nicole Perlroth</a>. You can read an excerpt from the book <a href="https://www.wired.com/story/untold-history-americas-zero-day-market/">here</a>.</p>

<p>If you want to discuss any of these topics, hop on to the Freenode server (IRC), and come to the <a href="https://news.kushaldas.in/tag:learnandteach" class="hashtag"><span>#</span><span class="p-category">learnandteach</span></a> channel. Or you can find me on fediverse <a href="https://toots.dgplug.org/@kushal">https://toots.dgplug.org/@kushal</a>.</p>

<p>Kushal</p>
]]></content:encoded>
      <guid>https://news.kushaldas.in/0x13</guid>
      <pubDate>Sun, 21 Feb 2021 04:53:03 +0000</pubDate>
    </item>
    <item>
      <title>0x12</title>
      <link>https://news.kushaldas.in/0x12?pk_campaign=rss-feed</link>
      <description>&lt;![CDATA[This week I will just pass on the links I think you all should read.&#xA;Hopefully this will help me to break out of the no newsletter state of mind. Last few months, I kept taking notes, but never managed to sit down and write this.&#xA;&#xA;Must read&#xA;&#xA;https://thewire.in/tech/rona-wilson-elgar-parishad-letters-planted-us-firm talks about how letters were planted on laptop to arrest the activists&#xA;&#xA;Links for the week&#xA;&#xA;https://cyber.fsi.stanford.edu/io/news/clubhouse-china data privacy issues in Clubhouse&#xA;https://www.bleepingcomputer.com/news/security/yandex-suffers-data-breach-after-sysadmin-sold-access-to-user-emails/ &#xA;https://news.hitb.org/content/breached-water-plant-employees-used-same-teamviewer-password-and-no-firewall real life issue of reusing the same password&#xA;https://www.bbc.com/news/technology-55977537 hidden spyware in apps from Iran&#xA;&#xA;Video for the week&#xA;&#xA;https://www.youtube.com/watch?v=I6ShaTlyzZQ This video is different, it is in Hindi language, with English subtitles. It is for the generation of folks who grew up with Internet. Please watch till the end. And if you don&#39;t know the person, then search about him after you watched the video.&#xA;&#xA;Book for the week&#xA;&#xA;We Are Bellingcat.&#xA;&#xA;  Bellingcat is an independent international collective of researchers, investigators and citizen journalists using open source and social media investigation to probe a variety of subjects &#xA;&#xA;I hope you will enjoy the book.&#xA;&#xA;If you want to discuss any of these topics, hop on to the Freenode server (IRC), and come to the #learnandteach channel. Or you can find me on fediverse https://toots.dgplug.org/@kushal.&#xA;&#xA;Kushal]]&gt;</description>
      <content:encoded><![CDATA[<p>This week I will just pass on the links I think you all should read.
Hopefully this will help me to break out of the <code>no newsletter</code> state of mind. Last few months, I kept taking notes, but never managed to sit down and write this.</p>

<h2 id="must-read" id="must-read">Must read</h2>
<ul><li><a href="https://thewire.in/tech/rona-wilson-elgar-parishad-letters-planted-us-firm">https://thewire.in/tech/rona-wilson-elgar-parishad-letters-planted-us-firm</a> talks about how letters were planted on laptop to arrest the activists</li></ul>

<h2 id="links-for-the-week" id="links-for-the-week">Links for the week</h2>
<ul><li><a href="https://cyber.fsi.stanford.edu/io/news/clubhouse-china">https://cyber.fsi.stanford.edu/io/news/clubhouse-china</a> data privacy issues in Clubhouse</li>
<li><a href="https://www.bleepingcomputer.com/news/security/yandex-suffers-data-breach-after-sysadmin-sold-access-to-user-emails/">https://www.bleepingcomputer.com/news/security/yandex-suffers-data-breach-after-sysadmin-sold-access-to-user-emails/</a></li>
<li><a href="https://news.hitb.org/content/breached-water-plant-employees-used-same-teamviewer-password-and-no-firewall">https://news.hitb.org/content/breached-water-plant-employees-used-same-teamviewer-password-and-no-firewall</a> real life issue of reusing the same password</li>
<li><a href="https://www.bbc.com/news/technology-55977537">https://www.bbc.com/news/technology-55977537</a> hidden spyware in apps from Iran</li></ul>

<h2 id="video-for-the-week" id="video-for-the-week">Video for the week</h2>

<p><iframe allow="monetization" class="embedly-embed" src="//cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FI6ShaTlyzZQ%3Ffeature%3Doembed&display_name=YouTube&url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DI6ShaTlyzZQ&image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FI6ShaTlyzZQ%2Fhqdefault.jpg&key=d932fa08bf1f47efbbe54cb3d746839f&type=text%2Fhtml&schema=youtube" width="640" height="360" scrolling="no" title="YouTube embed" frameborder="0" allow="autoplay; fullscreen" allowfullscreen="true"></iframe> This video is different, it is in Hindi language, with English subtitles. It is for the generation of folks who grew up with Internet. Please watch till the end. And if you don&#39;t know the person, then search about him after you watched the video.</p>

<h2 id="book-for-the-week" id="book-for-the-week">Book for the week</h2>

<p><a href="https://www.bellingcat.com/book/">We Are Bellingcat</a>.</p>

<blockquote><p>Bellingcat is an independent international collective of researchers, investigators and citizen journalists using open source and social media investigation to probe a variety of subjects</p></blockquote>

<p>I hope you will enjoy the book.</p>

<p>If you want to discuss any of these topics, hop on to the Freenode server (IRC), and come to the <a href="https://news.kushaldas.in/tag:learnandteach" class="hashtag"><span>#</span><span class="p-category">learnandteach</span></a> channel. Or you can find me on fediverse <a href="https://toots.dgplug.org/@kushal">https://toots.dgplug.org/@kushal</a>.</p>

<p>Kushal</p>
]]></content:encoded>
      <guid>https://news.kushaldas.in/0x12</guid>
      <pubDate>Sun, 14 Feb 2021 05:37:11 +0000</pubDate>
    </item>
    <item>
      <title>0x11</title>
      <link>https://news.kushaldas.in/0x11?pk_campaign=rss-feed</link>
      <description>&lt;![CDATA[For the last few months, there were no letters from me. My wife, Anwesha is showing COVID symptoms, and the tests came negative. But, her trouble is still continuing for around 3 months now. So, I tried to focus on minimal things.&#xA;&#xA;As I am trying to get back into a routine, I will most probably write much shorter notes here. &#xA;&#xA;On the major news, a 6600 words memo from former Facebook data engineer, Sophie Zhang is giving us how Facebook ignored fake accounts. These accounts mostly represented governments across the world and cause misinterpretation and changed political stories in elections around the world.&#xA;&#xA;Must read&#xA;&#xA;A story on the recent lawsuite against The Internet Archive.&#xA;&#xA;Links for the week&#xA;&#xA;https://www.cyberscoop.com/nsa-cellphone-location-data-guidance/ NSA advice on cellphone location data&#xA;https://www.bbc.com/news/world-us-canada-54110457 Hackers targeting US election&#xA;https://www.teiss.co.uk/marriott-ba-easyjet-security-vulnerabilities/ &#xA;https://www.cyberscoop.com/chinese-hackers-vatican-christians-church/ Chinese hackers targeting the Vatican&#xA;https://www.zdnet.com/article/zerologon-attack-lets-hackers-take-over-enterprise-networks/ Zerologon attack on Windows servers&#xA;&#xA;Service to try this week&#xA;&#xA;If you have a Twitter account and want to delete old tweets/dms, you must try Semiphemeral from Micah F Lee.&#xA;&#xA;Book for this week&#xA;&#xA;Working in Public: The Making and Maintenance of Open Source Software by Nadia Eghbal&#xA;&#xA;If you want to discuss any of these topics, hop on to the Freenode server (IRC), and come to the #learnandteach channel. Or you can find me on fediverse https://toots.dgplug.org/@kushal.&#xA;&#xA;Kushal]]&gt;</description>
      <content:encoded><![CDATA[<p>For the last few months, there were no letters from me. My wife, <a href="https://anweshadas.in">Anwesha</a> is showing COVID symptoms, and the tests came negative. But, her trouble is still continuing for around 3 months now. So, I tried to focus on minimal things.</p>

<p>As I am trying to get back into a routine, I will most probably write much shorter notes here.</p>

<p>On the major news, <a href="https://www.buzzfeednews.com/article/craigsilverman/facebook-ignore-political-manipulation-whistleblower-memo">a 6600 words memo</a> from former Facebook data engineer, Sophie Zhang is giving us how Facebook ignored fake accounts. These accounts mostly represented governments across the world and cause misinterpretation and changed political stories in elections around the world.</p>

<h2 id="must-read" id="must-read">Must read</h2>

<p><a href="https://www.thenation.com/article/society/publishers-are-taking-the-internet-to-court/">A story</a> on the recent lawsuite against <a href="https://archive.org/index.php">The Internet Archive</a>.</p>

<h2 id="links-for-the-week" id="links-for-the-week">Links for the week</h2>
<ul><li><a href="https://www.cyberscoop.com/nsa-cellphone-location-data-guidance/">https://www.cyberscoop.com/nsa-cellphone-location-data-guidance/</a> NSA advice on cellphone location data</li>
<li><a href="https://www.bbc.com/news/world-us-canada-54110457">https://www.bbc.com/news/world-us-canada-54110457</a> Hackers targeting US election</li>
<li><a href="https://www.teiss.co.uk/marriott-ba-easyjet-security-vulnerabilities/">https://www.teiss.co.uk/marriott-ba-easyjet-security-vulnerabilities/</a></li>
<li><a href="https://www.cyberscoop.com/chinese-hackers-vatican-christians-church/">https://www.cyberscoop.com/chinese-hackers-vatican-christians-church/</a> Chinese hackers targeting the Vatican</li>
<li><a href="https://www.zdnet.com/article/zerologon-attack-lets-hackers-take-over-enterprise-networks/">https://www.zdnet.com/article/zerologon-attack-lets-hackers-take-over-enterprise-networks/</a> Zerologon attack on Windows servers</li></ul>

<h2 id="service-to-try-this-week" id="service-to-try-this-week">Service to try this week</h2>

<p>If you have a Twitter account and want to delete old tweets/dms, you must try <a href="https://micahflee.com/2020/09/semiphemeral-automate-deleting-your-old-tweets-likes-and-direct-messages">Semiphemeral</a> from Micah F Lee.</p>

<h2 id="book-for-this-week" id="book-for-this-week">Book for this week</h2>
<ul><li><a href="https://www.amazon.com/dp/0578675862/">Working in Public: The Making and Maintenance of Open Source Software</a> by <a href="https://twitter.com/nayafia">Nadia Eghbal</a></li></ul>

<p>If you want to discuss any of these topics, hop on to the Freenode server (IRC), and come to the <a href="https://news.kushaldas.in/tag:learnandteach" class="hashtag"><span>#</span><span class="p-category">learnandteach</span></a> channel. Or you can find me on fediverse <a href="https://toots.dgplug.org/@kushal">https://toots.dgplug.org/@kushal</a>.</p>

<p>Kushal</p>
]]></content:encoded>
      <guid>https://news.kushaldas.in/0x11</guid>
      <pubDate>Tue, 15 Sep 2020 07:27:03 +0000</pubDate>
    </item>
    <item>
      <title>0x10</title>
      <link>https://news.kushaldas.in/0x10?pk_campaign=rss-feed</link>
      <description>&lt;![CDATA[This week a small Indian company made a name for themselves when Citizen Lab reported  how they hacked too many people as &#34;hackers for hire&#34;.  Nicknamed as &#34;Dark Basin&#34; is the company BellTroX InfoTech Services based out of Delhi. They attacked people from different backgrounds, journalists, NGOs, EU parliament members. &#xA;You should also read the excellent story from Reuters on the same topic.&#xA;&#xA;Links for the week&#xA;&#xA;Facebook paid third party company to develop 0day exploit for Tails to help FBI https://www.vice.com/en_us/article/v7gd9b/facebook-helped-fbi-hack-child-predator-buster-hernandez&#xA;Recovering conversation using your light blub https://www.zdnet.com/article/lamphone-attack-lets-threat-actors-recover-conversations-from-your-light-bulb/&#xA;&#xA;Must read&#xA;&#xA;Many of the young readers never read the Hacker Manifesto published in the Phrack back in 1986. &#xA;&#xA;Book for the week&#xA;&#xA;I discovered Practical Typography  and enjoyed a lot reading this. The book is filled with various practical tips and details, which we don&#39;t think much on a typical day. But, I feel this is something everyone should read at least once.&#xA;&#xA;If you want to discuss any of these topics, hop on to the Freenode server (IRC), and come to the #learnandteach channel. Or you can find me on fediverse https://toots.dgplug.org/@kushal.&#xA;&#xA;Kushal]]&gt;</description>
      <content:encoded><![CDATA[<p>This week a small Indian company made a name for themselves when <a href="https://citizenlab.ca/2020/06/dark-basin-uncovering-a-massive-hack-for-hire-operation/">Citizen Lab reported</a>  how they hacked too many people as “hackers for hire”.  Nicknamed as “Dark Basin” is the company BellTroX InfoTech Services based out of Delhi. They attacked people from different backgrounds, journalists, NGOs, EU parliament members.
You should also read the <a href="https://www.reuters.com/article/us-india-cyber-mercenaries-exclusive-idUSKBN23G1GQ">excellent story from Reuters</a> on the same topic.</p>

<h2 id="links-for-the-week" id="links-for-the-week">Links for the week</h2>
<ul><li>Facebook paid third party company to develop 0day exploit for Tails to help FBI <a href="https://www.vice.com/en_us/article/v7gd9b/facebook-helped-fbi-hack-child-predator-buster-hernandez">https://www.vice.com/en_us/article/v7gd9b/facebook-helped-fbi-hack-child-predator-buster-hernandez</a></li>
<li>Recovering conversation using your light blub <a href="https://www.zdnet.com/article/lamphone-attack-lets-threat-actors-recover-conversations-from-your-light-bulb/">https://www.zdnet.com/article/lamphone-attack-lets-threat-actors-recover-conversations-from-your-light-bulb/</a></li></ul>

<h2 id="must-read" id="must-read">Must read</h2>

<p>Many of the young readers never read the <a href="http://phrack.org/issues/7/3.html">Hacker Manifesto</a> published in the Phrack back in 1986.</p>

<h2 id="book-for-the-week" id="book-for-the-week">Book for the week</h2>

<p>I discovered <a href="https://practicaltypography.com/">Practical Typography</a>  and enjoyed a lot reading this. The book is filled with various practical tips and details, which we don&#39;t think much on a typical day. But, I feel this is something everyone should read at least once.</p>

<p>If you want to discuss any of these topics, hop on to the Freenode server (IRC), and come to the <a href="https://news.kushaldas.in/tag:learnandteach" class="hashtag"><span>#</span><span class="p-category">learnandteach</span></a> channel. Or you can find me on fediverse <a href="https://toots.dgplug.org/@kushal">https://toots.dgplug.org/@kushal</a>.</p>

<p>Kushal</p>
]]></content:encoded>
      <guid>https://news.kushaldas.in/0x10</guid>
      <pubDate>Sun, 14 Jun 2020 06:37:14 +0000</pubDate>
    </item>
  </channel>
</rss>