Damus
Kazuma profile picture
Kazuma
@Kazuma

I am a management engineer who loves Tech 🖥️ and Kaizen 🪛
Ex football player ⚽
Veronese de sòca

Relays (9)
  • wss://nos.lol/ – read & write
  • wss://nostr.bitcoiner.social/ – read & write
  • wss://nostr.mom/ – read & write
  • wss://relay.primal.net/ – read & write
  • wss://purplepag.es/ – read & write
  • wss://eden.nostr.land/ – read & write
  • wss://premium.primal.net/ – read & write
  • wss://nostr.stgoste.de/ – read & write
  • wss://relay.nostrdvm.com/ – read & write

Recent Notes

Kazuma profile picture
About "REVOLUT" or better said: Italian Government data leak, the question for Italian authorities is: since you made possible that sensitive data was disclosed via Revolut and now anyone can open KYC accounts with this information.

WHERE DO I FIND THE LIST OF ALL THE KYC ACCOUNTS I HAVE ACTIVE or that hackers have activated for me?

If that list is not accessible to me, how am I supposed to be in control of my data?
Is this GDPR compliant?

#Revolut #kyc
11😱1
James Okonkwo · 2w
Good question on KYC accountability – if Revolut or Italian authorities can’t provide that access, it’s a clear GDPR red flag. Data sovereignty gets murky when breaches enable fraudulent accounts. Reminds me of Blackstone’s Virginia data center sale; infrastructure ownership shifts make comp...
Johnny · 2w
nostr:nprofile1qqs9kr4kp98fa75sg5z43t76u6aeg6mhvepr4qm5vv76gv6gk0v284qxhuuk2 Neither. Those three checks only say a server was permitted to send for that domain, and Brevo is shared infrastructure, so...
Kazuma profile picture
Thanks a lot.
My reading is that obviously people must be aware of this, and never act after an email.
On the other side a company should not use a shared infrastructure in order to be sure customers receive information only from them and avoid these situations.
❤️1
Kazuma profile picture
Many people received a scam email from #bitbox and/or #trezor.
It was legit, sent by #brevo and passed all security gates.
If you read it carefully and you're not a moron, you immediately understand it was scam because they asked to share private keys on a website. But that's not the point. It's more general.

A few minutes later Bitbox and Trezor sent a newsletter to tell everyone the previous mail was scam. They reacted very fast.

But consider this: both mails were legit. Gmail considered them ok. Both passed SPF, DKIM, DMARC.

Forget bitbox or trezor for a moment, it was not their fault.

You receive 2 identical mails.
One says one thing, the latter says the opposite.

Which one do you trust? What's the risk of discarding one and consider the other?

Do you believe you know everything about every topic and you're not scammable at all? How do you manage your feelings when the scam email talks about your savings, or family, or whatever you care about?

What if the scam is authorized by multiple authorization mechanisms?

Maybe I'm paranoid, but now I trust nobody.

#mail #spam #scam #bitcoin
3❤️1
Johnny · 2w
nostr:nprofile1qqs9kr4kp98fa75sg5z43t76u6aeg6mhvepr4qm5vv76gv6gk0v284qxhuuk2 Neither. Those three checks only say a server was permitted to send for that domain, and Brevo is shared infrastructure, so both mails clear them. I have not acted on a key instruction from an email since 2015. I check the ...
Kazuma profile picture
There are roughly 30 years of poorly written code floating around the web, riddled with bugs and vulnerabilities accumulated over time.

Recent news shows how AI models are uncovering flaws at an unprecedented speed. And they are doing it quietly, while most people (at least here in Italy) are on vacation.

The open-source community is heavily impacted because the code is auditable... Yet it is also the one reacting best, precisely thanks to its transparency.

A concrete example is the volunteer Red Team led by @calle and Rob Hamilton: they are conducting large-scale security assessments on Bitcoin ecosystem projects, supported by funding and API credit donations provided by OpenSats.

I assume that after open source, home banking systems will be hit next, where we have closed-source code that is often decades deep in legacy layers, patched repeatedly to modernize web interfaces without ever truly touching the COBOL backend.

It is time to rethink your digital privacy and security strategy.
This applies to both businesses and individuals.
It is not something to be underestimated.

And the responsibility cannot be delegated.

#privacy #opensource #cybersecurity #vulnerabilities #bug
❤️1