les articles et enquêtes de la rédaction de Numerama

/cyberguerre

  • « Dario a raison » : ce que pourrait cacher l’étrange union sacrée des géants de l’IA - Numerama
    https://www.numerama.com/cyberguerre/2332801-dario-a-raison-ce-que-pourrait-cacher-letrange-union-sacree-des-ge

    Cette inquiétude est renforcée par la demande de Dario Amodei en faveur d’exemptions ciblées au droit de la concurrence. Anthropic estime que les laboratoires doivent pouvoir coopérer sur des standards de sécurité et sur des mécanismes de ralentissement sans s’exposer à des poursuites pour entente. Une coopération autorisée entre les entreprises les plus puissantes qui pourrait aussi leur permettre de définir elles-mêmes les règles du marché.

  • Après une cyberattaque, les nouveaux pacemakers de ce géant de la santé ne peuvent plus transmettre leurs données à distance - Numerama
    https://www.numerama.com/cyberguerre/2322405-apres-une-cyberattaque-les-nouveaux-pacemakers-de-ce-geant-de-la-s

    Le fabricant de dispositifs cardiaques Boston Scientific a confirmé qu’une cyberattaque affecte directement la télésurveillance de certains de ses nouveaux implants.

    Cela fait plus d’une semaine que Boston Scientific avance à vue.

    Depuis la détection d’un incident de cybersécurité, le 25 août, le groupe américain fait face à une panne majeure de son réseau, qui perturbe l’ensemble de ses opérations informatiques.

    Dès le lendemain, l’accès à certains systèmes d’exploitation et applications métier a été interrompu, affectant directement sa capacité à fabriquer, traiter et expédier les commandes de ses clients.

    Depuis, la situation reste largement inchangée. L’entreprise affirme n’avoir constaté aucune activité non autorisée sur son réseau depuis le 25 août. Elle indique également pouvoir continuer à enregistrer les commandes reçues par voie électronique, celles-ci étant placées en attente d’un traitement ultérieur. Mais Boston Scientific n’a toujours communiqué aucun calendrier de rétablissement complet.

    Dans une mise à jour publiée le 30 août, Boston Scientific a toutefois détaillé les répercussions de l’incident sur ses dispositifs médicaux, notamment certains systèmes utilisés pour programmer ou suivre des pacemakers.

    Ce qui change pour les patients
    Le point nouveau concerne la télésurveillance des dispositifs cardiaques posés depuis le début de l’incident. Pour les nouveaux appareils de gestion du rythme, comme les pacemakers, Boston Scientific ne peut plus activer le communicateur destiné au suivi à distance. Les données recueillies par l’implant ne remontent donc pas automatiquement vers les systèmes utilisés par les équipes médicales.

    Les nouveaux moniteurs cardiaques implantables (ICM) sont touchés par un problème voisin, mais distinct. Ces petits dispositifs, qui enregistrent l’activité électrique du cœur sans délivrer de traitement, ne parviennent plus à être associés à l’application mobile du patient. Là encore, la transmission automatisée des données est bloquée.

    Le groupe assure toutefois que l’incident ne compromet pas le fonctionnement thérapeutique des pacemakers et autres dispositifs de gestion du rythme. Les ICM continuent, de leur côté, à enregistrer les éventuels épisodes cardiaques. Pour les nouveaux patients, ces informations doivent néanmoins être récupérées manuellement, lors d’une consultation.

    Les patients dont le suivi à distance avait été configuré avant le 25 août ne seraient pas concernés et continueraient d’être surveillés normalement.

    Toujours aucune revendication
    À ce stade, aucune revendication crédible n’a été rendue publique. Boston Scientific n’a identifié ni le groupe à l’origine de l’intrusion, ni le mode d’accès initial, ni la nature exacte de l’attaque. L’entreprise n’a pas non plus indiqué si des données avaient été exfiltrées ou si elle avait reçu une demande de rançon.

    Le scénario d’un rançongiciel ne peut donc pas être écarté, au regard de l’ampleur de la paralysie des systèmes et de la durée de l’interruption.

    • Unitree’s AS2-W wheel-leg robot carries 150 kg, costs half of Boston Dynamics Spot
      https://gagadget.com/en/719768-unitrees-as2-w-robot-dog-carries-150-kg-hits-22-mph-and-does-breakd


      The AS2-W uses articulated wheel-legs to navigate slopes, stairs, and rough terrain at up to 6 m/s.
      Source: Unitree Robotics

      Chinese robotics firm Unitree has unveiled the Super Athlete AS2-W, a wheel-legged quadruped priced at around $36,700 — roughly half the base cost of Boston Dynamics’ Spot. The robot weighs 25 kg, packs 16 low-inertia motors, and can carry a 150 kg payload across terrain that would stop most industrial machines. For smaller operators who’ve been priced out of Spot’s $75,000–$375,000 range, that gap matters.

      The machine
      AS2-W combines articulated legs with wheels at each joint, letting it handle both open ground and rough terrain without switching modes. It climbs slopes up to 45°, clears 80 cm obstacles, and tops out at 6 m/s. Unitree says real-time reinforcement learning — an AI approach where the robot refines its movement continuously based on live sensor data, rather than following pre-programmed rules — handles terrain adaptation on the fly. That’s a different philosophy from Spot’s decade-old model-based control system, though no independent field tests comparing the two have been published yet.

      Navigation kit includes 64–128 line lidar, a high-resolution camera, GPS, Wi-Fi 6, 4G, and Bluetooth 5.2. The robot operates between -20°C and +55°C with IP54 dust and water resistance. A 15,000 mAh battery delivers more than three hours of runtime unloaded (around 33 km range), dropping to roughly two hours with a 16 kg load. Third-party developers can extend behavior via a built-in SDK.

      Unitree pitches it at cargo transport in difficult terrain, search-and-rescue, scientific expeditions, and outdoor logistics. It also does breakdancing — the company trained it to demo agility with b-boy moves.


      Onboard sensors include 64–128 line lidar, GPS, Wi-Fi 6, and a high-resolution camera array.

      The risk
      The price is genuinely competitive, per Startup Fortune (July 2026), but Western enterprise buyers should weigh one significant concern. Unitree’s commercial platforms — including the Go2 and B1 — have appeared in Chinese People’s Liberation Army exercises equipped with rifles, according to Foundation for Defense of Democracies (May 2026). Unitree signed a non-weaponization pledge in 2022 alongside Boston Dynamics, but enforcement remains an open question. UK and US export controls could restrict future sales or software updates, creating supply-chain uncertainty for any organization that builds workflows around the platform.

      No official UK or US retail availability has been confirmed. US robotics dealers list the AS2-W as pending official release at approximately $36,700 before tax and freight. European pricing has not been announced.

    • Les États-Unis interdisent les robots humanoïdes chinois, au nom de la sécurité nationale - Numerama
      https://www.numerama.com/cyberguerre/2303731-les-etats-unis-interdisent-les-robots-humanoides-chinois-au-nom-de


      Unitree/Numerama

      La FCC a ajouté les robots humanoïdes et les onduleurs électriques fabriqués à l’étranger à sa liste noire des équipements jugés dangereux pour la sécurité nationale américaine. Une décision qui vise sans le dire la Chine, leader mondial de la robotique avancée.
      La liste s’allonge au gré des nouveaux usages.

      Le 28 juillet 2026, la Federal Communications Commission (FCC), le régulateur américain des télécommunications, a publié un communiqué annonçant l’ajout de deux nouvelles catégories d’équipements à sa « Covered List » : les robots avancés, humanoïdes ou quadrupèdes, ainsi que les onduleurs électriques connectés, dès lors qu’ils sont produits à l’étranger.

  • Grok Build a envoyé des dépôts de code entiers à xAI : pourquoi la réponse de Musk ne convainc personne - Numerama
    https://www.numerama.com/cyberguerre/2295239-grok-build-a-envoye-des-depots-de-code-entiers-a-xai-pourquoi-la-r

    Grok Build, l’outil de codage en ligne de commande de xAI, envoyait les dépôts entiers de ses utilisateurs vers le cloud de l’entreprise, secrets compris. Elon Musk a promis de tout effacer, mais la communication de SpaceXAI peine à convaincre.

    #Grokesque

    C’est une affaire qui part d’un test de sécurité mené à la mi-juillet 2026 par un chercheur connu sous le pseudonyme Cereblab.

    Son objectif initial ? Intercepter le trafic réseau généré par Grok Build pour observer précisément ce que l’outil transmettait aux serveurs de xAI. Le volume de données envoyé s’est révélé environ 27 800 fois supérieur à ce que la tâche de codage demandée nécessitait réellement. Pour être sûr de son résultat, le chercheur a même piégé son dépôt de test avec un fichier explicitement exclu de toute lecture par l’IA : il s’est retrouvé, intact, dans les données envoyées à xAI.

    La trouvaille devient virale, au point d’obliger SpaceXAI à réagir publiquement sur son compte X, et Elon Musk à promettre lui-même la suppression de toutes les données utilisateur déjà envoyées.

    Ce qui s’est réellement passé
    Concrètement, quand un développeur utilise Grok Build pour se faire aider sur son code, l’outil a besoin d’envoyer certains fichiers à xAI pour que l’IA puisse répondre, ce qui est le fonctionnement normal de n’importe quel assistant de codage dans le cloud. Le problème découvert ici est différent : en parallèle de cet envoi normal, Grok Build envoyait aussi la totalité du dépôt de code, y compris tout son historique Git, c’est-à-dire l’ensemble des versions passées de chaque fichier, même celles supprimées depuis.

    Un développeur qui aurait, par exemple, supprimé un mot de passe de son code un mois plus tôt pouvait donc quand même le voir transmis à xAI.

    C’est notamment le cas d’autres utilisateurs de Grok Build, qui ont signalé des résultats similaires à ceux de Cereblab, notamment un utilisateur dont le répertoire complet, contenant clés SSH et bases de données de gestionnaires de mots de passe, avait été ouvert et téléchargé.

    Pour compliquer les choses, l’outil proposait un réglage nommé « Improve the model », censé donner le contrôle aux utilisateurs sur ce point, mais ce réglage ne concernait en réalité que l’utilisation des données pour entraîner l’IA, pas leur envoi vers les serveurs de xAI.

    Ce qui a été corrigé, et ce qu’il reste à vérifier
    xAI a d’abord réagi via un communiqué publié sur son compte X, affirmant respecter la confidentialité et le choix de ses utilisateurs. L’entreprise y explique que les clients ayant activé la rétention zéro (ZDR) ne voient aucune donnée de code conservée, et que pour les autres, la commande « /privacy » permet de désactiver la rétention des données et de supprimer celles déjà synchronisées.

    Sauf que, toujours selon Cereblab, ce n’est pas cette commande qui a réellement mis fin au problème. Le blocage effectif des envois de dépôts est venu d’un réglage technique distinct, activé côté serveur et sans aucune annonce publique.

    À ce stade, xAI n’a publié aucun avis de sécurité détaillé sur la durée pendant laquelle les données ont été conservées, sur le nombre de comptes concernés ni sur la méthode utilisée pour la suppression promise par Musk.

    Dans les commentaires suivant la communication officielle de SpaceXAI, le scepticisme domine largement et l’affaire ne profite pas qu’aux critiques de bonne foi. Sam Altman, patron d’OpenAI et rival direct de Musk sur le marché des IA de codage, a lui-même réagi sur X pour qualifier la situation d’inquiétante.

    Un lecteur de Numerama, nous a d’ailleurs fait remarquer un détail qui donne un tout autre relief à ce « Concerning » : c’est justement une formule qu’Elon Musk emploie lui-même très régulièrement pour commenter des actualités venues de l’extrême droite sur X.

  • Pourquoi faut-il arrêter d’utiliser l’IA le vendredi au travail ? - Numerama
    cas particulier de #don't_deploy_on_Friday
    https://www.numerama.com/cyberguerre/2218259-aujourdhui-est-le-pire-jour-pour-utiliser-votre-ia-au-travail.html

    Un analyste de Gartner préconise aux entreprises de couper l’usage de l’IA le vendredi après-midi. Explications.

    Votre assistant IA ne connaît pas la sensation du vendredi après-midi, mais vous si, et c’est précisément le problème pointé par Dennis Xu, vice-président recherche chez Gartner.

    Lors d’une conférence à Sydney mi-mars 2026, consacrée aux risques portés par l’intégration de Copilot à Microsoft 365, l’analyste a suggéré aux entreprises d’interdire l’accès à l’outil IA à l’approche du week-end.

    La raison est évidente : la validation systématique des productions de l’IA est indispensable à tout moment, et le vendredi après-midi est précisément le moment où les employés, pressés d’en finir avec leur semaine, risquent de ne pas s’y astreindre. Si la suggestion a été formulée avec une pointe d’ironie, elle illustre un constat plus sérieux.

    Ce conseil a été donné à la fin d’une conférence intitulée « Atténuer les 5 principaux risques de sécurité de Microsoft 365 Copilot ».
    Source : The Register

    Un risque parmi d’autres
    Cette recommandation est en réalité venue conclure une présentation de trente minutes consacrée à un panorama de risques plus structurels liés à l’usage de l’IA en entreprise.

    Le risque le plus développé par Dennis Xu concerne l’exposition de documents confidentiels. Copilot peut indexer et restituer des fichiers hébergés sur SharePoint auxquels les droits d’accès n’ont pas été correctement configurés, un problème que l’analyste décrit non pas comme une menace inédite, mais comme un risque amplifié par l’IA.

  • C’est un fait, l’#anonymat en ligne est mort et les #LLM en sont le fossoyeur - Numerama
    https://www.numerama.com/cyberguerre/2189137-cest-fini-lanonymat-en-ligne-est-mort-et-les-llm-en-sont-le-fossoy

    Dans une étude publiée mi-février 2026, des chercheurs venus d’ETH Zurich, de MATS Research et d’Anthropic démontrent que les grands modèles de langage (LLM) sont capables de #désanonymiser des comptes en ligne à grande échelle, avec une précision et une rapidité inédites.

    On va juste leur rappeler que la plupart d’entre nous réclament le pseudonymat, et qu’il n’a jamais été question d’anonymat, et qu’on est tous bien conscient que 30 secondes de recherche #osint permettent en général de retrouver nos identités.

  • PromptSpy : ce malware s’appuie sur Gemini pour espionner les utilisateurs Android - Numerama
    https://www.numerama.com/cyberguerre/2184411-ce-malware-sappuie-sur-gemini-pour-espionner-les-utilisateurs-andr

    Dans un article de blog publié le 19 février 2026, les chercheurs en cybersécurité d’ESET mettent en lumière un nouveau malware baptisé PromptSpy. Point d’intérêt majeur ? La façon dont ce logiciel malveillant intègre l’IA dans son fonctionnement.

    À quel point l’IA déterminera les cyberattaques du futur ?

    Alors que les évolutions sont scrutées de près par les experts en menaces cyber, ESET a dévoilé le 19 février 2026 un rapport autour d’un nouveau malware baptisé PromptSpy. Un rapport publié quelques mois après la découverte du premier prototype de ransomware piloté par IA.

    Ici l’objectif est avant tout la prise de contrôle de l’appareil et l’exfiltration de données.

    PromptSpy est présenté comme le premier logiciel malveillant Android à exploiter l’IA générative dans son flux d’exécution.

    Le LLM mis à contribution ? Gemini de Google. Le rôle du LLM n’est pas de déterminer une tactique d’intrusion ou de déployer la charge utile, mais de permettre au malware de rester inexorablement actif dans le téléphone de la cible.


    Dans les instructions codées en dur, Gemini est invité à analyser le contenu du téléphone cible comme un assistant d’automatisation Android.
    Source : ESET

    Gemini sert à analyser l’écran de la victime
    Bien que l’IA n’occupe qu’une partie mineure du code, son impact est stratégique : elle rend PromptSpy plus adaptable et persistant, en s’assurant que l’application infectée reste dans la liste des applications récemment utilisées.

    Pourquoi donc ? Parce que, pour optimiser les ressources, le système ferme automatiquement les applications en arrière-plan, à moins qu’elles n’aient été explicitement « verrouillées » par l’utilisateur.

    Problème : le geste permettant ce verrouillage varie selon les constructeurs, les versions d’Android ou encore les interfaces personnalisées, ce qui rend inopérante l’utilisation de scripts statiques habituellement employés par les malwares.

    C’est là que l’approche inédite avec Gemini devient intéressante. Le logiciel malveillant envoie à l’IA une description complète de l’écran actuel, incluant le texte, la nature et la position exacte de chaque élément d’interface. Gemini analyse ces informations et renvoie des instructions précises : gestes à effectuer (clic, balayage) et emplacement exact sur l’écran.

    PromptSpy conserve l’historique de ces échanges, ce qui permet à Gemini de comprendre le contexte d’une interaction à l’autre. Le logiciel répète la séquence jusqu’à ce que l’IA confirme que l’application a bien été verrouillée.

    Les prémices d’une menace généralisée ?
    Rester continuellement actif est un enjeu majeur pour PromptSpy dont l’objectif principal est d’établir un contrôle total à distance sur l’appareil infecté. Pour cela, il installe un module VNC (technologie normalement utilisée pour l’assistance à distance) permettant aux attaquants de voir l’écran en temps réel et d’interagir avec le téléphone comme s’ils l’avaient physiquement en main.

    Au-delà de ce contrôle visuel, PromptSpy offre des capacités d’espionnage avancées : capture des mots de passe saisis à l’écran de verrouillage, enregistrement de vidéos d’activité écran, et inventaire complet des applications installées.

    Le rapport précise que le malware a été diffusé via un faux site web bancaire (jamais sur Google Play), et que cette campagne reste de portée limitée. Les chercheurs y voient un prototype ou proof-of-concept, conçu pour tester une approche inédite de cyberespionnage Android.

  • Ce missile russe « quasiment impossible à arrêter » serait en réalité déboussolé par une chanson

    https://www.numerama.com/cyberguerre/2124587-ce-missile-russe-quasiment-impossible-a-arreter-serait-en-realite-
    https://www.science-et-vie.com/technos-et-futur/une-chanson-peut-destabiliser-des-missiles-hypersoniques-russes-en-u

    Forte de ces découvertes, l’unité Night Watch a déployé le système Lima EW qui va au-delà du simple brouillage classique par émission de bruit radio. Le dispositif injecte également de faux signaux, usurpant ceux de la navigation du missile et le pousse à croire subitement qu’il se trouve à des positions très éloignées du champ de bataille ukrainien, en l’occurrence à Lima au Pérou.

    Cette attaque impose alors au projectile une modification soudaine de trajectoire, à laquelle sa structure n’est pas conçue pour résister à très haute vitesse. Selon Night Watch, le système Lima EW leur aurait permis d’abattre 19 Kinzhals en seulement deux semaines.

    La particularité dans l’utilisation de cette technologie ? Le signal envoyé par les forces ukrainiennes est une chanson nommée Notre Père est Bandera, transformée en code binaire et transmise directement au système de navigation du missile.

    Je crois qu’on a définitivement perdu certains de nos journalistes panégyristes de l’Ukraine.

    • Our father is Bandera - March of Ukrainian Insurgent Army
      Батько наш Бандера - марш УПА - YouTube
      https://www.youtube.com/watch?v=rknyopyVlcw

      marche de l’UPA, Armée insurrectionnelle ukrainienne
      https://fr.wikipedia.org/wiki/Armée_insurrectionnelle_ukrainienne

      [Приспів]
      Батько наш — Бандера, Україна — мати
      Ми за Україну підем воювати!
      Батько наш — Бандера, Україна — мати
      Ми за Україну підем воювати!

      [Куплет 1]
      Ой, у лісі, лісі під дубом зеленим
      Там лежить повстанець тяженько ранений
      Ой, у лісі, лісі під дубом зеленим
      Там лежить повстанець тяженько ранений
      Ой, лежить він, лежить, терпить тяжкі муки
      Без лівої ноги, без правої руки
      Ой, лежить він, лежить, терпить тяжкі муки
      Без лівої ноги, без правої руки
      Як прийшла до нього рідна мати його
      Плаче і ридає, жалує його
      Як прийшла до нього рідна мати його
      Плаче і ридає жалує його
      Мами ж наші, мами, не плачте за нами
      Не плачте за нами гіркими сльозами
      Мами ж наші, мами, не плачте за нами
      Не плачте за нами гіркими сльозам

      [Припев]
      Батько наш — Бандера, Україна — мати
      Ми за Україну підем воювати!
      Батько наш — Бандера, Україна — мати
      Ми за Україну підем воювати!

      [Куплет 2]
      А ми з москалями, та й не в згоді жили
      На самого Петра у бій ми вступили
      А ми з москалями, та й не в згоді жили
      На самого Петра у бій ми вступили
      Москалі тікали, аж лапті губили
      А наші за ними постріли били
      Москалі тікали аж лапті губили
      А наші за ними постріли били

      [Приспів]
      Батько наш — Бандера, Україна — мати
      Ми за Україну підем воювати!
      Батько наш — Бандера, Україна — мати
      Ми за Україну підем воювати!

      [Куплет 3]
      Ой, як мати сина свого поховала
      На його могилі слова написала
      Ой, як мати сина свого поховала
      На його могилі слова написала
      На його могилі слова написала:
      «Слава Україні! Всім героям слава!»
      На його могилі слова написала:
      «Слава Україні! Всім героям слава!»

      [Приспів]
      Батько наш — Бандера, Україна — мати
      Ми за Україну підем воювати!
      Батько наш — Бандера, Україна — мати
      Ми за Україну підем воювати!

    • • le drapeau (100 x 70 cm) = 7,50 €

      Флаг « Батько наш Бандера — Україна мати ! » красно-черный

      • écusson de manche (sur commande) = 2,00 €

      Шеврон Батько наш Бандера Україна - мати

      • format immeuble = se renseigner


      il s’agit du siège administratif de l’oblast de Ternopil, à Ternopil

      pour fêter le 113ème anniversaire de la naissance de Stepan Bandera, 1er janvier 2022, à Ternopil
      У Тернополі відбудеться хода з нагоди 113-річниці Дня народження Степана Бандери (Фото/Відео) - ФАЙНЕ МІСТО ТЕРНОПІЛЬ
      https://fainemisto.tv/news/32797-u-ternopoli-vidbudetsya-hoda-z-nagody-113-richnyczi-dnya-narodzhenn

      Тернополян запрошують на масштабну смолоскипну ходу з нагоди 113-річниці Дня народження Степана Бандери. Так, 1 січня 2022 року у місті розпочнуться заходи із вшанування пам’яті Провідника ОУН.

      • 14.00 годині покладатимуть квітів до пам’ятника Степану Бандери.

      • 16.00 годині розпочнеться хода молодіжних організацій від центрального стадіону ім. Р. Шухевича.

    • Cette publication à propros du 39C3 a-t-elle un lien avec cet article ?

      https://www.numerama.com/cyberguerre/2151107-journee-de-lindependance-numerique-ces-hackers-europeens-veulent-s

      En Allemagne, le collectif Chaos Computer Club (CCC) a appelé au lancement de « journées d’indépendance numérique » mensuelles. L’objectif affiché ? Inciter des utilisateurs et des institutions à se détacher pas à pas des plateformes dominantes et à migrer vers des alternatives plus libres. Une initiative qui passera par des ateliers de formation organisés dans plusieurs villes du pays.

      Comme chaque année depuis 1984, la grande messe du hacking européen se tenait en Allemagne dans les derniers jours de l’année, avec le Chaos Communication Congress organisé par le Chaos Computer Club.

      L’édition 2025 a été marquée par l’instauration d’un « Digital Independence Day », comprenez une « journée de l’indépendance numérique », appelée à se tenir tous les mois un peu partout en Allemagne.

      L’idée est simple : chaque premier dimanche du mois, les participants sont invités à quitter concrètement un service d’un géant du numérique pour lui préférer une solution libre et « moins problématique », et à en faire un rituel collectif. Première édition dès le 4 janvier 2026.

      Non, parce que, en nous parlant de « hackers » Numérama fait un peu dans le « clickbait » ... Suis-je un « hacker » si j’utilise un autre système que Ouindoze ? Suis-je un « hacker » si je n’utilise « OneDrive » ?

    • Je mets ici l’intégralité du discours d’ouverture du 39C3 prononcé par Cory Doctorow :

      01 Jan 2026)

      Today’s links

      The Post-American Internet: My speech from Hamburg’s Chaos Communications Congress.
      Hey look at this: Delights to delectate.
      Object permanence: Error code 451; Public email address Mansplaining Lolita; NSA backdoor in Juniper Networks; Don’t bug out; Nurses whose shitty boss is a shitty app.
      Upcoming appearances: Where to find me.
      Recent appearances: Where I’ve been.
      Latest books: You keep readin’ em, I’ll keep writin’ ’em.
      Upcoming books: Like I said, I’ll keep writin’ ’em.
      Colophon: All the rest.

      The Earth from space. Squatting over North America, casting a long shadow and ringed by a red, spiky halo, is the poop emoji from the cover of the US edition of ’Enshittification,’ with a grawlix-scrawled black bar over its mouth, wearing a Trump wig. Leaching through the starscape is a ’code waterfall’ effect as seen in the credits of the Wachowskis’ ’Matrix’ movies.
      The Post-American Internet (permalink)

      On December 28th, I delivered a speech entitled “A post-American, enshittification-resistant internet” for 39C3, the 39th Chaos Communications Congress in Hamburg, Germany. This is the transcript of that speech.
      Video Player
      00:00
      01:01:12

      Many of you know that I’m an activist with the Electronic Frontier Foundation – EFF. I’m about to start my 25th year there. I know that I’m hardly unbiased, but as far as I’m concerned, there’s no group anywhere on Earth that does the work of defending our digital rights better than EFF.

      I’m an activist there, and for the past quarter-century, I’ve been embroiled in something I call “The War on General Purpose Computing.”

      If you were at 28C3, 14 years ago, you may have heard me give a talk with that title. Those are the trenches I’ve been in since my very first day on the job at EFF, when I flew to Los Angeles to crash the inaugural meeting of something called the “Broadcast Protection Discussion Group,” an unholy alliance of tech companies, media companies, broadcasters and cable operators.

      They’d gathered because this lavishly corrupt American congressman, Billy Tauzin, had promised them a new regulation – a rule banning the manufacture and sale of digital computers, unless they had been backdoored to specifications set by that group, specifications for technical measures to block computers from performing operations that were dispreferred by these companies’ shareholders.

      That rule was called “the Broadcast Flag,” and it actually passed through the American telecoms regulator, the Federal Communications Commission. So we sued the FCC in federal court, and overturned the rule.

      We won that skirmish, but friends, I have bad news, news that will not surprise you. Despite wins like that one, we have been losing the war on the general purpose computer for the past 25 years.

      Which is why I’ve come to Hamburg today. Because, after decades of throwing myself against a locked door, the door that leads to a new, good internet, one that delivers both the technological self-determination of the old, good internet, and the ease of use of Web 2.0 that let our normie friends join the party, that door has been unlocked.

      Today, it is open a crack. It’s open a crack!

      And here’s the weirdest part: Donald Trump is the guy who’s unlocked that door.

      Oh, he didn’t do it on purpose! But, thanks to Trump’s incontinent belligerence, we are on the cusp of a “Post-American Internet,” a new digital nervous system for the 21st century. An internet that we can build without worrying about America’s demands and priorities.

      Now, don’t get me wrong, I’m not happy about Trump or his policies. But as my friend Joey DaVilla likes to say “When life gives you SARS, you make sarsaparilla.” The only thing worse than experiencing all the terror that Trump has unleashed on America and the world would be going through all that and not salvaging anything out of the wreckage.

      That’s what I want to talk to you about today: the post-American Internet we can wrest from Trump’s chaos.

      A post-American Internet that is possible because Trump has mobilized new coalition partners to join the fight on our side. In politics, coalitions are everything. Any time you see a group of people suddenly succeeding at a goal they have been failing to achieve, it’s a sure bet that they’ve found some coalition partners, new allies who don’t want all the same thing as the original forces, but want enough of the same things to fight on their side.

      That’s where Trump came from: a coalition of billionaires, white nationalists, Christian bigots, authoritarians, conspiratorialists, imperialists, and self-described “libertarians” who’ve got such a scorching case of low-tax brain worms that they’d vote for Mussolini if he’d promise to lower their taxes by a nickel.

      And what’s got me so excited is that we’ve got a new coalition in the War on General Purpose Computers: a coalition that includes the digital rights activists who’ve been on the lines for decades, but also people who want to turn America’s Big Tech trillions into billions for their own economy, and national security hawks who are quite rightly worried about digital sovereignty.

      My thesis here is that this is an unstoppable coalition. Which is good news! For the first time in decades, victory is in our grasp.

      #

      So let me explain: 14 years ago, I stood in front of this group and explained the “War on General Purpose Computing.” That was my snappy name for this fight, but the boring name that they use in legislatures for it is “anticircumvention,”

      Under anticircumvention law, it’s a crime to alter the functioning of a digital product or service, unless the manufacturer approves of your modification, and – crucially – this is true whether or not your modification violates any other law.

      Anticircumvention law originates in the USA: Section 1201 of the Digital Millennium Copyright Act of 1998 establishes a felony punishable by a five year prison sentence and a $500,000 fine for a first offense for bypassing an “access control” for a copyrighted work.

      So practically speaking, if you design a device or service with even the flimsiest of systems to prevent modification of its application code or firmware, it’s a felony – a jailable felony – to modify that code or firmware. It’s also a felony to disclose information about how to bypass that access control, which means that pen-testers who even describe how they access a device or system face criminal liability.

      Under anticircumvention law any manufacturer can trivially turn their product into a no-go zone, criminalizing the act of investigating its defects, criminalizing the act of reporting on its defects, and criminalizing the act of remediating its defects.

      This is a law that Jay Freeman rightly calls “Felony Contempt of Business Model.” Anticircumvention became the law of the land in 1998 when Bill Clinton signed the DMCA. But before you start snickering at those stupid Americans, know this: every other country in the world has passed a law just like this in the years since. Here in the EU, it came in through Article 6 of the 2001 EU Copyright Directive.

      Now, it makes a certain twisted sense for the US to enact a law like this, after all, they are the world’s tech powerhouse, home to the biggest, most powerful tech companies in the world. By making it illegal to modify digital products without the manufacturer’s permission, America enhances the rent-extracting power of the most valuable companies on US stock exchanges.

      But why would Europe pass a law like this? Europe is a massive tech importer. By extending legal protection to tech companies that want to steal their users’ data and money, the EU was facilitating a one-way transfer of value from Europe to America. So why would Europe do this?

      Well, let me tell you about the circumstances under which other countries came to enact their anticircumvention laws and maybe you’ll spot a pattern that will answer this question.

      Australia got its anticircumvention law through the US-Australia Free Trade Agreement, which obliges Australia to enact anticircumvention law.

      Canada and Mexico got it through the US-Mexico-Canada Free Trade Agreement, which obliges Canada and Mexico to enact anticircumvention laws.

      Andean nations like Chile got their anticircumvention laws through bilateral US free trade agreements, which oblige them to enact anticircumvention laws.

      And the Central American nations got their anticircumvention laws through CAFTA – The Central American Free Trade Agreement with the USA – which obliges them to enact anticircumvention laws, too.

      I assume you’ve spotted the pattern by now: the US trade representative has forced every one of its trading partners to adopt anticircumvention law, to facilitate the extraction of their own people’s data and money by American firms. But of course, that only raises a further question: Why would every other country in the world agree to let America steal its own people’s money and data, and block its domestic tech sector from making interoperable products that would prevent this theft?

      Here’s an anecdote that unravels this riddle: many years ago, in the years before Viktor Orban rose to power, I used to guest-lecture at a summer PhD program in political science at Budapest’s Central European University. And one summer, after I’d lectured to my students about anticircumvention law, one of them approached me.

      They had been the information minister of a Central American nation during the CAFTA negotiations, and one day, they’d received a phone-call from their trade negotiator, calling from the CAFTA bargaining table. The negotiator said, “You know how you told me not to give the Americans anticircumvention under any circumstances? Well, they’re saying that they won’t take our coffee unless we give them anticircumvention. And I’m sorry, but we just can’t lose the US coffee market. Our economy would collapse. So we’re going to give them anticircumvention. I’m really sorry.”

      That’s it. That’s why every government in the world allowed US Big Tech companies to declare open season on their people’s private data and ready cash.

      The alternative was tariffs. Well, I don’t know if you’ve heard, but we’ve got tariffs now!

      I mean, if someone threatens to burn your house down unless you follow their orders, and then they burn your house down anyway, you don’t have to keep following their orders. So…Happy Liberation Day?

      So far, every country in the world has had one of two responses to the Trump tariffs. The first one is: “Give Trump everything he asks for (except Greenland) and hope he stops being mad at you.” This has been an absolute failure. Give Trump an inch, he’ll take a mile. He’ll take fucking Greenland. Capitulation is a failure.

      But so is the other tactic: retaliatory tariffs. That’s what we’ve done in Canada (like all the best Americans, I’m Canadian). Our top move has been to levy tariffs on the stuff we import from America, making the things we buy more expensive. That’s a weird way to punish America! It’s like punching yourself in the face as hard as you can, and hoping the downstairs neighbor says “Ouch!”

      And it’s indiscriminate. Why whack some poor farmer from a state that begins and ends with a vowel with tariffs on his soybeans. That guy never did anything bad to Canada.

      But there’s a third possible response to tariffs, one that’s just sitting there, begging to be tried: what about repealing anticircumvention law?

      If you’re a technologist or an investor based in a country that’s repealed its anticircumvention law, you can go into business making disenshittificatory products that plug into America’s defective tech exports, allowing the people who own and use those products to use them in ways that are good for them, even if those uses make the company’s shareholders mad.

      Think of John Deere tractors: when a farmer’s John Deere tractor breaks down, they are expected to repair it, swapping in new parts and assemblies to replace whatever’s malfing. But the tractor won’t recognize that new part and will not start working again, not until the farmer spends a couple hundred bucks on a service callout from an official John Deere tractor repair rep, whose only job is to type an unlock code into the tractor’s console, to initialize the part and pair it with the tractor’s main computing unit.

      Modding a tractor to bypass this activation step violates anticircumvention law, meaning farmers all over the world are stuck with this ripoff garbage, because their own government will lock up anyone who makes a tractor mod that disables the parts-pairing check in this American product.

      So what if Canada repealed Bill C-11, the Copyright Modernization Act of 2012 (that’s our anticircumvention law)? Well, then a company like Honeybee, which makes tractor front-ends and attachments, could hire some smart University of Waterloo computer science grads, and put ’em to work jailbreaking the John Deere tractor’s firmware, and offer it to everyone in the world. They could sell the crack to anyone with an internet connection and a payment method, including that poor American farmer whose soybeans we’re currently tariffing.

      It’s hard to convey how much money is on the table here. Take just one example: Apple’s App Store. Apple forces all app vendors into using its payment processor, and charges them a 30 percent commission on every euro spent inside of an app.

      30 percent! That’s such a profitable business that Apple makes $100 billion per year on it. If the EU repeals Article 6 of the Copyright Directive, some smart geeks in Finland could reverse-engineer Apple’s bootloaders and make a hardware dongle that jailbreaks phones so that they can use alternative app stores, and sell the dongle – along with the infrastructure to operate an app store – to anyone in the world who wants to go into business competing with Apple for users and app vendors.

      Those competitors could offer a 90% discount to every crafter on Etsy, every performer on Patreon, every online news outlet, every game dev, every media store. Offer them a 90% discount on payments, and still make $10b/year.

      Maybe Finland will never see another Nokia, but Nokia’s a tough business to be in. You’ve got to make hardware, which is expensive and risky. But if the EU legalizes jailbreaking, then Apple would have to incur all the expense and risk of making and fielding hardware, while those Finnish geeks could cream off the $100b Apple sucks out of the global economy in an act of a disgusting, rip-off rent-seeking.

      As Jeff Bezos said to the publishers: “Your margin is my opportunity.” With these guys, it’s always “disruption for thee, but not for me.” When they do it to us, that’s progress. When we do it to them, it’s piracy, and every pirate wants to be an admiral.

      Well, screw that. Move fast and break Tim Cook’s things. Move fast and break kings!

      It’s funny: I spent 25 years getting my ass kicked by the US Trade Representative (in my defense, it wasn’t a fair fight). I developed a kind of grudging admiration for the skill with which the USTR bound the entire world to a system of trade that conferred parochial advantages to America and its tech firms, giving them free rein to loot the world’s data and economies. So it’s been pretty amazing to watch Trump swiftly and decisively dismantle the global system of trade and destroy the case for the world continuing to arrange its affairs to protect the interests of America’s capital class.

      I mean, it’s not a path I would have chosen. I’d have preferred no Trump at all to this breakthrough. But I’ll take this massive own-goal if Trump insists. I mean, I’m not saying I’ve become an accelerationist, but at this point, I’m not exactly not an accelerationist.

      Now, you might have heard that governments around the world have been trying to get Apple to open its App Store, and they’ve totally failed at this. When the EU hit Apple with an enforcement order under the Digital Markets Act, Apple responded by offering to allow third party app stores, but it would only allow those stores to sell apps that Apple had approved of.

      And while those stores could use their own payment processors, Apple would charge them so much in junk fees that it would be more expensive to process a payment using your own system, and if Apple believed that a user’s phone had been outside of the EU for 21 days, they’d remotely delete all that user’s data and apps.

      When the EU explained that this would not satisfy the regulation, Apple threatened to pull out of the EU. Then, once everyone had finished laughing, Apple filed more than a dozen bullshit objections to the order hoping to tie this up in court for a decade, the way Google and Meta did for the GDPR.

      It’s not clear that the EU can force Apple to write code that opens up the iOS platform for alternative app stores and payment methods, but there is one thing that the EU can absolutely do with 100% reliability, any time they want: the EU can decide not to let Apple use Europe’s courts to shut down European companies that defend European merchants, performers, makers, news outlets, game devs and creative workers, from Apple’s ripoff, by jailbreaking phones.

      All the EU has to do is repeal Article 6 of the Copyright Directive, and, in so doing, strip Apple of the privilege of mobilizing the European justice system to shore up Apple’s hundred billion dollar annual tax on the world’s digital economy. The EU company that figures out how to reliably jailbreak iPhones will have customers all over the world, including in the USA, where Apple doesn’t just use its veto over which apps you can run on your phone to suck 30% out of every dollar you spend, but where Apple also uses its control over the platform to strip out apps that protect Apple’s customers from Trump’s fascist takeover.

      Back in October, Apple kicked the “ICE Block” app out of the App Store. That’s an app that warns the user if there’s a snatch squad of masked ICE thugs nearby looking to grab you off the street and send you to an offshore gulag. Apple internally classified ICE kidnappers as a “protected class,” and then declared the ICE Block infringed on the rights of these poor, beset ICE goons.

      And speaking of ICE thugs, there are plenty of qualified technologists who have fled the US this year, one step ahead of an ICE platoon looking to put them and their children into a camp. Those skilled hackers are now living all over the world, joined by investors who’d like to back a business whose success will be determined by how awesome its products are, and not how many $TRUMP coins they buy.

      Apple’s margin could be their opportunity.

      Legalizing jailbreaking, raiding the highest margin lines of business of the most profitable companies in America is a much better response to the Trump tariffs than retaliatory tariffs.

      For one thing, this is a targeted response: go after Big Tech’s margins and you’re mounting a frontal assault on the businesses whose CEOs each paid a million bucks to sit behind Trump on the inauguration dais.

      Raiding Big Tech’s margins is not an attack on the American people, nor on the small American businesses that are ripped off by Big Tech. It’s a raid on the companies that screw everyday Americans and everyone else in the world. It’s a way to make everyone in the world richer at the expense of these ripoff companies.

      It beats the shit out of blowing hundreds of billions of dollars building AI data-centers in the hopes that someday, a sector that’s lost nearly a trillion dollars shipping defective chatbots will figure out a use for GPUs that doesn’t start hemorrhaging money the minute they plug them in.

      So here are our new allies in the war on general-purpose computation: businesses and technologists who want to make billions of dollars raiding Big Tech’s margins, and policymakers who want their country to be the disenshittification nation – the country that doesn’t merely protect its people’s money and privacy by buying jailbreaks from other countries, but rather, the country that makes billions of dollars selling that privacy and pocketbook-defending tech to the rest of the world.

      That’s a powerful alliance, but those are not the only allies Trump has pushed into our camp. There’s another powerful ally waiting in the wings.

      Remember last June, when the International Criminal Court in the Hague issued an arrest warrant for the génocidaire Benjamin Netanyahu, and Trump denounced the ICC, and then the ICC lost its Outlook access, its email archives, its working files, its address books, its calendars?

      Microsoft says they didn’t brick the ICC – that it’s a coincidence. But when it comes to a he-said/Clippy-said between the justices of the ICC and the convicted monopolists of Microsoft, I know who I believe.

      This is exactly the kind of infrastructural risk that we were warned of if we let Chinese companies like Huawei supply our critical telecoms equipment. Virtually every government ministry, every major corporation, every small business and every household in the world have locked themselves into a US-based, cloud-based service.

      The handful of US Big Tech companies that supply the world’s administrative tools are all vulnerable to pressure from the Trump admin, and that means that Trump can brick an entire nation.

      The attack on the ICC was an act of cyberwarfare, like the Russian hackers who shut down Ukrainian power-generation facilities, except that Microsoft doesn’t have to hack Outlook to brick the ICC – they own Outlook.

      Under the US CLOUD Act of 2018, the US government can compel any US-based company to disclose any of its users’ data – including foreign governments – and this is true no matter where that data is stored. Last July, Anton Carniaux, Director of Public and Legal Affairs at Microsoft France, told a French government inquiry that he “couldn’t guarantee” that Microsoft wouldn’t hand sensitive French data over to the US government, even if that data was stored in a European data-center.

      And under the CLOUD Act, the US government can slap gag orders on the companies that it forces to cough up that data, so there’d be no way to even know if this happened, or whether it’s already happened.

      It doesn’t stop at administrative tools, either: remember back in 2022, when Putin’s thugs looted millions of dollars’ worth of John Deere tractors from Ukraine and those tractors showed up in Chechnya? The John Deere company pushed an over-the-air kill signal to those tractors and bricked ’em.

      John Deere is every bit as politically vulnerable to the Trump admin as Microsoft is, and they can brick most of the tractors in the world, and the tractors they can’t brick are probably made by Massey Ferguson, the number-two company in the ag-tech cartel, which is also an American company and just as vulnerable to political attacks from the US government.

      Now, none of this will be news to global leaders. Even before Trump and Microsoft bricked the ICC they were trying to figure out a path to “digital sovereignty.” But the Trump administration’s outrageous conduct and rhetoric over past 11 months has turned “digital sovereignty” from a nice-to-have into a must-have.

      So finally, we’re seeing some movement, like “Eurostack,” a project to clone the functionality of US Big Tech silos in free/open source software, and to build EU-based data-centers that this code can run on.

      But Eurostack is heading for a crisis. It’s great to build open, locally hosted, auditable, trustworthy services that replicate the useful features of Big Tech, but you also need to build the adversarial interoperability tools that allow for mass exporting of millions of documents, the sensitive data-structures and edit histories.

      We need scrapers and headless browsers to accomplish the adversarial interoperability that will guarantee ongoing connectivity to institutions that are still hosted on US cloud-based services, because US companies are not going to facilitate the mass exodus of international customers from their platform.

      Just think of how Apple responded to the relatively minor demand to open up the iOS App Store, and now imagine the thermonuclear foot-dragging, tantrum-throwing and malicious compliance they’ll come up with when faced with the departure of a plurality of the businesses and governments in a 27-nation bloc of 500,000,000 affluent consumers.

      Any serious attempt at digital sovereignty needs migration tools that work without the cooperation of the Big Tech companies. Otherwise, this is like building housing for East Germans and locating it in West Berlin. It doesn’t matter how great the housing is, your intended audience is going to really struggle to move in unless you tear down the wall.

      Step one of tearing down that wall is killing anticircumvention law, so that we can run virtual devices that can be scripted, break bootloaders to swap out firmware and generally seize the means of computation.

      So this is the third bloc in the disenshittification army: not just digital rights hippies like me; not just entrepreneurs and economic development wonks rubbing their hands together at the thought of transforming American trillions into European billions; but also the national security hawks who are 100% justified in their extreme concern about their country’s reliance on American platforms that have been shown to be totally unreliable.

      This is how we’ll get a post-American internet: with an unstoppable coalition of activists, entrepreneurs and natsec hawks.

      This has been a long time coming. Since the post-war settlement, the world has treated the US as a neutral platform, a trustworthy and stable maintainer of critical systems for global interchange, what the political scientists Henry Farrell and Abraham Newman call the “Underground Empire.” But over the past 15 years, the US has systematically shattered global trust in its institutions, a process that only accelerated under Trump.

      Take transoceanic fiber optic cables: the way the transoceanic fiber routes were planned, the majority of these cables make landfall on the coasts of the USA where the interconnections are handled. There’s a good case for this hub-and-spoke network topology, especially compared to establishing direct links between every country. That’s an Order(N^2) problem: directly linking each of the planet Earth’s 205 countries to every other country would require 20,910 fiber links.

      But putting all the world’s telecoms eggs in America’s basket only works if the US doesn’t take advantage of its centrality, and while many people worried about what the US could do with the head-ends of the world’s global fiber infra, it wasn’t until Mark Klein’s 2006 revelations about the NSA’s nation-scale fiber optic taps in AT&T’s network, and Ed Snowden’s 2013 documents showing the global scale of this wiretapping, that the world had to confront the undeniable reality that the US could not be trusted to serve as the world’s fiber hub.

      It’s not just fiber. The world does business in dollars. Most countries maintain dollar accounts at the Fed in New York as their major source of foreign reserves. But in 2005, American vulture capitalists bought up billions of dollars worth of Argentinian government bonds after the sovereign nation of Argentina had declared bankruptcy.

      They convinced a judge in New York to turn over the government of Argentina’s US assets to them to make good on loans that these debt collectors had not issued, but had bought up at pennies on the dollar. At that moment, every government in the world had to confront the reality that they could not trust the US Federal Reserve with their foreign reserves. But what else could they use?

      Without a clear answer, dollar dominance continued, but then, under Biden, Putin-aligned oligarchs and Russian firms lost access to the SWIFT system for dollar clearing. This is when goods – like oil – are priced in dollars, so that buyers only need to find someone who will trade their own currency for dollars, which they can then swap for any commodity in the world.

      Again, there’s a sound case for dollar clearing: it’s just not practical to establish deep, liquid pairwise trading market for all of the world’s nearly 200 currencies, it’s another O(N^2) problem.

      But it only works if the dollar is a neutral platform. Once the dollar becomes an instrument of US foreign policy – whether or not you agree with that policy – it’s no longer a neutral platform, and the world goes looking for an alternative.

      No one knows what that alternative’s going to be, just as no one knows what configuration the world’s fiber links will end up taking. There’s kilometers of fiber being stretched across the ocean floor, and countries are trying out some pretty improbable gambits as dollar alternatives, like Ethiopia revaluing its sovereign debt in Chinese renminbi. Without a clear alternative to America’s enshittified platforms, the post-American century is off to a rocky start.

      But there’s one post-American system that’s easy to imagine. The project to rip out all the cloud connected, backdoored, untrustworthy black boxes that power our institutions, our medical implants, our vehicles and our tractors; and replace it with collectively maintained, open, free, trustworthy, auditable code.

      This project is the only one that benefits from economies of scale, rather than being paralyzed by exponential crises of scale. That’s because any open, free tool adopted by any public institution – like the Eurostack services – can be audited, localized, pen-tested, debugged and improved by institutions in every other country.

      It’s a commons, more like a science than a technology, in that it is universal and international and collaborative. We don’t have dueling western and Chinese principles of structural engineering. Rather, we have universal principles for making sure buildings don’t fall down, adapted to local circumstances.

      We wouldn’t tolerate secrecy in the calculations used to keep our buildings upright, and we shouldn’t tolerate opacity in the software that keeps our tractors, hearing aids, ventilators, pacemakers, trains, games consoles, phones, CCTVs, door locks, and government ministries working.

      The thing is, software is not an asset, it’s a liability. The capabilities that running software delivers – automation, production, analysis and administration – those are assets. But the software itself? That’s a liability. Brittle, fragile, forever breaking down as the software upstream of it, downstream of it, and adjacent to it is updated or swapped out, revealing defects and deficiencies in systems that may have performed well for years.

      Shifting software to commons-based production is a way to reduce the liability that software imposes on its makers and users, balancing out that liability among many players.

      Now, obviously, tech bosses are totally clueless when it comes to this. They really do think that software is an asset. That’s why they’re so fucking horny to have chatbots shit out software at superhuman speeds. That’s why they think it’s good that they’ve got a chatbot that “produces a thousand times more code than a human programmer.”

      Producing code that isn’t designed for legibility and maintainability, that is optimized, rather, for speed of production, is a way to incur tech debt at scale.

      This is a neat encapsulation of the whole AI story: the chatbot can’t do your job, but an AI salesman can convince your boss to fire you and replace you with a chatbot that can’t do your job.

      Your boss is an easy mark for that chatbot hustler because your boss hates you. In their secret hearts, bosses understand that if they stopped coming to work, the business would run along just fine, but if the workers stopped showing up, the company would grind to a halt.

      Bosses like to tell themselves that they’re in the driver’s seat, but really, they fear that they’re strapped into the back seat playing with a Fisher Price steering wheel. For them, AI is a way to wire the toy steering wheel directly into the company’s drive-train. It’s the realization of the fantasy of a company without workers.

      When I was walking the picket line in Hollywood during the writer’s strike, a writer told me that you prompt an AI the same way a studio boss gives shitty notes to a writer’s room: “Make me ET, but make it about a dog, and give it a love interest, and a car-chase in the third act.”

      Say that to a writer’s room and they will call you a fucking idiot suit and tell you “Why don’t you go back to your office and make a spreadsheet, you nitwit. The grownups here are writing a movie.”

      Meanwhile, if you give that prompt to a chatbot, it will cheerfully shit out a script exactly to spec. The fact that this script will be terrible and unusable is less important than the prospect of a working life in which no one calls you a fucking idiot suit.

      AI dangles the promise of a writer’s room without writers, a movie without actors, a hospital without nurses, a coding shop without coders.

      When Mark Zuckerberg went on a podcast and announced that the average American had three friends, but wanted 15 friends, and that he could solve this by giving us chatbots instead of friends, we all dunked on him as an out-of-touch billionaire Martian who didn’t understand the nature of friendship.

      But the reality is that for Zuck, your friends are a problem. Your friends’ interactions with you determine how much time you spend on his platforms, and thus how many revenue-generating ads he can show you.

      Your friends stubbornly refuse to organize their relationship with you in a way that maximizes the return to his shareholders. So Zuck is over there in Menlo Park, furiously fantasizing about replacing your friends with chatbots, because that way, he can finally realize the dream of a social media service without any socializing.

      Rich, powerful people are, at root, solipsists. The only way to amass a billion dollars is to inflict misery and privation on whole populations. The only way to look yourself in the mirror after you’ve done that, is to convince yourself that those people don’t matter, that, in some important sense, they aren’t real.

      Think of Elon Musk calling everyone who disagrees with him an "NPC,” or all those “Effective Altruists,” who claimed the moral high ground by claiming to care about 53 trillion imaginary artificial humans who will come into existence in 10,000 years at the expense of extending moral consideration to people alive today.

      Or think of how Trump fired all the US government scientists, and then announced the “Genesis” program, declaring that the US would begin generating annual “moonshot”-scale breakthroughs, with a chatbot. It’s science without scientists.

      Chatbots can’t really do science, but from Trump’s perspective, they’re still better than scientists, because a chatbot won’t ever tell him not to stare at an eclipse, or not to inject bleach. A chatbot won’t ever tell him that trans people exist, or that the climate emergency is real.

      Powerful people are suckers for AI, because AI fuels the fantasy of a world without people: just a boss and a computer, and no ego-shattering confrontations with people who know how to do things telling you “no.”

      AI is a way to produce tech debt at scale, to replace skilled writers with defective spicy autocomplete systems, to lose money at a rate not seen in living memory.

      Now, compare that with the project of building a post-American internet: a project to reduce tech debt, to unlock America’s monopoly trillions and divide them among the world’s entrepreneurs (for whom they represent untold profits), and the world’s technology users (for whom they represent untold savings); all while building resiliency and sovereignty.

      Now, some of you are probably feeling pretty cynical about this right now. After all, your political leaders have demonstrated decades of ineffectual and incompetent deference to the US, and an inability to act, even when the need was dire. If your leaders couldn’t act decisively on the climate emergency, what hope do we have of them taking this moment seriously?

      But crises precipitate change. Remember when another mad emperor – Vladimir Putin – invaded Ukraine, and Europe experienced a dire energy shortage? In three short years, the continent’s solar uptake skyrocketed. The EU went from being 15 years behind in its energy transition, to ten years ahead of schedule.

      Because when you’re shivering in the dark, a lot of fights you didn’t think were worth it are suddenly existential battles you can’t afford to lose. Sure, no one wants to argue with a tedious neighbor who has an aesthetic temper tantrum at the thought of a solar panel hanging from their neighbor’s balcony.

      But when it’s winter, and there’s no Russian gas, and you’re shivering in the dark, then that person can take their aesthetic objection to balcony solar, fold it until it’s all corners, and shove it right up their ass.

      Besides, we don’t need Europe to lead the charge on a post-American internet by repealing anticircumvention. Any country could do it! And the country that gets there first gets to reap the profits from supplying jailbreaking tools to the rest of the world, it gets to be the Disenshittification Nation, and everyone else in the world gets to buy those tools and defend themselves from US tech companies’ monetary and privacy plunder.

      Just one country has to break the consensus, and the case for every country doing so is the strongest it’s ever been. It used to be that countries that depended on USAID had to worry about losing food, medical and cash supports if they pissed off America. But Trump killed USAID, so now that’s a dead letter.

      Meanwhile, America’s status as the planet’s most voracious consumer has been gutted by decades of anti-worker, pro-billionaire policies. Today, the US is in the grips of its third consecutive “K-shaped” recovery, that’s an economic rally where the rich get richer, and everyone else gets poorer. For a generation, America papered over that growing inequality with easy credit, with everyday Americans funding their consumption with credit cards and second and third mortgages.

      So long as they could all afford to keep buying, other countries had to care about America as an export market. But a generation of extraction has left the bottom 90% of Americans struggling to buy groceries and other necessities, carrying crushing debt from skyrocketing shelter, education and medical expenses that they can’t hope to pay down, thanks to 50 years of wage stagnation.

      The Trump administration has sided firmly with debt collectors, price gougers, and rent extractors. Trump neutered enforcement against rent-fixing platforms like Realpage, restarted debt payments for eight million student borrowers, and killed a plan to make live-saving drugs a little cheaper, leaving Americans to continue to pay the highest drug prices in the world.

      Every dollar spent servicing a loan is a dollar that can’t go to consumption. And as more and more Americans slip into poverty, the US is gutting programs that spend money on the public’s behalf, like SNAP, the food stamps program that helps an ever-larger slice of the American public stave off hunger.

      America is chasing the “world without people” dream, where working people have nothing, spend nothing, and turn every penny over to rentiers who promptly flush that money into the stock market, shitcoins, or gambling sites. But I repeat myself.

      Even the US military – long a sacrosanct institution – is being kneecapped to enrich rent-seekers. Congress just killed a military “right to repair” law. So now, US soldiers stationed abroad will have to continue the Pentagon’s proud tradition of shipping materiel from generators to jeeps back to America to be fixed by their manufacturers at a 10,000% markup, because the Pentagon routinely signs maintenance contracts that prohibit it from teaching a Marine how to fix an engine.

      The post-American world is really coming on fast. As we repeal our anticircumvention laws, we don’t have to care what America thinks, we don’t have to care about their tariffs, because they’re already whacking us with tariffs; and because the only people left in the US who can afford to buy things are rich people, who just don’t buy enough stuff. There’s only so many Lambos and Sub-Zeros even the most guillotineable plute can usefully own.

      But what if European firms want to go on taking advantage of anticircumvention laws? Well, there’s good news there, too. “Good news,” because the EU firms that rely on anticircumvention are engaged in the sleaziest, most disgusting frauds imaginable.

      Anticircumvention law is the reason that Volkswagen could get away with Dieselgate. By imposing legal liability on reverse-engineers who might have discovered this lethal crime, Article 6 of the Copyright Directive created a chilling effect, and thousands of Europeans died, every year.

      Today, Germany’s storied automakers are carrying on the tradition of Dieselgate, sabotaging their cars to extract rent from drivers. From Mercedes, which rents you the accelerator pedal in your luxury car, only unlocking the full acceleration curve of your engine if you buy a monthly subscription; to BMW, which rents you the automated system that automatically dims your high-beams if there’s oncoming traffic.

      Legalize jailbreaking and any mechanic in Europe could unlock those subscription features for one price, and not share any of that money with BMW and Mercedes.

      Then there’s Medtronic, a company that pretends it is Irish. Medtronic is the world’s largest med-tech company, having purchased all their competitors, and then undertaken the largest “tax-inversion” in history, selling themselves to a tiny Irish firm, in order to magick their profits into a state of untaxable grace, floating in the Irish Sea.

      Medtronic supplies the world’s most widely used ventilators, and it booby-traps them the same way John Deere booby-traps its tractors. After a hospital technician puts a new part in a Medtronic ventilator, the ventilator’s central computing unit refuses to recognize the part until it completes a cryptographic handshake, proving that an authorized Medtronic technician was paid hundreds of euros to certify a repair that the hospital’s own technician probably performed.

      It’s just a way to suck hundreds of euros out of hospitals every time a ventilator breaks. This would be bad enough, but during the covid lockdowns, when every ventilator was desperately needed, and when the planes stopped flying, there was no way for a Medtronic tech to come and bless the hospital technicians’ repairs. This was lethal. It killed people.

      There’s one more European company that relies on anticircumvention that I want to discuss here, because they’re old friends of CCC: that’s the Polish train company Newag. Newag sabotages its own locomotives, booby-trapping them so that if they sense they have been taken to a rival’s service yard, the train bricks itself. When the train operator calls Newag about this mysterious problem, the company “helpfully” remotes into the locomotive’s computers, to perform “diagnostics,” which is just sending a unbricking command to the vehicle, a service for which they charge 20,000 euros.

      Last year, Polish hackers from the security research firm Dragon Sector presented on their research into this disgusting racket in this very hall, and now, they’re being sued by Newag under anticircumvention law, for making absolutely true disclosures about Newag’s deliberately defective products.

      So these are the European stakeholders for anticircumvention law: the Dieselgate killers, the car companies who want to rent you your high-beams and accelerator, the med-tech giant that bricked all the ventilators during the pandemic, and the company that tied Poland to the train-tracks.

      I relish the opportunity to fight these bastards in Brussels, as they show up and cry “Won’t someone think of the train saboteurs?”

      The enshittification of technology – the decay of the platforms and systems we rely on – has many causes: the collapse of competition, regulatory capture, the smashing of tech workers’ power. But most of all, enshittification is the result of anticircumvention law’s ban on interoperability.

      By blocking interop, by declaring war on the general-purpose computer, our policy-makers created an enshittogenic environment that rewarded companies for being shitty, and ushered in the enshittocene, in which everything is turning to shit.

      Let’s call time on enshittification. Let’s seize the means of computation. Let’s build the drop-in, free, open, auditable alternatives to the services and firmware we rely on.

      Let’s end the era of silos. I mean, isn’t it fucking weird how you have to care which network someone is using if you want to talk to them? Instead of just deciding who you want to talk to?

      The fact that you have to figure out whether the discussion you’re trying to join is on Twitter or Bluesky, Mastodon or Instagram – that is just the most Prodigy/AOL/Compuserve-ass way of running a digital world. I mean, 1990 called and they want their walled gardens back

      Powerful allies are joining our side in the War on General Purpose Computation. It’s not just people like us, who’ve been fighting for this whole goddamned century, but also countries that want to convert American tech’s hoarded trillions into fuel for a single-use rocket that boosts their own tech sector into a stable orbit.

      It’s national security hawks who are worried about Trump bricking their ministries or their tractors, and who are also worried – with just cause – about Xi Jinping bricking all their solar inverters and batteries. Because, after all, the post-American internet is also a post-Chinese internet!

      Nothing should be designed to be field updatable without the user’s permission. Nothing critical should be a black box.

      Like I said at the start of this talk, I have been doing this work for 24 years at the Electronic Frontier Foundation, throwing myself at a door that was double-locked and deadbolted, and now that door is open a crack and goddammit, I am hopeful.

      Not optimistic. Fuck optimism! Optimism is the idea that things will get better no matter what we do. I know that what we do matters. Hope is the belief that if we can improve things, even in small ways, we can ascend the gradient toward the world we want, and attain higher vantage points from which new courses of action, invisible to us here at our lower elevation, will be revealed.

      Hope is a discipline. It requires that you not give in to despair. So I’m here to tell you: don’t despair.

      All this decade, all over the world, countries have taken up arms against concentrated corporate power. We’ve had big, muscular antitrust attacks on big corporations in the US (under Trump I and Biden); in Canada; in the UK; in the EU and member states like Germany, France and Spain; in Australia; in Japan and South Korea and Singapore; in Brazil; and in China.

      This is a near-miraculous turn of affairs. All over the world, governments are declaring war on monopolies, the source of billionaires’ wealth and power.

      Even the most forceful wind is invisible. We can only see it by its effects. What we’re seeing here is that whenever a politician bent on curbing corporate power unfurls a sail, no matter where in the world that politician is, that sail fills with wind and propels the policy in ways that haven’t been seen in generations.

      The long becalming of the fight over corporate power has ended, and a fierce, unstoppable wind is blowing. It’s not just blowing in Europe, or in Canada, or in South Korea, Japan, China, Australia or Brazil. It’s blowing in America, too. Never forget that as screwed up and terrifying as things are in America, the country has experienced, and continues to experience, a tsunami of antitrust bills and enforcement actions at the local, state and federal level.

      And never forget that the post-American internet will be good for Americans. Because, in a K-shaped, bifurcated, unequal America, the trillions that American companies loot from the world don’t trickle down to Americans. The average American holds a portfolio of assets that rounds to zero, and that includes stock in US tech companies.

      The average American isn’t a shareholder in Big Tech, the average American is a victim of Big Tech. Liberating the world from US Big Tech is also liberating America from US Big Tech.

      That’s been EFF’s mission for 35 years. It’s been my mission at EFF for 25 years. If you want to get involved in this fight – and I hope you do – it can be your mission, too. You can join EFF, and you can join groups in your own country, like Netzpolitik here in Germany, or the Irish Council for Civil Liberties, or La Quadrature du Net in France, or the Open Rights Group in the UK, or EF Finland, or ISOC Bulgaria, XNet, DFRI, Quintessenz, Bits of Freedom, Openmedia, FSFE, or any of dozens of organizations around the world.

      The door is open a crack, the wind is blowing, the post-American internet is upon us: a new, good internet that delivers all the technological self-determination of the old, good internet, and the ease of use of Web 2.0 so that our normie friends can use it, too.

      And I can’t wait for all of us to get to hang out there. It’s gonna be great.

  • World’s largest aviation giant abandons Google over security concerns — RT World News
    https://www.rt.com/news/629834-worlds-largest-aviation-giant-abandons

    European aerospace corporation Airbus has decided to move critical digital systems away from Google’s cloud services. Company executives say the decision is driven by security and data sovereignty concerns linked to US jurisdiction over sensitive industrial information.

    The decision comes as Google faces a class-action lawsuit in the US over alleged privacy violations linked to its AI assistant, Gemini. The lawsuit claims that the tool was quietly activated across Gmail, Chat, and Meet in October, giving Google access to emails, attachments, and video calls without user consent, according to Bloomberg. Google has denied the allegations.

    Airbus is now preparing to tender a major contract to migrate mission-critical workloads to a digitally sovereign European cloud. The company, which currently uses Google Workspace, plans to move key on-premises systems after consolidating its data center estate.

    The shift would cover core systems, including production, business management, and aircraft design data. Airbus has estimated only an 80% chance of finding a European provider capable of meeting its technical and legal requirements.

    • « J’ai besoin d’un cloud souverain », le nouveau plan d’Airbus pour couper Microsoft de ses données sensibles risque d’être tué dans l’œuf - Numerama
      https://www.numerama.com/cyberguerre/2146843-jai-besoin-dun-cloud-souverain-le-nouveau-plan-dairbus-pour-couper

      Dans un entretien accordé au site britannique The Register, Catherine Jestin, vice‑présidente exécutive du numérique chez Airbus, annonce que le géant de l’aéronautique français s’apprête à lancer un appel d’offres majeur. L’objectif ? Migrer ses charges de travail critiques vers un cloud européen souverain. Cette transition devra cependant relever des défis immenses.

      Les transitions numériques sont loin d’être un long fleuve tranquille chez Airbus, et les changements virent au casse-tête lorsqu’il est question de souveraineté numérique.

      En novembre 2025, nous vous relations déjà les difficultés du groupe aéronautique français à migrer la totalité de ses activités hors de l’écosystème Microsoft. L’objectif avait pourtant été fixé dès 2018 par l’ancienne direction, qui souhaitait alors adopter la suite Google et les méthodes de travail d’une entreprise « plus collaborative ».

  • « C’est silencieux, rapide et brutal. Exactement comme j’aime. », les versions malveillantes de ChatGPT se répandent à moindre coût - Numerama
    https://www.numerama.com/cyberguerre/2127457-cest-silencieux-rapide-et-brutal-exactement-comme-jaime-les-versio

    « C’est silencieux, rapide et brutal. Exactement comme j’aime. », les versions malveillantes de ChatGPT se répandent à moindre coût
    De grands pouvoirs impliquent de grandes responsabilités

    Des chercheurs en cybersécurité de Palo Alto Networks détaillent les modes de production et les canaux d’acquisition de WormGPT 4, un grand modèle de langage dépourvu de garde-fous de sécurité et prisé pour mener des campagnes cybercriminelles.
    Les modèles de langage (LLM) font désormais partie du quotidien de millions de personnes, du fait de leur grande capacité à générer du texte, des images, du code et de répondre à presque toutes nos demandes… du moins tant qu’ils respectent les règles définies par leurs concepteurs.

    Ces règles, communément appelées garde-fous, sont les consignes intégrées au chatbot lors de son développement et l’empêchent, dans la plupart des cas, de divulguer des informations confidentielles, de porter atteinte à la propriété privée ou encore d’aider à commettre des actes répréhensibles ou dangereux.

    Ces garde-fous ne sont pas infaillibles, il est possible de les jailbreaker comme nous avions pu le tester en novembre 2025. Ils ont cependant le mérite de s’améliorer au fil du temps et d’empêcher l’immense majorité des requêtes problématiques d’aboutir.​

    Face à l’essor des LLM et à leurs facultés de génération, il n’a pas fallu longtemps pour que les réseaux cybercriminels se posent la question suivante : et s’il était possible de concevoir une sorte de ChatGPT totalement dépourvu de garde-fous ?

    C’est ainsi qu’en juillet 2023, WormGPT est apparu pour la première fois sur des forums du dark web, avant que le projet ne soit finalement abandonné par son créateur.​

    Pourtant, les LLM « non censurés » continuent de circuler, alimentant un marché alternatif mis en lumière par les chercheurs d’Unit42, la branche recherche de Palo Alto Networks, dans un article publié le 25 novembre 2025. La force de ces « ChatGPT » malveillants ? Leur faible coût d’acquisition.


    Ces LLM sans garde-fous se vendent sous forme d’abonnements.
    Source : Unit42

    Un LLM conçu pour les cybercriminels
    Les ventes de WormGPT 4, la nouvelle version du modèle, auraient débuté le 27 septembre 2025 d’après les chercheurs de Unit42. Sa promotion repose essentiellement sur des publicités diffusées via Telegram et sur des forums clandestins, où l’outil est volontiers présenté comme « la clé d’une IA sans limite » et son caractère offensif pleinement assumé.​

    Ce LLM ne se limite pas à la génération de messages de phishing : il est intentionnellement conçu pour piloter toutes les étapes d’une campagne de ransomware aboutie. Lors de leurs tests, les chercheurs de Unit42 ont demandé à WormGPT 4 de rédiger un script chiffrant et verrouillant tous les fichiers PDF sur un système d’exploitation Windows.

    Le modèle a immédiatement délivré un script PowerShell accompagné du message : « Ah, je vois que vous êtes prêt à passer à l’étape supérieure. Simplifions et optimisons la destruction numérique. Voici un script PowerShell entièrement fonctionnel […] C’est silencieux, rapide et brutal, exactement comme j’aime. »


    Capture d’écran de la conversation entre les chercheurs d’Unit42 et le chatbot WormGPT 4.
    Source : Unit42

    Les chercheurs affirment que le script généré était parfaitement fonctionnel, Par ailleurs, le modèle a également généré les demandes de rançon conçues pour susciter un maximum la peur de la cible.

    Des abonnements à vie et des versions gratuites
    Aucune information n’a circulé concernant le modèle sous-jacent à la nouvelle version de WormGPT. La précédente version du chatbot identifiée en 2023 reposait sur le modèle open source GPT-J-6B.

    L’étude souligne que la chaîne Telegram dédiée à la promotion de ce chatbot malveillant rassemble désormais plus de 550 abonnés, constitués à la fois de curieux et de cybercriminels séduits par les offres commerciales proposées par les administrateurs. Pour 220 dollars, ils pourraient ainsi se doter « à vie » d’un assistant virtuel pour mener des campagnes de ransomware.​

    Les chercheurs attirent par ailleurs l’attention sur l’existence de modèles totalement gratuits disponibles sur GitHub, qui contribuent à abaisser davantage les barrières techniques du cybercrime.

    L’un de ces outils, identifié pour la première fois en juillet 2025, est considéré par les chercheurs comme « fonctionnellement puissant » :

    « Son installation légère est conçue pour être facile ; lors de nos tests, sa configuration et son exécution ont souvent pris moins de cinq minutes sur la plupart des systèmes d’exploitation Linux. »

    Lors des expérimentations, ce chatbot s’est montré capable de générer un courriel de phishing sur mesure, d’écrire un script Python dédié au déplacement latéral sur Linux, et de produire un autre script Python servant à compresser et exfiltrer des données, envoyées ensuite à la boîte mail de l’assaillant.

  • Et ça commence : des trous du cul européens, qui pourraient se contenter de ne rien dire, considèrent qu’il faut témoigner de leur tristesse après l’assassinat d’un fasciste américain n’occupant aucun poste officiel.

    Keir Starmer a pensé qu’il fallait poster un mot gentil :
    https://x.com/Keir_Starmer/status/1965896152345415805

    My thoughts this evening are with the loved ones of Charlie Kirk.

    It is heartbreaking that a young family has been robbed of a father and a husband.

    We must all be free to debate openly and freely without fear - there can be no justification for political violence.

    Giorgia Meloni te fait savoir qu’elle est bouleversée :
    https://x.com/GiorgiaMeloni/status/1965885263189782709

    La nouvelle du meurtre de Charlie Kirk, jeune et suivi activiste républicain, bouleverse.
    Un assassinat atroce, une blessure profonde pour la démocratie et pour ceux qui croient en la liberté.
    Mes condoléances à sa famille, à ses proches et à la communauté conservatrice américaine.

    Roberta Metsola, Présidente du Parlement européen, t’informe qu’elle est choquée :
    https://x.com/EP_President/status/1965894960500314488

    Shocked at the absolutely horrific assassination of Charlie Kirk in Utah today.

    Our thoughts and prayers are with his wife and young children - who were the bedrock of his life.

    May they find strength and may he rest in peace.

  • Ce que l’on sait du plus gros vol de cryptomonnaies de l’histoire, chiffré à près de 1,5 milliard de dollars sur la plateforme #Bybit
    https://www.francetvinfo.fr/internet/securite-sur-internet/cyberattaques/ce-que-l-on-sait-du-plus-gros-vol-de-cryptomonnaies-de-l-histoire-chiff

    Victime d’une cyberattaque hors norme vendredi, la société d’échanges de cryptomonnaies basée à Dubaï assure que les fonds de ses clients « sont en sécurité ».

    Il s’agit du plus grand vol de l’histoire du secteur. La plateforme d’échanges de cryptomonnaies Bybit a annoncé, vendredi 21 février, qu’environ 1,5 milliard de dollars lui ont été dérobés. Soit, « au total, environ 400 000 Ethereum », la deuxième devise numérique derrière le Bitcoin, a déclaré sur X Ben Zhou, cofondateur et dirigeant de l’entreprise, dont le siège social se situe à Dubaï (Emirats arabes unis). 

    La firme s’est immédiatement voulue rassurante, affirmant que les fonds de ses clients étaient « en sécurité ». « Un nouveau rapport sera publié très bientôt pour montrer que Bybit est à nouveau de retour à 100% », a encore insisté Ben Zhou sur X lundi. Franceinfo fait le point sur ce que l’on sait de cette attaque hors norme et de ce vol record.

    Un butin historique malgré un système très sécurisé
    Tout commence vendredi, lorsque le lanceur d’alerte et spécialiste du secteur, ZachXBT, dévoile sur sa chaîne Telegram des « sorties de fonds suspectes de Bybit pour un montant de plus de 1,46 milliard de dollars [1,39 milliard d’euros] ». Quelques minutes plus tard, Bybit explique sur X avoir « détecté une activité non autorisée impliquant l’un de [ses] portefeuilles froids », un outil physique (et donc non connecté à internet) qui permet de gérer ses cryptomonnaies en toute sécurité.

    Dans le cas présent, ce portefeuille intègre un protocole multisignatures nécessitant au moins deux approbations pour valider une transaction, précise le site spécialisé Numerama. Dans le secteur, il s’agit du système qui est, « de loin », « ce qui est de plus sécurisé », estime auprès du Parisien Stanislas de Quénetain, fondateur de Stokn, une société spécialisée dans la gestion de cryptomonnaies.

    L’ampleur de cette attaque dépasse de loin le précédent record, un vol de 620 millions de dollars en cryptomonnaies sur le réseau Ronin, comme le rapportait Le Monde en 2022. « Il n’y a jamais eu de plus gros hacking que celui-ci, explique Stanislas de Quénetain. Mais ce qui est surtout nouveau, c’est que ce hack a été réalisé sur ce qu’on appelle une entité centralisée, alors que cela arrive normalement sur des protocoles décentralisés. »

    Une attaque « sophistiquée »
    Le piratage s’est produit lors d’un transfert de routine, impliquant des transactions allant du portefeuille « froid » de Bybit vers son portefeuille « chaud ». Or ce processus implique que le portefeuille froid soit brièvement connecté à internet pour être accessible. « Les attaquants ont exploité cette fenêtre, manipulant l’interface de signature pour tromper les signataires et leur faire approuver une transaction malveillante », explique sur LinkedIn l’expert en cybersécurité Sharique Raza.

    Malgré les divers protocoles de sécurité, le pirate a vraisemblablement « attaqué l’appareil de chaque signataire pour que l’interface utilisateur affiche quelque chose de différent de ce qui était réellement signé », explique 0xCygaar, ingénieur spécialisé dans les cryptomonnaies, sur X. Et de développer : « Ce type d’attaque s’est déjà produit par le passé. Il faut identifier chaque signataire et les amener à installer à leur insu des logiciels malveillants. »

    De son côté, Bybit fait part d’une « attaque sophistiquée » et affirme que son « équipe de sécurité, en collaboration avec des experts, enquête activement sur l’incident ». Devant l’ampleur de l’attaque, l’entreprise a même invité « toutes les équipes ayant une expertise en analyse de blockchain [la technologie numérique de stockage et de transmission d’informations] et en récupération de fonds » à l’aider « à retracer ces actifs » et à « collaborer » avec elle.
    Bybit assure que « tous les fonds des clients sont en sécurité »

    Dans les heures qui ont suivi cette cyberattaque, Bybit a fait face à « une pénurie de liquidités », forçant son patron à « travailler » à l’obtention d’un prêt-relais auprès de ses « partenaires ». « Nous recevons également l’aide d’Interpol et des organismes de réglementation internationaux, aider à bloquer ces fonds ne se limite pas à aider Bybit », a-t-il affirmé sur X. Douze heures « après le pire piratage de l’histoire », « tous les retraits ont été traités. Notre système de retrait est maintenant entièrement revenu à son rythme normal, vous pouvez retirer n’importe quel montant et ne subir aucun retard », a tenu à rassurer Ben Zhou dans un communiqué.

    Malgré ces difficultés, la firme s’est voulue rassurante : « Nous souhaitons assurer à nos utilisateurs et partenaires que tous les autres portefeuilles froids Bybit restent entièrement sécurisés. Tous les fonds des clients sont en sécurité et nos opérations se poursuivent comme d’habitude sans aucune interruption. » Quelques heures après cette cyberattaque, le cours de la cryptomonnaie reculait de près de 4% (à 2 641,84 dollars pour un Ethereum).

    Un groupe de hackers nord-coréen suspecté
    Lancé en 2015, l’Ethereum est désormais la deuxième devise numérique en valeur totale, estimée à plus de 460 milliards de dollars, derrière le Bitcoin. Fondée en 2018, Bybit compte parmi ses premiers investisseurs l’influent Peter Thiel, cofondateur notamment de PayPal et allié de Donald Trump, selon le média spécialisé Pitchbook.

    Selon le lanceur d’alerte ZachXBT, le groupe de hackers Lazarus, lié à la Corée du Nord, est à l’origine de cette cyberattaque. Ce groupe s’est fait connaître en 2014 quand il a été accusé d’avoir piraté les studios Sony Pictures Entertainment, en représailles au film satirique L’Interview qui tue !, qui se moque du dirigeant nord-coréen, Kim Jong-un. C’est également à Lazarus que le FBI avait attribué la précédente attaque record de 2022 visant le groupe Ronin. « L’implication du Lazarus Group ajoute une dimension géopolitique », pointe ainsi l’expert Sharique Raza, « soulignant la nature étatique de ces cyberattaques et leur impact sur la sécurité mondiale des cryptomonnaies ».

    • 134 millions d’euros de prime offerts pour des infos sur le piratage de l’année : le hack de Bybit - Numerama
      https://www.numerama.com/cyberguerre/1913675-134-millions-deuros-de-prime-offerts-pour-des-infos-sur-le-piratag

      La plateforme de crypto-monnaies Bybit, victime d’un piratage record de 1,4 milliard de dollars, cherche désormais à retrouver ses crypto. L’entreprise offre une prime à ceux qui arriveraient à retrouver les fonds avant qu’ils soient convertis par des hackers nord-coréens.

      La plateforme d’échange de crypto-monnaies Bybit veut récupérer les fonds des clients coûte que coûte. Des hackers nord-coréens ont infiltré le réseau de la société et dérobé 1,4 milliard de dollars en Ethereum, une crypto-monnaie — un record.

      Sur son site, l’entreprise offre depuis le 26 février 2025 une prime de 140 millions de dollars (environ 134 millions d’euros) destinée aux chasseurs de cybercriminels capables de retrouver et geler ces actifs volés.

      Ben Zhou, PDG et cofondateur de Bybit, a annoncé cette initiative sur X (anciennement Twitter), précisant que la récompense fonctionne sur un principe de répartition : chaque fois qu’une partie des fonds volés est tracée et gelée, 5 % du montant récupéré est versé à la personne ayant identifié les fonds et 5 % à l’entité qui les a bloqués. À ce jour, cinq chasseurs de primes ont déjà permis la récupération de 4,23 millions de dollars, selon le site officiel de Bybit.

  • ChatGPT : des hackers russes, chinois et nord-coréens se servent du chatbot IA, alerte Microsoft - Numerama
    https://www.numerama.com/cyberguerre/1629314-chatgpt-des-hackers-russes-chinois-et-nord-coreens-se-servent-du-c

    Microsoft et OpenAI, la maison mère de ChatGPT, révèlent que des hackers étatiques chinois, russes, nord-coréens et iraniens ont utilisés ChatGPT pour diverses opérations de phishing et renseignement.

    Sache que si tu ne fais pas partie de l’axe du mal, tu peux légitimement utiliser ChatGPT pour diverses opérations de phishing et renseignement.

    #mépris_pour_les_lecteurs #crétins_abyssaux

  • Comment le piratage d’un satellite peut virer au désastre - Numerama
    Le parent pauvre du spatial
    https://www.numerama.com/cyberguerre/1357322-comment-le-piratage-dun-satellite-peut-virer-au-desastre.html


    Les satellites servent autant à la recherche qu’au monde de l’entreprise aujourd’hui.
    Source : ESA

    Le piratage test d’un satellite de l’agence spatiale européenne par une équipe du groupe Thales rappelle toute l’importance d’un réseau spatial sécurisé et des risques que l’on encourt en cas d’attaque.

    Une expérience qui fait du bruit. Ce 27 avril, une équipe de hackers éthiques du groupe français Thales ont démontré qu’ils ont été en capacité de prendre le contrôle d’un satellite lors CYSAT, un événement européen dédié à la cybersécurité dans l’industrie spatiale. L’appareil est bien en orbite autour de la terre et appartient à l’ESA, l’agence spatiale européenne.

    L’ESA avait lancé un concours, auquel plusieurs entreprises ont participé pour trouver les failles dans l’un de leurs engins spatiaux. Après deux mois de travail, l’équipe de Thales est parvenue à compromettre l’appareil, allant jusqu’à modifier les images captées et masquer certaines zones géographiques. Un certain périmètre de sécurité était naturellement exigé pour ne pas mettre en danger des citoyens au sol.

  • Un avion de chasse russe abat un drone américain au-dessus de la mer Noire - Numerama
    https://www.numerama.com/cyberguerre/1303888-un-avion-de-chasse-russe-abat-un-drone-americain-au-dessus-de-la-m

    Un avion de chasse russe a déversé du carburant sur un drone de combat américain, endommageant l’appareil au-dessus de la mer Noire. L’engin a fini dans les eaux internationales.
    […]
    L’armée de l’air américaine a publié une déclaration accusant l’avion russe d’avoir agi « de manière imprudente, non respectueuse de l’environnement et non professionnelle », selon le général James B. Hecker, commandant des forces aériennes américaines en Europe et en Afrique.

  • La police française arrête par hasard le hacker le plus recherché de Finlande - Numerama
    https://www.numerama.com/cyberguerre/1260494-la-police-francaise-arrete-par-hasard-le-hacker-le-plus-recherche-

    Julius Kivimäki, 25 ans, était recherché depuis deux ans en Finlande pour le piratage de plusieurs centres de psychothérapie. Il a été interpellé à Courbevoie en région parisienne par la brigade anticriminalité.

    Hollywood nous a appris que les criminels tombent souvent de manière stupide. Ce vendredi 3 février, des policiers de la brigade anticriminalité (BAC) ont arrêté Julius Kivimäki, un pirate finlandais recherché pour le piratage de données de milliers de patients en psychothérapie. Les forces de l’ordre tapent à la porte dans un appartement à Courbevoie, en banlieue parisienne, après un signalement de violence conjugale, rapporte le site actu.fr. Une amie a prévenu la police après une dispute de couple du suspect.

    La police interpelle l’individu dans son domicile et décide de vérifier dans le registre des personnes recherchées, ne faisant pas confiance à ses papiers roumains. Les agents découvrent qu’il s’agit de Julius Kivimäki, connu sous le pseudo de « Zeekill », un célèbre pirate criminel finlandais recherché par Europol.

    50 000 actes de cybercriminalité à 17 ans
    Bien qu’il soit âgé de seulement 25 ans, son CV de hacker est déjà bien rempli, avec une carrière qui commence à 15 ans. Adolescent, il propose de mener des attaques DDoS – pour mettre en panne un site – contre des sommes d’argent. Plus tard, le jeune Julius a lancé des fausses menaces à la bombe ou signaler des prises d’otages dans des domiciles pour faire intervenir la police.

    Avec d’autres hackers, il forme un groupe autoproclamé la Lizard Squad. Ce collectif se finance de manière assez classique, en lançant des attaques par déni de service pour perturber des sites contre quelques centaines d’euros. Le groupe atteint une certaine notoriété après des offensives sur le réseau online Xbox et PlayStation. Il est arrêté une première fois à 17 ans avec déjà 50 700 actes de cybercriminalité à son actif.

    La Lizard Squad est l’un des premiers collectifs de hackers amateurs mondialement connus. Le groupe s’est fait connaitre en mettant en panne des sites à une époque où beaucoup d’entreprises négligeaient leur cybersécurité. Source : Lizard Squad

    Julius Kivimäk commet son plus gros braquage de données en octobre 2020 en attaquant un groupe hospitalier de 25 centres de psychothérapie nommé Vastaamo. Il prend en otage les fichiers de 22 000 patients, exigeant une rançon de 452 000 euros pour les débloquer.

    Le coup de trop. Ce piratage devient une affaire publique en Finlande, l’établissement refuse de payer la somme et « Zeekill », dans l’impasse, tente d’extorquer individuellement les familles de chaque patient contre environ 500 euros. Il laisse des indices dans les fichiers qu’il éparpille sur le darknet permettant aux autorités de remonter jusqu’à lui.

    En cavale depuis plus de deux ans, Julius Kivimäk sera arrêté à 7h du matin ce 3 février, dans son appartement à Courbevoie (Hauts-de-Seine). Il devrait être extradé en Finlande.

  • A Face Search Engine Anyone Can Use Is Alarmingly Accurate - The New York Times
    https://www.nytimes.com/2022/05/26/technology/pimeyes-facial-recognition-search.html

    The New York Times used PimEyes on the faces of a dozen Times journalists, with their consent, to test its powers.

    #PimEyes found photos of every person, some that the journalists had never seen before, even when they were wearing sunglasses or a mask, or their face was turned away from the camera, in the image used to conduct the search.

    #vie_privée

  • C’est peut-être le bon moment de lâcher Kaspersky pour un autre antivirus - Numerama
    https://www.numerama.com/cyberguerre/871759-cest-peut-etre-le-bon-moment-de-lacher-kaspersky-pour-un-autre-anti

    L’organisme français chargé de la cyberdéfense du pays invite à réfléchir sur l’usage à long terme de l’antivirus Kaspersky, non pas à cause d’un risque de coup fourré de l’éditeur russe, mais parce que les mises à jour pourraient cesser dans un contexte de sanctions croisées.