Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mastodon.social/@jsrailton" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>jsrailton</span></a></span> <a href="https://infosec.space/tags/Govware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Govware</span></a> like <a href="https://infosec.space/tags/Pegasus" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Pegasus</span></a> isn't something that can be fixed outside of extensive <a href="https://infosec.space/tags/ITsec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ITsec</span></a>, <a href="https://infosec.space/tags/InfoSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InfoSec</span></a>, <a href="https://infosec.space/tags/OpSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpSec</span></a> & <a href="https://infosec.space/tags/ComSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ComSec</span></a> workups.</p><p>In fact it's easier to bootstrap an entirely new identity than trying to uninstall such persistent shite!</p><p>That being said, <a href="https://infosec.space/tags/VPN" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VPN</span></a> providers are just the newest <a href="https://infosec.space/tags/DigitalSnakeoil" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DigitalSnakeoil</span></a> sales reps and everything against them applies to <a href="https://infosec.space/tags/Antivirus" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Antivirus</span></a> as well...</p><p>So sad that <span class="h-card" translate="no"><a href="https://mastodon.social/@tomscott" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>tomscott</span></a></span> was just <a href="https://www.youtube.com/watch?v=WVDQEoe6ZWY" rel="nofollow noopener" target="_blank">naively debunking</a> them years ago...</p><p>The constant <a href="https://infosec.space/tags/disinfo" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>disinfo</span></a> sown by VPN and <a href="https://infosec.space/tags/AV" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AV</span></a> providers is so rampant that I'd not be surprised if one day <em>both</em> would finally be made illegal <em>for all the right reasons</em>:</p><ul><li><p>A VPN <a href="https://mobile.twitter.com/thegrugq/status/1085614812581715968" rel="nofollow noopener" target="_blank">won't save peoples asses from getting jailed</a> !</p></li><li><p>Any 3rd party <a href="https://infosec.space/tags/Kernelhack" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Kernelhack</span></a>-<a href="https://infosec.space/tags/BinaryBlob" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BinaryBlob</span></a> won't make one's <a href="https://infosec.space/tags/backdoored" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>backdoored</span></a> with Govware OS (regardless if <a href="https://infosec.space/tags/Windows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows</span></a> or <a href="https://infosec.space/tags/macOS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>macOS</span></a>) more secure, but rather less secure!</p></li><li><p>It should be the sole responsibility of the OS/Distro maintainers to make them secure by default, espechally on <a href="https://infosec.space/tags/iOS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>iOS</span></a> and <a href="https://infosec.space/tags/Android" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Android</span></a> where users don't have administrative / <a href="https://infosec.space/tags/root" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>root</span></a> privilegues!</p></li></ul>