Some background, I was a hacker for 15 years and survived some heinous shit including attempts of doxing by class enemies and actually being hunted by feds. But one of the techniques keeps coming back from the death all those decades is Electron web app framework HTTP leak. It’s a very simple 0day but niche to the point that Electron devs somehow can’t patch it. What this HTTP leak attack does is it allow traffic from an app client to be traced as soon as the attacker made contact with the client network server. Electron leaks both private and public IP addresses of user. You can demonstrate this yourself with just a reddit app and chat function, and tracert. It’s a trivia bug but if you have heard of things like Xbox, psn or steam resolver, it’s basically just Electron HTTP leak attack. And it costs actual thousands of human lives in both global south, and in US especially the Andrew Finch murder in Wichita because the doxer used resolver. And that’s a thing, once you get the IP, you can locate the target’s ISP narrowing down the subnet of it. But because Palestine subnet is significantly smaller than US, Zionist and American intelligence can just increase accuracy through host discovery or ping scanning to correlate all connected targets in the same network pinpoint exact device Electron leaking. Please consider this in your opsec.

  • he/him lady@lemmygrad.ml
    link
    fedilink
    arrow-up
    18
    ·
    5 days ago

    remember: “leave your phone at home”. and to the best of our abilities, form a network of friends and "guy who knows a guy"s when it comes to getting to and fro and sharing information (assuming the ultimate reason one needs their phone on them is for transportation and personal safety). it sucks so bad but us revolutionaries and leftists in 2025 [onward] have been embargoed as it were regarding mainstream technology and internet usage as a whole. it complicates praxis and is very obviously much manufactured by Western imperial forces.