<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="4.2.2">Jekyll</generator><link href="https://old.interferencias.tech/feed.xml" rel="self" type="application/atom+xml" /><link href="https://old.interferencias.tech/" rel="alternate" type="text/html" /><updated>2023-03-08T00:56:40+01:00</updated><id>https://old.interferencias.tech/feed.xml</id><title type="html">Interferencias</title><subtitle>Asociación ciberactivista en defensa de la privacidad en Internet y los derechos digitales promoviendo el uso de software libre. Seguridad informática para la reivindicación.</subtitle><author><name>Interferencias</name><email>info@interferencias.tech</email></author><entry><title type="html">Publicados los vídeos de esLibre 2021</title><link href="https://old.interferencias.tech/2021/11/02/videos-eslibre2021/" rel="alternate" type="text/html" title="Publicados los vídeos de esLibre 2021" /><published>2021-11-02T00:00:00+01:00</published><updated>2021-11-02T00:00:00+01:00</updated><id>https://old.interferencias.tech/2021/11/02/videos-eslibre2021</id><content type="html" xml:base="https://old.interferencias.tech/2021/11/02/videos-eslibre2021/"><![CDATA[<p><img src="https://old.interferencias.tech/assets/images/eslibre/2021/banner_anuncio.png" style="display: block; margin: 0 auto;" /></p>

<p>
Ya están disponibles los vídeos de nuestra sala "Derechos Digitales y Privacidad en Internet + Soberanía Digital en las Aulas (Fuera Google)" de esta edición de <strong>es<span style="color:red">Libre</span></strong>: podéis encontrarlos junto con el resto de <a href="https://commons.wikimedia.org/wiki/Category:EsLibre_2021" target="_blank"> vídeos de esta edición en Wikimedia Commons</a>.
</p>

<p>
Aunque también podeis encontrarlos con todo detalle de información en la página correspondiente que creamos aquí, así que simplemente os dejamos un enlace allí para que podáis echarle un ojo.
</p>

<h3>➡️ <a href="https://old.interferencias.tech/eslibre/2021">Sala esLibre 2021: Derechos Digitales y Privacidad en Internet + Soberanía Digital en las Aulas (Fuera Google)</a></h3>]]></content><author><name>Germán</name><email>germaaan@interferencias.tech</email></author><category term="eventos" /><category term="privacidad" /><category term="seguridad" /><summary type="html"><![CDATA[]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://old.interferencias.tech/%7B%22feature%22=%3E%22banners/header.jpg%22%7D" /><media:content medium="image" url="https://old.interferencias.tech/%7B%22feature%22=%3E%22banners/header.jpg%22%7D" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Envío de propuestas para la sala “Derechos Digitales y Privacidad en Internet + Soberanía Digital en las Aulas (Fuera Google)”</title><link href="https://old.interferencias.tech/2021/04/07/eslibre2021/" rel="alternate" type="text/html" title="Envío de propuestas para la sala “Derechos Digitales y Privacidad en Internet + Soberanía Digital en las Aulas (Fuera Google)”" /><published>2021-04-07T00:00:00+02:00</published><updated>2021-04-07T00:00:00+02:00</updated><id>https://old.interferencias.tech/2021/04/07/eslibre2021</id><content type="html" xml:base="https://old.interferencias.tech/2021/04/07/eslibre2021/"><![CDATA[<p><img src="https://old.interferencias.tech/assets/images/eslibre/2021/eslibre_2021_small.png" style="display: block; margin: 0 auto;" /></p>

<p>
Otro año más volvemos a sumarnos a colaborar en la organización de otra edición de <strong>es<span style="color:red">Libre</span></strong> y proponer una sala para el programa de la misma. Este año, a diferencia de los anteriores, estamos buscando centrarnos más en las temáticas de derechos digitales y privacidad en Internet.
</p>

<p>
También queremos intentar organizar algunas actividades que pongan el foco sobre el problema de la continua "invasión" por parte de las grandes compañías de Internet en el funcionamiento de las aulas de escuelas e institutos, algo que se ha visto acrecentado enormemente por la situación sanitaria actual y que sin duda le ha dado todavía más poder a empresas de conocida y cuestionable ética como Google.
</p>

<p>
Si tienes algo que decir sobre algunos de estos temas, ¡no dudes en mandarnos cualquier propuesta! Los formularios de envío puedes encontrarlos en la página que hemos añadido con toda la información:
</p>

<h3>➡️ <a href="https://old.interferencias.tech/eslibre">Sala Derechos Digitales y Privacidad en Internet + Soberanía Digital en las Aulas (Fuera Google)</a></h3>]]></content><author><name>Germán</name><email>germaaan@interferencias.tech</email></author><category term="eventos" /><category term="privacidad" /><category term="seguridad" /><summary type="html"><![CDATA[]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://old.interferencias.tech/%7B%22feature%22=%3E%22banners/header.jpg%22%7D" /><media:content medium="image" url="https://old.interferencias.tech/%7B%22feature%22=%3E%22banners/header.jpg%22%7D" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Publicados los vídeos de esLibre 2020</title><link href="https://old.interferencias.tech/2020/11/30/eslibre2020/" rel="alternate" type="text/html" title="Publicados los vídeos de esLibre 2020" /><published>2020-11-30T00:00:00+01:00</published><updated>2020-11-30T00:00:00+01:00</updated><id>https://old.interferencias.tech/2020/11/30/eslibre2020</id><content type="html" xml:base="https://old.interferencias.tech/2020/11/30/eslibre2020/"><![CDATA[<p><img src="https://old.interferencias.tech/assets/images/eslibre/eslibre_2020.jpg" style="display: block; margin: 0 auto;" /></p>

<p>
Ya os comentamos que este año dada la situación actual no pudimos celebrar las <strong>JASYP</strong>, pero eso no impidió organizar algo en su lugar. Aprovechando que la edición de este año de <strong>es<span style="color:red">Libre</span></strong> se realizó de forma online, organizamos una sala sobre <strong>Derechos Digitales, Privacidad en Internet y Seguridad Informática</strong>.
</p>

<p>
Todos los detalles ya los explicamos en su página correspondiente, así que simplemente os dejamos un enlace allí para que podáis echarle un ojo.
</p>

<h3>➡️ <a href="https://old.interferencias.tech/eslibre/2020">Sala Derechos Digitales, Privacidad en Internet y Seguridad Informática</a></h3>]]></content><author><name>Germán</name><email>germaaan@interferencias.tech</email></author><category term="eventos" /><category term="privacidad" /><category term="seguridad" /><summary type="html"><![CDATA[]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://old.interferencias.tech/%7B%22feature%22=%3E%22banners/header.jpg%22%7D" /><media:content medium="image" url="https://old.interferencias.tech/%7B%22feature%22=%3E%22banners/header.jpg%22%7D" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Sala esLibre 2020&amp;amp;#58 Derechos Digitales, Privacidad en Internet y Seguridad Informática</title><link href="https://old.interferencias.tech/2020/08/15/eslibre2020/" rel="alternate" type="text/html" title="Sala esLibre 2020&amp;amp;#58 Derechos Digitales, Privacidad en Internet y Seguridad Informática" /><published>2020-08-15T00:00:00+02:00</published><updated>2020-08-15T00:00:00+02:00</updated><id>https://old.interferencias.tech/2020/08/15/eslibre2020</id><content type="html" xml:base="https://old.interferencias.tech/2020/08/15/eslibre2020/"><![CDATA[<p><img src="https://old.interferencias.tech/assets/images/eslibre/eslibre_2020.jpg" style="display: block; margin: 0 auto;" /></p>

<p>
Desde <strong>Interferencias</strong> siempre nos gusta colaborar en iniciativas que nos parecen interesantes, y es por eso que tanto el <a href="https://eslib.re/2019/" target="_blank">año pasado</a> como <a href="https://eslib.re/2020/" target="_blank">este año</a> estamos colaborando en la organización de <strong>es<span style="color:red">Libre</span></strong>: un encuentro de personas interesadas en el conocimiento y la difusión del las <em>tecnologías libres y cultura abierta</em>. Concretamente <strong>la edición de este año será totalmente online los días 18 y 19 de septiembre</strong>, coincidiendo con el <strong>"<a href="https://www.softwarefreedomday.org/" target="_blank">Software Freedom Day</a>"</strong> (<em>que además, también es el cumpleaños oficioso de Interferencias</em> 🌚).
</p>

<p>
Como ya sabréis, este año finalmente no pudimos realizar nuestras <strong><a href="https://old.interferencias.tech/jasyp" target="_blank">JASYP '20</a></strong> debido a la situación actual, y ya que todos los años planteamos las Jornadas como una celebración donde compartir experiencias y conocimiento con la espontaneidad del trato en persona decidimos que no tendría sentido celebrarlas de forma online porque perdería su significado; <em>no se trata de ser otro congreso, se trata de ser una experiencia aprovechando todo lo que nos brinda Granada</em>.
</p>

<p>
Por todo esto que comentamos, finalmente hemos decidido presentar una <strong>propuesta de sala</strong> dentro del programa de <strong>es<span style="color:red">Libre</span></strong> para seguir llegando a tanta gente como sea posible. En un momento en el que las grandes compañías tecnológicas se frotan las manos pensando en todo el <em>beneficio que podrán sacar de nuestros datos</em> o el peligro que puede entrañar la tecnología más inocente del mundo si se le da usos con objetivos cuestionables (o peor, inconscientes), es más necesario que nunca disponer del conocimiento sobre cómo funcionan las tecnologías que está tan integradas en nuestro día a día que nos rodean de forma casi inapreciable.
</p>

<blockquote>
<strong>Hoy más que nunca debemos ser conscientes de la necesidad de proteger nuestra privacidad y nuestra soberanía digital</strong>: tenemos que saber <strong>QUÉ</strong> tenemos a nuestra disposición y <strong>CÓMO</strong> podemos actuar; y esto, sin duda alguna, es algo que viene de la mano del <strong>Software Libre</strong>.
</blockquote>

<p>
El planteamiento del contenido será muy parecido al que hacemos en las JASYP, pero con un formato distinto:
</p>

<h2 style="text-align: center;" id="programa">esLibre 2020: "Derechos Digitales, Privacidad en Internet y Seguridad Informática"</h2>
<h3 style="text-align: center;">Viernes 18 de septiembre</h3>

<h3 id="inicio">12:30-12:40 Presentación 'Sala Derechos Digitales, Privacidad en Internet y Seguridad Informática'</h3>

<p><strong>Germán Martínez</strong>: Ingeniero informático, activista por los derechos digitales y el software libre, coordinador en <strong>Interferencias</strong> y <a href="https://librelabgrx.cc/" target="_blank"><strong>LibreLabGRX</strong></a> y parte del equipo de organización de <a href="https://eslib.re/" target="_blank"><strong>esLibre</strong></a>.</p>

<ul>
  <li>Puedes encontrarle en Mastodon como <a href="https://mastodon.social/@germaaan_/" target="_blank">@germaaan_@mastodon.social</a> y en Twitter como <a href="https://twitter.com/germaaan_" target="_blank">@germaaan_</a>.</li>
</ul>

<h3 id="primera">12:40-13:10 Herramientas para mantener tu privacidad en Internet</h3>

<p><strong>Pablo Castro</strong>: activista del software libre y la libertad en Internet. Forma parte de la asociación <a href="https://trackula.org/" target="_blank"><strong>Trackula</strong></a> y se encarga de <a href="https://www.techtopias.com/" target="_blank"><strong>Techtopias</strong></a>, una newsletter quincenal sobre privacidad, soberanía digital y libertad en internet para estar al día de las noticias mas interesantes de este mundillo.</p>

<ul>
  <li>Puedes encontrarle en Mastodon como <a href="https://mastodon.social/@castrinho8/" target="_blank">@castrinho8@mastodon.social</a> y en Twitter como <a href="https://twitter.com/castrinho18" target="_blank">@castrinho18</a>.</li>
</ul>

<blockquote>
En pleno 2020, muchas grandes empresas tecnológicas basan su modelo de negocio en vender nuestra vida privada, nuestra forma de ser, qué vamos a ser en el futuro, llegando incluso a manipularnos.
<br /><br />En esta charla veremos rápidamente los peligros a los que se enfrenta la sociedad tecnológica actual y qué herramientas podemos tener e instalar de forma sencilla para intentar reducir la información que generamos a diario y así luchar por preservar nuestra privacidad.
</blockquote>

<h3 id="segunda">13:10-13:45 Self Sovereign Identity: identidad bajo el control de las personas</h3>

<p><strong>Jorge Cuadrado</strong>: investigador en ciberseguridad en el laboratorio de innovación de <strong>BBVA Next Technologies</strong>. Estudió Ingeniería Informática en la Universidad de Valladolid (UVA) y el Máster en Ciberseguridad de la Universidad Carlos III de Madrid (UC3M). Ha participado como ponente en múltiples congresos como: Cybercamp, RootedCon, Hack In The Box, X1RedMásSegura o <strong>JASYP</strong>. Sus focos de interés, sobre los que siempre tiene algún proyecto en marcha, son: privacidad, impresión 3D y electrónica.</p>

<ul>
  <li>Puedes encontrarle en Twitter como <a href="https://twitter.com/Coke727" target="_blank">@coke727</a> y su web personal <a href="https://www.croke.es" target="_blank">https://www.croke.es</a>.</li>
</ul>

<blockquote>
Self Sovereign Identity (SSID) es un sistema de identificación que ha surgido recientemente y que, conceptualmente, cambia significativamente respecto a modelos más tradicionales de identificación.
<br /><br />Mediante este esquema, las personas adquieren la responsabilidad de gestionar cómo y en qué cantidad se usan sus datos personales. Para ello, permite crear “tarjetas de identidad” digitales que pueden ser generales para cualquier servicio o específicas para cada caso. Pero… ¿qué ventajas y peligros hay detrás de SSID?
</blockquote>

<h3 id="tercera">16:00-16:25 ¿Existe vacuna para los sesgos en las inteligencias artificiales?</h3>

<p><strong>Emma Lopez</strong>:</p>

<ul>
  <li>Puedes encontrarle en Twitter como <a href="https://twitter.com/hell03610/" target="_blank">@hell03610</a>.</li>
</ul>

<blockquote>
Los humanos tenemos sesgos y parece que las máquinas inteligentes también, pero, ¿se trata esto de una feature o de un bug?
<br /><br />En esta charla veremos qué son las llamadas inteligencias artificiales y qué son los sesgos, por qué es tal fácil que permeen en el software, cuál es su impacto y qué podemos hacer para detectarlos y mitigarlos.
</blockquote>

<h3 id="cuarta">16:25-16:40 Fact-checking y fake news: caja de herramientas ciudadana para la verificación</h3>

<p><strong>Javier Cantón</strong>: sociólogo y comunicador audiovisual. Doctor en Ciencias Sociales, ha impartido docencia en las Universidades de Jaén, Granada, UNIR, Girona y UOC, así como diversos talleres y colaboraciones sobre pensamiento visual y visualización de datos. Investiga sobre desigualdad, redes sociales, visualidad y, más recientemente, desinformación y fake news, tema sobre el que ha elaborado material docente para una asignatura universitaria. Actualmente trabaja en <a href="https://medialab.ugr.es" target="_blank"><strong>Medialab UGR</strong></a>, coordinando <a href="https://medialab.ugr.es/proyectos/radiolab-ugr/" target="_blank"><strong>RadioLab UGR</strong></a> entre otros proyectos, e imparte docencia en UNIR y UOC.</p>

<ul>
  <li>Puedes encontrarle en Twitter como <a href="https://twitter.com/ProsumidorSoc" target="_blank">@ProsumidorSoc</a> y en su página web personal <a href="javiercanton.com" target="_blank">javiercanton.com</a>.</li>
</ul>

<blockquote>
Saturados de información y desconfianza, resulta cada vez más complicado discernir la información cierta de la falsa. La proliferación de las denominadas fake news está reconfigurando la esfera pública y los cauces de formación de la opinión pública, lo que supone un reto para nuestras democracias, que se fundamentan en el acceso a una información veraz para sus ciudadanos.
<br /><br />En este taller aprenderás diferentes métodos y herramientas libres para verificar la procedencia de una noticia y luchar contra las fake news y los bulos.
</blockquote>

<h3 id="quinta">16:40-17:15 Social Justice Code Repositories</h3>

<p><strong>Lorena Sánchez</strong>: Consultora de seguridad y cumplimiento en <strong>ElevenPaths</strong>. Jurista y politóloga por la Universidad Carlos III de Madrid. Máster en Gobierno de las Telecomunicaciones por la London School of Economics. Especialista en Derecho Tecnológico e Informática Forense. Editora del medio de análisis político y social <a href="https://polikracia.com/" target="_blank"><strong>Polikracia</strong></a>. Ha centrado su carrera profesional en la seguridad en organizaciones, aunque está especializada en derecho tecnológico, protección de datos, seguridad informática y su relación con las ciencias sociales y el derecho. En este sentido, investiga la interrelación entre política y tecnología desde distintos planos como los derechos fundamentales, la privacidad o las relaciones internacionales. Algunos de sus proyectos versan sobre infraestructuras críticas y seguridad internacional; seguridad y privacidad en sistemas de voto electrónico o la concepción de la privacidad en el plano social.</p>

<ul>
  <li>Puedes encontrarle en Twitter como <a href="https://twitter.com/LastStrawberry" target="_blank">@LastStrawberry</a>.</li>
</ul>

<blockquote>
¿Garantiza el software libre que el usuario sea libre? ¿Son necesarios y suficientes los principios del FSM para garantizar la justicia? ¿Cuál es el rol de los repositorios de código en la promoción de la justicia en el software? Estas son algunas de las preguntas que intentaremos desgranar en la charla con el propósito principal de analizar bajo qué condiciones el Free Software Movement funciona para alcanzar la justicia en la producción, uso y consumo de software. Así, la base de la charla será retar el funcionamiento de las tesis de Richard Stallman como teoría, poniendo en valor el rol de los repositorios de código abierto y buscando los puntos débiles que deben ser mejorados.
<br /><br />Si bien la charla presenta un punto de vista teórico, pretende ponerle sentido al FSM a través de diferentes teorías de la justicia preguntándose cómo el FSM puede ser clave en la libertad del usuario sin quedarse en papel mojado.
</blockquote>

<h3 id="sexta">17:30-17:55 Software Libre para las personas</h3>

<p><strong>Paula de la Hoz</strong>: Co-fundadora de <strong>Interferencias</strong>. Senior Red Team en <strong>Telefónica Ingeniería de Seguridad</strong>.</p>

<ul>
  <li>Puedes encontrarle en Mastodon como <a href="https://cybre.space/@terceranexus6" target="_blank">@terceranexus6@cybre.space</a> y en Twitter como <a href="https://twitter.com/Terceranexus6" target="_blank">@Terceranexus6</a>.</li>
</ul>

<blockquote>
Desde su origen, el Software Libre está ligado a la comunidad, a ser partícipe de proyectos con el ánimo de que lleguen a otras manos, las que sean, y sigan mejorando.
<br /><br />En la actualidad, desde asociaciones hasta grupos de vecinos se enfrentan a diario a un mundo ya protagonizado por la tecnología, y es aquí donde el software libre debería ser una herramienta esencial que defienda los intereses de las personas sin que ello suponga ceder seguridad y privacidad.
<br /><br />En esta charla pretendo presentar las posibles soluciones libres para las necesidades de asociaciones y otras comunidades, entre ellas <a href="https://gitlab.com/terceranexus6/barriocheck" target="_blank">BarrioCheck</a>, un proyecto para alertas de barrios basado en OSM que desarrollé hace poco y que pretende dar comienzo en Madrid.
<br /><br />Durante la charla pretenden cubrirse los siguientes temas: comunicación segura y libre, hardening básico e introducción a sysadmin de comunidades, instrucciones y recursos para nivel de usuario para miembros no técnicos, BarrioCheck, hardware y software libre para centros/bibliotecas/radios sociales; entre otros.
</blockquote>

<h3 id="septima">17:55-18:20 Hacktivismo no es nombre de señora</h3>

<p><strong>Sofía Prósper</strong>: Defensora de la privacidad, arquitecta e ilustradora. Forma parte de la asociación <a href="https://trackula.org/" target="_blank"><strong>Trackula</strong></a> y actualmente se encuentra construyendo <a href="https://iuvia.io" target="_blank"><strong>IUVIA</strong></a>, ambos proyectos centrados en la defensa de la privacidad en Internet.</p>

<ul>
  <li>Puedes encontrarle en Twitter como <a href="https://twitter.com/sofipros" target="_blank">@sofipros</a>.</li>
</ul>

<blockquote>
Viviendo el año más extraño de nuestras vidas, este atípico 2020 nos deja con nuestros derechos digitales afectados y con unos precedentes en solucionismo tecnológico que nadie hubiera imaginado si una pandemia no los hubiera instaurado velozmente.
<br /><br />El capitalismo de la vigilancia es sólo un síntoma de un sistema económico y político funcionando como se espera. Por eso es el momento idóneo para movernos, para investigar, para estar informadas y no parar de defender nuestras libertades antes de que la tecnología ‘nos venga a salvar’.
<br /><br />En esta charla nos gustaría, a parte de hacer una pequeña introducción de cuál es el estado actual de las cosas, mostrar proyectos e iniciativas que no se han rendido al ‘yo no tengo nada que esconder’ y siguen al pie del cañón llegando cada día a más gente.
</blockquote>

<h3 id="octava">18:20-18:45 ¿Hacia un feudalismo de los datos?¿Derecho o tecnología?¿Cómo defendernos?</h3>

<p><strong>Luis Fajardo</strong>: de perfil claramente universitario, ha sido juez y abogado. Fue responsable de las redes de la Facultad de Derecho de la UAM en los años 90, siendo becario de Formación de Profesorado Universitaario (FPI/FPU). Ha impartido docencia en las Universidades Autónoma de Madrid, Almería, Gerona, UNED y La Laguna, donde lo sigue haciendo en la actualidad, adscrito al Área de Derecho civil. Ha sido fundador de varias aociaciones, entre ellas el <strong>Centro de Alternativas Legales</strong>, y miembro de <strong>Madrid Wireless</strong>, el <a href="https://www.gulic.org/" target="_blank"><strong>Grupo de Usuario Linux de Canarias (GULiC)</strong></a>, Secretario de ESLIC (Empresas de Software Libre de Canarias), y la <a href="https://www.ull.es/servicios/osl/" target="_blank"><strong>Oficina del Software Libre de la ULL</strong></a>, con la que viene colaborando desde hace muchos años. Desde 1999 usa exclusivamente GNU/Linux en sus sistemas. Mantiene y administra diversos nodos del Fediverso, como <a href="https://encanarias.info/" target="_blank">https://encanarias.info</a> (<strong>Diaspora</strong>) y <a href="https://silba.me/" target="_blank"><strong>Silba.Me</strong></a> (<strong>Mastodon</strong>).</p>

<ul>
  <li>Puedes encontrarle en Diaspora desde <a href="https://encanarias.info/people/56066f30d1620135a1394b44294f2d2e" target="_blank"> encanarias.info</a>, en Mastodon como <a href="https://silba.me/@lfajardo" target="_blank">@lfajardo@silba.me</a> y en Twitter como <a href="https://twitter.com/lfajardo" target="_blank">@lfajardo</a>.</li>
</ul>

<blockquote>
La Administración está llena de malas prácticas, el mercado está dirigido a primar la corporocracia, que está sustituyendo a la democracia.
<br /><br />El Fediverso, las redes federadas, y los servicios libres (que pueden ser instalados “on premise”), pero no parecen suficientes. Realmente tenemos normas que intentan limitar el avance de la corporocracia, fundamentalmente el RGPD. Lamentablemente no se está usando, y debe lanzarse un aviso a navegantes.
<ul>
<li>Cómo nos enganchan: dispositivos que no obedecen a sus dueños, redes sociales que polarizan, manipulación informativa e información individualizada…</li>
<li>Cómo defenderse: elección de los servicios con unos parámetros técnicos (arranque libre, open source, interoperable, estándar y federado…) y jurídicos (que permite exigir aquellos criterios técnicos, básicamente, RGPD).</li>
</ul>
</blockquote>

<h1 style="text-align: center;">#somosruido 💻✊📣</h1>

<figure>
 <img src="/assets/images/jasyp/18/mosaico.jpg" alt="Mosaico JASYP '17" style="width:100%" />
 <figcaption style="text-align: center; padding-top: 0em"><strong>JASYP '17</strong></figcaption>
</figure>

<figure>
 <img src="/assets/images/jasyp/18/charlas/mosaico_v.jpg" alt="Mosaico JASYP '18" style="width:100%" />
 <figcaption style="text-align: center; padding-top: 0em"><strong>JASYP '18</strong></figcaption>
</figure>

<figure>
 <img src="/assets/images/jasyp/20/mosaico_jasyp_2019_small.png" alt="Mosaico JASYP '19" style="width:100%" />
 <figcaption style="text-align: center; padding-top: 0em"><strong>JASYP '19</strong></figcaption>
</figure>]]></content><author><name>Germán</name><email>germaaan@interferencias.tech</email></author><category term="eventos" /><category term="privacidad" /><category term="seguridad" /><summary type="html"><![CDATA[]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://old.interferencias.tech/%7B%22feature%22=%3E%22banners/header.jpg%22%7D" /><media:content medium="image" url="https://old.interferencias.tech/%7B%22feature%22=%3E%22banners/header.jpg%22%7D" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Safety on the streets with Python</title><link href="https://old.interferencias.tech/2020/07/23/safety-on-streets-python/" rel="alternate" type="text/html" title="Safety on the streets with Python" /><published>2020-07-23T00:00:00+02:00</published><updated>2020-07-23T00:00:00+02:00</updated><id>https://old.interferencias.tech/2020/07/23/safety-on-streets-python</id><content type="html" xml:base="https://old.interferencias.tech/2020/07/23/safety-on-streets-python/"><![CDATA[<p><img src="https://old.interferencias.tech/assets/images/dev.to/200723/01.jpg" style="display: block; margin: 0 auto;" /></p>

<p>For a few years I’ve been thinking in ways tech could help neighbourhoods into becoming more safe taking advantage of the people collaboration. It first came to me after realizing a neighbour a loved in my home town had some communication problems with the essential services. The whole idea of mine is logistically difficult to perform as so I ended up just theorising for a long time without actually writing a single line of code for that idea. Recently, after a discussion in <a href="https://joinmastodon.org">Mastodon</a>, I realized <strong>there are some tiny goals to make public spaces safer</strong> and that we could start from there.</p>

<p><img src="https://old.interferencias.tech/assets/images/dev.to/200723/02.gif" style="display: block; margin: 0 auto;" /></p>

<p>I’ve been curious about <strong>Open Street Map</strong> for a while, so I decided I could work in my spare time between projects in a simple python code that created a OSM with marks. The whole idea was to create a launching portal (static, at first) with a map-launching button, and the map contains marks with dangers around the neighbourhood. The warnings could be from to broke asphalt to unsafe LBGTIQ spaces. Or! in a more positive sight, safe spaces! (<strong>safe LBGTIQ</strong> shops and meeting points, <strong>feminist friendly</strong> spaces, etc) as well as identifying trigger spaces such as betting places/alcohol stores. It kind of depends on the needs of each neighbourhood. It only needs a JSON (there’s an example already) where you have to set location and the advise.</p>

<p><img src="https://old.interferencias.tech/assets/images/dev.to/200723/03.gif" style="display: block; margin: 0 auto;" /></p>

<p>The idea is for the people to be able to upload information through <strong>email or hashtags</strong>, some people already suggested to add a form and some of them are planning on merge request that option. I’m so happy about how many people from my city wanted to help as soon as I launched the repo and I decided to share it here in case you guys want to use it in your neighbourhoods as well, or in any case modify the <a href="https://gitlab.com/terceranexus6/barriocheck">repo</a>.</p>

<p><img src="https://old.interferencias.tech/assets/images/dev.to/200723/04.gif" style="display: block; margin: 0 auto;" /></p>

<p>Have fun and stay safe! I believe in the collaboration of the people for creating safer cities.</p>

<p>Right now <a href="https://gitlab.com/terceranexus6/barriocheck">it’s in Spanish</a>, as I thought it would help local groups to better understand it, but I hope to soon add the English translation.</p>

<p><em>Also written in: <a href="https://dev.to/terceranexus6/social-engineering-the-performance-security-5g8l">https://dev.to/terceranexus6/social-engineering-the-performance-security-5g8l</a></em></p>]]></content><author><name>Paula</name><email>inversealien@protonmail.com</email></author><category term="python" /><category term="seguridad" /><summary type="html"><![CDATA[]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://old.interferencias.tech/%7B%22feature%22=%3E%22banners/header.jpg%22%7D" /><media:content medium="image" url="https://old.interferencias.tech/%7B%22feature%22=%3E%22banners/header.jpg%22%7D" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Social Engineering&amp;amp;#58 The performance security</title><link href="https://old.interferencias.tech/2020/07/10/social-engineering-performance-security/" rel="alternate" type="text/html" title="Social Engineering&amp;amp;#58 The performance security" /><published>2020-07-10T00:00:00+02:00</published><updated>2020-07-10T00:00:00+02:00</updated><id>https://old.interferencias.tech/2020/07/10/social-engineering-performance-security</id><content type="html" xml:base="https://old.interferencias.tech/2020/07/10/social-engineering-performance-security/"><![CDATA[<p><img src="https://old.interferencias.tech/assets/images/dev.to/200710/01.webp" style="display: block; margin: 0 auto;" /></p>

<p>Disclaimer: All of the following information takes for granted you’ve been hired for it.</p>

<p>One of the best parts of offensive security is the wide range of attacks than can be performed. As the idea is to simulate a real cyberattack, there are several kind of things to do to approach the “victim”. Even most of it involves using various tools in the computer, it also implies physical access, phishing, and getting information though the users of the system. This parts involves a bit of a performance, to learn about what kind of people work there, what kind of clients do they have, etc. It’s helpful for either simulate being one of those or craft personalized attacks. For example, if you know that most of the staff use a specific tech brand, you can create a malicious gift (a pendrive, link, program, etc) which also requires some serious crafting, how good are you with stickers and presentation? ;)</p>

<p>Anyway when it comes to emulate other kind of person, there are many useful things you can use. When speaking through the phone, or in person, you need to have clear your basic information (name, age, personal details, contextual…) so first of all is building a character. The character could change depending on the situation, there are some random character generators out there, but you might want to create a more specific character.</p>

<p>I remember I had this job interview time ago in which saying I used to roleplay fiction with my friends was a nice flag. Since I was a kid I had to study contextual details and facial expressions for personal reasons, and apparently it came in handy for my professional development. Understanding how the people in a company works, communicate and perform is a huge tip into understanding what kind of flaws they might have. Also you have to know your limitations, as much as I would like to perform some roles, I have to contextualize my complexity, my voice and my general looks. I once asked a junior to act as my boss as he had this very strong voice, and I made myself a role as a junior (I was senior of that project) due to my soft voice, and it worked.</p>

<p>Investigating the people in a company includes:</p>

<ul>
  <li><strong>Learning about their structure</strong> (do they have separates offices or do they work all together?, do they have to dress formal? do they have managers, bosses, juniors, seniors or other kind of organization?) which sometimes is just a matter of browsing Linkedin, official website and social media.</li>
  <li><strong>Learning about their routines</strong> (do they have breakfast at the same place everyday? do they go outside the building for that? do they know each other or rotate so they have different workmates from time to time?) This information could lead into attacks as the one Naomi Wu did in China, in which she met a guy from a company who used to have coffee in front of the company building, or use sniffing devices.</li>
  <li><strong>Learning about their tech</strong> (do they use windows? apple? do they bring laptops outside or the equipment is inside the building all the time?)</li>
  <li><strong>Learning about the clients</strong> (are they used to attend callings from clients? do they have review pages that could give us context on certain issues that happened before?) This could give you context to work with, referring to that issue plus some public information (NIF for example) could make people think you are this client for real.</li>
</ul>

<p><img src="https://old.interferencias.tech/assets/images/dev.to/200710/02.gif" style="display: block; margin: 0 auto;" /></p>

<p>Of course believing your own story is important, so if you are using a phone is wise to have a <em>cheatsheet</em> in front of you with your fake information, and cautiously save it for afterwards in case you are successful and you need to use that character again. For example: name, ID, age, birth place, favourite color, pet, anything that you think is needed. Even using fake sounds such as a crying baby (a very useful resource to create a hurry-up environment), a barking dog or anything like that. Creating those kind of environments could be useful for gathering information that shouldn’t be released: for example in the case I mentioned before I was a “fucked up junior” in a Friday evening (when everyone wants to finish already). Every detail is important.</p>

<p>Using different phone numbers also allows you to dissociate your character from your professional number. If you are perfectionist enough you can create some fake profiles beforehand in social media in order to refer to them if the chance comes. But the whole thing is more about coming up with things naturally even in the most weird situations. I read about a useful schematic into character creation for Social engineering when I was studying for readteam some years ago and the woman authoring even had rings, accessories and outfit for specific situations. Actually it’s all about how far are you willing to go. I have some friends who had to craft a pen-drive present and we laughed about being crafty enough for making it cute and passable. There’s this guy (not friend of mine, but he gave a speech about it) who even asked his mom to collaborate for an attack into a prison. Not gonna lie, the hell of a fun job.</p>

<p><img src="https://old.interferencias.tech/assets/images/dev.to/200710/03.gif" style="display: block; margin: 0 auto;" /></p>

<p>Obviously we are not willing to cause trouble to anyone, so when we write about it afterwards we try to generally speak about the attack and don’t point at anyone. It’s important to focus on improving the security measures instead on the specific people. The idea is to afterward suggest how to improve the security methodology in the customer assistance and daily performance so everyone is at least informed into how to react against different situations. So… here you go some tips for avoid falling into this:</p>

<p><img src="https://old.interferencias.tech/assets/images/dev.to/200710/04.gif" style="display: block; margin: 0 auto;" /></p>

<ul>
  <li>If a hurry up email, calling or customer appears on anyday, but even more on Friday afternoon, don’t panic, slow down and calmly try to resolve the problem.</li>
  <li>Never ever ever discuss personal details or relevant information without letting your responsible know and NEVER through a non-safe channel. Never never change password through phone calls or anything. Even if it sounds like a really hurry-up situations. actually <em>specially</em> if so.</li>
  <li>If someone you don’t know acts like is working there, be cautious with the information disclosure and don’t let this person know important details until you are referenced by other workmates. Try to train yourself into what kind of information you can and cannot disclosure. My family sometimes ask me about my job and I clearly know what I can and cannot say, not because of them, but because of who else is listening.</li>
  <li>Careful with very cool presents at work. EXTREMELY careful with pendrives. set it ON FIRE</li>
  <li>If you see someone putting a RPI in your Network is probably not the cleaner. Call security. (There are some workmates that had to deal with detention more than once) this person might be a friendly redteam fella, or a real attacker, in both cases you need to tell security. We will deal.</li>
</ul>

<p><em>Also written in: <a href="https://dev.to/terceranexus6/social-engineering-the-performance-security-5g8l">https://dev.to/terceranexus6/social-engineering-the-performance-security-5g8l</a></em></p>]]></content><author><name>Paula</name><email>inversealien@protonmail.com</email></author><category term="seguridad" /><summary type="html"><![CDATA[]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://old.interferencias.tech/%7B%22feature%22=%3E%22banners/header.jpg%22%7D" /><media:content medium="image" url="https://old.interferencias.tech/%7B%22feature%22=%3E%22banners/header.jpg%22%7D" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Why anti-encryption laws are crazy</title><link href="https://old.interferencias.tech/2020/06/25/anti-encryption-laws-crazy/" rel="alternate" type="text/html" title="Why anti-encryption laws are crazy" /><published>2020-06-25T00:00:00+02:00</published><updated>2020-06-25T00:00:00+02:00</updated><id>https://old.interferencias.tech/2020/06/25/anti-encryption-laws-crazy</id><content type="html" xml:base="https://old.interferencias.tech/2020/06/25/anti-encryption-laws-crazy/"><![CDATA[<p><img src="https://old.interferencias.tech/assets/images/dev.to/200625/01.webp" style="display: block; margin: 0 auto;" /></p>

<h2 id="introduction">Introduction</h2>

<p>Since tech became open and community guided, the fear of developing tools for the users and not for the companies or the government has grown bigger. In recent <a href="https://www.eff.org/deeplinks/2020/06/senates-new-anti-encryption-bill-even-worse-earn-it-and-thats-saying-something">news</a> a new bill is presented in which Justice Department will be able to require manufacturers of OS and devices as well as communication providers the ability to decrypt data upon request.</p>

<p>The whole point of encryption is to <strong>ensure the security of your information</strong>. Requiring your information to be safe is not just a matter of “hiding” stuff. Several cyberattacks push Blue Teams and companies to keep their security in its peak, backdoors are a risk to everyone’s information. An encryption with a backdoor is no longer a trustworthy encryption, it might be a hard-to-open door, that’s all. Let’s explore a bit about encryption to make sense of this:</p>

<h2 id="from-diffie-and-hellman-to-rsa">From Diffie and Hellman to RSA</h2>

<p>If you guys ever had a calculus or algorithms subject you might have heard these names already. Whitfield Diffie and Martin Hellman are the cryptologist that name the method for securely exchanging cryptographic keys. The whole, basic idea of this method is to create a shared key without the intervention of third parties for obvious reasons, but it had it flaws as it’s based in <strong>symmetric keys</strong>. It’s still useful for many things, but RSA was based in the same idea using asymmetric keys. I had to calculate <strong>RSA</strong> with pen and paper at university and it’s a pain in the ass, so I will shortcut and give the general recipe:</p>

<ul>
  <li>Using a couple of large <strong>prime numbers</strong> and keep them secret, using randomness, which by the way isn’t that easy, I will explain later.</li>
  <li>The modulus for public and private keys in n is defined as part of the public key.</li>
  <li>We involve some magic called <strong>Carmichael’s totient function</strong> and <strong>Euclidean algorithm</strong>. Using a fast duckduckgo search we can create an idea of both, but the whole point is to have a solid computable method for defining the private key so it’s a one-way calculus and there’s no way of getting it back from the information provided, in case a naughty MiTM is happening (which was a real concern in Diffie-Hellman).</li>
</ul>

<p>Actually the main idea is to craft a <strong>modular multiplicative inverse</strong>, the main part of the private key, that can be used to resolve all, but this process is not compromised, and actually all the information used to calculate this value is disposable.</p>

<p><img src="https://old.interferencias.tech/assets/images/dev.to/200625/02.gif" style="display: block; margin: 0 auto;" /></p>

<p>Anyway after all this gibberish, <strong>the important fact here is that we craft a double-key that can’t be decrypted using the information of the public part</strong> (the shared one) as that part is a one way-ticket.</p>

<h2 id="randomness">Randomness</h2>

<p>We previously said that creating true randomness is not that easy, right? Well randomness is an important part of the process, so let me explain. If we think of a limit from the bottom (0 for example) to the top (let’s stay classy and say 10) and you are asked to randomly choose a number you could say anything (did you think of 7? Hah I knew it) and that might be considered random but let’s remember computers are very stupid creatures that depends on clear commands to work. So “programming” randomness depend on choosing random facts so the computer can craft some randomness.</p>

<p><img src="https://old.interferencias.tech/assets/images/dev.to/200625/03.gif" style="display: block; margin: 0 auto;" /></p>

<p>This is why when we create a public-private key using GPG we might be asked to move the mouse all around, open and close stuff and similar, <strong>the computer is trusting on your human randomness</strong>. This is safe enough for that case, but let’s think of a situation in which we need randomness and human interaction is not an option. In my case I’m thinking of an Arduino IoT project or similar. A formal, new generation computer would be able to do the work just fine, but for example in IoT we will need specific chips for encryption, mine is <strong>ATECC608A</strong>, that includes (<em>tadah tadah</em>) Elliptic Curve Diffie-Hellman. The idea is the same, is to perform one-way-ticket public and super safe private encryption embedded in a project. <strong>If encryption was supposed to be decrypted for anyone who commands it, do you think all this effort would be necessary?</strong></p>

<p>At this point you might already think what I was trying to explain at first: <strong>encryption is designed to be unbreakable on command</strong>, it’s the whole point. Not only due to the trust in this third person, but due to the method itself. Do you see any step in the process involving “<em>oh and create a copy key to this very trustworthy third party!</em>” <strong>no</strong>, because it makes literally no sense in theory. It doesn’t matter how much you trust this third party, accepting these terms involves:</p>

<ul>
  <li>Compromising your security even more, as your safety not only depends on being attacked, but it also depends on you trustworthy third party being attacked.</li>
  <li>Changing almost 25 years of hard work made by mathematicians in order to keep you safe to literally make the internet more dangerous.</li>
</ul>

<p>So, think about this when trying to build an opinion on how important encryption is. <strong>Anything that tries to break our safety for whichever reasons have to be at least, subject of suspicion</strong>.</p>

<p><em>Also written in: <a href="https://dev.to/terceranexus6/why-anti-encryption-laws-are-crazy-188k">https://dev.to/terceranexus6/why-anti-encryption-laws-are-crazy-188k</a></em></p>]]></content><author><name>Paula</name><email>inversealien@protonmail.com</email></author><category term="encriptación" /><category term="cifrado" /><category term="seguridad" /><summary type="html"><![CDATA[]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://old.interferencias.tech/%7B%22feature%22=%3E%22banners/header.jpg%22%7D" /><media:content medium="image" url="https://old.interferencias.tech/%7B%22feature%22=%3E%22banners/header.jpg%22%7D" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Genetic algorithms for brute forcing</title><link href="https://old.interferencias.tech/2020/06/04/genetic-algorithms-brute-forcing/" rel="alternate" type="text/html" title="Genetic algorithms for brute forcing" /><published>2020-06-04T00:00:00+02:00</published><updated>2020-06-04T00:00:00+02:00</updated><id>https://old.interferencias.tech/2020/06/04/genetic-algorithms-brute-forcing</id><content type="html" xml:base="https://old.interferencias.tech/2020/06/04/genetic-algorithms-brute-forcing/"><![CDATA[<p><img src="https://old.interferencias.tech/assets/images/dev.to/200604/01.webp" style="display: block; margin: 0 auto;" /></p>

<p>Due to my work I tend to use brute force lists a lot, mostly to test incorrect login management. Sometimes I feel I get really close to correct passwords either guessing or using profiling tools. I don’t know if some of you, when it comes to change the default or old passwords you just take your old one and change it a bit. That’s mostly wrong btw.</p>

<p>In any case recently I felt like hand-writing customized lists out of guessing on a text file was a poorly decision, so I decided to create a command that creates fitted guessing options from a fitting range using a genetic algorithm. I created a <a href="https://gitlab.com/terceranexus6/jock_pass/-/tree/master">GitLab repo</a> in order to share it and I’d like to improve it, mostly because I know C++ might not be the best option and also because I’m open to suggestions, in general.</p>

<p>If you are curious please check and merge request your ideas!</p>

<p>Example of use with a sample guessed password and the desired fitness 2:</p>

<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>$ ./jockpass myPasswordGu3ss 2
</code></pre></div></div>

<p><img src="https://old.interferencias.tech/assets/images/dev.to/200604/02.gif" style="display: block; margin: 0 auto;" /></p>

<p><em>Also written in: <a href="https://dev.to/terceranexus6/genetic-algorithms-for-brute-forcing-4e6j">https://dev.to/terceranexus6/genetic-algorithms-for-brute-forcing-4e6j</a></em></p>]]></content><author><name>Paula</name><email>inversealien@protonmail.com</email></author><category term="seguridad" /><category term="cpp" /><category term="bash" /><summary type="html"><![CDATA[]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://old.interferencias.tech/%7B%22feature%22=%3E%22banners/header.jpg%22%7D" /><media:content medium="image" url="https://old.interferencias.tech/%7B%22feature%22=%3E%22banners/header.jpg%22%7D" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">ハードウェアのハッキング</title><link href="https://old.interferencias.tech/2020/04/25/hardware-hacking-japanese/" rel="alternate" type="text/html" title="ハードウェアのハッキング" /><published>2020-04-25T00:00:00+02:00</published><updated>2020-04-25T00:00:00+02:00</updated><id>https://old.interferencias.tech/2020/04/25/hardware-hacking-japanese</id><content type="html" xml:base="https://old.interferencias.tech/2020/04/25/hardware-hacking-japanese/"><![CDATA[<p>私の専門 はハードウェアのハッキング！ 電子機器を設計を楽しんでいます。基本的な物理学を復習しましょう、お先に 。</p>

<p>回路は電気の元(Vcc)とGND(0V)と電子部品をしています。抵抗器はとても大事、回路を壊さないでために抵抗器がつかうなければならない。</p>

<p><img src="https://old.interferencias.tech/assets/images/dev.to/200425/01.jpg" style="display: block; margin: 0 auto;" /></p>

<p>ハッキング ために電子機器を設計は楽しいですしかしむずかしいですよ。はじめに、サイバー攻撃を考えてなければなrない。Bluetoothプロファイルの一覧はありますか?、ＷｉＦｉ 【ワイファイ】はありますか?</p>

<ul>
  <li>複雑の プロセシング を使て(ために)、RASPBERRY PIはとてもいいです。ネットワークの捕獲の仕掛けために私はRASPERRY PI ４ もとZEROを使て。</li>
  <li>ARDUINOはRASPBERRYより簡単です。でも、 PENDRIVEのバックドアのサイバー攻撃 ためにいいです。(ﾉ◕ヮ◕)ﾉ<em>:･ﾟ✧ [ コンピュータを注視 ほうがいいですよ ]</em>:･ﾟ✧</li>
</ul>

<p>便利電子部品:</p>

<ul>
  <li><a href="https://www.adafruit.com/product/2471">ESP8266 Bluetooth</a>とWIFIあります</li>
  <li><a href="https://www.adafruit.com/product/3400">RPI Zero W WIFI</a>あります</li>
  <li><a href="https://www.adafruit.com/product/2269">BLUE Fruit Sniffer Bluetooth</a>の スニファ</li>
  <li><a href="https://www.gearbest.com/other-accessories/pp_227676.html?lkid=15666791">Digispark Attiny85 PENDRIVE</a>のバックドア</li>
</ul>

<p><img src="https://old.interferencias.tech/assets/images/dev.to/200425/02.jpg" style="display: block; margin: 0 auto;" /></p>

<p><em>Also written in: <a href="https://dev.to/terceranexus6/-2gcp">https://dev.to/terceranexus6/-2gcp</a></em></p>]]></content><author><name>Paula</name><email>inversealien@protonmail.com</email></author><category term="seguridad" /><category term="hardware" /><summary type="html"><![CDATA[私の専門 はハードウェアのハッキング！ 電子機器を設計を楽しんでいます。基本的な物理学を復習しましょう、お先に 。]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://old.interferencias.tech/%7B%22feature%22=%3E%22banners/header.jpg%22%7D" /><media:content medium="image" url="https://old.interferencias.tech/%7B%22feature%22=%3E%22banners/header.jpg%22%7D" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Your friend and neighbour WiFi</title><link href="https://old.interferencias.tech/2020/03/29/friend-neighbour-wifi/" rel="alternate" type="text/html" title="Your friend and neighbour WiFi" /><published>2020-03-29T00:00:00+01:00</published><updated>2020-03-29T00:00:00+01:00</updated><id>https://old.interferencias.tech/2020/03/29/friend-neighbour-wifi</id><content type="html" xml:base="https://old.interferencias.tech/2020/03/29/friend-neighbour-wifi/"><![CDATA[<p><img src="https://old.interferencias.tech/assets/images/dev.to/200329/4ss2jhso1bkxean4vpw1_ab.jpg" style="display: block; margin: 0 auto;" /></p>

<p>Recently I’ve been reading about ways to help your neighbourhood with the COVID-19 crisis, here in Spain. But one of the tips they gave was quite unsecure, because it’s based in the fact that everyone is nice: “Share your WiFi!” well, it is a wonderful idea to share your Internet connection if you know how to protect it and have different channels for you and your guests. On the other hand trusting on unknown open WiFis is also a bad idea. I want to show today why, using a Wifi pineapple.</p>

<p>The <a href="https://shop.hak5.org/products/wifi-pineapple">original WiFi pineapple</a> is a redteam gadget designed by Hak5, an offensive security exclusively brand. There are also Raspberry PI versions, but I’ll use the original one. I’m using a pocket size version.</p>

<p><img src="https://old.interferencias.tech/assets/images/dev.to/200329/4ss2jhso1bkxean4vpw1.jpg" style="display: block; margin: 0 auto;" /></p>

<p><img src="https://old.interferencias.tech/assets/images/dev.to/200329/uxtmf8xne7yro1evzj32.jpg" style="display: block; margin: 0 auto;" /></p>

<p>This gadget simulates a router and captures traffic of the ones who connect to it. It aims to assist professionals in MITM (man in the middle) attacks, which consist on steal data of a connection or impersonate someone.</p>

<p><img src="https://old.interferencias.tech/assets/images/dev.to/200329/mitm.jpg" style="display: block; margin: 0 auto;" /></p>

<p>This gadget is a lot of fun I must confess. You can access to the information launching a local web interface, seeing the networks around you, the devices and all. So when you are an user, what you see is an open connection sometimes using a familiar name such as “Starbucks” or something similar, and you can use the Internet (as the <strong>Pineaaple</strong> is connected to a legit source of Internet connection) so you might not notice you are being watched! Side note, if you try this in a security conference, you might get pranked when trying to do this attack as you might encounter WiFi connections around you named “<strong>idiot</strong>” or “<strong>gotcha</strong>”.</p>

<p>In any case be careful out there, and even though an open WiFi is a huge temptation, don’t be gullible. And if, even though, you want to share your WiFi, create a Guest’s WiFi and share a password for it with neighbours.</p>

<p><em>Also written in: <a href="https://dev.to/terceranexus6/your-friend-and-neighbour-wifi-257a">https://dev.to/terceranexus6/your-friend-and-neighbour-wifi-257a</a></em></p>]]></content><author><name>Paula</name><email>inversealien@protonmail.com</email></author><category term="seguridad" /><category term="wifi" /><summary type="html"><![CDATA[]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://old.interferencias.tech/%7B%22feature%22=%3E%22banners/header.jpg%22%7D" /><media:content medium="image" url="https://old.interferencias.tech/%7B%22feature%22=%3E%22banners/header.jpg%22%7D" xmlns:media="http://search.yahoo.com/mrss/" /></entry></feed>