diff --git a/about.html b/about.html index 71bf8a5..70b4a82 100644 --- a/about.html +++ b/about.html @@ -28,7 +28,7 @@
Swivro is an organization focused on free speech, transparency, cybersecurity, and online privacy.
Swivro is an organization focused on free speech, transparency, cybersecurity, and online privacy. We do our best to help you keep your online privacy.
Hosted by Webdock.io© Copyright 2021 Swivro - All Rights Reserved\n
Ever been curious about what Swivro is? Maybe you found us on Google. Regardless, here's what we do as seen below.
Founded in 2016, Swivro is an online organization focused on cybersecurity, free-speech, online privacy, and anti-mass-surveillance. Our mission is to ensure that the internet operates in a way where people are not spied on, can remain fully anonymous if they wish to, are not unethically tracked, and can speak freely without censorship. We help you stay safe from cybercrime and unethical tracking, and show you how to keep your online privacy & stay secure. We explain how companies try to violate your online privacy, which companies try to violate your online privacy, alternatives to the companies that try to violate your online privacy, and much more. For queries, use a contact link seen on our footer. Swivro is owned by Albert Arnaud as of August 18th, 2021. We would like to thank the Electronic Frontier Foundation, Disroot, Startpage, PrivacyGuides, Njalla, PrivacyTools.io, and DuckDuckGo, for inspiration and ideas.
Recently, Apple released a new feature for all Apple users sounds absolutely fine, but in reality is very privacy-violating.
Apple is a technology company that designs and manufactures smartphones, personal computers, and more. Apple recently released a new feature that applies to all Apple devices. This new feature monitors all saved photos on your device, and constantly automatically checks them for child-abuse related material. The Center for Democracy and Technology has said that it is “deeply concerned that Apple’s changes in fact create new risks to children and all users, and mark a significant departure from long-held privacy and security protocols”. The Electronic Frontier Foundation has said that “Apple is opening the door to broader abuses”. Dr. Carmela Troncoso, a leading research expert in Security & Privacy and professor at EPFL in Lausanne, Switzerland, has said that while “Apple's new detector for child sexual abuse material (CSAM) is promoted under the umbrella of child protection and privacy, it is a firm step towards prevalent surveillance and control”. Apple doesn't understand what they've done, they are just focused on selling overpriced garbage. Sure, they sell the most powerful laptop, but it's still overpriced, and the power that the laptop has is unnecessary. Once you buy an Apple product, you fall into the Apple Trap and tell everyone how good Apple is, and then buy all of their products. There's no excuse.
October 28th, 2021, by Albert
Hydrogen Aerospace is a startup France-based aerospace company. We truly like their vision, but when it comes to cybersecurity, they quite literally aren't the one. We contacted Hydrogen on October 24th, 2021, regarding critical security issues on their website. It has taken them over 24 hours to fix one of many security issues, and we have yet to receive any formal response via email. The one simple issue they have fixed involved simply modifying a file on their server that hosts their website, which, as mentioned, took them over a ridiculous 24 hours. After we sent Hydrogen an encrypted email (with the list of security issues), we heard from them on Twitter, saying \"They saw your email and will take corrective actions even if a lot of what you mentioned is already done\". That last part is stupidly incorrect, as we proved that the security issues were still present. They then replied to our reply on Twitter (where we asked if we can expect a response), and the reply said \"The team saw your email, but will not give you update about it for security reason\". This is obvious straight bullsh*t. There should be no reason as to why we cannot receive a formal response from the company stating that they received my email, they understand the severity of these security issues, they are working on fixing them, and they appreciate our report & good intentions. Essentially ignoring our email (we are to assume it has been ignored or is not taken seriously seeing that we have not received a response) with a list of critical security issues that need to be solved is extremely rude and unprofessional. If they really can't give us an update via email due to \"security issue\", then this indicates they have another security issue affecting their email system. Hydrogen Aerospace needs to do better, act more professional, and learn to communicate properly when it comes to critical security issues that need to be solved; because so far we have only heard back from them via an unsecure privacy-violating social media platform (Twitter) where we were provided with a vague and irrational response.October 29th, 2021 Update: It's been over 6 days now and a security flaw that we reported has still yet to be fixed, and can be fixed in literally less than 5 minutes. We had to respond to the Owner (of hydrogen-aero.com) on Twitter over 5 times aggressively asking for a simple formal response (to our email) stating that they received it and that they are working on fixing the issues. All we got is a pointless delayed response saying \"Thank you\". Please, for your own online safety, stay away from this website with poor security.October 31st, 2021 Update: It's stupidly ridiculous how this company can't fix a very simple yet dangerous security issue. We don't promote hacking, but go ahead and exploit this issue that they refuse to fix. They are missing a DMARC record on their domain hydrogen-aero.com, so go ahead and send a forged email to whoever you want originating from hi@hydrogen-aero.com containing a (fake) virus link. Their website is also extremely vulnerable to the most simple DDoS attacks (HTTP Flood Attacks). OVH provides transport-level DDoS Protection, but not application-level, we're not sure if they know this or not because their website has no web application firewall (we were able to access the website via various types of bots including fake search engine bots). Hopefully this will force them to fix this issue.