







Or how to avoid getting locked-out of another Google Account This guide will describe how to setup a persistent browser (for Evil Corp) that’s isolated in a sandbox (with firejail) and forced to use a SOCKS5 proxy to retain a static IP address (using proxychains) Have you ever been locked out of your own account, and then got an email for your service provider annoyingly letting you know that they’ve “blocked a login attempt — for your protection?“ There’s countless reports of frustrated users who have permanently lost access to their own gmail accounts because of Google’s faulty “fraud protection” systems that locked the account owner out of their own account, due to false-positives. Problem Especially the past 10 years, large corporations have been using machine learning anomaly detection systems on their login pages. Unfortunately, sometimes this is (ab)used to have priority over credential authentication challenges. Even if you enter your username, password, and 2FA credentials correctly on the very first login attempt, you may get locked out of your own account because you “look different” Even if you enter your username, password, and 2FA credentials correctly on the very first login attempt, you may get locked . . . → Read More: Persistent, Sandboxed, Single-Site Browser (firejail and proxychains)
Antidetect Browser for Managing Multiple Accounts Safely | Gologin
Create and run multiple accounts on any platform without bans. Gologin antidetect browser helps you manage unlimited profiles safely with unique digital fingerprints.⚡️7-Days Trial!

Google accused of ‘predatory conduct’ over Gmail API withdrawal
Google has exploited a regulatory gap to withdraw access to the Gmail API, according to UK startup Gener8.

Google can keep its Chrome browser but will be barred from exclusive contracts | Hacker News
⠠⠵ avuko (@avuko@infosec.exchange)
@elena@aseachange.com @aral@mastodon.ar.al I couldn't resist, so I've wasted my precious time looking at "W Identity" today. Things are not right. It is basically a repurposed https://github.com/PeterWaher/IoTGateway Just look here: https://root.widentity.eu/Settings/Master.md It has a socks4(?) open on port 1080, some xmpp stuff on 5222 and 5269, another (seemingly broken) version of the website on 8088. The following pages are accessible without auth: (found by a simple "`egrep -LR 'Privilege:|Login:' * |grep md | grep Root`" through the source) ``` /Settings/PersonalData/LocalDatabase.md /Settings/PersonalData/LocalSensorsAndDevices.md /Settings/PersonalData/EventLogs.md /Settings/PersonalData/NetworkIdentity.md /Settings/PersonalData/WebPages.md /Settings/PersonalData/Backups.md /Settings/Master.md /Copyright.md /Starting.md [http response 307] /Login.md /Entities.md /Templates/Repeat.md /AdminDropdownComponent.md /Script.md /AdminDropdown.md /AlertPopup.md /Master.md /PromptPopup.md /ConfirmPopup.md /Markdown.md /Emojis.md /Smileys.md /Index.md /MarkdownEditor.md /ScriptColors.md /Master.md ``` Others pages also exist (no 404), but are only available after login. Which brings me to the biggest problem of all. This is an **ADMIN** interface. Nobody should **ever** put an admin interface to an identity management platform on the internet. #WSocial #Widentity
Sign in - Google Accounts
The new Security Checkup
Take 2 minutes to check your security status and get personalized tips to strengthen the security of your Google Account.
The OAuth mechanism and its most common flows
Every single time when you want to sign in to an application and you click on “Login with Google”, you are starting a protocol called…

CAPTCHA successor Privacy Pass has no easy answers for online abuse | The Mozilla Blog
As much as the Web continues to inspire us, we know that sites put up with an awful lot of abuse in order to stay online. Denial of service attacks, fraud

This ‘Privacy Browser’ Has Dangerous Hidden Features
The Universe Browser is believed to have been downloaded millions of times. But researchers say it behaves like malware and has links to Asia’s booming cybercrime and illegal gambling networks.

SLAP and FLOP: Apple's Lack of Full Site Isolation and iOS Browser Ban Puts Users at Risk - Open Web Advocacy
TL:DR; Yet again Apple’s ban on third-party browser engines weakens security rather than strengthens it.

Keeping the Web Open and Private in the Bot Era | The Mozilla Blog
If you’ve been running into endless CAPTCHAS or website login requests lately, you’re not imagining things. Websites, facing a rising tide of abu

Trust Me, I’m Local: Chrome Extensions, MCP, and the Sandbox Escape
Trust Me, I’m Local reveals how Chrome extensions and MCP abuses enabled sandbox escapes, exposing users to major security vulnerabilities.

I built a self-hosted 2FA server so I don’t have to trust Google anymore
Why rely on big tech for your 2FA codes when you can be your own provider?

Privacy vs. Profit: The Impact of Google's Manifest Version 3 (MV3) Update on Ad Blocker Effectiveness
Google's recent update to the manifest file for Chrome browser extensions, transitioning from manifest version 2 (MV2) to manifest version 3 (MV3), has raised concerns among users and ad blocker providers, who worry that the new restrictions, notably the shift from the powerful WebRequest API to the more restrictive DeclarativeNetRequest API, might reduce ad blocker effectiveness. Because ad blockers play a vital role for millions of users seeking a more private and ad-free browsing experience, this study empirically investigates how the MV3 update affects their ability to block ads and trackers. Through a browser-based experiment conducted across multiple samples of ad-supported websites, we compare the MV3 to MV2 instances of four widely used ad blockers. Our results reveal no statistically significant reduction in ad-blocking or anti-tracking effectiveness for MV3 ad blockers compared to their MV2 counterparts, and in some cases, MV3 instances even exhibit slight improvements in blocking trackers. These findings are reassuring for users, indicating that the MV3 instances of popular ad blockers continue to provide effective protection against intrusive ads and privacy-infringing trackers. While some uncertainties remain, ad blocker providers appear to have successfully navigated the MV3 update, finding solutions that maintain the core functionality of their extensions.

tholian-network/stealth
:rocket: Stealth - Secure, Peer-to-Peer, Private and Automateable Web Browser/Scraper/Proxy
🦫 alert! We published the second episode of "Teach the Web new Tricks", featuring native support for @atproto.com ! Learn more how we improve user agency and privacy at webbeef.org/atproto.html : - Native at:// protocol support. - Log in your PDS and forget OAuth ! - Authorize 3rd parties