The Citizen Lab is an academic research group at @UofT focusing on the intersection of technologies, human rights and global security.
Nov 25, 2024 • 6 tweets • 2 min read
📢 NEW REPORT: Our latest report reveals that the US storefront of @amazon uses a system to restrict shipments of certain products. We found 17k+ products that were restricted from being shipped to specific world regions, with the most common type of product being books 📚.
#censorship #AmazonCensorship #BannedBooks citizenlab.ca/2024/11/analys…
The books that were banned were largely related to sensitive topics like erotica, religion, the occult, and LGBTIQ issues. Even though these books were in stock and a seller was willing to ship, Amazon still restricted users from shipping them to that region. Countries affected are the UAE, Saudi Arabia, other Middle Eastern countries as well as Brunei Darussalam, Papua New Guinea, Seychelles, and Zambia.
Oct 15, 2024 • 5 tweets • 2 min read
💬NEW REPORT: The Citizen Lab takes a deep dive into the network encryption protocol used by #WeChat, an app with over one billion users. The app uses a custom #encryption protocol called “MMTLS” that introduces cryptographic weaknesses. Read the report: bit.ly/3zZPrrM
WeChat messages are encrypted twice, yet, double encryption doesn’t make it more secure. In #WeChat, messages are first encrypted with an old and vulnerable custom protocol called “Business-layer Encryption”, then encrypted again with MMTLS, which contains minor weaknesses.
Jan 18, 2022 • 6 tweets • 1 min read
NEW REPORT
Cross-country Exposure: Analysis of the MY2022 Olympics app
citizenlab.ca/2022/01/cross-…
MY2022, an app mandated for use by all attendees of the 2022 Olympic Games in Beijing, has a simple but devastating flaw where encryption protecting users’ voice audio and file transfers can be trivially sidestepped.
Sep 28, 2021 • 10 tweets • 2 min read
NEW REPORT
Pandemic Privacy: A preliminary analysis of collection technologies, data collection laws, and legislative reform during COVID-19 #cdnpolicitizenlab.ca/2021/09/pandem…
Our report examines the extent to which technologies adopted in 🇺🇸, 🇬🇧, and 🇨🇦 to combat the pandemic were unprecedented, why 🇨🇦 privacy laws didn’t impede government responses to COVID-19, and why proposed 🇨🇦 privacy reforms during the pandemic were misguided at best.
Sep 13, 2021 • 5 tweets • 1 min read
NEW REPORT
FORCEDENTRY: NSO Group iMessage Zero-Click Exploit captured in the Wild
citizenlab.ca/2021/09/forced…
While analyzing the phone of a Saudi activist infected with NSO Group’s Pegasus spyware, we found a zero-day zero-click exploit against iMessage. The exploit, called FORCEDENTRY, targets Apple’s image rendering library & was effective against Apple iOS, MacOS & WatchOS devices.