Opens profile photo
Follow
Joseph Cox
@josephfcox
Hacking/crime/privacy journalist. Co-founder of . Signal: +44 20 8133 5190. Email: joseph@404media.co Mastodon: infosec.exchange/@josephcox
404media.coJoined March 2011

Joseph Cox’s posts

Texas police are refusing to release the bodycam footage of the Uvlade school shooting to Motherboard because they claim it could be used by other shooters to determine "weaknesses" in cop response to crimes. Asked state Attorney General to block release
1,048
6,367
Today at VICE I was unable to pull a court record, which costs 10 cents, because the company isn't paying bills Meanwhile so many execs, some which led VICE to bankruptcy, make $700-900k, including bonuses at the time VICE laid off much cheaper workers. It's worse than I thought
Image
Image
Image
Image
97
5,728
New: Walmart has been selling 30TB and other SSDs at an insanely good price. Turns out, its just two SD cards with firmware designed to trick the PC into displaying much more storage Walmart removed the item from sale after we contacted for comment
82
5,047
'Girls Who Code' Teams Up With Tomahawk Missile Maker Raytheon Girls Who Code is a nonprofit that aims to close the gender gap in tech. It has various clubs and programs that seek to foster a love of STEM and tech in women Raytheon makes weapons of war
181
3,881
New: companies selling location data on visits to abortion clinics. We know because we just bought some data for $160. Could be used to see clinics being visited by people from across state lines. Threatens both the patient and clinic. The risk is real.
77
3,713
New: we've obtained the code the FBI used to backdoor an encrypted messaging app, and we're publishing parts of it today. Code shows app created a 'ghost' contact that hid itself from users contact lists and silently received every message. More findings:
26
2,296
New: journalist clicks 'view source' on a public government webpage, finds government site is exposing SSNs. Waits until the issue is fixed before publishing their story. Governor now wants to prosecute the journalist as 'hacker'
103
1,885
New: Amazon has AI cameras installed in its delivery vans; decide whether drivers get money. But the cameras are flawed, penalizing drivers when ~they~ get cut off by other cars, making them lose pay. "Really dystopian dark, robotic voice, shouts at me"
37
1,803
New: Facebook is removing posts and temporarily banning people who say that they will mail abortion pills to those who need it, or even just state the fact they can be mailed. In 2021 the FDA made it possible and legal to send abortion pills via mail
83
1,794
New: here is the user manual for a mass surveillance tool that U.S. local cops are actively using. Based on location data harvested from ordinary apps installed on peoples' phones. No warrant needed, just login and search
20
1,792
Guess I'll tweet this before Twitter completely implodes. Netflix has acquired the rights for my forthcoming book DARK WIRE, on how the FBI secretly ran a tech company for organized crime. If you need to reach me, Signal +44 20 8133 5190/Wickr josephcox
81
1,433
New: we asked tech companies if they would provide data to police about users + abortions Facebook, Twitter, Snapchat, TikTok, Google, Amazon, Discord, Verizon, AT&T, T-Mobile, Binance, Kraken, CashApp, Coinbase, Venmo, Uber and Lyft. None answered
45
1,333
New: the bombs weren't real. Neither was the voice. We've traced some of the nationwide swatting wave to a specific swatting-as-a-service. Uses syntheiszed voices to target schools, more. The automation of swatting tech threatens to make it more prevalent.
32
1,308
New: Vince Ramos wanted Phantom Secure to be the Uber of privacy-focused phones—flood the market and figure out laws later. Then the FBI investigated him. Based on Phantom sources, internal docs, FBI files, years of reporting, this is "The Network"
44
1,127
New: spoke to actors + unions across video games, animation, more about voice generating AI. Contracts that take rights from actors to later produce more lines with AI are already "very prevalent." Some being told can't work w/o signing these rights away
15
1,176
New: the US military has spent millions of dollars on a powerful internet monitoring tool that includes browsing data, email data, cookies, more. Data is worldwide, covers 90%+ of the internet, harvested from ISPs then sold to military by private company.
34
1,106
New: encryption used in police and military radios around the world has been scrutinized by outside researchers for the first time. The researchers found what they believe is an intentional backdoor, allowing those in the know to decrypt traffic
23
1,190
New: Homeland Security is using an AI-powered tool to analyze the social media of U.S. citizens and refugees. The tool can link a person's Social Security number to their social media and smartphone location data. According to internal doc we're publishing
41
1,160
Well, it happened: local cops have access to a tool called Fog Reveal that is based on location data harvested from ordinary smartphone apps. Cops using without warrants to see what devices in an area, track down individuals. Sold to cops for cheap.
11
1,114
Personal news: I'm writing a book on one of the craziest law enforcement stings ever, where the FBI secretly ran its own tech startup called Anom & used it to wiretap hundreds of organized crime gangs globally. DARK WIRE will tell that insane story from the people who were there.
Image
60
1,109
New: underneath mega-popular gaming platform Roblox's $68 billion business is an underground ecosystem of hackers who steal rare items from kids, marketplaces that cash out items for crypto, casinos, etc. We went inside the Roblox underground.
32
720
New: data broker SafeGraph has stopped selling location data of people who visit Planned Parenthood/family planning centers. Came after we found you could buy location data of people traveling to Planned Parenthood for $160. Saw sale stopped last night
25
705
New: the online advertising ecosystem is so bad—with risk of hackers and harvesting data on people—that U.S. intelligence community has deployed network-based ad blockers, according to letter sent by Congress. Shows just how malicious online advertising is
16
697
New: for years instead of getting a warrant, the DEA paid rogue employees inside U.S. airline, bus, and parcel private companies for access to reams of customer data. Bypassed the courts and simply bought info instead. Senators now trying to stop it.
13
706
New: it happened, AI voices are now a tool for harassment. Spoke to 4 victims. Attackers used AI to make a copy of their voice, had it read out the victim's address, post online. Anyone with their voice online—podcasters, streamers—could be victim to this
14
646
New: Google has introduced "inclusive warnings", pop-ups in GDocs. Google said "landlord" was not inclusive; Google had no notes when we uploaded full text of an interview of former KKK leader David Duke in which he says N-word and hunting black people
11
590
New: last year NYT ran a blockbuster investigation w/ calls of Russian soldiers criticizing the war. NYT only used first names to protect. We found the article actually had the soldiers' phone numbers in the page source code, exposing them for *months*
19
493
New: docs say a hacked company hired a third-party firm to secretly buy exclusive access to the data for $150,000. The idea was to stop the leak. It failed. Docs don't name companies but we found it was T-Mobile, and Mandiant did the incident response
11
456
New: leaked videos show how Disney is the biggest ad tech giant you've never heard of. Videos explain how to exploit Disney's first partner data; explains that it sources location data; planned to explore pharma data. All presented by Disney characters
12
467
New: a sweeping piece of legislation would outlaw the sale of location data. Comes directly after we reported that a broker was selling the location data of people visiting abortion clinics. Hugely ambitious. Led by senator Warren
7
459
New: recently BMW announced plans to charge a subscription for heated seats. We spoke to the grey market hackers prepared to bypass that lock, and who already remotely access BMWs to permanently unlock features as more cars move to a subscription model
23
426
New: researcher publishes code for a set of iPhone exploits. Exploits on Github; decided to share them after their "frustrating experience participating in Apple Security Bounty program." Another researcher said took them 30 mins to reproduce the vulns
4
404
New: obtained documents that show the U.S. Army wanted to spend millions to reach "Gen-Z," "females, Black & Hispanics", much through sponsorship deals with Call of Duty. Includes sponsoring individual YouTubers, tournaments, events. Also $600k for IGN
13
409
New: Twitter's most important anti-censorship tool is currently dead. It's Tor onion service, which it launched so Russians could still access the site, is offline. At the time, Twitter said this was a priority. Those priorities appear to have shifted
10
411
New: this is wild. Frank Ocean fans were in a frenzy over newly leaked music from the reclusive artist. The leaker sold some tracks for thousands of dollars to collectors. But most were fake, AI-generated. Communities now in disarray over what to trust
7
406
New: lawyers working for social network codebase Mastodon have sent formal letter to Trump's upcoming social network 'Truth Social' telling them to make its source code public. Comes after Truth Social used Mastodon code (license says code must be public)
7
340
New: an established location data firm, which gets GPS coordinates via ordinary apps installed on peoples' phones and then sells that data, is still receiving GPS data even when people *explicitly* opt-out. Shows just how shaky this billion $ industry is
6
327
New: biohacker collective has created business cards that are embedded with three doses of misoprostol, a medication that safely and effectively induces an abortion. Idea is to make it possible to mail the treatment undetected. "This Card is an Abortion"
6
287
New: a Deputy US Marshal was just charged for allegedly using a cop phone location service for tracking people he knew personally and their spouses. Happened in Uvalde, where police have been widely criticised for their failure to stop a mass shooter
1
291
Scoop: new internal Roblox documents show how the massive gaming platform—played by half of all children in the U.S.—planned to go all in on Chinese censorship. Documents also show Roblox thought that its Chinese partner, ultimately Tencent, might hack it
5
303
New: the "insanely broad" RESTRICT Act—the proposed legislation that could be used to ban TikTok—also threatens a bunch of other services, potentially including VPNs, digital rights experts said. "Raises serious human and civil rights concerns."
2
309
New: a stalkerware company that sells malware for Android and Windows is exposing screenshots harvested from target devices. The company, pcTattleTale, explicitly encourages illegal spying, tells users to install malware when spouse is sleeping.
4
271
New: today we pull back the curtain on one of the most important tech companies for organized crime called No. 1 BC We found its the encrypted phone of choice for the Italian mafia. Former sellers, industry sources, sensitive docs "Big on the market"
4
292
This is one of the most important pieces of journalism ever produced. Washington Post gets permission from parents of mass shooting victims to create 3D models of what AR-15s did to their children’s bodies. As close as we’ll get to publishing photos
7
286
New: docs on CDC's phone tracking. Saw if people complying with curfews. Bought for COVID response, but said it will use for lots of non-COVID too. Monitoring schools, places of worship. Data came from company funded by former Saudi intel head, Peter Thiel
20
265
New: the IRS wants to buy an internet mass monitoring tool. This tool allows investigators to see what is happening on the wider internet beyond their own network; asks for "65 days traffic history." The tool can be used to trace activity through VPNs
9
180