#CIPA

2026-01-16

The #KaiserPermanente #privacy class action news is huge—they just settled the case and everyone who used the Kaiser sites and apps gets real money (not just "credit monitoring" or some bullshit)

And Kaiser didn't even fight it—which means lots more cases will be possible against other companies that passed people's info to Big Tech.

Say what you want about #CIPA but for a vintage law it's carrying right now

mercurynews.com/2026/01/14/how

Oakland Privacyoaklandprivacy
2025-11-20

“With privacy under unprecedented attack by data brokers and social media, it is the wrong time to weaken these protections."

Take a look at this article co-written by OP member @dmarti discussing the repercussions of SB 690 on the dismantling of CA's CIPA.

adexchanger.com/data-driven-th

CIPA is not outdated. California law demands meaningful consent.

2025-11-18

Just did a #RECAP download for the amended complaint (Nov. 6) in Walsh v. Dollar Tree Stores, Inc. #CIPA #privacy #privateRightOfAction

courtlistener.com/docket/69643

2025-10-04

@kkarhan wait who is Arian? also, yes, and the problem with these #k12 #cipa #filtering #software is that they don't have #security pe0ple who can test vulnerabilities.
they only test what's required in the CIPA guidelines.

not only that, these can seriously cut funding for #school #district s because they don't just attack a part of the filter, EG via a #proxy or #vpn but rather, attack holes in the filtering systems directly

2025-09-29

welp, #k12 #sysadmins , I found a new #vulnerability of #contentkeeper #cloud AKA CK-Express TP extension client side.
the new vulnerability still evolves around DNS, but still works either way.
I have moved to enterprise cloud flare gateway and modified a DNS configuration.
the problem with blocking is it still goes someware.
so let me tell you an even better solution for this: DNS remapping!
specifically, remapping all requests to contentkeeper.net and it's related subdomains to 0.0.0.0 which means CK doesn't even know what it doesn't connect to.
again, fokes, this is why you don't use client side agents for web filtering!
this is not a good idea!
again, you're trusting contentkeeper will be able to connect without a single problem.
the problem with the last flaw was that it attempted to display a block page. but this? this is even better because it can't do anything at all, even during the first initialization process ,it will simply think the device is completely offline with no network connection.
and like the last one that simply blocked rather than remapped, it gives a device not supported error.
it still needs to be on first reinitialization, but this will work.
here's how it works.
first, a user makes a DNS request not to block, but to remap, DNS entries from contentkeeper.net to 0.0.0.0 . ideally, also connections to contentkeeper.com, goguardian.com, and some other services to the same IP (this is completely possible to do on cloud flares end in 1 policy) but that's out of the scope of this.
next, they point to their DNS string which cloud flare has assigned them, or, if it has a static DNS IP, point to that.
of course, again, it needs to point on startup, either through the signin screen or before opening chrome. even better, turn off the wifi for a bit, go to the settings of the saved networks, then from there change the nameservers, bam!
and once done, if CK-ETP attempts to start, it will not work.
yes, I have found a nother #security vulnerability which is even better than reblock.
#cybersecurity #security #webfiltering #cipa #contentkeeper

CIDASC :verified_sc:cidasc_bot@bolha.one
2025-09-19

📰 Cidasc promove Semana Interna de Prevenção de Acidentes do Trabalho em Florianópolis

A Comissão Interna de Prevenção de Acidentes e Assédio (Cipa) da Companhia Integrada de Desenvolvimento Agrícola de Santa Catarina (Cidasc), em Florianópolis, realizou, entre os dias 16 e 18 de[...]

🔗 cidasc.sc.gov.br/blog/2025/09/

#Cipa #DefesaAgropecuária #Sipat #CIDASC #SantaCatarina #SC

Imagem de capa da notícia, infelizmente por ser um bot hospedado gratuitamente, não consigo gerar texto alternativo!
2025-09-17

Unidad especializada de la CCSS ratifica “nulidad evidente, absoluta y manifiesta” de licitación relacionada con el Caso Barrenador

La Dirección Jurídica de la CCSS explicó que la Junta Directiva declaró la lesividad en nueve de los contratos, al adolecer de vicios de nulidad y dispuso el inicio del respectivo proceso judicial.
La entrada Unidad especializada de la CCSS rat [...]

#Barrenador #CCSS #CIPA #Contrato #Cooperativas #Impreso #Lesividad #Nulidad. #País #Salud

semanariouniversidad.com/pais/

2025-08-21

welp, the school is fucked once again.
a few months ago, if you remember, I reported a #vulnerability in CK-Express TP that allows for, during installation, a bypass by making CKETP think it is not compatible with your device. well now it just got a lot easier. in fact, before then I thought you had to turn your wifi off and on every second or2. but what if you could just do the easiest thing in the world? leave it alone!
that's right.
turn off the wifi during the installation process, wait for at least 5minutes totle, bam. you didn't even have to do much and you just bypassed the #web #filtering system.
now to be fare, the Chromebook has to be completely knew, with no already configured CKETP instance on the client. or, it has to be completely factory reset. here's how it works. a user logs into the device, presumably, for the first time, or for the first time prior to reset.
they go to Google.com while the ck-express TP extension is installed.
CK will start initialization.
during this time, you turn off the wifi, and leave it off for 5minutes.
turn it back on, and you should get a compatibility error message.
you just bypassed CK-express and now have unfettered access to the internet.
I don't have any midigations for schools, as there are wa lot of ways to power wash a device, especially a chromeOS device like a Chromebook.
#cybersecurity #sysadmin #k12 #cipa #contentkeeper

Oakland Privacyoaklandprivacy
2025-08-06

Big California Invasion of Act (#CIPA) case ends with jury finding Meta guilty of collecting menstrual data from period tracking app and using it for marketing. Exhibit A for why we still need this law. techcrunch.com/2025/08/05/jury

Tracy Rosenbergtwrling@sfba.social
2025-08-06

Big California Invasion of #Privacy Act (#CIPA) case ends with jury finding Meta guilty of collecting menstrual data from period tracking app #FLO and using it for marketing. Exhibit A for why we still need this law. techcrunch.com/2025/08/05/jury

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst