183231bcb, to random

Can anymany tell me how I'm "supposed" to use end-to-end encryption with XMPP?

As far as I can tell there are three totally different ways to do E2EE:

a)OTR : "[https://xmpp.org/extensions/xep-0364.html](Not intended to be a current standard), or technical specification, as better (albeit, newer and less well tested) methods of end-to-end encryption exist for XMPP. "

b)OpenPGP: There are at least two different XEPs about it. XEP-0027 is obsolete, while XEP-0373 is "experimental" but hasn't been updated in almost three years.

c)OMEMO: "Experimental" and hasn't been updated in over two years.

Is there a way to do E2EE in XMPP which is neither deprecated nor experimental? What's the "Current stable" way to do it?

trendless, (edited ) to privacy
@trendless@zeroes.ca avatar

Yet another reason why your private messages should be stored on a server you control or e2ee (ideally, both): it's likely the pseudonyms and accounts you use can be linked back to your IRL identity... and sold to anyone willing to pay

> This Global Identity System Tracks Everything You Do Online https://www.privateinternetaccess.com/blog/global-identity-system-tracks-you/

TechDesk, to Signal
@TechDesk@flipboard.social avatar

Signal becomes even more private by removing the need to share your phone number to new contacts. The secure messaging app has so far added support for usernames in beta.

https://flip.it/E5IVAq

itnewsbot, to telegram
@itnewsbot@schleuss.online avatar

Backdoors that let cops decrypt messages violate human rights, EU court says - Enlarge / Building of the European Court of Human Rights in Strasbourg ... - https://arstechnica.com/?p=2003350 -to-end

echo_pbreyer, to random German
@echo_pbreyer@digitalcourage.social avatar

🇬🇧 The judgement of the European Court of Human Rights on the right to is a victory for civil liberties! EU governments must finally remove the proposed destruction of secure encryption from the 2.0 bill!

https://www.patrick-breyer.de/en/european-court-of-human-rights-bans-weakening-of-secure-end-to-end-encryption-the-end-of-eus-chat-control-csar-mass-surveillance-plans/

neustradamus, to random
@neustradamus@mastodon.social avatar
alecm, to random

British man acquitted over London-Spain flight bomb hoax | …SnapChat leaking messages to security services & supporting KOSA? Not a good combo for user privacy | HT @rebeccamkern

SnapChat must* be surveilling their non-encrypted chats (i.e. all of them, but they travel over HTTPS for privacy) & triggering on sensitive words, either on-server or on-client, reporting to law enforcement who then over-react … PLUS they announced support for the illiberal & misconceived KidsOnlineSafetyAct.

The two, combined, are not a great indicator for how they view user privacy.

A Spanish court has cleared a British man of public disorder, after he joked to friends about blowing up a flight from London Gatwick to Menorca […] A key question in the case was how the message got out, considering Snapchat is an encrypted app. One theory, raised in the trial, was that it could have been intercepted via Gatwick’s Wi-Fi network. But a spokesperson for the airport told BBC News that its network “does not have that capability”. In the judge’s resolution, cited by the Europa Press news agency, it was said that the message, “for unknown reasons, was captured by the security mechanisms of England when the plane was flying over French airspace”. The message was made “in a strictly private environment between the accused and his friends with whom he flew, through a private group to which only they have access, so the accused could not even remotely assume… that the joke he played on his friends could be intercepted or detected by the British services, nor by third parties other than his friends who received the message,” the judgement added. It was not immediately clear how UK authorities were alerted to the message, with the judge noting “they were not the subject of evidence in this trial”.

https://www.bbc.co.uk/news/world-europe-68099669


[*] if the cause is not Snap themselves then their transport security is broken and that’s an even bigger story, being either being a weakness in the app or an undocumented man-in-the-middle HTTPS backdoor implemented by authorities in airport wireless transportation


Previously

Scoop for @politico@Snapchat is the first social media platform to support the Kids Online Safety Act. This comes as CcEO Evan Spiegel joins the heads of Meta, TikTok, X and Discord next week in a @JudiciaryDems hearing on child sexual abuse material. https://t.co/PTKLQpqtHP

— Rebecca Kern (@rebeccamkern) January 25, 2024

https://www.addtoany.com/add_to/copy_link?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F109036&linkname=British%20man%20acquitted%20over%20London-Spain%20flight%20bomb%20hoax%20%7C%20%E2%80%A6SnapChat%20leaking%20messages%20to%20security%20services%20%26%20supporting%20KOSA%3F%20Not%20a%20good%20combo%20for%20user%20privacy%20%7C%20HT%20%40rebeccamkernhttps://www.addtoany.com/add_to/threads?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F109036&linkname=British%20man%20acquitted%20over%20London-Spain%20flight%20bomb%20hoax%20%7C%20%E2%80%A6SnapChat%20leaking%20messages%20to%20security%20services%20%26%20supporting%20KOSA%3F%20Not%20a%20good%20combo%20for%20user%20privacy%20%7C%20HT%20%40rebeccamkernhttps://www.addtoany.com/add_to/facebook?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F109036&linkname=British%20man%20acquitted%20over%20London-Spain%20flight%20bomb%20hoax%20%7C%20%E2%80%A6SnapChat%20leaking%20messages%20to%20security%20services%20%26%20supporting%20KOSA%3F%20Not%20a%20good%20combo%20for%20user%20privacy%20%7C%20HT%20%40rebeccamkernhttps://www.addtoany.com/add_to/whatsapp?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F109036&linkname=British%20man%20acquitted%20over%20London-Spain%20flight%20bomb%20hoax%20%7C%20%E2%80%A6SnapChat%20leaking%20messages%20to%20security%20services%20%26%20supporting%20KOSA%3F%20Not%20a%20good%20combo%20for%20user%20privacy%20%7C%20HT%20%40rebeccamkernhttps://www.addtoany.com/add_to/email?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F109036&linkname=British%20man%20acquitted%20over%20London-Spain%20flight%20bomb%20hoax%20%7C%20%E2%80%A6SnapChat%20leaking%20messages%20to%20security%20services%20%26%20supporting%20KOSA%3F%20Not%20a%20good%20combo%20for%20user%20privacy%20%7C%20HT%20%40rebeccamkernhttps://www.addtoany.com/add_to/twitter?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F109036&linkname=British%20man%20acquitted%20over%20London-Spain%20flight%20bomb%20hoax%20%7C%20%E2%80%A6SnapChat%20leaking%20messages%20to%20security%20services%20%26%20supporting%20KOSA%3F%20Not%20a%20good%20combo%20for%20user%20privacy%20%7C%20HT%20%40rebeccamkernhttps://www.addtoany.com/add_to/mastodon?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F109036&linkname=British%20man%20acquitted%20over%20London-Spain%20flight%20bomb%20hoax%20%7C%20%E2%80%A6SnapChat%20leaking%20messages%20to%20security%20services%20%26%20supporting%20KOSA%3F%20Not%20a%20good%20combo%20for%20user%20privacy%20%7C%20HT%20%40rebeccamkernhttps://www.addtoany.com/add_to/linkedin?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F109036&linkname=British%20man%20acquitted%20over%20London-Spain%20flight%20bomb%20hoax%20%7C%20%E2%80%A6SnapChat%20leaking%20messages%20to%20security%20services%20%26%20supporting%20KOSA%3F%20Not%20a%20good%20combo%20for%20user%20privacy%20%7C%20HT%20%40rebeccamkernhttps://www.addtoany.com/share

https://alecmuffett.com/article/109036

itnewsbot, to UnitedKingdom
@itnewsbot@schleuss.online avatar

Apple warns proposed UK law will affect software updates around the world - Enlarge

Apple is "deeply concerned" that proposed changes to ... - https://arstechnica.com/?p=1999789

alecm, to random

I wish that I could be as optimistic as @ciaranmartinoxf regarding the eventual wisdom of the British state regarding end-to-end encryption, but I cannot…

There will have to be at least 2x changes of Government before what Ciaran is asking for below, can happen; the first will be an ouster of the Tories which is necessary because they are fuelling the Home Office mindset (NB: not the other way around) that “The Tech Companies Must Be Brought To Heel” in the most authoritarian way possible, because they have a confused understanding of how social media is all of us, mediated; they recognise that the unwashed public having a voice is a bad thing for them, but they believe that the middlmen can/will be the ones to fix it.

The problem is: Labour are in the same position but for mirror reasons. They whine about billionaires and “surveillance capitalism” and channel Ciaran’s second tweet, re-interpreting it as “the role of Government is to create new and different ways to protect the most vulnerable [demographics]” which – being literally a statist party – to them also means “tech interventionism” and trying to stop technology rather than trying to improve humans.

We are in thrall to politicians who are trying to find levers to pull in pursuit of protecting people, rather than educating them towards invulnerability.

The only way I can see this loop – 5 to 10 years of the same – being shortened is perhaps a LibDem coalition happening at some point and acting to rein-in the Home Office … but that seems hardly likely, and TBH it didn’t work out so well when Lynne Featherstone was in position to do something similar like that.

The only question is how much time is wasted before the state accepts the reality of basic modern communications security, & works out new & different ways to protect the most vulnerable in this new secure reality that users across the world demand 2/2https://t.co/fJ6YeGW4My

— Ciaran Martin (@ciaranmartinoxf) December 13, 2023

https://www.addtoany.com/add_to/copy_link?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F108637&linkname=I%20wish%20that%20I%20could%20be%20as%20optimistic%20as%20%40ciaranmartinoxf%20regarding%20the%20eventual%20wisdom%20of%20the%20British%20state%20regarding%20end-to-end%20encryption%2C%20but%20I%20cannot%E2%80%A6https://www.addtoany.com/add_to/facebook?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F108637&linkname=I%20wish%20that%20I%20could%20be%20as%20optimistic%20as%20%40ciaranmartinoxf%20regarding%20the%20eventual%20wisdom%20of%20the%20British%20state%20regarding%20end-to-end%20encryption%2C%20but%20I%20cannot%E2%80%A6https://www.addtoany.com/add_to/linkedin?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F108637&linkname=I%20wish%20that%20I%20could%20be%20as%20optimistic%20as%20%40ciaranmartinoxf%20regarding%20the%20eventual%20wisdom%20of%20the%20British%20state%20regarding%20end-to-end%20encryption%2C%20but%20I%20cannot%E2%80%A6https://www.addtoany.com/add_to/mastodon?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F108637&linkname=I%20wish%20that%20I%20could%20be%20as%20optimistic%20as%20%40ciaranmartinoxf%20regarding%20the%20eventual%20wisdom%20of%20the%20British%20state%20regarding%20end-to-end%20encryption%2C%20but%20I%20cannot%E2%80%A6https://www.addtoany.com/add_to/email?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F108637&linkname=I%20wish%20that%20I%20could%20be%20as%20optimistic%20as%20%40ciaranmartinoxf%20regarding%20the%20eventual%20wisdom%20of%20the%20British%20state%20regarding%20end-to-end%20encryption%2C%20but%20I%20cannot%E2%80%A6https://www.addtoany.com/add_to/hacker_news?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F108637&linkname=I%20wish%20that%20I%20could%20be%20as%20optimistic%20as%20%40ciaranmartinoxf%20regarding%20the%20eventual%20wisdom%20of%20the%20British%20state%20regarding%20end-to-end%20encryption%2C%20but%20I%20cannot%E2%80%A6https://www.addtoany.com/add_to/twitter?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F108637&linkname=I%20wish%20that%20I%20could%20be%20as%20optimistic%20as%20%40ciaranmartinoxf%20regarding%20the%20eventual%20wisdom%20of%20the%20British%20state%20regarding%20end-to-end%20encryption%2C%20but%20I%20cannot%E2%80%A6https://www.addtoany.com/add_to/threads?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F108637&linkname=I%20wish%20that%20I%20could%20be%20as%20optimistic%20as%20%40ciaranmartinoxf%20regarding%20the%20eventual%20wisdom%20of%20the%20British%20state%20regarding%20end-to-end%20encryption%2C%20but%20I%20cannot%E2%80%A6https://www.addtoany.com/share

https://alecmuffett.com/article/108637

alecm, to random

OPEN LETTER: Make DMs Safe | this is the kind of initiative that the UK Home Office are attempting to lobby against

https://www.makedmssafe.com/

https://www.addtoany.com/add_to/copy_link?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F108634&linkname=OPEN%20LETTER%3A%20Make%20DMs%20Safe%20%7C%20this%20is%20the%20kind%20of%20initiative%20that%20the%20UK%20Home%20Office%20are%20attempting%20to%20lobby%20againsthttps://www.addtoany.com/add_to/facebook?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F108634&linkname=OPEN%20LETTER%3A%20Make%20DMs%20Safe%20%7C%20this%20is%20the%20kind%20of%20initiative%20that%20the%20UK%20Home%20Office%20are%20attempting%20to%20lobby%20againsthttps://www.addtoany.com/add_to/linkedin?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F108634&linkname=OPEN%20LETTER%3A%20Make%20DMs%20Safe%20%7C%20this%20is%20the%20kind%20of%20initiative%20that%20the%20UK%20Home%20Office%20are%20attempting%20to%20lobby%20againsthttps://www.addtoany.com/add_to/mastodon?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F108634&linkname=OPEN%20LETTER%3A%20Make%20DMs%20Safe%20%7C%20this%20is%20the%20kind%20of%20initiative%20that%20the%20UK%20Home%20Office%20are%20attempting%20to%20lobby%20againsthttps://www.addtoany.com/add_to/email?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F108634&linkname=OPEN%20LETTER%3A%20Make%20DMs%20Safe%20%7C%20this%20is%20the%20kind%20of%20initiative%20that%20the%20UK%20Home%20Office%20are%20attempting%20to%20lobby%20againsthttps://www.addtoany.com/add_to/hacker_news?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F108634&linkname=OPEN%20LETTER%3A%20Make%20DMs%20Safe%20%7C%20this%20is%20the%20kind%20of%20initiative%20that%20the%20UK%20Home%20Office%20are%20attempting%20to%20lobby%20againsthttps://www.addtoany.com/add_to/twitter?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F108634&linkname=OPEN%20LETTER%3A%20Make%20DMs%20Safe%20%7C%20this%20is%20the%20kind%20of%20initiative%20that%20the%20UK%20Home%20Office%20are%20attempting%20to%20lobby%20againsthttps://www.addtoany.com/add_to/threads?linkurl=https%3A%2F%2Falecmuffett.com%2Farticle%2F108634&linkname=OPEN%20LETTER%3A%20Make%20DMs%20Safe%20%7C%20this%20is%20the%20kind%20of%20initiative%20that%20the%20UK%20Home%20Office%20are%20attempting%20to%20lobby%20againsthttps://www.addtoany.com/share

https://alecmuffett.com/article/108634

itnewsbot, to medical
@itnewsbot@schleuss.online avatar

Meta defies FBI opposition to encryption, brings E2EE to Facebook, Messenger - Enlarge (credit: Getty Images | Chesnot )

Meta has started ena... - https://arstechnica.com/?p=1989426 -to-endencryptionmessenger

TechDesk, to meta
@TechDesk@flipboard.social avatar

Facebook Messenger joins the likes of WhatsApp and Signal, by embracing end-to-end encryption protection. Personal chats and and calls on Facebook and Messenger will default to this new private service.

https://flip.it/k8G2rK

foss_android, to foss
@foss_android@mstdn.social avatar

Deku SMS
SMS app with end to end encryption and photo sharing support

Deku SMS is a feature-rich, open-source default SMS app designed to enhance your messaging experience while prioritizing your privacy and security. With Deku SMS, you can seamlessly send and receive end-to-end encrypted SMS messages, ensuring that your conversations remain confidential.

Download: https://www.f-droid.org/packages/com.afkanerd.deku/

afranke, to rust
@afranke@mamot.fr avatar

After two and a half years of rewrite, 5 is finally out! Get the 4 client from https://flathub.org/fr/apps/org.gnome.Fractal and enjoy new features such as , location sharing, or multi-account with Single-Sign On 🚀

:boost_ok:

BenjaminHCCarr, to Matrix
@BenjaminHCCarr@hachyderm.io avatar

Decentralized messaging network says it now has 115M users
The team behind the Matrix open standard and real-time communication protocol has announced the release of its second major version .0 , bringing to group VoIP, faster loading times, and more.
https://www.bleepingcomputer.com/news/security/decentralized-matrix-messaging-network-says-it-now-has-115m-users/

mattblaze, to random
@mattblaze@federate.social avatar

Reminder about Mastodon "private" messages. Aside from not being end-end-encrypted (and so visible to instance administrators), they CC anyone @-mentioned ANYWHERE in the body of the message (not just those listed at the start).

They are now called "private mentions" rather than "private messages", but if you don't fully understand the semantics, this behavior may be unexpected and/or cause unpleasant side effects.

MagusNet, (edited )
EC_DIGIT, (edited ) to random
@EC_DIGIT@social.network.europa.eu avatar

Tomorrow, in the European Parliament, the 🇪🇺 Institutions will kick off the European Cybersecurity Month! 🕵️

Watch the addressing of our Commissioner Johannes Hahn, and panel discussion with our Director General Veronica Gaffey.

⏰ Streaming will start at 10:00 👉 https://europa.eu/!CykfYd

ami,

Everyone in : The cybersecurity proposal is a terrible idea that will chill OSS development!

Everyone in : is a terrible idea that will destroy !

@EC_DIGIT: Join us next month as we celebrate how well cyber security is going in the EU

freezenet, (edited ) to business
@freezenet@noc.social avatar

Signal CEO Reaffirms Exit of UK if Ordered to Break Encryption Via Online Safety Bill

The CEO of encrypted chat service, Signal, has reaffirmed that they will leave the UK if they are asked to break their encryption.

Fallout from the UKs disastrous passage

https://www.freezenet.ca/signal-ceo-reaffirms-exit-of-uk-if-ordered-to-break-encryption-via-online-safety-bill/

ErikJonker, to random
@ErikJonker@mastodon.social avatar

De lijst van is bekend, zoals het hoort kunnen leden er nog wat aan veranderen overigens 😀 .
https://d66.nl/nieuws/nieuwe-generatie-d66ers-op-kandidatenlijst/

muzicofiel,

@ErikJonker jammer, als thema ontbreekt . We weten inmiddels dat dit thema heeft losgelaten en zelfs op sommige vlakken anti-privacy is geworden.

cityroler, to MLS
@cityroler@chaos.social avatar

🥁🥁🥁 Say hi to Messaging Layer Security! After 5 years in the making, the protocol has been published as RFC 9420. is the first standardized and fully specified end-to-end protocol. The specification is freely accessible, and its security has been analyzed in numerous academic publications.

We wrote a blog post giving a high-level overview of MLS, its practical applications, and why it matters.
https://blog.phnx.im/rfc-9420-mls/

phoenix_r_d, to MLS
@phoenix_r_d@mastodon.social avatar

The Messaging Layer Security (MLS) protocol has been published as RFC 9420 today! MLS is the first standardized and fully specified end-to-end encryption protocol. The specification is freely accessible, and its security has been analyzed in numerous academic publications.

Check out our blog post for a high-level overview of MLS, its practical applications, and why it matters.
https://blog.phnx.im/rfc-9420-mls/

jmaris, to random
@jmaris@eupolicy.social avatar

Sad that some MEPs who vigorously defended to guarantee women private & safe access to , are now attacking it by supporting ( reg).

When you break you break it for everyone.

https://www.europarl.europa.eu/doceo/document/B-9-2022-0365_EN.html

NBCactus, to random

Protecting our online privacy is more important than ever. End-to-end encryption ensures that our messages and data are secure from prying eyes. Let's demand it from all our communication tools!

RachaelAva1024, to random

As an act of protest against the EARN IT act and the STOP CSAM act, today, I'm wearing my "Encryption is not a crime" T-shirt while I'm out shopping. It's not much, but hopefully, it does something.

Jon6705, to privacy
@Jon6705@mastodon.world avatar

WhatsApp and other encrypted messaging apps unite against law plan

https://www.bbc.co.uk/news/technology-65301510

  • All
  • Subscribed
  • Moderated
  • Favorites
  • Leos
  • tacticalgear
  • magazineikmin
  • thenastyranch
  • Youngstown
  • slotface
  • everett
  • InstantRegret
  • vwfavf
  • kavyap
  • tsrsr
  • mdbf
  • PowerRangers
  • DreamBathrooms
  • cubers
  • khanakhh
  • hgfsjryuu7
  • ngwrru68w68
  • Durango
  • cisconetworking
  • rosin
  • osvaldo12
  • tester
  • GTA5RPClips
  • ethstaker
  • modclub
  • normalnudes
  • anitta
  • All magazines