retr0id,
@retr0id@retr0.id avatar
CatboyCody,

@retr0id Quad-Rot13 for extra security.
... keys? erm... nervous finger twiddling erm... oh, look there! A partying blobcat!
:apartyblobcat:

Sh4d0w_H34rt,
@Sh4d0w_H34rt@mstdn.social avatar

@retr0id crypto-scum are dirtbags but they do offer one piece of wisdom, that is if you don't control the keys you don't own jack. Control your own keys never trust anyone else.

SecurityWriter,

deleted_by_author

  • Loading...
  • SecurityWriter,

    deleted_by_author

  • Loading...
  • hayo,

    @SecurityWriter @retr0id easier is indeed my primairy reason to do anything to do with security. Better yet, don't encrypt at all. No hacker will expect that powermove, and will think the data is worthless!

    SecurityWriter,

    @retr0id @hayo Holy shit, I had this exact conversation today.

    kkarhan,
    @kkarhan@mstdn.social avatar

    @retr0id And that's why I don't trust @signalapp / #Signal, #Telegram, #WhatsApp, #iMessage, etc.

    Only #SelfHosting & #SelfCustody of #Keys allow for real #E2EE and thus #security...

    retr0id,
    @retr0id@retr0.id avatar

    @kkarhan @signalapp idk about the others, but iiuc both signal and imessage give you key custody

    saagar,

    @retr0id @signalapp @kkarhan If you set up iCloud correctly at least

    kkarhan,
    @kkarhan@mstdn.social avatar

    @saagar @signalapp @retr0id Even then I'd say this is flaky at best, since one can't really evidence that to be the case if tuere's neither FLOSS clients nor Server implementatioms to test against...

    Unlike + or /MIME - encrypted ...

    retr0id,
    @retr0id@retr0.id avatar

    @kkarhan @saagar @signalapp Signal is FLOSS https://github.com/signalapp/Signal-Desktop https://github.com/signalapp/Signal-Server

    Besides, the whole point of E2EE is that you don't need to trust the server.

    kkarhan,
    @kkarhan@mstdn.social avatar

    @retr0id @saagar @signalapp it's not if you can't yoir own + build your own from scratch.

    Besides collects so much metadata it has a stench like had.

    What's the point of an if they - in clear violation of & - conmect that to a which im more juristictions than ever can't be obtained anonymously in.any legal capacity???

    paula,
    kkarhan,
    @kkarhan@mstdn.social avatar

    @paula @saagar @signalapp @retr0id Complain at those that made are a because they decided is -only for no good reason...

    anedroid,
    @anedroid@wspanialy.eu avatar

    @kkarhan @retr0id @signalapp Well, if you use Molly, you're basically using Signal fork built from source w/o proprietary blobs that's usable with the official Signal server. Then all you need to do, is to match the security number with your peer.

    kkarhan,
    @kkarhan@mstdn.social avatar

    @anedroid @retr0id @signalapp

    Why would anyone want a solution to begin with?

    To me stinks like and , because all is bad as it leads to .

    IOW: Why does it need a fecking ???

    fla,
    @fla@mastodon.social avatar

    @kkarhan @anedroid @retr0id @signalapp

    Dude, each time I am looking at the hashtag I see a message from you ranting about it. I think you can relax and pick another fight. What about Google for example, you surely have things to point about them, don't you?

    kkarhan,
    @kkarhan@mstdn.social avatar

    @fla @anedroid @retr0id @signalapp I already said so:

    !

    If you want me to entertain you, pay me!

    anedroid,
    @anedroid@wspanialy.eu avatar

    @kkarhan @retr0id @signalapp Agree. That's why I use @element for my daily conversations. It's just that my reason to avoid Signal is not bad encryption.

    joeo10,
    @joeo10@mastodon.sdf.org avatar

    @anedroid @kkarhan @retr0id @signalapp @element
    Here's a great example from dessalines' great "Why Not Signal?" essay on what makes a good messaging platform. https://dessalines.github.io/essays/why_not_signal.html#what-makes-a-good-messaging-platform

    Notables include:

    End-to-end encrypted
    Open source
    Federated
    Self hosted
    No required linkable identifiers (and no Signal's recent announcement on them hiding phone numbers doesn't even count.)

    Good messaging alternatives include:
    Matrix. XMPP, Briar, SimpleX

    kkarhan,
    @kkarhan@mstdn.social avatar

    @joeo10 @anedroid @retr0id @signalapp @element

    Exactly!

    I recommend - for most users [ and are excellent clients for that!] but if you are an organization then consider and if you already have a and use / MIME then @delta / may be a good option [tho I'd recommend using a seperate eMail account for that!]...

    kkarhan,
    @kkarhan@mstdn.social avatar

    @joeo10 @anedroid @retr0id

    IMHO @signalapp disqualifies itfels being a & "solution" that also demands data they have no "legitimate interest" to request or store so violating [ or at least ] and @element seems keen on forcing - changes to if not aka. The "You can't make money off it!" - !

    olives,
    @olives@qoto.org avatar

    @kkarhan @joeo10 @anedroid @retr0id Don't forget the fake foundation ("Matrix Foundation") which is now apparently just Element the for-profit start-up (previously they were technically two different things).

    It's the bait and switch which bugs me.

    https://www.crunchbase.com/organization/new-vector-im/company_financials

    https://techcrunch.com/2019/10/10/new-vector-scores-8-5m-to-plug-more-users-into-its-open-decentralized-messaging-matrix/

    https://matrix.org/about/ "The Matrix.org Foundation exists to act as a neutral custodian for Matrix"

    kkarhan,
    @kkarhan@mstdn.social avatar

    @olives @joeo10 @anedroid @retr0id

    EXACTLY THAT!!

    It rubs me on all the wrong ends, whereas I can at least understand it when does put some -y stuff behind a paywall but actually has a license to their product.

    Plus it does work.

    KiltedQueer,
    @KiltedQueer@mstdn.social avatar

    @olives @kkarhan @joeo10 @anedroid @retr0id I find Matrix/Element tae no be a very useful chat platform.

    kkarhan,
    @kkarhan@mstdn.social avatar
    KiltedQueer,
    @KiltedQueer@mstdn.social avatar

    @kkarhan @olives @joeo10 @anedroid @retr0id I shall look intae this. It is available in the AUR for Arch, and as a Flatpak. Thank ye.

    kkarhan,
    @kkarhan@mstdn.social avatar
    KiltedQueer,
    @KiltedQueer@mstdn.social avatar

    @kkarhan @olives @joeo10 @anedroid @retr0id Ok, set up an "organisation" but it seems tae be a sort of Discord without traffic.

    kkarhan,
    @kkarhan@mstdn.social avatar

    @KiltedQueer @olives @joeo10 @anedroid @retr0id better, because it actually works and Threads and stuff just works...

    And unlike it's not a shit they host with money on , or whatever but instead you can and even write your own client because it has an actual ...

    https://zulip.com/api/
    https://zulip.com/help/getting-your-organization-started-with-zulip

    There's even a : https://github.com/zulip/zulip-terminal

    anedroid,
    @anedroid@wspanialy.eu avatar

    @joeo10 @kkarhan @retr0id @signalapp @element I already use SimpleX. I like it for reliable audio calls, no need to create account (and so choosing your username and storing your credentials somewhere). It's like an unlimited phone number generator with end-to-end encryption.

    kkarhan,
    @kkarhan@mstdn.social avatar

    @anedroid @joeo10 @retr0id @signalapp @element So kinda like ?
    http://webcall.timur.mobi/

    Cuz I'm used to for that as it flawlessly integrates in and I've deployed both several times in production...

    alteropen,
    @alteropen@noc.social avatar

    @kkarhan @anedroid @retr0id @signalapp you have completely pivoted your point yet signal has its downsides but signals number 1 biggest strength is you can definitely trust its encryption. maybe you don't trust their metadata handling etc but your first point was you didn't trust signal due to its encryption, which is just a wild thing to say.

    kkarhan,
    @kkarhan@mstdn.social avatar

    @alteropen @anedroid @retr0id

    Keep shilling @signalapp if that pays your bills, but don't spew that into my timeline.

    I've said ait and I'll repeat myself again:

    If was actually designed to be secure, they'd not make it a , & solution, collect unnecessary like and espechally not incorporate in a juristiction [] which is known for , / and .

    kkarhan,
    @kkarhan@mstdn.social avatar

    @alteropen @anedroid @retr0id @signalapp likewise there are so many reasons not to trust any provider - regardless if , @protonmail or whatever...

    Because all providers WILL SNITCH ON USERS WHEN PUSH COMES TO SHOVE!
    !https://twitter.com/thegrugq/status/1085614812581715968

    Anyone who claims otherwise is running a and is being paid to snitch.
    https://www.youtube.com/watch?v=QCx_G_R0UmQ

    But don't take my word for it:
    https://gist.github.com/WonderSwan/72deb6c85de2be8e4922

    em,

    @retr0id end to end encrypted (the ends are your device and a publicly accessible firebase bucket)

    lanodan,
    @lanodan@queer.hacktivis.me avatar

    @em @retr0id Your device? Nah, their botnet node.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • DreamBathrooms
  • magazineikmin
  • InstantRegret
  • thenastyranch
  • cubers
  • Youngstown
  • ethstaker
  • slotface
  • mdbf
  • rosin
  • Durango
  • kavyap
  • GTA5RPClips
  • khanakhh
  • JUstTest
  • tacticalgear
  • ngwrru68w68
  • cisconetworking
  • modclub
  • everett
  • osvaldo12
  • tester
  • anitta
  • Leos
  • normalnudes
  • megavids
  • provamag3
  • lostlight
  • All magazines