amszmidt, to random
@amszmidt@mastodon.social avatar

Do people still use ?

amszmidt,
@amszmidt@mastodon.social avatar

@cms Once I got a security bug report by someone, encrypted .. that was exciting. And painful, since is quite hard to use.

lued, to linux
@lued@troet.cafe avatar

EN:
Unfortunately, I can't find a good entry point for this topic:
How do you implement server-side mail encryption and decryption for s/mime? I use Postfix+Cyrus.

DE:
Ich finde für das Thema leider keinen guten Einstieg:
Wie realisiert ihr serverseitige Mailver- und entschlüsselung für s/mime? Ich nutze Postfix+Cyrus.

kkarhan,
@kkarhan@mstdn.social avatar

@lued Das ist ja der Trick:
Das geht garnicht, jedenfalls nicht offiziell.

Es gibt ne Menge Appliances die quasi als Man-in-the-Middle agieren um dies umzusetzen aber IMHO ist das allenfalls Blenderei wenn nicht sogar digitales Schlangenöl.

Es ist einfacher allen Nutzer*innen beizubringen wie / funktioniert als das zu realisieren...

Sonst gäb's keine |s...

@cryptoparty

kkarhan,
@kkarhan@mstdn.social avatar

@lued @cryptoparty Wenn sich was findet, sag' Bescheid...

Ich bezweifle allerdings dass es etwas in der Richtung gibt.

Ich selbst nutze echte mit Self-Custody der Keys [] also macht es wenig Sinn was anderes zu machen.

Zumal ich eh auf mein Zeug mit denselben Keys signiere...

efi, to random
@efi@chitter.xyz avatar

all of the fedidrama with blocklists comes down to the idea that instances are needed for proxying traffic, but this is only true because identities are not decentralized, which is a fundamental mistake of the mastodon era of software
this is not really up to debate
without decentralized identity we will have this problem of someone else deciding what data we have access to, so if you don't like that, you have to push for it, the same way mastodon pushed for the democratization of this centralized model away from twitter, and even before mastodon others did so in a less accessible way
give power to the users by making it accessible, not by pretending that everyone can learn to use docker

kkarhan,
@kkarhan@mstdn.social avatar

@efi That would require people to learn how to use #Keyoxide, #GnuPG / #OpenPGP and #SelfHost their shit which - lets be honest - nobody but the most #TechLiterate do.

And sadly we can't ban #TechIlliterates from using #Tech or the #Internet...

orhun, to rust
@orhun@fosstodon.org avatar

Just released the new version of gpg-tui! 🥳

🦀 A terminal user interface for GnuPG - written in Rust

⭐ GitHub: https://github.com/orhun/gpg-tui

🔐 Changelog: https://github.com/orhun/gpg-tui/blob/master/CHANGELOG.md

video/mp4

kaiengert, to random
@kaiengert@mastodon.social avatar

Hello community of users. I'd like to know if some of you are still stuck at Thunderbird version 68 and the old Add-on. Is there any missing functionality in Thunderbird 115 that is still preventing you from migrating? @thunderbird

hako, to random
nobodyinperson, to manjaro
@nobodyinperson@fosstodon.org avatar

Damn, it took me less than five hours to reproduce my :manjaro: setup in :nixos: from zero 💪:

  • getting working
  • homedir encryption with
  • all software I need
  • even managed to package 3 custom things not in nixpkgs (passrofi, my client fork, bemoji)

Nix Packaging is indeed 𝘀𝗼 much easier than , or packaging!

This is the result: https://gitlab.com/nobodyinperson/nixconfig

leak, to random
@leak@hachyderm.io avatar

Cryptography is a tool for turning a whole swathe of problems into key management problems. Key management problems are way harder than (virtually all) cryptographers think.

kkarhan,
@kkarhan@mstdn.social avatar

@roywig @thatandromeda @leak it is "good enough", cuz we ain't 15 years ago where eberything needed archaic commands.

integrates / out of the box for some time.
& do support - and like are so easy, it literally took me 5 minutes to explain the use and setup a complete in it.

People aren't stupid, they are lazy and get groomed into being ...

That is the problem!

kuketzblog, to Signal German
@kuketzblog@social.tchncs.de avatar

Tipp Nr.5: Verwende keine unsicheren oder unverschlüsselten E-Mails für den Austausch sensibler Informationen. Nutze stattdessen sichere Kommunikationskanäle wie verschlüsselte E-Mails (bspw. GPG/OpenPGP) oder Messaging-Apps wie Signal oder Threema. Meide proprietäre Software/Apps, denen es an Transparenz mangelt. Die Verschlüsselung ist schlichtweg nicht überprüfbar - Backdoors bzw. Abhörhintertürchen inklusive.

netzpolitik_feed, to random German
@netzpolitik_feed@chaos.social avatar

Schon bald sollen alle EU-Bürger:innen über eine digitale Brieftasche verfügen, mit der sie sich on- wie offline ausweisen können. Ein Konsultationsprozess des Bundesinnenministeriums zeigt nun, welche Interessen die Wirtschaft dabei verfolgt. Und wie diese im Widerspruch zu Datenschutz und Privatsphäre stehen.

https://netzpolitik.org/2023/eidas-konsultation-wirtschaft-will-an-die-wallets/

kkarhan,
@kkarhan@mstdn.social avatar

@netzpolitik_feed @netzpolitik_org ja, das ist eine Horroridee...

Wie wäre es wenn ich einfach meinen - anerkannt bekomme?

Wäre sinnvoller und sicherer!

fsf, to random
@fsf@hostux.social avatar

GNU Spotlight with Amin Bandali: Twelve new GNU releases in the last month, including , , #R, and more. Full details: https://u.fsf.org/400 Big thanks to @bandali0 @bandali, all the devs, and other contributors!

ablackcatstail, to random

Cryptography came to my rescue today. Thank you ! When I had suspicions that a coworker wanted to get me fired I signed a document with my private key. When she summarily accused me of an alteration she made, revealed that she made the alteration and not me. The infosec officer and HR escorted her out. . I love being underestimated.

tarnkappeinfo, to Podcast German
@tarnkappeinfo@social.tchncs.de avatar
kkarhan,
@kkarhan@mstdn.social avatar

@tarnkappeinfo warum kann man bei nicht einfach

gpg --encrypt ./unencrypted.file ./pubkey.asc
bzw.
gog --decrypt ./encrypted.file.gpg ./private.key.asc

machen?

Das gegenwärtige Setup verhindert wirksam gute.Skriptbarkeit in & !

marcel, to random German

Ihr entschuldigt mich kurz? Ich gehe mich mal kurz erbrechen... #40MillionenEuroFuerDieTonne

kkarhan,
@kkarhan@mstdn.social avatar

@bison @marcel IMHO ist wie eine absolute -Idee denn es wäre signifikant einfacher, billiger und effektiver ne - + / für und zwangsweise einzuführen.

Vorallem weils weiterhin und ermöglicht und als Client das supr easy macht.

Kann daher verstehen dass einige Anwält*innen sich dem shice von wegen beA wie auch DeMail konsequent verweigern.

koko, to random

there's two ends to the "don't touch my UX, it's perfect the way it is now" spectrum: websites that get redesigned every 2 years to appease shareholders, and GIMP

kkarhan,
@kkarhan@mstdn.social avatar

@koko ...as well as - oriented tools like that don't allow basic shit like "encrypt/decrypt file with keyfile" but expect people to use "keyrings"...

FediFollows, to random

End-to-end Encryption / #E2EE picks of the day:

(all these are FOSS & E2EE)

➡️ @cryptpad - Online collaborative office suite

➡️ @briar - P2P messaging for activists, journalists etc

➡️ @delta - Encrypted chat system, piggybacks existing email accounts

➡️ @Tutanota - Independent email provider, supports E2EE wherever possible

➡️ @prav - XMPP app & service, developed by co-op in India

➡️ @gajim - XMPP app for Linux, Mac, Win

➡️ @Monal - XMPP app for iOS & Mac

➡️ @kaidan - XMPP app for KDE

kkarhan,
@kkarhan@mstdn.social avatar

@FediFollows @cryptpad @briar @delta @prav @gajim @Monal @kaidan instead of relying on providers like @Tutanota and @protonmail, ise actual like /MIME / as natively supoorted in out of the box!

Remember:
= !!!

thunderbird, to android
@thunderbird@mastodon.online avatar

Thunderbird for Android gets one step closer, as K-9 Mail integrates Thunderbird's Autoconfiguration feature for new accounts.

Read info on that, all the other important developments, and some awesome community contributions in the new progress report:
https://blog.thunderbird.net/2023/06/thunderbird-for-android-k-9-mail-may-2023-progress-report/

kkarhan,
@kkarhan@mstdn.social avatar

@codewiz @thunderbird @mozilla that's not what I consider support the same way as has today...

Shure there was a time where one needed & installed seperately, but nowadays that's not needed either...

blake, to random

In case it helps someone else: To change the smartcard PIN on my , gpg --change-pin does NOT work for some reason. Using gpg --card-edit and putting admin and then passwd into the prompt lets me do it though.

lauren, to random
@lauren@mastodon.laurenweinstein.org avatar

***** The obvious solution to the Google passkeys problem *****

Use of passkeys should require -- at least when biometric phone locks are not in use -- an authentication system separate from that used to unlock the phone. That way, a spied unlock password and stolen phone would not give the thief the ability to use the passcodes stored on the phone with such ease. -L

kkarhan,
@kkarhan@mstdn.social avatar

@resuna @lauren I do have to agree that we really need to make stuff more accessible...

Just like made - easier and more accessible than anything else...
https://mastodon.laurenweinstein.org/@lauren/110328347314531806

kde, to random
@kde@floss.social avatar

g10 Code becomes a KDE patron🎉! g10 Code are the creators and maintainers of , the vital engine 🔒 that is one of the fundamental technologies that ensures 🔑 and online.

https://dot.kde.org/2023/04/25/g10-code-becomes-kde-patron

freemo, to linux
@freemo@qoto.org avatar

It is so nice to finally have my whole company as well as my personal computers on hardware encryption, pgp key enabled, password store behibd pgp key, yubikey based pgp card, and ssh key using my pgp key through yubikey.

Other than being more secure it also means i dont need to backup my ssh keys or password store credentials, its all reproducable from my pgp keys.

phryk, to random
@phryk@mastodon.social avatar

After thinking about it a bunch, I have decided that I'll refactor my cryptographic deadhand to use python-gnupg until the sequoia-sop python bindings are released.

The official bindings are just too damn broken to be of any real use – and I think that says a lot.

Honestly, I'm not at all sure how people can release something like that as "production grade" (for security-critical tooling, no less) and not feel deeply ashamed.

shemeshg,

@phryk

GPGME

Please do note that the ME stands for 'Made Easy'. ;-)

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • kavyap
  • DreamBathrooms
  • tacticalgear
  • magazineikmin
  • khanakhh
  • everett
  • Youngstown
  • mdbf
  • slotface
  • rosin
  • ethstaker
  • InstantRegret
  • thenastyranch
  • JUstTest
  • ngwrru68w68
  • cisconetworking
  • cubers
  • osvaldo12
  • modclub
  • GTA5RPClips
  • tester
  • Durango
  • provamag3
  • anitta
  • Leos
  • normalnudes
  • lostlight
  • All magazines