hko, (edited ) to rust
@hko@fosstodon.org avatar

I just released version 0.0.1 of the new crate https://crates.io/crates/openpgp-card-state

This crate paves the way for convenient handling of card User PINs, for users whose threat model allows persisting the PIN locally on the host computer.

If a User PIN is stored, applications can obtain it via this crate, and perform cryptographic operations without prompting the user for PIN entry.

Currently org.freedesktop.Secret is supported for storage.

Thoughts are welcome!

fsf, to random
@fsf@hostux.social avatar

Did someone say encryption? Encryption helps protect the privacy of people you communicate with, and makes life difficult for bulk surveillance systems. Learn more with our Email Self Defense guide: https://u.fsf.org/1df

joel, to random
@joel@fosstodon.org avatar

integration with stuff is kinda broken after an update to the former. The app crashes everytime I write an email, because I have draft encryption enabled

This is so sad :'c

blueghost, to email
@blueghost@mastodon.online avatar

Thunderbird is an email client with built-in support for PGP encryption.

Messages are encrypted/decrypted in the client and remain encrypted on email servers, this is client-side encryption.

Some email providers support PGP encryption server-side, this method could be vulnerable to third-party decryption of emails.

PGP: https://en.wikipedia.org/wiki/Pretty_Good_Privacy
Client side encryption: https://en.wikipedia.org/wiki/Client-side_encryption

Website: https://www.thunderbird.net
Mastodon: @thunderbird

hko, to random
@hko@fosstodon.org avatar

Having decidedly too much fun playing with ancient artifacts.

Note the two version 2 public keys from 1992. They were created just over a year after Phil Zimmermann first released PGP (on 6 June 1991), deep in the crypto war era.

These keys predate the name by around half a decade.

At over 31 years old, nation-state actors can definitely factor John Gilmore's RSA 1024 key today.
However, I believe the cost still exceeds a hobbyist budget even now.

freemo, to security
@freemo@qoto.org avatar

It was a very very long weekend preparing Yubikeys with pgp keys.

freemo, to security
@freemo@qoto.org avatar

GPG/PGP tip: When trust-signing company keys, either from another company key or a personal key, sign it so you trust the whole company, not just the individual key. To do this use tsign and select a depth of 2 with a domain restriction that matches the company's domain. This will cause you to automatically trust all employees of the company that are trusted by the company's master key and verified without you needing to set the trust individually or verify individual identities.

Master_P_the_Gu, to random German

I'm looking for an idea:
In my @thunderbird , I sign mails for different accounts digitally using . Automatic signing is switched on.
In the options, all acc's look the same, I cannot find any stored passwords anywhere inside my TB.
For one acc, I am not asked for a passphrase, mails are signed and sent immediately.
For one other acc, I am asked for a passphrase, bot only after a long wait for the pga-dialogue to appear.
What could possibly be wrong?
Cheers!

NiemPseu, to random Dutch
@NiemPseu@mastodon.nl avatar

Na dik 15 jaar @thunderbird weer geïnstalleerd. Google en gekoppeld en sleutels geïmporteerd.

dpecos, to random

Are you attending a / -party? I've written a small post on how to best prepare and get ready!

Super useful as a checklist to not to forget anything!

https://danielpecos.com/2024/01/23/attending-a-pgp-gnupg-signing-party/

DM_Ronin, to privacy
@DM_Ronin@mstdn.social avatar

Wow - apparently WhatsApp's design allows to gather information on which devices the client is installed, and Meta said it's all by design https://m.opnxng.com/@TalBeerySec/hi-meta-whatsapp-with-privacy-6d646c5aa3bc

Reminds me of a story back in 2017, when a flaw in encryption was found in WA and they replied with "it's not a bug, it's a feature" - and in response, my friends and I decided to add PGP encryption to WA Web as a hackathon project :blobfoxlaugh:

sergio_101, to random
@sergio_101@mastodon.social avatar

Everyone talks about Bob sending Alice an encrypted message but never asks how scandalous it is.

todb, to random

I swear to Christ every time I need to do something in I get enraged all over again.

What's the cipher algorithm that PGP private keys are encrypted with when you set password protection on private keys? Something called S2k? What the fork is that?

Just be normal PGP. Please.

fsf, to random
@fsf@hostux.social avatar

Did someone say encryption? Encryption helps protect the privacy of people you communicate with, and makes life difficult for bulk surveillance systems. Learn more with our Email Self Defense guide: https://u.fsf.org/1df

dsfgs, to random

Esteemed I2Peers @i2p, @sadiedoreen, @social and @mark22k.

It has come to our attention that M$Windows users are without a sig file.

See https://geti2p.net/download

Or (for example) https://files.i2p-projekt.de/2.4.0/

All mirrors appear to be affected.

dsfgs,

Happy New Year esteemed I2Peers @i2p @sadiedoreen @social @mark22k.

Let's not forget that MS Windows users are unable to download with a 'sig'/'asc' file at this time. Holiday periods are typically good times for people to install and learn new, great things like I2P, PGP () and possibly linux. A positive experience with can go a long way.

See prior above toot for further details if needed.

We will not tag anyone further on this issue, unless one opts-in.

@GnuPG @martijn

paulox, to random
@paulox@fosstodon.org avatar

During the migration work to the new PC I found this guide by Jordan Williams on backing up and restoring OpenPGP keys using Gnu Privacy Guard (also known as GnuPG and GPG) useful 🎉

https://www.jwillikers.com/backup-and-restore-a-gpg-key

#PGP #OpenPGP #GnuPG #GPG #Keys #Backup #Restore

D_70WN, to random German
@D_70WN@chaos.social avatar

Gibt es ausser Posteo.de und Mailbox.org noch vertrauenswürdige E-Mail Anbieter aus Deutschland?

Tuta(nota) und reine IMAP Anbieter scheiden komplett aus, wie alle Freemailer.

kkarhan,
@kkarhan@mstdn.social avatar

@D_70WN @vegos_f06 @albigdd Glaubst doch wohl nicht, dass davor schützt?

Das wird eh alles arxhiviert wenn nicht sogar auf vorrat gespeichert...

Ob legal oder Illegal ist den Behörden shiceeegal...

Das einzig effektive was hilft, sind , , & :

D.h. wer konsequent /MIME nutzt und sauber Identitäten trennt dem kann ne Durchsuchung shiceegal sein!

https://mstdn.social/@kkarhan/111631190348553830

glacasa, to random French
@glacasa@dotnet.social avatar

Proton Mail versus Tuta (Tutanota) encryption

https://proton.me/blog/proton-vs-tuta-encryption

« encrypted “emails” within Tuta, which cannot extend beyond their walled garden, are not really emails at all: they are encrypted messages using a proprietary format »

gerowen, to random
@gerowen@mastodon.social avatar

Considering upgrading my personal key from 4096 bit DSA/Elgamal to ECDSA/ED25519 . Not sure it's worth the bother, given the schism that's probably going to come to a head in the next year or two as everybody tries to agree on an open, resistant asymmetric standard.

I've had my Elgamal key for years, and I have no reason to believe it has been compromised, it's just a thought. I don't use it much other than XMPP chats and file encryption between myself and family.

lps, to privacy
@lps@masto.1146.nohost.me avatar

Anyone remember this?

https://en.wikipedia.org/wiki/Pretty_Easy_privacy

I used the email client, which did the magic of PGP encryption without all the fuss.

As long as the recipient used the same email client, and was trusted, voilà encrypted email:)

Sad that it seems dead.

TheDoctor512, to random German
@TheDoctor512@mastodon.social avatar

Wir treffen jetzt auf ein Phänomen, dass bereits vor einigen Jahren vorausgesagt wurde. Unternehmen bauen ihre Digitalisierung zurück und gehen zurück auf analoge Prozesse.
Warum? Weil der Medienbruch teuer ist. Die Hauptursache ist die hohe analoge Bürokratie des Staates und die nicht vorhandene Digitalisierung.
Selbst wenn Unternehmen digital aufgestellt sind, durch die analoge Bürokratie müssen sie jedesmal enorme Wandlungsaufwand betreiben.

kkarhan,
@kkarhan@mstdn.social avatar

@TheDoctor512 Allein dieses -tum gehört abgeschafft!

Warum kann ich nicht einfach meine Unterlagen per /MIME verschlüsselt und signiert den Behörden zukommen lassen?

Das ist Ende-zu-Ende gesichert und manipulationssicher...

Stattdessen musste ich mir extra ne lokale (!) Faxnummer (!!) zulegen und diese auf nen PBX legen um Faxe zu erhalten - im Jahre 2020!

esm, to random
@esm@wetdry.world avatar

I THINK THE MATRIX CHAT PROTOCOL SUCKS

kkarhan,
@kkarhan@mstdn.social avatar

@hexaheximal @esm @hexaheximal @protonmail I do work on getting that part fixed...
https://github.com/KBtechnologies/PocketCrypto

In the meantime, learn #OpenPGP / #GnuPG (#PGP/MIME) and/or #XMPP+#OMEMO...

Tools like #enc make it even easier to do so...
https://github.com/life4/enc

Just like #gpa and #Kleopatra on #GUI Desktops or #OpenKeychain on #Android...

kkarhan, to chat German
@kkarhan@mstdn.social avatar

A little personal post I should propably pin:

Don't sent me any links/invites to , / or whatever sites/services.

I WILL IGNORE THEM!

If you want to contact me, you'll find all the info you want on my profile.

To protect against , all messages/eMails get automatically filtered as junk on server-side.

If you want a reply, add your to those.

Thanks for your attention!

kkarhan,
@kkarhan@mstdn.social avatar

@eatyourglory no, but that's due to and them being shitty to devs.
There are / /MIME implementations for tho...

https://www.openpgp.org/software/#ios

kkarhan,
@kkarhan@mstdn.social avatar

@me_the_fl00f @eatyourglory

OFC...

Personally, I'm disappointed that 's own doesn't do /MIME, because that's some very basic feature...

kkarhan,
@kkarhan@mstdn.social avatar

@eatyourglory @thunderbird @cryptoparty That's a aseriously good question, because unless has on and , will be a .

And Inot talking aboit the but /MIME as well!

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • rosin
  • thenastyranch
  • mdbf
  • DreamBathrooms
  • everett
  • magazineikmin
  • GTA5RPClips
  • Youngstown
  • cisconetworking
  • ethstaker
  • slotface
  • ngwrru68w68
  • kavyap
  • provamag3
  • cubers
  • InstantRegret
  • Durango
  • osvaldo12
  • modclub
  • tester
  • Leos
  • khanakhh
  • normalnudes
  • tacticalgear
  • megavids
  • anitta
  • lostlight
  • All magazines