yawnbox, to random
@yawnbox@disobey.net avatar

i understand how people have learned to love ActivityPub, and we are all wanting to defend it, we share this

a Google (Facebook) getting into the email (ActivityPub) business has not made email worse, its just an option. sure, surveillance ridden and cop friendly, ok, then dont use it

i was thinking last night how awesome it was when WhatsApp adopted the Signal protocol and gave 2 billion users worldwide strong content privacy by default. is it ever going to be a utopia? lol no

kkarhan,
@kkarhan@mstdn.social avatar

@yawnbox I think it's illusional to belive that any of the will ship non- or -free services amd products.

Simply because not doing so will make it illegal to market worldwide due to laws like / & .

Every & solution is inherently bad.

Remember:
= no real !
hosting it = no real control about data!

FediFollows, to random

End-to-end Encryption / picks of the day:

(all these are FOSS & E2EE)

➡️ @cryptpad - Online collaborative office suite

➡️ @briar - P2P messaging for activists, journalists etc

➡️ @delta - Encrypted chat system, piggybacks existing email accounts

➡️ @Tutanota - Independent email provider, supports E2EE wherever possible

➡️ @prav - XMPP app & service, developed by co-op in India

➡️ @gajim - XMPP app for Linux, Mac, Win

➡️ @Monal - XMPP app for iOS & Mac

➡️ @kaidan - XMPP app for KDE

kkarhan,
@kkarhan@mstdn.social avatar

@FediFollows @cryptpad @briar @delta @prav @gajim @Monal @kaidan instead of relying on providers like @Tutanota and @protonmail, ise actual like /MIME / as natively supoorted in out of the box!

Remember:
= !!!

Em0nM4stodon, to random

“Why do you use Signal and all this Encryption!
Do you have anything to hide? 😡“

Yes! I do!

  • The color of my underwear
  • My friends’ cats photos
  • My failed gym class grades
  • My first attempt at "portrait"
  • The outcome of my last meal
  • The weird mole on my left toe
  • How much I cried watching Star Trek
  • How much cheese there is in my fridge
  • My failed knitting experiment
  • The horrible poem I just wrote
  • My bank card pin number
  • My social security number
  • My main password
  • The web search history for your birthday gift

Privacy is a Human Right! ✊

Not sharing publicly what you do not wish to share is your right! 🔒✨

🎉

Suran,

@Em0nM4stodon

@atkelar

But not:

  • my mobile telephone number

shakil_tcs, to opensource
@shakil_tcs@mstdn.starnix.network avatar

This is a request to all FOSS projects who only use matrix for communicating with the community.

Please consider bridging your rooms with IRC or XMPP.
India has banned Element, the most widely used Matrix client. I know it's just a client, but to be safe it's wiser to stay away from matrix for a while. So please help us in this regard.

RTP,
@RTP@fosstodon.org avatar

@shakil_tcs To those interested, Found Element response to India banning Element (Matrix client)

https://element.io/blog/india-bans-flagship-client-for-the-matrix-network/

davew, to random
@davew@mastodon.social avatar

Twitter was not great but at least there was one place, a place of record. Now there are at least 3 and posting to all feels like pissing in the wind. Where do we go from here.

TryshHQ, (edited )

@davew

Yes, sure, the internet is ‘open’ but as we’ve all experienced : quickly embraced by corporate interests who centralized & commercialized all human experiences and interactions it enabled.

Decentralized federated services is the right path and there’s ample device compute power in consumers hands but we need resilient Tech & Commercial models that easily blends / bridges private ( ) and public (open) spaces – otherwise we're fucked.

openrightsgroup, to random
@openrightsgroup@social.openrightsgroup.org avatar

Client-side scanning of private chat messages was top of the Today programme political debate this morning with @Mer__edith and Ciaran Martin, former Head of the National Cyber Security Centre.

Client-side scanning is a technology that intercepts and checks chat messages on mobile phones before being encrypted.

@Mer__edith: these are mass surveillance measures that operate at scale. The government has used sleight of hand to put them in.

openrightsgroup,
@openrightsgroup@social.openrightsgroup.org avatar

Will client-side scanning impact UK’s international reputation?

Ciaran Martin: it’s an unhappy situation. UK could take reputational hit for introducing it in law but then never actually use it. The language of the debate is toxic. We should stop shouting at each other and get around a table.

ORG's Policy Manager, Dr Monica Horten agrees, there needs to be a grown up debate about client-side scanning and other proactive measures in the .

EwanCroft, to fediverse

Is there any news on if is getting for Direct Messages? :blobfoxthinking:

jo,

@EwanCroft AFAIK re: the protocol, what we can direct messaging thanks to birdsite language is really just a one-to-one post. Even if established over AP, it's unlikely to federate well at this stage. Perhaps better to keep as the go-to for that?

smallcircles,
@smallcircles@social.coop avatar

@jo @EwanCroft

FYI the topic of on the is being discussed at the SocialCG mailing list and on the Fediverse Devs matrix channel.

https://lists.w3.org/Archives/Public/public-swicg/2023May/0160.html

https://matrix.to/#/#fediverse-developer-network:matrix.org

filen, to random
@filen@fosstodon.org avatar

Desktop Client version 2.0.22 is now available.
You can read the full change log on our blog:

https://blog.filen.io/desktop-client-update-2-0-22/

islamicaudiobooks,
@islamicaudiobooks@mastodon.social avatar
gedeonm, to random
@gedeonm@mastodon.social avatar

I suggest Apple starts spending some serious money lobbying in the EU against this egregious potential law. Fantasy land stuff. https://daringfireball.net/linked/2023/05/22/wired-spain-e2ee

demi7en,

🤔 The quite obviously can't do anything about legislation in other democracies, let alone dictatorships, apart from being a positive example for respecting the UN charter for (which itself is toothless because now the despots are lobbying for their stooges to run key international organizations!).

The point being that representative democracy must and will address any harebrained attempts to deprive citizens of inviolable right to privacy instead of corporations (or anyone who can afford lobbyists!) deciding a suitable compromise that also appeals to the sharks.

Democracy worldwide in under attack, but the defence against interference must become more sophisticated than denying free citizens' private communications. In fact those very dictatorships hostile to democracy would love to see democracies panic and ban (end-to-end-encryption) because that would only help validate their repression.

And wrt. to your initial lobbying battle cry again, Corp is just about the least qualified nominally western corporation to lobby over any privacy issues in Europe because they've bet their entire corporate body on being in 's good graces for over two decades now.

@gedeonm @randahl

khaleesicodes, to random
@khaleesicodes@eupolicy.social avatar

In diesem Dokument bestätigen diverse EU-Mitgliedsstaaten, dass die “Slippery Slope” zum Bruch und Zugriff auf durch die ihr Ziele ist

https://www.wired.com/story/europe-break-encryption-leaked-document-csa-law/amp

khaleesicodes,
@khaleesicodes@eupolicy.social avatar

Deutschland setzt sich für den Schutz von
“die Bundesregierung ist dabei, geeignete Technologien zu erproben. DE hält es für notwendig […], dass keine Technologien eingesetzt werden, die die Verschlüsselung stören, schwächen, umgehen oder verändern.”

khaleesicodes,
@khaleesicodes@eupolicy.social avatar

Spanien möchte Anbieter in der EU das anbieten von am liebsten vollständig verbieten.

Belgien möchte gerne wieder zu “Sicherheit durch und trotz Verschlüsselung”

mysk, to infosec

The Platformer's recent article about Twitter claims that Twitter's encrypted DMs are not end-to-end encrypted:

"These messages are not encrypted end to end, making them vulnerable to so-called man-in-the-middle attacks."

This is wrong. Twitter's encrypted DMs truly are end-to-end encrypted. That is, no one other than the sender and recipient can decrypt the messages. However, Twitter does not provide a mechanism for users to verify the public key of other contacts. And this makes the design vulnerable to man-in-the-middle attacks.

... 1/2 🧵

@caseynewton

Threema lets users see the public key of every contact to verify that chats are end-to-end encrypted
Signal lets users see the safety number of each one-to-one chat to verify that the chat is end-to-end encrypted

mysk,

.... 2/2 🧵

Users negotiate a shared key to start an encrypted conversation using their public keys. After the negotiation phase, both the sender and recipient agree on a shared key to encrypt/decrypt messages in the conversation. Thus, every user has to trust that Twitter delivers the correct public key of the DM counterpart. Otherwise, an attacker can intercept the communication between one user and Twitter and act on behalf of the victim to negotiate the shared key with the DM counterpart. In the end, the attacker obtains the shared key and can decrypt [also alter and re-encrypt] the messages in the encrypted DM.

This major flaw does not disqualify the communication from being end-to-end encrypted. Twitter can easily overcome this flaw by letting users view the fingerprint of their own public keys.

Link to the Platformer article:

https://www.platformer.news/p/why-you-cant-trust-twitters-encrypted

pluralistic, to random
@pluralistic@mamot.fr avatar

If you've followed my work for a long time, you've watched me transition from a "" who posts 5-15 short hits every day to an "essay-" who posts 5-7 long articles/week. I'm loving the new mode of working, but returning to linkblogging is also intensely, unexpectedly gratifying:

https://pluralistic.net/2023/05/02/wunderkammer/#jubillee

--

If you'd like an essay-formatted version to read/share, here's a link to pluralistic.net, my surveillance-free, ad-free, tracker-free blog:

https://pluralistic.net/2023/05/13/four-bar-linkage/#linkspittle

1/

pluralistic,
@pluralistic@mamot.fr avatar

Kutcher, it seems, has learned nothing from SESTA/FOSTA. Now he's campaigning to ban working cryptography, in the name of ending the spread of CSAM. In March, Kutcher addressed the over the "" proposal, which, broadly speaking, is a ban on Messaging ():

https://www.brusselstimes.com/417985/ashton-kutcher-spotted-in-the-european-parliament-promoting-childrens-rights

Now, banning E2EE would be a catastrophe.

15/

artikel10ev, to random

"How I accidentally breached a nonexistent database and found every private key in a 'state-of-the-art' encrypted messenger"

https://crnkovic.dev/testing-converso/

strypey,
@strypey@mastodon.nzoss.nz avatar

"Unfortunately, is not open source and their website is totally silent on cryptographic primitives and protocols, which is highly unusual for a self-proclaimed 'state-of-the-art' privacy application."

https://crnkovic.dev/testing-c…

"Highly unusual" is the understatement of the century. If anyone believes encryption software can reliably protect their privacy without publishing full source code, I have a bridge they may wish to purchase.

@artikel10ev

eff, to random
@eff@mastodon.social avatar

The sponsors of the EARN IT Act and the STOP CSAM Act have made it clear they want to surveil user messages. We can still stop these bills, if there’s enough public pushback. The Senate is listening. https://www.eff.org/deeplinks/2023/05/dangerous-earn-it-bill-advances-out-committee-several-senators-offer-objections

Em0nM4stodon,

@eff

THIS
IS
VERY
IMPORTANT!! 👆👆👆👆👆👆👆👆👆

If you are in the USA, fill this please! 🇺🇸​✔️​​

Pretty please!! 🥺​👆👆👆👆👇👇👇👇
https://act.eff.org/action/the-earn-it-act-is-back-seeking-to-scan-us-all/

aral, to random
@aral@mastodon.ar.al avatar

Encrypted messaging provider: “We make our money selling this to the police.”

Tech folks: This is cool and normal.

aral,
@aral@mastodon.ar.al avatar

Since folks are asking and replies don‘t always federate properly:

https://mastodon.matrix.org/@element/110340953550548309

colin_brosseau,
@colin_brosseau@toot.aquilenet.fr avatar

@aral

Could you please give us a source?

downey, to random
@downey@floss.social avatar

🚨 Here's the important news about that statists REALLY want to distract you from seeing or talking about this week:

🇮🇳 Government in just blocked 14 different encrypted apps such as and .

🔒 Privacy is a human right. Protect it with all your might.

:boost_love: Spread the word.

https://epaper.mvkashmir.com/epaper/edition/198/paper/page/3

kkarhan,
@kkarhan@mstdn.social avatar

@downey True, & don't do , but neither does or or .

= .

No public APIs = no client & server diversity = backdoors are trivial to integrate.

downey,
@downey@floss.social avatar

@kkarhan While both good, neither of those examples are fully decentralized and Zulip still doesn't offer as far as I know.

All three of 14 I mentioned are decentralized platforms.

🤔

cloudy, to fediverse German

Wo jetzt alle zu rennen weil sie weg von wollen:

Interessant wäre evtl auch ein Federated Chat Service...
Hab ein bisschen nachgedacht und möglicherweise ist das sogar mit zu machen.
So ein bisschen "back to the roots" mäßig, zurück in Richtung TS3. Wobei natürlich die Frage wäre wie viele Leute bereit wären ihren eigenen Server zu hosten wenn Dinge wie existieren

chpietsch,
@chpietsch@digitalcourage.social avatar

@cloudy

Die meisten Messenger basieren auf XMPP, auch wenn sie das nicht immer dazusagen.

Bei @digitalcourage benutzen wir das gute alte XMPP zusammen mit , um zu haben.

Auf meinem Mastodon-Server sind nur wenige deiner Posts angekommen. Das ist normal. So bin ich schnell auf einen alten Post von dir gestoßen.

danie10, to opensource
@danie10@mastodon.social avatar

SimpleX E2EE messenger for iOS and Android has no user IDs at all – It could be the most secure and private messenger ever

Other apps have user IDs: Signal, Matrix, Session, Briar, Jami, Cwtch, etc. SimpleX does not, not even random numbers. This radically improves your privacy.

When users have persistent identities, even if this is just a random number, like a Session ID, the ...continues

See https://gadgeteer.co.za/simplex-e2ee-messenger-for-ios-and-android-has-no-user-ids-at-all-it-could-be-the-most-secure-and-private-messenger-ever/

Em0nM4stodon, (edited ) to random

Them 👉 https://www.laquadrature.net/en/2023/06/05/criminalization-of-encryption-the-8-december-case/

“Do you use encrypted messaging (WhatsApp, Signal, Telegram, ProtonMail)? “

Me: Yes! Of course! Don’t you? 🤨

“For your personal data, do you use an encryption system? “

Me: Yes! Of course! Don’t you? 🤨

“Why do you use this kind of encryption and anonymization applications on the Internet?“

Me:

  1. Because Privacy is a Human Right 🔒✨
  2. To protect from thieves
  3. To protect from stalkers
  4. To protect from phishing
  5. To keep my personal data away from surveillance capitalism

Why don’t YOU want to protect yourself from that? 🤨

🎉

konstantin, to random

Given the increase of delusional/ignorant sentiments in governance groups, leading them to believe that removing encryption will help them fight crime or protect certain groups online (e.g. children), it's definitely time to reach out to your .

Don't hesitate to point out arguments (even the obvious ones) and facts ranging from technical feasibility all the way to what depends on our ability to safely and securely communicate and remain anonymous online.

Jdreben, to aitools
@Jdreben@mastodon.world avatar

The irony of the 🙄 At least they're... kind of teaching people?

...They're just missing the part where you have to trust at the "end", and you shouldn't. Ugh. I'd actually trust a carrier pigeon more.

https://youtu.be/zvI4cVGWJhM

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • Durango
  • thenastyranch
  • ngwrru68w68
  • InstantRegret
  • DreamBathrooms
  • modclub
  • magazineikmin
  • Youngstown
  • everett
  • ethstaker
  • slotface
  • rosin
  • anitta
  • kavyap
  • osvaldo12
  • GTA5RPClips
  • cisconetworking
  • provamag3
  • khanakhh
  • tacticalgear
  • cubers
  • Leos
  • normalnudes
  • megavids
  • tester
  • lostlight
  • All magazines