DM_Ronin, to privacy
@DM_Ronin@mstdn.social avatar

Wow - apparently WhatsApp's design allows to gather information on which devices the client is installed, and Meta said it's all by design https://m.opnxng.com/@TalBeerySec/hi-meta-whatsapp-with-privacy-6d646c5aa3bc

Reminds me of a story back in 2017, when a flaw in encryption was found in WA and they replied with "it's not a bug, it's a feature" - and in response, my friends and I decided to add PGP encryption to WA Web as a hackathon project :blobfoxlaugh:

thibaultamartin, to privacy
@thibaultamartin@mamot.fr avatar

Everyone has a right to privacy, not just tech enthusiasts. So what does it take to design solutions to escape surveillance capitalism, at scale?

A tale of tech, systemic change, and paper keys, with real bits of @nextcloud inside

https://ergaster.org/posts/2024/01/18-escaping-surveillance-capitalism-at-scale/

Em0nM4stodon, to Signal

Check out my new
awesome @signalapp shirt! :signal:​✨

I love it!
It is perfect for the colder weather 💙
Better yet:
IT GLOWS UNDER BLACKLIGHT 🤩

If you want to support
your favorite end-to-end encrypted messaging app 👇

"You know how to get there so...": https://signalapp.myshopify.com/products/use-signal-green-black-l-s-t-shirt

Photo of a very brightly glowing greenish and blueish design on a dark fabric with the Signal logo, name, and Cantonese characters translating to: "You know how to get there so..."

avolha, to infosec Polish

W jaki sposób Meta wprowadza szyfrowanie e2e do facebookowego Messengera, co to jest Labyrinth i czy możemy czuć się w pełni bezpieczni, korzystając dziś z tego komunikatora - wyjaśnia @mateuszchrobok

https://yt.elonego.com/watch?v=_GxNLWBHxvI

Em0nM4stodon, to privacy

There is a lot to build in
the digital rights and data privacy realm.

Embrace the arrival of
more trustworthy end-to-end encrypted and privacy-focused messaging apps, email services, VPN services, browsers, operating systems, mobile devices, security tokens, etc.

Embrace the development of
more organizations, groups, and projects growing to defend our digital rights and fight to make the future a brighter place.

We need them all! 💜

We need them all to win,
together! ✊🔒

phoenix_r_d, to random
@phoenix_r_d@mastodon.social avatar

In case you missed our talk about Messaging Layer Security (MLS) at , you can re-watch it now.
👉 https://media.ccc.de/v/37c3-12064-rfc_9420_or_how_to_scale_end-to-end_encryption_with_messaging_layer_security

MLS is the first standardized and fully specified end-to-end encryption protocol. It brings substantial improvements in performance and security compared to existing protocols. We have been involved in the design and development of the MLS protocol since the very beginning.

MaidSafeCoin (EMAID) now available on the BitMart exchange! (safenetforum.org)

We are delighted to announce that we have partnered with #BitMart to offer a primary listing for #eMAID (ERC20 token) with trading commencing on 10 January 2024. The pair being offered is EMAID/#USDT. With the sad news of #Bittrex closing its doors last year and ending trading of Omni #MAID, this is great news for the future of...

josh, to Matrix
@josh@josh.tel avatar

deleted_by_author

  • Loading...
  • smallcircles,
    @smallcircles@social.coop avatar

    @MishaVelthuis @darnell @josh @matrix

    For me, I haven't much to say, other than I hope these messaging services die in a fire, decentralized or not. Even when we ignore their overly dominant, monopolist positions, their disregard of , the Advertising platforms are inherently untrustworthy. doesn't mean much either. Look e.g. at this article by @protonmail on "keylogger" injection by , and ..

    https://mastodon.social/@protonmail/111699323585240444

    thenewoil, to privacy
    phoenix_r_d, to random
    @phoenix_r_d@mastodon.social avatar

    We ended 2023 with a talk at . @raphaelrobert and Konrad presented the new standard for end-to-end encryption, Messaging Layer Security (MLS). The room was packed and some people couldn't attend in person – luckily the talk is now online and can be watched again.
    🍿 https://media.ccc.de/v/37c3-12064-rfc_9420_or_how_to_scale_end-to-end_encryption_with_messaging_layer_security

    Thank you @ccc and all helping hands for the great event!

    openrightsgroup, to random
    @openrightsgroup@social.openrightsgroup.org avatar

    This year the government attacked with the spy clause in the .

    Over 1.1K supporters joined our Don't Scan Me campaign to oppose powers that can force messaging services to scan our private messages.

    Find out more ➡️ https://www.openrightsgroup.org/campaign/save-encryption/

    openrightsgroup, to Cybersecurity
    @openrightsgroup@social.openrightsgroup.org avatar

    ORG and @edri sent an open letter warning that powers in the to scan private messages threaten our and .

    Over 80 civil society groups and experts joined us to oppose the spy clause that breaks .

    "These measures will embolden hostile and abusive regimes who will be only too pleased to use the UK as an excuse to monitor the private messages of their citizens."

    🗣️ Dr Monica Horten

    Read more ➡️ https://www.openrightsgroup.org/press-releases/online-safety-bill-protect-encrypted-messaging/

    thejapantimes, to worldnews
    @thejapantimes@mastodon.social avatar
    SirTapTap, to random
    @SirTapTap@mastodon.social avatar

    Last Boost: I really feel needs to rapidly become ubiquitous, expected, and normalized before bills that seek to ban it find the right wording to survive media scrutiny.

    That's why fan art is safe and fan games aren't, btw. Copyright wise, no difference. Fan art, esp selling it, is unquestionably not ok by most copyright standards.

    Only the unspoken "it's always been like this" keeps it safe. Sometimes that's the most critical part. People hate change. Preemptive laws are v dangerous.

    daniel, to random
    @daniel@gultsch.social avatar

    As it is a long, long tradition Conversations is available for free on the Google Play store for the last week of December.

    This tradition was originally born so that when I meet people at Chaos Communication Congress and they ask what I do, they have an easy way to install Conversations. In that regard it's a very special year as we are seeing the return of CCC.

    However if you are meeting loved ones to celebrate something else these days that’s fine too.🎄

    https://play.google.com/store/apps/details?id=eu.siacs.conversations

    tallship,
    @tallship@social.sdf.org avatar

    @daniel

    Prefer to recommend that folks install , , and other forks from F-Droid:
    https://f-droid.org/en/packages/com.cheogram.android/

    .

    thenewoil, to email
    consideration, to random

    @CenDemTech applauds Meta for taking this action to enhance the security of the billion+ Messenger users. Indeed, we helped form the Global Encryption Coalition a few years ago in part to encourage companies to extend E2EE to their services. Encryption protects dissidents, journalists, human rights defenders, victims of domestic violence, government officials who handle national secrets, and everyone else against unwarranted eavesdropping."

    https://cdt.org/insights/cdt-welcomes-rollout-of-encryption-by-default-for-facebook-messenger/

    nixCraft, to random
    @nixCraft@mastodon.social avatar

    Are you using Dropbox cloud storage? You do not want 3rd party AI technology partners to have access to your Dropbox files? Flip this switch, which is on by default. Go to web->account-> settings- 3rd party AI. Please turn it off. Please boost so everyone know how bad this move is … 😡

    kkarhan,
    @kkarhan@mstdn.social avatar

    @olives @nixCraft OFC is gonna lie about that.

    Why else would solutions like [have] exist[ed]?

    It's only when the has of all the keys!

    If ut were properly encrypted, their !" would not be able to see anything but random noise.

    The sad part us that Dropbox didn't get fined for this breach of trust by @EU_Commission or anyone else - or at least not in a way that it would be considered a penalty for them...

    mikka, to random German
    @mikka@medic.cafe avatar

    The whinging about Treads is sad.

    There are a number of ways this can go:

    1. Threads won't federate. Happy now?
    2. Threads federates, you don't subscribe to anyone on the instance. Happy now?
    3. Threads federates, you blacklist the whole instance in your user blacklist. Now happy?
    4. Threads federates, you subscribe to a few people whose writing you like. Happy?
    5. Threads federates. Threads users realize, they can jump ship to another Instance and still talk with and to and about their friends. Threads loses users. Happy!
    kkarhan,
    @kkarhan@mstdn.social avatar

    @mikka ASnd yes, if it was my decision, like / , and would be blocked...

    If I had the funding, I'd explicity start an eMail provider that blocks everything but - encrypted [ PGP/MIME ] eMails and forces everyone to properly encrypt their shit.

    Because I ran out of spoons and 10+ years after and there is no excuse to act like a Snitch!

    https://medic.cafe/@mikka/111553030936431498

    Em0nM4stodon, to privacy

    Tiny Privacy Tip About Encryption News 🔒🎉

    As end-to-end encryption becomes more popular (yay! :rainbowdance:​),

    Celebrate yes,

    But also remain skeptical about how this word is used and if this claim warrants your trust.

    Do not trust blindly.

    End-to-end encryption is a wonderful protection when well implemented. But not all apps that use end-to-end encryption are equals.

    Verify that:

    1. The provider is trustworthy :blobcatthinkingglare:​​

    2. Trustworthy third-parties have verified and confirmed the provider's claims 🔍​

    3. Metadata is also encrypted and/or that, ideally, its collection is minimized :blobcatpeekaboo:​

    4. Solid security measures protect the data as well (For example, if your data is end-to-end encrypted from your password but your password is vulnerable then your data is vulnerable as well) 🛡️​

    5. Encryption is truly end-to-end, meaning only the sender and the receiver can access the data and nobody else ​:ablobcatpeek:​

    Finally keep in mind that even if a service uses minimal encryption (for example one that still collects a lot of unencrypted metadata) it is still better than the same service using no content encryption at all,

    BUT there are almost always much better services that offer truly complete and well implemented end-to-end encryption for their services.

    Always favor the latter when you have a choice 🔒✨

    4enzikat0r, to Facebook

    The application is getting a security overhaul, including , , message edit, “upgraded quality” media attachments, & disabling

    https://www.techradar.com/computing/software/facebook-messenger-gets-its-biggest-ever-update-including-a-major-privacy-boost

    kkarhan,
    @kkarhan@mstdn.social avatar

    @4enzikat0r don't believe the claims of !

    It's not real unless you have 100% of all the keys!

    Those ain't "disappearing" unless you have full control of all the servers and clients that could've recieved/stored/cashed/intercepted them!

    Everything else is just a way to bamboozle !

    esm, to random
    @esm@wetdry.world avatar

    I THINK THE MATRIX CHAT PROTOCOL SUCKS

    kkarhan,
    @kkarhan@mstdn.social avatar

    @hexaheximal @esm

    Any with of all Keys should be considered security-sensitive and thus should not he used as a .

    Also supports -Apps and if you don't have administrative privilegues on a machine then consider it insecure and nit trustworthy for yourself as a user!

    hexaheximal,
    @hexaheximal@blob.cat avatar

    @hexaheximal @kkarhan @esm I also forgot about the most obvious thing...

    Back in the 90s, Bill Gates infamously decided to kill Netscape. He did it because he knew that web apps would make the operating system irrelevant.

    While his solution was wrong, he correctly predicted that web apps were going to take over.

    Look at all of the desktop apps which are just Electron wrappers now too. It's very common. (and before you say that electron is bad and discard it, which is likely, https://github.com/nukeop/nuclear/blob/master/docs/electron.md)

    > Any with of all Keys should be considered security-sensitive and thus should not he used as a .

    This is irrelevant too. Browsers have really good sandboxing nowadays, and on chromium you can even create multiple profiles within the UI. The reality is that, as long as the client-side code can be trusted (reminder that you can self-host element and/or cinny if you don't trust it - I've done that before) as well as the browser itself, it's about the same in terms of security.

    You are fighting against reality.

    kkarhan, to chat German
    @kkarhan@mstdn.social avatar

    A little personal post I should propably pin:

    Don't sent me any links/invites to , / or whatever sites/services.

    I WILL IGNORE THEM!

    If you want to contact me, you'll find all the info you want on my profile.

    To protect against , all messages/eMails get automatically filtered as junk on server-side.

    If you want a reply, add your to those.

    Thanks for your attention!

    kkarhan, (edited )
    @kkarhan@mstdn.social avatar

    @alcea @eatyourglory @thunderbird @cryptoparty

    Don't believe @protonmail 's #ads and remember that the only secure #encryption is real #E2EE with #SelfCustody of #Keys!

    Because when push comes to shove, noone will save your ass if that means risking jail...
    https://twitter.com/thegrugq/status/1085614812581715968

    #NotYourKeys = #NotYourData !!!

    http://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad.onion/post/547af5650b3853a3b24e

  • All
  • Subscribed
  • Moderated
  • Favorites
  • normalnudes
  • tsrsr
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • khanakhh
  • hgfsjryuu7
  • Youngstown
  • slotface
  • vwfavf
  • rosin
  • ngwrru68w68
  • kavyap
  • PowerRangers
  • Leos
  • ethstaker
  • cubers
  • everett
  • modclub
  • InstantRegret
  • tacticalgear
  • Durango
  • mdbf
  • cisconetworking
  • tester
  • GTA5RPClips
  • osvaldo12
  • anitta
  • All magazines