@jonah@neat.computer
@jonah@neat.computer avatar

jonah

@jonah@neat.computer

Founder https://mastodon.neat.computer/@privacyguides, podcast co-host https://social.lol/@techlore, infosec educator. • Instance admin @ https://mstdn.party, https://mstdn.plus, and https://neat.computer

Want to support my work on #MstdnParty or any other project? A tip at https://ko-fi.com/jonaharagon would be hugely appreciated 😎

Minneapolis, MN, USA | he/him :bisexual_flag:

This profile is from a federated server and may be incomplete. Browse more on the original instance.

jonah, to random
@jonah@neat.computer avatar

A few hours ago I received an email that the Open Collective Foundation is dissolving at the end of this year, with new donations no longer being accepted by mid March.

This is an absolute disaster for our work at @privacyguides, which has been fiscally hosted by OCF for many years now. Now we have to incorporate as an independent 501(c)(3) or find another fiscal host, move to another platform to accept donations, and deal with losing all our current regular donors. I predict a lot of lawyer time in my future.

What a headache 😭

jonah, to apple
@jonah@neat.computer avatar

You can tell Apple is absolutely FURIOUS about the DMA from their latest press release. My favorite quote is: "EU users will be confronted with a list of default browsers before they have the opportunity to understand the options available to them. The screen also interrupts EU users’ experience the first time they open Safari intending to navigate to a webpage."

That's a heck of a way to say that EU users will be asked to choose their favorite browser!

https://www.jonaharagon.com/posts/apple-is-incredibly-salty-about-the-digital-markets-act/

jonah, to Youtube
@jonah@neat.computer avatar

The Kids Online Safety Act just won't go away. If you live in the US, make sure your lawmaker is opposed to KOSA (and ask them to pass some real federal privacy laws while you're at it).

https://www.youtube.com/watch?v=BPynqBY1Fe8

✉️ https://www.stopkosa.com/ ⬅️

jonah, to random
@jonah@neat.computer avatar

Signal called out specifically by Apple today, as they add post-quantum cryptography to iMessage: https://security.apple.com/blog/imessage-pq3/

I will be very interested to hear what @signalapp / @Mer__edith has to say about this 😄

jonah, (edited ) to random
@jonah@neat.computer avatar

Okay, I have too many of these stickers. If you want one now's your chance:

There's a small price to cover a stamp for shipping and the rest will be donated to @privacyguides, but if you really want these and can't pay, DM me for a 100% off code 😄

jonah, to fediverse
@jonah@neat.computer avatar

I’ve been very supportive of @Gargron in the past, I quite like his vision for and I understand a lot of the decisions he’s made in regard to unified design and governance over the project that lots of other people seem to disagree with.

But, this latest change to the official mobile app—promoting mastodon.social over everything else—is exceptionally bad, no way around it. It’s the biggest problem that chat has too, and I REALLY don’t want to see it here.

https://mstdn.social/@feditips/110233282251253677

jonah, to mastodon
@jonah@neat.computer avatar

Interesting new filled in square icon in the v4.3.0 alpha when you boost a post.

I just realized that's probably for colorblind people using the web interface, what a neat feature 😄

The same icon gray and not filled in when not selected.

jonah, to random
@jonah@neat.computer avatar

Had a very fun time chatting with the @shortexplanations team yesterday about the work we're doing at @privacyguides ~ consider checking it out on YouTube: https://www.youtube.com/watch?v=WzYRhnjWlRQ

jonah, to random
@jonah@neat.computer avatar

I will not be suspending/defederating Threads[.]net on my Mastodon instances, and I've written a post to explain why and preemptively answer some questions for everyone who trusts me with their accounts:

https://fediverse.neat.pub/2023/07/10/threads/

I hope this explanation makes sense for those who wanted us to defederate with Threads. Federating with Threads does not impact your own privacy, contrary to popular claims. We still reserve the right to limit/silence Threads (and likely will after they launch, I elaborate on this in the post above).

jonah, to random
@jonah@neat.computer avatar

It would be cool if took the opposite approach to Google Play App Signing, by using their build system to create a code transparency key that developers could then bundle with their app, and then developers could in turn sign that bundle with their own signing key.

That way F-Droid could distribute apps that they’ve verified reproducible builds for (and check the CT signature in the F-Droid app), without having to sign the app with their own key—a common complaint about the default F-Droid repo.

jonah, to random
@jonah@neat.computer avatar

📣 Update your iPhone folks! iOS 17.2 just released, and among the changes brings a long-awaited security upgrade for iMessage, Key Verification: https://youtu.be/-2gzN6125P4

jonah,
@jonah@neat.computer avatar

@amade also, there's a second feature—which is not as exciting because you don't feel like a secret agent establishing a secure comms channel by comparing codes, but just as cool because it's fully automatic—called Key Transparency (https://security.apple.com/blog/imessage-contact-key-verification/) which is conceptually similar to Certificate Transparency (https://en.wikipedia.org/wiki/Certificate_Transparency), in that it enables your phone to further audit the responses from Apple's key exchange server.

KT is opt-in as well though, so all this is to say that Contact Key Verification is still worth enabling on your phone even if you never intend to manually compare safety numbers with anyone :)
@dryak

jonah, to mastodon
@jonah@neat.computer avatar

Seeing a lot of spreadsheets going around with people to follow on , which is super cool, but y'all should check out and add yourselves to , a site with a bunch of different lists which has been around on the fediverse basically forever: https://communitywiki.org/trunk 😄

jonah, to random
@jonah@neat.computer avatar

Does anyone remember https://last-chance-for-eidas.org/?

Because eIDAS 2.0 passed in the EU last month without much note from... anyone. EFF, Mozilla, etc. (https://eur-lex.europa.eu/eli/reg/2024/1183/oj)

It appears to have the exact same text that the @eff was originally concerned about.

I'm not a lawyer so uh, is this something we're concerned about? 🤔

Providers of web-browsers shall not take any measures contrary to their obligations set out in Article 45, in particular the requirements to recognise qualified certificates for website authentication and to display the identity data provided in a user-friendly manner.

jonah, to random
@jonah@neat.computer avatar
jonah, to random
@jonah@neat.computer avatar

If @protonprivacy is serious about the recovery email/numbers being optional, they should remove this non-dismissable (dark pattern) warning in their settings tbh

It's even worse now that it shows an orange dot on the security center sidebar icon in the inbox as well, there's no escape! Let me accept the risk!

jonah, to random
@jonah@neat.computer avatar

I'm not a fan of the "private" device-based age verification solutions that would undoubtedly like us to adopt

https://www.jonaharagon.com/posts/age-verification-is-incompatible-with-the-internet/

jonah, to random
@jonah@neat.computer avatar

There is now nearly 10 minutes of video footage (after extensive editing/cuts) of me struggling and ultimately failing to perform even the most basic task of purchasing Mobilecoin, much less actually using it, to prove that Signal's Mobilecoin integration is the single most useless feature to have ever graced this fine messaging platform.

Now available for streaming on Techlore 😂 https://www.youtube.com/watch?v=0DSGq9FQKU4

jonah, to infosec
@jonah@neat.computer avatar

Why didn't I see anyone talking about adding (in GUI) support for configuring/disabling JavaScript JIT and WebAssembly in 122? Seems like a killer security feature.

https://discuss.privacyguides.net/t/v8-javascript-wasm-engine-can-be-disabled-configured-on-a-per-site-basis-in-chromium-122/17126

jonah, to random
@jonah@neat.computer avatar

and have been upgraded to Mastodon v4.2.7. As always, let me know if you notice anything off 😃

Changelog for the technical: https://github.com/mastodon/mastodon/releases/tag/v4.2.7

jonah, to fediverse
@jonah@neat.computer avatar

I gotta say, I didn’t really care about quote posts that much either way, but replies are some of my favorite interactions on Mastodon and facilitated actual conversation, and I’m going to be sad to see some of that go away in favor of the upcoming quote posts.

It’s the difference between talking with someone and talking about someone, and I think it’s going to be a significant culture shift here.

jonah, to random
@jonah@neat.computer avatar

Okayyyy, I made a bit of a mistake (saved the database dump to /tmp and subsequently rebooted before restoring the backup).

It's not a huge deal, I just have to redo the database backup (which took a while the first time around), so... mstdn.party is going to be offline a little longer than I hoped 😢

BrodieOnLinux, to random
@BrodieOnLinux@linuxrocks.online avatar

YouTube actually added a good feature for once, you can now set 3 thumbnails for a video and it will automatically A/B test them for you, you could already do this manually but this massively stream lines the process.

jonah,
@jonah@neat.computer avatar

@BrodieOnLinux still waiting for this feature on my channels

nateb, to random
@nateb@mastodon.thenewoil.org avatar

I just learned and confirmed that MySudo is censoring profanity in messages. I have reason to believe it's not them, but actually their carrier (Twilio).

What the actual fuck?

jonah,
@jonah@neat.computer avatar

@nateb have you confirmed on multiple carriers? because that sort of censorship also happens on the receiving end (T-Mobile comes to mind in particular)

jonah, to Minnesota
@jonah@neat.computer avatar

is SO close to getting a good state flag (design F1953 obviously), so... as a Minnesotan I definitely expect a major disappointment at the 11th hour tomorrow when the commission inevitably chooses the worst possible corporate-y flag design instead 😭

jonah,
@jonah@neat.computer avatar

of course none of these hold a candle to Laser Loon. RIP

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • khanakhh
  • kavyap
  • thenastyranch
  • everett
  • tacticalgear
  • rosin
  • Durango
  • DreamBathrooms
  • mdbf
  • magazineikmin
  • InstantRegret
  • Youngstown
  • slotface
  • megavids
  • ethstaker
  • ngwrru68w68
  • cisconetworking
  • modclub
  • tester
  • osvaldo12
  • cubers
  • GTA5RPClips
  • normalnudes
  • Leos
  • provamag3
  • anitta
  • lostlight
  • All magazines