helvede.net is one of the many independent Mastodon servers you can use to participate in the fediverse.
Velkommen til Helvede, fediversets hotteste instance! Vi er en queerfeministisk server, der shitposter i den 9. cirkel. Welcome to Hell, We’re a DK-based queerfeminist server. Read our server rules!

Server stats:

168
active users

#comsec

0 posts0 participants0 posts today
Replied in thread

@dalias @lauren
@pixelschubsi

Also the blatant dismissal of absolitely basic #OpSec & #ComSec is just flabberghasting.

Only #decentralized, #OpenSource & #OpenStandards can actuall survive long-term and remain #secure.

It's the same reasons we use #PGPG/MIME & #SSH and not #X400 & #X25!

IOW: Think "How can you weaponize Signal?" and see what you csn do just holding key people in contempt...

The less #info a provider has, the less they can be forced to snitch upon customers.

"#JustUseSgnal!" is a form of dangerous "#TechPopulism" aimed at bamboozling #TechIlliterates who don't know better, abusing information asymetry to pull rank instead of investing the time and effort to *explain "how" and "why" this is indeed a good or bad idea.

The only ones that have a chance to beat that are @delta / #deltaChat but that's just #PGP/MIME #eMail in a nice UI...

  • You may now laugh at me and think my "#TinfoilHat sits too tight" but I'm shure sooner or later I'll be evidenced as correct...
Hachyderm.ioCassandrich (@dalias@hachyderm.io)@kkarhan@infosec.space @signalapp@mastodon.world @monocles@monocles.social @lauren@mastodon.laurenweinstein.org Very few systems promoted as Signal alternatives match the cryptographic privacy properties (see: ratcheting, etc.) of Signal. The claims about "located in the USA" and "Cloud Act" are all nonsense because the only threat to Signal users from this is availability (seizure and shutdown of the server infrastructure), not undetected breakage of privacy properties. There are presently no systems with superior privacy properties to Signal *and* level of functionality on par with what general public expects. There are a lot (like the XMPP stuff, *sigh*, and Matrix) that are worse in both regards. If you're happy with reduced functionality, Cwtch (and possibly some other similar Tor-based systems) or VeilidChat are stronger, but it's gonna be a while before you convince normies to use them, and in the mean time they're still going to be on insecure shit like WhatsApp, FB Messenger, Telegram, etc...

If you are a small ISP and you host anything vaguely similar to this, and it gets discovered, the FBI will drop by your home after midnight, and take you in a van blindfolded in the middle of the night.

But for Google Doxx... business as usual.

Replied in thread

@anelki I do agree to some extent.

#PGP/MIME & #XMPP+#OMEMO keep the coversation contents secure, but merely encrypting messages is just 10% of #ComSec!

Like: If you use some garbage Android 8.1 device that never got security updates then you can use #Signal all day and that won't protect ya ass!

none of them will refuse to comply with a duely submitted subopena, otherwise @Mer__edith would already be in prison.

Twitterthaddeus e. grugq on Twitter“I’m gonna tell you a secret about “logless VPNs” — they don’t exist. Noone is going to risk jail for your $5/mo https://t.co/Q2aOQJkG4g”
Replied in thread

@jensorensen
Which reminds me. I occasionally shop at #Ocado and have never had a problem with the process... except the other day I could no longer get the 'login' button to 'stay depressed'. After spotting some 'interesting' traffic I tried (temporarily) relaxing my firewall rules wrt certain g00gle domains and, et voila, all was 'normal'.
#WTF #privacy #surveillance #consumer #security #comsec #thirdpartyparasites

RANT: Yet another reason why I'll never buy a new car in my life

  • I had a rental (#Peugeot2008) which is one of these garbage "#Crossover" / #SuperUselessVehicles that are PHAT outside but crammed af inside due to a needlessly W I D E center console and barely adjustable driver seat and steering wheel.

  • This car is basically impossible to reverse without staring at it's backup camera as it has a giant-ass deadzone behind it.

  • It's shitty front allows children to hide even easier than the rear and makes parking even more stressful

But what made my blood boil is the obnoxiousness with which it's shitty tablet decided to randomly (!), whilst driving >50km/h to just pop up a demand for #tracking bs, offering only "allow" and "later" instead of a "no thanks" / "don't ask me again" option.

  • Shit like this can literally kill people as they fiddle around trying to dismiss it.

  • I had it pop up 2x (!) within 5 mins (!!) on the same (!!!) trip [not plulling ignition key!] And at tue 2nd time decided to pull over to document this shit.

This kind of #Enshittification in the form of a #Car comitting an "Exhaustion Attack" against it's own driver needs to be outlawed, not mandated!

Cc: @bmdv @EUCommission / @EU_Commission

@Joseph I've to disagree with @deviantollam on that part solely because #Cyberfacism at the U.S. border necessitates said #ITsec, #InfoSec, #OpSec and #ComSec...

Like even if I wanted to enter the #USA [which I don't considering the fact that more and more states try to criminalize the very existance of several of my mutuals and don't get any repercussions for doing so!] I'd certainly not bring any device with me with any data on it!

defcon.social/@deviantollam/11

DEF CON SocialDeviant Ollam (@deviantollam@defcon.social)Sigh. Every year around this time we see people posting the same tired, old advice about DefCon that hasn't felt relevant in over a decade: "Don't turn on your laptop" and "Bring a burner phone" and all that other hooey. Am I going to have to do a video that pushes back against this? 🫣

@enno not that surprising given that every #SingleVendor / #SingleProvider "solution" for communications will inherently have #Govware #backdoors, otherwise they'd be illegal!

That's why noone who takes #ITsec, #InfoSec, #OpSec & #comSec 100% seriously will use them for anything but posting public info.

That's how the drug dealers using #EncroChat & #ANØM got caught and why noone should trust any #VPN or #Messenger!

youtube.com/watch?v=WVDQEoe6ZW
twitter.com/thegrugq/status/10

So that's how the #French #Police cracked shit...

Thanks @tails for the info:
tails.boum.org/security/argon2

I guess a lot of people now have their weekends f**ked because they gonna need to re-encrypt shit.

Gladly I'm not affected as I user 128-digit passwords wherever possible...
github.com/kkarhan/misc-script

But a lot of you folks may be!

Please check your crypto settings NOW!

tails.boum.orgTails - Weak cryptographic parameters in LUKS1