helvede.net is one of the many independent Mastodon servers you can use to participate in the fediverse.
Velkommen til Helvede, fediversets hotteste instance! Vi er en queerfeministisk server, der shitposter i den 9. cirkel. Welcome to Hell, We’re a DK-based queerfeminist server. Read our server rules!

Server stats:

167
active users

#Encrochat

0 posts0 participants0 posts today
Replied in thread

@froge @fj I'm not replacing @signalapp with "random tools" but good options.

Like @delta & @thunderbird as well as @monocles / #monoclesChat & @gajim which owrk flawlessly over @torproject / #Tor using @tails / @tails_live / #Tails and @guardianproject / #Orbot respectably.

Considering the costs of even acquiring and upkeeping an #anonymous #SIM, I'd rather pay €2 p.m. for #XMPP+#OMEMO and #PGP/MIME-supported #eMail with thr option of self-custody than $2,50+ p.m. just to keep a phone number.

Or is anyone here expecting @Mer__edith to risk jail for life amd not comply with #CloudAct?

It stenches like #ANØM, because NOTHING IS FOR FREE and running a #VCmoneyBurningParty is expensive...

Infosec.SpaceKevin Karhan :verified: (@kkarhan@infosec.space)@osman@hachyderm.io If your #OpSec, #InfoSec, #ComSec and/or #ITsec relies on @signalapp@mastodon.world and/or @Mer__edith@mastodon.world [risking jail *or worse*](https://web.archive.org/web/20210908180219/https://twitter.com/thegrugq/status/1085614812581715968), you fucked up! - If #Signal was secure, it would've been shutdown like #EncroChat & #SkyECC. Seriously, to me #Signal stenches #Honeypot like #ANØM & #CryptoAG. - All Signal fans do is #FUD #PGP/MIME and#XMPP+#OMEMO which are truly #decentralized and allow real #SelfHosting as well as #SelfCustody for complete control of all the data and keys... That's why I get people setup with it!
Replied in thread

@dalias @lauren
@pixelschubsi

Also the blatant dismissal of absolitely basic #OpSec & #ComSec is just flabberghasting.

Only #decentralized, #OpenSource & #OpenStandards can actuall survive long-term and remain #secure.

It's the same reasons we use #PGPG/MIME & #SSH and not #X400 & #X25!

IOW: Think "How can you weaponize Signal?" and see what you csn do just holding key people in contempt...

The less #info a provider has, the less they can be forced to snitch upon customers.

"#JustUseSgnal!" is a form of dangerous "#TechPopulism" aimed at bamboozling #TechIlliterates who don't know better, abusing information asymetry to pull rank instead of investing the time and effort to *explain "how" and "why" this is indeed a good or bad idea.

The only ones that have a chance to beat that are @delta / #deltaChat but that's just #PGP/MIME #eMail in a nice UI...

  • You may now laugh at me and think my "#TinfoilHat sits too tight" but I'm shure sooner or later I'll be evidenced as correct...
Hachyderm.ioCassandrich (@dalias@hachyderm.io)@kkarhan@infosec.space @signalapp@mastodon.world @monocles@monocles.social @lauren@mastodon.laurenweinstein.org Very few systems promoted as Signal alternatives match the cryptographic privacy properties (see: ratcheting, etc.) of Signal. The claims about "located in the USA" and "Cloud Act" are all nonsense because the only threat to Signal users from this is availability (seizure and shutdown of the server infrastructure), not undetected breakage of privacy properties. There are presently no systems with superior privacy properties to Signal *and* level of functionality on par with what general public expects. There are a lot (like the XMPP stuff, *sigh*, and Matrix) that are worse in both regards. If you're happy with reduced functionality, Cwtch (and possibly some other similar Tor-based systems) or VeilidChat are stronger, but it's gonna be a while before you convince normies to use them, and in the mean time they're still going to be on insecure shit like WhatsApp, FB Messenger, Telegram, etc...
Replied in thread

@CCC Das wird dem Wüst aber nix nützen, denn sie können nix anfangen, mit den Daten. Der einzige Grund für den Irrsinn ist, dass die Polizei zu langsam ist. Das ist sie, weil sie im Verfahrensirrsinn gefangen ist. (zertifiziert in 3facher Ausfertigung).

Anstatt positive Lehren aus #Encrochat zu ziehen, kommen die Herren Ahnungslos mit der Überwachungsgiesskanne, die ihnen von irgendwelchen Appartschiks eingeflüstert werden.

Das Risiko für Demokratie wird erhöht ohne wirklichen Gegenwert.

Another successful French/Dutch (via #Europol) infiltration of an encrypted messaging service, using the same Joint Investigation Team procedure as against #Encrochat. I wonder how they technically targeted the service this time — another weakness in the updating mechanism or other client software; handset vulnerability… 🧐 We’ll find out when the first trials take place! europol.europa.eu/media-press/

EuropolInternational operation takes down another encrypted messaging service used by criminals | EuropolBlack glove holding phone
Replied in thread

This goes back to the Trojan Horse & its warning.

Yes, making a horse that soldiers can hide in and then spring out of is ingenious.

But it’s useless unless you can make your enemy accept the thing you’ve primed. Coordinated & wholesale.

And orgs should know better.

See also: cops using EncroChat to catch whole drug dealing and organised crime networks.

I mean come on people.
#Encrochat #Cybersecurity

newyorker.com/magazine/2023/04

Replied in thread

@leitmedium ich halte das für Geschwätz seitens @signalapp und @Mer__edith im speziellen, weil die sich bisher nirgendwo zurückgezogen haben.

Ich garantiere dir dass wenn mit Beugehaft bedroht jede*r bei Signal deren User doxxed - so wie's VPN-Anbieter taten und tun.

Wenn Signal wirklich auf #Sicherheit und #Privatsphäre fokussiert wäre, dann hätten diese einfach nen #XMPP + #OMEMO - Server im @torproject / #Tor - Netzwerk aufgezogen und auch das gesamte #Backend #dezentralisiert!

  • Wäre Signal so sicher wie diese behaupten, dann wäre der Dienst qua #CloudAct lange verboten und das Personal in Haft!
Twitterthaddeus e. grugq on Twitter“I’m gonna tell you a secret about “logless VPNs” — they don’t exist. Noone is going to risk jail for your $5/mo https://t.co/Q2aOQJkG4g”

Things that #UK still exchanges data about and works alongside #EU post #Brexit

* #weather forecasting and monitoring (including climate research)

* #RoadSafety and traffic regulations

* #drugs prohibition (during EU membership UK was viewed as a source of good practice, especially for testing of drug use by drivers)

* law enforcement and #surveillance in general (consider the fallout from #Encrochat )

so the gammons have gained exactly 0 extra freedoms, and are even angrier..

Replied in thread

@Em0nM4stodon

In a similar vein, make sure that things like your fingerprints aren't easily shown in any photos you share online. Take this almost hilarious example from a couple years ago as to why you should be careful about including your fingerprints in photos you upload.

A drug dealer was identified because of a picture of a block of cheese he posted online, and was subsequently arrested. In the photo, it clearly showed his fingerprints thanks to modern camera technology allowing for higher image resolutions.

If law enforcement is able to capture a person's fingerprint reliably through a photo, then so can anyone else. With enough time and skill, a bad actor use it for nefarious purposes and potentially even unlock your phone with a rubber mold.

Remember, you can always change a password, but you can't change your fingerprint.

theverge.com/tldr/2021/5/24/22

The VergeA photo of cheese just got a UK drug dealer sentenced to 13 years in prisonBy Jon Porter

@enno not that surprising given that every #SingleVendor / #SingleProvider "solution" for communications will inherently have #Govware #backdoors, otherwise they'd be illegal!

That's why noone who takes #ITsec, #InfoSec, #OpSec & #comSec 100% seriously will use them for anything but posting public info.

That's how the drug dealers using #EncroChat & #ANØM got caught and why noone should trust any #VPN or #Messenger!

youtube.com/watch?v=WVDQEoe6ZW
twitter.com/thegrugq/status/10

@AnarchoNinaWrites OFC!

In fact, all those services stench like the #Honeypots they are and I'd call LEAs to be "criminally incompetent" if they didn't sabotage it [#EncroChat] or did actually run it from day 0 [#ANØM]...

Cuz when push comes to shove, they'll all rat out their users!
youtube.com/watch?v=QCx_G_R0Um
twitter.com/thegrugq/status/10

Replied in thread

@atomicpoet @zakiuem even Signal and Briar ain't good.

All #centralized and/or #SingleVendor / #SingleProvider Messenger Services are inherently insecure as they'll be obligated to comply with #Govware #backdoor requirements aka. " #LawfulInterception "...

Otherwise they'd be illegal and forcibly shut down by LEAs - just like #EncroChat was [which was also #insecure for the aforementioned reasons + being #CCSS and not #FLOSS thus not auditable]...