Hiker, to random

Jetzt mal eine wirklich sehr nerdige #Frage.
Für diejenigen, die E-Mail-Verschlüsselung mit #GnuPG / #OpenPGP verwenden:
Lässt ihr die Betreffzeile offen oder wird die bei euch auch verschlüsselt?

kkarhan, to random German

Whilst I work on 's aka. / , I'm thinking about the other, more featureful versions.
https://github.com/OS-1337/OS1337/tree/main/docu/ideas

Besides a to launch a version there are a lot of tools I'd love to support:

  1. a Package Manager so people can just install & update shit easily:
    https://github.com/OS-1337/spm

  2. Good default Configs for a System like NTP & DNS Servers unless those are being offered per DHCP.
    https://github.com/OS-1337/conf.d

kkarhan,
  1. A repo that includes said built binaries as packages:
    https://github.com/OS-1337/pkgs

  2. Additional useful and vital packages to make OS/1337 a useable -based OS.

Stuff like:

And a plethera of other tools that are quite essential...
https://github.com/OS-1337/OS1337/blob/main/docu/ideas/packages.list.tsv

So help is appreciated...

mattblaze, to random
@mattblaze@federate.social avatar

Reminder about Mastodon "private" messages. Aside from not being end-end-encrypted (and so visible to instance administrators), they CC anyone @-mentioned ANYWHERE in the body of the message (not just those listed at the start).

They are now called "private mentions" rather than "private messages", but if you don't fully understand the semantics, this behavior may be unexpected and/or cause unpleasant side effects.

MagusNet, (edited )
amszmidt, to random
@amszmidt@mastodon.social avatar

Do people still use ?

amszmidt,
@amszmidt@mastodon.social avatar

@cms Once I got a security bug report by someone, encrypted .. that was exciting. And painful, since #GnuPG is quite hard to use.

lued, to linux
@lued@troet.cafe avatar

EN:
Unfortunately, I can't find a good entry point for this topic:
How do you implement server-side mail encryption and decryption for s/mime? I use Postfix+Cyrus.

DE:
Ich finde für das Thema leider keinen guten Einstieg:
Wie realisiert ihr serverseitige Mailver- und entschlüsselung für s/mime? Ich nutze Postfix+Cyrus.

#linux #foss #cyrus #postfix #mailing #encryption #decryption #smime

kkarhan,

@lued Das ist ja der Trick:
Das geht garnicht, jedenfalls nicht offiziell.

Es gibt ne Menge Appliances die quasi als Man-in-the-Middle agieren um dies umzusetzen aber IMHO ist das allenfalls Blenderei wenn nicht sogar digitales Schlangenöl.

Es ist einfacher allen Nutzer*innen beizubringen wie #GnuPG / #OpenPGP funktioniert als das zu realisieren...

Sonst gäb's keine #CryptoParty|s...

@cryptoparty

kkarhan,

@lued @cryptoparty Wenn sich was findet, sag' Bescheid...

Ich bezweifle allerdings dass es etwas in der Richtung gibt.

Ich selbst nutze echte #E2EE mit Self-Custody der Keys [#GnuPG] also macht es wenig Sinn was anderes zu machen.

Zumal ich eh auf #Arbyte mein Zeug mit denselben Keys signiere...

efi, to random
@efi@chitter.xyz avatar

all of the fedidrama with blocklists comes down to the idea that instances are needed for proxying traffic, but this is only true because identities are not decentralized, which is a fundamental mistake of the mastodon era of software
this is not really up to debate
without decentralized identity we will have this problem of someone else deciding what data we have access to, so if you don't like that, you have to push for it, the same way mastodon pushed for the democratization of this centralized model away from twitter, and even before mastodon others did so in a less accessible way
give power to the users by making it accessible, not by pretending that everyone can learn to use docker

kkarhan,

@efi That would require people to learn how to use #Keyoxide, #GnuPG / #OpenPGP and #SelfHost their shit which - lets be honest - nobody but the most #TechLiterate do.

And sadly we can't ban #TechIlliterates from using #Tech or the #Internet...

orhun, to rust
@orhun@fosstodon.org avatar

Just released the new version of gpg-tui! 🥳

🦀 A terminal user interface for GnuPG - written in Rust

⭐ GitHub: https://github.com/orhun/gpg-tui

🔐 Changelog: https://github.com/orhun/gpg-tui/blob/master/CHANGELOG.md

#rustlang #gnupg #terminal #tui #linux

video/mp4

kaiengert, to random
@kaiengert@mastodon.social avatar

Hello community of users. I'd like to know if some of you are still stuck at Thunderbird version 68 and the old Add-on. Is there any missing functionality in Thunderbird 115 that is still preventing you from migrating? @thunderbird

hako, to random
nobodyinperson, to manjaro
@nobodyinperson@fosstodon.org avatar

Damn, it took me less than five hours to reproduce my :manjaro: #Manjaro setup in :nixos: #NixOS from zero 💪:

  • getting #GnuPG working
  • homedir encryption with #eCryptfs
  • all software I need
  • even managed to package 3 custom things not in nixpkgs (passrofi, my #OpenTimeStamps client fork, bemoji)

Nix Packaging is indeed 𝘀𝗼 much easier than #ArchLinux, #Debian or #RPM packaging!

This is the result: https://gitlab.com/nobodyinperson/nixconfig

leak, to random

Cryptography is a tool for turning a whole swathe of problems into key management problems. Key management problems are way harder than (virtually all) cryptographers think.

kkarhan,

@roywig @thatandromeda @leak it is "good enough", cuz we ain't 15 years ago where eberything needed archaic commands.

#Thunderbird integrates #OpenPGP / #GnuPG out of the box for some time.
#Gaijim & #MonoclesChat do support #XMPP - #OMEMO and #PasswordManagers like #Enpass are so easy, it literally took me 5 minutes to explain the use and setup a complete #Noob in it.

People aren't stupid, they are lazy and get groomed into being #TechIlliterate #Consoomers...

That is the problem!

kuketzblog, to Signal German
@kuketzblog@social.tchncs.de avatar

Tipp Nr.5: Verwende keine unsicheren oder unverschlüsselten E-Mails für den Austausch sensibler Informationen. Nutze stattdessen sichere Kommunikationskanäle wie verschlüsselte E-Mails (bspw. GPG/OpenPGP) oder Messaging-Apps wie Signal oder Threema. Meide proprietäre Software/Apps, denen es an Transparenz mangelt. Die Verschlüsselung ist schlichtweg nicht überprüfbar - Backdoors bzw. Abhörhintertürchen inklusive.

netzpolitik_feed, to random German
@netzpolitik_feed@chaos.social avatar

Schon bald sollen alle EU-Bürger:innen über eine digitale Brieftasche verfügen, mit der sie sich on- wie offline ausweisen können. Ein Konsultationsprozess des Bundesinnenministeriums zeigt nun, welche Interessen die Wirtschaft dabei verfolgt. Und wie diese im Widerspruch zu Datenschutz und Privatsphäre stehen.

https://netzpolitik.org/2023/eidas-konsultation-wirtschaft-will-an-die-wallets/

kkarhan,

@netzpolitik_feed @netzpolitik_org ja, das ist eine Horroridee...

Wie wäre es wenn ich einfach meinen #GnuPG-#Pubkey anerkannt bekomme?

Wäre sinnvoller und sicherer!

fsf, to random
@fsf@hostux.social avatar

GNU Spotlight with Amin Bandali: Twelve new GNU releases in the last month, including #GCC, #GnuPG, #R, and more. Full details: https://u.fsf.org/400 Big thanks to @bandali0 @bandali, all the devs, and other contributors!

ablackcatstail, to random

Cryptography came to my rescue today. Thank you #GNUPG! When I had suspicions that a coworker wanted to get me fired I signed a document with my private key. When she summarily accused me of an alteration she made, #gpg revealed that she made the alteration and not me. The infosec officer and HR escorted her out. #Buhbye. I love being underestimated.

tarnkappeinfo, to Podcast German
@tarnkappeinfo@social.tchncs.de avatar
kkarhan,

@tarnkappeinfo warum kann man bei #GnuPG nicht einfach

gpg --encrypt ./unencrypted.file ./pubkey.asc
bzw.
gog --decrypt ./encrypted.file.gpg ./private.key.asc

machen?

Das gegenwärtige Setup verhindert wirksam gute.Skriptbarkeit in #bash & #fish!

marcel, to random German

Ihr entschuldigt mich kurz? Ich gehe mich mal kurz erbrechen... #40MillionenEuroFuerDieTonne

kkarhan,

@bison @marcel IMHO ist #beA wie #DeMail eine absolute #Bullshit-Idee denn es wäre signifikant einfacher, billiger und effektiver ne #eMail-#Archivierung + #GnuPG / #OpenPGP für #Verschlüsselung und #Signatur zwangsweise einzuführen.

Vorallem weils weiterhin #Datenhoheit und #Dezentralisierung ermöglicht und #Thunderbird als Client das supr easy macht.

Kann daher verstehen dass einige Anwält*innen sich dem shice von wegen beA wie auch DeMail konsequent verweigern.

koko, to random

there's two ends to the "don't touch my UX, it's perfect the way it is now" spectrum: websites that get redesigned every 2 years to appease shareholders, and GIMP

kkarhan,

@koko ...as well as #CLI - oriented tools like #GnuPG that don't allow basic shit like "encrypt/decrypt file with keyfile" but expect people to use "keyrings"...

FediFollows, to random

End-to-end Encryption / #E2EE picks of the day:

(all these are FOSS & E2EE)

➡️ @cryptpad - Online collaborative office suite

➡️ @briar - P2P messaging for activists, journalists etc

➡️ @delta - Encrypted chat system, piggybacks existing email accounts

➡️ @Tutanota - Independent email provider, supports E2EE wherever possible

➡️ @prav - XMPP app & service, developed by co-op in India

➡️ @gajim - XMPP app for Linux, Mac, Win

➡️ @Monal - XMPP app for iOS & Mac

➡️ @kaidan - XMPP app for KDE

kkarhan,

@FediFollows @cryptpad @briar @delta @prav @gajim @Monal @kaidan instead of relying on providers like @Tutanota and @protonmail, ise actual #E2EE like #PGO/MIME / #GnuPg as natively supoorted in #Thunderbird out of the box!

Remember:
#NotYourKeys = #NotInControl!!!

thunderbird, to android
@thunderbird@mastodon.online avatar

Thunderbird for Android gets one step closer, as K-9 Mail integrates Thunderbird's Autoconfiguration feature for new accounts.

Read info on that, all the other important developments, and some awesome community contributions in the new progress report:
https://blog.thunderbird.net/2023/06/thunderbird-for-android-k-9-mail-may-2023-progress-report/

kkarhan,

@codewiz @thunderbird @mozilla that's not what I consider support the same way as #Thunderbird has today...

Shure there was a time where one needed #Enigmail & #GnuPG installed seperately, but nowadays that's not needed either...

blake, to random

In case it helps someone else: To change the #OpenPGP smartcard PIN on my #YubiKey, gpg --change-pin does NOT work for some reason. Using gpg --card-edit and putting admin and then passwd into the prompt lets me do it though.

#gpg #gnupg

phryk, to random
@phryk@mastodon.social avatar

After thinking about it a bunch, I have decided that I'll refactor my cryptographic deadhand to use python-gnupg until the sequoia-sop python bindings are released.

The official #GPGME bindings are just too damn broken to be of any real use – and I think that says a lot.

Honestly, I'm not at all sure how people can release something like that as "production grade" (for security-critical tooling, no less) and not feel deeply ashamed.

shemeshg,

@phryk

GPGME

Please do note that the ME stands for 'Made Easy'. ;-)

#gpgme #gnupg

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • everett
  • rosin
  • thenastyranch
  • mdbf
  • osvaldo12
  • Youngstown
  • InstantRegret
  • slotface
  • DreamBathrooms
  • kavyap
  • ngwrru68w68
  • tester
  • normalnudes
  • megavids
  • magazineikmin
  • tacticalgear
  • khanakhh
  • GTA5RPClips
  • ethstaker
  • Durango
  • Leos
  • anitta
  • cubers
  • cisconetworking
  • modclub
  • provamag3
  • lostlight
  • All magazines