yossarian, to programming
kushal,
@kushal@toots.dgplug.org avatar

@glyph @gpshead @yossarian I beg to differ on that point. @saptaks & I are building https://tumpa.rocks/

Here is an example where we can have better UX focused tools in the #OpenPGP land.

arstechnica, to random
@arstechnica@mastodon.social avatar

Microsoft is scanning the inside of password-protected zip files for malware

If you think a password prevents scanning in the cloud, think again.

https://arstechnica.com/information-technology/2023/05/microsoft-is-scanning-the-inside-of-password-protected-zip-files-for-malware/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

kikobar, (edited )
@kikobar@acc4e.com avatar

@arstechnica yes, password-protected zip files are just an illusion of privacy.

In fact, these researchers were not using them for privacy, but as a way of sending malware samples to each-other without being stopped by the malware scanners.

What I don't understand is why so many banks and financial institutions are so fond of them. They keep sending sensitive information via email on password-protected zip files where the password is your ID or your birthday... 🙄

Proper end-to-end encryption has been around for decades. 🤷‍♂️

#privacy #security #pgp #openpgp

hko, to random
@hko@fosstodon.org avatar

I've just released an alpha.1 version of OpenPGP CA 0.13:
https://crates.io/crates/openpgp-ca/0.13.0-alpha.1

This release offers a preview of the new "Split" mode.

For details about split mode OpenPGP CA, see https://gitlab.com/openpgp-ca/openpgp-ca-web/-/blob/split/content/doc/split-mode.md (some details may change between now and the first stable release in the 0.13 series)

This work was supported by NLnet @NGIZero, thank you!

blake, to random

In case it helps someone else: To change the #OpenPGP smartcard PIN on my #YubiKey, gpg --change-pin does NOT work for some reason. Using gpg --card-edit and putting admin and then passwd into the prompt lets me do it though.

#gpg #gnupg

decathorpe, to random
@decathorpe@mastodon.social avatar
  1. I pushed another update for #Sequoia #OpenPGP (version 1.16.0), which fixes a handful of parser bugs that could result in crashes caused by out-of-bounds array accesses. All affected applications were rebuilt with the new version. 🕶️

This also included the latest version of sequoia-octopus-librnp, which provides better compatibility with recent versions of #Thunderbird.

Updating sequoia-sq to the latest version is still blocked, because some of the new dependencies have blocking issues 😐

kaiengert, to random
@kaiengert@mastodon.social avatar

We have a new #OpenPGP passphrase protection feature in #Thunderbird Daily (development) builds, in response to requests we received in the past. Here's a description and call for testing:
https://thunderbird.topicbox.com/groups/e2ee/Tdc427a8b0255b85a/passphrase-protection-for-openpgp-secret-keys
I'd welcome some testing and feedback.

deepsec, to random

Press Release: A 40-year Step Backwards for Secure Communication
The UK government's Online Safety Bill wants to set back the state-of-the art for secure communication 40 years backwards. The proposal includes compulsory backdoors for communication platforms and wil
https://blog.deepsec.net/press-release-a-40-year-step-backwards-for-secure-communication/
.0

Goffi, to random French
@Goffi@mastodon.social avatar

#OX (XEP-0373, XEP-0374: #OpenPGP for #XMPP, without security problems of historical XEP-0027) implementation has been merged to #Libervia, thanks to Syndace again, and #NLnet for their funding.

OX doesn't have PFS (https://en.wikipedia.org/wiki/Forward_secrecy) but that means that new devices can access archives, which may be desirable. Also, it can encrypt arbitrary elements.

It is also a brick for incoming feature such as #pubsub #e2e #encryption .

stay tuned

  • All
  • Subscribed
  • Moderated
  • Favorites
  • provamag3
  • InstantRegret
  • mdbf
  • ethstaker
  • magazineikmin
  • GTA5RPClips
  • rosin
  • thenastyranch
  • Youngstown
  • osvaldo12
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • JUstTest
  • Durango
  • everett
  • cisconetworking
  • Leos
  • normalnudes
  • cubers
  • modclub
  • ngwrru68w68
  • tacticalgear
  • megavids
  • anitta
  • tester
  • lostlight
  • All magazines