Tutanota, to opsec
@Tutanota@mastodon.social avatar

Are you a journalist, activist or whistleblower in need of an anonymous email account that doesn't require a personally identifiable recovery email address or phone number?

Tuta has you covered. 👉 https://tuta.com/blog/anonymous-email

This is anonymity done right. 😎
#anonymous #opsec #privacy #encryption

cs, (edited ) to random
@cs@mastodon.sdf.org avatar

Do you have your own web site? Do you use https for it?

cs,
@cs@mastodon.sdf.org avatar

@rmbolger I've considered this, but there's a lot of moving parts, and as a hobbyist, this all comes out of my pocket. I just renewed my annual hosting in February, too. I put the call out in January asking folks if they had any recommendations, and no one did (obviously I don't have much reach as a mastodon user).

cs,
@cs@mastodon.sdf.org avatar

Thanks for participating, folks

gcluley, to random
@gcluley@mastodon.green avatar

I've managed to get my paws on "Dark Wire" by @josephcox, a great new book telling the incredible true story of how the FBI launched a fake encrypted messaging service and spied on the communications of the world's most notorious criminal gangs.

An amazing tale.

echo_pbreyer, to random German
@echo_pbreyer@digitalcourage.social avatar

🇬🇧 Have you heard about the #EUGoingDark plan to reintroduce blanket #DataRetention & undermine #encryption 🔓?

Intransparent 🇪🇺 work on what the new EU Parliament & Commission should implement after the #EUelections will be finalised in Mai & June.
#Pirates

fsf, to random
@fsf@hostux.social avatar

Did someone say #encryption? Encryption helps protect the privacy of people you communicate with, and makes life difficult for bulk #surveillance systems. Learn more with our Email Self Defense guide: https://u.fsf.org/1df

remixtures, to Bulgaria Portuguese
@remixtures@tldr.nettime.org avatar

#EU #Spain #Catalonia #Cybersecurity #Privacy #Encryption #Wire #Proton: "As part of an investigation into people involved in the pro-independence movement in Catalonia, the Spanish police obtained information from the encrypted services Wire and Proton, which helped the authorities identify a pseudonymous activist, according to court documents obtained by TechCrunch.

Earlier this year, the Spanish police Guardia Civil sent legal requests through Swiss police to Wire and Proton, which are both based in Switzerland. The Guardia Civil requested any identifying information related to accounts on the two companies’ respective platforms. Wire responded providing the email address used to register the Wire account, which was a Protonmail address. Proton responded providing the recovery email for that Protonmail account, which was an iCloud email address, according to the documents.

In the request, which listed “organised crime” and “terrorism” as the nature of the investigation, Spanish police wrote that it wanted to “find out who were the perpetrators of the facts taking place in the street riots in Catalonia in 2019.”"

https://techcrunch.com/2024/05/08/encrypted-services-apple-proton-and-wire-helped-spanish-police-identify-activist/

kubikpixel, to terraform German
@kubikpixel@chaos.social avatar

Jetzt keine (doofe) Sprüche, dass veganer Tofu nicht schmeckt und seltsam wäre, es geht um IT-Sicherheit! ;)

»Freie Terraform-Alternative – Opentofu ermöglicht "state encryption":
Seit über zehn Jahren klagen Terraform-Nutzer über unverschlüsselte state files. Version 1.7 der freien Alternative Opentofu bietet nun optionale Verschlüsselung an.«

🔑 https://www.golem.de/news/freie-terraform-alternative-opentofu-ermoeglicht-state-encryption-2405-184861.html


lobingera,
@lobingera@chaos.social avatar

@kubikpixel Ähm "dass veganer Tofu nicht schmeckt" - es gibt nicht-veganen Tofu?

kubikpixel,
@kubikpixel@chaos.social avatar

@lobingera nö 😉

kushal, to linux
@kushal@toots.dgplug.org avatar

Oh, cryptsetup luksDump output changed over the years! #Linux #encryption.

purpleidea,
@purpleidea@mastodon.social avatar

@kushal Tell us more...

kushal,
@kushal@toots.dgplug.org avatar

@purpleidea I have to update the guides, nothing super special but changes in output means changes in user guide.

LinuxAndYarn, to random
@LinuxAndYarn@mastodon.social avatar

Has anyone had to deal with #Imperva? For some goddamned reason they've backslid and will no longer accept 4096-bit #encryption certificates and demand 2048-bit certs again.

kubikpixel, to rust
@kubikpixel@chaos.social avatar

Do any of you #Rust developers know what the #EMail Server @stalwartlabs uses for an #OpenPGP solution – Is it #rPGP or even Sequoia--PGP? 🤔

I would like to use @sequoiapgp on the basis of personal arguments and this #RustLang E-Mail #encryption 🔐📧

wiktor,
@wiktor@metacode.biz avatar

Based on their Cargo.toml (https://github.com/stalwartlabs/mail-server/blob/e10083651b4bf58d4a78c49f285efac9c5bad4e2/crates/jmap/Cargo.toml#L48) it seems they’re using experimental cryptographic backend which is not "considered mature enough for general consumption": https://gitlab.com/sequoia-pgp/sequoia/-/tree/main/openpgp?ref_type=heads#experimental-and-variable-time-cryptographic-backends

Additionally it looks like they’re not using the recommended way of importing Sequoia: https://gitlab.com/sequoia-pgp/sequoia/-/tree/main/openpgp?ref_type=heads#how-to-select-crypto-backends-in-crates

I don’t have any personal association with Stalwart but maybe it'd be a good idea to report that at https://github.com/stalwartlabs/mail-server/issues ?

👋

kubikpixel,
@kubikpixel@chaos.social avatar

@wiktor thanks! 👍

kubikpixel, to privacy
@kubikpixel@chaos.social avatar

Not the first and certainly not the last time!

»Proton Mail Discloses User Data Leading to Arrest in Spain«

🔓 https://restoreprivacy.com/protonmail-discloses-user-data-leading-to-arrest-in-spain/


#privacy #email #security #encryption #cryptography #itsecurity #arrest

martijn,
@martijn@ieji.de avatar

@kubikpixel the user didn't practice great secops and put in an apple email as the recovery address. Swiss law requires proton to give up that decryptable recovery address. It's then #apple who handed over name, address and phone number. But apparently that doesn't make a good headline

kubikpixel,
@kubikpixel@chaos.social avatar

@martijn Yes, Switzerland collects more data than anywhere else in Europe. Every provider is obliged to keep the collected data (IP & Co.) for 6 months. But very few people outside of Switzerland are aware of this, which is why they are sold as neutral and equally secure 🤐

👉 https://arstechnica.com/information-technology/2021/09/privacy-focused-protonmail-provided-a-users-ip-address-to-authorities/

tallship, to privacy

#e2ee is a goal, not a promise. As far back as I can remember, forums like those supporting #Enigmail and #gpg were staffed with volunteers from the privacy community who repeatedly insisted on answering questions, like, "Is <this> (whatever this might be) totally secure?" with stock questions like, "What is it that you consider 'totally secure?" or answers such as, "Secure is a relative term, nothing is completely secure, how secure do you need your mission's communications to be?"

Phrases such as, reasonably secure should be indicators of how ridiculous it is to assume that any secure platform is EVER completely, and totally secure.

That begs the question, "Exactly how secure do you require your communications to be?" The answer is always, ... relative.

Which means that you should always believe Ellen Ripley when she says, "Be afraid. Be very afraid!"

https://www.city-journal.org/article/signals-katherine-maher-problem

#tallship #encryption #PGP #secure_communication #Privacy #FOSS

.

mikedev,

My experience is that state actors won't even try to decrypt your communications. That's old school - and a horribly inefficient use of resources. They'll come after you with a keylogger or manufactured legal nightmares or torture - to either or both sides of the communication; depending on the perceived value of your secret.

It all comes down to 4 fundamental questions:

  • What is the value of your secret to you
  • What resources do you have available to protect it
  • What is the perceived value of your secret to your adversary
  • What resources do they have available to divulge it
remixtures, to Cybersecurity Portuguese
@remixtures@tldr.nettime.org avatar

: "Researchers have devised an attack against nearly all virtual private network applications that forces them to send and receive some or all traffic outside of the encrypted tunnel designed to protect it from snooping or tampering.

TunnelVision, as the researchers have named their attack, largely negates the entire purpose and selling point of VPNs, which is to encapsulate incoming and outgoing Internet traffic in an encrypted tunnel and to cloak the user’s IP address. The researchers believe it affects all VPN applications when they’re connected to a hostile network and that there are no ways to prevent such attacks except when the user's VPN runs on Linux or Android. They also said their attack technique may have been possible since 2002 and may already have been discovered and used in the wild since then."

https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose

alshafei, to privacy
@alshafei@mastodon.social avatar
narunya,
@narunya@mastodon.social avatar

@alshafei Note that Proton doesn't zero access encrypt the subject lines and recipient/sender addresses, as per: https://proton.me/support/proton-mail-encryption-explained

which leaks a substantial amount of metadata.

cyrus,
@cyrus@wetdry.world avatar

@runoutgroover

(just to be clear, Tuta has to give way more under German law than Proton under Swiss law)

br00t4c, to internet
@br00t4c@mastodon.social avatar

End-to-end encryption may be the bane of cops, but they can't close that Pandora's Box

https://go.theregister.com/feed/www.theregister.com/2024/05/05/e2ee_police/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • anitta
  • khanakhh
  • mdbf
  • InstantRegret
  • Durango
  • Youngstown
  • rosin
  • slotface
  • thenastyranch
  • osvaldo12
  • ngwrru68w68
  • kavyap
  • cisconetworking
  • DreamBathrooms
  • megavids
  • magazineikmin
  • cubers
  • vwfavf
  • modclub
  • everett
  • ethstaker
  • normalnudes
  • tacticalgear
  • tester
  • provamag3
  • GTA5RPClips
  • Leos
  • JUstTest
  • All magazines