5am, to security
@5am@fosstodon.org avatar

Need an easy and secure way to send a password to someone (typically as a one-off)? I wrote about a solution, the Password Pusher tool:
https://www.samhowell.uk/posts/2024/03/sending-passwords-securely/

Tutanota, to privacy
@Tutanota@mastodon.social avatar

Who are your and heroes? Let us know in the comments!

garry, to technology
@garry@mstdn.social avatar

Unpatchable security flaw in Apple Silicon Macs breaks encryption

'University researchers have found an unpatchable security flaw in Apple Silicon Macs, which would allow an attacker to break encryption and get access to cryptographic keys.
The flaw is present in M1, M2, and M3 chips, and because the failing is part of the architecture of the chips, there’s no way for Apple to fix it in current devices …'

https://9to5mac.com/2024/03/22/unpatchable-security-flaw-mac/

openrightsgroup, to privacy
@openrightsgroup@social.openrightsgroup.org avatar

Do you share our concerns with Government's plans to control the UK's tech industry and force them to place secret backdoors in their software? If so then take action today and write to your MP https://action.openrightsgroup.org/write-your-mp-about-threats-our-online-security-and-privacy -

openrightsgroup, to privacy
@openrightsgroup@social.openrightsgroup.org avatar

UK Civil Society and the Tech Industry join forces to warn of new 'Mass surveillance' fears. https://bbc.co.uk/news/technology-68625232 -

stefano, to Cybersecurity
@stefano@bsd.cafe avatar

A capable colleague passed on a request from their client. They want to know if the VM disks are encrypted at rest, if the keys are rotated periodically, and if there's a key retention procedure in place. Ironically, the client's VPS runs on Ubuntu 18.04, which has been out of updates for a year, and despite numerous notifications to upgrade, they believe it can wait. 😄

davemark, to science
@davemark@mastodon.social avatar

"Cloudflare translates photos of 100 lava lamps into random data for use in SSL encryption."

Wait, what? This true?

Apparently so. @cloudflare uses a clever camera rig pointed at a wall of lava lamps to generate random numbers.

WOW.

https://www.cloudflare.com/learning/ssl/lava-lamp-encryption/

protonmail, to random
@protonmail@mastodon.social avatar

Today is the #idesofmarch, marking Julius Caesar's assassination and a turning point in Roman history. But, what does this have to do with #encryption, you ask?

Here's a fun fact:
⬇️

1 / 3

protonmail,
@protonmail@mastodon.social avatar

Caesar used to communicate privately by encrypting his correspondence with what came to be called the #caesarcipher.

This simple and widely known encryption technique is a substitution cipher in which each letter in plaintext is replaced by another letter following a fix position further up or down the alphabet.
This modest form of #encryption required no mathematics, and it could be done by finger-counting.

2 / 3

ai6yr, to ai
encryptme, to privacy
@encryptme@aus.social avatar

Denying anybody access to encryption - including children - is an attack on human rights. Plain and dystopian... I mean simple. Plain and simple.

#privacy #encryption #surveillance #humanrights

https://www.accessnow.org/press-release/nevada-must-ensure-end-to-end-encryption-for-all/

remixtures, to Cybersecurity Portuguese
@remixtures@tldr.nettime.org avatar

#CyberSecurity #Encryption #QuantumComputing: "If we do not encrypt our data with a quantum-secure algorithm right now, an attacker who is able to store current communication will be able to decrypt it in as soon as a decade. This store-now-decrypt-later attack is the main motivator behind the current adoption of post-quantum cryptography (PQC), but other future quantum computing threats also require a well-thought out plan for migrating our current, classical cryptographic algorithms to PQC.

This is the first of a series of blog posts in the Bug Hunters blog, dedicated to the topic of PQC, where we in Google's Cryptography team share our latest thoughts and reasons about the PQC migration, starting with the threat model we are working with.

Given the long timelines, our stances may evolve over time, with this blog post reflecting our understanding at the beginning of 2024." https://bughunters.google.com/blog/5108747984306176/google-s-threat-model-for-post-quantum-cryptography

danyork, to meta
@danyork@mastodon.social avatar

This was an easy blog post for me to write! There is so much wrong with the State of Nevada’s request for an injunction to prevent Meta from rolling out end-to-end encryption in Facebook Messenger. For starters, WhatsApp has had E2EE since 2016, Apple iMessage since 2011 … and more.

Hopefully the district court in Nevada will agree and NOT allow the injunction! We’ll see.

#E2EE #Encryption #Nevada #Meta

From: @internetsociety
https://techpolicy.social/@internetsociety/112083762463331724

internetsociety, to random
@internetsociety@techpolicy.social avatar

Last night we joined an effort to stop the State of Nevada from making it easier for children’s personal information to be obtained by child predators, criminal gangs, foreign nations, and others.

Together with the ACLU, @riana , @eff , @CenDemTech , @mozilla , @fight , and @signalapp , and Access Now, we filed an amicus brief asking the court to protect children by ensuring they can use the most secure communication possible!

Read more:
https://www.internetsociety.org/blog/2024/03/nevada-wants-to-reduce-online-protections-for-children/

#E2EE #encryption #nevada

CenDemTech, to random
@CenDemTech@techpolicy.social avatar

🚨 Late last night, @CenDemTech joined ACLU, @eff & research scholar @riana in filing a brief urging NV district court to reject efforts of the AG to prevent people in Nevada from using an #E2EE messaging service if they are under the age of 18. https://cdt.org/insights/cdt-defends-encryption-against-broadside-attack-from-nevada-ag/

CenDemTech,
@CenDemTech@techpolicy.social avatar

The Nevada AG's assault on #encryption is extraordinary and without precedent: it is suing a tech company to deny an entire class of users the ability to communicate securely using its encrypted messaging app. #E2EE https://cdt.org/insights/cdt-defends-encryption-against-broadside-attack-from-nevada-ag/

CenDemTech,
@CenDemTech@techpolicy.social avatar

End-to-end #encryption is essential to secure comms on inherently insecure internet+has been available by default for years from other messaging services. Denying children the opportunity to use #E2EE encrypted messaging does not protect them, but instead exposes them to danger.

CenDemTech,
@CenDemTech@techpolicy.social avatar

When a teenager confides with their parents & friends sensitive info about their health, fears, activities, & who they are with + where they are going, the communications containing that info must be secured by #encryption to promote child safety. #E2EE https://cdt.org/insights/cdt-defends-encryption-against-broadside-attack-from-nevada-ag/

CenDemTech,
@CenDemTech@techpolicy.social avatar

CDT has long supported #encryption, and is a founding member of the Global Encryption Coalition, which counts among its members other amici including the lead drafters, @internetsociety, @mozilla, @signalapp, Access Now & @fight: https://cdt.org/insights/cdt-defends-encryption-against-broadside-attack-from-nevada-ag/

Tutanota, to technology
@Tutanota@mastodon.social avatar

With the launch of our new post-quantum your data will now be safe from "Harvest Now, Decrypt Later" tactics. 👨‍🌾🔓

Find out all the ways the can get at your data and how Tuta Mail protects you! 👉 https://tuta.com/blog/post-quantum-cryptography

This approach is often taken by government agencies like the NSA or in order to decrypt encrypted messages once the is available. 🕵️

blueghost, to Signal
@blueghost@mastodon.online avatar

Signal is an encrypted messaging application that supports post-quantum cryptography.

Google Gmail is the email provider for Signal Messenger LLC, this is the company that develops the Signal messaging application and the Signal protocol.

Signal support can be contacted from within the application by going to Signal Settings (profile) > Help > Contact Us.

Website: https://signal.org

fsf, to random
@fsf@hostux.social avatar

Did someone say encryption? Encryption helps protect the privacy of people you communicate with, and makes life difficult for bulk surveillance systems. Learn more with our Email Self Defense guide: https://u.fsf.org/1df #GPG #PGP #E2E #encryption

fsf, to random
@fsf@hostux.social avatar

Did someone say encryption? Encryption helps protect the privacy of people you communicate with, and makes life difficult for bulk surveillance systems. Learn more with our Email Self Defense guide: https://u.fsf.org/1df #GPG #PGP #E2E #encryption

youronlyone, to security
@youronlyone@c.im avatar

To security experts: Do you use #VPN for services that are already end-to-end encrypted? Or, you add their apps in split-tunnelling mode?

Or, to rephrase it: is there any use in keeping end-to-end encrypted apps behind a VPN?

This is under the assumption that all things are equal (no ISP issues; no need to bypass any network set up; end-to-end encryption is enabled by default).

#e2ee #encryption #security #AskingExperts

forteller, to privacy
@forteller@tutoteket.no avatar

2024: Facebook is talking about opening up for interoperability between Messenger, WhatsApp and @signalapp

2021: Facebook is working on analyzing encrypted messages, without having to decrypt them first https://www.theinformation.com/articles/facebook-researchers-hope-to-bring-together-two-foes-encryption-and-ads

How far have they come on that work in these three years, I wonder

remixtures, to Bulgaria Portuguese
@remixtures@tldr.nettime.org avatar

#EU #DMA #WhatsApp #Cybersecurity #Interoperability #Encryption: "Europe’s DMA mandates that interoperability should not weaken security and privacy: “The level of security—including end-to-end encryption where applicable—that the gatekeeper provides to its own end-users shall be preserved across the interoperable services.”

This was always going to be a near impossibility. End-to-end encryption with endpoint assurance clearly only works where the two “ends” can actually be assured, which means—realistically—they are the same. Two WhatsApp or iMessage or Signal apps. DMA envisages a world where Signal messages might be sent to WhatApp users. And that so-called interoperability, by its very nature, breaks that model.

As EFF warned back in 2022, “requiring interoperability without unacceptable tradeoffs in security or privacy is a very high hurdle, one that might turn out to be insurmountable.”

https://www.forbes.com/sites/zakdoffman/2024/03/08/new-whatsapp-warning-iphone-15-pro-max-samsung-s24-ultra-upgrade/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • anitta
  • khanakhh
  • mdbf
  • InstantRegret
  • Durango
  • Youngstown
  • rosin
  • slotface
  • thenastyranch
  • osvaldo12
  • ngwrru68w68
  • kavyap
  • cisconetworking
  • DreamBathrooms
  • megavids
  • magazineikmin
  • cubers
  • vwfavf
  • modclub
  • everett
  • ethstaker
  • normalnudes
  • tacticalgear
  • tester
  • provamag3
  • GTA5RPClips
  • Leos
  • JUstTest
  • All magazines