@ju916@chaos.social
@ju916@chaos.social avatar

ju916

@ju916@chaos.social

Just ju - breaking things and writing about it @heise

This profile is from a federated server and may be incomplete. Browse more on the original instance.

ju916, to Cybersecurity German
@ju916@chaos.social avatar

Da können wir von der Security ja jetzt Feierabend machen ... https://www.heise.de/news/l-f-Cisco-erfindet-die-Security-neu-9691102.html

ju916,
@ju916@chaos.social avatar

@Krisuuu gute Erholung

ju916, to random German
@ju916@chaos.social avatar

Das Internet schrammt haarscharf an einem Super-GAU vorbei - und fast niemanden interessiert es ¯_(ツ)_/¯
https://www.heise.de/hintergrund/Die-xz-Hintertuer-das-verborgene-Oster-Drama-der-IT-9673038.html

ju916,
@ju916@chaos.social avatar

@mp full ack ... solange es nicht knallt, kann man einfach so weitermachen

Krisuuu, to random German

Habe schon lange nicht mehr so einen gut geschrieben Artikel gelesen.

Danke @ju916

https://www.heise.de/hintergrund/Die-xz-Hintertuer-das-verborgene-Oster-Drama-der-IT-9673038.html

ju916,
@ju916@chaos.social avatar

@Krisuuu danke für die Blumen :)

zackwhittaker, to random
@zackwhittaker@mastodon.social avatar

This is a really good and important look at Lockdown Mode by @lhn. "Surprisingly usable" — yes! The tiny bit of friction that users experience with Lockdown Mode (such as having to copy and paste links manually from Messages to Safari) quickly becomes second nature.

https://www.wired.com/story/apple-lockdown-mode-hands-on/

ju916,
@ju916@chaos.social avatar

@zackwhittaker @lhn for me the thing hurting most is the added complexity in opening a PDF

ju916, to random
@ju916@chaos.social avatar

@evawolfangel super cool, wie du das Mikro-Chaos gestern gemanaged hast #37c3 - der Talk war auch toll.

ju916, to random
@ju916@chaos.social avatar

on #37c3 now - ping me to meet

kuketzblog, to random German
@kuketzblog@social.tchncs.de avatar

Ich kann mich des Eindrucks nicht erwehren, dass die Chefin von Signal den Kern des Problems a) nicht angesprochen b) nicht erkannt hat. 👇

https://social.tchncs.de/@Mer__edith/111563865488495642

Das Problem lässt sich nur durch einen Verzicht auf die Push-Dienste von Google/Apple lösen.

ju916,
@ju916@chaos.social avatar

@kuketzblog das hat sie doch: sie sagt ganz klar, dass es derzeit keine wirklich praktikable Option gibt, auf diese Dienste zu verzichten. Und auch dass das ein Problem ist, das ihnen bewusst ist.

ju916, to Matrix
@ju916@chaos.social avatar

What matrix chatserver do you use and why? #matrix #chat #37c3

ju916,
@ju916@chaos.social avatar

to clarify: I am looking for a nice homeserver - no time/energy to run my own

18+ ju916, (edited ) to privacy
@ju916@chaos.social avatar

I am a little surprised that a lot of people use their own resolver for reasons. I think this is counter productive and putting their privacy at risk. Let me explain why in a thread and offer a better alternative 1/n

ju916,
@ju916@chaos.social avatar

DNS data is collected and analysed continuously by interested parties. search for „passive DNS“ to learn more about that. The data is even sold. 3/n

ju916,
@ju916@chaos.social avatar

Normally you send your DNS requests to a resolver - by default the one of your provider. They do the actual name resolution for you and answer with the IP address 4/n

ju916,
@ju916@chaos.social avatar

This means that an interested party - lets name it NSA - which is monitoring for example the DNS authority for y.z will only see the request of your provider (or whatever public resolver you use). Your interest in x.y.z remains hidden to them. 5/n

ju916,
@ju916@chaos.social avatar

Your DNS requests are only visible to your provider (and whoever can coerce them into helping them). More on this later when we talk about DoT. But the rest of the internet will never see your interest in x.y.z (setting aside things like SNI - but that is for another thread) 6/n

ju916,
@ju916@chaos.social avatar

To avoid the dependency (and censorship) from a third party some ppl operate their personal resolver (for example outbound on a pi-hole). All their devices will query this resolver - even from abroad via VPN. 7/n

ju916,
@ju916@chaos.social avatar

While this makes sense for a company or an organization, it is dangerous for individuals. Because NSA’s monitoring of y.z will suddenly record your personal IP and they now can trace your interest in x.y.z back to you. 8/n

ju916,
@ju916@chaos.social avatar

So my recommended setup for aware individuals is: always use a public resolver that is operated by a third party you trust. Maybe that is @quad9dns or @mullvad or @digitalcourage. This way your DNS requests are hidden behind their IP 9/n

ju916,
@ju916@chaos.social avatar

And to protect the transport from your device to the resolver from monitoring and manipulation by third parties use DNS over TLS (DoT). Every privacy aware DNS provider will offer that nowadays. Thanks for reading this far. EOT 10/10

ju916,
@ju916@chaos.social avatar

@Michael1 @heisec In your example monitoring the authority for .org gives them that you are talking to eff.org - and probably is making you suspicious ;)

ju916,
@ju916@chaos.social avatar

@MrKanister using pi-hole is fine. Because in its default configuration it acts as a forwarder and does not resolve on its own. Pi-hole gives you more control about what you block.

ju916,
@ju916@chaos.social avatar

@partim @quad9dns @mullvad @digitalcourage of course you can always do better 😅

ju916,
@ju916@chaos.social avatar

@loremo my ISP has to have special listening interfaces for autonomous access by state authorities - it’s the law. So I trust them only as much as I have to.

ju916,
@ju916@chaos.social avatar

@pixelcode obviously. But I was surprised how many ppl answered that they use their own resolver for more here https://chaos.social/@ju916/111431465864529542

so I wrote that thread.

ju916,
@ju916@chaos.social avatar

@loremo not every resolver of course. But @digitalcourage has been fighting for #privacy for a long time. I trust them to do the right things for the right reasons. Quad9 has a strong commitment to privacy and their hq is located in Switzerland and therefore outside of easy reach for german institutions. Just find the org you trust…

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • ngwrru68w68
  • tester
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • megavids
  • tacticalgear
  • osvaldo12
  • normalnudes
  • cubers
  • cisconetworking
  • everett
  • GTA5RPClips
  • ethstaker
  • Leos
  • provamag3
  • anitta
  • modclub
  • lostlight
  • All magazines