Discussion
Loading...

Discussion

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
evacide
evacide
@evacide@hachyderm.io  ·  activity timestamp 2 days ago

If you are organizing folks in Minneapolis right now, you may find this guide to Signal for beginners by @mshelton useful: https://freedom.press/digisec/blog/signal-beginners/

Freedom of the Press

Signal, the secure messaging app: A guide for beginners

Also available in Spanish.
  • Copy link
  • Flag this post
  • Block
Leander Lindahl
Leander Lindahl
@leanderlindahl@mastodon.social replied  ·  activity timestamp yesterday

@evacide @mshelton I'd like to suggest Delta chat @delta easy to install and get started with, no phone number, no central server, open source and doesn't rely on US tech from Mountain View, CA.

Signal is a really good app. But it makes me uncomfortable.

  • Copy link
  • Flag this comment
  • Block
PKPs Powerfromspace1
PKPs Powerfromspace1
@Powerfromspace1@mstdn.social replied  ·  activity timestamp yesterday

@evacide @mshelton 👌🙃

  • Copy link
  • Flag this comment
  • Block
Paulo Delgado
Paulo Delgado
@pdd@mastodon.social replied  ·  activity timestamp yesterday

@evacide @mshelton every time I see your posts:

Meme:  A cat seating at a breakfast table, reading the newspaper and feeling the urge to buy a burner phone. The caption reads "I should get a burner phone"
Meme: A cat seating at a breakfast table, reading the newspaper and feeling the urge to buy a burner phone. The caption reads "I should get a burner phone"
Meme: A cat seating at a breakfast table, reading the newspaper and feeling the urge to buy a burner phone. The caption reads "I should get a burner phone"
  • Copy link
  • Flag this comment
  • Block
Risotto Bias
Risotto Bias
@risottobias@toot.risottobias.org replied  ·  activity timestamp 2 days ago

@evacide @mshelton thank you both <3

  • Copy link
  • Flag this comment
  • Block
DrBob, Neurologist, 🧠Mechanic
DrBob, Neurologist, 🧠Mechanic
@drrjv@vmst.io replied  ·  activity timestamp 2 days ago

@evacide @mshelton Another option: #Meshtastic

https://meshtastic.org

  • Copy link
  • Flag this comment
  • Block
Lily Cohen
Lily Cohen
@lily@foothills.social replied  ·  activity timestamp 2 days ago

@drrjv @evacide @mshelton Ummm if you’re at all familiar with Meshtastic “security”, or completely lack thereof, absolutely please do not use it where you need security!!!

And this is coming from a mesh nerd…

  • Copy link
  • Flag this comment
  • Block
Lily Cohen
Lily Cohen
@lily@foothills.social replied  ·  activity timestamp 2 days ago

@drrjv @evacide Also I reread what I typed after the fact and My passion on the subject and wanting to make sure others don’t try to use it as a secure solution (trust me I think mesh tech is cool AF) could be interpreted as confrontational, accusatory, or as a doglile and was not intended to read that way. My apologies if it was received that way! 💜

  • Copy link
  • Flag this comment
  • Block
Taran Rampersad
Taran Rampersad
@knowprose@mastodon.social replied  ·  activity timestamp yesterday

@lily @drrjv @evacide I read it as a needed dash of cold water. Mesh is cool, but beta testing in production is never good, and in the environment we speak of, the stakes are higher.

You were right to say it. No apology needed.

  • Copy link
  • Flag this comment
  • Block
Jérôme
Jérôme
@jerome@jasette.facil.services replied  ·  activity timestamp 2 days ago

@lily @drrjv @evacide oh my yes… mesh is great as an alternative way to communicate outside the internet, but don’t rely on it for security or privacy

  • Copy link
  • Flag this comment
  • Block
🌱🏴‍🅰️🏳️‍⚧️🐧📎 Ambiyelp
🌱🏴‍🅰️🏳️‍⚧️🐧📎 Ambiyelp
@ambiguous_yelp@veganism.social replied  ·  activity timestamp 2 days ago

@evacide @mshelton

Signal is centralised and was attempted backdoored by the uks online safety bill and saved by signal threatening to walk. Simplex is open source and quantum resistant e2ee like signal and also has its secret group chats and metadata protection like Signal but SimpleX is also decentralised with ip protection, tor support, no persistent id basically "a burner phone for every contact"
Signals centralisation also makes it more vulnerable to total censorship, all you need to do is block signals domains, being a decentralised network SimplexChat has no single point of failure to censor and anyone can run their own relay node

#PSA #E2EE #Privacy #Encryption #Anonymity #Signal #SimpleX #UnitedKingdom #OnlineSafetyAct #Censorship

  • Copy link
  • Flag this comment
  • Block
David Chisnall (*Now with 50% more sarcasm!*)
David Chisnall (*Now with 50% more sarcasm!*)
@david_chisnall@infosec.exchange replied  ·  activity timestamp yesterday

@ambiguous_yelp @evacide @mshelton

Signal has Tor support built in, which it uses in unfriendly countries where it’s blocked, such as Iran. This doesn’t help in cases where it’s a friendly country (i.e. one that members of the Foundation may want to visit or risk extradition to), because actively circumventing a ban would place them under legal risk.

The thing that makes this particularly bad for Signal is their choice of AGPLv3 for their apps. Apple does not allow code under this license in their App Store and so Signal relies on a CLA that allows them (and only them) to relicense the code to ship the App Store version.

If a court requires Apple to block Signal from the App Store, Signal is gone for about half of the users in that country. Google Play has no such restriction (and Android allows other install mechanisms), so you can install things like Molly on Android even if Signal stops distributing their client in a particular country. But that doesn’t really help if half of your contacts suddenly disappear.

This is (one of the reasons) why communication protocols should have a permissible licensed reference implementation.

  • Copy link
  • Flag this comment
  • Block
billy joe bowers-8647
billy joe bowers-8647
@billyjoebowers@mastodon.online replied  ·  activity timestamp 2 days ago

@evacide @mshelton

Signal notifies you when someone in your contacts list signs up, and I get a notice every week or two.

  • Copy link
  • Flag this comment
  • Block
Karel 'Clock' K.
Karel 'Clock' K.
@clock@f.cz replied  ·  activity timestamp 2 days ago

@evacide @mshelton IMO Signal is dangerous because relies on phone number and SIM for authentication! Phone operator can intercept these!

  • Copy link
  • Flag this comment
  • Block
Sassinake! - ⊃∪∩⪽
Sassinake! - ⊃∪∩⪽
@Sassinake@mastodon.social replied  ·  activity timestamp 2 days ago

@evacide @mshelton

just, you know, be sure of who you invite in your group.

  • Copy link
  • Flag this comment
  • Block
Christian Rickert
Christian Rickert
@christianrickert@23.social replied  ·  activity timestamp 2 days ago

@evacide @mshelton

Don’t volunteer data for ICE’s database: Your life might depend on it sooner or later.

https://www.vice.com/en/article/palantirs-ceo-finally-admits-to-helping-ice-deport-undocumented-immigrants/

VICE

Palantir’s CEO Finally Admits to Helping ICE Deport Undocumented Immigrants

Palantir has tried to downplay its role in ICE's detainment and deportation of immigrants for years, but Alex Karp said the quiet part loud at Davos.
  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-beta.35 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct