Discussion
Loading...

Discussion

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
evacide
evacide
@evacide@hachyderm.io  ·  activity timestamp 5 days ago

Why do your organizing over Signal? So that you don't do your organizing on an app that hasn't been tested or reviewed, run by a guy who doesn't tell his users about data breaches and security problems.

https://www.ibtimes.co.uk/stopice-hacked-names-locations-over-100k-users-were-sent-fbi-ice-hsi-1775307

  • Copy link
  • Flag this post
  • Block
Orlando Gentil
Orlando Gentil
@OG@bolha.us replied  ·  activity timestamp 5 days ago

@evacide XMPP is a good alternative. Pick any server or bring up your own (self-hosted or SaaS). Several clients to choose from. Federated and decentralized.

  • Copy link
  • Flag this comment
  • Block
evacide
evacide
@evacide@hachyderm.io replied  ·  activity timestamp 5 days ago

@OG Have you done a lot of large-scale grassroots organizing using XMPP? I'd love to hear about it.

  • Copy link
  • Flag this comment
  • Block
Orlando Gentil
Orlando Gentil
@OG@bolha.us replied  ·  activity timestamp 4 days ago

@evacide disroot.org has a lot of users. Adding @isadora . She manages the instance I use and is a XMPP guru/advocate. But the beautiful thing is that the instances don't need to be huge.

  • Copy link
  • Flag this comment
  • Block
Isadora
Isadora
@isadora@transverso.org replied  ·  activity timestamp 4 days ago

@OG @evacide

hey guys :)

there's no doubt a single xmpp instance can handle hundreds to thousands of users in a pretty box. ejabberd software is proven support such amount of users without needing to scale....

the main challenge though, is how to avoid government interference in other layers of communication... you can host a xmpp in europe or any other country, but traffic is still flowing through fiber infrastructure, routing... and we don't know how to assure it's not being observed...

for private groups and 1:1 messaging, the end to end encryption will be a great ally, but it's worthy saying transit encryption with TLS is probably vulnerable to government amount of money invested in surveillance, so another layer of security beyond end to end encryption could be using Tor - in this scenario the xmpp service won't be able to federate, but will work fine for local accounts (inside same server).

hope this info could be useful :)

  • Copy link
  • Flag this comment
  • Block
evacide
evacide
@evacide@hachyderm.io replied  ·  activity timestamp 4 days ago

@isadora @OG I have some concerns about running the server, but my question was about getting large numbers of people to use XMPP and then getting those users to engage in organizing, ideally organizing so sensitive and so prone to government interference that Signal is not a sufficient solution.

  • Copy link
  • Flag this comment
  • Block
F4GRX Sébastien
F4GRX Sébastien
@f4grx@chaos.social replied  ·  activity timestamp 5 days ago

@evacide this is so sad :(

  • Copy link
  • Flag this comment
  • Block
FurballsNHairballs
FurballsNHairballs
@ChrisHolladay@mastodon.social replied  ·  activity timestamp 5 days ago

@evacide
Let me guess...no way to sue the operator of the app?

  • Copy link
  • Flag this comment
  • Block
ℂ𝕖𝕝𝕖𝕤𝕥𝕖@world: /# :blinking_cursor:
ℂ𝕖𝕝𝕖𝕤𝕥𝕖@world: /# :blinking_cursor:
@celeste_42bit@infosec.exchange replied  ·  activity timestamp 5 days ago

@evacide Using anything else but Signal seems like madness to me nowadays.

  • Copy link
  • Flag this comment
  • Block
Matt Panaro
Matt Panaro
@eigen@mattstodon.panar.ooo replied  ·  activity timestamp 5 days ago

@evacide is there a point at which the advice becomes, "stop trying to organize over smartphones entirely"? It seems like it'd be pretty easy (and likely, nowadays) that Google/Apple could extract whatever data the Feds wanted.

  • Copy link
  • Flag this comment
  • Block
Кути'й Пингвин'ыч
Кути'й Пингвин'ыч
@CutePenguin@mastodon.ml replied  ·  activity timestamp 5 days ago

@evacide
Signal and similar solutions from-box simply easy for use
Use messagers, similar Matrix - it hard and threatens unexpected encrypt all sending messages
I used Matrix approximately year and half - and absolutely all servers, where i create my accounts, today already down
+
i lost several important correspondence with potential buyers my second hand computer components
And i'm glad, that opensource party started this understand
(Oh, i forgot - certainly: Russian Communication Supervision goverment service BANNED XMPP protocol on territory our country,
while
Telegram available so far
- it superfluous rock to vegetable garden for opensource, which anyway turned out to be worse than closesource solutions, alas...)

  • Copy link
  • Flag this comment
  • Block
glasspshr
glasspshr
@glasspusher@beige.party replied  ·  activity timestamp 5 days ago

@evacide holy shit

  • Copy link
  • Flag this comment
  • Block
chrfr
chrfr
@chrfr@fosstodon.org replied  ·  activity timestamp 5 days ago

@evacide There may be an update to this story:
https://www.risky.biz/risky-bulletin-stopice-blames-hack-on-a-cbp-agent-here-in-socal/

Risky Bulletin: StopICE blames hack on "a CBP agent here in SoCal" - Risky Business Media

StopICE, an app that lets Americans track the location of US Immigration and Customs Enforcement (ICE) raids, has played down a recent sec [Read More]
  • Copy link
  • Flag this comment
  • Block
adb
adb
@adbenitez@mastodon.social replied  ·  activity timestamp 5 days ago

@evacide signal is centralized and depends on phone numbers, there is a lot of room for thr gov to mess around just with amazon's collaboration, not even signal, better to go with something like Delta Chat

there is even a "Signal Contingency Plan" that recommends it:
https://m.youtube.com/watch?v=B7p7plhdADc

  • Copy link
  • Flag this comment
  • Block
evacide
evacide
@evacide@hachyderm.io replied  ·  activity timestamp 5 days ago

@adbenitez "Delta Chat is a messenger application that operates over email and enables opportunistic encryption for its users." I would not recommend any encrypted messaging system that fails open in situations where knowing that every messaging is e2ee encrypted every single time is important.

  • Copy link
  • Flag this comment
  • Block
Gustavo
Gustavo
@qgustavor@urusai.social replied  ·  activity timestamp 5 days ago

@evacide @adbenitez@mastodon.social I guess they enforced E2EE somehow. What actually grinds my gears about Delta is that they take proven unsafe crypto and add a bunch of things in order to fix the issues then they slapped a "sandboxed app environment" based on JavaScript!

It's like they don't want to be taken seriously by cryptography and security experts! Even with security audits (I don't recall if they got one, but even if they got one) the design and the management of it looks terrible!

It is like if one found a completely broken house and, instead of making a new one from scratch with a safe foundation, they decided to fix the cracks one by one, then moved an elephant and an entire circus inside.

  • Copy link
  • Flag this comment
  • Block
adb
adb
@adbenitez@mastodon.social replied  ·  activity timestamp 5 days ago

@evacide
> Delta Chat is a messenger application that operates over email and enables opportunistic encryption for its users."

that are very old news, Delta Chat used to be like that in the past, encryption is not opportunistic anymore, instead it is perpetual, if a chat is encrypted it is encrypted forever and the key of that contact can never be manipulated/replaced by servers, the key is your identity

about email, that is an extra option, you can read your inbox as chat in Delta Chat

  • Copy link
  • Flag this comment
  • Block
evacide
evacide
@evacide@hachyderm.io replied  ·  activity timestamp 5 days ago

@adbenitez Thank you. That is useful.

  • Copy link
  • Flag this comment
  • Block
Sven222
Sven222
@sven222@soc.hardwarepunk.de replied  ·  activity timestamp 5 days ago
@evacide @adbenitez I think we have enough proplems in the EMail system, we do not need the chat as a problem on top. We usw for organizing our groups XMPP. A protocol that is getting evolved since 27 years. It just works.
  • Copy link
  • Flag this comment
  • Block
evacide
evacide
@evacide@hachyderm.io replied  ·  activity timestamp 5 days ago

@sven222 @adbenitez I am glad you have found a solution that works for your organizing needs. Most of the people that I am brought in to advise on digital privacy and security in organizing are not very technical and very busy. It is important to me to keep my advice as simple and easy as possible while still allowing them to do their work. Even getting people to download an app onto their phone that they don't already have is a hurdle.

  • Copy link
  • Flag this comment
  • Block
Sven222
Sven222
@sven222@soc.hardwarepunk.de replied  ·  activity timestamp 5 days ago
@evacide @adbenitez Yeah, we have on different groups similar experiences. We gladly have the experience at some members to host our own Server. With New Members we sit together and install the Chatclient with them, and do account creation together. It helps to have a small admin team in the groups.
  • Copy link
  • Flag this comment
  • Block
David Chisnall (*Now with 50% more sarcasm!*)
David Chisnall (*Now with 50% more sarcasm!*)
@david_chisnall@infosec.exchange replied  ·  activity timestamp 5 days ago

@sven222 @evacide @adbenitez

This is exactly the wrong thing to do if you are organising anything that the government might object to. It doesn't matter how good the security of the protocol is (and, for XMPP, it is not great), they don't need to know what the content of the messages are, the simple fact that you're all using the same XMPP server is sufficient to identify everyone in your group. And that's something that a passive adversary who can see packets going to your server can see (they can see that a TLS session was established on the XMPP port and what the remote IP was). This is information that they can get without sending a warrant to you or having any access to your server.

In contrast, Signal has around 100M active users, all talking to the same set of servers. Identifying the few hundred of those that are part of some local activist group is incredibly hard. And everyone sending cat pictures to their parents is adding to the anonymity set. Someone monitoring the Signal servers passively (e.g. by watching every packet that arrives in their AWS hosts) gets almost no useful information. Someone who compromises the server can, if they trigger the fallback to not using sealed sender, see who is sending messages to whom (this is detectable on the client, but the Signal app doesn't warn you. It probably should). Without that, all they get easily is the last time you connected to the network. They probably can also correlate IPs used to send messages with sealed sender and IPs used to log in, but that requires recording state that the Signal server doesn't currently (so requires a full compromise of the server).

  • Copy link
  • Flag this comment
  • Block
rakoo
rakoo
@rakoo@blah.rako.space replied  ·  activity timestamp 5 days ago
@evacide @adbenitez

good thing, then, that deltachat isn't one of those, unless you explicitly set it up to not be like that. With accounts setup in the default way, ie with chatmail relays, the latter refuses messages that are not encrypted
  • Copy link
  • Flag this comment
  • Block
evacide
evacide
@evacide@hachyderm.io replied  ·  activity timestamp 5 days ago

@rakoo @adbenitez For non-technical people, I prefer to keep things as simple as possible and avoid recommending solutions that have a setting that fails open, even if it is not the default, in situations where it is important for every message to be e2ee.

  • Copy link
  • Flag this comment
  • Block
obsequentialist
obsequentialist
@amsomniac@mastodon.mit.edu replied  ·  activity timestamp 5 days ago

@evacide and be careful who you let into your group :/

  • Copy link
  • Flag this comment
  • Block
LittlePolarBear
LittlePolarBear
@LittlePolarBear@freeradical.zone replied  ·  activity timestamp 5 days ago

@evacide
Saw a guy with no coding exp try to pitch an #ICE app he built with AI on the #rva reddit. Got rightly flamed for it. Wild how flippant some people are about infosec.

  • Copy link
  • Flag this comment
  • Block
Alex
Alex
@Mellivora@im-in.space replied  ·  activity timestamp 5 days ago

@evacide wasn't this the guy who didn't understand basic technical questions and made it apple only or was that another guy?

  • Copy link
  • Flag this comment
  • Block
Only Exception
Only Exception
@Only_Exception@mstdn.plus replied  ·  activity timestamp 5 days ago

@evacide I got a reason too, so ICE can’t use the power bestowed to them by our god king to breach Signal to track me down and have me go missing in a prison.

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.7 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct