mastodon.green is one of the many independent Mastodon servers you can use to participate in the fediverse.
Plant trees while you use Mastodon. A server originally for people in the EU, but now open for anyone in the world

Administered by:

Server stats:

1.2K
active users

#omemo

13 posts10 participants0 posts today

#discord IS LITERALLY THE PROBLEM!

I'm shure fecking #dread has better moderation and I'd rather use #MicrosoftTeams + #Slack cuz those at least have proper #moderation tools.

  • And I'd rather subscribe to the #LKML and see my inbox getting hosed than using any shitty #SaaS!

Case in point: I'd rather #SelfHost all my comms infrastructure than to ever use something like Discord or any other #GDPR-violating SaaS that is just enshittification.

I'd rather recommend people to instead choose a tool that does everything but horrible to go with multiple smaller & good tools

Check @alternativeto and @european_alternatives for options.

Replied in thread

@rubdos @ts-new

I agree, that there is no server-side meta data protection on #XMPP. But it compensates by

1. impede mass data surveillance, thanks to federation, and

2. making multiple accounts, incl. anonymous and burner accounts, very easy.

Note, that most #Jabber clients do default to #OMEMO E2EE "on" now. It took a long time, though.

Replied in thread

@Madmonkey @kenobit

Sorry, if I misintpret your post, trying to understand Italian based on my mediocre Spanish 🙂

#XMPP itself does not define #e2ee, but almost all clients do support #OMEMO encryption, which is more or less copied from Signal.

In addition, you can choose a trustworthy provider, such a #cooperative or club.

Maybe for that reasons, German #police seems to believe (wrongly), that #Jabber (the traditional name of XMPP) were "the first pillar of #cybercrime"!

Replied in thread

@joo4mart @phreaknerd @melsdung Ja und entgegen @nocci's reply liefer ich "Praktikable Lösungen" auch.

Ich helfe auch gern, nur gegen Unwillen und Faulheit kann ich nicht agieren.

  • Besonders wenn ich weder dafür bezahlt noch dazu authorisiert bin als #WohlwollenderDiktator entsprechendes durchzusetzen!

Gibt @cryptoparty@mastodon.earth / @cryptoparty@chaos.social für jene die sich drum scheren.

  • Den Rest bestrachte ich als #Risiko in Sachen #InfoSec, und leider hat meine Lebenserfahrung mir damit bisher immer Recht gegeben!

Macht doch was ihr wollt aber heult nicht wenn vorhersehbare Konsequenzen weh tun!

MastodonDer vegane Debianer 🇺🇦 🍀 (@joo4mart@social.tchncs.de)@phreaknerd @kkarhan@infosec.space @melsdung@nrw.social @nocci@punk.cyber77.de @torproject@mastodon.social @monocles@monocles.social Danke für die klare Sicht auf die wesentlichen Dinge. Zudem sollten wir immer bedenken, dass ca. 95% der Menschen keine Nerds sind, die sich stundenlang mit Details spezifischer Software beschäftigen wollen/können. Und für diesen vielen Menschen braucht es praktikable Lösungen.
Replied in thread

@pixelcode @phreaknerd @melsdung @nocci das bzgl. #Signal halte ich bestenfalls für ne #Werbelüge, weil nicht evidenzierbar!

Und wer #monocles oder anderen Anbietern nicht vertraut kann #XMPP selbst.hosten und hat bei #OMEMO ohnehim doe Kontrolle über die Schlüssel.

Alles andere ist naiver Glauben dass @Mer__edith für Nutzer*innen Knast riskieren würde…
infosec.space/@kkarhan/1142345

Infosec.SpaceKevin Karhan :verified: (@kkarhan@infosec.space)Content warning: Rant re: Signal Shills being dangerous Tech Illiterates

There are no known security issues with "Siacs OMEMO" / OMEMO v0.3¹ despite of what some very loud Signal fans would like you to believe. It has been audited by a third party² who took a longer look at it than all of the Signal fans combined.

Yes, #OMEMO v0.7+ (or TWOMEMO 😜) is a cleaner spec with more features (most notably Stanza Content Encryption). That’s why we wrote it. I’m a co-author. That doesn’t mean v0.3 is insecure.

¹: xmpp.org/extensions/attic/xep-
²: conversations.im/omemo/audit.p

xmpp.orgXEP-0384: OMEMO Encryption
Replied in thread

@signalapp no it's not.

Being a #centralized, #SingleVendor & #SingleProvider solution subject to #CloudAct makes you inherently vulnerable by your own choice and thus trivial to shutdown compared to real #E2EE with #SelfCustody of all the keys and true #decentralization as well as #SelfHosting (i.e. #PGP/MIME [see @delta / #deltaChat et. al.] and #XMPP+#OMEMO [see @monocles / #monoclesChat et. al.]!)

And don't even get me started on you collecting #PII (espechally #PhoneNumbers) for no valid reason, (thus violating #GDPR & #BDSG)...

But yeah, I'll be patient to shout "#ToldYaSo" to your annoying cult of fanboys!