writing.exchange is one of the many independent Mastodon servers you can use to participate in the fediverse.
A small, intentional community for poets, authors, and every kind of writer.

Administered by:

Server stats:

325
active users

#Encrochat

0 posts0 participants0 posts today
Replied in thread

@dalias @lauren
@pixelschubsi

Also the blatant dismissal of absolitely basic #OpSec & #ComSec is just flabberghasting.

Only #decentralized, #OpenSource & #OpenStandards can actuall survive long-term and remain #secure.

It's the same reasons we use #PGPG/MIME & #SSH and not #X400 & #X25!

IOW: Think "How can you weaponize Signal?" and see what you csn do just holding key people in contempt...

The less #info a provider has, the less they can be forced to snitch upon customers.

"#JustUseSgnal!" is a form of dangerous "#TechPopulism" aimed at bamboozling #TechIlliterates who don't know better, abusing information asymetry to pull rank instead of investing the time and effort to *explain "how" and "why" this is indeed a good or bad idea.

The only ones that have a chance to beat that are @delta / #deltaChat but that's just #PGP/MIME #eMail in a nice UI...

  • You may now laugh at me and think my "#TinfoilHat sits too tight" but I'm shure sooner or later I'll be evidenced as correct...
Hachyderm.ioCassandrich (@dalias@hachyderm.io)@kkarhan@infosec.space @signalapp@mastodon.world @monocles@monocles.social @lauren@mastodon.laurenweinstein.org Very few systems promoted as Signal alternatives match the cryptographic privacy properties (see: ratcheting, etc.) of Signal. The claims about "located in the USA" and "Cloud Act" are all nonsense because the only threat to Signal users from this is availability (seizure and shutdown of the server infrastructure), not undetected breakage of privacy properties. There are presently no systems with superior privacy properties to Signal *and* level of functionality on par with what general public expects. There are a lot (like the XMPP stuff, *sigh*, and Matrix) that are worse in both regards. If you're happy with reduced functionality, Cwtch (and possibly some other similar Tor-based systems) or VeilidChat are stronger, but it's gonna be a while before you convince normies to use them, and in the mean time they're still going to be on insecure shit like WhatsApp, FB Messenger, Telegram, etc...
Replied in thread

@zdl @evacide that any the fact that @signalapp is incorportated in the #USA, making them susceptible to #GDPR & #BDSG-incompatible #cyberfacist bs like #CloudAct.

Remember: #KYC IS THE ILLICIT ACTIVITY when it comes to #Communication!

Compare that to @monocles / #monoclesChat which don't demand any PII or KYC and allow people to pay for their services with #Monero and #CashByMail besides #SEPA #WireTransfer, #Stripe & #PayPal whilst supporting both decentralization (#XMPP is not a #SingleVendor / #SingleProvider solution!), implementing real #SelfCustody (#OMEMO, #OTR & #PGP is supported out of the box) for all the keys, and proper #Anonymitiy (using @torproject / #Tor & @guardianproject #Orbot for #privacy), so in case they ever get a duely sumitted warrant by a court they'd have to comply with, they'll most likely have no data whatsoever on clients that could allow identification.

  • And that is a good thing, because whilst very unlikely, one cannot exclude the non-zero chance of i.e. #MLAT|s being filed with knowingly false information by 3rd countries.

Also having no PII is a matter of reducing #liabiluty in the sense of #DataProtection: All data requested and by #monocles is the bare minimum mandated for #accounting...

Replied in thread

@CCC Das wird dem Wüst aber nix nützen, denn sie können nix anfangen, mit den Daten. Der einzige Grund für den Irrsinn ist, dass die Polizei zu langsam ist. Das ist sie, weil sie im Verfahrensirrsinn gefangen ist. (zertifiziert in 3facher Ausfertigung).

Anstatt positive Lehren aus #Encrochat zu ziehen, kommen die Herren Ahnungslos mit der Überwachungsgiesskanne, die ihnen von irgendwelchen Appartschiks eingeflüstert werden.

Das Risiko für Demokratie wird erhöht ohne wirklichen Gegenwert.

Trotz großem Ermittlungserfolg floriert der Drogenhandel in Europa

Der Hack des Kryptohandy-Anbieters EncroChat vor vier Jahren galt als großer Schlag gegen die organisierte Kriminalität - vor allem gegen den Drogenhandel. Doch es gibt Zweifel an der Nachhaltigkeit des Ermittlungserfolgs. Von M. Seekamp.

➡️ tagesschau.de/investigativ/enc

tagesschau.de · Trotz großem Ermittlungserfolg floriert der Drogenhandel in EuropaBy Mirco Seekamp, NDR

Bundesverfassungsgericht erklärt EncroChat-Datennutzung für zulässig

Bereits vor zwei Jahren hatte der Bundesgerichthof entschieden: EncroChat-Daten dürfen in deutschen Strafprozessen genutzt werden. Jetzt hat auch das Bundesverfassungsgericht eine Verfassungsbeschwerde dagegen abgewiesen. Von Max Bauer.

➡️ tagesschau.de/inland/bundesver

tagesschau.de · Bundesverfassungsgericht erklärt EncroChat-Datennutzung für zulässigBy Max Bauer
Continued thread

This goes back to the Trojan Horse & its warning.

Yes, making a horse that soldiers can hide in and then spring out of is ingenious.

But it’s useless unless you can make your enemy accept the thing you’ve primed. Coordinated & wholesale.

And orgs should know better.

See also: cops using EncroChat to catch whole drug dealing and organised crime networks.

I mean come on people.
#Encrochat #Cybersecurity

newyorker.com/magazine/2023/04

Replied in thread

@GrapheneOS It doesn't change the fact that #security requires #transparency and thus full access & reproduceability from source.

To give you a good example, source-available #Tarsnap demonstrates that stuff is truly securely encrypted by enabling #SelfCustody of keys and thus show they can't decrypt anything!

  • You may call me paranoid, but having 'massive trust issues' saved not only my own life more often than I'd be able to disclose so you may see this as a 'survivorship bias', but we'll only see #MassSurveillance becoming impossible when people ain't just users of some big-ass platform that can be easily targeted once it becomes inconvenient for it's host nation, but actually push for #decentralization and #TechLiteracy.

"Just use A, B, C & D, E, F" is the real threat as it sugfests people a false sense if security.

  • Just like a dresh #TechInspection doesn't prevent one to hose an engine due to lack of oil!

Collecting any #PII IS the illicit activity NO MATTER the excuse...

Sooner or later the #Enshittification of #Signal will reach a point where you'd rethink and consider apologizing...

GrapheneOS MastodonGrapheneOS (@GrapheneOS@grapheneos.social)@kkarhan@infosec.space @h3artbl33d@exquisite.social @arikb@mastodon.sdf.org @tails@fosstodon.org @tails_live@venera.social Please stop leaving replies to our threads with advice. PGP and OTR are obsolete. You're giving people bad advice with a large number of comments on our threads. If you won't stop doing it yourself, we'll deal with it.
Replied in thread

@GrapheneOS @signalapp I didn't say all of them have it...

Re: #Signal I'd not consider it #disinfo as we've seen more elaborate Setups like #EncroChat & #ANØM fall.

I remember when #Signal did a good #E2EE Messenger (#TextSecure) and that had a reason to use #PhoneNumbers as it merely encrypted #SMS, but that OFC has other issues.

Replied in thread

@GrapheneOS I think both apps are shit as *both #Telegram and @signalapp demand #PII in the form of #PhoneNumbers.

OFC Telegram is (by my personal observation) almost exclusively being used by #Scammers and other #TechIlliterate criminals.

Replied in thread

@leitmedium ich halte das für Geschwätz seitens @signalapp und @Mer__edith im speziellen, weil die sich bisher nirgendwo zurückgezogen haben.

Ich garantiere dir dass wenn mit Beugehaft bedroht jede*r bei Signal deren User doxxed - so wie's VPN-Anbieter taten und tun.

Wenn Signal wirklich auf #Sicherheit und #Privatsphäre fokussiert wäre, dann hätten diese einfach nen #XMPP + #OMEMO - Server im @torproject / #Tor - Netzwerk aufgezogen und auch das gesamte #Backend #dezentralisiert!

  • Wäre Signal so sicher wie diese behaupten, dann wäre der Dienst qua #CloudAct lange verboten und das Personal in Haft!
Twitterthaddeus e. grugq on Twitter“I’m gonna tell you a secret about “logless VPNs” — they don’t exist. Noone is going to risk jail for your $5/mo https://t.co/Q2aOQJkG4g”

EuGh erlaubt grundsätzlich Beweise aus Encrochats vor Gericht

Tausende Festnahmen, Beschlagnahmungen in Millionenhöhe - alles dank Beweisen aus der Überwachung von Encrochat-Kryptohandys. Der Europäische Gerichtshof hat nun zur Verwendung dieser Daten vor deutschen Gerichten geurteilt. Von Max Bauer.

➡️ tagesschau.de/ausland/europa/e

tagesschau.de · EuGh erlaubt grundsätzlich Beweise aus Encrochats vor GerichtBy Max Bauer
Replied in thread

@cstross @aeva @zip

The #UK is a #cyberfacist hellhole and the fact that people didn't pitchfork the UK government into was/were when it was enacting these injustices means they've been groomed into accepting that shite with disinfo, FUD and fearmongering...

Not that it changes the fact that the UK has more organozed crime than ever - it's just rich assholes committing white collar crimes that are the problem...

Tho the argument of organized crime being idiots is exemplified by #EncroChat and #ANØM...

And now you know why I'm not into tmorganized crime: I'm "cursed" being too smart to to bs... ^

infosec.space/@kkarhan/1121604

Infosec.SpaceKevin Karhan :verified: (@kkarhan@infosec.space)@zip@wandering.shop no! Because #biometrics are so trivial to steal , claiming they are secure is basically gaslightingneveryone that knows this 20 year old *"How to copy a #Fingerprint?"* video from @CCC@social.bau-ha.us ! http://ftp.ccc.de/documentation/Fingerabdruck_Hack/fingerabdruck.mpg You can change change your #PIN, hide it during entry or randomize the number button locations on the lockscreen, but you can't practically change your fingerprints. I mean, #India got it's national #ID register havked and basically a billion ID card holders got doxxed including their fingerprints...

Things that #UK still exchanges data about and works alongside #EU post #Brexit

* #weather forecasting and monitoring (including climate research)

* #RoadSafety and traffic regulations

* #drugs prohibition (during EU membership UK was viewed as a source of good practice, especially for testing of drug use by drivers)

* law enforcement and #surveillance in general (consider the fallout from #Encrochat )

so the gammons have gained exactly 0 extra freedoms, and are even angrier..

#EncroChat saga continuation:

The Belgian court on Monday started hearing cases of more than 120 people charged with drug and arms trafficking, extortion, acts of torture and attempted murder. It’s one of the country’s biggest trials ever — not just due to its scale but also because it’ll test investigators’ daredevilish methods of hacking encrypted communications services and siphoning off droves of data that were then used as evidence to charge drug networks spanning the European continent.

History:

In July 2020, French and Dutch authorities unveiled how they had been able to obtain more than 100 million messages from EncroChat, a “cryptophone” company selling encrypted communication services and devices that were used by criminal networks, many of which were involved in drug trafficking and organized crime.

Less than a year later the French, Belgian and Dutch authorities added an even larger scalp to their efforts to crack open encrypted comms when they disclosed that a similar service, Sky ECC, had been infiltrated. Police have been able to monitor the information flow of approximately 70,000 users from that operation and, with the help of Europe’s law enforcement agency Europol, started a gargantuan effort of decrypting the data and opening investigations.

https://www.politico.eu/article/belgium-court-case-encryption-softwares-encrochat-sky-ecc-cryptophone-hack-drug-gangs-trial-historic-case/

POLITICO · The great cryptophone hack: Drug gangs on trial in ‘historic’ Belgian caseBy Elisa Braun