home.social

#e2eencryption — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #e2eencryption, aggregated by home.social.

  1. Every app claims to be "private."

    Most are lying.

    How to tell the difference:

    🚩 RED FLAG: Won't show you code
    ✅ GREEN FLAG: Open source on GitHub

    🚩 RED FLAG: No security audit
    ✅ GREEN FLAG: Published audit from Trail of Bits/NCC Group/Cure53

    🚩 RED FLAG: Just says "encrypted"
    ✅ GREEN FLAG: Says "end-to-end encrypted"

    You don't need to be technical. You need to know what questions to ask.

    Full guide: snugg.social/en/blog/how-to-ve

    #Privacy #Security #OpenSource #E2EEncryption #PrivacyMatters

  2. Every app claims to be "private."

    Most are lying.

    How to tell the difference:

    🚩 RED FLAG: Won't show you code
    ✅ GREEN FLAG: Open source on GitHub

    🚩 RED FLAG: No security audit
    ✅ GREEN FLAG: Published audit from Trail of Bits/NCC Group/Cure53

    🚩 RED FLAG: Just says "encrypted"
    ✅ GREEN FLAG: Says "end-to-end encrypted"

    You don't need to be technical. You need to know what questions to ask.

    Full guide: snugg.social/en/blog/how-to-ve

    #Privacy #Security #OpenSource #E2EEncryption #PrivacyMatters

  3. Every app claims to be "private."

    Most are lying.

    How to tell the difference:

    🚩 RED FLAG: Won't show you code
    ✅ GREEN FLAG: Open source on GitHub

    🚩 RED FLAG: No security audit
    ✅ GREEN FLAG: Published audit from Trail of Bits/NCC Group/Cure53

    🚩 RED FLAG: Just says "encrypted"
    ✅ GREEN FLAG: Says "end-to-end encrypted"

    You don't need to be technical. You need to know what questions to ask.

    Full guide: snugg.social/en/blog/how-to-ve

    #Privacy #Security #OpenSource #E2EEncryption #PrivacyMatters

  4. Every app claims to be "private."

    Most are lying.

    How to tell the difference:

    🚩 RED FLAG: Won't show you code
    ✅ GREEN FLAG: Open source on GitHub

    🚩 RED FLAG: No security audit
    ✅ GREEN FLAG: Published audit from Trail of Bits/NCC Group/Cure53

    🚩 RED FLAG: Just says "encrypted"
    ✅ GREEN FLAG: Says "end-to-end encrypted"

    You don't need to be technical. You need to know what questions to ask.

    Full guide: snugg.social/en/blog/how-to-ve

    #Privacy #Security #OpenSource #E2EEncryption #PrivacyMatters

  5. Every app claims to be "private."

    Most are lying.

    How to tell the difference:

    🚩 RED FLAG: Won't show you code
    ✅ GREEN FLAG: Open source on GitHub

    🚩 RED FLAG: No security audit
    ✅ GREEN FLAG: Published audit from Trail of Bits/NCC Group/Cure53

    🚩 RED FLAG: Just says "encrypted"
    ✅ GREEN FLAG: Says "end-to-end encrypted"

    You don't need to be technical. You need to know what questions to ask.

    Full guide: snugg.social/en/blog/how-to-ve

    #Privacy #Security #OpenSource #E2EEncryption #PrivacyMatters

  6. Platform privacy comparison:

    Signal: 3 data points collected (phone#, account date, last connection)

    WhatsApp: 11+ categories, all shared with Meta

    Telegram: Most chats stored unencrypted

    Discord: ZERO encryption

    Choose wisely. Full breakdown: snugg.social/en/blog/encrypted

    #PrivacyTools #E2EEncryption #OpenSource

  7. 🚨 BREAKING: UK watchdog declares that making apps with end-to-end encryption is akin to starting World War #III. 🤦‍♂️ Meanwhile, the rest of the world continues to use #Signal to send #memes and complain about bad Wi-Fi. 📱💥
    techradar.com/vpn/vpn-privacy- #UKwatchdog #E2Eencryption #WiFiWar #HackerNews #ngated

  8. 🚨 BREAKING: UK watchdog declares that making apps with end-to-end encryption is akin to starting World War #III. 🤦‍♂️ Meanwhile, the rest of the world continues to use #Signal to send #memes and complain about bad Wi-Fi. 📱💥
    techradar.com/vpn/vpn-privacy- #UKwatchdog #E2Eencryption #WiFiWar #HackerNews #ngated

  9. 🚨 BREAKING: UK watchdog declares that making apps with end-to-end encryption is akin to starting World War #III. 🤦‍♂️ Meanwhile, the rest of the world continues to use #Signal to send #memes and complain about bad Wi-Fi. 📱💥
    techradar.com/vpn/vpn-privacy- #UKwatchdog #E2Eencryption #WiFiWar #HackerNews #ngated

  10. 🚨 BREAKING: UK watchdog declares that making apps with end-to-end encryption is akin to starting World War #III. 🤦‍♂️ Meanwhile, the rest of the world continues to use #Signal to send #memes and complain about bad Wi-Fi. 📱💥
    techradar.com/vpn/vpn-privacy- #UKwatchdog #E2Eencryption #WiFiWar #HackerNews #ngated

  11. #e2ee #e2eencryption

    AMD: Microcode Signature Verification Vulnerability

    "... security vulnerability in some AMD Zen-based CPUs. This vulnerability allows an adversary with local administrator privileges (ring 0 from outside a VM) to load malicious microcode patches."

    github.com/google/security-res

    This is exactly the attack against which #confidentialcomputing should protect us

    And it won't, when the attacker has access to ring0 of the hardware. Everywhere you don't run yourself.

    #cloud

  12. #e2ee #e2eencryption

    AMD: Microcode Signature Verification Vulnerability

    "... security vulnerability in some AMD Zen-based CPUs. This vulnerability allows an adversary with local administrator privileges (ring 0 from outside a VM) to load malicious microcode patches."

    github.com/google/security-res

    This is exactly the attack against which #confidentialcomputing should protect us

    And it won't, when the attacker has access to ring0 of the hardware. Everywhere you don't run yourself.

    #cloud

  13. #e2ee #e2eencryption

    AMD: Microcode Signature Verification Vulnerability

    "... security vulnerability in some AMD Zen-based CPUs. This vulnerability allows an adversary with local administrator privileges (ring 0 from outside a VM) to load malicious microcode patches."

    github.com/google/security-res

    This is exactly the attack against which #confidentialcomputing should protect us

    And it won't, when the attacker has access to ring0 of the hardware. Everywhere you don't run yourself.

    #cloud

  14. #e2ee #e2eencryption

    AMD: Microcode Signature Verification Vulnerability

    "... security vulnerability in some AMD Zen-based CPUs. This vulnerability allows an adversary with local administrator privileges (ring 0 from outside a VM) to load malicious microcode patches."

    github.com/google/security-res

    This is exactly the attack against which #confidentialcomputing should protect us

    And it won't, when the attacker has access to ring0 of the hardware. Everywhere you don't run yourself.

    #cloud

  15. #e2ee #e2eencryption

    AMD: Microcode Signature Verification Vulnerability

    "... security vulnerability in some AMD Zen-based CPUs. This vulnerability allows an adversary with local administrator privileges (ring 0 from outside a VM) to load malicious microcode patches."

    github.com/google/security-res

    This is exactly the attack against which #confidentialcomputing should protect us

    And it won't, when the attacker has access to ring0 of the hardware. Everywhere you don't run yourself.

    #cloud

  16. @Tejan Ausland @Kevin Karhan :verified: Generally, Hubzilla does optionally offer encrypted conversation.

    I'm not sure, however, if it encrypts the messages themselves, including in the database, or if it only encrypts the transfer.

    It only works between Hubzilla channels that have this app enabled anyway because both sides need it. This mostly reduces its availability to communication between private hubs because some major public hubs don't have it enabled at hub level, so you can't enable it on your channel either if you're on one of those hubs. And, obviously, it doesn't work for communication with anything that's ActivityPub-based.

    Also, I'm not sure how up-to-date it is. It's clearly a thing from the 2010s when there was that dream of a "grid" of Hubzilla hubs as its own decentralised network with StatusNet/GNU social, diaspora*, Friendica, WordPress, LiveJournal, Tumblr, Twitter etc. as optional satellites.

    #Long #LongPost #CWLong #CWLongPost #FediMeta #FediverseMeta #CWFediMeta #CWFediverseMeta #Hubzilla #Encryption #E2EE #E2EEncryption