home.social

#e2eencryption — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #e2eencryption, aggregated by home.social.

fetched live
  1. Every app claims to be "private."

    Most are lying.

    How to tell the difference:

    🚩 RED FLAG: Won't show you code
    ✅ GREEN FLAG: Open source on GitHub

    🚩 RED FLAG: No security audit
    ✅ GREEN FLAG: Published audit from Trail of Bits/NCC Group/Cure53

    🚩 RED FLAG: Just says "encrypted"
    ✅ GREEN FLAG: Says "end-to-end encrypted"

    You don't need to be technical. You need to know what questions to ask.

    Full guide: snugg.social/en/blog/how-to-ve

    #Privacy #Security #OpenSource #E2EEncryption #PrivacyMatters

  2. Every app claims to be "private."

    Most are lying.

    How to tell the difference:

    🚩 RED FLAG: Won't show you code
    ✅ GREEN FLAG: Open source on GitHub

    🚩 RED FLAG: No security audit
    ✅ GREEN FLAG: Published audit from Trail of Bits/NCC Group/Cure53

    🚩 RED FLAG: Just says "encrypted"
    ✅ GREEN FLAG: Says "end-to-end encrypted"

    You don't need to be technical. You need to know what questions to ask.

    Full guide: snugg.social/en/blog/how-to-ve

    #Privacy #Security #OpenSource #E2EEncryption #PrivacyMatters

  3. Platform privacy comparison:

    Signal: 3 data points collected (phone#, account date, last connection)

    WhatsApp: 11+ categories, all shared with Meta

    Telegram: Most chats stored unencrypted

    Discord: ZERO encryption

    Choose wisely. Full breakdown: snugg.social/en/blog/encrypted

    #PrivacyTools #E2EEncryption #OpenSource

  4. 🚨 BREAKING: UK watchdog declares that making apps with end-to-end encryption is akin to starting World War #III. 🤦‍♂️ Meanwhile, the rest of the world continues to use #Signal to send #memes and complain about bad Wi-Fi. 📱💥
    techradar.com/vpn/vpn-privacy- #UKwatchdog #E2Eencryption #WiFiWar #HackerNews #ngated

  5. 🚨 BREAKING: UK watchdog declares that making apps with end-to-end encryption is akin to starting World War #III. 🤦‍♂️ Meanwhile, the rest of the world continues to use #Signal to send #memes and complain about bad Wi-Fi. 📱💥
    techradar.com/vpn/vpn-privacy- #UKwatchdog #E2Eencryption #WiFiWar #HackerNews #ngated

  6. #e2ee #e2eencryption

    AMD: Microcode Signature Verification Vulnerability

    "... security vulnerability in some AMD Zen-based CPUs. This vulnerability allows an adversary with local administrator privileges (ring 0 from outside a VM) to load malicious microcode patches."

    github.com/google/security-res

    This is exactly the attack against which #confidentialcomputing should protect us

    And it won't, when the attacker has access to ring0 of the hardware. Everywhere you don't run yourself.

    #cloud

  7. #e2ee #e2eencryption

    AMD: Microcode Signature Verification Vulnerability

    "... security vulnerability in some AMD Zen-based CPUs. This vulnerability allows an adversary with local administrator privileges (ring 0 from outside a VM) to load malicious microcode patches."

    github.com/google/security-res

    This is exactly the attack against which #confidentialcomputing should protect us

    And it won't, when the attacker has access to ring0 of the hardware. Everywhere you don't run yourself.

    #cloud

  8. @Tejan Ausland @Kevin Karhan :verified: Generally, Hubzilla does optionally offer encrypted conversation.

    I'm not sure, however, if it encrypts the messages themselves, including in the database, or if it only encrypts the transfer.

    It only works between Hubzilla channels that have this app enabled anyway because both sides need it. This mostly reduces its availability to communication between private hubs because some major public hubs don't have it enabled at hub level, so you can't enable it on your channel either if you're on one of those hubs. And, obviously, it doesn't work for communication with anything that's ActivityPub-based.

    Also, I'm not sure how up-to-date it is. It's clearly a thing from the 2010s when there was that dream of a "grid" of Hubzilla hubs as its own decentralised network with StatusNet/GNU social, diaspora*, Friendica, WordPress, LiveJournal, Tumblr, Twitter etc. as optional satellites.

    #Long #LongPost #CWLong #CWLongPost #FediMeta #FediverseMeta #CWFediMeta #CWFediverseMeta #Hubzilla #Encryption #E2EE #E2EEncryption
  9. @Tejan Ausland @Kevin Karhan :verified: Generally, Hubzilla does optionally offer encrypted conversation.

    I'm not sure, however, if it encrypts the messages themselves, including in the database, or if it only encrypts the transfer.

    It only works between Hubzilla channels that have this app enabled anyway because both sides need it. This mostly reduces its availability to communication between private hubs because some major public hubs don't have it enabled at hub level, so you can't enable it on your channel either if you're on one of those hubs. And, obviously, it doesn't work for communication with anything that's ActivityPub-based.

    Also, I'm not sure how up-to-date it is. It's clearly a thing from the 2010s when there was that dream of a "grid" of Hubzilla hubs as its own decentralised network with StatusNet/GNU social, diaspora*, Friendica, WordPress, LiveJournal, Tumblr, Twitter etc. as optional satellites.

    #Long #LongPost #CWLong #CWLongPost #FediMeta #FediverseMeta #CWFediMeta #CWFediverseMeta #Hubzilla #Encryption #E2EE #E2EEncryption
  10. "End-to-end encryption means that the information is scrambled in transit and only the sender and recipient can access it. Regular text messages (SMS messages) and voice calls are usually not encrypted, and can be intercepted in transit or stored on a carrier’s server for extended periods of time.

    Email services such as Gmail and Outlook generally offer encryption in transit, which means they can be read on the companies’ servers and by the end users. Messages that are encrypted in transit can’t be nabbed from a telecom network in an accessible format, but they could be accessed through an email service provider or a law enforcement request to that company.

    End-to-end encryption—the kind offered by services like WhatsApp and Signal—is considered the best bet for privacy, particularly when paired with the option to auto-delete messages after a set period of time, says Mullin."

    inc.com/jennifer-conrad/why-yo

    #CyberSecurity #Privacy #Encryption #E2EEncryption #Signal

  11. "End-to-end encryption means that the information is scrambled in transit and only the sender and recipient can access it. Regular text messages (SMS messages) and voice calls are usually not encrypted, and can be intercepted in transit or stored on a carrier’s server for extended periods of time.

    Email services such as Gmail and Outlook generally offer encryption in transit, which means they can be read on the companies’ servers and by the end users. Messages that are encrypted in transit can’t be nabbed from a telecom network in an accessible format, but they could be accessed through an email service provider or a law enforcement request to that company.

    End-to-end encryption—the kind offered by services like WhatsApp and Signal—is considered the best bet for privacy, particularly when paired with the option to auto-delete messages after a set period of time, says Mullin."

    inc.com/jennifer-conrad/why-yo

    #CyberSecurity #Privacy #Encryption #E2EEncryption #Signal

  12. So wie sich das anhört sind die Hacker durch die Vordertüre gekommen, also wahrscheinlich über diese Wiretap Schnittstellen die Provider für Strafverfolgungsbehörden einbauen müssen. Wundert einen jetzt nicht wirklich, oder? https://www.heise.de/news/Wegem-schwerem-Cyberangriff-auf-US-Provider-FBI-wirbt-fuer-Verschluesselung-10187110.html #hacking #wiretap #e2eencryption

  13. Privacy: 2+ hrs into the hearing, protecting #encryption, #privacy & stopping #spyware are finally raised, thanks to S&D's Kaljurand. But Brunner's response pits safety against privacy - a common trope of the outgoing Commissioner.

    What's more, despite an outright ask for him to commit to protecting #E2EEncryption, Brunner skirts the question. A silver lining? He compliments the Parliament's position on the #CSAReg, which rejected the Commission's mass surveillance and encryption-breaking plans

  14. Privacy: 2+ hrs into the hearing, protecting #encryption, #privacy & stopping #spyware are finally raised, thanks to S&D's Kaljurand. But Brunner's response pits safety against privacy - a common trope of the outgoing Commissioner.

    What's more, despite an outright ask for him to commit to protecting #E2EEncryption, Brunner skirts the question. A silver lining? He compliments the Parliament's position on the #CSAReg, which rejected the Commission's mass surveillance and encryption-breaking plans

  15. #CyberSecurity #Privacy #Discord #E2EE #E2EEncryption #SocialMedia: "Last year, we announced that we were experimenting with new encryption protocols and technologies for audio and video calls on Discord. After extensive experimenting, designing, developing, and auditing, we’re excited to announce Discord’s audio and video end-to-end encryption (“E2EE A/V” or “E2EE” for short), which we like to refer to as our DAVE protocol.

    Discord is committed to protecting the privacy and data of the roughly 200 million people who use our platform every month. As we continue to be a place that helps our users deepen friendships around games and shared interests, we are thrilled to be launching more secure and private voice and video calls.

    Today, we’ll start migrating voice and video in DMs, Group DMs, voice channels, and Go Live streams to use E2EE. You will be able to confirm when calls are end-to-end encrypted and perform verification of other members in those calls.

    We’d like to explain why we’re bringing E2EE A/V to Discord, share our design and implementation goals, and provide a high-level technical overview of how the new protocol works."

    discord.com/blog/meet-dave-e2e

  16. #CyberSecurity #Privacy #Discord #E2EE #E2EEncryption #SocialMedia: "Last year, we announced that we were experimenting with new encryption protocols and technologies for audio and video calls on Discord. After extensive experimenting, designing, developing, and auditing, we’re excited to announce Discord’s audio and video end-to-end encryption (“E2EE A/V” or “E2EE” for short), which we like to refer to as our DAVE protocol.

    Discord is committed to protecting the privacy and data of the roughly 200 million people who use our platform every month. As we continue to be a place that helps our users deepen friendships around games and shared interests, we are thrilled to be launching more secure and private voice and video calls.

    Today, we’ll start migrating voice and video in DMs, Group DMs, voice channels, and Go Live streams to use E2EE. You will be able to confirm when calls are end-to-end encrypted and perform verification of other members in those calls.

    We’d like to explain why we’re bringing E2EE A/V to Discord, share our design and implementation goals, and provide a high-level technical overview of how the new protocol works."

    discord.com/blog/meet-dave-e2e