home.social

#tallship — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #tallship, aggregated by home.social.

  1. @monniele The two closest actual production initiatives, or perhaps, production grade proof of concepts, at least in my mind, were/are Keybase and KeyOxide, respectively - not that #Keybase is gone, but just a scroll back a couple of days I quote posted a post linked to @simontatham 's Fedi post two weeks ago about Zoom privacy mining one of your clipboards.

    You can find my post just scrolling back 4 days until you see Kewl Hand Luke, finally pretending to relent to the Captain's perverse requirement of total and complete subjugation.

    Anyway, Keybase has been a modern day ghost town since Chris Coyne abrubtly announced he had sold it to Zoom and then rode off into the sunset. The underlying issue is indeed trust, and Zoom could and may have introduced new keys at anytime w/o notification.

    I'm getting off the point a bit, I think. The concept of both Keybase and #KeyOxide is that of an ever increasing cross-convoluted web of signed cryptographic proofs that atest that "I am who I say I am".

    Certainly, There's no way to certify my:

    client side attestation that verifies the user's intent rather than just their device ID.

    ... After all, I might be psychotically afflicted with bi-polar disorder twice a week (I'm not, but still), but I do believe that mal-intents, for the most part, aren't going to go through weeks and years of building cross-connects showcasing their personalities and presence, like the everyday schmoes like you and I might because we, as people, typically like to share essentially who we are... or at least, who we see ourselves as :)

    I do think that FOSS based community managed services can go a long way towards at least assuring, if not certifying, with a great degree of confidence that we are who we say [we think] we are though.

    There's an elephant in the room though that no one has pointed at. Even Simon mentions it so matter-of-factly that I don't believe the emphasis that we need to place on this is being ascribed to the problem - Zoom is (almost certainly) privacy mining password vaults via the clipboard - VaultWarden, KeypassXC, Pass, Ente Auth, Etc., if not ubiquitous, are certainly increasingly commonplace utilities in everyday use on Androids and Desktops globally. Industrial password farming from the clipboard is a very real threat.

    Well at the risk of already having bored you to death, or maybe just preaching to the choir, I'll close now, thanking you for your thoughtful reply :)

    #tallship #OpenSource #FOSS #KeepassXC #KeepassDX #kdbx #VaultWarden #pass #passwordstore #OpenKeyChain #Identity #Privacy

  2. @monniele The two closest actual production initiatives, or perhaps, production grade proof of concepts, at least in my mind, were/are Keybase and KeyOxide, respectively - not that #Keybase is gone, but just a scroll back a couple of days I quote posted a post linked to @simontatham 's Fedi post two weeks ago about Zoom privacy mining one of your clipboards.

    You can find my post just scrolling back 4 days until you see Kewl Hand Luke, finally pretending to relent to the Captain's perverse requirement of total and complete subjugation.

    Anyway, Keybase has been a modern day ghost town since Chris Coyne abrubtly announced he had sold it to Zoom and then rode off into the sunset. The underlying issue is indeed trust, and Zoom could and may have introduced new keys at anytime w/o notification.

    I'm getting off the point a bit, I think. The concept of both Keybase and #KeyOxide is that of an ever increasing cross-convoluted web of signed cryptographic proofs that atest that "I am who I say I am".

    Certainly, There's no way to certify my:

    client side attestation that verifies the user's intent rather than just their device ID.

    ... After all, I might be psychotically afflicted with bi-polar disorder twice a week (I'm not, but still), but I do believe that mal-intents, for the most part, aren't going to go through weeks and years of building cross-connects showcasing their personalities and presence, like the everyday schmoes like you and I might because we, as people, typically like to share essentially who we are... or at least, who we see ourselves as :)

    I do think that FOSS based community managed services can go a long way towards at least assuring, if not certifying, with a great degree of confidence that we are who we say [we think] we are though.

    There's an elephant in the room though that no one has pointed at. Even Simon mentions it so matter-of-factly that I don't believe the emphasis that we need to place on this is being ascribed to the problem - Zoom is (almost certainly) privacy mining password vaults via the clipboard - VaultWarden, KeypassXC, Pass, Ente Auth, Etc., if not ubiquitous, are certainly increasingly commonplace utilities in everyday use on Androids and Desktops globally. Industrial password farming from the clipboard is a very real threat.

    Well at the risk of already having bored you to death, or maybe just preaching to the choir, I'll close now, thanking you for your thoughtful reply :)

    #tallship #OpenSource #FOSS #KeepassXC #KeepassDX #kdbx #VaultWarden #pass #passwordstore #OpenKeyChain #Identity #Privacy

  3. @monniele The two closest actual production initiatives, or perhaps, production grade proof of concepts, at least in my mind, were/are Keybase and KeyOxide, respectively - not that #Keybase is gone, but just a scroll back a couple of days I quote posted a post linked to @simontatham 's Fedi post two weeks ago about Zoom privacy mining one of your clipboards.

    You can find my post just scrolling back 4 days until you see Kewl Hand Luke, finally pretending to relent to the Captain's perverse requirement of total and complete subjugation.

    Anyway, Keybase has been a modern day ghost town since Chris Coyne abrubtly announced he had sold it to Zoom and then rode off into the sunset. The underlying issue is indeed trust, and Zoom could and may have introduced new keys at anytime w/o notification.

    I'm getting off the point a bit, I think. The concept of both Keybase and #KeyOxide is that of an ever increasing cross-convoluted web of signed cryptographic proofs that atest that "I am who I say I am".

    Certainly, There's no way to certify my:

    client side attestation that verifies the user's intent rather than just their device ID.

    ... After all, I might be psychotically afflicted with bi-polar disorder twice a week (I'm not, but still), but I do believe that mal-intents, for the most part, aren't going to go through weeks and years of building cross-connects showcasing their personalities and presence, like the everyday schmoes like you and I might because we, as people, typically like to share essentially who we are... or at least, who we see ourselves as :)

    I do think that FOSS based community managed services can go a long way towards at least assuring, if not certifying, with a great degree of confidence that we are who we say [we think] we are though.

    There's an elephant in the room though that no one has pointed at. Even Simon mentions it so matter-of-factly that I don't believe the emphasis that we need to place on this is being ascribed to the problem - Zoom is (almost certainly) privacy mining password vaults via the clipboard - VaultWarden, KeypassXC, Pass, Ente Auth, Etc., if not ubiquitous, are certainly increasingly commonplace utilities in everyday use on Androids and Desktops globally. Industrial password farming from the clipboard is a very real threat.

    Well at the risk of already having bored you to death, or maybe just preaching to the choir, I'll close now, thanking you for your thoughtful reply :)

    #tallship #OpenSource #FOSS #KeepassXC #KeepassDX #kdbx #VaultWarden #pass #passwordstore #OpenKeyChain #Identity #Privacy

  4. @apps

    This is excellent news, a demonstration of courage and commitment to one's values that warrants notice, but moreover, notice being taken by other #Fediverse software developers, and further, #FOSS in general.

    @tom79 has already demonstrated such courage a few years ago when the Tusky devs decided to convert their #Android app to #Crippleware, and arguably criminally promote that bait & switch at the #Google_Playstore - once the news of this treachery got out it almost got Tusky permanently removed, and did nothing but provide the impetus for massive amounts of Tusky forks to be made available at the #playstore, with the hardcoded cripples removed, many within minutes of every Tusky update - their ratings crashed into the "two's" within days of releasing their product as crippleware.

    That wasn't really the news, however. Against an almost unbearable assault of threats and denigration by an army of snot-nosed children on the Fediverse moving in blind lockstep, #FediLab, the very best Android Fediverse app supporting over a dozen Fediverse platforms including #PixelDev, #Friendica #PeerTube, and at least half a dozen others, stood fast, refusing to join in conspiratorial behavior to disenfranchise the #Freedom everyday users expected, in the spirit and letter of the #FSF and #GPL.

    When the dust settled, FediLab prevailed and a black cloud remains over Tusky to this day with respect to trust that was never reclaimed from average, everyday users. Much of this is water under the bridge, considering the plethora of Fediverse clients for both Android and web-based #PWS innovations, but the point being made is that here we are, on the eve of another evil being inflicted upon the #Freedom_of_choice by the user, in an insidious attempt to subjugate the users by virtue of giving developers a choice between subverting them through the threat of hamstringing or disenfranchising them.

    The Fedilab Development team has been through this before, and stood fast at the helm to ensure the freedom of choice for the users, and this time they stand firm again for the same freedoms - but this time, not just for the users, but their very existence, in the face of the dystopian despotism of the Alphabet Corporation (Google).

    By now it's become quite clear that it's not so much about the #privacy of #pseudonymity that many developers insist upon, although that is an important part of the issue; but rather, the ultimatum between being swearing fealty to an evil baron or insisting on the abandonment of crippleware in favor of insuring their products derived from intensely hard work and effort is available directly via #git repos everywhere, and app distribution services like F-Droid.

    Thank you @apps - still the very best #Android app!

    #tallship #KYC #fdroid #OpenSource #Free_Software_Movement FSM

    RE: https://toot.fedilab.app/users/apps/statuses/117277154889320838