eupolicy.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
This Mastodon server is a friendly and respectful discussion space for people working in areas related to EU policy. When you request to create an account, please tell us something about you.

Server stats:

244
active users

#govware

0 posts0 participants0 posts today
Replied in thread

@ai6yr @briankrebs OFC this targets #TechIlliterates and the only effective means here are:

  1. Teach #TechLiteracy instead of consumerism.
  2. Mandate #confirmation & #notification - #PopUp|s for every use of #Clipboard (similar to #webcam use by websites)...
  3. Ban #JavaScript - seriously!
  4. Ban #Windows, because it's a #Govware, espechally since #Windows10 and even more so on #Windows11 that is *insecure in every configuration!
  5. Put #TechIlliterates before a system they can't feck up. I.e. @tails_live @tails / #Tails for that reason alone (can't run such commands if they neither got #root nor any #persistent #storage to target).
  6. Normalize the use of @torproject #TorBrowser!
  7. #Teach #tech #literacy instead of #consumerism!
  8. Ban #GAFAMs and their shitty products!
  9. Migrate every #TechIlliterate to #Linux and don't give them administrative privilegues.
  10. Teach tech literacy instead of consumerism!
Replied in thread

@ulrichkelber +9001%

Replied in thread

@dalias @lauren
@pixelschubsi

Also the blatant dismissal of absolitely basic #OpSec & #ComSec is just flabberghasting.

Only #decentralized, #OpenSource & #OpenStandards can actuall survive long-term and remain #secure.

It's the same reasons we use #PGPG/MIME & #SSH and not #X400 & #X25!

IOW: Think "How can you weaponize Signal?" and see what you csn do just holding key people in contempt...

The less #info a provider has, the less they can be forced to snitch upon customers.

"#JustUseSgnal!" is a form of dangerous "#TechPopulism" aimed at bamboozling #TechIlliterates who don't know better, abusing information asymetry to pull rank instead of investing the time and effort to *explain "how" and "why" this is indeed a good or bad idea.

The only ones that have a chance to beat that are @delta / #deltaChat but that's just #PGP/MIME #eMail in a nice UI...

  • You may now laugh at me and think my "#TinfoilHat sits too tight" but I'm shure sooner or later I'll be evidenced as correct...
Hachyderm.ioCassandrich (@dalias@hachyderm.io)@kkarhan@infosec.space @signalapp@mastodon.world @monocles@monocles.social @lauren@mastodon.laurenweinstein.org Very few systems promoted as Signal alternatives match the cryptographic privacy properties (see: ratcheting, etc.) of Signal. The claims about "located in the USA" and "Cloud Act" are all nonsense because the only threat to Signal users from this is availability (seizure and shutdown of the server infrastructure), not undetected breakage of privacy properties. There are presently no systems with superior privacy properties to Signal *and* level of functionality on par with what general public expects. There are a lot (like the XMPP stuff, *sigh*, and Matrix) that are worse in both regards. If you're happy with reduced functionality, Cwtch (and possibly some other similar Tor-based systems) or VeilidChat are stronger, but it's gonna be a while before you convince normies to use them, and in the mean time they're still going to be on insecure shit like WhatsApp, FB Messenger, Telegram, etc...
Replied in thread

@ehtron @ulrichkelber @bkastl beim @bsi bin ich mir angesichts dessen dass #Govware wie #Windows (insbesondere #Windows11), #MicrosoftOffice / #Office365 und #GAFAM-Produkte/-Dienste trotz #CloudAct (und der Unvereinbarkeit dessen mit #DSGVO & #BDSG) nicht verbiten sind unsicher ob diese nicht gemeingefährlich inkompetent sind.

  • Angesichts diverser #InfoSec, #OpSec, #ComSec & #ITsec-Fuvkups bekannter Firmen die "#BSI-zertifizierte Sicherheitsprodukte" vermarkten an denen die #NatSec deutschlands hängt ist mir da echt zum kotzen...
Replied in thread

@FrankM natürlich ist es gut wenn Leute endlich die #Govware aus Redmond entsorgen!

Alles andere wäre Akzeptanz von #umweltverbrechen!

youtube.com/watch?v=ODFc8xYjsm

Replied in thread

@heiseonline was solln die #FaschistischeKackshice wieder???

Wird sich in der realität erst recht keiner dran halten!

  • Zumal die Länder eh #Govware wie #Windows nutzen und daher erstmal nix zu meciern haben!!!
heise online · Bundesländer beschließen Porno-Filter für BetriebssystemeBy Stefan Krempl

There are reports about government acquiring software for "breaching encrypted-messaging applications such as #Telegram and #Signal."

They most likely talk not about breaking the encryption or the apps, but about connecting your phone via USB to a machine trying to hack into your phone's operating system (iOS, Android).

So, changing the app makes no difference. Stick with your encrypted messenger (and Telegram is not one of them, despite their claims)

#GovWare #Spyware
newyorker.com/news/news-desk/t

@wravoc instead of insulting @froge how about we actually do make things better and let actual facts speak.

  • If you're here to just spam my mentions, then please let me know so I can mute this conversation as I got more pressing things than virtual "circlejerking" on my agenda.

#ITsec is garbage because absolute fundamentals are disregarded by highest decisionmakers and regulators to users:

Not to mention the fact that we still allow #Govware that is insecure in any configuration like #Windows to not only exist but be sold and used by real public administrations and businesses which oftentimes just pour #DigitalSnakeoil on it and then do a "surprised Pikachu face" when that shit explodes in their face.

youtube.com/watch?v=w3_0x6oaDm

Replied in thread

@HonkHase @GrapheneOS +1

Indeed I've to dive deeper into #GrapheneOS's security geatures.

  • Pretty shure you also have a "decoy mode" password implemented that wipes all tue keys if not go as far as to show a fake unlocked android.

Kinda like "#ArcaneOS" (a botched @LineageOS fork) but without #Govware #Backdoors...

Replied in thread

@jakob_thoboell @DigitalWriter@bildung.social @jdohrmann EXAKT DAS Sehe ich genauso.

Zumal #Windows und #MicrosoftOffice nicht nur unbrauchbare #Govware & #Bloatware sind, sondern deren nicht-standardkonformes Verhalten problematisch ist!

Replied in thread

@ditol @samueljohn @linuzifer

THIS is where I disagree...

You may think it's elitist, but if people are too lazy to learn even fundamentals like how to use #Tails then maybe they should just not do #tech at all?

  • Like: We expect people to show at the every least theoretical proficiency in terms of #TrafficCode and #VehicleSafety in +every juristiction I'm aware of* and literally mandated #DrivingLicense|s for that reason.

I'll gladly teach #TechIlliterates but I won't waste my time on people that spread disinfo...

It's 2024: @tails_live / @tails has been out for over a decade and there are a shitload of guides ranging from written documentation to Zoomer-friendly TikTok-Style shorts on how to get started.

FOR THE LAST TIME:

*STOP MAKING EXCUSES TO JUSTIFY ESCALATING COMMITMENT TO EVIDENTLY BAD SOLUTIONS!"

Whereas with #SelfCustody of all the keys as well as #ReproduceableBuilds and real #decentralization, this would be evidently impossible even if all the devs wanted to comply honestly and not just because they could be held at gunpoint.

  • #Signal is not your friend. It's merely a tax-exempt "non-profit" corporation, and corporations are explicitly nobodys friend - espechally when they demand #PII like phone numbers for useage.

Compare that to #monocles where you do pay like €2 p.m. but in return get #standard #protocols like #IMAP, #SMTP & #XMPP and can pay anonymously and not have to provide any PII whatsoever!

  • And unlike #Signal they ain't dependent on #VC funding and #grant money to keep the lights on.

Make of that what you will, but just like allowing flatearthers to roam freely without caretaker supervision doesn't make the world less round, so won't the facts change about #ITsec, #InfoSec, #OpSec & #ComSec.

Because all #centralized, #SingleVendor & #SingleProvider solutions are bad, and if they don't even allow for #SelfCustody then they are just a #grift to #scam tech-illiterates that don't know and/or don't care!

Infosec.SpaceKevin Karhan :verified: (@kkarhan@infosec.space)Attached: 1 image @Catweazle@vivaldi.net @baeuchle@chaos.social @Linux@kitty.social @torproject@mastodon.social @Vivaldi@vivaldi.net Claiming that ["[...] Mullvad is as private as Tor [...]"]( https://social.vivaldi.net/@Catweazle/113344664983833218 ) disqualified your for any future discussion. - If you can't distinguish between a #VPN and #Tor then you are either *criminally incompetent* or *acting as a #UsefulIdiot* by *spreading #FUD and known #disinfo*, which *can get people killed* who believe this bs! I'll set you some timeout, so you can think about it and apologize in due time! #thxbye #EOD #next
Replied in thread

@GrapheneOS I think both apps are shit as *both #Telegram and @signalapp demand #PII in the form of #PhoneNumbers.

OFC Telegram is (by my personal observation) almost exclusively being used by #Scammers and other #TechIlliterate criminals.