toad.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mastodon server operated by David Troy, a tech pioneer and investigative journalist addressing threats to democracy. Thoughtful participation and discussion welcome.

Administered by:

Server stats:

274
active users

#comsec

2 posts1 participant0 posts today
Replied in thread

@t3n ja, und das Problem ist halt durch #Shitcoins und jene #PostPrivacy basierend.

Anders als #Banken wo die #ITsec, #InfoSec, #OpSec & #ComSec nicht nur keine #Transparenz des Kontostandes bietet sondern welche auch explizit Pläne für solche Szenarien haben, wo Leute ggf. bedroht werden und gezwungen werden deren Konto leerzuräumen.

  • Und während quasi kaum eine Bank >€5k pro Kunde und Tag ausspuckt, ist ein #Shitcoin (#Bspw. #Bitcoin oder #Ethereum) - Wallet zuhause quasi so als würde jemensch damit prahlen Geld unters Bett zu packen, nur mit dem Unterschied dass Kriminelle vorab genau wissen, wieviel dort ist und die Flüsse in Echtzeit kontrollieren können und jene Shitcoins schnell soviel wert sein können wie ne Matratze aus €5-Geldscheinen...
Replied in thread

@silhouette @richi @signalapp @torproject

1. You completely miss the points! There is no "#TechnicalNecessity" to demand #PII like a #PhoneNumber - espechally for a "#privacy"-focussed messenger!

2. & 3. #Signal is able and willing to comply with #Cyberfacism and pushing a #Shitcoin (#MobileCoin) makes it trivial to criminalize the App for "illegal & unregilated banking". If #Moxie or @Mer__edith cared they'd yeet that thing (or didn't even integrate it to begin with!) to avoid the attention. And yes Signal does restrict the App functionality when using a phone number from #Russia & #Iran (among other nations), thus affecting not only those in need of safe comms but by sending a verification code to them, earmarking them for police & intelligence. Which bings.me to the 1st agrument.

4. #Tor has a stellar record in terms of stability, integrity and censorship circumvention. DIY'ing something instead if following almost two decades of solid progress is absurd and violates "don't roll your own crypto" as a rule!

5. Only with #SelfCustody can you protect your own data. Or do you really expect Staff from Signal to not talk when facing lifetime in jail? If they have the keys, they can decrypt it, thus their #E2EE is just a "#TrustMeBro!" concept. I mean, what prevents them from being forced into backdooring all comms to @icij as per #NSL? Any "guarantee" without self-custody is worthless by virtue of being unenforceable!

Signal pushing #TechPopulism instead of teaching folks that their #ComSec is worth diddly-piss wothout.#OpSec, #InfoSec & #ITsec is dangerous!

  • And yes claiming "JuSt UsE sIgNaL!" is dangerous in the era of #Trump's #cyberfacist regime acting as it does (like with the #ICC)!

Not to mention there are better options that don't do that shite (i.e. demand PII) and just work. @monocles / #monoclesChat & @delta / #deltaChat for example can adapt way better to said risks and ain't run by a #VCmoneyBurningParty!

Avatar for silhouette
dumbfuckingweb.sitePost by sleepy silhouette, @silhouette@dumbfuckingweb.site@kkarhan@infosec.space @richi@vmst.io @signalapp@mastodon.world @torproject@mastodon.social >PII afaik the only info is that you have registered to Signal and the last time you've connected. Other services do this too, for technical reasons. >USA irrelevant given the guarantees of their E2...
Replied in thread

@ip6li @bsi @bnd @bwi @itzbund

Und um eins klarzustellen: Es ist nicht so als würde ich es per-se ablehnen für @Bundesregierung zu arbeiten.

Nur wenn ich faktisch qua #Technologiestack #Microsoft #Windows meiner #Pflicht zur #Vertraulichkeit (#MicrosoftRecall ist integrierte #Malware) nicht nachkommen kann ist dies weder mit #Berufsethik noch Berufshaftpflicht, Rechtsschutzversicherung, Amtseid oder #Verfassungstreue vereinbar!

Ob @bnd angesichts des #Trump - #Regimes und dessen Aktionen [gegen den #IStGH] und der #cyberfaschistisch|en Macht qua #CloudAct endlich Alarm schlägt was #GAFAM-Produkte oder generell #Technologie aus den #USA, besonders aber #Microsoft Produkte wie #Windows, #MicrosoftOffice & #WindowsServer angeht?

Und da ich nunmal #Bürger dieses Landes bin wird dies leider auch mein Problem - entgegen aller Warnungen meinerseits!

  • Was hindert die #US-Regierung daran Deutschland, die #EU oder den Rest der Welt mittels entsprechender Produkte in #Geiselhaft zu nehmen?

Oder ist jene #Abhängigkeit von der Laune und dem Guten Willen aus D.C. gar politisch gewollt?

#DEpol#ITsec#InfoSec
Replied in thread

@dave_andersen @AVincentInSpace personally I consider any "#KYC" a risk-factor, and @signalapp has proven their ability and willingness to restrict functionality (i.e. their #Shitcoin-#Scam #MobileCoin) based off said #PhoneNumbers (Cuban, Russian and North Korean Numbers were excluded) which are in fact #PII (even if one doesn't have to #ID for obtaining a #SIM, they are circumstantial PII)...

  • They have neither "legitimate interest" nor legal mandate to collect said data (or to integrate a scammy Shitcoin for that matter) as the discontinuation of #ChatSecure / #TextSecure has eliminated the "technical necessity" to have those.

Either way they either have to yeet #Hegseth as client and/or stop collecting PII like PhoneNumbers - they gotta have to do something

#ITsec is a different story, but unlike #Signal these do not depend on a #PhoneNumber and work through @torproject / #Tor.

  • And I've been using Tor for almost 15 years daily now...
Replied in thread

@dzwiedziu @fj @signalapp not really, as the #Metadata #FUD cited by #Signal is mitigateable with proper measures.

  • You can't even run Signal over @torproject and even if that point is moot when you're forced to quasi-#KYC by virtue of a #PhoneNumber aka. #PII they have neither legitimate interest nor technical reason to demand in the first place!

Every claim that things like #ITsec, #InfoSec, #OpSec & #ComSec can be solved with "Just use Signal!" is "#TechPopulism" at best if not being a "#UsefulIdiot"!