lingo.lol is one of the many independent Mastodon servers you can use to participate in the fediverse.
A place for linguists, philologists, and other lovers of languages.

Server stats:

69
active users

#singlevendor

0 posts0 participants0 posts today
Replied in thread

@signalapp It's not #disinfo when one points out that you demand #PII aka. #PhoneNumbers from Users and that is literally a architectural vulnerability, alongside your #proprietary & #Centralized #Infrastructure.

Not to mention the lack of @torproject / #Tor support with an #OnionService or the willingness to fulfill #cyberfacist "Embargoes" or shilling a #Shitcoin #Scam named #MobileCoin!

  • #KYC is the illicit activity!!!

And don't get me started on the #cyberfacism that is #CloudAct.

  • If you were secure, criminals would've used your platform so hard, it would've been shutdown like #EncroChat and #SkyECC.

I may nit have allvthe.evidence yet, but #Signal stenches like #ANØM: #Honeypot-esque!

Replied in thread

@ueeu I think crucial parts is looking at it's components, dependencies, size and for apps permissions.

#ReproduceableBuilds for example are important, so the actually released source code is what people actually get served as basis.

Plus in terms of #security, choose *real #E2EE with #SelfCustody of all the #Keys!

Replied in thread

@lauren no, because @signalapp is subject to #CloudAct (= incompatible with #GDPR & #BDSG if you ever care!) and collects #PII in the firirm of #PhoneNumbers, which are at best pseudonymous but trivial to track and at most means that people inviting others without their consent comitted an illegal disclosure if PII!

Give #XMPP+#OMEMO a shot: @monocles / #monocles & @gajim / #gajim.

1 2 3 4 5

Replied in thread

You use XMPP+OMEMO because you think it's neat.

I use XMPP+OMEMO because all centralized, single-vendor and/or single-provider messengers are inherently garbage, collect PII like phone numbers for no "legitimate reason" and don't offer proper End-to-End - Encryption with self-custody of all the keys, making them either honeypots or prime targets for warrants.

  • We are not the same!
Infosec.SpaceKevin Karhan :verified: (@kkarhan@infosec.space)@evacide@hachyderm.io NO, YOU CANNOT USE @signalapp@mastodon.world WITHOUT A PHONE NUMBER!!! * They still require a phone number as they still do restrict the functionality of their App based off the phone number given! Also we've all seen that #centralized, #SingleVendor & #SingleProvider solutions are inherently bad - so why should anyone use #Signal over #XMPP+#OMEMO or XMPP+#PGP/MIME ??? #Signal, like every provider in the #USA, is subject to #CloudAct ** and will obviously hand over the #metadata they collected without legitimate interest if told to do so. *** After all, clients like @monocles@monocles.social ' #monoclesChat **** make XMPP w/ OMEMO and PGP/MIME extremely user-friendly... Im many juristictions, you cannot legally obtain an anonymous prepaid SIM legally! ***** - - - Sources: * https://social.tchncs.de/@kuketzblog/111968247576555678 ** https://en.wikipedia.org/wiki/CLOUD_Act *** https://web.archive.org/web/20220112020000/https://twitter.com/thegrugq/status/1085614812581715968 **** https://f-droid.org/en/packages/de.monocles.chat/ ***** https://infosec.space/@kkarhan/111968383793566135
Replied in thread

@rysiek also #Telegram - like @signalapp - demand and collect #PII like #PhoneNumbers which ain't possible to acquire anonymoisly in more and more juristictions.

Using #XMPP+#OMEMO by contrast is secure and adding @torproject / #Tor to tunnel it makes it even more anonymous.

  • So don't expect any messenger to cover your 6, but instead go out of your way so that even when held at gunpoint, they can't decrypt comms!

Cnsider every #Messenger that doesn't #decentralize and support #Tor oit of tue box to be insecure!

Twitterthaddeus e. grugq on Twitter“I’m gonna tell you a secret about “logless VPNs” — they don’t exist. Noone is going to risk jail for your $5/mo https://t.co/Q2aOQJkG4g”
Replied in thread

@evacide NO, YOU CANNOT USE @signalapp@mastodon.world WITHOUT A PHONE NUMBER!!! *

They still require a phone number as they still do restrict the functionality of their App based off the phone number given!

Also we've all seen that #centralized, #SingleVendor & #SingleProvider solutions are inherently bad - so why should anyone use #Signal over #XMPP+#OMEMO or XMPP+#PGP/MIME ???

#Signal, like every provider in the #USA, is subject to #CloudAct ** and will obviously hand over the #metadata they collected without legitimate interest if told to do so. ***

After all, clients like @monocles ' #monoclesChat **** make XMPP w/ OMEMO and PGP/MIME extremely user-friendly...

Im many juristictions, you cannot legally obtain an anonymous prepaid SIM legally! *****


- - -

Sources:

* social.tchncs.de/@kuketzblog/1

** en.wikipedia.org/wiki/CLOUD_Ac

*** web.archive.org/web/2022011202

**** f-droid.org/en/packages/de.mon

*****
infosec.space/@kkarhan/1119683

MastodonMike Kuketz 🛡 (@kuketzblog@social.tchncs.de)In der neuen Beta von Signal können jetzt Benutzernamen verwendet werden. Die Telefonnummer (als interner Identifier) wird dadurch allerdings nicht abgelöst. Bedeutet: Auch in Zukunft ist die Telefonnummer für die Nutzung von Signal erforderlich. Man muss diese nur nicht mehr jedem Chat-Teilnehmer verraten. 👇 https://signal.org/blog/phone-number-privacy-usernames/ #signal #messenger #telefonnummer #benutzername #datenschutz #privatsphare
Replied in thread

@Mer__edith Well, it is up to us, by boycotting businesses that produce, research, use, employ, support, sell or buy that tech as well as consequently only accepting tech and solutions that make it hard if not nearly-impossible to do these kinds of #MassSurveillance...

This necessitates everything to be #OpenSource'd and #decentralized properly and refusal to use any #centralized #SingleVendor and/or #SingleProvider solution whatsoever...

Replied in thread

@kobayashi90 very simple:
Like @protonmail they act as a #SingleVendor / #SingleProvider solution and @signalapp not only refuses to distribute their app as #sourcecode so @fdroidorg and others can actually release reproducible builds but they also don't make it #SelfHosting capable.

Not to mention their reliance of #GoogleAPIs and #centralization in the #USA and thus subject to #CloudAct as well as collecting #PhoneNumbers and being thus able and willing to do #Cyberfacism on behalf of US Gov.

Replied in thread

@evacide okay, you want it simple?

1. DONT' USE ANY #proprietary #SingleVendor / #SingleProvider and/or #unencrypted comms at all!

2. DON'T TALK TO ANYONE WHO ISN'T LEGALLY FORCED UNDER THREAT OF JAIL AND LIFELONG UNEMPLOYABILITY TO STFU EVEN TOWARDS COPS & JUDGES!

3. STFU!

4. Act plausibly deniable!

5. Don't take anything that can and thus will be used to track you - including any mobile phones - even switched off!

6. Use @torproject #TorBrowser to look up stuff!