just a reminder — do NOT do things you don't want your admin seeing in direct messages. if you want to, ask that person for an end-to-end encrypted messaging service like signal or matrix.
@tauon Actually, you want to use a truly secure as in real #E2EE solution like #XMPP+#OMEMO as in @monocles / #monoclesChat and @gajim /#gajim...
@kkarhan@infosec.space signal is more secure than xmpp+omemo
@tauon no, it is not because it is a #Centralized, #proprietary, #SingleVendor & #SingleProvider solution subject to #CloudAct that collects #PII like #PhoneNumbers, which makes it inherently less secure, as they are able and willing to restrict access as they please.
centralisedtbh i agree, i don't like that signal is centralised, but that isn't insecure, it's just an anti-feature
proprietaryno it isn't, every element of signal is open source
subject to cloud actwhat is that? are you talking about subpoenaing of information? they legally have to do that anyway, and can't give anything except for the account creation date and the date that the account was last accessed
collects pii like phone numbersi'm pretty sure they don't
1) #CloudAct is just #CyberFacism, look it up!
https://en.wikipedia.org/wiki/CLOUD_Act
-
2) @signalapp 's #Server code is proprietary and since it's centralized we can't trust that the code they release is what's running on their backend!
-
3) #Signal still demands #PhoneNumbers which are #PII either by association (#Number => #ICCID = #SIM = #IMSI => #IMEI => Location Data as I explained before [infosec.space]twice [infosec.space]) or mandatory #KYC / #ID requirements (even on prepaid cards), which an increasing amount of juristictions do...
-
But don't take my word for it.
https://www.youtube.com/watch?v=tJoO2uWrX1M
@tauon Also what goid is an encryption like @signalapp is you don't have #SelfCustody of all the keys?
I can setup over a dozen #TechIlliterates 1:1 with #XMPP accounts and #monoclesChat & @gajim / #gajim in the time it takes me to get a #nonKYC #eSIM from overseas with a phone number as mandated by @signalapp and maintaining that number for #Signal will easily cost like $2,50 p.m. at minimum.
In fact even legitimately acquiring and registering a #Prepaid #SIM in-store in #Germany takes longer than setting up #Fdroid & monocles chat & a XMPP account whilst on throttled #EDGEland speeds...
@kkarhan@infosec.space @Seyd@declin.eu
how? it literally is
Signal unconditionally requires my passport during registration.what the fuck? it shouldn't do that
@Seyd @tauon you dont need a SIM card, you can use a service such as juicysms.com/
@Seyd ive had this happen with other companies before, i guess if youre concerned about that you could use something like Crypton or Stealths that act just like a normal phone operator, but for a virtual number. so like you pay $15/month and they give you complete control over the number. its a lot more expensive but it prevents this kind of thing from happening.
@kali@dystopia.zip @Seyd@declin.eu @tauon@possum.city A nice workaround. How long until they find out and ban phone numbers provided by this service?
Clearly they wanted to outsource identity management because they can't be arsed to design it themselves.