Jonkman Microblog
  • Login
Show Navigation
  • Public

    • Public
    • Network
    • Groups
    • Popular
    • People

Conversation

Notices

  1. lnxw48a1 (lnxw48a1@nu.federati.net)'s status on Tuesday, 31-Jan-2023 22:28:04 EST lnxw48a1 lnxw48a1
    #Session seems to be a usable messenger, but its current incarnation lacks "perfect forward secrecy":{https://en.wikipedia.org/wiki/Forward_secrecy}. See https://getsession.org/session-protocol-explained and https://getsession.org/blog/session-protocol-technical-information

    > PFS means that if long-term keys for a given conversation are compromised, only a small amount of recent messages can be decrypted. However, under typical circumstances, the only way long term keys can be compromised is through full physical device access — in which case an attacker could simply pull the already-decrypted messages from the local database. As is often said in the infosec community, physical access is total access.

    I understand this, but maybe y'all can reinstate PFS and not store messages unencrypted. So that (for example) a police officer on a fishing expedition cannot obtain your full history and content of conversations by seizing your phone.
    In conversation Tuesday, 31-Jan-2023 22:28:04 EST from nu.federati.net permalink

    Attachments

    1. File without filename could not get a thumbnail source.
      Forward secrecy - Wikipedia
    2. Invalid filename.
      The Session Protocol: What’s changing — and why - Session Private Messenger
      from Session
      Session is moving to a purpose-built new encryption protocol: the Session Protocol. Read all about why we’re making the move, and what it means for users.
    3. Invalid filename.
      Session Protocol: Technical implementation details - Session Private Messenger
      from Session
      Read up on the technical information behind the new Session Protocol, and our plans for rolling it out.
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

Jonkman Microblog is a social network, courtesy of SOBAC Microcomputer Services. It runs on GNU social, version 1.2.0-beta5, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All Jonkman Microblog content and data are available under the Creative Commons Attribution 3.0 license.

Switch to desktop site layout.