Notices by Bob Mottram (bob@social.freedombone.net), page 11
-
Bob Mottram (bob@social.freedombone.net)'s status on Thursday, 11-Jan-2018 16:28:00 EST Bob Mottram
@morph @lnxw48a1 It went something like this:
I set up a keybase account ages ago when I think it was still invites only. I don't remember it ever asking for a private key. Since last year my main gpg key has changed and I now use gpg 2.x. Keybase was complaining of breakages. I tried fixing them but it didn't work - most likely because of the new gpg version. So I tried resetting the key details and starting again. In that process it asks to enter the public key and then a private key. I do a double take. Is it asking me for what I think it is? Why yes, it is. I seem to have inadvertently landed in the timeline where people upload their private keys to keyservers. I want out of this universe!
Researching it a bit I notice that this is actually a years old issue. I am very late to the party. I don't really get any value out of keybase anyway, so I'll just leave the account dormant with no keys. If people want my public key they can get it in other ways. -
Bob Mottram (bob@social.freedombone.net)'s status on Thursday, 11-Jan-2018 16:00:59 EST Bob Mottram
@yukiame @lnxw48a1 I may be late to this particular party, but I'm not buying it. A passphrase is not a substitute for a private key. -
Bob Mottram (bob@social.freedombone.net)'s status on Thursday, 11-Jan-2018 15:40:05 EST Bob Mottram
@yukiame Even if keybase is trusted there's the inevitable data leak in future and then letter agencies crack all the passphrases (especially the weak noob ones).
I don't think I can endorse that and I'm curious/suspicious about the whole idea of asking anyone - noob or expert - to upload a private key, so I'm retiring any support for keybase.io within !Freedombone. -
Bob Mottram (bob@social.freedombone.net)'s status on Thursday, 11-Jan-2018 15:30:42 EST Bob Mottram
@yukiame So folks upload their private keys (hey, what universe am I in now?), then there's an inevitable data leak, then suddenly letter agencies have the keys and have cracked the passphrases.
Profit! -
Bob Mottram (bob@social.freedombone.net)'s status on Thursday, 11-Jan-2018 15:28:19 EST Bob Mottram
@yukiame #notallnoobs -
Bob Mottram (bob@social.freedombone.net)'s status on Thursday, 11-Jan-2018 15:22:52 EST Bob Mottram
@yukiame That's even worse for noobs, because it means that they're likely to use an easy to crack passphrase. -
Bob Mottram (bob@social.freedombone.net)'s status on Thursday, 11-Jan-2018 15:14:37 EST Bob Mottram
@yukiame Plus if I try resetting and starting over it asks me to upload my private key, which is a bit concerning. Well, a lot concerning actually. Even if the private key is client side encrypted with a passphrase that gives whoever owns the server a full time opportunity to try to crack it. -
Bob Mottram (bob@social.freedombone.net)'s status on Thursday, 11-Jan-2018 15:04:15 EST Bob Mottram
Trying to update my keybase.io account and failing. I think I'll just abandon it, because I don't think it adds any value over and above existing keyservers. -
h (h@social.coop)'s status on Thursday, 11-Jan-2018 14:43:46 EST h
The Management Engine: an attack on computer users' freedom
via @fsf
With security issues like the Spectre and Meltdown vulnerabilities discovered in Intel chips in early 2018, it became more important than ever to talk about the necessity of software freedom in these deeply embedded technologies. Thanks to Denis GNUtoo Carikli, we have a new basis for that conversation in this article.
https://www.fsf.org/blogs/sysadmin/the-management-engine-an-attack-on-computer-users-freedom
-
Bob Mottram (bob@social.freedombone.net)'s status on Thursday, 11-Jan-2018 13:42:34 EST Bob Mottram
See, they can partner with all manner of dubious organizations, but they can't make something which works inside of Iran when the chips are down, and will won'tfix any issues related to that. https://signal.org/blog/skype-partnership -
Bob Mottram (bob@social.freedombone.net)'s status on Thursday, 11-Jan-2018 13:26:48 EST Bob Mottram
@cwebber @banjofox @rowan Is there a fediverse high scores table? -
Janelle Shane (janellecshane@wandering.shop)'s status on Thursday, 11-Jan-2018 12:57:50 EST Janelle Shane
I trained a neural network on the list of thesis titles from MIT. Need a research topic? http://aiweirdness.com/post/169581821297/thesis-titles-generated-by-neural-network
-
Parker Higgins (xor@mastodon.xyz)'s status on Thursday, 11-Jan-2018 12:18:19 EST Parker Higgins
The Kodak KashMiner is both a terrible idea and such a cool weird cyberpunk aesthetic. I want to replicate the case and use it as a lunchbox https://mastodon.xyz/media/QQA7Eyl1adLAbOGvwvw
-
Bob Mottram (bob@social.freedombone.net)'s status on Thursday, 11-Jan-2018 12:30:11 EST Bob Mottram
#Iran: Graffiti that says "Freedom of women = Freedom of all society" https://social.freedombone.net/attachment/73571