Jonkman Microblog
  • Login
Show Navigation
  • Public

    • Public
    • Network
    • Groups
    • Popular
    • People

Notices by Micah Lee ๐Ÿ”‘ (micahflee@mastodon.social), page 14

  1. Micah Lee ๐Ÿ”‘ (micahflee@mastodon.social)'s status on Tuesday, 22-May-2018 01:46:46 EDT Micah Lee 🔑 Micah Lee ๐Ÿ”‘
    • Damien Sirkis โ™ฅ๏ธ๐Ÿ ๐ŸŽต

    @damien have you had any complaints?

    In conversation Tuesday, 22-May-2018 01:46:46 EDT from mastodon.social permalink
  2. Micah Lee ๐Ÿ”‘ (micahflee@mastodon.social)'s status on Tuesday, 15-May-2018 23:12:27 EDT Micah Lee 🔑 Micah Lee ๐Ÿ”‘

    PGP users,

    I implemented a simple #efail exploit for Apple Mail, which is vulnerable to direct exfiltration with its default settings. The mitigation, disabling remote content, works but is brittle. So never click "Load Remote Content". (Thunderbird/Enigmail is vulnerable in a similar way, but I haven't tried that one yet.)

    https://www.youtube.com/watch?v=_67Pz9zpPb0&feature=youtu.be

    In conversation Tuesday, 15-May-2018 23:12:27 EDT from mastodon.social permalink

    Attachments

    1. EFAIL direct exfiltration exploit for macOs Mail
      By Micah Lee from YouTube
  3. Micah Lee ๐Ÿ”‘ (micahflee@mastodon.social)'s status on Friday, 04-May-2018 13:39:27 EDT Micah Lee 🔑 Micah Lee ๐Ÿ”‘

    Domain fronting is critical to the open web https://blog.torproject.org/domain-fronting-critical-open-web

    Tor is an open network, and all Tor relay IPs are public, which makes it simple for repressive governments to block them all.

    Meek is a domain fronting pluggable transport that censored users rely on to bypass these blocks. Since Amazon and Google have blocked domain fronting, only Microsoft's Azure cloud still works, but Tor hears Microsoft might block it next.

    In conversation Friday, 04-May-2018 13:39:27 EDT from mastodon.social permalink
  4. Micah Lee ๐Ÿ”‘ (micahflee@mastodon.social)'s status on Wednesday, 02-May-2018 19:32:51 EDT Micah Lee 🔑 Micah Lee ๐Ÿ”‘

    My 9-year-old nephew (who isn't white) was searching Google Images, with SafeSearch turned on, for NASA pictures. He found a meme that he thought was funny because it had a NASA logo and a snake.

    It was an antisemitic meme with a swastika, a symbol which he's never seen before. I've gotta talk with him about Nazis and the internet now. And why is Google letting Nazi memes through when SafeSearch is enabled?

    In conversation Wednesday, 02-May-2018 19:32:51 EDT from mastodon.social permalink
  5. Micah Lee ๐Ÿ”‘ (micahflee@mastodon.social)'s status on Tuesday, 01-May-2018 17:38:03 EDT Micah Lee 🔑 Micah Lee ๐Ÿ”‘
    • Scary Jerry
    • Michela
    • Rising From the Abyss ๊™ฎ
    • upshotknothole@mastodon.social

    @jerry @upshotknothole @michela @tessaracht PKI and CAs are a problematic system, but one that appears to be basically permanent.

    And Let's Encrypt is basically the very best part of this system, a response to the for-profit CA racket where everyone who wants web security had to pay up. They're not the problem.

    The system of PKI and CAs is the real problem. We need a decentralized replacement system to solve that problem.

    In conversation Tuesday, 01-May-2018 17:38:03 EDT from mastodon.social permalink
  6. Micah Lee ๐Ÿ”‘ (micahflee@mastodon.social)'s status on Tuesday, 01-May-2018 17:32:31 EDT Micah Lee 🔑 Micah Lee ๐Ÿ”‘
    • Scary Jerry
    • Michela
    • Rising From the Abyss ๊™ฎ
    • upshotknothole@mastodon.social

    @jerry @upshotknothole @michela @tessaracht I don't think anyone will buy Let's Encrypt because because it's a non-profit organization without a profit motive, and I think they understand how important their role is.

    Centralizing trust isn't really a problem with Let's Encrypt, it's a problem with PKI in general. As long as certificates require central Authorities to vouch for them, this problem will always exist.

    In conversation Tuesday, 01-May-2018 17:32:31 EDT from mastodon.social permalink
  7. Micah Lee ๐Ÿ”‘ (micahflee@mastodon.social)'s status on Tuesday, 01-May-2018 16:25:41 EDT Micah Lee 🔑 Micah Lee ๐Ÿ”‘
    • gutigen

    @gutigen Signal isn't a honeypot. They have the ability to collect metadata (like all service providers, including mastodon.social), but unlike most others services they promise not to log any of it to disk: https://signal.org/signal/privacy/

    They demonstrated that they're telling the truth with their response to this subpoena: https://signal.org/bigbrother/eastern-virginia-grand-jury/

    In conversation Tuesday, 01-May-2018 16:25:41 EDT from mastodon.social permalink
  8. Micah Lee ๐Ÿ”‘ (micahflee@mastodon.social)'s status on Tuesday, 01-May-2018 16:21:10 EDT Micah Lee 🔑 Micah Lee ๐Ÿ”‘
    • Tlacaelel (thenameless) 7.7

    @Tlacaelel no it isn't. Your argument doesn't make any sense either.

    Microsoft integrated the HTTPS protocol into Skype, too. Does this mean that CIA and NSA have backdoored Mastodon, since it also uses HTTPS?

    In conversation Tuesday, 01-May-2018 16:21:10 EDT from mastodon.social permalink
  9. Micah Lee ๐Ÿ”‘ (micahflee@mastodon.social)'s status on Tuesday, 01-May-2018 16:15:58 EDT Micah Lee 🔑 Micah Lee ๐Ÿ”‘
    • Marsxyz ๐Ÿ‡ง๐Ÿ‡ช

    @marsxyz I don't see how a federated Signal would have changed this situation at all. They'd just block the whole network, and Signal would still need censorship circumvention.

    The fact that much of the web is centralized under cloud services like AWS and Google sucks, but at least it makes domain fronting possible -- assuming the companies are ok with it, which apparently they're not.

    In conversation Tuesday, 01-May-2018 16:15:58 EDT from mastodon.social permalink
  10. Micah Lee ๐Ÿ”‘ (micahflee@mastodon.social)'s status on Tuesday, 01-May-2018 15:38:01 EDT Micah Lee 🔑 Micah Lee ๐Ÿ”‘

    Amazon threatens to suspend Signal's AWS account over censorship circumvention https://signal.org/blog/looking-back-on-the-front/

    Amazon and Google are both coming out opposed to people using their services for domain fronting, to circumvent censorship.

    Note that Signal is actively blocked in Egypt, Oman, UAE, and Iran. So, that sucks.

    In conversation Tuesday, 01-May-2018 15:38:01 EDT from mastodon.social permalink
  11. Micah Lee ๐Ÿ”‘ (micahflee@mastodon.social)'s status on Tuesday, 01-May-2018 14:25:03 EDT Micah Lee 🔑 Micah Lee ๐Ÿ”‘
    • upshotknothole@mastodon.social

    @upshotknothole CAs are already (sort of) federated. You can choose whoever you want. The reason Let's Encrypt is so popular is because 1) it's free, 2) thanks to certbot it's simpler to deploy than everything else.

    Let's Encrypt will completely dominate I think until there's another free CA that also offers automated certs.

    Doing this would be a huge expensive project of course, like Let's Encrypt itself was (expensive, because it costs money to buy your way into browser trust stores).

    In conversation Tuesday, 01-May-2018 14:25:03 EDT from mastodon.social permalink
  12. Tinker โ˜€๏ธ (tinker@infosec.exchange)'s status on Tuesday, 01-May-2018 13:00:56 EDT Tinker ☀️ Tinker โ˜€๏ธ

    NPR article posted today (May 1st) mentions Mastodon! They link to joinmastodon.org (not mastodon.social) which is great!

    โ€œAs Facebook Shows Its Flaws, What Might A Better Social Network Look Like?โ€

    #Mastodon #News

    https://www.npr.org/sections/thetwo-way/2018/05/01/607361849/as-facebook-shows-its-flaws-what-might-a-better-social-network-look-like

    In conversation Tuesday, 01-May-2018 13:00:56 EDT from infosec.exchange permalink Repeated by micahflee
  13. The Final Straw Radio (thefinalstrawradio@chaos.social)'s status on Friday, 27-Apr-2018 14:57:39 EDT The Final Straw Radio The Final Straw Radio
    • EFF
    • sub.Media

    Hey folks, we're new to this medium. As an #Introduction we produce a weekly #anarchistpodcast & radio show and based in the U.S. South. We followed @submedia here, heard about it on the lasted #tfn. We'll be posting our weekly podcasts and occasional #anarchist tech shows (#error451), where Bursts (host) is usually joined by William Budington, who also works at the @EFF , to talk ~ tech security concerns and work-arounds. Hit us up if you wanna know more and check our bio for our website.

    In conversation Friday, 27-Apr-2018 14:57:39 EDT from chaos.social permalink Repeated by micahflee
  14. Micah Lee ๐Ÿ”‘ (micahflee@mastodon.social)'s status on Tuesday, 01-May-2018 10:26:12 EDT Micah Lee 🔑 Micah Lee ๐Ÿ”‘
    • fridaysforfuture, but everyday

    @paulfree14 it isn't really about Zuckerberg. It started with revelations that Cambridge Analytica used FB data from millions of users (who opted into sharing their and their friends' data to some psychology app) to build targeted ad profiles used to elect Trump. And the privacy nightmare of Facebook, and how vulnerable its algorithms are to things like fake news and Russian influence campaigns.

    An issue with #DeleteFacebook is it didn't offer alternatives (to be fair, there are none).

    In conversation Tuesday, 01-May-2018 10:26:12 EDT from mastodon.social permalink
  15. Micah Lee ๐Ÿ”‘ (micahflee@mastodon.social)'s status on Tuesday, 01-May-2018 02:21:31 EDT Micah Lee 🔑 Micah Lee ๐Ÿ”‘
    • Ryan

    @fullywoolly well, you can if you store the key in Local storage. But it has the hushmail/cryptocat/ProtonMail/lavabit problem.

    Since it's a website and not a native app, you basically download the source code each time you load the page. So the server could choose to serve _you_ a backdoor while giving everyone else the secure version of the JavaScript, with no way to detect it.

    In conversation Tuesday, 01-May-2018 02:21:31 EDT from mastodon.social permalink
  16. Micah Lee ๐Ÿ”‘ (micahflee@mastodon.social)'s status on Tuesday, 01-May-2018 02:00:13 EDT Micah Lee 🔑 Micah Lee ๐Ÿ”‘
    • Ryan
    • Sebastian

    @fullywoolly @hinterwaeldler yes, it's called Secret Conversations. It only works if both users are using the Messenger mobile app (because FB doesn't hold the keys, it doesn't work in a browser, true with any e2e).

    https://www.wired.co.uk/article/messenger-secret-messages-end-to-end-encryption

    In conversation Tuesday, 01-May-2018 02:00:13 EDT from mastodon.social permalink
  17. Micah Lee ๐Ÿ”‘ (micahflee@mastodon.social)'s status on Tuesday, 01-May-2018 01:38:45 EDT Micah Lee 🔑 Micah Lee ๐Ÿ”‘
    • Sebastian

    @hinterwaeldler I agree

    In conversation Tuesday, 01-May-2018 01:38:45 EDT from mastodon.social permalink
  18. Micah Lee ๐Ÿ”‘ (micahflee@mastodon.social)'s status on Tuesday, 01-May-2018 01:36:27 EDT Micah Lee 🔑 Micah Lee ๐Ÿ”‘
    in reply to

    The other WhatsApp founder who already left Facebook, Brian Acton, gave $50 million to start the Signal Foundation with Moxie Marlinspike, and is part of the #DeleteFacebook campaign. Facebook must hate these guys.

    https://techcrunch.com/2018/02/21/signal-expands-into-the-signal-foundation-with-50m-from-whatsapp-co-founder-brian-acton/

    In conversation Tuesday, 01-May-2018 01:36:27 EDT from mastodon.social permalink
  19. Micah Lee ๐Ÿ”‘ (micahflee@mastodon.social)'s status on Tuesday, 01-May-2018 01:34:11 EDT Micah Lee 🔑 Micah Lee ๐Ÿ”‘

    "The billionaire chief executive of WhatsApp, Jan Koum, is planning to leave the company after clashing with its parent, Facebook, over the popular messaging serviceโ€™s strategy and Facebookโ€™s attempts to use its personal data and weaken its encryption, according to people familiar with internal discussions."

    https://www.washingtonpost.com/business/economy/whatsapp-founder-plans-to-leave-after-broad-clashes-with-parent-facebook/2018/04/30/49448dd2-4ca9-11e8-84a0-458a1aa9ac0a_story.html

    In conversation Tuesday, 01-May-2018 01:34:11 EDT from mastodon.social permalink

    Attachments

    1. WhatsApp founder plans to leave after broad clashes with parent Facebook
      from Washington Post
      Jan Koum disagreed with Facebook over the popular messaging serviceโ€™s strategy and Facebookโ€™s attempts to use its personal data and weaken its encryption.
  20. Micah Lee ๐Ÿ”‘ (micahflee@mastodon.social)'s status on Monday, 30-Apr-2018 18:11:26 EDT Micah Lee 🔑 Micah Lee ๐Ÿ”‘
    • Bob Mottram ๐Ÿ”ง โ˜• โœ…

    @bob I've been on a mastodon hiatus for quite a while

    In conversation Monday, 30-Apr-2018 18:11:26 EDT from mastodon.social permalink
  • After
  • Before
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

Jonkman Microblog is a social network, courtesy of SOBAC Microcomputer Services. It runs on GNU social, version 1.2.0-beta5, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All Jonkman Microblog content and data are available under the Creative Commons Attribution 3.0 license.

Switch to desktop site layout.