bolha.us is one of the many independent Mastodon servers you can use to participate in the fediverse.
We're a Brazilian IT Community. We love IT/DevOps/Cloud, but we also love to talk about life, the universe, and more. | Nós somos uma comunidade de TI Brasileira, gostamos de Dev/DevOps/Cloud e mais!

Server stats:

252
active users

#e2ee

10 posts9 participants6 posts today

»Gmail Gets End-To-End Encryption From Google As 21'st Birthday Present:
[…] Google Claims To Have Invented An Entirely New Type Of Encryption For Gmail Users […]«

This is not an April joke and yes Google offers OpenPGP for Gmail Accounts. This is not difficult to set up but too many people are too lazy in my opinion.

📧 forbes.com/sites/daveywinder/2

#e2ee#openpgp#email
Continued thread

Privacy Guides is formally taking a stand against dangerous and frightening technologies.

Security-focused developers and misguided "advocates" have long attempted to convince those involved in privacy and security that E2EE is an advanced security measure designed to protect your sensitive data, and Privacy Guides has stood by for far too long not setting the record straight.

privacyguides.org/articles/202

www.privacyguides.org · The Dangers of End-to-End Encryption
More from Privacy Guides
Replied in thread

@signalapp no it's not.

Being a #centralized, #SingleVendor & #SingleProvider solution subject to #CloudAct makes you inherently vulnerable by your own choice and thus trivial to shutdown compared to real #E2EE with #SelfCustody of all the keys and true #decentralization as well as #SelfHosting (i.e. #PGP/MIME [see @delta / #deltaChat et. al.] and #XMPP+#OMEMO [see @monocles / #monoclesChat et. al.]!)

And don't even get me started on you collecting #PII (espechally #PhoneNumbers) for no valid reason, (thus violating #GDPR & #BDSG)...

But yeah, I'll be patient to shout "#ToldYaSo" to your annoying cult of fanboys!

Replied in thread

@ueeu I think crucial parts is looking at it's components, dependencies, size and for apps permissions.

#ReproduceableBuilds for example are important, so the actually released source code is what people actually get served as basis.

Plus in terms of #security, choose *real #E2EE with #SelfCustody of all the #Keys!

Bald Ende mit Ende-zu-Ende-Verschlüsselung bei WhatsApp?

«WhatsApp-Nachrichten sind Ende-zu-Ende-verschlüsselt. Für Kommunikationen mit der eingebauten KI ergibt das aber kaum Sinn. Denn die Gesprächsverläufe mit der KI werden von Meta gespeichert. Die KI wird mit ihnen auch trainiert.

Die KI lässt sich wohl nicht deaktivieren.»
#WhatsApp #KI #AI #E2EE #Meta #MetaAI
netzpolitik.org/2025/angriff-a

netzpolitik.org · Angriff auf Privatsphäre: Meta-Messenger führen KI-Assistenten in Europa einKünftig können Nutzer*innen von WhatsApp und Co. mit einer KI chatten und auch sprechen. Dabei werden ihre Daten mit Meta geteilt. Und ein Test-Feature lässt die KI sogar durchgängig mithören.

What happens encrypted, stays encrypted… unless you add the world press to the chat 🤡

How to #PracticeSafeText:

1️⃣ Use end-to-end encryption.
2️⃣ Check your contacts.

FAO: The US Administration. theatlantic.com/politics/archi

Donate to our campaign to #SaveEncryption: indiegogo.com/projects/save-en

Replied in thread

@fj I still think @signalapp has fundamental flaws like demanding #PII (#PhoneNumbers can't be obtained anonymously around the globe and are trivial to track down to devices and thus users), being subject to #CloudAct as an unnecessary & 100% avoidable risk as well as #Shitcoin-#Scam shilling (#MobileCoin) and it's #proprietary, #SingleVendor & #SingleProvider nature that makes it inferior to real #E2EE with #SelfCustody like #PGP/MIME & #XMPP+#OMEMO!

Replied in thread

@licho @osman provide evidence the code @signalapp released is actually being deployed.

Not to mention pushing a #Shitcoin-#Scam (#MobileCoin) disqualifies #Signal per very design!
youtube.com/watch?v=tJoO2uWrX1M

  • Given the collection of #PII like #PhoneNumbers, the ability to restrict functionality based off those and the fact that #Signal is subject to #CloudAct make it inherently not trustworthy.

And don't even get me started on the fact.it's not sustainable to run it as a #VCmoneyBurningParty!

Same as identifying users: They already got a #PhoneNumber which in many juristictions one can't even obtain without #ID legally, thus making it super easy to i.e. find and locate a user. Even tze cheapest LEAs can force their local M(V)NOs to #SS7 a specific number...

  • All these are unnecessary risks, that could've been avoided, but explicitly don't even get remediated retroactively!

Again: Signal has a #Honeypot stench, and you better learn proper #E2EE, #SelfCustody and #TechLiteracy because corporations can't pull the 5th [Amendment] on your behalf!

🇫🇷 A Win For Encryption: France Rejects Backdoor Mandate

「 The proposed law was a surveillance wish list disguised as anti-drug legislation. Tucked into its text was a resurrection of the widely discredited “ghost” participant model—a backdoor that pretends not to be one. Under this scheme, law enforcement could silently join encrypted chats, undermining the very idea of private communication 」

techdirt.com/2025/03/24/a-win-

Techdirt · A Win For Encryption: France Rejects Backdoor MandateIn a moment of clarity after initially moving forward a deeply flawed piece of legislation, the French National Assembly has done the right thing: it rejected a dangerous proposal that would have g…