shakedown.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A community for live music fans with roots in the jam scene. Shakedown Social is run by a team of volunteers (led by @clifff and @sethadam1) and funded by donations.

Administered by:

Server stats:

289
active users

#legitimateinterest

1 post1 participant0 posts today
Replied in thread

@walkinglampshade @jrredho @fj It's basic #InfoSec, really:

Thus #Signal fails at protevting #Journalists and theor sources because they do have that data and can be #subopena'd for it if they don't already provide #BulkSurveillance & #LawfulInterception #API|s to comply with #CloudAct. (Or are you guys so naive and believe @Mer__edith will risk dying of old age in jail for non-paying users?)

  • This entire "thread vector" just doesn't exist with #XMPP+#OMEMO nor #PGP/MIME!

And if you believe "this won't ne used/abused me because I'm from 'Murica!" and point at #ANØM as an example, then you really ignored all tze #Cyberfacism since 9/11…

Twitterthaddeus e. grugq on Twitter“I’m gonna tell you a secret about “logless VPNs” — they don’t exist. Noone is going to risk jail for your $5/mo https://t.co/Q2aOQJkG4g”
Replied in thread

@tauon

1) #CloudAct is just #CyberFacism, look it up!
en.wikipedia.org/wiki/CLOUD_Act

-

2) @signalapp 's #Server code is proprietary and since it's centralized we can't trust that the code they release is what's running on their backend!

-

3) #Signal still demands #PhoneNumbers which are #PII either by association (#Number => #ICCID = #SIM = #IMSI => #IMEI => Location Data as I explained beforetwice) or mandatory #KYC / #ID requirements (even on prepaid cards), which an increasing amount of juristictions do...

-

But don't take my word for it.
youtube.com/watch?v=tJoO2uWrX1M

en.wikipedia.orgCLOUD Act - Wikipedia
Replied in thread

@frodo @evacide @monocles

I don't compromise on #ITsec, #InfoSec, #OpSec and #ComSec.

If I were to use #Signal or #Threema or #Telegram or #SimpleX or whatever shit messenger is trendy, I'd indirectly vouch for it and endorse it.

Trust must be earned, and @signalapp didn't even bother to do basic design considerations:

  • All their "but #Metadata" #FUD is horseshite when they demand #PII like a #PhoneNumber and are openly able and willing to discriminate and/or restrict service solely based off said info they have NO "#legitimateInterest" in demanding at all!
#metadata#fud#pii
Replied in thread

@privacyint Furthermore your website contains #Cloudflare #Cookies & [malicious per concept] #JavaScript, which has no "#LegitimateInterest" to be there.

Please reconsider your #TechStack AND the opening, cuz 40k p.a. won't get you a legal consultant except #remote or part-timer...

Replied in thread

@GrapheneOS @thomas @wonka Also I think the issues usually outweigh the benefits - at least when we look at individuals & devices owned by consumers vs. corporate #ITsec where locking down devices is seen as desireable!

  • It should be the sole discretion of the devices' owners whether or not such a feature should be used or accessible and it shpuld be disallowed to coerce people into "consenting" under threat of denied access.

Because for every "#LegitimateInterest" (i.e. #2FA #Authenticator) I can find a dozen reasons this "functionaloty" should be discontinued and considered malware.