shakedown.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A community for live music fans with roots in the jam scene. Shakedown Social is run by a team of volunteers (led by @clifff and @sethadam1) and funded by donations.

Administered by:

Server stats:

289
active users

#Onionshare

2 posts2 participants0 posts today

New Privacy Guides article 🎙️✨
by me (kinda):

This article is an
interview with Micah Lee!

We are absolutely delighted at Privacy Guides that @micahflee has accepted to speak with us this week.

Thank you so much for your time Micah, this is a fantastic interview.

Check it out here! 👇

privacyguides.org/articles/202

www.privacyguides.org · Interview with Micah Lee: Cyd, Lockdown Systems, OnionShare, and more
More from Em :official_verified:

If you don't know who Micah Lee is yet, here's why you should: Micah is an information security engineer, a software engineer, a journalist, and an author who has built an impressive career developing software for the public good, and working with some of the most respected digital rights organizations in the United States.

privacyguides.org/articles/202

www.privacyguides.org · Interview with Micah Lee: Cyd, Lockdown Systems, OnionShare, and more
More from Em :official_verified:

This week in #FDroid (TWIF) is live:

- #K9Mail developer quits Mozilla, thanks @cketti for all the good work
- #surveillance laws want #backdoor access in #France again
- #FOSSGIS 2025 in March, get the app
- #onionshare crash fix soon
- #RiMusic might be in danger
- #SimpleX has group growing pains
- #Termux GUI is finally available
- #Threema Libre reacts
- #VLC with Remote Access
- #XScreenSaver has nice privacy policy

Click for +218 lines of news: f-droid.org/2025/02/27/twif.ht

f-droid.orgSaving screens | F-Droid - Free and Open Source Android App RepositoryThis Week in F-DroidTWIF curated on Thursday, 27 Feb 2025, Week 9F-Droid coreTermux:GUI, A plugin for Termux to use the Android GUI from terminal application...
Continued thread

There are also some treats for advanced users who want to run #OnionShare in headless mode: we documented how to run the CLI as a systemd unit file:

docs.onionshare.org/2.6.3/en/a

and we documented all the configuration settings, including for persistent onions:

docs.onionshare.org/2.6.3/en/a

docs.onionshare.org/2.6.3/en/a

I gave some tips here on how to pre-generate an onion address, so you can do it all without ever needing the UI: github.com/onionshare/onionsha

docs.onionshare.orgAdvanced Usage — OnionShare 2.6.3 documentation

I just released #OnionShare 2.6.3 !

github.com/onionshare/onionsha

onionshare.org/dist/2.6.3

You can verify the packages with my GPG key 00AE817C24A10C2540461A9C1D7CDE0234DB458D (docs.onionshare.org/2.6.3/en/i).

This release is mostly bug fixes and dependency updates, with some new translations (Gaeilge, Slovenčina and Tamil).

You can also now configure a Saved (Persistent) tab to automatically start as soon as OnionShare has started and Tor has connected.

Enjoy!

GitHubRelease OnionShare 2.6.3 · onionshare/onionshare2.6.3 Feature: It is now possible to view what URLs are visited in Share/Website mode using the CLI tool, with --log-filenames. Feature: It is now possible to automatically start a saved persisten...
Replied in thread

@lispi314 @dalias @lauren

Not only that, but @signalapp being.located in #Trumpist #USA means they gotta have to follow said laws and that means if flexed upon using #FOSTA & #SESTA or god forbid made-up claims to commit #TransGenocide and prosecute #Trans minors and/or their parents and/or medical professionals, THIS WILL BLOW UP IN THEIR FACES like a grenade used as ball gag and fuse pulled!

For comparison: @monocles doesn't demand #PII like a #PhoneNumber or anything at all and if you don't trust them either (which is fair - never trust anyone, neither Signal nor #monocles nor me!) you can not only choose from various providers but literally #SelfHost your own (even as an #OnionService on @torproject / #Tor) and thus have full control of all the comms.

Replied in thread

@delta @leaf @n0iroh the closest "#serverless / #P2P" I've seen is #OnionShare [made by @micahflee]...

Tho I think the true #future will be #decentralized, #federated and similar to eMail...

  • Personally #XMPP+#OMEMO is a good fit. I do think that #deltaChat's approach to using #PGP/MIME is good and can work even in more restrictive scenarios (i.e. corporations when #E2EE & #Messaging require indexed archives for compliance reasons!)...
onionshare.orgOnionShareOnionShare is a tool for anonymous peer-to-peer file sharing, chatting, and web hosting.

One thing that @torproject is missing is a way to check availability and reachability of #Bridges with a simple tool.

  • This is kinda vital as I do occasionally setup private #bridges and also want to enshure the private #TorBridges list I have is up to date.

Manually adding/removing one #bridge after the other in #TorBrowser and see if those connect is a relatively inefficient process and merely pinging them isn't viable either, espechally on #meek, #obfs4 and #snowflake type bridges.

  • Now to make the obvious clear: I'd NEVER publicly list any #TorBridge on my lists.d repo obviously, because that would only harm #Tor...

I'm not even asking for like a fancy tool that is as clean as @micahflee 's #OnionShare but merely a #CLI thing (if necessary I'd build some #bash script) to automatically attempt to connect to said bridge and either spit out an ok or error.

  • Something one can just feed with a text file and that'll spit out a different file with ok/working bridges and/or discards the non-working ones from the list.

And yes, this tool is kinda crucial as I want to quickly sift through a load of bridges that work on restricted ports (22, 80, 443) and thus can bypass the #GreatFirewall and #Roskomnadzor filtering...

  • So people fleeing can at least safely communicate.

If anyone at #TorProject needs more details, I'll gladly exchange them in a secure manner.

List of useful things. Contribute to greyhat-academy/lists.d development by creating an account on GitHub.
GitHubGitHub - greyhat-academy/lists.d: List of useful thingsList of useful things. Contribute to greyhat-academy/lists.d development by creating an account on GitHub.
Replied in thread

@xoron I don't want to discourage you at all - in fact I think your goal is not just noble but also worth aspiring to.

  • My recommendation is always to scout out existing solutions, protocols and standards and see if those can be salvaged / used and if not, reason why. #PGP/MIME may seem crusty but a good UI can make it easy. Same.goes for #OMEMO & #OTR...

But whatever you do, please "DO NOT DIY ENCRYPTION!"

  • Instead delegate it to drop-in libraries (i.e. crypto++ for C++) that are well, maintained and getting audited.

Prioritize features early on and make a decision what you want and if/how these can be accomplished. If necessary, have different modes / functions one has to context-switch (i.e. videocalling can't work in an airgapped network unless your callers are in the same (W)LAN).

  • If possible choose to stay platform-independent in terms of tech, so like #WebCall, #JitsiMeet, etc. you can simply package that up with nw.js... (Except if you need like a minimalist, (n)curses-style TUI tool like #enc)

User-test early on. Espechally with "#TechIlliterates", if you can.

  • Focus on a #MVP (minimum viable product) early on.

Write #documentation early on since that'll remove headaches. And I don't just mean #CommentYourCode but go deep and explain in detail why you chose something. This will help not just you.

Make yourself a list what you like and dislike from those.

Don't be afraid if your #App can't tick all the boxes at first release. Rather feel free to slowly ibtegrate them.

Needless to say I do sincerely wish you good luck and only the best in terms of success.

nwjs.ioNW.jsnwjs
Replied in thread

@halva @lynn @signalapp @deilann

The problem is one needs to literally acquire a phone number and have access to it, and the demand of a phone number itself is bad. This makes it unnecessarily complex and expensive compared to using @monocles / #monoclesChat.
(Cuz if I've to pay to communicate, I might just choose a provider that isn't a #VC #MoneyBurningParty but a long-term sustainable solution based off #OpenStandards!)

  • I'm sorry for your location. My sincere condolences!

Still, #Signal doesn't allow #SelfCustody of all the keys & #SelfHosting, which makes it vulnerable as a #proprietary #centralized, #SingleVendor & #SingleProvider solution.

And with #CloudAct on one hand and #Trump wanting to "Speedrun Hitler", I'd not rely on Signal.

  • The "Metadata" #FUD is just a marketing bs because Signal will comply with warrants, whereas nothing prevents me from buying a Thin client, setting up an #OnionService to tunnel everything over @torproject / #Tor and rig it to disconnect power if tampered with or upon command.

I have setup comms for critical operations (incl. helping people flee Russia!) and I'd rather choose #OnionShare over #Signal if #Metadata is a real concern.

  • Internet Access, even in "P.R." #China, is something feasible to workout given the massive prevalence of public #WiFi. Also it's easier to spoof/anonymize a MAC than an #IMEI or even #IMSI, so making one dependent on #PhoneNumbers to even sign up is inherently bad!
Twitterthaddeus e. grugq on Twitter“I’m gonna tell you a secret about “logless VPNs” — they don’t exist. Noone is going to risk jail for your $5/mo https://t.co/Q2aOQJkG4g”
Replied in thread

@mattblaze Remember:

The only winning move is to commit "#AssetDenial" and commit to untappable communications with proper #E2EE via @torproject / #Tor.

  • @micahflee made #OnionShare which is basically the most idiot-proof way to communicate over Tor to this day!

onionshare.org

onionshare.orgOnionShareOnionShare is a tool for anonymous peer-to-peer file sharing, chatting, and web hosting.
Replied in thread

@lmorchard @vkc nodds in agreement I'm flabberghasted by rising #MediaIlliteracy & #TechIlliteraxy despite things being easier to do than ever before.

  • This ain't like 1999 where one had to buy a book to learn #HTML and be rich enough to afford #ADSL!

Nowadays even a cheap smartphie can host an #OnionService and stuff like #OnionShare even makes way easier...

Replied in thread

@Skivling @jpaskaruk @james

Please understand as a maintainer of a project intended for many legitimately legal uses, I cannot help you with things like violating copyright.

Otherwise I'd be thrilled to get early feedback on #distrans but it's still quite early stage. I have sent a few large files around with it though. A 4G Kali ISO made it through intact.

It's currently only single-file and point-to-point, but resuming interrupted downloads and trackers are coming soon if I can find some happy fun #rust #hacking time.

I'm also considering a simple GUI that lets you send a file, #onionshare style...