shakedown.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A community for live music fans with roots in the jam scene. Shakedown Social is run by a team of volunteers (led by @clifff and @sethadam1) and funded by donations.

Administered by:

Server stats:

261
active users

#securemessaging

0 posts0 participants0 posts today

👏 'The technology behind [the Guardian newspaper's new open source tool] #SecureMessaging conceals the fact that messaging is taking place at all by making the communication indistinguishable from other data sent to and from the app by our millions of regular users. By using the Guardian app, other users are effectively providing “cover” and helping us to protect sources.'

theguardian.com/membership/202

The Guardian · In a dangerous era for journalism – a powerful new tool to help protect sourcesBy Katharine Viner

I don’t have confirmation on this, and it was I think being mentioned in the context of more secure messaging apps like Signal (and one would guess others offering end-to-end encryption like WhatsApp too) still allowing access to unencrypted (not secure) data by parts of the phone.

Can someone confirm if this is accurate?

I did a talk at #hackmas on "Secure Messaging (and attacks against it)" and the great organization team has already put the video recording online at
media.ccc.de/v/26cd6d27-247f-5. Many thanks to the audience for so many insightful questions and discussions - it is rare that the audience is so engaged and aware of nuance! Slides are available at mayrhofer.eu.org/talk/secure-m

Abstract: Secure messaging apps are one of the most-used app categories on current mobile devices, and a significant subset of human communication is handled through them. This makes them an interesting target for forensics, surveillance, and general information collection for intelligence services and police institutions. In this talk, we will discuss various options for such surveillance and their respective difficulties, pointing out which options do not seem realistic given all the practical considerations.

TL;DR: There is no good option for surveiling E2EE messenger apps; all of them are broken or practically unrealistic in various ways. I don't see an option to do that without real, significant problems that make all of us less safe. Please stop claiming that it is possible without these nasty issues.

Replied in thread

@m0xee @bascule As a side note, while Signal still couples your account with your phone number (they are giving a few reasons for keeping it that way), exposing your phone number is now completely optional. Now, by default, other parties won’t see your phone number and won’t be able to find you by your phone number (but you can still switch it on as an option).

signal.org/blog/phone-number-p

Signal MessengerKeep your phone number private with Signal usernamesSignal’s mission and sole focus is private communication. For years, Signal has kept your messages private, your profile information (like your name and profile photo) private, your contacts private, and your groups private – among much else. Now we’re taking that one step further, by making your...