hessen.social ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
hessen.social ist die Mastodongemeinschaft für alle Hessen:innen und alle, die sich Hessen verbunden fühlen

Serverstatistik:

1,7 Tsd.
aktive Profile

#encryption

34 Beiträge32 Beteiligte0 Beiträge heute

"[T]he main thing that people need to understand about Signal is that messages are encrypted from my phone to your phone in such a way that Signal can't read them as they go through their servers. The government could not read them off of Signal servers even with a warrant, even if they really wanted to. But if somebody has access to your phone, they can read those messages the same way you can by looking at them with their eyeballs because the messages have to be decrypted for you to read.

Now, there are a lot of ways that you can get access to somebody's phone. You can look over their shoulder while they're reading their messages, right? You can find out their password and unlock their phone, right? You can use forensic tools that police have like a Cellebrite or a break-in device to unlock phones, and then you can read the messages that way. You can also use malware. Installing malware on somebody's phone is a way that governments often gain access to people's private encrypted communications. Things like Pegasus malware or they're recently written about malware from Paragon Solutions that was going after WhatsApp messages, which was also end-to-end encrypted.

A concern about national security folks using these devices for the communications is that it makes it much more likely that their devices will get targeted by malware. And there's a lot of countries that have espionage capabilities that have the capability to target people's phones that would be very interested in knowing what Pete Hegseth is talking about, or what other high-level cabinet officials are talking about. So that makes for a very juicy intelligence target for foreign intelligence, and I think it's safe to assume that's something that many countries are now going to be going after."

techpolicy.press/about-that-si

Tech Policy Press · About that Signal Chat | TechPolicy.PressTo learn more about the scandal, Justin Hendrix spoke to Just Security co-editor-in-chief Ryan Goodman and EFF senior staff technologist Cooper Quintin.
#USA#Trump#CyberSecurity
Fortgeführter Thread

🧵 Following part 1, here is the part 2 of my series of articles on how to build a #crossplatform search engine from scratch, in #rustlang .

📰 This article is about how we go from a document to a set of structured indexes.

💬 Enjoy reading it, feel free to provide some feedback, here or directly on GitHub 😉

🔗 Here is the link: jdrouet.github.io/posts/202503

jdrouet · Building a search engine from scratch, in Rust: part 2Or how we'll go from a set of documents to a set of structured indexes.
Fortgeführter Thread

Is Signal the secure messaging app everyone's talking about? 🤔 A recent incident involving US officials has experts weighing in! 🔐 This article explores Signal's security features, encryption, & why it's favored by journalists & security pros. 📱➡️ latimes.com/california/story/2 #SignalApp #Privacy #Cybersecurity #Encryption

Signal app on a smartphone is seen on a mobile device screen Tuesday, March 25, 2025, in Chicago. (AP Photo/Kiichiro Sato)
Los Angeles Times · What is the signal messaging app and is it secure?Von Karen Garcia

"Whittaker acknowledges that WhatsApp licenses Signal’s end-to-end encryption technology. Nevertheless, a lot of personal and intimate information isn’t protected. According to Signal’s president, this involves users’ location data, contact lists, when they send someone a message, when they stop, what users are in their group chats, their profile picture, and much more.

“These differences may be marketing gloss to Meta, but to us, they’re fundamental life or death issues that the public deserves to understand so they can make an informed choice,” Whittaker concludes.

On Sunday, WhatsApp sent a message to Dutch users stating that the company can’t read their messages, including text and voice messages, photos, videos, and calls.

“They are protected by end-to-end encryption because we are always committed to protecting your privacy,” the note reads."

cybernews.com/news/whatsapp-si

What is BLAKE3?

Even if I use a big fan from the use of BLAKE3 to hash, it is not possible to use it in a very advantageous way everywhere. What kind of thing is always what you have to question as a programmer. In the case of a product, the following conditions are met.

🔏 academy.bit2me.com/en/que-es-b

Qué es Blake3
Bit2Me Academy · What is BLAKE3?Meet BLAKE3, one of the fastest, most secure and efficient hashing algorithms in the computing and blockchain world.
#hash#BLAKE3#encryption

After the article from The Atlantic, I've seen a lot of misinformation circulating among journalists. I'm not getting into the political side of things, but many are focusing on the fact that Signal was used, claiming it's "not encrypted" or "not secure." This really saddens me because it spreads the wrong message.

#Signal#Privacy#Security
Fortgeführter Thread

Good news: The provision attacking #encryption was rejected. ❤️

Bad news: The #spyware provision, allowing police the remote activation of devices' microphone and camera, passed. 💔

What's next? The French National Assembly is set to vote on the full text next week, Tuesday, 1 April. They will then begin negotiations with the French Senate before the final law can be passed.

@LaQuadrature

Days after the Signal leak, the Pentagon warned the app was the target of hackers

Several days after top national security officials accidentally included a reporter in a Signal chat about bombing Houthi sites in Yemen, a Pentagon-wide advisory warned against using the messaging app, even for unclassified information.

#Signal #messaging #encryption #privacy #pentagon #government #technology #tech

npr.org/2025/03/25/nx-s1-53398

UK urges critical orgs to adopt quantum cryptography by 2035

The UK's National Cyber Security Centre (NCSC) has published specific timelines on migrating to post-quantum cryptography (PQC), dictating that critical organizations should complete migration by 2035.

#PQC #quantum #cryptography #encryption #UK #security #cybersecurity #hacking #infosec

bleepingcomputer.com/news/secu

BleepingComputer · UK urges critical orgs to adopt quantum cryptography by 2035Von Bill Toulas
Fortgeführter Thread

#Meta is testing #AI voice control in #WhatsApp – with implications for our #privacy
"The idea sounds slick: you open a chat, start speaking, and the AI replies. No buttons, no clicks – everything feels intuitive. But here’s the catch: if a system is always ready to listen, then the real question becomes unavoidable – when is it actually listening, and what happens to what it hears?

Meta knowingly trained its AI on pirated content. And now this very system is supposed to be deeply embedded in our private conversations?

This goes far beyond smart tech that “understands” our voice. We’re looking at a company that has consciously disregarded legal boundaries to rush its AI to market. The trust such deeply integrated features would require? Meta has already thrown that out the window.

The real danger? Everything feels “smart” and “convenient.” But that very sense of effortlessness is part of the strategy. The more invisible the intrusion, the lower the resistance. And in the meantime, habits are being formed – ones that are hard to undo."
via @lazou
#spyware #Encryption #surveillance
onecloud.srvdns.de/s/cxkRiqL8R

🚨 Let’s Encrypt at risk from Trump cuts to OTF: “Let’s Encrypt received around $800,000 in funding from the OTF”

Dear @EUCommission, get your heads out of your arses and let’s find @letsencrypt €1M/year (a rounding error in EU finances) and have them move to the EU.

If Let’s Encrypt is fucked, the web is fucked, and the Small Web is fucked too. So how about we don’t let that happen, yeah?

(In the meanwhile, if the Let’s Encrypt folks want to make a point about how essential they are, it might be an idea to refuse certificates to republican politicians. See how they like their donation systems breaking in real time…)

CC @nlnet @NGIZero@mastodon.xyz

#USA #fascism #OpenTechFund #LetsEncrypt #SSL #TLS #encryption #EU #web #tech #SmallWeb #SmallTech mastodon.social/@publictorsten

Mastodonpublictorsten (@publictorsten@mastodon.social)Wenn Let’s Encrypt plötzlich nicht mehr klappt, wird das halbe Internet aus Zertifikatsfehlern bestehen. https://www.heise.de/news/Nach-Trump-Dekret-Kampf-um-US-Foerdermittel-fuer-Tor-F-Droid-und-Let-s-Encrypt-10328226.html