Earlier quoted context omitted.
Idk if you consider Twitter a big tech company, but they do: https://developer.twitter.com/en/pricing . I don't believe Google or FB does though.
That isn't selling user data. All that is on the site itself, they are just making it easier to access. I'm talking about their click streams and other things that are invisible to the public. That data no one sells because it is how they target their ads.
Briar Project
111–120 of 189 posts
Re: Briar Project
#112Earlier quoted context omitted.
This is precisely why it's important to make these tools (protocols/applications) part of the core layer of how businesses operate consumer-facing services online; it's only true if the ratio of "interesting" communication over these channels is high enough. In an alternative timeline where ISPs where more strictly regulated and trusted and everything was cleartext HTTP, I'm certain that HTTPS/TLS would face pushback…
Oppressors can (and I think some already do) subvert HTTPS by mandating installation of government-issued certs so they can do their MITM.
Re: Briar Project
#113Earlier quoted context omitted.
TEMPEST is a generic term for extracting data that emanates from channels which were are not supposed to carry data. It’s usually an attack, used to spy on people. The classic example is pointing a high speed camera at an office window across the street and recording the brightness of the walls. Even if the office computer is hidden out of sight the attacker can reconstruct what’s on screen by analysing subtle change…
> The classic example is pointing a high speed camera at an office window across the street and recording the brightness of the walls. Even if the office computer is hidden out of sight the attacker can reconstruct what’s on screen by analysing subtle changes in brightness reflected off the wall. Is this feasible now?
Re: Briar Project
#114Earlier quoted context omitted.
I understand your frustration, but Signal didn't notify your contacts because you installed it. It notified the other person, because he had your phone number. Your local Signal installation regularly checks if any of your contacts (with the phone numbers you have of them) are registered at the Signal servers - and then lets you know it, such that you can text this contact securely.
The technical details do not really matter. Many people might have my phone number, possibly from a long ago. But the number itself is pretty safe -- there is no way to tell if this phone is in use or not. Signal breaks that assumption -- it immediately tells every other user that this number is alive, valid, and can be contacted right now. This is a terrible idea to do by default, especially if one cannot disable it…
This is all based on your address-book so it doesn't matter if the other party knows your number or not.
Re: Briar Project
#115Earlier quoted context omitted.
Have you looked at 'threema'? I recently installed it and I'm actually pleasantly surprised. However, all of these bloody messengers mean that my contacts list is spread across a multitude of programs: we need the iOS/Android equivalent of pidgin.
Threema is closed source which is something I don't really like when it comes to security as there are no independent audits. Edit: Generally, Threema seems interesting feature-wise, but I think the price (4€) will prevent my contacts from using it...
Re: Briar Project
#116In an authoritarian regime with large masses of human and technological resources determined to have control over its population, nothing is really secure. Sending a message that can't be read by a third party? You're suspect. Have an illegal app installed on your registered "report to big brother" phone? Expect an unfriendly visit by big brother police. Don't have a "big brother" phone? There are various ways of sni…
Targeting users who rely upon secure apps is becoming common in flawed democracies as well and more countries are eager to join that list. Several people, including minors were arrested in Kashmir when police found VPN app on their mobile during routine checks[0]. Government's logic being 'Why use VPN, if you are not a terrorist?'
At the same time journalists, activists are heavily dependent upon secure apps like this to make their voice heard outside, all the more reason for all of us who are lucky to not have gestapo knocking our doors because we used a VPN to watch PornHub to make usage of such secure apps (messaging, email, VPN etc.) very common.
[0]https://scroll.in/article/954711/in-kashmir-a-spree-of-arres...
Re: Briar Project
#117I've been looking for secure messengers during the last few weeks. I use WhatsApp, Signal, and Telegram. Telegram isn't very secure, WhatsApp is owned by Facebook and even Signal - while very secure - requires a cell phone number... Briar seems great in this regard but isn't available on iPhone and has no support for images, calls, voice messages, etc. Apparently they're going to support images and a desktop client,…
> Telegram isn't very secure Can someone elaborate?
The second one is more difficult to evaluate. If you use the above mentioned "secret chat" feature, Telegram employs their own closed-source encryption scheme. That's usually an indicator to be cautious from the get-go. Since it's closed source, it can't really be trusted.
See [Wikipedia](https://en.wikipedia.org/wiki/Telegram_(software)#Security) for a timeline in regards to the security.
Re: Briar Project
#118Earlier quoted context omitted.
Which requires you to trust your neighbours. To which you might say: aha! Just use end to end encryption! And sure, you can. But at that point, what benefits are you getting over using E2E with a centralised system? Very few. And you’re getting a bunch of drawbacks in terms of reliability too.
I dunno, a centralized server means a centralized off-switch, that's a pretty huge drawback in terms of reliability.
Re: Briar Project
#119Earlier quoted context omitted.
> Telegram isn't very secure Can someone elaborate?
There are different aspects to this. The first and the easily verifiable one is that they default to client-server-client connections, not end-to-end encryption. If you want to have an end-to-end encrypted channel, you have to explicitly open a "secret chat". However, this removes the convenience of cross device syncing. The second one is more difficult to evaluate. If you use the above mentioned "secret chat" featur…
https://telegram.org/apps#source-code
Encryption for secret chats doesn't involve server, so technically it can be analyzed.
It's a pity Telegram decided to roll their own encryption scheme. I use Telegram a lot for daily business because it's superior desktop messenger product. I would gladly participate if somebody started a crowd-funding for Telegram's security and encryption audit.
Re: Briar Project
#120Earlier quoted context omitted.
Authoritarian regimes are often far less technologically advanced than free countries. They will often import technology from free countries and be constrained by whatever freedom respecting decisions they've made.
This is like saying that the weapons advanced countries sell to less advanced countries are more "life-respecting".