GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Sexy Moon (moon@shitposter.club)'s status on Sunday, 05-Nov-2023 19:42:54 JST Sexy Moon Sexy Moon
    Even though I don't NEED another security key (I already have one more than I actually use) I think I am gonna finally buy a NitroKey and try it out because I want to know if it's better.
    In conversation Sunday, 05-Nov-2023 19:42:54 JST from shitposter.club permalink
    • Embed this notice
      Sexy Moon (moon@shitposter.club)'s status on Sunday, 05-Nov-2023 19:50:43 JST Sexy Moon Sexy Moon
      in reply to
      • Avatar of Chaos
      @MK2boogaloo I actually have a FSFE OpenPGP USB device (two in fact) where the hardware and software are fully free but they can only do PGP not FIDO2, OTP etc.

      NitroKey hardware and software are both open source, that is one of the reasons I'm looking into it.
      In conversation Sunday, 05-Nov-2023 19:50:43 JST permalink
    • Embed this notice
      Avatar of Chaos (mk2boogaloo@freebeerextremist.com)'s status on Sunday, 05-Nov-2023 19:50:45 JST Avatar of Chaos Avatar of Chaos
      in reply to
      @Moon why are you using proprietary key, Moon?
      In conversation Sunday, 05-Nov-2023 19:50:45 JST permalink
    • Embed this notice
      Avatar of Chaos (mk2boogaloo@freebeerextremist.com)'s status on Sunday, 05-Nov-2023 19:55:49 JST Avatar of Chaos Avatar of Chaos
      in reply to
      @Moon that's the problem here Moon, it's not FSF certified. There's no telling what's going to happen to your baby server.
      In conversation Sunday, 05-Nov-2023 19:55:49 JST permalink
      Sexy Moon likes this.
    • Embed this notice
      Sheriff CJ (The Impostor)?? (colonelj@freespeechextremist.com)'s status on Sunday, 05-Nov-2023 23:00:55 JST Sheriff CJ (The Impostor)?? Sheriff CJ (The Impostor)??
      in reply to
      @Moon if a fedi admin wanted to plant a tracking cookie into my browser to spy on me, how would they actually accomplish this?
      In conversation Sunday, 05-Nov-2023 23:00:55 JST permalink
      mia likes this.
    • Embed this notice
       (mint@ryona.agency)'s status on Sunday, 05-Nov-2023 23:00:55 JST  
      in reply to
      • Sheriff CJ (The Impostor)??
      @colonelj @Moon As easy as adding a Set-Cookie header in nginx and then adding a cookie header to logs. i think most modern browsers restrict third-party cookies, so it'll work only when you visit the site directly.
      In conversation Sunday, 05-Nov-2023 23:00:55 JST permalink
      mia likes this.
    • Embed this notice
      Sexy Moon (moon@shitposter.club)'s status on Sunday, 05-Nov-2023 23:45:13 JST Sexy Moon Sexy Moon
      in reply to
      • Sheriff CJ (The Impostor)??
      @colonelj A fedi admin could not plant a tracker on their instance that could track you across other websites, unless they also controlled those other websites.

      A site admin can only read the cookies of sites they control.

      Are you concerned about a specific thing you've heard?
      In conversation Sunday, 05-Nov-2023 23:45:13 JST permalink
    • Embed this notice
      feld (feld@bikeshed.party)'s status on Sunday, 05-Nov-2023 23:52:05 JST feld feld
      in reply to
      • Avatar of Chaos
      @Moon @MK2boogaloo last I looked the Nitrokeys didn't support smartcard
      In conversation Sunday, 05-Nov-2023 23:52:05 JST permalink
    • Embed this notice
      Parker Banks (parker@pl.psion.co)'s status on Monday, 06-Nov-2023 00:31:33 JST Parker Banks Parker Banks
      in reply to
      • Sheriff CJ (The Impostor)??
      @Moon @colonelj I thought something similar happened to chudbere/clairebere though.
      In conversation Monday, 06-Nov-2023 00:31:33 JST permalink
    • Embed this notice
      Sexy Moon (moon@shitposter.club)'s status on Monday, 06-Nov-2023 00:31:33 JST Sexy Moon Sexy Moon
      in reply to
      • Sheriff CJ (The Impostor)??
      • Parker Banks
      @parker @colonelj I thought they got tricked into downloading a Minecraft server plugin with malware in it.
      In conversation Monday, 06-Nov-2023 00:31:33 JST permalink
    • Embed this notice
      Sexy Moon (moon@shitposter.club)'s status on Monday, 06-Nov-2023 00:34:53 JST Sexy Moon Sexy Moon
      in reply to
      • feld
      • Avatar of Chaos
      @feld @MK2boogaloo the only applet I would install on a smartcard would be the pgp applet anyway
      In conversation Monday, 06-Nov-2023 00:34:53 JST permalink
      feld likes this.
    • Embed this notice
      Parker Banks (parker@pl.psion.co)'s status on Monday, 06-Nov-2023 01:15:36 JST Parker Banks Parker Banks
      in reply to
      • feld
      • Avatar of Chaos
      @Moon @feld @MK2boogaloo Nah this was before that ever happened. Something about checking what sites she visited. I can't remember though, so likely have some details fuzzy.
      In conversation Monday, 06-Nov-2023 01:15:36 JST permalink
    • Embed this notice
      Sexy Moon (moon@shitposter.club)'s status on Monday, 06-Nov-2023 01:15:36 JST Sexy Moon Sexy Moon
      in reply to
      • feld
      • Parker Banks
      • Avatar of Chaos
      @parker @feld @MK2boogaloo I will say that it is not supposed to be possible. However there have been side-channel attacks where for example, you could put a tracker on your site that makes requests to other sites. the javascript can't read the response but you can time the request somehow, and based on the timing you can determine if it was probably in the user's browser cache already and that tells you they had been to that site before. I don't know if that is still possible but it had been done in the past.
      In conversation Monday, 06-Nov-2023 01:15:36 JST permalink
    • Embed this notice
      feld (feld@bikeshed.party)'s status on Monday, 06-Nov-2023 02:06:28 JST feld feld
      in reply to
      • Avatar of Chaos
      @Moon @MK2boogaloo that's the one I need too
      In conversation Monday, 06-Nov-2023 02:06:28 JST permalink
      Sexy Moon likes this.
    • Embed this notice
       (mint@ryona.agency)'s status on Monday, 06-Nov-2023 04:48:40 JST  
      in reply to
      • Sheriff CJ (The Impostor)??
      • PonyPanda
      @PonyPanda @colonelj @Moon Never used it, can't say. I'm using a combination of uBlock+uMatrix, but the latter definely has a learning curve.
      In conversation Monday, 06-Nov-2023 04:48:40 JST permalink
    • Embed this notice
      PonyPanda (ponypanda@freespeechextremist.com)'s status on Monday, 06-Nov-2023 04:48:41 JST PonyPanda PonyPanda
      in reply to
      • 
      • Sheriff CJ (The Impostor)??
      @mint @colonelj @Moon is Privacy Badger actually any good?
      In conversation Monday, 06-Nov-2023 04:48:41 JST permalink
    • Embed this notice
      PonyPanda (ponypanda@freespeechextremist.com)'s status on Monday, 06-Nov-2023 04:50:43 JST PonyPanda PonyPanda
      in reply to
      • 
      • Sheriff CJ (The Impostor)??
      @mint @Moon @colonelj I got uBlock.
      In conversation Monday, 06-Nov-2023 04:50:43 JST permalink
       likes this.
    • Embed this notice
      Sexy Moon (moon@shitposter.club)'s status on Monday, 06-Nov-2023 10:07:56 JST Sexy Moon Sexy Moon
      in reply to
      • Sheriff CJ (The Impostor)??
      I don’t know how this would work tbh
      In conversation Monday, 06-Nov-2023 10:07:56 JST permalink
      mia likes this.
    • Embed this notice
      Sheriff CJ (The Impostor)?? (colonelj@freespeechextremist.com)'s status on Monday, 06-Nov-2023 10:07:57 JST Sheriff CJ (The Impostor)?? Sheriff CJ (The Impostor)??
      in reply to
      @Moon i'm just going by what they said :cirnoShrug: maybe they were full of shit the whole time, but it is concerning if it's truly that easy to fedi admins to track their users.

      <2022-06-27T02:58:23.000Z> [ADMIN 1]: im going to set up a trap in that poast's webserver will log all traffic by that IP and track him around, then we can paint a picture of where he went and what he was trying to do
      <2022-06-27T02:58:47.000Z> [ADMIN 1]: but we are going to watch it for a few weeks. he will slip up with referral sites or other cookies that can be tracked and i will find them
      <2022-06-27T02:59:00.000Z> [ADMIN 1]: [ADMIN 2] is more autistic about this stuff then i am so i expect results from at least one of us




      <2023-02-12T09:19:45.000Z> [ADMIN 1]: this person had a very specific way of searching for shit which made it super easy to find her
      <2023-02-12T09:20:13.000Z> [ADMIN 1]: so she moved to another instance -- [NODE 2] -- whos' admin im great friends with and we often work toghether on shit, like this -- which continued tracking her
      <2023-02-12T09:20:51.000Z> [ADMIN 1]: we planted a tracking cookie that recorded her steps after leaving poast until she came back to poast and she would frequently namesearch herself on twitter and come back to poast. it was really sad
      In conversation Monday, 06-Nov-2023 10:07:57 JST permalink
      mia likes this.
    • Embed this notice
      Sexy Moon (moon@shitposter.club)'s status on Monday, 06-Nov-2023 10:56:02 JST Sexy Moon Sexy Moon
      in reply to
      • Sheriff CJ (The Impostor)??
      • cyberpunklord420
      • The Problem :verified_pink:
      @colonelj @marine @ehhh you can't force the browser to do this.
      In conversation Monday, 06-Nov-2023 10:56:02 JST permalink
    • Embed this notice
      Sheriff CJ (The Impostor)?? (colonelj@freespeechextremist.com)'s status on Monday, 06-Nov-2023 10:56:03 JST Sheriff CJ (The Impostor)?? Sheriff CJ (The Impostor)??
      in reply to
      • Sheriff CJ (The Impostor)??
      • cyberpunklord420
      • The Problem :verified_pink:
      @ehhh @Moon @marine (particularly if it's a pleroma issue, as it should be patched)
      In conversation Monday, 06-Nov-2023 10:56:03 JST permalink
    • Embed this notice
      Sheriff CJ (The Impostor)?? (colonelj@freespeechextremist.com)'s status on Monday, 06-Nov-2023 10:56:04 JST Sheriff CJ (The Impostor)?? Sheriff CJ (The Impostor)??
      in reply to
      • cyberpunklord420
      • The Problem :verified_pink:
      @ehhh @marine @Moon I've never specifically asked how an admin would go about tracking a user through tracking cookies. even moon is perplexed, or appears to be, at how one could accomplish this. it's a pretty big deal.
      In conversation Monday, 06-Nov-2023 10:56:04 JST permalink
    • Embed this notice
      The Problem :verified_pink: (marine@breastmilk.club)'s status on Monday, 06-Nov-2023 10:56:05 JST The Problem :verified_pink: The Problem :verified_pink:
      in reply to
      • Sheriff CJ (The Impostor)??
      • cyberpunklord420

      @ehhh @colonelj @Moon CJ has been asking this same question, in different ways, since before i left. It’s intended to start drama if Moon’s dumb enough to answer it a certain way.

      In conversation Monday, 06-Nov-2023 10:56:05 JST permalink
    • Embed this notice
      cyberpunklord420 (ehhh@varishangout.net)'s status on Monday, 06-Nov-2023 10:56:05 JST cyberpunklord420 cyberpunklord420
      in reply to
      • Sheriff CJ (The Impostor)??
      • The Problem :verified_pink:
      @colonelj Really, dude?

      @marine @Moon
      In conversation Monday, 06-Nov-2023 10:56:05 JST permalink
    • Embed this notice
      cyberpunklord420 (ehhh@varishangout.net)'s status on Monday, 06-Nov-2023 10:56:06 JST cyberpunklord420 cyberpunklord420
      in reply to
      • Sheriff CJ (The Impostor)??
      • The Problem :verified_pink:
      I think it's normal for people novice to the technical part of security to ask questions like these (unless you're saying that @colonelj has been asking the same question over and over to people for a different reason.)

      @marine @Moon
      In conversation Monday, 06-Nov-2023 10:56:06 JST permalink
      mia likes this.
    • Embed this notice
      The Problem :verified_pink: (marine@breastmilk.club)'s status on Monday, 06-Nov-2023 10:56:07 JST The Problem :verified_pink: The Problem :verified_pink:
      in reply to
      • Sheriff CJ (The Impostor)??

      @colonelj @Moon CJ, stop stirring shit. Jfc.

      In conversation Monday, 06-Nov-2023 10:56:07 JST permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.