GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Alex Gleason (alex@gleasonator.com)'s status on Tuesday, 29-Nov-2022 09:21:33 JST Alex Gleason Alex Gleason
    • @polarisera reposted your post

    Rant on E2EE messages:

    Twitter says adopt E2EE encrypted messages based on Signal, but it has an impossible task ahead of it.

    The reason Signal works is because it doesn’t scale. Yes, you can have it on your laptop and your phone, but even that’s a lot to ask.

    When I send you a message on Signal, I actually send a separate message to every known device you have on Signal. If that’s 20 devices, I send 20 separate messages. If everyone has 20 devices, it becomes a big problem.

    Therefore, Signal doesn’t have a website you can visit and log in, because it can’t afford for everyone’s browser tab to be a “device”. Also, new devices are blank slates that can’t sync data from old devices.

    Signal exists to encrypt EVERYTHING about your conversations. If the CIA got into Signal’s database they wouldn’t be able to tell:

    1. who you’ve been sending messages to
    2. how many messages you’ve sent, or at what times
    3. if you’ve even sent messages at all

    This is because of the double-ratchet algorithm that regenerates keypairs between every message as part of an agreement with the recipient.

    Encryption can absolutely work in the Twittersphere, but we need to compromise a bit on privacy for better UX. The best solution is to just encrypt the message BODY. Then it becomes like email. Yes, we can see who you’ve been talking to and how many messages you’ve sent and at what times, but we can’t see what you were actually saying. It’s exactly the same as PGP encryption in email. That’s what makes sense. People who need that level of privacy should be using Signal instead of Twitter or the Fediverse.

    Incidentally, there’s been some great work done recently by a gay furry that I think makes a lot of sense for encrypted messages on the Fediverse: https://github.com/soatok/mastodon-e2ee-specification

    RT: https://spinster.xyz/objects/0d4533e8-fe31-4f6d-a021-2117697ff370

    In conversation Tuesday, 29-Nov-2022 09:21:33 JST from gleasonator.com permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      GitHub - soatok/mastodon-e2ee-specification: Soatok's Proposal for End-to-End Encryption in Mastodon
      Soatok's Proposal for End-to-End Encryption in Mastodon - GitHub - soatok/mastodon-e2ee-specification: Soatok's Proposal for End-to-End Encryption in Mastodon

    • Embed this notice
      King Henry VIII (goodperson@nicecrew.digital)'s status on Tuesday, 29-Nov-2022 09:24:04 JST King Henry VIII King Henry VIII
      in reply to
      • @polarisera reposted your post
      Just get infinite money.
      In conversation Tuesday, 29-Nov-2022 09:24:04 JST permalink
    • Embed this notice
      Alex Gleason (alex@gleasonator.com)'s status on Tuesday, 29-Nov-2022 09:24:04 JST Alex Gleason Alex Gleason
      in reply to
      • @polarisera reposted your post
      • King Henry VIII

      @GoodPerson @polarisera Lol duh! Throwing money at the problem can defy the laws of physics.

      In conversation Tuesday, 29-Nov-2022 09:24:04 JST permalink
    • Embed this notice
      Cum_Death :verified: (sneedvicious@rdrama.cc)'s status on Tuesday, 29-Nov-2022 10:30:54 JST Cum_Death :verified: Cum_Death :verified:
      in reply to
      • @polarisera reposted your post
      @alex @polarisera Correct me if im wrong but. missing from your cia glow opps is number 4: an approximation of message size.

      These are a fucking lot of info still
      In conversation Tuesday, 29-Nov-2022 10:30:54 JST permalink
      Alex Gleason likes this.
    • Embed this notice
      Alex Gleason (alex@gleasonator.com)'s status on Tuesday, 29-Nov-2022 16:27:37 JST Alex Gleason Alex Gleason
      in reply to
      • d3n

      @d3n Can you log into a website for WhatsApp?

      In conversation Tuesday, 29-Nov-2022 16:27:37 JST permalink
    • Embed this notice
      d3n (d3n@noagendasocial.com)'s status on Tuesday, 29-Nov-2022 16:27:39 JST d3n d3n
      in reply to

      @alex They will probably take the same shortcuts as whatsapp..

      In conversation Tuesday, 29-Nov-2022 16:27:39 JST permalink
    • Embed this notice
      @polarisera reposted your post (polarisera@spinster.xyz)'s status on Tuesday, 29-Nov-2022 16:36:02 JST @polarisera reposted your post @polarisera reposted your post
      in reply to
      • Cum_Death :verified:
      @SneedVicious @alex He's vegan, btw
      In conversation Tuesday, 29-Nov-2022 16:36:02 JST permalink
      Alex Gleason likes this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.