It's getting harder and harder to not publicly say critical things about the competition...
Notices by Chester Wisniewski (chetwisniewski@securitycafe.ca), page 2
-
Embed this notice
Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Saturday, 20-Jan-2024 09:53:28 JST Chester Wisniewski
-
Embed this notice
Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Friday, 01-Dec-2023 05:43:06 JST Chester Wisniewski
Great! TransUnion, whom I have the pleasure of receiving free credit monitoring from due to the MGM Casino breach in Sept, has a policy of only allowing 15 characters or less. Not like anything important is on the line or anything. Oh, they get bonus points for letting me skip the password with a trivial security question! #InfoSec #NotAFeature @boblord @thorsheim
-
Embed this notice
Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Monday, 26-Jun-2023 15:07:37 JST Chester Wisniewski
@atomicpoet @iameli It sounds good, but I don't see it being possible without compromising many people's safety. Suggesting it is safe without having studied the underlying risks is dangerous and irresponsible. (2/2)
-
Embed this notice
Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Monday, 26-Jun-2023 15:07:37 JST Chester Wisniewski
@atomicpoet @iameli federation by definition will decrease security and privacy. We all want a pony, but it's just not possible. Side channel attacks, differential communication analysis, key distribution/generation and many other issues make federation a dangerous compromise.
We would all like CSAM to be eliminated, but it isn't possible to have secure & private communication and yet still scan for it. Similarly federation requires compromises that would put many people at risk. (1/2)
-
Embed this notice
Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Monday, 26-Jun-2023 14:42:37 JST Chester Wisniewski
@atomicpoet @iameli I'm sure the women and minorities who will be stalked and harassed when their privacy is impacted by your proposed solution will find solace in the world being a more just place.
-
Embed this notice
Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Monday, 26-Jun-2023 14:38:04 JST Chester Wisniewski
@atomicpoet @iameli I don't disagree, but you are making a decision for others. You are asking they sacrifice their safety and security to achieve some misinformed version of fairness. My 30 years of working in security and privacy tell me this is a very bad way to solve the problem you are trying to solve. You are trying to reinvent SMS, which we already have and is already terrible.
-
Embed this notice
Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Monday, 26-Jun-2023 14:32:53 JST Chester Wisniewski
@atomicpoet @iameli Being a zealot helps no one. Understanding risks, benefits and politics are all important factors. Spreading misinformation and then insisting that people should work harder to achieve likely impossible goals is not helping anyone.
Is Meta evil? Absolutely. Is federation the answer to all problems? Absolutely not. Stick to what you know and work to help people make better choices.
-
Embed this notice
Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Monday, 26-Jun-2023 14:23:12 JST Chester Wisniewski
@atomicpoet What? I'm quite sure that WhatsApp uses the Signal protocol these days.
-
Embed this notice
Chester Wisniewski (chetwisniewski@securitycafe.ca)'s status on Monday, 26-Jun-2023 14:23:10 JST Chester Wisniewski
@atomicpoet I don't think Federation is really possible with secure protocols like Signal. WhatsApp apparently completed the transition in 2016 https://signal.org/blog/whatsapp-complete/