GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by pixelschubsi (pixelschubsi@troet.cafe)

  1. Embed this notice
    pixelschubsi (pixelschubsi@troet.cafe)'s status on Wednesday, 24-Dec-2025 01:21:03 JST pixelschubsi pixelschubsi
    in reply to
    • Daniel Gultsch
    • Tris

    @daniel @tris I'm also genuinely surprised that people believe that ActivityPub, a protocol even named after its purpose, to publish activities, is a good protocol to pursue private instant messaging. The goals of those two couldn't be more detrimental.

    I do see a purpose of being able to reuse your "ActivityPub identities", which actually are just WebFinger identities. Maybe someone should specify how to discover XMPP accounts via WebFinger and push that as a solution for AP messaging?

    In conversation about 3 months ago from troet.cafe permalink
  2. Embed this notice
    pixelschubsi (pixelschubsi@troet.cafe)'s status on Sunday, 07-Dec-2025 17:27:28 JST pixelschubsi pixelschubsi
    in reply to
    • aœ bärlin

    @aoeBerlin Auf den Website https://cdu-denkmal.de/ wird der Sohn zitiert. In vorherigen Interviews haben sich sowohl der Sohn als auch die Witwe negativ über die CDU geäußert.

    In conversation about 3 months ago from gnusocial.jp permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: cdu-denkmal.de
      Bau das Walter Lübcke Memorial direkt vor die Parteizentrale der CDU
      Bau das Walter Lübcke Memorial direkt vor die Parteizentrale der CDU und werde Teil der Brandmauer
  3. Embed this notice
    pixelschubsi (pixelschubsi@troet.cafe)'s status on Saturday, 29-Nov-2025 20:37:13 JST pixelschubsi pixelschubsi
    in reply to
    • ✧✦Catherine✦✧

    @whitequark the rasterizing and putting on the screen is performed by the browser, not the website. Optimized SVGs are magnitudes smaller and often also faster to render than raster images most websites still use today. But the main reason websites are megabytes in size today, is that they rely on complex frameworks that do a ton of things on the client (in JavaScript) that's really not needed for getting the content on the screen.

    In conversation about 4 months ago from troet.cafe permalink
  4. Embed this notice
    pixelschubsi (pixelschubsi@troet.cafe)'s status on Saturday, 29-Nov-2025 20:37:12 JST pixelschubsi pixelschubsi
    in reply to
    • ✧✦Catherine✦✧
    • Josh Simmons

    @dotstdy @whitequark the same caching of rendered images actually applies to raster images, except their rendering is more of a decoding. Still, the svg instruction to draw a hexagon with a gradient on it is usually significantly smaller and faster from request to render cache than a high resolution jpeg that has the very same effective rendering result.

    In conversation about 4 months ago from troet.cafe permalink
  5. Embed this notice
    pixelschubsi (pixelschubsi@troet.cafe)'s status on Friday, 24-Oct-2025 23:24:15 JST pixelschubsi pixelschubsi
    in reply to
    • Hailey
    • ✧✦Catherine✦✧

    @hailey @whitequark Except that using gzip inside encryption makes you susceptible for CRIME/BREACH style attacks.

    In conversation about 5 months ago from gnusocial.jp permalink
  6. Embed this notice
    pixelschubsi (pixelschubsi@troet.cafe)'s status on Thursday, 20-Feb-2025 03:01:43 JST pixelschubsi pixelschubsi
    • Signal
    • Rich Felker
    • monocles
    • Amber

    @puppygirlhornypost2 @signalapp @dalias @monocles @kkarhan

    For legal reasons, I can't speak about a bunch of internals of Play Services. This page https://developers.google.com/android/guides/overview?hl=en clearly shows that Google has the power to issue automatic updates to the part that is not inside the embedded library. I leave it up to your imagination that for technical reasons, some play services features (including Google Maps) had to replace IPC with dynamic loading.

    In conversation about a year ago from troet.cafe permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.gstatic.com
      Overview of Google Play services  |  Google for Developers
  7. Embed this notice
    pixelschubsi (pixelschubsi@troet.cafe)'s status on Thursday, 20-Feb-2025 02:15:10 JST pixelschubsi pixelschubsi
    in reply to
    • Signal
    • Lauren Weinstein
    • Rich Felker
    • monocles

    @dalias @kkarhan @signalapp @monocles @lauren

    If you are saying, Signal is doing a better job in ensuring that big tech doesn't get rich with the data of its users than WhatsApp, I'll happily sign that.

    But to me - and also how Signal advertises itself - it's not only against big tech, but also against state actors. And then this becomes a whole different story.

    In conversation about a year ago from troet.cafe permalink
  8. Embed this notice
    pixelschubsi (pixelschubsi@troet.cafe)'s status on Thursday, 20-Feb-2025 02:11:41 JST pixelschubsi pixelschubsi
    in reply to
    • Signal
    • Lauren Weinstein
    • Rich Felker
    • monocles

    @dalias @kkarhan @signalapp @monocles @lauren

    As far as I know, this is turned off by default and even then only visible if people look at the details of a message (which they don't do, realistically). Remember that this only has to happen for a single message to create the link in the contact graph. So if any, this is a red herring, not a mechanism that prevents Signal servers from creating a contact graph, if e.g. forced by the crazy government of the country they are located in.

    In conversation about a year ago from troet.cafe permalink
  9. Embed this notice
    pixelschubsi (pixelschubsi@troet.cafe)'s status on Thursday, 20-Feb-2025 02:00:59 JST pixelschubsi pixelschubsi
    in reply to
    • Signal
    • Lauren Weinstein
    • Rich Felker
    • monocles

    @dalias @kkarhan @signalapp @monocles @lauren

    Honestly, "RCE" is the whole purpose of the library embedded here. That's not an issue, it's a feature, Google sells this as dynamically updating your dependency. This is why Signal cannot be made available in the F-Droid store.

    In conversation about a year ago from troet.cafe permalink
  10. Embed this notice
    pixelschubsi (pixelschubsi@troet.cafe)'s status on Thursday, 20-Feb-2025 01:54:12 JST pixelschubsi pixelschubsi
    in reply to
    • Signal
    • Lauren Weinstein
    • Rich Felker
    • monocles

    @dalias @kkarhan @signalapp @monocles @lauren

    As is described in the issue, the fallback to revealing the sender when sealed sender fails is not in any way communicated to the user and happens fully automatically. In fact, it randomly happens to users every now and then and that is by design. If it were to notify users when this happens, it would be very confusing.

    In conversation about a year ago from troet.cafe permalink
  11. Embed this notice
    pixelschubsi (pixelschubsi@troet.cafe)'s status on Thursday, 20-Feb-2025 01:51:08 JST pixelschubsi pixelschubsi
    in reply to
    • Signal
    • Lauren Weinstein
    • Rich Felker
    • monocles

    @dalias @kkarhan @signalapp @monocles @lauren

    Mastodon removes the line number from the shared link in the nice preview.

    In the shared file, line 123 is the reference to a proprietary and obfuscated library that is included as part of the build process. This library was never audited, but it is known to, when used, dynamically load and execute code without any additional sandboxing (thus inheriting all the permissions and access to the private files of the app calling into the library).

    In conversation about a year ago from troet.cafe permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      http://preview.In/
  12. Embed this notice
    pixelschubsi (pixelschubsi@troet.cafe)'s status on Thursday, 20-Feb-2025 01:43:20 JST pixelschubsi pixelschubsi
    in reply to
    • Signal
    • Lauren Weinstein
    • Rich Felker
    • monocles

    @dalias @kkarhan @signalapp @monocles @lauren

    Contact graph is who you are sending messages to. Signal servers can always see who receives a message and they can trivially see who sent a message if sealed senders is turned off (which, as is shown, can be done by the server). So Signal in fact has access to your contact graph.

    They also have access to a bunch of other metadata, like the Apple/Google push token that is known to be used to spy on people: https://www.reuters.com/technology/cybersecurity/governments-spying-apple-google-users-through-push-notifications-us-senator-2023-12-06/

    In conversation about a year ago from troet.cafe permalink

    Attachments


  13. Embed this notice
    pixelschubsi (pixelschubsi@troet.cafe)'s status on Thursday, 20-Feb-2025 01:43:19 JST pixelschubsi pixelschubsi
    in reply to
    • Signal
    • Lauren Weinstein
    • Rich Felker
    • monocles

    @dalias @kkarhan @signalapp @monocles @lauren

    And I'm not even talking about Signal directly uploading the numbers in your device's phone book (although encrypted in a way that they likely have no direct access to it, but others likely do).

    In conversation about a year ago from troet.cafe permalink
  14. Embed this notice
    pixelschubsi (pixelschubsi@troet.cafe)'s status on Thursday, 20-Feb-2025 01:39:06 JST pixelschubsi pixelschubsi
    in reply to
    • Signal
    • Lauren Weinstein
    • Rich Felker
    • monocles

    @dalias @kkarhan @signalapp @monocles @lauren

    Here's the link to the Signal source code dependency file importing a proprietary, obfuscated library that is known to dynamically load and execute arbitrary code from a server in the context of the calling process, thereby granting it access to everything that happens inside the app: https://github.com/signalapp/Signal-Android/blob/main/gradle/libs.versions.toml#L123

    In conversation about a year ago from troet.cafe permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      Signal-Android/gradle/libs.versions.toml at main · signalapp/Signal-Android
      A private messenger for Android. Contribute to signalapp/Signal-Android development by creating an account on GitHub.
  15. Embed this notice
    pixelschubsi (pixelschubsi@troet.cafe)'s status on Thursday, 20-Feb-2025 01:21:39 JST pixelschubsi pixelschubsi
    in reply to
    • Signal
    • Lauren Weinstein
    • Rich Felker
    • monocles

    @dalias @kkarhan @signalapp @monocles @lauren

    How do you know that Signal company does not share their metadata and contacts graph with Facebook. You make this assumption and you are probably right, but you have no way to verify.

    In conversation about a year ago from troet.cafe permalink
  16. Embed this notice
    pixelschubsi (pixelschubsi@troet.cafe)'s status on Thursday, 20-Feb-2025 01:19:45 JST pixelschubsi pixelschubsi
    in reply to
    • Signal
    • Lauren Weinstein
    • Rich Felker
    • monocles

    @dalias @kkarhan @signalapp @monocles @lauren

    Users, to a large degree, download the Signal app from the Google Play Store and Apple App Store. The apps shipped through this can hardly be verified by endusers. A modified version of the app could be delivered to selected users.

    The official Signal app for Android is not fully open source and in its non-free parts does have a mechanism built-in that allows the code to be changed at runtime without allowing external auditors to review it.

    In conversation about a year ago from troet.cafe permalink
  17. Embed this notice
    pixelschubsi (pixelschubsi@troet.cafe)'s status on Thursday, 20-Feb-2025 01:16:52 JST pixelschubsi pixelschubsi
    in reply to
    • Signal
    • Lauren Weinstein
    • Rich Felker
    • monocles

    @dalias @kkarhan @signalapp @monocles @lauren

    Specifically for this context, sealed-senders is one of the few features of Signal that differentiates it from WhatsApp, which uses largely the same crypto. If the few extra privacy features of Signal are just best-effort and it's fine they only work if the server does not misbehave, Signal becomes almost the same as WhatsApp - except that the one company that controls everything has a different name.

    In conversation about a year ago from troet.cafe permalink
  18. Embed this notice
    pixelschubsi (pixelschubsi@troet.cafe)'s status on Thursday, 20-Feb-2025 01:14:48 JST pixelschubsi pixelschubsi
    in reply to
    • Signal
    • Lauren Weinstein
    • Rich Felker
    • monocles

    @dalias @kkarhan @signalapp @monocles @lauren

    People always go with "Signal has the best crypto" to argue why Signal and only Signal. However, crypto alone is not the only thing in the world.

    Good crypto might be necessary for good privacy and security, but it doesn't alone solve the problem. If Signal would send a clear test backup of all messages to their servers, all this great crypto would be worth nothing.

    In conversation about a year ago from troet.cafe permalink
  19. Embed this notice
    pixelschubsi (pixelschubsi@troet.cafe)'s status on Friday, 14-Feb-2025 11:24:50 JST pixelschubsi pixelschubsi
    in reply to
    • Signal
    • Lauren Weinstein
    • Rich Felker
    • monocles

    @dalias @kkarhan @signalapp @monocles @lauren

    Some people like to make bold statements without verifying first.

    The server *can* do malicious things (even targeted, so it maybe already is happening without anyone known) that result in exactly an "undetected breakage of privacy properties". Here's an issue about this, closed with the comment that privacy features are only best-effort with no guarantee: https://github.com/signalapp/Signal-Android/issues/13842

    In conversation about a year ago from troet.cafe permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      Signal silently falls back to "unsealed sender" messages if server returns 401 when trying to send "sealed sender" messages · Issue #13842 · signalapp/Signal-Android
      Guidelines I have searched searched open and closed issues for duplicates I am submitting a bug report for existing functionality that does not work as intended This isn't a feature request or a di...
  20. Embed this notice
    pixelschubsi (pixelschubsi@troet.cafe)'s status on Monday, 23-Dec-2024 04:33:51 JST pixelschubsi pixelschubsi
    in reply to
    • Arne Babenhauserheide
    • Jan Böhmermann ?

    @ArneBab @janboehm
    Da ging es um zwei Sätze auf der ZDF-Webseite:

    > Schönbohm steht wegen möglicher Kontakte zu russischen Geheimdienstkreisen über den umstrittenen Verein 'Cyber-Sicherheitsrat Deutschland' in der Kritik

    und an einer anderen Stelle:

    > Er soll Kontakte zu russischen Geheimdienstkreisen gehabt haben

    Beides m.M.n. recht neutrale Berichterstattung und macht sich die Behauptung nicht zu eigen, aber sieht das Gericht wohl anders.

    Siehe https://www.lto.de/recht/nachrichten/n/lg-muenchen-i-26o1261223-arne-schoenbohm-zdf-jan-boehmermann

    In conversation about a year ago from troet.cafe permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.lto.de
      Schönbohm ./. ZDF: Magazin Royale hat falsch berichtet
      from LTO
      Das LG München I hat entschieden: Im ZDF tätigte Jan Böhmermann falsche Aussagen über den Ex-BSI-Chef, die eine Nähe zu Russland suggerierten.
  • Before

User actions

    pixelschubsi

    pixelschubsi

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          305097
          Member since
          10 Dec 2024
          Notices
          21
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.