GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Martin (mshelton@mastodon.social), page 2

  1. Embed this notice
    Martin (mshelton@mastodon.social)'s status on Friday, 22-Nov-2024 16:43:45 JST Martin Martin
    • Signal

    Ever since the welcome rollout of @signalapp usernames and phone number privacy options, we've gotten some questions about Signal's many new types of identifiers. Here are the differences between each one. https://freedom.press/training/blog/signal-identifiers/

    In conversation about a year ago from mastodon.social permalink

    Attachments


  2. Embed this notice
    Martin (mshelton@mastodon.social)'s status on Thursday, 21-Nov-2024 14:51:32 JST Martin Martin

    Always
    Be
    Clicking
    'Download update'
    https://www.securityweek.com/apple-confirms-zero-day-attacks-hitting-intel-based-macs/

    In conversation about a year ago from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.securityweek.com
      Apple Confirms Zero-Day Attacks Hitting macOS Systems
      from @https://www.twitter.com/ryanaraine/
      Apple rushes out out major macOS and iOS security updates to cover a pair of vulnerabilities already being exploited in the wild.
  3. Embed this notice
    Martin (mshelton@mastodon.social)'s status on Tuesday, 19-Nov-2024 05:28:29 JST Martin Martin

    Want to try Proton Mail? Note:
    -Proton Mail is encrypted between Proton / PGP users. Otherwise it's normal email. E.g., when you email Gmail, it's not private
    -Subject lines are not encrypted
    -Not anonymous https://techcrunch.com/2021/09/06/protonmail-logged-ip-address-of-french-activist-after-order-by-swiss-authorities/
    -Unfortunately it's still email
    https://freedom.press/digisec/blog/protonmail-pro/

    In conversation about a year ago from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: techcrunch.com
      ProtonMail logged IP address of French activist after order by Swiss authorities | TechCrunch
      from Natasha Lomas
      ProtonMail, a hosted email service with a focus on end-to-end encrypted communications, has been facing criticism after a police report showed that French
    2. Domain not in remote thumbnail source whitelist: media.freedom.press
      Proton Mail like a pro
      from @harlo
      Proton Mail is a Switzerland-based email client that offers end-to-end encryption between its users by default. This means that communication between anyone whose email is managed by Proton Mail can only be viewed by members of that party; No outside parties, including Proton Mail itself, can view the content of …
  4. Embed this notice
    Martin (mshelton@mastodon.social)'s status on Friday, 15-Nov-2024 07:07:30 JST Martin Martin

    We often talk to journalists about likely attacks from trolls. One of the most common ways trolls get your personal data (e.g., email, phone number) is through data brokers. If you haven't already, it's a very good time to invest in a data broker opt-out service (e.g., DeleteMe, Optery).

    In conversation about a year ago from mastodon.social permalink
  5. Embed this notice
    Martin (mshelton@mastodon.social)'s status on Wednesday, 13-Nov-2024 07:32:55 JST Martin Martin

    The best time to set up secure communication channels was a long time ago. The next best time is now. Here's a short list of guides to check out to get started: https://freedom.press/digisec/guides/secure-communication/

    In conversation about a year ago from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: media.freedom.press
      Secure communication
      Defending press freedom for the next generation
  6. Embed this notice
    Martin (mshelton@mastodon.social)'s status on Wednesday, 13-Nov-2024 02:54:43 JST Martin Martin

    Something concrete we can do right now to protect journalists and their sources in 2025: Tell your reps to pass the PRESS Act.

    Nationwide, the PRESS Act expands protections for journalists from government requests on forcibly giving up confidential sources. We can pass this! Contact your reps here: https://go.peoplepower.org/letter/congress-press-act#

    In conversation about a year ago from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: s3.amazonaws.com
      Tell Congress: Protect Journalists, Pass the PRESS Act
      Earlier this year, the US House unanimously passed the PRESS Act, a bill which would prevent the government from compelling journalists to disclose their sources or records created as part of their reporting, except in extreme cases. This is the second time the PRESS Act has passed the House. Unfortunately, despite bipartisan support in the House and in the Senate, where it is sponsored by Senator Wyden and co-sponsored by Senators Durbin, Lee, and Graham, the PRESS Act has not yet received a vote in the Senate. We need to make sure Congress passes the PRESS Act this year. While the majority of states already have shield laws in place that protect journalists from compelled disclosure of their sources, the PRESS Act provides uniform protections to journalists across the country, ensuring their ability to freely report information and to hold our leaders accountable. Tell the Senate: Pass the PRESS Act and protect journalists’ ability to do their jobs.
  7. Embed this notice
    Martin (mshelton@mastodon.social)'s status on Tuesday, 12-Nov-2024 07:47:28 JST Martin Martin
    in reply to

    This sounds simple, but the implications of Signal usernames can't be understated. No one knows who you are unless you tell them, or they have your number already. This underscores the importance of building networks of trust. You still need established channels for people to prove who they are.

    In conversation about a year ago from mastodon.social permalink
  8. Embed this notice
    Martin (mshelton@mastodon.social)'s status on Tuesday, 12-Nov-2024 07:47:28 JST Martin Martin
    in reply to

    You can always change the username later. It's important to know that the username is just for beginning a conversation, and not the same as the display name someone sees in the chat. More on all the Signal identifiers here: https://freedom.press/digisec/blog/signal-identifiers/

    In conversation about a year ago from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: media.freedom.press
      Understanding every one of Signal’s identifiers
      from @mshelton
      We’ve heard some questions about the difference between Signal usernames, phone numbers, profile names, profiles, and nicknames. Let’s talk about it.
  9. Embed this notice
    Martin (mshelton@mastodon.social)'s status on Tuesday, 12-Nov-2024 07:47:28 JST Martin Martin
    • Signal

    Okay, so you're using @signalapp for encrypted messaging. Cool. It's a good time to use usernames instead of a phone number to talk to people. That and lots more about how to make the most of Signal's security features in here: https://freedom.press/digisec/blog/locking-down-signal/

    In conversation about a year ago from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: media.freedom.press
      Locking down Signal
      from @mshelton
      Also available in Spanish.
  10. Embed this notice
    Martin (mshelton@mastodon.social)'s status on Tuesday, 12-Nov-2024 07:47:27 JST Martin Martin
    in reply to

    Signal's new "call links" feature has important implications:
    - This makes it easier to start a call with other users (including strangers)
    - You don't have to give away your identity to anyone in conversation
    - Again, this all underscores the need for trusted networks, and vetting who is included

    In conversation about a year ago from mastodon.social permalink
  11. Embed this notice
    Martin (mshelton@mastodon.social)'s status on Tuesday, 12-Nov-2024 07:47:27 JST Martin Martin
    in reply to

    Signal now supports an option to send links to calls. This could be a very big deal, because you don't even need to join a group chat to join a call any more. https://signal.org/blog/call-links/

    In conversation about a year ago from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: signal.org
      Improving Private Signal Calls: Call Links & More
      from @signalapp
      If you love group calls on Signal, but don’t want to create a group chat for every combination of your friends or colleagues, you’re in luck. Today we’re launching call links: Share a link with anyone on Signal and in just a tap or click they can join the call. No group chat required.
  12. Embed this notice
    Martin (mshelton@mastodon.social)'s status on Tuesday, 12-Nov-2024 07:47:27 JST Martin Martin
    in reply to

    End-to-end encryption only helps if you are talking to people who you trust. The "ends" — the devices used by people in conversation — really need to be trustworthy. Keep those devices up to date, and take seriously the relationships you're going to include in these conversations.

    In conversation about a year ago from mastodon.social permalink
  13. Embed this notice
    Martin (mshelton@mastodon.social)'s status on Thursday, 07-Nov-2024 07:16:24 JST Martin Martin

    I don't really have any words that can meet this moment. One small thing I can offer is digital security assistance to people at risk. Most of my experience is supporting journalists and media activists with security. If this in any way overlaps with your needs, reach out: https://mshelt.onl/contact.html

    In conversation about a year ago from mastodon.social permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Martin Shelton
  14. Embed this notice
    Martin (mshelton@mastodon.social)'s status on Saturday, 10-Aug-2024 06:39:25 JST Martin Martin
    • Mike Masnick ✅

    This interview with @mmasnick and Don McGowan, a former NCMEC board member, is eye opening. McGowan talks about the board's political alignment and connects this to its selective attention when it comes to its safety efforts. It's a pretty damning interview. https://www.techdirt.com/2024/08/08/the-many-reasons-why-ncmecs-board-is-failing-its-mission-from-a-ncmec-insider/

    In conversation Saturday, 10-Aug-2024 06:39:25 JST from mastodon.social permalink

    Attachments


  15. Embed this notice
    Martin (mshelton@mastodon.social)'s status on Saturday, 13-Jul-2024 19:46:03 JST Martin Martin
    in reply to

    The AT&T breach underscores the importance of being mindful of call and text metadata — something Signal handles much better than traditional phone calls and texts. Unlike your telecom provider, Signal doesn't retain logs of your calls and texts on their servers. Your activities are stored on your device and with anyone you speak to. https://freedom.press/training/signal-beginners/

    In conversation Saturday, 13-Jul-2024 19:46:03 JST from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: media.freedom.press
      Signal, the secure messaging app: A guide for beginners
      How to get started using Signal, the encrypted messaging app.
  16. Embed this notice
    Martin (mshelton@mastodon.social)'s status on Saturday, 13-Jul-2024 19:45:30 JST Martin Martin

    If you're a journalist who used AT&T between May 1-October 31, 2022, you're going to want to revisit your call and text history from that time and see which of your sources you were communicating with. These records have been improperly secured by AT&T. https://www.usatoday.com/story/tech/2024/07/12/att-data-breach-who-affected-what-to-do/74379292007/

    In conversation Saturday, 13-Jul-2024 19:45:30 JST from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.usatoday.com
      How to know if you were affected by the AT&T data breach and what to do next
      from Gabe Hauari
      AT&T said Friday the call and text message records of nearly all of its cellular customers were exposed in a data breach. Here's what we know.
  17. Embed this notice
    Martin (mshelton@mastodon.social)'s status on Friday, 10-May-2024 04:57:45 JST Martin Martin
    • Signal

    I like how Elon's own community notes fact check him on @signalapp.

    In conversation Friday, 10-May-2024 04:57:45 JST from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/112/412/568/334/301/766/original/9255be7a3d029349.png
  18. Embed this notice
    Martin (mshelton@mastodon.social)'s status on Friday, 10-May-2024 04:57:44 JST Martin Martin
    in reply to
    • Meredith Whittaker

    No one's going to respond more effectively than @Mer__edith, so if you want to learn more, just read Meredith's post: https://twitter.com/mer__edith/status/1787958712595784166

    In conversation Friday, 10-May-2024 04:57:44 JST from mastodon.social permalink

    Attachments


  19. Embed this notice
    Martin (mshelton@mastodon.social)'s status on Friday, 15-Mar-2024 09:52:02 JST Martin Martin

    The founder behind @mozilla's data broker removal service… Apparently runs data broker sites?

    "The data privacy company Onerep.com bills itself as a Virginia-based service for helping people remove their personal information from almost 200 people-search websites. However, an investigation into the history of onerep.com finds this company is operating out of Belarus and Cyprus, and that its founder has launched dozens of people-search services over the years." https://krebsonsecurity.com/2024/03/ceo-of-data-privacy-company-onerep-com-founded-dozens-of-people-search-firms/

    In conversation Friday, 15-Mar-2024 09:52:02 JST from mastodon.social permalink

    Attachments


    1. Domain not in remote thumbnail source whitelist: krebsonsecurity.com
      CEO of Data Privacy Company Onerep.com Founded Dozens of People-Search Firms
      The data privacy company Onerep.com bills itself as a Virginia-based service for helping people remove their personal information from almost 200 people-search websites. However, an investigation into the history of onerep.com finds this company is operating out of Belarus and…
  20. Embed this notice
    Martin (mshelton@mastodon.social)'s status on Friday, 23-Feb-2024 06:44:22 JST Martin Martin
    in reply to

    In response to username changes, we've also made some small updates to our guide on setting up a secondary Signal account.
    - We try to help people decide if this guide addresses their specific need for a secondary account, or if usernames are sufficient for their needs.
    - We no longer recommend an iPod Touch because it has been discontinued, and we encourage people to use devices that have long-term security updates. https://freedom.press/training/secondary-signal-account/

    In conversation Friday, 23-Feb-2024 06:44:22 JST from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: media.freedom.press
      So you want a second Signal account
      How to set up a second account on Signal, the encrypted messaging app.
  • After
  • Before

User actions

    Martin

    Martin

    Security therapist. Deputy Director of Digital Security @freedomofpress. Journalism, digital security, research.If you want to get security news and updates from our team somewhere that's not Twitter, subscribe to the newsletter: https://freedom.press/newsletters/

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          35044
          Member since
          22 Nov 2022
          Notices
          50
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.