TimePencil

joined 8 months ago

@voracitude

Sean Bean? Naaah.
The husband survived.
Sean Bean pretty much only takes roles where his character dies...!
🤪
@galoisghost

[–] TimePencil@infosec.exchange 2 points 2 days ago (1 children)

@Salvo

Wearing clothing without washing it first is NOT advisable.

When a label reads, "wash before wearing," it is a safety instruction.

If one wishes to wear new underpants that are "factory fresh" complete with formaldehyde, go for it. Just don't act surprised when diagnosed with leukaemia...

https://www.choice.com.au/shopping/everyday-shopping/clothing/articles/chemicals-in-clothing

@melbaboutown

[–] TimePencil@infosec.exchange 5 points 3 days ago

@No1

What have you got against Great White Sharks?
What have they ever done to you?

AFAIK, every time Pauline Hanson goes swimming at a beach, an environmental impact statement needs to be completed, and clean up operations commence soon afterwards.

@MHLoppy

[–] TimePencil@infosec.exchange 3 points 3 days ago (1 children)

@pulsewidth

Yeah! I hear you, especially regarding 'onboarding' often being a barrier. (Thankfully, Signal is bloody easy.)

My own attitude to family and friends is to say, "If ya wanna communicate with me, these are the acceptable options..."

If they don't wish to use appropriate methods, that's fine, but they can't message me. Bugger 'em!

I encourage the use of Signal as a 'gateway drug"... I mean, "app," and several people have subsequently added other private messaging apps as options.

[–] TimePencil@infosec.exchange 5 points 4 days ago (3 children)

@quokka

I know I'm going to regret asking this, but why not Signal?

Yes, I know it has the disadvantage of not being decentralised, and it's not anonymous as a phone number is required.

However, for the *vast majority* of people, it is the simplest and easiest solution to gaining E2EE comms.

@Davriellelouna

[–] TimePencil@infosec.exchange 1 points 1 week ago (3 children)

@BlueSquid0741

Are Ice Break (2 litre) bottles not recyclable?

There's no deposit on them, but they're marked with "please recycle".

@Davriellelouna

The back of a 2 litre Ice Break (ice coffee) bottle.

[–] TimePencil@infosec.exchange 6 points 1 week ago* (last edited 1 week ago)

@Vanilla_PuddinFudge

Yes...
... but that's OK.

Lemme explain...

A Signal user will commonly have the client app installed on their mobile device.

They may also have a second client on a laptop that syncs the same data.

If the user goes on holiday for a week but leaves their laptop behind, it won't be synced to the laptop.

On return from holiday, the laptop client uses its decryption keys to retrieve the last week's worth of messages.

I *think* Signal can do this (retrieve cached messages from the Signal servers) for up to 14 days.

That said, the entire Signal cache is encrypted on their servers, and one's messages are fully E2EE and retrievable only by the user.

(However, one weakness of Signal is that a desktop or laptop client's cache is stored unencrypted. To secure these, one needs to use full disk encryption at the OS level or higher.)

@DarkCloud

[–] TimePencil@infosec.exchange 1 points 1 week ago (1 children)

@sunzu2

"Under FISA order, signal would provide logs."

How would Signal do this? Logs of what?

Corresponding parties? Messages? They don't have them.

They'd have to rewrite their backend code to obtain them, and changes would also need to be made to the Signal client apps.

It would not matter if the FISA Court ordered that logs be produced in secret by Signal. Any such logs could not be obtained without significant changes to the way Signal works. Users would know.

Yes, Signal does have some shortcomings, but these are acceptable in most 'use cases' for most threat models.

Signal is best used as a private, E2EE alternative to SMS. Only a fool would use it for the *most sensitive* of communications. (Like, you know, discussing an impending military strike...)

We all know of the alternatives, including (but not limited to) SimpleX, Session, Briar, Element etc.

@maniacalmanicmania @9tr6gyp3 @signalapp

[–] TimePencil@infosec.exchange 1 points 1 week ago (3 children)

@sunzu2

Read the Affidavit produced here:
https://signal.org/bigbrother/santaclara/

Read Signal's complete source code here:
https://github.com/signalapp

Once you understand the code, you'll understand "what they can do" and what they cannot do.

When you've identified any flaw in the code that runs the Signal servers that would allow IP logging, let me know. I'll be glad to file the bug report on your behalf.

@maniacalmanicmania @9tr6gyp3 @signalapp

[–] TimePencil@infosec.exchange 1 points 1 week ago (5 children)

@sunzu2

Signal knows *when* a user wqs last connected, but not the IP address of that connection. The system has been specifically designed to minimise the meta data available for collection.

@maniacalmanicmania @9tr6gyp3 @signalapp

[–] TimePencil@infosec.exchange 1 points 1 week ago (7 children)

@sunzu2

To do the things you are suggesting that Signal could be forced to do, Signal would have to rewrite its entire codebase as well as the client apps.

Fortunately, Signal is open source, and such changes would be noticed.

As it stands, it doesn't matter what is demanded nor by whom as the only user data, including traffic analysis, that Signal can currently reveal is insignificant.

Signal simply cannot disclose data it itself cannot access.

Yes, decentralised services are preferable, but Signal has probably the easiest onboarding experience for the average user, especially those new to the concept of E2EE.

@maniacalmanicmania @9tr6gyp3 @signalapp

[–] TimePencil@infosec.exchange 4 points 1 week ago (9 children)

@sunzu2

Nope and I was wrong.
@signalapp is only able to produce LESS information than I previously stated.

  1. The phone number (which will already be known by the relevant authority.)
  2. Last connection date.
  3. Account creation date.

That's it. Nothing else.
Signal does NOT log users' IP addresses.

See this for more information:
https://signal.org/bigbrother/santaclara/

@maniacalmanicmania @9tr6gyp3 @signalapp

view more: next ›