Dev from Germany, also interested in DnD and some video games

  • 0 Posts
  • 11 Comments
Joined 3 years ago
cake
Cake day: June 28th, 2023

help-circle
  • Im not a big fan of meta and WhatsApp, but these claims are a bit much. Any employee gets access to messages through a well documented internal process? “No separate decryption step is required” , so the WhatsApp CLIENT is not doing any actual e2e encryption and no attempt at reverse engineering or traffic analysis has ever seen that this is the case?

    Where can one see, what these whistleblowers have actually published? I would expect to see this “simple process” and how that interface actually works… And I would expect any journalist to request some proof (show me the last message i sent to Alice) before trusting an anonymous whistleblower making such an extraordinary claim.

    From what I heard so far, that anonymous whistleblower could be a troll or an ex-employee who just wants to cause some trouble for meta.

    We should not trust anything blindly, even if it fits with our view of the world. Meta is an evil company, but as long as there is no indication for these specific allegations to be true, we should treat them as unfounded allegations.



  • I don’t think that googles mail Client supports pgp. And if you use a client you trust with Google mail, the content of your mail is encrypted.

    They will still use metadata to track who you are talking to and about what. The Mail subject is metadata and therefore not encrypted.

    So to keep your conversations private, dont use gmail, and probably don’t use mail at all, use something build with encryption in mind.


  • Its main “security” feature is that they are uncooperative towards most governments. If a government makes a legally binding request to signal, they recieve IP, Account creation date and other unavoidable stuff and signal is transparent about that. If telegram gets that request, they probably ignore it, but maybe they don’t and there is no way to know as a user.

    Also telegram is the platform of drug dealers, nazis and conspiracy theorists. So even if it had e2e by default, I would still prefer using another platform.



  • GrapheneOS is popular with degoogling, but that’s not its primary goal. If there is a tradeoff between independence from Google and security, they will always choose to increase security.

    GrapheneOS is also probably the only custom rom that cooperates with Google to get access to vulnerabilities and patches before the embargo is lifted.

    If you want to be completely independent from Google, GrapheneOS is not what you’re looking for. Its it’s a security focused os that also has some degoogling features, not the other way around.