SHARD — Secure Messaging App

A quick look at what is coming this Weekend #shardmsgr

#secure #privacy #messenger #message #private #media #send #communicate #security #encrypted #signal #safety #safe #whatsapp #instagram

#Shardmsgr the Messenger that is NOT spying on you.

qqo-opp

Client application for the qqo-opp network.

Shocked that it has taken me so long, thanks to a heads-up from a friend & #nixos via #claudecode, to see that I should have set up:
(1) #ECH on my #reverseproxy serving my sites
(2) #DoT on my daily driver.
#DNS url names (web addresses) are *not* #encrypted by default even on sensible operating systems!
The incessant leakage to #ISP & intermediaries of site names visited in 99.9% of cases is an egregious #privacy issue I never knew of. Using #DoH is next? All fixes rely on #CloudFlare OMG
Dashlane explains how attackers managed to download encrypted password vaults

By targeting large numbers of users, attackers increased their chances of success.

Ars Technica

#Android Gets Fake Call Detection That Uses #RCS

#Phone by #Google wants to combat the "growing threat of #impersonation #scams " and protect Android users against "sophisticated, AI-powered #deepfake attacks" with fake call detection. [...] Fake call detection requires that both parties are on Android and use the Phone by Google app, while #GoogleMessages and #GoogleContacts also have to be installed. When a contact calls, their phone "sends a silent confirmation signal in real time to your device to verify the call is legitimate and truly coming from the contact's device." This digital handshake uses end-to-end #encrypted RCS (Rich Communication Services).
#encryption #e2ee #privacy #security

https://tech.slashdot.org/story/26/06/02/2357229/android-gets-fake-call-detection-that-uses-rcs?utm_source=rss1.0mainlinkanon&utm_medium=feed

Android Gets Fake Call Detection That Uses RCS - Slashdot

An anonymous reader quotes a report from 9to5Google: Phone by Google wants to combat the "growing threat of impersonation scams" and protect Android users against "sophisticated, AI-powered deepfake attacks" with fake call detection. [...] Fake call detection requires that both parties are on Androi...

We Sued #ICE to Get Its #Spyware Contract. The Agency Is #Redacting Essentially Everything

#Immigration and #Customs Enforcement (ICE) contracted with a spyware company that tells customers it ensures they can use the tool without the agency being caught doing so, according to documents obtained by 404 Media through our ongoing lawsuit against ICE.

In September, we sued ICE for documents related to its $2 million contract with #Paragon , a company that makes powerful spyware for remotely #hacking phones and accessing #encrypted messaging apps.
#encryption

https://www.404media.co/we-sued-ice-to-get-its-spyware-contract-the-agency-is-redacting-essentially-everything/

We Sued ICE to Get Its Spyware Contract. The Agency Is Redacting Essentially Everything

Paragon's software is capable of remotely breaking into phones and accessing messages from encrypted messaging apps. Our lawsuit aims to pry records about it from ICE.

404 Media

So far my #HomeAssistant instance had been running on the local subnet, behind the #Router's #Firewall and so was inaccessible from outside my house’s network. However, I’ve now got it onto the #Internet. Of course, there are inherent risks and potential problems with this if malicious actors want to crack the system and so I made sure that it’s only accessible as an #Encrypted connection via #HTTPS rather than #HTTP.

#GNU #Linux #FreeSoftware #HAOS

#Oura says it gets #government demands for user data. Will it share how many?

Oura users' data is not end-to-end #encrypted and can be handed to the government. Will the #wearable tech maker say how often it turns over data?
#privacy #security #surveillance #tracking #e2ee #encryption #subpoena

https://this.weekinsecurity.com/oura-says-it-gets-government-demands-for-user-data-will-it-share-how-many/

Oura says it gets government demands for user data. Will it share how many?

Oura users' data is not end-to-end encrypted and can be handed to the government. Will the wearable tech maker say how often it turns over data?

~this week in security~

Mounted my first Luksbox, protected by a Yubikey. Works very well.

Compared to Gocryptfs: you have support for FIDO2 keys.

Compared to veracrypt and truecrypt, the big advantage is you don't have to reserve x Gb for the encrypted partition.

#luks #encrypted #partition #volume #fido #crypt #file #linux

cc: @Penthertz