@Sascha woe gut dass ich meine nie veröffebtlicht habe, weil es einfach nen absolutes Unding ist.
- Dieser Shice wird ne Menge Sexarbeiter*innen gefärden!
@Sascha woe gut dass ich meine nie veröffebtlicht habe, weil es einfach nen absolutes Unding ist.
- Dieser Shice wird ne Menge Sexarbeiter*innen gefärden!
@electric_gumball yes and I stick with it.
#dlDoxxing #Cyberfascism #Privacy #PII #HumanRights #CivilRights #ITsec #InfoSec #OpSec #ComSec
@lackthereof it's not a "strange complaint", but a massive problem, because it creates dependency on a proven insecure network that is more often than not controlled if not run by hostile actors…
@signalapp mandating #PhoneNumners is a huge red flag because at best any #PhoneNumber is pseudonymous like a #Shitcoin-Wallet and that any #privacy is broken the moment it has any (even remotely circumstantial) connection to someone.
Not to mention #Signal's #App is a huge shitshow…
@[email protected] This has always struck me as the strangest complaint about Signal. You don't need to distribute your phone number to actually communicate with other signal users. Presumably you want some form of 2fa, because losing your account would be bad. And you don't want to be tied to some cloud based email provider. And it's literally a phone app so every single user has the dependency.
@krutonium @eff @torproject "Know Your Customer" aka. mandating people to self-d0x to use a service!
@neil IMHO It's overdue that #Android #developers press charges for #extortion and #blackmail against #Google and that @EUCommission bans this #coercion of #SelfDoxxing, because Google has NO "legitimate interests" (and #Enshittification is not a legitimate interest worth protection by regulators!)…
@seabass thanks for the info.
Personally, I use @fdroidorg / #Fdroid exclusively and think that their approach for their own repo (pull the #git sources for any #App and compile the release version before signing it with F-Droid's key) is sufficiently secure.
apt, they've to provide their own signatures and knowingly adding malicious repos will enable #malware…Personally, I hope @EUCommission and other #regulators will tell #Google that this is unacceptable and I hope developers will instead file charges for #blackmail and #extortion against Google rather than #SelfDoxxing!
@adisonverlice the problem is that this is mandatory "#SelfDoxxing" and puts genuine #developers at risk whilst also empowering malicious actors.
IDK if you've read and/or understood the original post by Google, but this will apply to EVERY ANDROID DEVELOPER regardless if they ever put their #Apps on #GooglePlay or prefer to distribute manually (requiring device owners to manually "allow 3rd party app sources") or whatever.
I'm not shure if @LineageOS / #lineageOS, @e_mydata / #eOS or @GrapheneOS / #GrapheneOS will go out of their way to disable this since I assume this is enforced with the "#GooglePlay Services Framework" but I'm convinced #Google will mandate it for every Google Play - enabled & -certified device!
Also like any *"#KYC"* this doesn't work because #Malicious Actors will just used #forged #ID|s and/or have some #StrawPeople at hand. - Just like #DrugTraffickers register #Companies with #fake #IDs and/or pawns. See #Navigatix and their [35,5t cocaine loads](https://www.youtube.com/watch?v=-I8q0v02_Dw&t=135s) which are known as #OperationPlexus by German Police...
In jedem Falle sollte mensch niemals und unter keinen Umständen irgendwem seine [echten] Personalien Mitteilen oder gar nen Perso-Foto bzw. Selfie schicken!
Alles andere führt nur zu #Identitätsdiebstahl und #Identitätsmissbrauch wo entsprechende Opfer dann z.T. als Beschuldigte*r in tausenden Fällen dann gearscht ist...
³[Selbst nicht beim legalen Waffenkauf! Da wird stattdessen ne Kopie der WBK samt Nummer verlangt weil der Kauf wird quasi in Echtzeit gemeldet und ohne passenden Voreintrag im System ist auch kein Erwerb möglich!...]
#KYCisTheIllicitActivity #InfoSec #ComSec #OpSec #KYC #IllicitActivity
@rysiek @agturcz that's not how you fix #TechIlliteracy, espechally since things changed for the better.
@monocles / #monoclesChat & @gajim / #gajim are quite easy, whereas @signalapp / #Signal demands #PII in the form of a #Phone number which is more often than not not legally obtainable without "#KYC" aka. "forced #SelfDoxxing" all whilst being an extremely #centralized, #SingleVendor & #SingleProvider solution that falls under #CloudAct ant thus cannot adhere to #GDPR & #BDSG!
"JuSt UsE sIgNaL !" won't fix #TechIlliteracy but rather provide false sense of security to #TechIlliterates when the correct solution is to teach proper #TechLiteracy like @cryptoparty / @cryptoparty / #CryptoParty does...Otherwise we'd only perpetuate the #Enshittification-#Lifecycle as has happened with #AIM, #ICQ, #BBM and so many more...
If #Signal and @Mer__edith actually cared, they would've setup their system truly decentralized as an #OnionService over @torproject / #Tor!
#THXBYE #EOD #ITsec #InfoSec #OpSec #ComSec #DigitalSnakeoil #FakeSec
@[email protected] I ran and hosted a bunch of XMPP servers a while back. It was a pain to use, and it was easy for users to make mistakes and accidentally send messages in the clear. You are making people les safe. Last time: please stop doing this in my mentions and replies. @[email protected] @[email protected]