@Sascha woe gut dass ich meine nie veröffebtlicht habe, weil es einfach nen absolutes Unding ist.

- Dieser Shice wird ne Menge Sexarbeiter*innen gefärden!

#Amazon #Doxxing #SelfDoxxing #Wishlist

@electric_gumball yes and I stick with it.

#dlDoxxing #Cyberfascism #Privacy #PII #HumanRights #CivilRights #ITsec #InfoSec #OpSec #ComSec

@lackthereof it's not a "strange complaint", but a massive problem, because it creates dependency on a proven insecure network that is more often than not controlled if not run by hostile actors

  • Also #eMail, like #XMPP+#OMEMO, is based around #OpenStandards so you ain't forced to use any provider that is subject to #CloudAct nor known to snitch on customers without a valid domestic warrant
    • And if you trust noone, you can just host your eMail Server on a Rasberry Pi at home. It'll certainly be less convenient and more expensive but the you also get all the benefits of it being not possible to seize it without breaking into your home.

@signalapp mandating #PhoneNumners is a huge red flag because at best any #PhoneNumber is pseudonymous like a #Shitcoin-Wallet and that any #privacy is broken the moment it has any (even remotely circumstantial) connection to someone.

  • Because even if you ain't forced into #SelfDoxxing to obtain a #Prepaid - #SIM (aka. "#KYC") and/or Phone Number it is still a bad design.
    • Not to mention that this conpletely twarts their "#Metadata - #FUD" completely.

Not to mention #Signal's #App is a huge shitshow

The Lack Thereof :v_bi: (@[email protected])

@[email protected] This has always struck me as the strangest complaint about Signal. You don't need to distribute your phone number to actually communicate with other signal users. Presumably you want some form of 2fa, because losing your account would be bad. And you don't want to be tied to some cloud based email provider. And it's literally a phone app so every single user has the dependency.

beige.party

@krutonium @eff @torproject "Know Your Customer" aka. mandating people to self-d0x to use a service!

  • It spread well beyond the [admittedly false!] pretense of "combatting #MoneyLaundering and Terrorism Financing"
Know your customer - Wikipedia

Seriously, #Facebook abusing their #users as #AI #sources and maximizing #DarkPatterns is not coincidential, and I wounder how people who don't have or want a Facebook account can actually object against that shit or #ShadowProfiles without #SelfDoxxing and gambling on #StasiBook having good vibes that day...
A History of Facebook's (& Meta's) Decline

YouTube

@neil IMHO It's overdue that #Android #developers press charges for #extortion and #blackmail against #Google and that @EUCommission bans this #coercion of #SelfDoxxing, because Google has NO "legitimate interests" (and #Enshittification is not a legitimate interest worth protection by regulators!)…

@seabass thanks for the info.

Personally, I use @fdroidorg / #Fdroid exclusively and think that their approach for their own repo (pull the #git sources for any #App and compile the release version before signing it with F-Droid's key) is sufficiently secure.

  • OFC one can add 3rd party repos to it and those could be malicious as similar to #Linux package managers like apt, they've to provide their own signatures and knowingly adding malicious repos will enable #malware

Personally, I hope @EUCommission and other #regulators will tell #Google that this is unacceptable and I hope developers will instead file charges for #blackmail and #extortion against Google rather than #SelfDoxxing!

@adisonverlice the problem is that this is mandatory "#SelfDoxxing" and puts genuine #developers at risk whilst also empowering malicious actors.

  • In fact I know multiple developers that'll refuse to do this shit as a matter of principle - myself included!

IDK if you've read and/or understood the original post by Google, but this will apply to EVERY ANDROID DEVELOPER regardless if they ever put their #Apps on #GooglePlay or prefer to distribute manually (requiring device owners to manually "allow 3rd party app sources") or whatever.

  • It's the sheer principle!

I'm not shure if @LineageOS / #lineageOS, @e_mydata / #eOS or @GrapheneOS / #GrapheneOS will go out of their way to disable this since I assume this is enforced with the "#GooglePlay Services Framework" but I'm convinced #Google will mandate it for every Google Play - enabled & -certified device!

Kevin Karhan :verified: (@[email protected])

Also like any *"#KYC"* this doesn't work because #Malicious Actors will just used #forged #ID|s and/or have some #StrawPeople at hand. - Just like #DrugTraffickers register #Companies with #fake #IDs and/or pawns. See #Navigatix and their [35,5t cocaine loads](https://www.youtube.com/watch?v=-I8q0v02_Dw&t=135s) which are known as #OperationPlexus by German Police...

Infosec.Space

In jedem Falle sollte mensch niemals und unter keinen Umständen irgendwem seine [echten] Personalien Mitteilen oder gar nen Perso-Foto bzw. Selfie schicken!

  • Es gibt sehr, sehr wenige die wirklich sowas verlangen dürfen [bspw. #Autovermietung] oder gar müssen [siehe #Banken] aber die werden i.d.R. einen persönlich hereinbestellen [bspw.: Autovermietung machts bei Schlüsselübergabe] oder seriöse Lösungen [bspw.: #POSTIDENT] nutzen. Auf jeden Fall wird kein Händler³ im Internet sowas verlangen!

Alles andere führt nur zu #Identitätsdiebstahl und #Identitätsmissbrauch wo entsprechende Opfer dann z.T. als Beschuldigte*r in tausenden Fällen dann gearscht ist...

³[Selbst nicht beim legalen Waffenkauf! Da wird stattdessen ne Kopie der WBK samt Nummer verlangt weil der Kauf wird quasi in Echtzeit gemeldet und ohne passenden Voreintrag im System ist auch kein Erwerb möglich!...]

#KYCisTheIllicitActivity #InfoSec #ComSec #OpSec #KYC #IllicitActivity

Wenn internationale Banden DEINE IDENTITÄT benutzen: Betrüger-Netzwerken auf der Spur | Story SWR

YouTube

@rysiek @agturcz that's not how you fix #TechIlliteracy, espechally since things changed for the better.

@monocles / #monoclesChat & @gajim / #gajim are quite easy, whereas @signalapp / #Signal demands #PII in the form of a #Phone number which is more often than not not legally obtainable without "#KYC" aka. "forced #SelfDoxxing" all whilst being an extremely #centralized, #SingleVendor & #SingleProvider solution that falls under #CloudAct ant thus cannot adhere to #GDPR & #BDSG!

Otherwise we'd only perpetuate the #Enshittification-#Lifecycle as has happened with #AIM, #ICQ, #BBM and so many more...

  • Mark my words, cuz I've been proven correct up to this point.

If #Signal and @Mer__edith actually cared, they would've setup their system truly decentralized as an #OnionService over @torproject / #Tor!

#THXBYE #EOD #ITsec #InfoSec #OpSec #ComSec #DigitalSnakeoil #FakeSec

Michał "rysiek" Woźniak · 🇺🇦 (@[email protected])

@[email protected] I ran and hosted a bunch of XMPP servers a while back. It was a pain to use, and it was easy for users to make mistakes and accidentally send messages in the clear. You are making people les safe. Last time: please stop doing this in my mentions and replies. @[email protected] @[email protected]

Mastodon 🐘