@Yzijux what do people expect from a #Centralized, #SingleVendor & #SinglePrivided solution...

@TheMorpheus Merke: alle #zentralsiert|en, #SingleVendor und/oder #SingleProvider - Dienste sind inhärent unsicher und shice.

Egal ob #threema, #Signal, #discord, oder wasauchimmer...

@divVerent The problem is that @signalapp mandates #PII like #PhoneNumbers, which is critical for said #phishing...

#Signal can spout all their "#Metadata" - #FUD all day but in the end they fall under #CloudAct and will snitch on users because if they didn't it would've been a statistical inevitability that @Mer__edith and #Moxie would've been in jail and Signal shutdown like #EncroChat was.

  • Make of that what you will, but demanding a #PhoneNumber [which is either directly ("#KYC!") or indirectly / circumstantially linked to a person should be seen as *THE BIGGEST RED FLAG for any service.
    • It's like asking for an #ID at a store not as means to "verify age" with like a #DOB & Photo on something not trivial to forge but rather demanding someone's address just to buy a beer!

@signalapp those attacks.would've not.been successful if you weren't a #proprietary, #centralized, #SingleVendor / #SingleProvider "solution" that doesn't do #SelfCustoy of all the.keys nor allows for #SelfHosting nor demands #PII like #PhoneNumbers that can be leveraged for that.

Can't #phish if one doesn't have credentials for #phishing attacks ffs!

  • Can't get #phished if noone demands, stores, process or even demands such details in the first place!

Also which #Government is that incompetent to not be able to setup their own comms?

@DanielLuecking Angesichts dessen dass @signalapp ein zentralisierter #SingleVendor & #SingleProvider - #Chat-Anbieter ist betrachte ich es als deren Versagen.

@pinkforest thus the only correct reaction is multiple approaches:

Otherwiae we get the #Enshittification cycle going...

@novet @ambiguous_yelp I'll never trust any #SingleVendor and/or #SingleProvider solution, but demand real #E2EE with #SelfCustody and #SelfHosting capability as #FLOSS with reproduceable builds

  • Something #Signal can't and won't deliver as a matter of principle!

https://infosec.space/@kkarhan/114935952643402592

Unlike #monoclesChat, #gajim (#XMPP+OMEMO) & #deltachat as well as #Thunderbird!

Kevin Karhan :verified: (@[email protected])

My [reservations](https://infosec.space/@kkarhan/114234551915193036) and [criticism](https://infosec.space/@kkarhan/114862595629371002) re: #Signal are not just valid, but the reality is *even worse than I thought*: - The fact that @[email protected] requires not only their shitty #Android #App, and a #PhoneNumber but literally won't allow people to use their shitty #Desktop-App unless they have an Android device with a camera pointed at it makes it utterly unuseable for certain users *who don't have a fucking #camera in their Android*… Seriously, do they expect folks to deal with that shit? - It's already worse in terms of #UX than #telegram and #discord and that too makes #XMPP+#OMEMO clients like @[email protected] / #monoclesChat & @[email protected] / #gajim easier and faster to onboard #TechIlliterates onto. - Whichever asshole decided that a *replacement for #SMS* should mandate #PII like a #PhoneNumber & not be natively cross-platform should be banned from doing any #tech in their life. Trying to circumvent this shit and helping folks with it makes me so fucking angry that I'm now explicitly refusing to support it! FIX THAT SHIT, @[email protected], and if it means you need to kick some devs in their crouch then consider this a necessary *"investment"*… #sarcasm #TechSupport #TalesFromTechSupport #Enshittification #SignalSucks #TelegramSucks #Messengers

Infosec.Space

@nono2357 I disgree re: @signalapp / #Signal because it being a #SingleVendor & #SingleProvider 'solution' that by @Mer__edith 's own admission is hard locked-in at #aws and thus doubly subject to #CloudAct makes it a horrible choice, as they also collect #PII (in the form of #PhoneNumbers) and still peddle a #Shitcoin that even #Cryptocurrency expert users like @techlore can't even get to work.

https://www.youtube.com/watch?v=0DSGq9FQKU4
https://www.youtube.com/watch?v=tJoO2uWrX1M

We Tried Signal's MobileCoin So You Never Have To...

YouTube

@stman @theruran @50htz @vidak @forthy42 @brume @gorekhaa so yeah, we need a modern equivalent of the original PX-1000, something that isn't an overly complex and backdoored shitbox, but that is simple af.

With options for:

  • PS/2 [or USB] Keyboard
  • serial (thermal) printer
  • parallel (20x4) LC-Display (or Braille Screen)
  • acoustic modem (AFSK, using 3,5mm TRRS connector and adapters to line in/out and RJ-9 (handset)/RJ-11 (POTS/PSTN) phone.
  • IrDA & Consumer-IR & QR-code reader module for public key exchange
  • SDR reciever/transmitter (for paging).

Basically a encryption/decryption unit that has:

  • User input [PS/2](keyboard, QR-Code reader)
  • User output [Screen, Printer]
  • Remote input [IR, IrDA, Modem, SDR-Reciever]
  • Remote output [IR, IrDA, Modem, SDR Transciever]

Something that just acts as a "Clear Box" (aka. "black box", but transparent) to do critical comms. Something that literally wipes it's memory after use and doesn't store anything on it, but requires the user to keep their key safe!

You know, something that looks like a sleek communicator and isn't a proprietary shitbox that depends on *"#TrustMeBro!" - #centralized, #SingleVendor / #SingleProvider architecture!*…

Kevin Karhan :verified: (@[email protected])

@[email protected] @[email protected] @[email protected] @[email protected] @[email protected] [I know the story…](https://www.youtube.com/watch?v=FYgHiYDKrFU&t=2279) #TLDW: #TextLite made a good device and #Phillips as a #CIA puppet was tasked to obtain all those devices, remove them from circulation and replace them with an #insecure variant. https://cryptomuseum.com/crypto/philips/px1000/index.htm

Infosec.Space

@Soeren_loeg the fact that @signalapp not only does "#KYC with extra steps" by mandating a #PhoneNumber to this day as well as being solely under #CloudAct whilst basically being a #centralized, #proprietary, #SingleVendor & #SingleProvider solution makes them the ideal candidate for a longterm #HoneyPot like #ANØM aka. #OperationIronside aka. #OperationTrøjanShield.

Not to mention #Signal ticks way too many "#sus" boxes…

Kevin Karhan :verified: (@[email protected])

My [reservations](https://infosec.space/@kkarhan/114234551915193036) and [criticism](https://infosec.space/@kkarhan/114862595629371002) re: #Signal are not just valid, but the reality is *even worse than I thought*: - The fact that @[email protected] requires not only their shitty #Android #App, and a #PhoneNumber but literally won't allow people to use their shitty #Desktop-App unless they have an Android device with a camera pointed at it makes it utterly unuseable for certain users *who don't have a fucking #camera in their Android*… Seriously, do they expect folks to deal with that shit? - It's already worse in terms of #UX than #telegram and #discord and that too makes #XMPP+#OMEMO clients like @[email protected] / #monoclesChat & @[email protected] / #gajim easier and faster to onboard #TechIlliterates onto. - Whichever asshole decided that a *replacement for #SMS* should mandate #PII like a #PhoneNumber & not be natively cross-platform should be banned from doing any #tech in their life. Trying to circumvent this shit and helping folks with it makes me so fucking angry that I'm now explicitly refusing to support it! FIX THAT SHIT, @[email protected], and if it means you need to kick some devs in their crouch then consider this a necessary *"investment"*… #sarcasm #TechSupport #TalesFromTechSupport #Enshittification #SignalSucks #TelegramSucks #Messengers

Infosec.Space