50 Followers
163 Following
92 Posts
IT-Security student @ TU Darmstadt
Working on @twonly
Githubhttps://github.com/otsmr
Bloghttps://tsmr.eu
Working onhttps://twonly.eu

The Mullvad founder gave millions to extremist far right party:

https://www.flamman.se/techprofil-ger-miljoner-till-orebropartiet/

Techprofil ger miljoner till Örebropartiet

It-bolaget Mullvads grundare donerade fem miljoner – till parti som vill se ”storskalig återvandring”

Flamman

For the cryptography fans among you, here’s a little challenge with a 50€ prize :)

For @twonly, I’m planning a backup method where users no longer have to remember a password. The idea: Instead of trusting the server, just trust your friends.

You can find the exact details here: https://tsmr.eu/blog/2026-passwordless-recovery

#cryptography #bugbounty #e2ee

Break my Passwordless Recovery Protocol and get a 50€ Bug-Bounty

I designed a passwordless recovery protocol using trusted friends and a server-side second factor for my privacy-focused messaging app twonly. To ensure its security before release, I am launching a 50€ bug bounty challenge for anyone who can find a vulnerability in the protocol.

RE: https://cyberplace.social/@GossiTheDog/116759868416707730

We heard that Twitter/X too is critical for national security and folks outside the US should no longer be able to use it.

Heard that too?

Facebook as well, no? #securityfirst

RE: https://mastodon.social/@threemaapp/116730695713372347

Ein Glück, dass twonly keine Telefonnummern verwendet. 💪

Um trotzdem User Discovery anbieten zu können, verwendet twonly "Gemeinsame Freunde" um so Freunde finden zu können, ohne dass der jemals Server die Telefonnummer oder den Social Graph lernt.

Mehr dazu gibt es hier: https://twonly.eu/de/blog/2026-mutual-friends.html

Snapchat now displays personalized ads directly in your chats. Your personal data, such as your phone number and app usage, is used for personalization.

If you don't want that, switch to twonly now, where your data isn't analyzed for advertising purposes but is instead end-to-end encrypted.

#E2EE #privacy #europe #unplugtrump #unplugbigtech #opensource #snapchat

How do we advertise as a small bootstrapped privacy tech company staying true to our principles?
Paying Google, Meta&co for ad space was never an option. Instead we decided to sponsor @noybeu and support their crucial work defending our rights, and booked an ad-slot in this weeks GDPRtoday newsletter

thank you for everything you do @noybeu 💚💜

It’s still early days for Air, but the foundation on which it is built is solid. The @sovtechfund funded a security audit conducted by @srlabs of the underlying end-to-end encryption.

https://blog.phnx.im/openmls-independent-security-audit/

OpenMLS independent security audit: results, history, and what comes next

OpenMLS, our implementation of the Messaging Layer Security (MLS) protocol, has undergone a security audit. The audit is an important milestone for OpenMLS. In this post, we share the results and take the opportunity to give a broader introduction to OpenMLS.

Phoenix R&D

In Yesterday's IO Keynote Google declared war on the remnants of the Web.

While they packaged it as a lot of "AI" talk what their whole approach of decontextualizing information, of taking away links to sources and instead producing some LLM generated response means is that they want to establish a new abstraction layer on the web. Where Zuckerberg with his Metaverse failed Google is starting the next attack: Your website, your work no longer matters.

Well it matters as (unpaid) raw material for their synthetic text extruders but not as cultural artifact you can share with others.

This is a literal revolution but one against the participatory web, against us: The goal is to take away the web and guide people into Google's abstraction on top of it. An abstraction they control and moderate. It's about monopolizing access to information.

If you care about the web, about people's ability to participate in it as more than mere passive consumers, this needs to be taken seriously. De-Googlifying your mental apparatus becomes more urgent today. Find other search engines, don't use their browser. Or wake up in a slopified AOL kind of environment.

We recently updated twonly. Here are the two biggest updates:

1. Backups: Rebuilt to handle larger files, letting you keep all your contacts and messages.

2. Memories Viewer: Completely redesigned so you can select, export, or favorite multiple images at once and to be more performant.

This also sets up our next features: password(less) recovery and encrypted cloud backups. We also fixed several bugs to make messaging much more reliable.

Today is #DeleteWhatsAppDay 🚮

Five years after WhatsApp’s controversial privacy policy change, Meta is expected to become the world’s largest digital ad company, making it more important than ever to question data-driven business models: https://threema.com/bp/deletewhatsappday-more-relevant-than-ever