50 Followers
163 Following
93 Posts
IT-Security student @ TU Darmstadt
Working on @twonly
Githubhttps://github.com/otsmr
Bloghttps://tsmr.eu
Working onhttps://twonly.eu

"A shocking backroom deal is underway to revive Chat Control 1.0 this Friday — and on Monday 29 June, the final trilogue for permanent mass scanning takes place."

If you haven't already done so, please send an email to help stop the chat control.

https://fightchatcontrol.eu/#contact-tool

Fight Chat Control - Protect Digital Privacy in the EU

Learn about the EU Chat Control proposal and contact your representatives to protect digital privacy and encryption.

The Mullvad founder gave millions to extremist far right party:

https://www.flamman.se/techprofil-ger-miljoner-till-orebropartiet/

Techprofil ger miljoner till Örebropartiet

It-bolaget Mullvads grundare donerade fem miljoner – till parti som vill se ”storskalig återvandring”

Flamman

For the cryptography fans among you, here’s a little challenge with a 50€ prize :)

For @twonly, I’m planning a backup method where users no longer have to remember a password. The idea: Instead of trusting the server, just trust your friends.

You can find the exact details here: https://tsmr.eu/blog/2026-passwordless-recovery

#cryptography #bugbounty #e2ee

Break my Passwordless Recovery Protocol and get a 50€ Bug-Bounty

I designed a passwordless recovery protocol using trusted friends and a server-side second factor for my privacy-focused messaging app twonly. To ensure its security before release, I am launching a 50€ bug bounty challenge for anyone who can find a vulnerability in the protocol.

RE: https://cyberplace.social/@GossiTheDog/116759868416707730

We heard that Twitter/X too is critical for national security and folks outside the US should no longer be able to use it.

Heard that too?

Facebook as well, no? #securityfirst

@jbjrkng Or they switch from Snapchat to @twonly :)

RE: https://mastodon.social/@threemaapp/116730695713372347

Ein Glück, dass twonly keine Telefonnummern verwendet. 💪

Um trotzdem User Discovery anbieten zu können, verwendet twonly "Gemeinsame Freunde" um so Freunde finden zu können, ohne dass der jemals Server die Telefonnummer oder den Social Graph lernt.

Mehr dazu gibt es hier: https://twonly.eu/de/blog/2026-mutual-friends.html

Snapchat now displays personalized ads directly in your chats. Your personal data, such as your phone number and app usage, is used for personalization.

If you don't want that, switch to twonly now, where your data isn't analyzed for advertising purposes but is instead end-to-end encrypted.

#E2EE #privacy #europe #unplugtrump #unplugbigtech #opensource #snapchat

How do we advertise as a small bootstrapped privacy tech company staying true to our principles?
Paying Google, Meta&co for ad space was never an option. Instead we decided to sponsor @noybeu and support their crucial work defending our rights, and booked an ad-slot in this weeks GDPRtoday newsletter

thank you for everything you do @noybeu 💚💜

It’s still early days for Air, but the foundation on which it is built is solid. The @sovtechfund funded a security audit conducted by @srlabs of the underlying end-to-end encryption.

https://blog.phnx.im/openmls-independent-security-audit/

OpenMLS independent security audit: results, history, and what comes next

OpenMLS, our implementation of the Messaging Layer Security (MLS) protocol, has undergone a security audit. The audit is an important milestone for OpenMLS. In this post, we share the results and take the opportunity to give a broader introduction to OpenMLS.

Phoenix R&D

In Yesterday's IO Keynote Google declared war on the remnants of the Web.

While they packaged it as a lot of "AI" talk what their whole approach of decontextualizing information, of taking away links to sources and instead producing some LLM generated response means is that they want to establish a new abstraction layer on the web. Where Zuckerberg with his Metaverse failed Google is starting the next attack: Your website, your work no longer matters.

Well it matters as (unpaid) raw material for their synthetic text extruders but not as cultural artifact you can share with others.

This is a literal revolution but one against the participatory web, against us: The goal is to take away the web and guide people into Google's abstraction on top of it. An abstraction they control and moderate. It's about monopolizing access to information.

If you care about the web, about people's ability to participate in it as more than mere passive consumers, this needs to be taken seriously. De-Googlifying your mental apparatus becomes more urgent today. Find other search engines, don't use their browser. Or wake up in a slopified AOL kind of environment.