Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. When I said that your discord clone doesn’t need e2ee, I got a lot of comments along the lines of “ then how would I use it to organize the revolution!” The answer is: you don’t.

When I said that your discord clone doesn’t need e2ee, I got a lot of comments along the lines of “ then how would I use it to organize the revolution!” The answer is: you don’t.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
9 Indlæg 5 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • 0xabad1dea@infosec.exchange0 This user is from outside of this forum
    0xabad1dea@infosec.exchange0 This user is from outside of this forum
    0xabad1dea@infosec.exchange
    wrote sidst redigeret af
    #1

    When I said that your discord clone doesn’t need e2ee, I got a lot of comments along the lines of “ then how would I use it to organize the revolution!” The answer is: you don’t. If you have more users than can comfortably share a Signal chat and hence want to use discord or something like it, you cannot POSSIBLY be vetting all of them to a high standard of trust. Your logs ARE leaking. End-to-end encryption between more people than can fit around a dinner table is pointless.

    This article confirms what I already assumed, that “open source [information sense, not code sense] intelligence gathering on social media” includes, for the US government, asking for links to join groups that may *feel* private. My own discord has literally like a thousand idlers. It would be very *lucky* if none of them were logging for potentially nefarious purposes! And I remind the active users of this occasionally.

    https://www.kenklippenstein.com/p/exclusive-ice-masks-up-in-more-ways

    ratsnakegames@mastodon.socialR owlor@meow.socialO 5225225@furry.engineer5 3 Replies Last reply
    1
    0
    • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

      When I said that your discord clone doesn’t need e2ee, I got a lot of comments along the lines of “ then how would I use it to organize the revolution!” The answer is: you don’t. If you have more users than can comfortably share a Signal chat and hence want to use discord or something like it, you cannot POSSIBLY be vetting all of them to a high standard of trust. Your logs ARE leaking. End-to-end encryption between more people than can fit around a dinner table is pointless.

      This article confirms what I already assumed, that “open source [information sense, not code sense] intelligence gathering on social media” includes, for the US government, asking for links to join groups that may *feel* private. My own discord has literally like a thousand idlers. It would be very *lucky* if none of them were logging for potentially nefarious purposes! And I remind the active users of this occasionally.

      https://www.kenklippenstein.com/p/exclusive-ice-masks-up-in-more-ways

      ratsnakegames@mastodon.socialR This user is from outside of this forum
      ratsnakegames@mastodon.socialR This user is from outside of this forum
      ratsnakegames@mastodon.social
      wrote sidst redigeret af
      #2

      @0xabad1dea i also don't think that organizing revolutions is the majority usecase for Discord

      0xabad1dea@infosec.exchange0 me@mastodon.cysioland.plM 2 Replies Last reply
      0
      • ratsnakegames@mastodon.socialR ratsnakegames@mastodon.social

        @0xabad1dea i also don't think that organizing revolutions is the majority usecase for Discord

        0xabad1dea@infosec.exchange0 This user is from outside of this forum
        0xabad1dea@infosec.exchange0 This user is from outside of this forum
        0xabad1dea@infosec.exchange
        wrote sidst redigeret af
        #3

        @ratsnakegames no but this is mastodon so no-one’s sure what other social activities exist

        1 Reply Last reply
        0
        • ratsnakegames@mastodon.socialR ratsnakegames@mastodon.social

          @0xabad1dea i also don't think that organizing revolutions is the majority usecase for Discord

          me@mastodon.cysioland.plM This user is from outside of this forum
          me@mastodon.cysioland.plM This user is from outside of this forum
          me@mastodon.cysioland.pl
          wrote sidst redigeret af
          #4

          @ratsnakegames @0xabad1dea to be fair, e2ee is also useful for selling drugs

          ratsnakegames@mastodon.socialR 1 Reply Last reply
          0
          • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

            When I said that your discord clone doesn’t need e2ee, I got a lot of comments along the lines of “ then how would I use it to organize the revolution!” The answer is: you don’t. If you have more users than can comfortably share a Signal chat and hence want to use discord or something like it, you cannot POSSIBLY be vetting all of them to a high standard of trust. Your logs ARE leaking. End-to-end encryption between more people than can fit around a dinner table is pointless.

            This article confirms what I already assumed, that “open source [information sense, not code sense] intelligence gathering on social media” includes, for the US government, asking for links to join groups that may *feel* private. My own discord has literally like a thousand idlers. It would be very *lucky* if none of them were logging for potentially nefarious purposes! And I remind the active users of this occasionally.

            https://www.kenklippenstein.com/p/exclusive-ice-masks-up-in-more-ways

            owlor@meow.socialO This user is from outside of this forum
            owlor@meow.socialO This user is from outside of this forum
            owlor@meow.social
            wrote sidst redigeret af
            #5

            @0xabad1dea I wonder about the government agent whose job it is to pretend to be a puppygirl in order to infiltrate a discord group where people mainly argue about the best way to take HRT.

            0xabad1dea@infosec.exchange0 1 Reply Last reply
            0
            • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

              When I said that your discord clone doesn’t need e2ee, I got a lot of comments along the lines of “ then how would I use it to organize the revolution!” The answer is: you don’t. If you have more users than can comfortably share a Signal chat and hence want to use discord or something like it, you cannot POSSIBLY be vetting all of them to a high standard of trust. Your logs ARE leaking. End-to-end encryption between more people than can fit around a dinner table is pointless.

              This article confirms what I already assumed, that “open source [information sense, not code sense] intelligence gathering on social media” includes, for the US government, asking for links to join groups that may *feel* private. My own discord has literally like a thousand idlers. It would be very *lucky* if none of them were logging for potentially nefarious purposes! And I remind the active users of this occasionally.

              https://www.kenklippenstein.com/p/exclusive-ice-masks-up-in-more-ways

              5225225@furry.engineer5 This user is from outside of this forum
              5225225@furry.engineer5 This user is from outside of this forum
              5225225@furry.engineer
              wrote sidst redigeret af
              #6

              @0xabad1dea to be honest, i disagree, not because it's safe to fedpost in a chat of hundreds of users, but because it makes e2ee itself less suspicious, and more noisy to infiltrate

              yes, a fed can lurk in a large member count e2ee chat, but that still involves the effort to join, and possibly even talk sometimes when spoken to. and they'll absolutely not be in every chat.

              as opposed to "hey discord let us run grep across your message database"

              like, we're at the point for the web where every website[maintained] is encrypted, even if it would be fine for most to be plaintext. (and we got to that point by making TLS pretty much free)

              e2ee is only really considered optional/a misfeature in some cases because it's not free, but it should be.

              0xabad1dea@infosec.exchange0 1 Reply Last reply
              0
              • owlor@meow.socialO owlor@meow.social

                @0xabad1dea I wonder about the government agent whose job it is to pretend to be a puppygirl in order to infiltrate a discord group where people mainly argue about the best way to take HRT.

                0xabad1dea@infosec.exchange0 This user is from outside of this forum
                0xabad1dea@infosec.exchange0 This user is from outside of this forum
                0xabad1dea@infosec.exchange
                wrote sidst redigeret af
                #7

                @Owlor I imagine there’s a recurring issue with them going native 😂

                1 Reply Last reply
                0
                • 5225225@furry.engineer5 5225225@furry.engineer

                  @0xabad1dea to be honest, i disagree, not because it's safe to fedpost in a chat of hundreds of users, but because it makes e2ee itself less suspicious, and more noisy to infiltrate

                  yes, a fed can lurk in a large member count e2ee chat, but that still involves the effort to join, and possibly even talk sometimes when spoken to. and they'll absolutely not be in every chat.

                  as opposed to "hey discord let us run grep across your message database"

                  like, we're at the point for the web where every website[maintained] is encrypted, even if it would be fine for most to be plaintext. (and we got to that point by making TLS pretty much free)

                  e2ee is only really considered optional/a misfeature in some cases because it's not free, but it should be.

                  0xabad1dea@infosec.exchange0 This user is from outside of this forum
                  0xabad1dea@infosec.exchange0 This user is from outside of this forum
                  0xabad1dea@infosec.exchange
                  wrote sidst redigeret af
                  #8

                  @5225225 sorry, I can't hear you. maybe we should both just delete all our keys and generate new ones? just click through whatever warning it shows you, this happens all the time

                  1 Reply Last reply
                  0
                  • me@mastodon.cysioland.plM me@mastodon.cysioland.pl

                    @ratsnakegames @0xabad1dea to be fair, e2ee is also useful for selling drugs

                    ratsnakegames@mastodon.socialR This user is from outside of this forum
                    ratsnakegames@mastodon.socialR This user is from outside of this forum
                    ratsnakegames@mastodon.social
                    wrote sidst redigeret af
                    #9

                    @me if i were to sell drugs, i wouldn't do it in a group chat

                    1 Reply Last reply
                    0
                    • jwcph@helvede.netJ jwcph@helvede.net shared this topic
                    Svar
                    • Svar som emne
                    Login for at svare
                    • Ældste til nyeste
                    • Nyeste til ældste
                    • Most Votes


                    • Log ind

                    • Har du ikke en konto? Tilmeld

                    • Login or register to search.
                    Powered by NodeBB Contributors
                    Graciously hosted by data.coop
                    • First post
                      Last post
                    0
                    • Hjem
                    • Seneste
                    • Etiketter
                    • Populære
                    • Verden
                    • Bruger
                    • Grupper