JB Carroll reshared this.
JB Carroll reshared this.
reshared this
JB Carroll reshared this.
Same story different day
Susan ✶✶✶✶ likes this.
JB Carroll reshared this.
Guide on using remote attestation in a way that's compatible with GrapheneOS.GrapheneOS
Guide on using remote attestation in a way that's compatible with GrapheneOS.GrapheneOS
@Baffling7384 It will get hidden and the developers will never see it. It's unclear if it will even count as a rating.
We're pointing it out so that people don't try to link our guide in a review and end up with their review not helping.
Is there a list for banking apps which reliable work with GraphenOS?
(Background: I'm thinking about to change my bank, this might be one criteria)
Maintained Compatibility List for International Banking Apps This list includes banking apps that have been tested, submitted, reviewed, and verified as compatible.akc3n, Tommy, spring-onion (PrivSec - A practical approach to Privacy and Security)
@sparklepanic Yes, that's caused by the app marking their Play Store listing as requiring the Play Integrity API with the device or strong integrity level. The app may not actually require it and may work without it if installed from elsewhere. However, the app may check install location and enforce installing it from the Play Store.
If they properly implement the Play Integrity API, their services will check that the app passes it to use the services. Many apps are missing doing this though.
Im convinced. No more apps. Got it
If your website doesn't work, I'm not interested in using your shit.
JB Carroll likes this.
reshared this
JB Carroll reshared this.
Just gave a talk on the project I've been working for six months: Start Your Own Internet Resiliency Club
Short version: collect a group of networking experts in the same city, buy them all LoRa radios and power banks, install Meshtastic, and pick a channel to communicate on. If you lose all power and communications, you can communicate over LoRa to bootstrap the recovery of the real internet
ripe90.ripe.net/programme/meet…
A RIPE Meeting is a five-day event where Internet Service Providers (ISPs), network operators and other interested parties from all over the world gather.ripe90.ripe.net
JB Carroll reshared this.
The web page with the quick start guide is here:
we've explored this, but it seems like if you're in a relatively hilly area like we are, the signal propagates so poorly LoRa has not enough range to be meaningfully usable
Amsterdam is pretty flat, right?
JB Carroll reshared this.
"So, when we first hear about the Insurrection Act, it may trigger our alarmism. But better to face it now, before it comes, than learn about it on-the-fly."
wagingnonviolence.org/2025/04/…
With the Insurrection Act looming, now is the time to learn how it might unfold and the strategic ways to respond.Daniel Hunter (Waging Nonviolence)
JB Carroll reshared this.
My wife told me to stop singing Wonderwall.
I said maybe.
reshared this
JB Carroll reshared this.
reshared this
JB Carroll reshared this.
JB Carroll reshared this.
reshared this
JB Carroll reshared this.
JB Carroll reshared this.
reshared this
JB Carroll reshared this.
Signal provides:
- Excellent protection against third party interception of communications (wiretapping).
- Limited protection against compromised (hacked) or lost devices
- No protection against certain common usage mistakes (accidentally including a reporter in your large group war planning chat).
reshared this
JB Carroll reshared this.
If you look at the systems that are supposed to be used for classified communications, the underlying cryptography isn’t particularly different from Signal (the AES cipher can be used to protect classified material). That’s not what failed here.
The difference is that systems like Signal are designed to *facilitate* communication with anyone. Classified systems are designed to *limit* communication to authorized recipients.
Both are sensible for their respective - very different - purposes.
my fam straight up refused to abandon Whatsapp.
Reason: meh… it’s just easier
My anti-facist rants are falling on complacent ears. So I’m blissfully out of the loop on family discussions and photos. 🤷🏻♂️
"Signal" was Hitler's magazine published by the Wehrmacht of Nazi Germany from 1940. Recently Putin renamed his death squads Africa Corps same as the Nazi killers. Historical references names and dates are a favorite of the wanted war criminal Putin.
I hope the same name for "Signal" is just a coincidence.
Sadly, there is no defense against a classic PEBKAC attack.
(Problem Exists Between Keyboard And Chair)
Matt Blaze reminds us that Signal provides: "No protection against certain common usage mistakes (accidentally including a reporter in your large group war planning chat)." -- @mattblaze
Next minute:
"White House inadvertently texted top-secret Yemen war plans to journalist
In extraordinary blunder top Trump cabinet members added Atlantic editor to chat discussing strikes on Houthis"
@jqheywood
A totally preventable PEBKAC* security incident.
* Problem Exists Between Keyboard And Chair.
🧐
Where are Signal's servers based, now again? What is Signal's legal jurisdiction, now again?
I'm grateful to Signal for keeping the family conversations private, like strategizing on where we can buy eggs.
(Not even kidding on that, we've used Signal to compare egg prices while shopping)
reshared this
JB Carroll reshared this.
The fatal flaw SpaceX can't overcome.Will Lockett (Planet Earth & Beyond)
reshared this
JB Carroll reshared this.
DOGE Staffer Known as 'Big Balls' Reportedly the Grandkid of a KGB Spy gizmodo.com/doge-staffer-known…
"THESE 'EXPERTS' LEFT THEIR DATABASE OPEN."Jason Koebler (404 Media)
reshared this
JB Carroll reshared this.
You haven't been following the downfall of Twitter, have you ?
Or those dumpster fires that are the SSybertruck an Teska Semi, right?
Or how he got his ass fired from PayPall because he wanted to use Windows Server instead of Linux to run the service?
Elons incompetence has been showing for a while.
We stay strong against hate and hatred, and in response to the recent abuse campaign on our platform, we have renewed our commitment to fight for a better world. We apologize to everyone who was greeted with an abusive message this morning.
Read about the recent incident and our position on our blog: blog.codeberg.org/we-stay-stro…
Thanks to all your kind words of support, this is much appreciated. #StaySafe
#HateOnline #Hate #RightwingTrolls #rightwingExtremists
Codeberg is currently suffering from hate campaigns due to far-right forces,...blog.codeberg.org
Hypolite Petovan likes this.
reshared this
josh and JB Carroll reshared this.
If you work in government and are asked to remove content from websites (as a result of executive orders), please use the HTTP status code 451 instead of 404.
451 is the correct status code to use for these cases, and you'll be doing the rest of the country a service by using it.
Addendum: you should also include a Link header with the link relation "blocked-by" that "Identifies the entity that blocks access to a resource following receipt of a legal demand."
JB Carroll reshared this.
I just noticed the Monty Python joke @timbray managed to include in that RFC. 🤣
Thank you, Tim!
wait but you mean anyone maintaining a website of a government agency?
Or do you mean people responsible for implementing govt-mandated blocking of 3rd party web content?
If the latter, I'd think the people who do that work for ISPs, not governments?
reading these RFCs makes me realise how precious the internet is.
I yearn for a world where we can all be this professional and unhinged at the same time, connecting our worlds through hypertext and without JavaScript tracking popups.
"Legal demand"
Ha!
"DO IT OR LOSE YOUR JOB!"
Or more like it it's one of Musk Muppets who's got the passwords.
Why would this be different from other directives?
This seems to indicate the information was legally a problem, for example false and misleading.
HTTP status code 451:
Unavailable for Legal Reasons
HTTP status code 404:
Does not exist, has moved or is broken
HTTP Cat for status 451 Unavailable For Legal Reasonshttp.cat
This is mostly unnecessary hairsplitting, but I think it could be argued that semantically 451 is the correct code when the content is not removed but is blocked for YOU but not necessarily for everybody else (using geolocation or something else). I think that's why it's a 4xx client error.
So, if the pages are made unavailable for everybody (in other words, removed), I would say 404 is the correct code. Do I actually care? Absolutely not xD
While I appreciate the cleverness of this idea, we need to do more.
If you're being forced to remove content from websites, please consider archiving the site yourself first.
Relatedly, here's a six minute video about Rene Carmille, a French archivist who foiled Nazi attempts to identity Jewish people:
youtube.com/watch?v=tOEFO1kU8r…
Based on the extraordinary career of Rene Carmille, history's first known computer hacker. Much of the Vichy bureaucracy, including the operation of the deat...YouTube
And change the text to read:
<head><title>Unavailable For Illegal Reasons
Sensitive content
Sensitive content
Sensitive content
True: "you'll be doing the rest of the country a service by using it"
Also true, most likely: "you'll be doing the rest of the world a service by using it"
rfc-editor.org/rfc/rfc7725.htm…
5. Security Considerations
Clients cannot rely upon the use of the 451 status code. It is possible that certain legal authorities might wish to avoid transparency, and not only demand the restriction of access to certain resources, but also avoid disclosing that the demand was made.
Every 4 years, a team of libraries & research organizations work together to preserve material from U.S. government websites during the transition of administrations. 🗳️
Get the latest on the 2024/2025 End of Term Web Archive @eotarchive ➡️ blog.archive.org/2025/02/06/up…
JB Carroll reshared this.
Starting to get the itch to re-do my server, as this is the year Ubuntu 20.04 LTS loses support. Was thinking TrueNAS but wanted a little more freedom with lower ports. Now thinking about using #ZFSBootMenu on Alpine as a host for converting most everything to #docker :
docs.zfsbootmenu.org/en/v3.0.x…
Then make a few zpools for different benefits for my nextcloud docks and the other services I use...
Now not to get tempted with getting a refurb DL580 G9. 😅
Brian Ó likes this.
reshared this
Tech Cyborg and Paul 🐧 reshared this.
JB Carroll likes this.
reshared this
JB Carroll reshared this.
Anyway, if you also want to be cool and help in archiving the US government, head on over to the Archive Team wiki at:
You'll need the technical ability to be able to install VirtualBox or Docker and run an appliance/container.
You can also help archive other things, not just the US gov. There's a lot of the web that's at risk.
On the little server I have running here at home, I'm now helping @internetarchive back up US Government websites and data.
You can help, too:
1. Download and run the ArchiveTeam Warrior
2. Set the selected project to "usgovernment" (or select US Government from the available projects in the web interface)
I'm running Warrior as a container with podman, but there are various other ways to run it.
More details at wiki.archiveteam.org/
reshared this
JB Carroll reshared this.
This leader board has grown significantly since I posted. That's probably not from my influence, but if so, thank you for helping!
Even if you only turn on the #ArchiveTeamWarrior for a little while and let it process just a few hundred or a few thousand items, you're helping out!
ooh this sounds like my kinda jam! 🤘
What if you’re like me and don’t have your own server though?
If you have a spare laptop or other device that you're okay with leaving on, they have a virtual machine that can be run on windows and linux. You just need to download the image and install virtual box and open the image in virtualbox. See under basic usage:
rewarp likes this.
reshared this
Ben Ramsey, rewarp and Scott the F is implicit Baxter reshared this.
JB Carroll likes this.
docker-compose up -d
, and allowed the appropriate ports on the yaml file through ufw. Looks like it's scanning NIH now. 😎 Probably the easiest deployment I've ever run!
reshared this
JB Carroll reshared this.
Noam writes likes this.
Rich Stein (he/him) reshared this.
A guide to using Signal for government workers a.wholelottanothing.org/a-guid…A guide to using Signal for government workers
🔒Editor's note: A friend of mine works in the federal government and wrote a guide for their fellow federal workers on how to use Signal.Matthew Haughey (A Whole Lotta Nothing)
Rich Stein (he/him) reshared this.
WASHINGTON—In an effort to assuage any fears over the constitutionality of the Trump administration’s flurry of executive actions, a D.C.The Onion Staff (The Onion)
JB Carroll reshared this.
Thought I'd write an #introduction for all those #newhere from the Musk exodus:
I'm an analytical chemist. I've hosted my own #Friendica node (instance) at my home since 2018, shortly after the Cambridge Analytica scandal. From there, I got bit by the #selfhosting bug and am now hosting my own #opensource replacements for many FAANG services.
Welcome all to the #fediverse ! If you are thinking about self-hosting and have questions, would be happy to help as able!
#introductions
like this
pal, darkphoenix, glitchy edition, aguragorn, Steven Brady, Susan ✶✶✶✶, Garry Knight, Guy Geens, CF 🇺🇦, helladeboo and STORMZ OV KREATION ⚡🌎⚡ like this.
reshared this
Steven Brady and Ed Winchester reshared this.
√-ʇoɾəuɐnɾ 🍜🦄
in reply to The Oatmeal • • •*(Warning: does not work^ at night, so get your kicks—shutter clicks?—while you can!)
^(Well, not without batteries. But then you’re getting devices for self-illumination…)