Expert developer, Buddhist

  • 0 Posts
  • 20 Comments
Joined 1 year ago
cake
Cake day: June 21st, 2023

help-circle








  • Lung@lemmy.worldtoPrivacy@lemmy.worldWhat's the best messaging platform?
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    2
    ·
    3 months ago

    Ok, my bad, it’s not mostly funded now (though funding isn’t totally clear for all of its history) but we do know it was handed 3m near the start by Open Technology Fund which an arm of the US Agency for Global Media which is the US govt, and at best has the mission of pushing us news ideology globally. Ex they did Radio Free Asia after tianamen square, and guess what, that was conceptualized by none other than senator Joe Biden

    Yeah the encryption is probably okay, and I use it daily, but these backdoors are often hella sneaky and we know that the US govt loves doing shit like that if they can


  • Lung@lemmy.worldtoPrivacy@lemmy.worldWhat's the best messaging platform?
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    4
    ·
    3 months ago

    It’s basically just Signal if you want ease of use + good security. Not totally 100% since it is funded almost exclusively by the US govt, and I can’t be sure if the encryption is not backdoored, but it’s the best bet we got. IRC: not secure, XMPP / Matrix maybe ok but hard to use for most, Telegram wouldn’t really trust though in theory has e2e, Whatsapp and Google world stuff even less faith. Honestly none of it is super great, but Signal has the best balance imo. There’s also some crypto based messaging stuff that’s used on darknets but that’s the clunkiest

    I think the only fully guaranteed method is having a pre shared one time pad encryption key between two parties & then send the encrypted text however you want (ex post on a far corner of a mostly dead online forum or Reddit). That doesn’t have any fancy algos that may be bugged, or private/public key stuff




  • Nah, the OS has proprietary overlays that vendors put in there. And it’s not like you’re reviewing and compiling your own software - you’re dependent on your provider to be honest with the software they actually installed. But factually you have no idea if the android phone you purchased has been modified. And Android itself is so huge that backdoors can be sneaky. We have already caught several instances of attempted backdoors in Linux - but there’s always the fear we didn’t find them all

    If this all sounds way too paranoid, then review Snowden leaks




  • You bet your ass they can. Since when has Facebook taken anybody’s privacy seriously? And you remember all the Snowden leaks? Like how AT&T has been a government apparatus for spying for decades? Or how about the way that the USA taps under sea cables to monitor data, causing China to build totally parallel backbone infrastructure

    The better question is whether Signal, despite being open source, is actually secure. It’s very plausible that the govt has backdoors somewhere, for either encryption, the OS, the programming language, the app store, or some random dependency lib

    The answer is yes, the US government spies on everything, and has a complete profile of everyone


  • Well, I’m pretty pissed, and it feels like Google, probably the biggest Internet company, has really gone insane. I mean, a web company stops selling domains? Why? It makes total sense with their Cloud offerings and other stuff like managed Gmail/apps

    Anyway I have like a dozen domains there so I’m just going to hang in for the rollover and hopefully I don’t need to do anything. Ultimately, I use this stuff like 2ce a year so it doesn’t really matter who holds the domains for me



  • I manage like 200 servers in Google cloud k8s but I don’t think I’d do that for home use. The core purpose is to manage multiple servers and assign processes between them, auto scaling, cluster internal network - running docker containers for single instance apps for personal use doesn’t require this kind of complexity

    My NAS software has a docker thing just built into it. I can upload or specify a package and it just runs it on the local hardware. If you have a Linux shell, I guess all you really have to do is run dockerd to start the daemon, make sure your network config allows connections, and upload your docker containers to it for running