1676
53
1677
21
1678
13
Send Messages Privately. No Cloud. No Trace. (chat.positive-intentions.com)
submitted 1 year ago* (last edited 1 year ago) by xoron@programming.dev to c/privacy@programming.dev

How it works: https://positive-intentions.com/docs/projects/chat

TLDR: im working on a p2p messaging webapp. webapps are generally not considered secure because of the nature of serving satics over the internet. this is correct, but not a limitation of this project. (selfhosting options: https://positive-intentions.com/blog/docker-ios-android-desktop).

as a webapp, i can provide the app with zero-installation and no-registration. the storage is local-only from your browser/device. so “the cloud”, but the cloud storage capacity is made up of your devices. this allows for things like p2p authentication: https://positive-intentions.com/blog/security-privacy-authentication.

Future: im aiming to create the most secure messaging app out there... (more than signal, simplex, etc). i know i have a have a long way to go to get there. the UI is fairly ugly for the average user, but i think the mechanics are working as expected. i think javascript is underrated in what you can do with it. i actively investigting improving the encryption approach further to align to how the signal protocol works (currently using the classic diffie-helman key-exchange).

Support: i would like to keep this project open source, but open-source funding is not working for me. i dont want your donations because it isnt sustainable for a long-term project. i have so far only experienced grant-funding rejections. i have no idea what im doing in trying to get funding for this project, so any support/advice is appriciated. in recognition of the project in its current state not able to get funding... (sorry) i will have to go close-source (which id like to avoid because it undemines several cybersecurity claims id like to make.)

1679
47

Presumably, there is some kind of way I can work around it, I saw something about clearing the cache because of stored failures of handshaking, but it seems like on the whole maybe it is time to start fuckin' with Peertube or something instead.

1680
32
submitted 1 year ago by throws_lemy to c/privacy@programming.dev

A group representing several major airlines alongside travel companies and airports is opposing a Senate bill that would require the Transportation Security Administration (TSA) to generally use manual ID verification at security checkpoints instead of facial recognition.

The bill, introduced by Sen. Jeff Merkley (D-Ore.), would broadly restrict TSA’s ability to use biometrics and facial recognition, carving out a few exemptions for the agency’s PreCheck and other Trusted Traveler programs. Passengers may still opt in to the use of facial recognition at the checkpoint.

In a letter Monday to Sens. Ted Cruz (R-Texas) and Maria Cantwell (D-Wash.), the air industry groups said the law was a “step backward” and that facial recognition technology made security screenings far more efficient.

1681
31

Their Matrix Chat post goes like this:

We have updated our Homeserver Terms and Privacy Policy. We strongly encourage you to read these documents in full, but for clarity these are some of the main changes:

  • Updated the minimum age requirements for use of the Matrix.org Homeserver to be 18 years old;
  • Introduced new measures to comply with our obligations under the Online Safety Act and the Digital Services Act;
  • Introduced new payment terms to support paid plans on the Matrix.org Homeserver;
  • Describe the new data processors to support paid plans on the Matrix.org Homeserver.

Each of the documents has a detailed version history which we encourage you to review. The updated Homeserver Terms and Privacy Policy take effect on ~~14 August~~ 7 August, 2025. These terms apply to you by continuing to use the homeserver after that date. If you have any questions please drop us an email to legal@matrix.org

Source: https://old.reddit.com/r/privacy/comments/1mdgbi4/matrix_homeserver_the_default_one_set_in_the_uk/

Couldn't find an official blog post from Matrix, if someone has one, feel free to share

1682
29
1683
27
1684
18
1685
21
1686
7

“(1) GENERAL DUTY.—In order to reduce the proliferation of the unlawful sale, distribution, or manufacture (as applicable) of counterfeit substances and certain controlled substances, a provider shall, as soon as reasonably possible after obtaining actual knowledge of any facts or circumstances described in paragraph (2), and in any event not later than 60 days after obtaining such knowledge, submit to the Attorney General a report containing—

“(A) the mailing address, telephone number, facsimile number, and electronic mailing address of, and individual point of contact for, such provider;

“(B) information described in subsection (c) concerning such facts or circumstances; and

“(C) for purposes of subsection (j), information indicating whether the facts or circumstances were discovered through content moderation conducted by a human or via a non-human method, including use of an algorithm, machine learning, or other means.

1687
56
1688
39
1689
9
1690
35
1691
13

Is there a massive difference between the two? Anything I should be wary of with either of them before I use it? I'm definitely privacy focused and have been trying out both but have been wondering if Vivaldi with uBlock Origin serves my purpose just as well as LibreWolf would.

1692
29
1693
146
1694
18

About the Online Safety Act in the UK and the Digital Services Act in Europe

1695
45
1696
66

... Who would have thought?

1697
140

Taken from the readme of the app on github:

The current release provides only basic functionality, with several key features to be introduced in future versions, including:

App and device verification based on Google Play Integrity API and Apple App Attestation

Additional issuance methods beyond the currently implemented eID based method.

These planned features align with the requirements and methods described in the Age Verification Profile.

There is an issue opened to remove this as it's basically telling us that to verify our age in the EU an American corporation has the last word, making it not only a privacy nightmare but a de-facto monopoly on the phone market that will leave out of the verification checks even the fairphone (european) with /e/os.

1698
26

cross-posted from: https://infosec.pub/post/32096847

In the last days I spent a disproportionate amount deleting old accounts I found in my password manager, and mostly because so many companies - despite the GDPR - have rudimentary, manually when not completely nonexistent processes to delete your data.

In this post I describe my process going through about 100 old accounts and trying to delete them all, including a top 10 for the weirdest, funniest or most interesting cases I encountered while doing so.

1699
27
1700
31
view more: ‹ prev next ›

Privacy

5093 readers
23 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 3 years ago
MODERATORS