Tootfinder

Opt-in global Mastodon full text search. Join the index!

@ripienaar@devco.social
2026-01-27 07:52:47

One to keep an eye on. it.slashdot.org/story/26/01/27<…

@a@paperbay.org
2025-12-28 07:54:18

I’m looking at age for many times especially to replace OpenPGP. They did a new release and for encryption at rest, it’s indeed a good replacement.
But how to integrate it with email encryption ? They recently did a keyserver words.filippo.io/keyserver-tlo and releas…

@aral@mastodon.ar.al
2026-01-29 09:10:28

Rule of thumb: End-to-end encryption is meaningless unless you know and control exactly who the ends are. (Let’s call this the Waltz principle.)
Same goes unless the context your encrypted messenger is running in is secure. Signal can encrypt your messages all day long but you’re still screwed if the custom keyboard app you installed on your phone is sending them off to someone else before they even reach Signal.

@tinoeberl@mastodon.online
2026-01-26 16:17:26

‼️ Wer Windows 11 mit einem Online-#Microsoft-Konto nutzt, speichert seine #BitLocker-Schlüssel automatisch in der #Cloud.
Diese können bei einem rechtlichen Ersuchen an das

@kubikpixel@chaos.social
2026-01-24 14:41:01

»Microsoft confirms it will give the FBI your Windows PC data encryption #key if asked—you can thank Windows 11's forced online accounts for that:
#Windows 11's online Microsoft Account requirement means your #PC

@alejandrobdn@social.linux.pizza
2026-01-23 21:29:14

Microsoft gave FBI a set of BitLocker encryption keys to unlock suspects’ laptops: Reports techcrunch.com/2026/01/23/micr<…

@migueldeicaza@mastodon.social
2026-01-24 03:32:59

Turns out that Microsoft's BitLocker security for the data stored on your hard drive is just a placebo.
Might as well give your password to everyone:
techcrunch.com/2026/01/23/micr

Microsoft provided the FBI with the recovery keys to unlock encrypted data on the hard drives of three laptops as part of a federal investigation, Forbes reported on Friday.
Many modern Windows computers rely on full-disk encryption, called #BitLocker, which is enabled by default.
This type of technology should prevent anyone except the device owner from accessing the data if the computer is …

@grahamperrin@bsd.cafe
2025-11-27 06:49:01

@… I should probably change my vote, but I'll stick with first choice, which involved root-on-ZFS.
That's not particularly neckbeardy, but then it took more than six months for me to notice that I also had OpenZFS-native encryption. A hidden beardy quality …
@…

@Techmeme@techhub.social
2025-11-15 00:05:53

X replaces DMs with Chat, a new messaging system that it says is E2EE, supports file sharing, video calling, and more, rolling out first to iOS and the web (Karissa Bell/Engadget)
engadget.com/social-media/x-is

@grumpybozo@toad.social
2026-01-25 23:18:58

The truth is, I’ve never trusted FileVault or really any whole-disk encryption.
I have a couple of FreeBSD machines using geli but not on their boot disk (is that even a thing?) and I’ve never been willing to jump into FileVault because it seems to have had a steady stream of “Oh, well, hope you have a backup” problems.
#Sysadminnery

@thesaigoneer@social.linux.pizza
2025-12-26 08:32:30

@… : Just a quick shoutout and thank you!
Your tutorial on setting up VoidLinux, on ZFS, with encrypted swap worked great. Followed all steps, and everything (including hibernate and restore) works exactly as expected.
Learned some things along the way (encryption, zfsbootmgr) and, most of all, had a lot of fun doing it ;-)
Tomorrow I'll be…

@adamhotep@infosec.exchange
2025-12-28 04:40:27

RE: infosec.exchange/@oots/1157940
Reminder: Bluetooth isn't secure, even with its encryption.

@chpietsch@fedifreu.de
2026-01-22 20:50:49

Telnet is a remote login protocol that became obsolete in 1995 when SSH became available because SSH offers transport encryption while telnet does not.
Those who kept a telnetd running for whatever reason (and did not hide it behind a firewall) have had a root backdoor for the last ten years.
The telnetd server invokes /usr/bin/login (normally running as root) passing the value of the USE…

@matematico314@social.linux.pizza
2026-01-24 23:07:39

#LB Mas quando eu digo que não tenho confiança em nenhum software de código fechado, me chamam de neurótico...
mastodon.sdf.org/@dlakelan/115

@boris@cosocial.ca
2026-01-22 17:31:57

“The core idea is that your conversations with an AI assistant should be as private as your conversations with a person. Not because you’re doing something wrong, but because privacy is what lets you think freely.”
Moxie Marlinspike, Confessions to a data lake confer.to/blog/2025/12/confess

@metacurity@infosec.exchange
2025-11-14 14:02:08

Before you head out for the weekend, check out today's Metacurity for the most critical infosec developments you should know, including
--Chinese state hackers used Anthropic to automate cyber intrusions,
--UK MoD knew of Excel's security risks before Afghan data leak,
--NHS investigates Clop's attack claims,
--ASUS patches DSL router critical flaws,
--DoorDash reveals October security incident,
--US feds warn of Akira's expanded encryption …

@nobodyinperson@fosstodon.org
2026-01-16 12:06:55

Great, ecryptfs was dropped from nixpkgs, because apparently it wasn't updated in 10 years 😑
ecrypts was always my go-to solution for encrypting only my home directory, if full disk encryption is not available.
So what does one use now for homedir encryption?
github.com/NixOS/nixpkgs/pull/

@pre@boing.world
2025-11-23 12:15:10
Content warning: re: bitcoin conference report

Not sure what the difference between a panel and a"fireside chat" is. There is no fire.
But here's a fireside chat on what nostr is.
Nostr is freedom for Identity. Accounts without hosts. Publishing without publidhers. Censorship resistance without platforms deciding who gets to say what.
It's not a silo in which you can be tapped as the service enshitifies, since it's a protocol with accounts you control, you can't switch clients or relays without loosing social graph or contacts.
Nostr is notes and Other Stuff, what other stuff? the panel is working on an audiobook publishing system with perhaps a required payment and affiliate revenue share. E-commerce, video publishing, zap stream for live video with zap payments.
Onboarding can be tricky with private key management needing to be understood and such a range of options of clients and what relays are. Can we make it easier?
Perhaps by abstracting away the fact it's nostr at all. Devine users don't even know they are using nostr. But this robs users of the understanding they may need to move clients or use the same account for video and notes, say.
Perhaps by making a private messagnger, the panel thinks people are used to using multiple messenger apps. Though I find they hate that, and that's why they refuse to install signal. They feel they don't need it since they already have WhatsApp with a bigger network.
In the end it's education. We have to teach literacy so people can read and write, we have to teach public keys encryption so people can do so securely.
#bitfest #nostr

@Techmeme@techhub.social
2026-01-24 17:25:51

Microsoft confirms it does provide BitLocker recovery keys for encrypted data if it receives a valid legal order and the user has stored the keys on its servers (Thomas Brewster/Forbes)
forbes.com/sites/thomasbrewste

@mgorny@pol.social
2025-11-21 16:46:36

Dziś dowiedziałem się, że ludzie na serio przetłumaczyli "end-to-end encryption" jako "szyfrowanie od końca do końca" 🤦.

@publicvoit@graz.social
2026-01-23 16:48:06

#Microsoft hands out your #Windows #Bitlocker disk #encryption recovery key if

@michabbb@social.vivaldi.net
2025-11-15 18:39:45

🔬 Seeing "post-quantum key exchange" warnings in your SSH sessions?
Here's what it actually means and whether you should worry about it.
Modern #SSH connections use #encryption that could theoretically be broken by future

@adulau@infosec.exchange
2025-12-05 05:29:22

ML-KEM Mythbusting
"There have been some recent concerns about ML-KEM, NIST’s standard for encryption with Post-Quantum Cryptography, related standards of the IETF, and lots of conspiracy theories about malicious actors subverting the standardization process. "
#pqc #pqcrypto

@thesaigoneer@social.linux.pizza
2025-12-25 10:57:01

Checking out, before cooking, that guide by @… .Installing VoidLinux, zfs, encryption and hibernation. Gonna follow all those steps meticioulsy., but not today.
It is no surprise ssh works ootb on Slackware.
Pots and pans are calling, happy xmas all!!

One of the world’s premier security organizations has canceled the results of its annual leadership election
-- after an official lost an encryption key needed to unlock results stored in a verifiable and privacy-preserving voting system.
The International Association of Cryptologic Research (IACR) said Friday that the votes were submitted and tallied using Helios,
an open source voting system that uses peer-reviewed cryptography to cast and count votes in a verifiable, con…

@stf@chaos.social
2026-01-06 13:05:38

#Applied #cryptography cannot solve a #security problem. It can only convert a security problem into a key-management problem.
Corollary: If you aren’t actually solving the key-management problem, yo…

@piger@mastodon.social
2026-01-20 21:40:58

ahh, the good old times before ssh and its smug encryption
openwall.com/lists/oss-securit

@pre@boing.world
2025-11-21 15:17:31

Black Coffee from lnbits likes internet of things, but doesn't like the way it tends to work with centralised servers and spying companies running them.
But what if your coffee pot and lights and smart plugs were nostr instead?
Nobody can cut your machine off, it has it's own keys and encryption, you could even ruin your own relay to talk to it instead of using public relays.
Remote control without having to expose the home network.
You could even make it require zaps and so make a vending machine.
Demonstration by sending lightning requests to the coffee pot on stage works better than the mikes that have been feeding back this afternoon 😆
#nostr #nostrshire #internetOfThings

@johl@mastodon.xyz
2025-12-08 14:01:28

I really wish #Mastodon had end to end encryption for DMs.

@lil5@social.linux.pizza
2025-11-16 16:50:40

#telegram is so shit, Ads, unable to block unknown invites, shit encryption if any.
And the foss community is just bending over backwards.
I have a #matrix server I’m happy to share with anyone who wants to move off of telegram.

Ad in telegram
@samueljohn@mastodon.world
2026-01-19 06:15:52

RE: mastodon.social/@404mediaco/11
This is why we should continue to fight for our right on privacy, encryption, and don't give away all our data to big tech. Germany should not buy Palantir!

@rene_mobile@infosec.exchange
2025-12-09 13:04:44

The list of members for the newly starting "Expert Group for a Technology Roadmap on Encryption (E04005)" is now online: ec.europa.eu/transparency/expe

@Techmeme@techhub.social
2026-01-21 05:05:50

Signal's Meredith Whittaker says deeper integration of AI agents into devices is "perilous" for encryption, since agents need access to lots of data across apps (Shona Ghosh/Bloomberg)
bloomberg.com/news/articles/20

@aral@mastodon.ar.al
2025-12-14 08:57:11

“EU Revives Plan for Year-Long Data Retention Across Digital Services, Including Encrypted Apps … Officials insist they do not intend to compromise encryption or read private messages. What they want is the so-called metadata: who contacted whom, from where, at what time, and through which service.” –

@metacurity@infosec.exchange
2025-11-18 13:37:01

Even as much of the internet is inaccessible right now, Metacurity appears unaffected. So check out today's issue for the most critical infosec developments you should know, including
--CISA says it will rebuild with more staff in 2026 to rectify cuts in 2025,
--Microsoft’s Azure cloud computing service was hit with 15.7 Tbps DDoS attack,
--Russian telecom Protei was hacked and site defaced,
--Companies warn of inflexibility if UK bans ransom payments,
--A cr…

@joe@toot.works
2026-01-08 01:52:48

... why?
"State file encryption and hardware attestation keys are no longer enabled by default."
#TailScale

@hanno@mastodon.social
2026-01-05 12:17:31

My motivation to get into PGP fights these days is very limited, but, well, sometimes I can't escape the "someone is wrong on the Internet" feeling.
The author of @… still does not understand what "Authenticated Encryption" means ("still", because I've seen these discussions back in the efail days). It is a pretty central conce…

@fgraver@hcommons.social
2025-11-11 19:51:36

Very strange thing happened with my files on the tab.digital @…… I noticed today they have been spontaneously encrypted; apparently not by some cryptoransomer, but a known bug that has plagued random users for at least two years. All the text files, regardless of file type, now start with the header HBEGIN:oc_encryption_module:OC_DEFAULT_MODULE:cipher:AES-256-CT…

@grumpybozo@toad.social
2025-12-08 16:20:57

Or one could use LibreOffice or Apache OpenOffice and not be dependent on some distant service provider.
Online office suites confuse me. It’s unclear what *modern* problem they address. Sharing files is a solved problem. Common data formats exist. mastodon.social/@DevOpsPink/11

@teledyn@mstdn.ca
2025-12-02 06:23:00
Content warning: re: intense Gnome frustrations no one should be forced to read

I have a theory: in my travels through various docs on various components I came across a strategy some apps use where they salt the encryption with the hash your current password. If any of these apps did that, moving .local files to the new machine would fail unlocking things because the passwords are different.

@michabbb@social.vivaldi.net
2025-12-11 22:03:21

🔐 AES encryption & space-saving compression protect your data from unauthorized access
💿 Creates rescue disk & backup images in VHD/VHDX format - opens
directly in #Windows Explorer
🛡️ Protects against data loss from viruses, hackers or defective hard drives - suitable for beginners
🌐

@Techmeme@techhub.social
2025-10-30 13:10:53

WhatsApp launches passkey-encrypted backups for iOS and Android, letting users encrypt their stored message history using their face, fingerprint, or a code (Jess Weatherbed/The Verge)
theverge.com/news/809842/whats

@Techmeme@techhub.social
2025-11-14 11:10:46

Meta plans to launch WhatsApp third-party app integration in Europe "over the coming months" as required by the DMA, starting with BirdyChat and Haiket (Thomas Ricker/The Verge)
theverge.com/news/820858/whats

@thesaigoneer@social.linux.pizza
2025-12-16 12:13:17

Got home early today. Of course I had to geek out 🤣 KDE is under the bus, so I reached for VoidLinux (to add dwl to it later). And hey, other distro's: look at their documentation. Can be brief, but It Just Works. Diligently followed the disk encryption setup, very well written and laid out. A pleasure, I love runit.And VoidLinux, another great distribution.
#voidlinux

404 Media speaks with @meredithmeredith.bsky.social,
the president of the Signal Foundation to talk all about the state of Signal today,
the threat of AI to end-to-end encryption,
what backdoors actually look like, and much more.
When did you start using Signal?
Listen now:
youtu.be…

@metacurity@infosec.exchange
2026-01-01 21:13:38

Based on another report I just read from Iran's PressTV (state-sponsored service with an expired encryption cert today), this sounds like a giant DDoS attack.
Iran says repelled ‘one of world’s most complex’ cyberattacks on national infrastructure

@Techmeme@techhub.social
2026-01-13 17:45:51

A look at Confer, an open-source AI assistant project from Signal creator Moxie Marlinspike that is designed to provide end-to-end encryption for AI chats (Dan Goodin/Ars Technica)
arstechnica.com/security/2026/

@pre@boing.world
2025-12-06 15:09:49

Future Plans:
I have like ten years of data in my log, converted from those prior prototypes. I will be adding ways to more usefully compare and analyse data going this far back.
It could maybe use a milestone function, to track singular events which don't take actual time so don't spread on the grid. Snack tracking and the like.
It could likely use a flashcard system, with spaced repetition to review the flashcards, for better memory and recall.
Synching between devices might be nice, and lots will suggest doing that through Nostr, but Nostr is a bit public. Would need an encryption layer. Do nostr relays want to relay encrypted data from one user to themselves I suspect Veilid ( veilid.com/ ) would be a better option. The "no servers" ethos probably includes nostr relays.
Mostly I plan just more and better ways to view the ten years and growing of data I already have. And to do some other things for a bit so my log isn't just full of "Vibecoding Exocortex" like it is the last two weeks 😉

Google is rolling out Android RCS Archival on Pixel
and other Android phones,
allowing employers to intercept and archive RCS chats on work-managed devices.
In simpler terms, your employer will now be able to read your RCS chats in Google Messages, despite end-to-end encryption.”

@Techmeme@techhub.social
2025-12-06 11:36:11

A look at Phreeli, a privacy-focused phone carrier that lets users sign up with only a ZIP code and uses an encryption system based on "zero-knowledge proofs" (Andy Greenberg/Wired)
wired.com/story/new-anonymous-