mathstodon.xyz is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Mastodon instance for maths people. We have LaTeX rendering in the web interface!

Server stats:

3K
active users

#OnionServices

1 post1 participant0 posts today
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mastodon.nl/@koenvh" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>koenvh</span></a></span> <a href="https://infosec.space/tags/FunFact" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FunFact</span></a>: <em>THIS</em> is actually real when it comes to <a href="https://infosec.space/tags/OnionServices" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OnionServices</span></a> on <a href="https://infosec.space/tags/Tor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tor</span></a> / <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>torproject</span></a></span> despite (or rather because of) having a self-routing and self-administrating, self-authentificating namespace utilizing <a href="https://infosec.space/tags/Pubkeys" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Pubkeys</span></a> for addressing.</p><ul><li><span class="h-card" translate="no"><a href="https://alecmuffett.com/article/author/alecm" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>alecm</span></a></span> / <span class="h-card" translate="no"><a href="https://mastodon.social/@alecmuffett" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>alecmuffett</span></a></span> actually has <a href="https://github.com/alecmuffett/real-world-onion-sites/blob/master/master.csv" rel="nofollow noopener noreferrer" target="_blank">a pretty substantial list</a>.</li></ul><p><a href="https://github.com/greyhat-academy/lists.d/blob/main/onion.domains.list.tsv" rel="nofollow noopener noreferrer" target="_blank">Mine</a> merely covers a few <a href="https://infosec.space/tags/BonaFide" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BonaFide</span></a> ones and there are literal <a href="https://infosec.space/tags/scam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>scam</span></a> businesses when it comes to the kinds of sites I won't name nor list!</p>
SkotchY<p><span class="h-card" translate="no"><a href="https://pony.social/@cadey" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>cadey</span></a></span> My thoughts on <a href="https://ieji.de/tags/Anubis" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Anubis</span></a> after encountering it multiple times as a user:<br>* mascot is nice, creative and intuitive to understand<br>* as a user of tor it works! cloudflare and others reject me as a bot, but anubis left me through, thank you<br>* onion services do not require anubis protection, though, right? Since they have their own proof of work system integrated by default …<br><a href="https://blog.torproject.org/introducing-proof-of-work-defense-for-onion-services/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">blog.torproject.org/introducin</span><span class="invisible">g-proof-of-work-defense-for-onion-services/</span></a></p><p>… equi-x function based on what Tor uses?<br><a href="https://pony.social/@cadey/114236263848292147" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">pony.social/@cadey/11423626384</span><span class="invisible">8292147</span></a></p><p><a href="https://ieji.de/tags/OnionServices" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OnionServices</span></a> <a href="https://ieji.de/tags/tor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tor</span></a> <a href="https://ieji.de/tags/proofof" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>proofof</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mastodon.ar.al/@aral" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>aral</span></a></span> <span class="h-card" translate="no"><a href="https://ec.social-network.europa.eu/@EUCommission" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>EUCommission</span></a></span> <span class="h-card" translate="no"><a href="https://social.nlnet.nl/@nlnet" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>nlnet</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@letsencrypt" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>letsencrypt</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@cacert" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>cacert</span></a></span> not only that, I think we need self-governing namespaces similar to <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>torproject</span></a></span> <a href="https://infosec.space/tags/OnionServices" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OnionServices</span></a> (even tho they are prone to <a href="https://infosec.space/tags/typosquatting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>typosquatting</span></a>-esque <a href="https://infosec.space/tags/sibil" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sibil</span></a>/#EvilTwin-style <a href="https://infosec.space/tags/phishing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>phishing</span></a> attacks!)...</p>
Adam - K3CAN<p>Trying to understand how to host an <a href="https://social.k3can.us/tags/onion" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>onion</span></a> site. Can someone confirm if I'm understanding this correctly and maybe fill in a gap or two?</p><p>The <a href="https://social.k3can.us/tags/tor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tor</span></a> client runs on a server and (somehow) receives requests from the network. The tor client then sends those requests to a webserver (via IP:Port), where the server does its normal thing by checking the host requested and matching it to the appropriate virtual server block. The site is served by the webserver <em>back</em> the tor client, who in turn sends it back out over the tor network.</p><p>Is that right? What port does the tor client actually listen to for incoming requests (what would I need to allow in my firewall)? Do tor and the webserver have to run on the same machine, or can I run tor on my reverse proxy and have it point to a webserver on another machine like a standard http site? If I have multiple clearnet and onion sites on the same server, is there any risk of one exposing the other?</p><p><a href="https://social.k3can.us/tags/selfhost" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>selfhost</span></a> <a href="https://social.k3can.us/tags/onionservices" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>onionservices</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://toot.wales/@clubchonky" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>clubchonky</span></a></span> personally, I disagree to an extent.</p><p><span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>torproject</span></a></span> / <a href="https://infosec.space/tags/Tor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tor</span></a> is well battle-tested and combat-hardened and using <a href="https://infosec.space/tags/OnionServices" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OnionServices</span></a> works just fine, as none of the traffic leaves through <a href="https://infosec.space/tags/ExitNodes" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ExitNodes</span></a>...</p>
Kevin Karhan :verified:<p>Also friendly reminder for <a href="https://infosec.space/tags/developers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>developers</span></a> of <a href="https://infosec.space/tags/Apps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Apps</span></a> using <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>torproject</span></a></span> / <a href="https://infosec.space/tags/Tor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tor</span></a> and/or accessing <a href="https://infosec.space/tags/OnionServices" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OnionServices</span></a> using <span class="h-card" translate="no"><a href="https://social.librem.one/@guardianproject" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>guardianproject</span></a></span> / <a href="https://infosec.space/tags/Orbot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Orbot</span></a>:</p><ul><li>Set <a href="https://infosec.space/tags/DNS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DNS</span></a> to <code>localhost:5400</code> unless you want it to <a href="https://infosec.space/tags/leak" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>leak</span></a> the use of Tor.</li></ul><p>You may trust <span class="h-card" translate="no"><a href="https://mastodon.online/@mullvadnet" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>mullvadnet</span></a></span> but even they can't resolve <code>…onion</code> (and likely wouldn't <em>even if it was that simple</em>) because <a href="https://en.m.wikipedia.org/wiki/.onion" rel="nofollow noopener noreferrer" target="_blank"><em>that's how it works!</em></a></p>
Kevin Karhan :verified:<p>Seems like the <a href="https://infosec.space/tags/OnionService" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OnionService</span></a> for <code>jabber.ccc.de</code> @ <code>m2ylflyeak6i6o4hsfwcrfwcq2bbjxk6nf2rnmm7fu6qiuu3hybenzid.onion</code> is down.</p><ul><li>Can anyone else confirm?</li></ul><p>Cc: <span class="h-card" translate="no"><a href="https://anonsys.net/profile/ccc" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>ccc@anonsys.net</span></a></span> <span class="h-card" translate="no"><a href="https://social.bau-ha.us/@CCC" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>CCC@social.bau-ha.us</span></a></span> <span class="h-card" translate="no"><a href="https://chaos.social/@ccc" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>ccc@chaos.social</span></a></span> <span class="h-card" translate="no"><a href="https://chaos.social/@clubdiscordia" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>clubdiscordia</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>torproject</span></a></span> </p><p><a href="https://infosec.space/tags/DownForEveryoneOrJustMe" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DownForEveryoneOrJustMe</span></a> <a href="https://infosec.space/tags/DownDetector" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DownDetector</span></a> <a href="https://infosec.space/tags/DownDetection" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DownDetection</span></a> <a href="https://infosec.space/tags/Downtime" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Downtime</span></a> <a href="https://infosec.space/tags/Tor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tor</span></a> <a href="https://infosec.space/tags/OnionServices" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OnionServices</span></a> <a href="https://infosec.space/tags/CCC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CCC</span></a> <a href="https://infosec.space/tags/Jabber" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Jabber</span></a> <a href="https://infosec.space/tags/XMPP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>XMPP</span></a> <a href="https://infosec.space/tags/Chat" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Chat</span></a> <a href="https://infosec.space/tags/Onion" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Onion</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://sfba.social/@not2b" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>not2b</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@dangillmor" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>dangillmor</span></a></span> I mean, she's just a <a href="https://infosec.space/tags/cyberfacist" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cyberfacist</span></a> like <a href="https://infosec.space/tags/Zensursula" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Zensursula</span></a>, and the only correct way to deal with these <a href="https://infosec.space/tags/facists" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>facists</span></a> is to <em>"<a href="https://infosec.space/tags/EncryptHarder" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EncryptHarder</span></a>!"</em> (with <a href="https://infosec.space/tags/XMPP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>XMPP</span></a>+<a href="https://infosec.space/tags/OMEMO" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OMEMO</span></a> &amp; <a href="https://infosec.space/tags/PGP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PGP</span></a>/MIME) and tunnel everything through <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>torproject</span></a></span> / <a href="https://infosec.space/tags/Tor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tor</span></a> and setup <a href="https://infosec.space/tags/OnionServices" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OnionServices</span></a> for <em>everything</em>!</p><ul><li>Remember: <a href="https://infosec.space/tags/KYC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>KYC</span></a> <em>IS</em> THE <a href="https://infosec.space/tags/IllicitActivity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IllicitActivity</span></a> and this goes espechally for requring <a href="https://infosec.space/tags/PII" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PII</span></a> like <a href="https://infosec.space/tags/PhoneNumbers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PhoneNumbers</span></a>, <span class="h-card" translate="no"><a href="https://mastodon.world/@signalapp" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>signalapp</span></a></span> / <a href="https://infosec.space/tags/Signal" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Signal</span></a>!</li></ul>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://gruene.social/@max" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>max</span></a></span> <br>To <a href="https://gruene.social/@max/113872018769294131" rel="nofollow noopener noreferrer" target="_blank">quote you directly</a>:</p><blockquote><p>"[...] easy to use solutions that are at the same time private and secure. [...]"</p></blockquote><ul><li>The fact that <span class="h-card" translate="no"><a href="https://mastodon.world/@signalapp" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>signalapp</span></a></span> requires <a href="https://infosec.space/tags/PII" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PII</span></a> like a <a href="https://infosec.space/tags/PhoneNumber" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PhoneNumber</span></a> which more often than not <em>cannot be legally acquired anonymously</em> makes it not <a href="https://infosec.space/tags/private" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>private</span></a>. </li></ul><p>It is easier, faster, cheaper and overall simpler to get someone setup with <a href="https://infosec.space/tags/XMPP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>XMPP</span></a> + <a href="https://infosec.space/tags/OMEMO" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OMEMO</span></a> espechally if they don't have a <a href="https://infosec.space/tags/PhoneNumber" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PhoneNumber</span></a> and/or <a href="https://infosec.space/tags/ID" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ID</span></a> to acquire a <a href="https://infosec.space/tags/SIM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SIM</span></a>. </p><p>And if you go and say, <em>"Just buy a [insert country here] [e]SIM!"</em> and expect <a href="https://infosec.space/tags/TechIlliterates" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TechIlliterates</span></a> without a <a href="https://infosec.space/tags/CreditCard" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CreditCard</span></a>, <a href="https://infosec.space/tags/PayPal" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PayPal</span></a> or other means of <a href="https://infosec.space/tags/OnlinePayment" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OnlinePayment</span></a> to fiddle around with some <a href="https://infosec.space/tags/eSIM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>eSIM</span></a> if not having to get some <a href="https://infosec.space/tags/eSIMcard" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>eSIMcard</span></a> because they can only afford to maintain one SIM and can't spend triple-digits on a new devices then you <em>completely missed the point</em>!</p><ul><li>I can much faster and easier get TechIlliterates setup show them around - either in a <span class="h-card" translate="no"><a href="https://mastodon.earth/@cryptoparty" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>cryptoparty@mastodon.earth</span></a></span> / <span class="h-card" translate="no"><a href="https://chaos.social/@cryptoparty" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>cryptoparty@chaos.social</span></a></span> / <a href="https://infosec.space/tags/CryptoParty" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CryptoParty</span></a> - style <a href="https://infosec.space/tags/classroom" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>classroom</span></a> / <a href="https://infosec.space/tags/seminar" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>seminar</span></a> or 1:1 tutoring than I can <em>legally acquire and activate a new SIM in <a href="https://infosec.space/tags/Germany" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Germany</span></a></em> [since 07/2017]...</li></ul><p>It's not that I expect anyone to get <a href="https://infosec.space/tags/TechLiterate" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TechLiterate</span></a> within minutes, but similar to setting up a cordless DECT phone it's something one has to do once in 5 years and just have them put the password in a safe spot to retain...</p> <p>Point is that <a href="https://infosec.space/tags/Signal" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Signal</span></a> <a href="https://infosec.space/tags/WontFix" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WontFix</span></a> their setup and that was evidently clear even before <span class="h-card" translate="no"><a href="https://mastodon.world/@Mer__edith" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>Mer__edith</span></a></span> succeeded <a href="https://infosec.space/tags/MoxieMarlinspike" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>MoxieMarlinspike</span></a>: Their entire operation has a <em>distinct <a href="https://infosec.space/tags/CryptoAG" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CryptoAG</span></a> stench</em> as it's an <a href="https://infosec.space/tags/unsustainable" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>unsustainable</span></a> <a href="https://infosec.space/tags/VCmoneyBurning" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VCmoneyBurning</span></a> party!</p><ul><li><a href="https://infosec.space/tags/CloudAct" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CloudAct</span></a> and the <a href="https://infosec.space/tags/NOBUS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NOBUS</span></a> <a href="https://en.wikipedia.org/wiki/NOBUS#Criticism" rel="nofollow noopener noreferrer" target="_blank">hegemony</a> ain't something that just got executed now (neither was <a href="https://infosec.space/tags/GDPR" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GDPR</span></a> &amp; <a href="https://infosec.space/tags/BDSG" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BDSG</span></a>!)... </li></ul><p>A counterexample on how this could've been done are <a href="https://infosec.space/tags/Tor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tor</span></a>, <a href="https://infosec.space/tags/eMail" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>eMail</span></a> and other <em>truly <a href="https://infosec.space/tags/OpenSource" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenSource</span></a></em> as in <a href="https://infosec.space/tags/MultiVendor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>MultiVendor</span></a> &amp; <a href="https://infosec.space/tags/MultiProvider" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>MultiProvider</span></a> standards. </p><ul><li><p><em>NOTHING</em> compells Signal to <a href="https://en.wikipedia.org/wiki/Signal_(software)" rel="nofollow noopener noreferrer" target="_blank">demand PII</a>, run a <a href="https://infosec.space/tags/Shitcoin" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Shitcoin</span></a> <a href="https://infosec.space/tags/Scam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Scam</span></a> <a href="https://en.wikipedia.org/wiki/Signal_(software)#In-app_payments" rel="nofollow noopener noreferrer" target="_blank">aka.</a> <a href="https://infosec.space/tags/MobileCoin" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>MobileCoin</span></a> that even seasoned <a href="https://infosec.space/tags/TechLiterates" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TechLiterates</span></a> and <a href="https://infosec.space/tags/CryptoBros" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CryptoBros</span></a> <a href="https://www.youtube.com/watch?v=0DSGq9FQKU4" rel="nofollow noopener noreferrer" target="_blank">can't setup properly</a>, and in fact Signal using <a href="https://en.wikipedia.org/wiki/Signal_(software)#Controversial_use" rel="nofollow noopener noreferrer" target="_blank">phone numbers makes it trivial to discriminate against users and easier for them to identify them</a>!</p></li><li><p>If <a href="https://infosec.space/@kkarhan/113869305765533809" rel="nofollow noopener noreferrer" target="_blank">my reasoning</a> didn't resonate with you, then try helping i.e. undocumented migrants aka. <em>"<a href="https://infosec.space/tags/SansPapier" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SansPapier</span></a>|s"</em> to get setup with it without violating laws and/or ToS and/or needing an imported SIM which I'm shure most folks don't have on hand!</p></li></ul><p>Whereas it's trivial to get people setup on <a href="https://github.com/greyhat-academy/lists.d/blob/main/xmpp.servers.list.tsv" rel="nofollow noopener noreferrer" target="_blank">one of many XMPP servers I've personally tested</a>!</p><ul><li>Not to mention clients like <span class="h-card" translate="no"><a href="https://monocles.social/@monocles" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>monocles</span></a></span> / <a href="https://infosec.space/tags/monoclesChat" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>monoclesChat</span></a> and <span class="h-card" translate="no"><a href="https://fosstodon.org/@gajim" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>gajim</span></a></span> / <a href="https://infosec.space/tags/gajim" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>gajim</span></a> are way more user-friendly and unlike Signal can also work perfectly fine over <a href="https://infosec.space/tags/Tor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tor</span></a>, including <a href="https://infosec.space/tags/OnionServices" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OnionServices</span></a> as endpoints. </li></ul><p>AFAIK Signal doesn't even have an <a href="https://infosec.space/tags/OnionService" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OnionService</span></a> / <a href="https://en.wikipedia.org/wiki/.onion" rel="nofollow noopener noreferrer" target="_blank"><code>.onion</code></a> for their Website, much less any <a href="https://infosec.space/tags/API" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>API</span></a> enpoints to use it with!</p><ul><li>Them relying on <a href="https://infosec.space/tags/ClownFlare" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ClownFlare</span></a> is just something that makes them even <em>more <a href="https://infosec.space/tags/sus" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sus</span></a></em> as there is <em><a href="https://en.wikipedia.org/wiki/Cloudflare#Controversies" rel="nofollow noopener noreferrer" target="_blank">no legitimate reason</a></em> to use a <a href="https://infosec.space/tags/RogueISP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RogueISP</span></a> like that.</li></ul> <p>You're free to also provide evidence and supporting data to your arguments, rather then <em>neighsaying</em> against <em>proven to be more secure and reliable [by virtue of decentralization]</em> options like XMPP+OMEMO and/or <a href="https://infosec.space/tags/PGP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PGP</span></a>/MIME. </p><ul><li>What gets my blood boiling is the constant <a href="https://infosec.space/tags/disinfo" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>disinfo</span></a> by <a href="https://mstdn.social/@rysiek/113868777937162686" rel="nofollow noopener noreferrer" target="_blank">Signal</a> <a href="https://mstdn.social/@rysiek/113869169340313254" rel="nofollow noopener noreferrer" target="_blank">Fanboys</a> like <span class="h-card" translate="no"><a href="https://mstdn.social/@rysiek" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>rysiek</span></a></span> who sell it like <a href="https://infosec.space/tags/DigitalSnakeoil" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DigitalSnakeoil</span></a> akin to <a href="https://infosec.space/tags/AntivirusSoftware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AntivirusSoftware</span></a>, because it's at best <em>"<a href="https://infosec.space/tags/TechPopulism" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TechPopulism</span></a>"</em> and at worst <a href="https://infosec.space/@agturcz@circumstances.run/113868748895262202" rel="nofollow noopener noreferrer" target="_blank">will mislead "TechIlliterates"</a> with a <a href="https://infosec.space/@kkarhan/113868987217053362" rel="nofollow noopener noreferrer" target="_blank">false sense of security</a>, which in turn puts more users at risk.</li></ul><p>The <em>proper fix</em> is to actually <em>assess the situation</em> and acknowledge the <em>risks and limitations</em> as well as the very nature of communications, which means <em>upgrading later</em> is exponentially more painful, thus getting people <em>properly setup once</em> is way easier.</p><ul><li>Just because <em>WE</em> [ or rather <span class="h-card" translate="no"><a href="https://mstdn.social/@rysiek" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>rysiek</span></a></span> in this case ] rather <em>privilegued enough</em> to not be <em>hatecrimed in their current location</em> doesn't mean this is the case for everyone. And having places like Signal rely on a <em>"<a href="https://infosec.space/tags/CDN" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CDN</span></a>"</em> is just another <em>red flag</em> to me because questions like <a href="https://circumstances.run/@agturcz/113866980398547492" rel="nofollow noopener noreferrer" target="_blank">this one</a> just don't arise with <a href="http://monocles.chat" rel="nofollow noopener noreferrer" target="_blank">monocles.chat</a> as people can just exercise proper <a href="https://infosec.space/tags/SelfCustody" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SelfCustody</span></a> and just use Tor!</li></ul><p>Speaking of <a href="https://infosec.space/tags/monocles" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>monocles</span></a>: That business is at least <a href="https://infosec.space/tags/sustainable" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sustainable</span></a> because it's funded by users <a href="https://store.monocles.eu/produkt/monocles-starter-account/" rel="nofollow noopener noreferrer" target="_blank">(€2 p.m.)</a> which they can <a href="https://monocles.eu/more/#payment-section" rel="nofollow noopener noreferrer" target="_blank">pay anonymously</a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://chaos.social/@kasiandra" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>kasiandra</span></a></span> ganz einfach: </p><ul><li>Nutze Dienste und Services, die dich nicht bevormunden oder diskriminieren!</li></ul><p>Sei es <span class="h-card" translate="no"><a href="https://monocles.social/@monocles" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>monocles</span></a></span> / <a href="https://infosec.space/tags/monoclesSearch" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>monoclesSearch</span></a> oder <a href="https://infosec.space/tags/DuckDuckGo" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DuckDuckGo</span></a> für die Suche!</p><ul><li>Bevorzuge Seiten auf <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>torproject</span></a></span> / <a href="https://infosec.space/tags/Tor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tor</span></a> aka. <a href="https://infosec.space/tags/OnionServices" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OnionServices</span></a> (enden mit .onion) und beschwer' dich laut bei Anbietern, Berbraucherschützern und Regulolierungsbehörden wenn du als Tor-Nutzer*in diskriminiert wirst!</li></ul>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mamot.fr/@ploum" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>ploum</span></a></span> instead of <span class="h-card" translate="no"><a href="https://mastodon.world/@signalapp" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>signalapp</span></a></span> which also falls under <a href="https://infosec.space/tags/CloudAct" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CloudAct</span></a> and is also a <a href="https://infosec.space/tags/Proprietary" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Proprietary</span></a>, <a href="https://infosec.space/tags/SingleVendor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SingleVendor</span></a> &amp; <a href="https://infosec.space/tags/SingleProvider" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SingleProvider</span></a> solution, consider <a href="https://infosec.space/tags/XMPP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>XMPP</span></a>+<a href="https://infosec.space/tags/OMEMO" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OMEMO</span></a> for real <a href="https://infosec.space/tags/E2EE" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>E2EE</span></a> with <a href="https://infosec.space/tags/SelfCustody" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SelfCustody</span></a> of all the keys!</p><ul><li><p>Fir <a href="https://infosec.space/tags/eMail" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>eMail</span></a> &amp; <a href="https://infosec.space/tags/Chat" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Chat</span></a>, I can recommend <span class="h-card" translate="no"><a href="https://monocles.social/@monocles" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>monocles</span></a></span> as a paid provider who doesn't run <a href="https://infosec.space/tags/ads" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ads</span></a> and doesn't fall under Cloud Act or similar laws. (Also they have excellent <a href="https://infosec.space/tags/Apps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Apps</span></a> that work with basically all providers usibg standard-compliant servers &amp; APIs!)</p></li><li><p>You may want to consider <a href="https://infosec.space/tags/Torifying" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Torifying</span></a> everything by using <span class="h-card" translate="no"><a href="https://social.librem.one/@guardianproject" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>guardianproject</span></a></span> <a href="https://infosec.space/tags/Orbot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Orbot</span></a> and push everything on <a href="https://infosec.space/tags/mobile" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>mobile</span></a> through <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>torproject</span></a></span> / <a href="https://infosec.space/tags/Tor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tor</span></a>.</p></li><li><p>In fact, some providers like cock.li even have <a href="https://infosec.space/tags/OnionServices" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OnionServices</span></a> to directly connect to them.</p></li><li><p><a href="https://infosec.space/tags/MicrosoftOutlook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>MicrosoftOutlook</span></a> literally steals your Login <a href="https://infosec.space/tags/credentials" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>credentials</span></a>, so using <span class="h-card" translate="no"><a href="https://mastodon.online/@thunderbird" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>thunderbird</span></a></span> is a necessity anyway. Don't forget to change your logins either way!</p></li><li><p><a href="https://infosec.space/tags/Firefox" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Firefox</span></a> is okay, but <a href="https://infosec.space/tags/TorBrowser" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TorBrowser</span></a> should be normalized as well.</p></li><li><p>Consider launching a <span class="h-card" translate="no"><a href="https://mastodon.earth/@cryptoparty" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>cryptoparty</span></a></span> to teach other the same.</p></li><li><p>Nirmalize using <span class="h-card" translate="no"><a href="https://venera.social/profile/tails_live" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>tails_live</span></a></span> / <span class="h-card" translate="no"><a href="https://fosstodon.org/@tails" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>tails</span></a></span> / <a href="https://infosec.space/tags/Tails" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tails</span></a> as your <a href="https://infosec.space/tags/DailyDriver" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DailyDriver</span></a>!</p></li></ul>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://peoplemaking.games/@eniko" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>eniko</span></a></span> no, in fact none of that stuff is nevessary and there are a shitload of <a href="https://infosec.space/tags/OnionServices" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OnionServices</span></a> on <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>torproject</span></a></span> / <a href="https://infosec.space/tags/Tor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tor</span></a> that are using clean <a href="https://infosec.space/tags/HTML" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HTML</span></a> without <a href="https://infosec.space/tags/JavaScript" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>JavaScript</span></a>!</p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://infosec.exchange/@resingm" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>resingm</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.space/@ada" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>ada</span></a></span> Call me weird but I fail to see where <em>"yet another protocol"</em> instead of <a href="https://infosec.space/tags/HTTP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HTTP</span></a>(S) is of benefit.</p><ul><li>I mean there are <a href="https://infosec.space/tags/BlogHosters" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BlogHosters</span></a> that offer hosting of <a href="https://infosec.space/tags/OnionServices" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OnionServices</span></a> on <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>torproject</span></a></span> / <a href="https://infosec.space/tags/Tor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tor</span></a> and basically almost all paid-for managed webhosters that use a FLOSS'd CMS and not a proprietary platform usually don't shove clients' sites full with Tracking Garbage...</li></ul>
yawnbox :rebel:<p>In case you don't know, <span class="h-card" translate="no"><a href="https://fosstodon.org/@cwtch" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>cwtch</span></a></span> is a decentralized end to end encrypted chat app</p><p>there's no servers by default, meaning no central authority</p><p>transport is based completely on Tor onion services, which itself is decentralized and provides automatic and transparent end to end encryption</p><p>(though <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>torproject</span></a></span> still hasn't deployed any post-quantum cryptography into Tor, Cwtch is not as robust as newer PQ Signal or iMessage)</p><p>the profile ID that you share with your people is based on the Tor onion address that your profile is using for communications. if you shut down Cwtch, your Tor onion address also gets shut down, so you can't receive messages while you're offline, by default</p><p>it's my opinion that using Tor onion services for chat apps is a no-brainer. everyone with a Cwtch profile is both a client and a server. you are your own server. because of how Tor onion services works, as a reverse proxy, you don't need to host a "public" service on the internet. and e2ee, key management, encryption is all automatic. you can't fuck it up! its crazy to me that apps like Matrix don't take advantage of this. Tor onion services is an extremely powerful tool and so many people ignore or think of FUD</p><p><a href="https://disobey.net/tags/Tor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tor</span></a> <a href="https://disobey.net/tags/onionservices" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>onionservices</span></a> <a href="https://disobey.net/tags/anonymity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>anonymity</span></a> <a href="https://disobey.net/tags/e2ee" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>e2ee</span></a> <a href="https://disobey.net/tags/cwtch" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cwtch</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://bonn.social/@cryptoparty" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>cryptoparty</span></a></span> +9001%</p><p>Außerdem geht es darum <a href="https://infosec.space/tags/Massen%C3%BCberwachung" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Massenüberwachung</span></a> so kostenintensiv und unrealistisch wie möglich zu machen...</p><ul><li>Es reicht nicht Leuten zu zeigen wie <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>torproject</span></a></span> / <a href="https://infosec.space/tags/Tor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tor</span></a> und <span class="h-card" translate="no"><a href="https://venera.social/profile/tails_live" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>tails_live</span></a></span> / <span class="h-card" translate="no"><a href="https://fosstodon.org/@tails" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>tails</span></a></span> / <a href="https://infosec.space/tags/Tails" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tails</span></a> funktioniert, sondern wir müssen die konsequente Nutzung von <a href="https://infosec.space/tags/TorBrowser" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TorBrowser</span></a> normalisieren und Behörden, Organisationen und Firmen dazu nötigen, <a href="https://infosec.space/tags/OnionServices" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OnionServices</span></a> zu betreiben und <a href="https://infosec.space/tags/DontBlockTor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DontBlockTor</span></a> umzusetzen!</li></ul><p>Hier muss die doppelte*" Aggression"* geliefert werden die <a href="https://infosec.space/tags/Cyberfaschisten" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Cyberfaschisten</span></a> uns <a href="https://infosec.space/tags/Polizeistaat" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Polizeistaat</span></a>-Fans an den Tag legen!</p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mastodon.social/@dw_innovation" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>dw_innovation</span></a></span> okay, maybe not the answer I hoped for given that this means manually dropping security in <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>torproject</span></a></span> / <a href="https://infosec.space/tags/TorBrowser" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TorBrowser</span></a>.</p><ul><li>Still I'm not completely sketched out by that given <a href="https://infosec.space/tags/DWnews" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DWnews</span></a> reputation, but I know this could he done better, as various websites and even stores and forums as <a href="https://infosec.space/tags/OnionServices" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OnionServices</span></a> showcase...</li></ul><p>Given upcoming <a href="https://infosec.space/tags/accessibility" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>accessibility</span></a> requirements in <a href="https://infosec.space/tags/Germany" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Germany</span></a> I'm convinced cross-testing with <a href="https://infosec.space/tags/LynxBrowser" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LynxBrowser</span></a> over <a href="https://infosec.space/tags/Tor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tor</span></a> will likely be one of those things that'll necessitate changing that.</p><ul><li>A potential workaround is to use an <em>"accessibility proxy"</em> like <span class="h-card" translate="no"><a href="https://bitbang.social/@ActionRetro" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>ActionRetro</span></a></span> 's <a href="https://infosec.space/tags/FrogFind" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FrogFind</span></a> <a href="https://youtu.be/c_v2_vTogS8" rel="nofollow noopener noreferrer" target="_blank">¹</a> which already comes in handy on <em>extreme narrowband</em> connections like <a href="https://infosec.space/tags/Iridium" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Iridium</span></a> <a href="https://youtu.be/UWkjuDI9RSo" rel="nofollow noopener noreferrer" target="_blank">²</a>...</li></ul>
Kevin Karhan :verified:<p>Hey, <span class="h-card" translate="no"><a href="https://mastodon.social/@dw_innovation" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>dw_innovation</span></a></span> , </p><p>for some reason <a href="https://www.dwnewsgngmhlplxy6o2twtfgjnrnjxbegbwqx6wnotdhkzt562tszfid.onion" rel="nofollow noopener noreferrer" target="_blank">your OnionService</a> doesn't seem to work and require <a href="https://infosec.space/tags/JavaScript" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>JavaScript</span></a>, which is a big no-go on <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>torproject</span></a></span> / <a href="https://infosec.space/tags/Tor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tor</span></a> as <a href="https://infosec.space/tags/JS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>JS</span></a> can and has been known to be a security issue and big no-no for all serious <a href="https://infosec.space/tags/OnionServices" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OnionServices</span></a>... </p><p>Can you <a href="https://infosec.space/tags/plzfix" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>plzfix</span></a> this? <br><a href="https://infosec.space/tags/thx" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>thx</span></a></p>
Kevin Karhan :verified:<p>Sadly the <a href="https://infosec.space/tags/paywalling" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>paywalling</span></a> of <a href="https://infosec.space/tags/grsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>grsec</span></a> / <a href="https://infosec.space/tags/grsecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>grsecurity</span></a> also killed more <a href="https://infosec.space/tags/downstream" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>downstream</span></a> projects like <a href="https://web.archive.org/web/20191230091137/https://en.wikipedia.org/wiki/Tor-ramdisk" rel="nofollow noopener noreferrer" target="_blank">tor-ramdisk</a> which was a minimalist <a href="https://infosec.space/tags/busybox" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>busybox</span></a> / <a href="https://infosec.space/tags/linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>linux</span></a> <a href="https://infosec.space/tags/distro" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>distro</span></a> <a href="https://blogs.gentoo.org/blueness/2014/05/23/tor-ramdisk-a-tiny-embedded-image-to-host-a-tor-relay-or-exit/" rel="nofollow noopener noreferrer" target="_blank">designed</a> to host <a href="https://infosec.space/tags/OnionServices" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OnionServices</span></a>. It was <a href="https://tor-talk.torproject.narkive.com/jgOoi0bN/tor-ramdisk-20160810-released" rel="nofollow noopener noreferrer" target="_blank">pretty nifty</a> and the <a href="https://infosec.space/tags/SourceCode" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SourceCode</span></a> is <a href="https://gitlab.torproject.org/legacy/gitolite/tor-ramdisk/" rel="nofollow noopener noreferrer" target="_blank">still</a> <a href="https://web.archive.org/web/20200329155520/https://gitweb.torproject.org/tor-ramdisk.git" rel="nofollow noopener noreferrer" target="_blank">online</a> and hosted by <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>torproject</span></a></span> on their <a href="https://infosec.space/tags/gitlab" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>gitlab</span></a>, abeit seemingly abandoned since 2018...</p>
Kevin Karhan :verified:<p><a href="https://infosec.space/tags/BlamingTheUser" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BlamingTheUser</span></a> instead of <a href="https://infosec.space/tags/FixingTech" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FixingTech</span></a> is just a <a href="https://infosec.space/tags/TechBro" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TechBro</span></a> way of <a href="https://infosec.space/tags/VictimBlaming" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VictimBlaming</span></a>! </p><p><a href="https://infosec.space/tags/FACT" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FACT</span></a>: <a href="https://infosec.space/tags/JavaScript" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>JavaScript</span></a> is a clear case of <a href="https://minidisc.tokyo/notes/9wa94v68fi" rel="nofollow noopener noreferrer" target="_blank">everything wrong with modern tech stacks</a> and it </p><ul><li>DON'T BE LIKE <a href="https://shigusegubu.club/objects/b4fd3cc1-8e71-4fde-94d7-e633ee3c585e" rel="nofollow noopener noreferrer" target="_blank">THAT</a> <a href="https://shigusegubu.club/objects/3431a795-578d-43ac-8c2e-4e66b8c7155f" rel="nofollow noopener noreferrer" target="_blank">GUY</a>!</li></ul><p>Espechally when <a href="https://minidisc.tokyo/notes/9wa94v68fi" rel="nofollow noopener noreferrer" target="_blank">the situation is so obvious</a>...</p><ul><li><a href="https://infosec.space/tags/JS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>JS</span></a> <a href="https://mastodon.sdf.org/@gnemmi/112869080794988869" rel="nofollow noopener noreferrer" target="_blank">should've never been made</a> and I hope upcoming <a href="https://infosec.space/tags/accessibility" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>accessibility</span></a> requirements will kill it for good, if <a href="https://infosec.space/tags/privacy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>privacy</span></a> and <a href="https://infosec.space/tags/ITsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ITsec</span></a> regulations didn't.</li></ul><p>If your website can't be used with <a href="https://infosec.space/tags/LynxBrowser" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LynxBrowser</span></a> over <a href="https://infosec.space/tags/Iridium" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Iridium</span></a> and/or <a href="https://infosec.space/tags/TorBrowser" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TorBrowser</span></a> in it's strictest security settings, than it should be illegal!</p><ul><li>Cuz unlike with JavaScript, one can't make a <a href="https://infosec.space/tags/Shitcoin" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Shitcoin</span></a> <a href="https://infosec.space/tags/DriveByMining" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DriveByMining</span></a> <a href="https://infosec.space/tags/malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>malware</span></a> in <a href="https://infosec.space/tags/HTML" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HTML</span></a> &amp; <a href="https://infosec.space/tags/CSS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CSS</span></a>! </li></ul><p>If you need evidence for the woeful unnecessarity of JS, please go and look up all the <a href="https://infosec.space/tags/OnionServices" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OnionServices</span></a> that don't!</p><ul><li>AS IT SHOULD BE!</li></ul>
Den Datafag Trollmann :flag: <span class="h-card"><a class="u-url mention" href="https://infosec.space/@kkarhan" rel="nofollow noopener noreferrer" target="_blank">@<span>kkarhan</span></a></span> <span class="h-card"><a class="u-url mention" href="https://limepeeps.perchinup.top/@radmin" rel="nofollow noopener noreferrer" target="_blank">@<span>radmin</span></a></span> <span class="h-card"><a class="u-url mention" href="https://minidisc.tokyo/@SuperDicq" rel="nofollow noopener noreferrer" target="_blank">@<span>SuperDicq</span></a></span> &gt;WHAT ABOUT <a class="hashtag" href="https://shigusegubu.club/tag/thxbye" rel="nofollow noopener noreferrer" target="_blank">#THXBYE</a> <a class="hashtag" href="https://shigusegubu.club/tag/eod" rel="nofollow noopener noreferrer" target="_blank">#EOD</a> IS NOT CLEAR?<br><br>if you <a class="hashtag" href="https://shigusegubu.club/tag/eod" rel="nofollow noopener noreferrer" target="_blank">#EOD</a> then why are you continuing it? I'm continuing discussion with other people participating, you don't need to reply.<br><br>&gt;THE WHOLE <a class="hashtag" href="https://shigusegubu.club/tag/adblocking" rel="nofollow noopener noreferrer" target="_blank">#ADBLOCKING</a> STUFF LIKE <a class="hashtag" href="https://shigusegubu.club/tag/noscript" rel="nofollow noopener noreferrer" target="_blank">#NoScript</a> SHOULD NOT HAVE A REASON TO EXIST TO BEGIN WITH!<br><br>Much like anti-virus and other anti-malware and such, firewalls shouldn't exist, all C programs must be compiled from source and made with benign and honest intend with no malpractices and no accidents ever.<br><br>&gt;I AVOID THAT SHIT BECAUSE IT IS A NET NEGATIVE TO THE WORLD, LIKE <a class="hashtag" href="https://shigusegubu.club/tag/windows" rel="nofollow noopener noreferrer" target="_blank">#WINDOWS</a>, AND THUS I WON'T WASTE TIME OR ENERGY HAVING TO CLEANUP DIGITAL FECES FROM MY TRAFFIC AFTER I GOT.IT SHIT ALL OVER THE WEB!!!<br><br>you avoid it but rest of the world can't. It's all over the world, have you seen CrowdStrike outage?<br><br>&gt;THERE IS NO LEGITIMATE REASON FOR <a class="hashtag" href="https://shigusegubu.club/tag/javascript" rel="nofollow noopener noreferrer" target="_blank">#JavaScript</a> WHEN THERE ARE AMPLE OF RICH WEBSITES, ESPECHALLY <a class="hashtag" href="https://shigusegubu.club/tag/onionservices" rel="nofollow noopener noreferrer" target="_blank">#OnionServices</a> SHOWING THAT THEY DON'T NEED THAT SHITE!<br><br>There is legitimate reason, it's called making a GUI application.<br><br>Can you please disable your cruise control (aka CapsLock)?