mathstodon.xyz is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Mastodon instance for maths people. We have LaTeX rendering in the web interface!

Server stats:

2.8K
active users

#secure

3 posts3 participants2 posts today

I hate my #bank...

"As a #security measure" when you #login, instead of typing it the whole #password, you have to type in 8 #random characters from it, like 1st, 4th, 10th etc.

What does this #secure against? Your user being able to log in? Every time I have to open a #notepad and type out my password, count the characters, and type them in one by one, instead of JUST USING A PASSWORD #MANAGER.

If an #attacker knows your password... WHAT DIFFERENCE DOES THIS MAKE?!

Replied in thread

@torproject @ZDNet TBH, I'd always recommend people to use @tails / @tails_live / #Tails if they want a secure and private OS.

  • Shure in theory one could do more #secure with #OpenBSD, but that's neither easy to use for non-#IT-folks nor easy to onboard people into.

Tails by contrast just comes with #TorBrowser, @thunderbird and other nifty tools preconfigured from the get go and allows people to get started, regardless if it's a #journalist or someones' grandma who may not have her own dedicaded machine but instead uses an external SSD/HDD to just boot into her desktop and not rely on the #malware-laced #Internetcafé's #Windows installation...

Not to mention it avoids a lot of #pitfalls that other distros like @kalilinux will deliberaltely keep open because their goals are diametral to that.

Periodic reminder for those trying to #DeGoogle their lives:

Great news for those looking to securely store your #photos online, and keep other apps from prying (Google!), I highly recommend Ente. The founder and lead Dev is a former Google employee and committed to P R I V A C Y.

ente.io is cross platform, under rigorous development, Open Source, E2EE, and you can use it for free with 10GB of storage (up from 5GB previously).

They just announced their first major version update today (Ente v1.0).
Easily import your Google Photos and Instagram pics too.

And... if you need more storage, use MY referral code below. If you are on a paid plan, we each get an extra 10GB of FREE storage.
My paid plan of 50GB is only $2.99/mo. (US)

⟶ Ente referral code: * RVCAPI *
⟶ Apply it in Settings → General → Referrals, to get additional 10 GB free, after you signup for a paid plan.

enteMastodon server migrationOur journey migrating to Fosstodon

Daniel J. Bernstein (#djb, to those who know and love him [1]) has a new blog entry about the NIST post-quantum #cryptography standardization process that's been ongoing for some years. Also, follow him @djb .

If you're not aware of some of the controversy about how NIST is running this process, it's a must-read.

blog.cr.yp.to/20250423-mceliec

My $0.02: it sure looks like NIST is backstopping an attempt by the NSA to get everyone to standardize on cryptography #standards that the #NSA knows how to break.

Again.

Yes, they did it before. If you read up on the Dual_EC calamity and its fallout, and how this time it was supposed to be different - open, transparent, secure - then prepare to be disappointed. NIST is playing #Calvinball with their rules for this contest, yanking the rug out from under contenders that appear to be more #secure and better understood, while pushing alternatives that are objectively worse (#weaker encryption, less studied, poorer #performance).

Frankly, I think organizations outside of the #USA would be foolish to trust anything that comes out of #NIST's current work. Well, those inside the USA too, but some of those may be forced by law to use whatever NIST certifies.

[1] Some people think djb is "prickly", not lovable. Oddly, it seems that the only people who say this are those who are wildly incorrect about code/algorithms and are being gently but publicly corrected about by djb at the time

blog.cr.yp.tocr.yp.to: 2025.04.23: McEliece standardization

Selhosted P2P E2EE File Transfer & Messaging PWA

* #OpenSource
* #CrossPlatform
* #PWA
* #iOS, #Android, #Desktop (self compile)
* App store, Play store (coming soon)
* Desktop
* #Windows, #MacOS, #Linux (self compile)
* run `index.html` on any modern #browser
* #Decentralized
* #Secure
* #NoCookies
* #P2P #encrypted
* No registration
* No installing
* #Messaging
* Group Messaging (coming soon)
* Text Messaging
* #Multimedia Messaging
* #Screensharing (on desktop browsers)
* Offline Messaging (in #research phase)
* #FileTransfer
* #VideoCalls
* #DataOwnership
* #SelfHosted
* GitHub pages Hosting
* #LocalOnly storage

Check it out!

positive-intentions.com

(Degoogled links to the apps)
- Chat: chat.positive-intentions.com
- File: file.positive-intentions.com
- GitHub: github.com/positive-intentions