ᗪᗩᗰᑎ

  • 1 Post
  • 50 Comments
Joined 2 years ago
cake
Cake day: June 18th, 2023

help-circle


  • my personal dislike for it is that the claims of decentralization are countered by how expensive it is to operate in a truly decentralized manner.

    To be truly decentralized you would need to run a relay server, not just a PDS which many people already do and simply holds your data. Unfortunately, the cost to run a relay server today is already about $500+ a month [1] and will only be getting more expensive.

    Lastly, while the fediverse has figured out decentralized DM’s, Bluesky DM’s are completely centralized [1] and only work thanks to being funneled through their servers. I wouldn’t call what they have private considering they can read what everyone on Bluesky is saying privately. Granted, fediverse DM’s are not encrypted either, but at least they’re decentralized and don’t allow a single provider access to everyone’s private messages.

    [1] https://dustycloud.org/blog/how-decentralized-is-bluesky/






  • Signal is better than Session if you value privacy:


    The Session developers dropped Perfect Forward Secrecy because it would be hard to work around it.

    First things first, let’s talk about what we’re leaving behind: Perfect Forward Secrecy (PFS) and deniability.

    Source: https://getsession.org/session-protocol-explained

    In plain English, they dropped a security feature for their own convenience to the detriment of their users’ security.

    For anyone unsure what PFS provides:

    The value of forward secrecy is that it protects past communication.

    Source: https://en.wikipedia.org/wiki/Forward_secrecy

    The Session devs also claim:

    Session provides protections against these types of threats in other ways — through fully anonymous account creation, onion routing, and metadata minimisation, for example.

    Reading between the lines, we can interpret that as introducing security through obscurity, which is generally considered bad practice - https://cwe.mitre.org/data/definitions/656.html

    Lastly, Session does not provide quantum resistant encryption, the latest and greatest tech in ensuring your messages stay private. Signal, SimpleX (via PQXDH [1] ) and iMessage (via PQ3 [2] ) - as far as I’m aware - are the only messaging platforms that support quantum-resistant encryption.

    If you want something like Signal but without phone numbers, give SimpleX a try. It’s basically a fork of Signal with a ton of privacy features, like working without a phone number. I like it but the UX still needs a lot of polish before I try getting family/friends on it.

    [1] https://signal.org/blog/pqxdh/

    [2] https://security.apple.com/blog/imessage-pq3/



  • but the hardware is not capable. it’s running a miniscule custom 260k LLM and the “claim to fame” is that it wasn’t slow. great? we already know tiny models are fast, they’re just not as accurate and perform worse than larger models, all they did was make an even smaller than normal model. this is akin to getting Doom to run on anything with a CPU, while cool and impressive, it doesn’t do much for anyone other than being an exercise in doing something because you can.



  • Checkout Notesnook. I’ve tried most of the ones you’ve listed and have been really enjoying how well it works compared to the competition considering its end-to-end encrypted.

    A few features:

    • Clients and server are open source.
    • End-to-end encrypted note syncing.
    • You can publish public notes.
    • You can publish privates notes that require a password to view.
    • You can self-host the sync server.
    • You can self-host the publishing server.
    • Full offline mode.
    • At rest encryption.
    • Multi-platform clients with feature parity (Android, iOS, Linux, Windows, MacOS, Web).
    • Most if not all of the general features you’d expect from a notes taking application.

    One thing I really like about the project is how open they are about what they’re doing, why they’re doing it and what the future holds. It’s been great seeing their roadmap (https://notesnook.com/roadmap/) and seeing promised features land with new ones being added, and I’ve only been using it for less than a year now!



  • ᗪᗩᗰᑎtoGreentextAnon hates Apple
    link
    fedilink
    arrow-up
    2
    ·
    29 days ago

    Yep, I’ve seen this ~exact post a several times, same general structure and points, none of it acknowledging that the attacks on other people in the community started long before the alleged swat.

    Just re-iterating what I’ve seen online - would love some sources or evidence to what you posted as those are 100% valid criticisms if true.

    I don’t really follow the drama but have seen others comment on it before. It’s the reason I try to reply to posts with sources as I hate rumors being spread and the only way to combat misinformation is to provide evidence. What you claimed is pretty damning, if you’re able to provide a soruce I would love to read and educate myself in adding more context to the situation. Thanks!







  • as usual, devs are lost in implementing ludicrously complex scenarios for threat models that touch but a percentile of users, instead of implementing functionality that’s normal everywhere else.

    as usual, users are lost in complaining about a privacy-centered application prioritizing on privacy-centered solutions, instead of using the hundreds of other already insecure applications that are normal everywhere else.

    people really will complain about anything. It’s like progress means nothing, unless a fully working solution is available day 1, it’s completely worthless. bff