I currently use Telegram for my friends and family, but have reluctantly come to the conclusion that the UK Government is either reaching agreement for backdoors with messaging services, or is trying its hardest to.

I’m also on Element/Matrix. Before I try to get my contacts to join me on there, should I be aware of any privacy issues or is that a good place to head?

  • Telorand@reddthat.com
    link
    fedilink
    English
    arrow-up
    4
    ·
    1 day ago

    As far as I know Meta only collects and abuses data it get’s from people where there are now laws in place to prevent it (so why wouldn’t they do it).

    Unfortunately, in practice, the laws don’t seem to mean much to the wealthy.

    Like other gigantic companies that have billions of dollars, it’s easier and more profitable to ask forgiveness than permission; paying legal fines that are 0.01% of their overall profits is just the cost of doing business. Zuck has been caught on multiple occasions skirting the law (see the most recent revelation of them surreptitiously leeching scores of books from Anna’s Archive and a previous one of partnering with Cambridge Analytica, for example).

    I’m all good with having companies submit to hostile financial audits, but I’m not sure how a CPA would be qualified to validate security or privacy. Code security audits should be done by cryptographic experts, and I think you would need both.

    Perhaps one day, we’ll have Certified Public Cryptographers that have a fiduciary duty to ensure people are secure or private.

    • Vinstaal0@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      15 hours ago

      A CPA is required to higher other professionals when their knowledge doesnt reach to the subject in question, so yeah they would get a security or privacy specialist to help them. The upside of using a CPA is that they would look at the entire process. The rapport of a CPA is going to be a lot more expensive though.

      In the US people defend that companies don’t publish their annual reports, plus some people also defend these companies regardless of what they do. It’s almost religion. But if you would require companies to at least publish some figures and require bigger companies to have a statement signet by a CPA then more of these companies would have issues. Since a CPA can generally get in a lot of trouble if they mess up (at least here in NL)

      They don’t need to be hostile audit’s, heck that’s probably the worst way of doing it. Work together with the company and help them to pass the audit and they will be more transparent .

      • Telorand@reddthat.com
        link
        fedilink
        English
        arrow-up
        1
        ·
        9 hours ago

        Sounds like we want the same thing, except I think it’s perhaps too high of an expectation to have a CPA that can do both financial accounting and cryptography.

        • Vinstaal0@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          7 hours ago

          A CPA is required to use experts in fields to they are no expert in, but the proces part of the entire situation is very import as well so that’s why I suggested a CPA do it. (Plus a signature from a CPA means more)