• 1 Post
  • 216 Comments
Joined 2 years ago
cake
Cake day: July 11th, 2023

help-circle








  • Agreed. This is American style storm in a teacup politics when we have bigger fish to fry -including his actual failures as a parliamentarian and lawmaker. It will cost more to move him out and in again, and putting his autistic daughter through two moves for “optics” is just dumb. Keep pointing out that he’s such a weak leader they needed to hand him the easiest seat in Canada on a platter, and /that/ will do more damage than pretending anyone cares about him staying rent free in Stornaway for a couple months.


  • You are talking out of your ass. First, a timing attack requires numbers to correlate - reasonable numbers of people using a node or server and a LOT of packets going back and forth. Neither are true for a Signal server. Second, they don’t get the phone numbers if contacts are using only their username (with phone number sharing disabled). Your criticisms are over the top and not at all nuanced to the degree of protection of metadata that was built into signal. If it was as bad as you imply, a whole heck of a lot of the most respected security researchers would have to be complete idiots.




  • That a timing attack could be successful is not a given. It’s a possibility, yes, but there is very likely sufficient mixing happening to make that unrealistic or unreliable. An individual doesn’t create much traffic, and thousands are using the server constantly. Calling it a honeypot or claiming the phone number and device is are available is a stretch.

    Timing attacks can work in tor when you are lucky enough to own both the entrance and exit node for an individual because very few people will be using both, and web traffic from an individual is relatively heavy and constant to allow for correlation.





  • At least in theory, this is mitigated. The signal activation server sees your phone number, yes. If you use Signal, the threat model doesn’t protect you from someone with privileged network or server access learning that you use Signal (just like someone with privileged network access can learn you use tor, or a vpn, etc).

    But the signal servers do not get to see the content of your group messages, nor the metadata about your groups and contacts. Sealed sender keeps that private: https://signal.org/blog/sealed-sender/

    You would obviously want to join those groups with a user Id rather than your phone number, or a malicious member could out you. It’s not the best truly anonymous chat platform, but protection from your specific threat model is thought through.

    edit: be sure to go to Settings > Privacy > Phone Number. By default anyone who already has your phone number can see you use signal (used for contact discovery, this makes sense to me for all typical uses of Signal), and in a separate setting, contacts and groups can see your phone number. You will absolutely want to un-check that one if you follow my suggestion above.


  • It’s insane that this is even needed. Show me ads for things relevant to the content of the web page and nothing else. If I’m reading about furnace filters, sure, show me an ad for buying furnace filters, I might buy from you, but don’t follow me around for 2 weeks shoving furnace filter ads in my face. If I’m not reading about them anymore, I’ve moved on.

    The added benefit of this approach for advertisers would be that you can literally embed the ads in the page, making ad-blockers ineffective. They literally chose the worst method for everyone involved.


  • I use both Nextcloud’s Memories app and Immich simultaneously for now, with the same photos. Immich is pointed at a read-only bind-mount of my Nextcloud photos folder on the server side, so they see the same photos. My photos are a mess and I absolutely need the local AI stuff, and right now, neither is perfect, so I have both running and bounce back and forth. If one of them clearly pulls ahead, I’ll probably settle on that one in isolation.


  • This really could use some clarification on what category these belong to. Most of these projects are open source projects where you can either self-host the tool, or choose from one of many free or paid instances online. If someone lacks the technical skill, hardware, or time to self-host, they should shop around. Often there is an “official” instance by the developers, but that’s not always the best option. Sometimes a paid option with more resources is going to be more stable and performant.

    Other suggestions are individual companies services, and a couple of these are just applications you install on your device. It would be helpful to readers to clarify.