digitalcourage.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Diese Instanz wird betrieben von Digitalcourage e.V. für die Allgemeinheit. Damit wir das nachhaltig tun können, erheben wir einen jährlichen Vorausbeitrag von 1€/Monat per SEPA-Lastschrifteinzug.

Server stats:

855
active users

#e2ee

35 posts28 participants6 posts today
Continued thread

Obviously, #Google (under order from the US government) could serve compromised “updates” at any time to individual users.

It would be technically possible to enable users to compare a “fingerprint” (hash) of security-critical plugins they are running, such as the one supporting Gmail’s #E2EE capability. If I can see I’m getting a different plugin for my OS/CPU to 99% of other users on the same platform, that’s a big warning sign. But I haven’t seen such software widely deployed (yet) 🧐

Continued thread

Secondly, it’s not clear if #gmail is using this workaround just for message recipients who don’t have their own “digital #X509 certificates” to enable message encryption yet (which would be justifiable) or not (which would be an improvement over the status quo, but not genuine #E2EE.)

Continued thread

I’m not the religious cultist some are over defining #E2EE. When it comes to organisational communications, it seems sensible to me to define the endpoint as the organisation, not the individual recipient. And as one widely-used example, this is how #WhatsApp for Business works

pretty sure this can work for #e2ee private mentions... worst case it just obfuscates text search.

- verifying key: [86,10,27,184,67,57,76,92,187,198,164,56,154,224,189,35,72,85,79,149,217,241,238,155,33,64,193,202,178,136,183,50]
- exchange key: [222,204,53,153,33,212,247,174,180,162,45,216,108,13,79,187,183,21,57,109,201,247,102,189,30,155,165,169,213,33,100,78]

ordinarylabs.io/s00persneakyha

ordinarylabs.ios00per sneaky hacker t001s 101only to be used by wolves, dragons, lions, tigers, bears, bats, orcas & octopuses.

arstechnica.com/security/2025/

Google's new #Gmail feature allows businesses to send end-to-end encrypted emails, but it's not true end-to-end encryption.

The #encryption and decryption occur on the user's device, but the keys are managed by the organization.

Because the organization retains custody of the keys, they can easily snoop on communications.

Ars Technica · Are new Google E2EE emails really end-to-end encrypted? Kinda, but not really.By Dan Goodin
Replied in thread

@michel42
Gerade als Antwort in eine andere Diskussion geschickt:-)

Schon mal #deltachat in Betracht gezogen?
Bietet ähnlichen Funktionsumfang wie #Whatsapp #Signal #SignalApp und nutzt dafür aber Standard Internet Protokolle (Email Standards) für #E2EE über sog. chat relays. Diese speichern nur kurzfristig die (immer verschlüsselten) Nachrichten.
#deltachat läuft nicht nur auf #Android oder #iOS sondern auch unter #linux #macos #ubuntutouch oder wer unbedingt will auch #windoof
Man kann es gleichzeitig auf mehreren Geräten nutzen. Außerdem unterstützt es mehrere Profile.

@delta
delta.chat

delta.chatDelta Chat: The e-mail messengerChat over e-mail and head back to the future with us! Delta Chat is like Telegram or Whatsapp but without the tracking or central control. Delta Chat does not need your phone number. Check out our ...
Replied in thread

@debacle @sturmsucht @urbanprivacy @xmpp
Schon mal #deltachat in Betracht gezogen?
Bietet ähnlichen Funktionsumfang wie #Whatsapp #Signal #SignalApp und nutzt dafür aber Standard Internet Protokolle (Email Standards) für #E2EE über sog. chat relays. Diese speichern nur kurzfristig die (immer verschlüsselten) Nachrichten.
#deltachat läuft nicht nur auf #Android oder #iOS sondern auch unter #linux #macos #ubuntutouch oder wer unbedingt will auch #windoof
Man kann es gleichzeitig auf mehreren Geräten nutzen. Außerdem unterstützt es mehrere Profile.

#Google acaba de llamar #E2EE a un recién estrenado método de cifrado en #GMail que de hecho es la muestra más evidente de lo que podrían querer quienes apoyan #ChatControl.
Las claves de cifrado quedan en mano de los administradores, y quien tenga acceso a ellas puede husmear en las comunicaciones de cualquiera bajo su paraguas. Venden su gestor de contraseñas igual.

Si las llaves de tu coche las custodia otro, no es tu coche.
Con las claves de cifrado sucede lo mismo.

arstechnica.com/security/2025/

Ars Technica · Are new Google E2EE emails really end-to-end encrypted? Kinda, but not really.By Dan Goodin

Es ist naiv, ein Risiko durch zu starke Abhängigkeit von einem Oligopol nicht als solches zu erkennen.

Es ist dumm, dann auch noch auf #e2ee zu verzichten, wenn man diese Anbieter benutzt (ist es sonst natürlich auch).

Man kann seinen Aktenschrank auch gleich offen auf die Straße stellen...

golem.de/news/hyperscaler-bund

#digitalesouveranitat

[Edit: neuer Link]

Golem.de · Hyperscaler: Bundesregierung nutzt US-Cloud ohne Verschlüsselung - Golem.deBy Achim Sawall

I said it before on Mastodon. I'm reposting this again. Comparing #DeltaChat and #Matrix together, if you want hassle free and consistent messenger for private #E2EE chats, don't go for Matrix. DeltaChat is way better.

However, if you want something like a public forum, or a public chatroom, don't go for DeltaChat. Matrix is way better suited for that. And DeltaChat does not support public groups at all. In DeltaChat groups, there is no admin or moderator and everyone have got permission to remove or add the others.

I think I have to write a longer post on my personal blog about these two, comparing them together.

PS: Another Matrix encryption bug few minutes ago triggered repost of this.

#EuropeanCommission takes aim at end-to-end #encryption & proposes #Europol become an #EU #FBI

The European Commission announced on Tues its intention to join the ongoing debate about lawful access to data & end-to-end encryption while unveiling a new internal #security strategy

#ProtectEU , as the strategy has been named, describes the general areas that the bloc’s executive would like to address … although …does not offer any detailed policy proposals
#e2ee

therecord.media/european-commi

therecord.mediaEuropean Commission takes aim at end-to-end encryption and proposes Europol become an EU FBIThe Commission said it would create roadmaps regarding both the “lawful and effective access to data for law enforcement” and on encryption.
Replied in thread

@bontchev
From the "on ProtectEU: a European Internal Security Strategy" document:

"[...] a framework for access to data which responds to the needs to enforce our laws and protect our values is essential. At the same time, ensuring digital systems remain secure from unauthorised access is equally vital to preserve cybersecurity and protect against emerging security threats. Such access frameworks must also respect fundamental rights, ensuring inter alia that privacy and personal data are adequately protected."

and

"the preparation of a Technology Roadmap on encryption, to identify and assess technological solutions that would enable law enforcement authorities to access encrypted data in a lawful manner, safeguarding cybersecurity and fundamental rights."

--> this roadmap should be published in the first half of 2025.

Crypto wars reloaded

#e2ee#privacy#cyber

We would like to endorse what @kuketzblog writes about the inclusion of an “AI assistant” into an instant messenger that is still widely used:

It is unfortunate that many journalists do not realise how dangerous the new AI in WhatsApp really is. Der Spiegel, for example, writes in a recent article: “Meta AI does not have access to users' private chats, however, thanks to end-to-end encryption.” As a matter of fact, the AI does have access as it is used in the context of private chats or group chats. Sadly, this misinformation lulls users into a false sense of security. 🤦

Source (in German): social.tchncs.de/@kuketzblog/1

MastodonMike Kuketz 🛡 (@kuketzblog@social.tchncs.de)Es ist bedauerlich, dass viele Journalisten nicht erkennen, wie gefährlich die neue KI in WhatsApp wirklich ist. Der Spiegel schreibt bspw. in einem aktuellen Beitrag: »Zugriff auf Privatchats von Usern hat Meta AI jedoch nicht, dank der Ende-zu-Ende-Verschlüsselung.« Dabei hat die KI durchaus Zugriff, wenn sie im Kontext privater Chats oder Gruppenchats verwendet wird. So verbreiten sich leider Falschinformationen, die Nutzer in falscher Sicherheit wiegen. 🤦
#whatsapp#ai#e2ee