#CashByMail

Kevin Karhan :verified:kkarhan@infosec.space
2025-12-07

@opensourceopenmind @ArneBab also it's a matter of principle.

  • It's being criminalized to get an anonymous phone # in the first place, and the sheer demand fir something like that is neither excuseable nor relevant.

There are more efficient means to discourage scammers & spammers without destroying #privacy.

Worst-case make it a commercial service that is a subscription one can pay via #Monero and/or #CashByMail!

Kevin Karhan :verified:kkarhan@infosec.space
2025-11-21

@schnur und @Tutanota soweit ich weiß unterstützt kein #IMAP & #SMTP.

Ich selbst rate zu @monocles weil dies jene Standards untrtstützt, nicht gegen @torproject / #Tor & #VPN-Nutzer diskriminiert und neben #Monerovauch #CashByMail als Zahlungsmethode akzeptieren!

Kevin Karhan :verified:kkarhan@infosec.space
2025-11-18

@blueghost @thegoodcloud nifty...

Personally I can vouch for @monocles / #monoclesOcean which is a #Nextcloud without much fuss that can be paid for #CashByMail & #Monero as well as #SEPA, #Stripe & #PayPal and @Stuxhost which comes with @CollaboraOffice included.

Both use @nextcloud at their core and I do like how #Nextcloud really makes it simple to do #ManagedServices & #SelfHosting without feature disparity!

Kevin Karhan :verified:kkarhan@infosec.space
2025-10-20

@tiefling @thegaffer If you have a #NAS (personally I'm not a fan of #Synology as I had to work with their products professionally!) then OFC it makes sense to use it...

Besides its completely anonymous to use with #CashByMail and #Monero as payment options...

Kevin Karhan :verified:kkarhan@infosec.space
2025-07-08

@smote legally yes, practically no because already the #prohibitionist shite has already migrated away from that.

  • Note the fine wording here, which only states "crypto asset service providers [...] maintaining anonymous accounts"...

Exchanges like #ChangeNow will just do #KYC and everyone who doesn't want/can will merely go to back alleys and swap that way or simply use non-EU exchanges and/or swap Monero into some shitcoins and/or the other way around.

  • Obviously neither recommending nor vouching for any services for obvious reasons. All I'm saying is that it's never about #MoneyLaundering or #CTF, but merely exerting #Cyberfacism against #TechIlliterates whilst those that do want to facilitate illicit business have enough mules in traditional finance...

Again: #CashByMail is still not illegal...

#NotLegalAdvice #NotFinancialAdvice #EUpol #Monero

Kevin Karhan :verified:kkarhan@infosec.space
2025-07-08

@smote Do you think #TradFinance is any less bad?

  • #Banksters love filthy money, otherwise every big banking hub and all the dictatorships in the MENA region invested in *washing their dictatorships would be sanctioned harder than North Korea.

  • #Monero is the "least worst" in terms of #Cryptocurrency. I don't deny the problem. I just have yet to see a "lesser evil" that doesn't demand trust into centralized entities to not steal money or cancel accounts.

Again: #CashByMail does still exist!

#NotLegalAdvice #NotFinancialAdvice #sarcasm

Kevin Karhan :verified:kkarhan@infosec.space
2025-07-08

@finalstaticfox @dansup nodds in agreement...

infosec.space/@kkarhan/1148181

Kevin Karhan :verified:kkarhan@infosec.space
2025-07-08

@jmcs @dansup given how #PayPal bans people at random (and refuses to elaborate why when asked for, as said person hasn't violated their ToS!) I'd not trust them either.

So if you don't trust #cryptocurrency at all [which I don't blame you for when there's only one non - #Shitcoin on the market], consider #CashByMail instead.

Kevin Karhan :verified:kkarhan@infosec.space
2025-06-17

@derekmorr

Let it go, already. No one uses MobileCoin. You can’t even find an exchange to buy it.

Then why does @signalapp still have that shit in it? @Mer__edith could've pulled that #Shitcoin yet refuses to do do!

The Cloud Act is a non-issue. Signal doesn’t have data on users, so they can’t be forced to disclose it.

That's literally wrong!

  • #Signal not only collects #PII in the form of a #PhoneNumher but explicitly is able and willing to use that to dsicriminate against users and restrict app functionality based off their presumed juristiction. There is no "legitimate interest" for.doing so nor any legal mandate to do so (unless we excuse the ehole #MobileCoin-#Scam!)

It’s been 30 years, and no one uses xmpp. Let it go.

Wrong again. Otherwise there wouldn't be thriving ecosystems and Apps to this day. It's just that corporate shills refuse to acknowledge that Signal - like all centralized, proprietary, #SingleVendor and/or #SingleProvider kessengers before and after - will inevitably die as their business model is not sustainable. Sake with #ICQ really. The only exceptions are those that abolish #privacy for #profit, integrate actually working payments or sellout to a #cyberfacist #government (all those apply to #WeChat!)

It’s shocking that people who claim to care about security and privacy push niche apps with terrible UX and no PFS like Delta or XMPP instead of the only private messenger with any real market share, Signal.

You know what's shocking to me: People who are unable or rather unwilling.to acknowledge that Signal is garbage and it's requirement for a #PhoneNumber kills any #privacy benefits it may have on paper by virtue of being at best pseudonymous (assuming the userd don't live in a juristiction that demands "#KYC" for even prepaid #SIM cards (ime. #Germany) or god forbid even #IMEI|s (i.e. #Turkey has a literal allowlist that'll kick any device off it's MNOs after 90 days within 365 days.

  • The #UScentric approach to #privacy and #threats makes Signal absolutely useless in many cases, and I do speak here from experience.

I'd rather help people onboard #XMPP+#OMEMO like @monocles and/or @gajim or #PGP/MIME like @delta & @thunderbird (incl. setting them up with #Orbot / #TorBrowserBundle / @tails_live so their traffic gets through @torproject and doesn't provide any useable IP addresses.

  • I've literally been there and done that!

As for #Sustainability, providers like monocles.eu finance themselves by subscriptions (starting at €2 p.m.) which people can pay fully anonymous using #CashByMail and #Monero on top of common payment methods (i.e. SEPA wire transfer)...

  • So even if you think "#monocles is a #honeypot" that is mitigateable ciz unlike with Signal you can choose your own client, choose a different provider & exervise self-custody of all tue keys!
Kevin Karhan :verified:kkarhan@infosec.space
2025-05-07

@Linux for @monocles it's about their mail & messaging solutions which are subscription-financed and in return just work on any devices as well as their nextcloud.

The ither two I can understand fully...

Kevin Karhan :verified:kkarhan@infosec.space
2025-05-06

@debby @monocles @Stuxhost well, @delta / #deltaChat is not using #XMPP+#OMEMO (unlike #monoclesChat & #gajim) but #PGP/MIME on regular #eMail, which makes it way easier to setup in organizations as not "yet another server needed" and also easier to comply with mandatory #archival laws in #business use-cases.

Kevin Karhan :verified:kkarhan@infosec.space
2025-04-21

@Linux @jeffowski you need some help?

Personally I'd recommend @monocles as they request no #PII and support anonymous payment incl. #CashByMail & #Monero!

Kevin Karhan :verified:kkarhan@infosec.space
2025-04-08

@linuxer @stormii @karl_ist_super ja, sowas wie @monocles / #monoclesChat, @gajim / #gajim & @delta / #deltaChat...

  • Nur weil etwas alle/die meisten machen wird's nicht weniger falsch!

Natürlich kannste #Signal nutzen, nur dann musste halt auch drauf klarkommen dass so zentralisierter shice durch eine christofaschistische Regierung (#USA) irgendwann eingestampft wird.

  • Davon dass es eine bescheuerte Idee ist aus gründen von #Datenschutz, einen Anbieter zu nutzen der ne #Telefonnummer verlangt mal abgesehen.

#Monocles verlangt hingegen garkeine Daten und erlaubt anonymes Bezahlen per #Monero & #CashByMail !

#thxbye #EOD

Kevin Karhan :verified:kkarhan@infosec.space
2025-03-25

@froge @fj I'm not replacing @signalapp with "random tools" but good options.

Like @delta & @thunderbird as well as @monocles / #monoclesChat & @gajim which work flawlessly over @torproject / #Tor using @tails / @tails_live / #Tails and @guardianproject / #Orbot respectably.

Considering the costs of even acquiring and upkeeping an #anonymous #SIM, I'd rather pay €2 p.m. for #XMPP+#OMEMO and #PGP/MIME-supported #eMail with the option of self-custody than $2,50+ p.m. just to keep a phone number.

Or is anyone here expecting @Mer__edith to risk jail for life amd not comply with #CloudAct?

It stenches like #ANØM, because NOTHING IS FOR FREE and running a #VCmoneyBurningParty is expensive...

Kevin Karhan :verified:kkarhan@infosec.space
2025-03-22

@cmccullough that being said I can recommend @monocles which do not require any #PII wjatsoever and allow #anonymous payment via #Monero & #CashByMail!
monocles.eu/more/#payment-sect

Another option may be @Stuxhost ...

Kevin Karhan :verified:kkarhan@infosec.space
2025-03-19

@ckrypto if@signalapp@mastodon.world wasn't complying with #CloudAct, @Mer__edith would be in jail.

Not to mention even if Signal keeps their "#OpenSource" code updated - which is doubtful, NOONE can actually #verify that it's the code you actually use - regardless if #backend / #Server or #client / #App!

  • #Signal is as secure as #ANØM, otherwise it would've been shutdown ages ago.

Also if Signal was designed for #security, it would've been #decentralized as #XMPP+#OMEMO and not demand #PII like #PhoneNumbers which oftentimes cannot be obtained anonymously in many juristictions at all!

By comparison, @delta doesn't require any PII, only an #eMail account, and @monocles isn't a #VCmoneyBurningParty but sustainable due to #subscription and they don't even require any personal details for #payment: #CashByMail and #Monero are accepted.

Again: It's Signal alone who have to evidence they are trustworthy, and all I get are "#TrustMeBro!" replies, which means they are not to be trusted.

  • Not to mention, it's just not sustainable to run a #service without #revenue, even if it's run entirely by unpaid volunteers and gets all it's #hosting and #costs donated, someone has to pay for expenses due to #abuse of a service (which is an inevitability come mass adoption)...

Whereas with #XMPP I can completely setup my own server and client, even build my own if I don't trust anyone else and pay someone to audit the code.

Whereas with XMPP & PGP/MIME #eMail I can layer @torproject / #Tor over it, make it an #OnionService and keep that thing under my bed with a literal killswitch...

Kevin Karhan :verified:kkarhan@infosec.space
2025-02-21

@truls46 Ein gutes Gegenbeispiel zu @signalapp ist @monocles / #monoclesChat:

Ich denke mal das sollte hinreichend meine Argumebte darlegen.

  • Kernpunkt ist und bleibt: Signal ist bestenfalls gemeingefährlich-inkompetent oder ein #Honeypot!
Kevin Karhan :verified:kkarhan@infosec.space
2025-02-13

@Beggarmidas @Em0nM4stodon

For comparison monocles / @monocles doesn't collect any #PII whatsoever and one can get their #Apps not only for free (or choose one's own #clients because unlike #Signal they only use open & standardized protocols!) but also pay using #CashByMail and #Monero for maximum #privacy.

So it's not a #VCmoneyBurningParty but actually #sustainable!

Kevin Karhan :verified:kkarhan@infosec.space
2025-02-11

@Chiquidrakula @COSAntiFascists @iris @Em0nM4stodon @cryptoparty@mastodon.earth @cryptoparty@chaos.social @thunderbird

#FACT: It's not real #E2EE unless you have100% #SelfCustody of all the keys!

Thus the correct way as #monoclesMail says is to use your own client and keep your keys to yourself.

Now OFC, monocles charge €2 p.m. for their starter account but they also accept #SEPA #WireTransfer, #Monero, #CashByMail, #Stripe and #PayPal for #payments, so it's pretty flexible and affordable given they don't put #ads in your #inbox or invade user privacy!

Kevin Karhan :verified:kkarhan@infosec.space
2025-01-23

@lucasmz @Avitus @david_chisnall the benefit of #XMPP+#OMEMO is that there are several providers, including free options...

All #PII incl. #PhoneNumbers can and will be abused by existing governments and if users don't pay, then they are the product and their data is the one to be sold.

After all, you have the same cost problem with phone numbers. Even if one doesn't pay per line/number and never pay for calls and texts, they still have to top it up to extent validity.

  • And again: It's way easier for a government to demand an ID for a #SIM that works in networks around their country (i.e. #Turkey demands registration on a per-#IMEI - basis *with #ID) than to tunnel XMPP+OMEMO through @torproject over #EDGEland-speed #2G networks.

Plus you relying an unfixably insecure #Telephony makes a system inherently unsafer than it needs to be...

  • This is how people get caught!

Also #Signal is able and willing to use said PII to restrict and ban users and if I were some dissident in Cuba or North Korea or even just Eritrea or Yemen I'd not rely on non-enforcement of #OFAC / #USML / #ITAR since Signal can obviously distinguish & identify accounts by virgue if their #PhoneNumber!

  • Always think "How can this be weaponized against someone?" when it comes to #privacy!

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst