#OfflinePGP

Kevin Karhan :verified:kkarhan@infosec.space
2025-05-24

@patrickcmiller which is yet another reason why I explicitly recommend to not trust #Browsers & #WebApps but use either proper clients (i.e. @monocles / #monoclesMail & @thunderbird ) or do the #airgapped #OfflinePGP method!

youtube.com/watch?v=vdab4T_CoN8

Kevin Karhan :verified:kkarhan@infosec.space
2025-04-08

@JessTheUnstill @Pibble

And yes, I treat all devices as insecure and would rather invest the time and effort needed get #TechIlliterates up to speed on the #OfflinePGP method!

Given the cheapness of storage (legitimate 1TB microSD cards exist and they ain't 4-digit items!) I'd legitimately look into #OTP #encryption and (IF I had the €€€€€€ to do so!) would even sponsor implementing it in #OpenVPN, #WireGuard and #OpenSSH (for #SSH-Tunmeling).

  • The #US is a #RogueNation with a Rogue Government! The sooner we accept this reality the sooner we can not only adjust to it but act accordingly…

I sincerely wish y'all could legitimately call me a tinfoilhat but so far I've been proven right all the time...

Kevin Karhan :verified:kkarhan@infosec.space
2025-03-27
Kevin Karhan :verified:kkarhan@infosec.space
2025-02-11

@Chiquidrakula @COSAntiFascists @iris @Em0nM4stodon @cryptoparty@mastodon.earth @cryptoparty@chaos.social

Now if you don't trust @monocles nor @protonprivacy (which IMHO is fair and correct!) and you can't use @thunderbird or something because you have no private computer with internet access [i.e. only a work-issued laptop you can't use for anything non-work - related] and you can't just boot into @tails_live / @tails / #Tails or a portable #Linux #Desktop distro at all then the real "#GalaxyBrainChair" - level "#BigThink" you can do is go the "#OfflinePGP" route and thus encrypt & decrypt your messages on a different device entirely.

  • The main problem may be that you'd then have to get that to the machine from which you can send it, which as we all know from the #MattKC video means you gotta "keep it brief" [as in 2.944 bytes short] if you want to do the webcam & screen method of #airgapping...

I just didn't have time to get the "Airgapped Transfer Protocol" done, but setting the *"Barcode Scanner" App into bulk mode makes it less tedious to import stuff to an Android device...

  • Again: The nice part with #OpenPGP & #PGP/MIME is that you don't have to trust anyone but yourself and maybe your communication partners' ability to make proper #Keys and get the #Pubkey to you...
Kevin Karhan :verified:kkarhan@infosec.space
2025-01-21

@anelki the only ones that believe in "#SecureEmail" after #DNMX, #SkyECC, #EncroChat, #ANØM aka. #OperationIronside aka. #OperationTrøjanShield are #TechIlliterates!

Use #OfflinePGP-Method or @tails_live / @tails / #Tails or don't even bother!!!

Kevin Karhan :verified:kkarhan@infosec.space
2024-08-29

@GrapheneOS @signalapp I didn't say all of them have it...

Re: #Signal I'd not consider it #disinfo as we've seen more elaborate Setups like #EncroChat & #ANØM fall.

I remember when #Signal did a good #E2EE Messenger (#TextSecure) and that had a reason to use #PhoneNumbers as it merely encrypted #SMS, but that OFC has other issues.

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst