#e2eencryption

Thomas Fricke (he/his)thomasfricke@23.social
2025-02-10

#e2ee #e2eencryption

AMD: Microcode Signature Verification Vulnerability

"... security vulnerability in some AMD Zen-based CPUs. This vulnerability allows an adversary with local administrator privileges (ring 0 from outside a VM) to load malicious microcode patches."

github.com/google/security-res

This is exactly the attack against which #confidentialcomputing should protect us

And it won't, when the attacker has access to ring0 of the hardware. Everywhere you don't run yourself.

#cloud

2025-01-11
@Tejan Ausland @Kevin Karhan :verified: Generally, Hubzilla does optionally offer encrypted conversation.

I'm not sure, however, if it encrypts the messages themselves, including in the database, or if it only encrypts the transfer.

It only works between Hubzilla channels that have this app enabled anyway because both sides need it. This mostly reduces its availability to communication between private hubs because some major public hubs don't have it enabled at hub level, so you can't enable it on your channel either if you're on one of those hubs. And, obviously, it doesn't work for communication with anything that's ActivityPub-based.

Also, I'm not sure how up-to-date it is. It's clearly a thing from the 2010s when there was that dream of a "grid" of Hubzilla hubs as its own decentralised network with StatusNet/GNU social, diaspora*, Friendica, WordPress, LiveJournal, Tumblr, Twitter etc. as optional satellites.

#Long #LongPost #CWLong #CWLongPost #FediMeta #FediverseMeta #CWFediMeta #CWFediverseMeta #Hubzilla #Encryption #E2EE #E2EEncryption
Miguel Afonso Caetanoremixtures@tldr.nettime.org
2024-12-06

"End-to-end encryption means that the information is scrambled in transit and only the sender and recipient can access it. Regular text messages (SMS messages) and voice calls are usually not encrypted, and can be intercepted in transit or stored on a carrier’s server for extended periods of time.

Email services such as Gmail and Outlook generally offer encryption in transit, which means they can be read on the companies’ servers and by the end users. Messages that are encrypted in transit can’t be nabbed from a telecom network in an accessible format, but they could be accessed through an email service provider or a law enforcement request to that company.

End-to-end encryption—the kind offered by services like WhatsApp and Signal—is considered the best bet for privacy, particularly when paired with the option to auto-delete messages after a set period of time, says Mullin."

inc.com/jennifer-conrad/why-yo

#CyberSecurity #Privacy #Encryption #E2EEncryption #Signal

2024-12-05

So wie sich das anhört sind die Hacker durch die Vordertüre gekommen, also wahrscheinlich über diese Wiretap Schnittstellen die Provider für Strafverfolgungsbehörden einbauen müssen. Wundert einen jetzt nicht wirklich, oder? https://www.heise.de/news/Wegem-schwerem-Cyberangriff-auf-US-Provider-FBI-wirbt-fuer-Verschluesselung-10187110.html #hacking #wiretap #e2eencryption

2024-11-05

Privacy: 2+ hrs into the hearing, protecting #encryption, #privacy & stopping #spyware are finally raised, thanks to S&D's Kaljurand. But Brunner's response pits safety against privacy - a common trope of the outgoing Commissioner.

What's more, despite an outright ask for him to commit to protecting #E2EEncryption, Brunner skirts the question. A silver lining? He compliments the Parliament's position on the #CSAReg, which rejected the Commission's mass surveillance and encryption-breaking plans

2024-10-20

Just in case you missed this news and are wondering what happened to the controversial draft EU law about chat control, here it is

edri.org/our-work/dutch-decisi

#freesoftware #privacy #e2eencryption #nophasebook #nowassup

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst