#onionservice

OMG 🇪🇺 🇺🇦 :linux:pascal_f@infosec.exchange
2025-05-21

@kkarhan
Hab ich schon einmal angeregt.

Direktvertrieb mit Gehaltsband ohne überflüssige Recruiter, die eh nur lügen.

Und einer der Stelle repräsentativ entsprechenden Person. Azubis und Berufsanfänger, die noch zu Hause wohnen und nebenbei studieren sind eher ungeeignet, eine längere Karriere zu überblicken.

Bei den harten Auflagen schafft aber ohne Umschulung niemand, was zu posten.😃

#WasFehlt #Stellenmarkt #Bullshit #Gehaltstransparenz #Filler #Arbeitszeiten #Arbeitsort #Vertragsart #Gehalt #Bewertungen #KI #ChatBots #BotAccounts #Spam #Werbung #Moderatoren #Meldungen #JavaScript #Cookies #Tracking #Kontaktdaten #OnionService #Tor #eMail #PGP #XMPP #OMEMO #Chat #WebCall #Bewerbungsgespräche #BuzzwordBingo

Kevin Karhan :verified:kkarhan@infosec.space
2025-05-12

@lukeshu So I guess #Anubis has an explicit exception to handle #Lynx and will instead rely on rate-limits and other static means to detect #scrapers and handle with #UserAgent #abuse cases, like #fail2ban-style autobanning of violating IPs...

  • This makes sense for a #WAF like Anubis and would've been the only viable option I'm aware of.

I wounder if anyone has tried using Anubis on @torproject / #Tor to protect #OnionService|s since that would be a reasonable application for it as well.

2025-05-09

#Tor is mainly known for the anonymity it provides, but the #onionservice is also awesome for easy networking and #encryption I just made my #yacy instance accessible via a .onion-addresse in about 10 Minutes.

@torproject is awesome! @orbiterlab

BOFH [Braydmedia Admin]BOFH@glitch.braydmedia.de
2025-05-03
Kevin Karhan :verified:kkarhan@infosec.space
2025-04-28

@ranjit yes!

Kevin Karhan :verified:kkarhan@infosec.space
2025-04-27

@woffs @stefanmuelller wenn die von @tazgetroete ist werd' ich die in meine Liste an #OnionService|s packen...

Kevin Karhan :verified:kkarhan@infosec.space
2025-04-26

@stefanmuelller @tazgetroete was ich hoffe: #taz macht nen #OnionService auf und verweigert sich #Schutzgelderpressern wie #ClownFlare weiterhin!

Kevin Karhan :verified:kkarhan@infosec.space
2025-04-22

@debby that assumes @protonprivacy actually cares about #Privacy, which they evidently don't, cuz otherwise they'd never even #log or #request any #PII to begin with and instead offer their Services via @torproject / #Tor as #OnionService

  • Not to mention they fuck around with customers' #eMails, thus having prevented people from contributing to the #LKML in the past...

To me this isn't a big loss, but a conditionless surrender in favour of better competitiors like @monocles and even @Stuxhost for that matter...

100% TAX ✅ ✅shoppingtonz
2025-03-31

Tor onion service joke...

Facebook's v3. "You’re Temporarily Blocked"
JOKE

Not a joke. The opposite! Successes!:
* BBC News 2+ v3s ❕❕❕
* Reddit's v3 works fine!
* The Guardian v3!
* Voice of America 3+ v3s ❕❕❕

Kevin Karhan :verified:kkarhan@infosec.space
2025-03-30

Still no #VPN fan but @airvpn / #AirVPN at least has a purpose given they have an #OnionService at: airvpn3epnw2fnsbx5x2ppzjs6vxtd

Kevin Karhan :verified:kkarhan@infosec.space
2025-03-27

@pixelcode @taylan Your nonchalant "So what?" gets people publicly murdered by the state in many juristictions...

  • Which is why there is no substitute to teaching proper #TechLiteracy ffs!

If things were so easy as in "JuSt UsE sIgNaL!" then @signalapp would be shut down.

If you do think so then you should really get some professional help, cuz you seem rather lost...

  • #Signal doesn't even bother to have an #OnionService, much less to provide means to use their service without self-doxxing with a #PhoneNumber, which at best is pseudonymous and requires money to attain and maintain...

It's #centralization is an absolute nightmare and mist be deemed as criminally neglectful!

Kevin Karhan :verified:kkarhan@infosec.space
2025-03-27

@Andromxda @pixelcode How can you claim something you can't evidence?

It makes you look like one of those folks shilling #VPN|s that ain't logless after all...

  • I don't believe in #marketing #lies and #Signal can't (and won't) be able to evidence that they don't log shit.

At least they should be honest about things and not claim bs, cuz demanding a #PhoneNumber is just #KYC with extra steps like demanding any #SSN or other #PII. Makes them look like chinese MMORPGs that demand ID card numbers for account signups, thus #paywalling the ability to use their service anonymously...

Kevin Karhan :verified:kkarhan@infosec.space
2025-03-26

@signalapp It's not #disinfo when one points out that you demand #PII aka. #PhoneNumbers from Users and that is literally a architectural vulnerability, alongside your #proprietary & #Centralized #Infrastructure.

Not to mention the lack of @torproject / #Tor support with an #OnionService or the willingness to fulfill #cyberfacist "Embargoes" or shilling a #Shitcoin #Scam named #MobileCoin!

  • #KYC is the illicit activity!!!

And don't get me started on the #cyberfacism that is #CloudAct.

  • If you were secure, criminals would've used your platform so hard, it would've been shutdown like #EncroChat and #SkyECC.

I may nit have allvthe.evidence yet, but #Signal stenches like #ANØM: #Honeypot-esque!

Kevin Karhan :verified:kkarhan@infosec.space
2025-03-25

@froge @forthy42 @fj to me, @signalapp being centralized and not even doing tue absolute minimum of supporting @torproject / #Tor and having at least an #OnionService as #API-Endpoint makes them #UsefulIdiots.

It's several things like that that rubvme the wrong way and that make it uncomfortable.

Kevin Karhan :verified:kkarhan@infosec.space
2025-03-19

@ckrypto if@signalapp@mastodon.world wasn't complying with #CloudAct, @Mer__edith would be in jail.

Not to mention even if Signal keeps their "#OpenSource" code updated - which is doubtful, NOONE can actually #verify that it's the code you actually use - regardless if #backend / #Server or #client / #App!

  • #Signal is as secure as #ANØM, otherwise it would've been shutdown ages ago.

Also if Signal was designed for #security, it would've been #decentralized as #XMPP+#OMEMO and not demand #PII like #PhoneNumbers which oftentimes cannot be obtained anonymously in many juristictions at all!

By comparison, @delta doesn't require any PII, only an #eMail account, and @monocles isn't a #VCmoneyBurningParty but sustainable due to #subscription and they don't even require any personal details for #payment: #CashByMail and #Monero are accepted.

Again: It's Signal alone who have to evidence they are trustworthy, and all I get are "#TrustMeBro!" replies, which means they are not to be trusted.

  • Not to mention, it's just not sustainable to run a #service without #revenue, even if it's run entirely by unpaid volunteers and gets all it's #hosting and #costs donated, someone has to pay for expenses due to #abuse of a service (which is an inevitability come mass adoption)...

Whereas with #XMPP I can completely setup my own server and client, even build my own if I don't trust anyone else and pay someone to audit the code.

Whereas with XMPP & PGP/MIME #eMail I can layer @torproject / #Tor over it, make it an #OnionService and keep that thing under my bed with a literal killswitch...

Kevin Karhan :verified:kkarhan@infosec.space
2025-03-16

@CppGuy @fesshole the only thibg you can do is force Google to nuke history and take it as lession to use #DuckDuckGo's #OnionService on @torproject / #TorBrowser instead.

Kevin Karhan :verified:kkarhan@infosec.space
2025-02-26

@Natanox @ccc@anonsys.net @chaosupdates @CCC@social.bau-ha.us @ccc@chaos.social @ccchh leider ist m2ylflyeak6i6o4hsfwcrfwcq2bbjxk6nf2rnmm7fu6qiuu3hybenzid.onion / jabber.ccc.de #OnionService immernoch down!

Kevin Karhan :verified:kkarhan@infosec.space
2025-02-21

@truls46 #facehoof

  • Deshalb schaut mensch vorher sich um.

Ich empfehle nur Server die ich selbst getestet habe, außerdem hilft @torproject / #Tor & @guardianproject / #Orbot dabei, diese idealerweise als #OnionService zu erreichen.

  • Wo keine #PII wie #Telefonnummer oder #IPs verlangt, abgefragt, übermittelt oder gespeichert werden, können diese auch nicht ausgehändigt werden.
Kevin Karhan :verified:kkarhan@infosec.space
2025-02-21

@erebion @inaruck genau das ist der Falsche Ansatz, da Threat Models sich ständig verschieben und nicht ausgegangen werden kann, dass es dabei bleibt.

Keine*r deloyed drölfzig Messenger oder migriert bedarfsweise User*innen umher.

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst