- Ari YaroAwell, that's that then
- time for all the electron app devs to not patch this until half a year later
that's true, they need to start making significant mindset/outlook changes when it comes to proper securityThis reply could not be found.- this is too little and too late (although it is some solace for apps only obtained through gplay/fdroid and no direct APKs)
- @3dprinterthing:tchncs.de3I prefer the peace of mind of obtaining builds with verifiable integrity from the original source. At least things are starting to go in the right direction, even if it's over a decade late.
- @3dprinterthing:tchncs.de3
Mmm nice. IP address blacklisted so can't view. Nice one.This reply could not be found. - Ari YaroAjust use a vpn
In reply to
3@3dprinterthing:tchncs.deMmm nice. IP address blacklisted so can't view. Nice one. - or a proxy
- @3dprinterthing:tchncs.de3I am.
- Seems my VPN is blocked. Pretty crappy.
- bitter_piano joined the room
- @rr9t6:matrix.org left the room
- gone.pushing962Use this then
- Danny
NoThis reply could not be found.
So a thief can still recover personal files. That doesnt sound secure.This reply could not be found.- slate-moduleSWould-be thief would have to get past the encryption on your device
- ninchukaVPN IP could've been used for abuse of some kind which they blocked, unless they block all VPN IP's
In reply to
3@3dprinterthing:tchncs.deSeems my VPN is blocked. Pretty crappy. - jwayn596is Obsidian on the official Arch repository?
- this isnt the AUR right
- slate-moduleSyea
- it's the Extra repo
- jwayn596I thought Arch only allowed open source stuff on the official repository
- interesting
- slate-moduleSaren't they famous for not sticking to the FOSS-only mentality?
- fibbyFif you got that from my description then I don't know how to help :D
In reply to
DannySo a thief can still recover personal files. That doesnt sound secure. - slate-moduleSLike I think Ubuntu's the only other mainstream distro that offers the nvidia drivers by default
In reply to
Sslate-modulearen't they famous for not sticking to the FOSS-only mentality? - jwayn596over the past couple of weeks, i've been experimenting with Cryptomater as an alternate solution to 7zip for encrypting files. In this link in their documentation https://docs.cryptomator.org/en/latest/security/security-target/
It says that Cryptomater is intended for Cloud storages and not Local storages. However, I had been using it solely for encrypting files on a USB Drive. Is this bad practice? - Valynorno you can put the containers anywhere you like
- slate-moduleS^
- jwayn596
This part of the guideline interests me particularly
Cryptomator is not a complete replacement for other encryption tools based on container files if the aforementioned meta information should be encrypted. Cryptomator does not provide protection if programs create backup copies of the encrypted files when working with them. Such files are not detected by Cryptomator and may remain on the computer even after unlocking a vault. Cryptomator cannot provide protection if the local computer is infected with malware which reads entered passwords and file contents (e.g., files in an unlocked vault).
- fibbyFIt's not terrible but these containers that are intended for cloud storage use slightly different encryption that might be weaker, for example Cryptomator will still leave certain metadata basically unencrypted.
In reply to
jwayn596over the past couple of weeks, i've been experimenting with Cryptomater as an alternate solution to 7zip for encrypting files. In this link in their documentation https://docs.cryptomator.org/en/latest/security/security-target/
It says that Cryptomater is intended for Cloud storages and not Local storages. However, I had been using it solely for encrypting files on a USB Drive. Is this bad practice? - Valynor* no you can put the containers anywhere you like (USB drives are notoriously bad though)
- slate-moduleSThe first bullet point is the main one you need to pay attention to IMO.
In reply to
jwayn596This part of the guideline interests me particularly
Cryptomator is not a complete replacement for other encryption tools based on container files if the aforementioned meta information should be encrypted. Cryptomator does not provide protection if programs create backup copies of the encrypted files when working with them. Such files are not detected by Cryptomator and may remain on the computer even after unlocking a vault. Cryptomator cannot provide protection if the local computer is infected with malware which reads entered passwords and file contents (e.g., files in an unlocked vault).
- fibbyFDepending on what you're doing with your files other encryption methods might be better suited for you. Depends on how often you want to access, where you're storing it etc.
- slate-moduleSThe second and third are kinda given caveats
- jwayn596I've been basically experimenting with encryption using 7zip and Cryptomater, figuring out how to incorporate it into my workflow.
- ValynorJjwayn596 7zip is not recommended at all. you should view the encryption it offers as "nice to have" but not rely on it in any way
- jwayn596which is why i was looking at cryptomater, 7zip still seems useful for wrapping and sending a standalone encrypted file.
In reply to
ValynorJjwayn596 7zip is not recommended at all. you should view the encryption it offers as "nice to have" but not rely on it in any way - but even cryptomater states its not the end all be all, so I'm just looking for the tools that someone who heavily uses encryption would use
- fibbyFJust because 7zip is bad doesn't mean Cryptomator is the best for encrypting files for every use case. It is decent for cloud storage, but I would argue gocryptfs and cryfs are better (depending on if you prefer speed or security) for cloud storage.
In reply to
jwayn596which is why i was looking at cryptomater, 7zip still seems useful for wrapping and sending a standalone encrypted file. - slate-moduleSwhy?
- fibbyFBut for standalone encryption of files/directories there are better suited tools.
- Valynorthere really is no ultimate solution, it's just about finding the best tool for the job, i.e. for your personal needs
In reply to
jwayn596but even cryptomater states its not the end all be all, so I'm just looking for the tools that someone who heavily uses encryption would use - jwayn596Lets say bob wants to encrypt his 4k blu ray rips to backup to the cloud.
Jane wants to send a classified document to her boss
Leo wants to encrypt scans of his IDs on a local drive. - ValynorJjwayn596 jane should not send classified stuff over the internet ;-)
- jwayn596you'd be surprised what the canadian government does 🤭
In reply to
ValynorJjwayn596 jane should not send classified stuff over the internet ;-) - #1 PowerShell Fan (on Windows)mfw Jane is committing treason
- fibbyFOne tool that I like is Kryptor.
- But there are many out there.
- Valynoryeah but there are pretty clear rules how you are supposed to do this and if you deviate from that it's prison time pretty quickly
In reply to
jwayn596you'd be surprised what the canadian government does 🤭 - jwayn596its just an example
In reply to
Valynoryeah but there are pretty clear rules how you are supposed to do this and if you deviate from that it's prison time pretty quickly - #1 PowerShell Fan (on Windows)too late
- it's prison for jane
- jwayn596fine, lets say a whistleblower is sending stuff to a journalist
- fibbyFSecureDrop
In reply to
jwayn596fine, lets say a whistleblower is sending stuff to a journalist - Valynoruse signal from a burner phone
In reply to
jwayn596fine, lets say a whistleblower is sending stuff to a journalist - fibbyF* SecureDrop (sorry being unhelpful...)
- #1 PowerShell Fan (on Windows)inb4 they live in a KYC SIM country
- jwayn596i know the NYT has a secure drop thing on tor, but specific to just sending a file that is encryrpted, what tool would you use to encrypt a file
- ValynorJjwayn596 something like https://hat.sh/ perhaps
- slate-moduleSpicocrypt?
- jwayn596interesting tool, it seems similar to
- ValynorJjwayn596 hat.sh is just client-side encryption/decryption though, how you are sending the file is up to you
- but both sites make it easy for the other side to decrypt
- jwayn596This is a really great tool.
- does it upload anything to a server?
- no nvm it says no
- Valynorhat is offline, it's just an app running locally in a browser tab
- jwayn596quite impressive. I'm definitely taking a look into this. If they offer a standalone crossplatform app that doesn't need a browser that would make it probably my go-to
- but its fine as is
- #1 PowerShell Fan (on Windows)
- Albin joined the room
- ceruleanix
This message is being deleted…
^This reply could not be found.- Valynorno memes in Main, please
- Goldmaster joined the room
- exaCORE
Do you use a particular CMS with Astro or do you simply edit the markdown files?This reply could not be found. - GoldmasterThought I would be best to ask here. I am wondering how did people settle on their current email service? Other than using the trials and research, but what made people say, yep this is the service to use and put their money where their mouth is?
I'm currently using mailbox and have paid the the 3 quid but want to give fastmail a go as they seam to be ok. But I'm not sure how "trustworthy" they are. I'm not sure if they are open source.
What are peoples thoughts, and how did other settle as I feel email is the hardest longest to sort. - FallenStarBy watching YouTube videos such as Techlore's and using sites like Alternativeto.net picking an email provider was kinda simple, there are lots of good providers thankfully. Privacy Guides also has recommendations on the site.
- friaa lot of times you just settle for what's the most convenient, like you might already have a gmail account so you just use gmail
- slate-moduleSG#1 PowerShell Fan (on Windows): what do you use to harden office again?
- GoldmasterYes thank you. Mailbox is quite well recommended. I do like the features it has but I find that some are a bit over the top. Such as open talk and then a video conference thing.
In reply to
FallenStarBy watching YouTube videos such as Techlore's and using sites like Alternativeto.net picking an email provider was kinda simple, there are lots of good providers thankfully. Privacy Guides also has recommendations on the site. - slate-moduleS*G#1 PowerShell Fan (on Windows): what was the tool you used to harden office?
- GoldmasterTrue, issue is that you often get spam in the spam inbox and well its Gmail and my younger self didn't really know that if something like Gmail is free, you're the product. When I could have used posteo. But I didn't have a credit card then
In reply to
friaa lot of times you just settle for what's the most convenient, like you might already have a gmail account so you just use gmail - Plus I don't have to add any numbers or anything like that
- slate-moduleSI mean the privacy aspect is fair, but how does using gmail affect how much spam you get?
- Nate B (he/him)I'm not sure what "cms" is. Someone else built it for me. I just edit the markdown
In reply to
exaCOREDo you use a particular CMS with Astro or do you simply edit the markdown files? - exaCOREOk thank you :)
- GoldmasterIt's mainly because of how long I have used Gmail. Signed up for various accounts over the years ect and well yeah
In reply to
Sslate-moduleI mean the privacy aspect is fair, but how does using gmail affect how much spam you get? - Mr. Muffin changed their avatar
- Mr. Muffin changed their name to Mr. Muffin -> @c0nfigurati0n:matrix.org
- #1 PowerShell Fan (on Windows)
- friaget rekt
- gmc1999 joined the room