[PG] Main

  • Ari Yaro
    A
    well, that's that then
  • time for all the electron app devs to not patch this until half a year later
  • This reply could not be found.
    that's true, they need to start making significant mindset/outlook changes when it comes to proper security
  • this is too little and too late (although it is some solace for apps only obtained through gplay/fdroid and no direct APKs)
  • @3dprinterthing:tchncs.de
    3
    I prefer the peace of mind of obtaining builds with verifiable integrity from the original source. At least things are starting to go in the right direction, even if it's over a decade late.
  • @3dprinterthing:tchncs.de
    3
    This reply could not be found.
    Mmm nice. IP address blacklisted so can't view. Nice one.
  • Ari Yaro
    A
    In reply to
    3
    @3dprinterthing:tchncs.de

  • Mmm nice. IP address blacklisted so can't view. Nice one.
  • just use a vpn
  • or a proxy
  • @3dprinterthing:tchncs.de
    3
    I am.
  • Seems my VPN is blocked. Pretty crappy.
  • bitter_piano joined the room
  • @rr9t6:matrix.org left the room
  • gone.pushing962
    Use this then
  • Danny
    This reply could not be found.
    No
  • This reply could not be found.
    So a thief can still recover personal files. That doesnt sound secure.
  • slate-module
    S
    Would-be thief would have to get past the encryption on your device
  • ninchuka
    In reply to
    3
    @3dprinterthing:tchncs.de

  • Seems my VPN is blocked. Pretty crappy.
  • VPN IP could've been used for abuse of some kind which they blocked, unless they block all VPN IP's
  • jwayn596
    is Obsidian on the official Arch repository?
  • this isnt the AUR right
  • slate-module
    S
    yea
  • it's the Extra repo
  • jwayn596
    I thought Arch only allowed open source stuff on the official repository
  • interesting
  • slate-module
    S
    aren't they famous for not sticking to the FOSS-only mentality?
  • fibby
    F
    In reply to
    Danny

  • So a thief can still recover personal files. That doesnt sound secure.
  • if you got that from my description then I don't know how to help :D
  • slate-module
    S
    In reply to
    S
    slate-module

  • aren't they famous for not sticking to the FOSS-only mentality?
  • Like I think Ubuntu's the only other mainstream distro that offers the nvidia drivers by default
  • jwayn596
    over the past couple of weeks, i've been experimenting with Cryptomater as an alternate solution to 7zip for encrypting files. In this link in their documentation https://docs.cryptomator.org/en/latest/security/security-target/

    It says that Cryptomater is intended for Cloud storages and not Local storages. However, I had been using it solely for encrypting files on a USB Drive. Is this bad practice?
  • Valynor
    no you can put the containers anywhere you like
  • slate-module
    S
    ^
  • jwayn596

    This part of the guideline interests me particularly

    Cryptomator is not a complete replacement for other encryption tools based on container files if the aforementioned meta information should be encrypted. Cryptomator does not provide protection if programs create backup copies of the encrypted files when working with them. Such files are not detected by Cryptomator and may remain on the computer even after unlocking a vault. Cryptomator cannot provide protection if the local computer is infected with malware which reads entered passwords and file contents (e.g., files in an unlocked vault).

  • fibby
    F
    In reply to
    jwayn596

  • over the past couple of weeks, i've been experimenting with Cryptomater as an alternate solution to 7zip for encrypting files. In this link in their documentation https://docs.cryptomator.org/en/latest/security/security-target/

    It says that Cryptomater is intended for Cloud storages and not Local storages. However, I had been using it solely for encrypting files on a USB Drive. Is this bad practice?
  • It's not terrible but these containers that are intended for cloud storage use slightly different encryption that might be weaker, for example Cryptomator will still leave certain metadata basically unencrypted.
  • Valynor
    * no you can put the containers anywhere you like (USB drives are notoriously bad though)
  • slate-module
    S
    In reply to
    jwayn596

  • This part of the guideline interests me particularly

    Cryptomator is not a complete replacement for other encryption tools based on container files if the aforementioned meta information should be encrypted. Cryptomator does not provide protection if programs create backup copies of the encrypted files when working with them. Such files are not detected by Cryptomator and may remain on the computer even after unlocking a vault. Cryptomator cannot provide protection if the local computer is infected with malware which reads entered passwords and file contents (e.g., files in an unlocked vault).

  • The first bullet point is the main one you need to pay attention to IMO.
  • fibby
    F
    Depending on what you're doing with your files other encryption methods might be better suited for you. Depends on how often you want to access, where you're storing it etc.
  • slate-module
    S
    The second and third are kinda given caveats
  • jwayn596
    I've been basically experimenting with encryption using 7zip and Cryptomater, figuring out how to incorporate it into my workflow.
  • Valynor
    J
    jwayn596
    7zip is not recommended at all. you should view the encryption it offers as "nice to have" but not rely on it in any way
  • jwayn596
    In reply to
    Valynor

  • J
    jwayn596
    7zip is not recommended at all. you should view the encryption it offers as "nice to have" but not rely on it in any way
  • which is why i was looking at cryptomater, 7zip still seems useful for wrapping and sending a standalone encrypted file.
  • but even cryptomater states its not the end all be all, so I'm just looking for the tools that someone who heavily uses encryption would use
  • fibby
    F
    In reply to
    jwayn596

  • which is why i was looking at cryptomater, 7zip still seems useful for wrapping and sending a standalone encrypted file.
  • Just because 7zip is bad doesn't mean Cryptomator is the best for encrypting files for every use case. It is decent for cloud storage, but I would argue gocryptfs and cryfs are better (depending on if you prefer speed or security) for cloud storage.
  • slate-module
    S
    why?
  • fibby
    F
    But for standalone encryption of files/directories there are better suited tools.
  • Valynor
    In reply to
    jwayn596

  • but even cryptomater states its not the end all be all, so I'm just looking for the tools that someone who heavily uses encryption would use
  • there really is no ultimate solution, it's just about finding the best tool for the job, i.e. for your personal needs
  • jwayn596
    Lets say bob wants to encrypt his 4k blu ray rips to backup to the cloud.

    Jane wants to send a classified document to her boss

    Leo wants to encrypt scans of his IDs on a local drive.
  • Valynor
    J
    jwayn596
    jane should not send classified stuff over the internet ;-)
  • jwayn596
    In reply to
    Valynor

  • J
    jwayn596
    jane should not send classified stuff over the internet ;-)
  • you'd be surprised what the canadian government does 🤭
  • #1 PowerShell Fan (on Windows)
    mfw Jane is committing treason
  • fibby
    F
    One tool that I like is Kryptor.
  • But there are many out there.
  • Valynor
    In reply to
    jwayn596

  • you'd be surprised what the canadian government does 🤭
  • yeah but there are pretty clear rules how you are supposed to do this and if you deviate from that it's prison time pretty quickly
  • jwayn596
    In reply to
    Valynor

  • yeah but there are pretty clear rules how you are supposed to do this and if you deviate from that it's prison time pretty quickly
  • its just an example
  • #1 PowerShell Fan (on Windows)
    too late
  • it's prison for jane
  • jwayn596
    fine, lets say a whistleblower is sending stuff to a journalist
  • fibby
    F
    In reply to
    jwayn596

  • fine, lets say a whistleblower is sending stuff to a journalist
  • SecureDrop
  • Valynor
    In reply to
    jwayn596

  • fine, lets say a whistleblower is sending stuff to a journalist
  • use signal from a burner phone
  • fibby
    F
    * SecureDrop (sorry being unhelpful...)
  • #1 PowerShell Fan (on Windows)
    inb4 they live in a KYC SIM country
  • jwayn596
    i know the NYT has a secure drop thing on tor, but specific to just sending a file that is encryrpted, what tool would you use to encrypt a file
  • Valynor
    J
    jwayn596
    something like https://hat.sh/ perhaps
  • slate-module
    S
    picocrypt?
  • jwayn596
    interesting tool, it seems similar to
  • Valynor
    J
    jwayn596
    hat.sh is just client-side encryption/decryption though, how you are sending the file is up to you
  • but both sites make it easy for the other side to decrypt
  • jwayn596
    This is a really great tool.
  • does it upload anything to a server?
  • no nvm it says no
  • Valynor
    hat is offline, it's just an app running locally in a browser tab
  • jwayn596
    quite impressive. I'm definitely taking a look into this. If they offer a standalone crossplatform app that doesn't need a browser that would make it probably my go-to
  • but its fine as is
  • #1 PowerShell Fan (on Windows)
  • Albin joined the room
  • ceruleanix

    This message is being deleted…

  • This reply could not be found.
    ^
  • Valynor
    no memes in Main, please
  • Goldmaster joined the room
  • exaCORE
    This reply could not be found.
    Do you use a particular CMS with Astro or do you simply edit the markdown files?
  • Goldmaster
    Thought I would be best to ask here. I am wondering how did people settle on their current email service? Other than using the trials and research, but what made people say, yep this is the service to use and put their money where their mouth is?

    I'm currently using mailbox and have paid the the 3 quid but want to give fastmail a go as they seam to be ok. But I'm not sure how "trustworthy" they are. I'm not sure if they are open source.

    What are peoples thoughts, and how did other settle as I feel email is the hardest longest to sort.
  • FallenStar
    By watching YouTube videos such as Techlore's and using sites like Alternativeto.net picking an email provider was kinda simple, there are lots of good providers thankfully. Privacy Guides also has recommendations on the site.
  • fria
    a lot of times you just settle for what's the most convenient, like you might already have a gmail account so you just use gmail
  • slate-module
    S
    G
    #1 PowerShell Fan (on Windows)
    : what do you use to harden office again?
  • Goldmaster
    In reply to
    FallenStar

  • By watching YouTube videos such as Techlore's and using sites like Alternativeto.net picking an email provider was kinda simple, there are lots of good providers thankfully. Privacy Guides also has recommendations on the site.
  • Yes thank you. Mailbox is quite well recommended. I do like the features it has but I find that some are a bit over the top. Such as open talk and then a video conference thing.
  • slate-module
    S
    *
    G
    #1 PowerShell Fan (on Windows)
    : what was the tool you used to harden office?
  • Goldmaster
    In reply to
    fria

  • a lot of times you just settle for what's the most convenient, like you might already have a gmail account so you just use gmail
  • True, issue is that you often get spam in the spam inbox and well its Gmail and my younger self didn't really know that if something like Gmail is free, you're the product. When I could have used posteo. But I didn't have a credit card then
  • Plus I don't have to add any numbers or anything like that
  • slate-module
    S
    I mean the privacy aspect is fair, but how does using gmail affect how much spam you get?
  • Nate B (he/him)
    In reply to
    exaCORE

  • Do you use a particular CMS with Astro or do you simply edit the markdown files?
  • I'm not sure what "cms" is. Someone else built it for me. I just edit the markdown
  • exaCORE
    Ok thank you :)
  • Goldmaster
    In reply to
    S
    slate-module

  • I mean the privacy aspect is fair, but how does using gmail affect how much spam you get?
  • It's mainly because of how long I have used Gmail. Signed up for various accounts over the years ect and well yeah
  • Mr. Muffin changed their avatar
  • Mr. Muffin changed their name to Mr. Muffin -> @c0nfigurati0n:matrix.org
  • #1 PowerShell Fan (on Windows)
  • fria
    get rekt
  • gmc1999 joined the room

You're viewing an archive of events from 2023-10-01. Use a Matrix client to start chatting in this room.

October 2023

  1. Sun
  2. Mon
  3. Tue
  4. Wed
  5. Thu
  6. Fri
  7. Sat
  8. 1
  9. 2
  10. 3
  11. 4
  12. 5
  13. 6
  14. 7
  15. 8
  16. 9
  17. 10
  18. 11
  19. 12
  20. 13
  21. 14
  22. 15
  23. 16
  24. 17
  25. 18
  26. 19
  27. 20
  28. 21
  29. 22
  30. 23
  31. 24
  32. 25
  33. 26
  34. 27
  35. 28
  36. 29
  37. 30
  38. 31
Go
  • 12 AM
    12 AM
  • 1 AM
    1 AM
  • 2 AM
    2 AM
  • 3 AM
    3 AM
  • 4 AM
    4 AM
  • 5 AM
    5 AM
  • 6 AM
    6 AM
  • 7 AM
    7 AM
  • 8 AM
    8 AM
  • 9 AM
    9 AM
  • 10 AM
    10 AM
  • 11 AM
    11 AM
  • 12 PM
    12 PM
  • 1 PM
    1 PM
  • 2 PM
    2 PM
  • 3 PM
    3 PM
  • 4 PM
    4 PM
  • 5 PM
    5 PM
  • 6 PM
    6 PM
  • 7 PM
    7 PM
  • 8 PM
    8 PM
  • 9 PM
    9 PM
  • 10 PM
    10 PM
  • 11 PM
    11 PM

Developer options

Toggles

Backend timing

todo: window.tracingSpansForRequest

Room ID

!hivhhAIsQaZlvTdlXe:neat.chat