@h4ckernews@mastodon.social avatar h4ckernews Bot , to random
@iodomi@infosec.exchange avatar iodomi , to random

Hi, I'm pleased to show you this new project

Introducing, OnionNote :ablobcatmaracasevil: it is a anonymous, open source and end-to-end encrypted pastebin service that is ran on Tor. It features:

  • AES-256-GCM encryption algorithm
  • Zero logs, cookies, javascript or identifiers
  • Randomized file timestamps
  • Burn after read and expiration time
  • Additional password protection

Source code: https://codeberg.org/OnionNote/OnionNote
Public instance: http://moout2vwirwzzhcpzi5j5fhkujpcekjjuzmqcf7cbwsgxxm2cgvupxyd.onion/

Also if you want to support this project, please consider donating thru BTC or XMR (addresses are on the onion website)!

@h4ckernews@mastodon.social avatar h4ckernews Bot , to random
@h4ckernews@mastodon.social avatar h4ckernews Bot , to random
@Linux@mastodon.cr avatar Linux , to random

🤦

"WhatsApp cannot be trusted, because META (Facebook) is likely spying on everyone."

"Oh yeah, totally! They're working closely with the United States government, and who knows what they'll do now that they've embraced fascism?!"

"So, what should we use?"

"I have an idea! Let's use Signal — supposedly super secret and private — but also based in the United States. And let’s just completely ignore that fact."

"Sounds good to me!"

🤦

I don’t understand — perhaps I never will — why, when people are given unlimited choices, society collectively picks the dumb one.

There are alternatives, and they’re outside the reach of the United States:

https://codeberg.org/Linux-Is-Best/Outside_US_Jurisdiction/src/branch/main/Encrypted_Messages.md

@h4ckernews@mastodon.social avatar h4ckernews Bot , to random
@h4ckernews@mastodon.social avatar h4ckernews Bot , to random
@h4ckernews@mastodon.social avatar h4ckernews Bot , to random
lorentz , to Selfhosted in Encrypting data on local servers?

If you want to encrypt only the data partition you can use an approach like https://michael.stapelberg.ch/posts/2023-10-25-my-all-flash-zfs-network-storage-build/#encrypted-zfs to ulock it at boot.

TL;DR: store half of the decryption key on the computer and another half online and write a script that at boot fetches the second half and decrypt the drive. There is a timewindow where a thief could decrypt your data before you remove the key if they connect your computer to the network, but depending on your thread model can be acceptable.
you can also decrypt the root portion with a similar approach but you need to store the script in the initramfs and it is not trivial.

Another option I've seen suggested is storing the decryption key on a USB pendrive and connect it with a long extension cord to the server. The assumption is that a thief would unplug all the cables before stealing your server.

@techlore@social.lol avatar techlore , to random

For many years, people have asked me if it's safe to keep 2FA codes in the same place as your passwords. Here's my opinion on whether or not you should do it:
https://youtu.be/xHEX6wWYgS0

samuel ,
@samuel@social.familylison.com avatar

@techlore proton pass is good in that your data on proton pass is fully . So if you use a hardware based such as a to secure the main account, and have all your other accounts within use software based passkeys and 2FA, wouldn't be as much of a risk even if Proton Pass got breached as a service.

@ProPublica@newsie.social avatar ProPublica , to random

Some of the data used by Cambridge Analytica highlighted gun owners’ most personal information, like:
• If they owned cats
• Whether they were dieting
• If they were recently divorced
• Their political opinions

https://www.propublica.org/article/gun-owners-cambridge-analytica-data-psychological-profiles-privacy?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon-post

Yoshi ,
@Yoshi@toot.community avatar

@ProPublica Get you act behind a , , email, and protected computer. Just bc you're paranoid doesn't mean and aren't out to get you! Even if you're not the target, you don't want to end up as collateral damage.

@idontlikenames@mastodon.gamedev.place avatar idontlikenames , to random

¿ανατασαεσαϊγκιντεκιλλωϡτέ↺

#芥

video/mp4

@Heitec@mastodon.social avatar Heitec , to random

Signal Is Now a Great Encrypted Alternative to Zoom and Google Meet
And Signal app is FREE 😁

https://lifehacker.com/tech/signal-is-now-a-great-encrypted-alternative-to-zoom-google-meet

@Tutanota@mastodon.social avatar Tutanota , to random