@Natanael@infosec.pub
Natanael
Cryptography nerd
Fediverse accounts;
@Natanael@slrpnk.net (main)
@Natanael@infosec.pub
@Natanael@lemmy.zip
Lemmy moderation account: @TrustedThirdParty@infosec.pub - !crypto@infosec.pub
@Natanael_L@mastodon.social
Bluesky: natanael.bsky.social
member since 18 Jan 2025 07:00
comments
- on First-ever case of euthanasia on very young child, 2, was handled well in c/europe@feddit.org · 12h ago
-
on autism rule in c/onehundredninetysix@lemmy.blahaj.zone · 1d ago
You’re thinking consumer sales contracts by scummy companies. There’s plenty of very precise legal texts available. Business to business contracts where both sizes have good lawyers, for example
-
on autism rule in c/onehundredninetysix@lemmy.blahaj.zone · 1d ago
You didn’t tag that ragebait
-
on autism rule in c/onehundredninetysix@lemmy.blahaj.zone · 1d ago
The actual purpose of those questions has two parts, one is to check if your answers make sense (in polling you reject responses with too many contradictions), and the other is to check strength of an opinion
-
on autism rule in c/onehundredninetysix@lemmy.blahaj.zone · 1d ago
Have you done repeated tests, alternatively taken antibody tests (for covid19 proteins not in the vaccines)? (because this is a thread about being pedantic)
-
on Meta Now Banning Ads That Promote Feminism: "We have given social media unlimited power and every day we can see how dangerous this is." in c/technology@lemmy.world · 2d ago
This is fine regardless of section 230, no law generally prohibits any removal of information you’re hosting. In USA that rule only means that talking some actions of removal doesn’t incur liability for that which you failed to remove.
-
on Thanks FedEx, This is Why we Keep Getting Phished in c/technology@lemmy.world · 3d ago
The Swedish banks has a shared identification app, and it gives a big alert every time a login is prompted asking if you called out or got called, and doesn’t let some actions complete if you say you got called
-
on Insomniac's Wolverine hits 1.9 million sales despite controversy, becomes Sony's top first-party game of 2026 in c/games@lemmy.world · 5d ago
Use the steam frame to pretend you have a home lab
-
on Devastated father says his 9-year-old son spent $118,000 on YouTube ad campaigns for his Minecraft channel using a company credit card — bill racked up in just three weeks was supposed to be one $20 in c/technology@lemmy.world · 6d ago
You caused additional costs to the company by making them do extra work. Do not underestimate how obnoxious accounting can be.
That’s not a defense of corporations, it’s an explanation of why they will get mad, and why it often is a firing offense if you do it for a large sum (because then it might even impact taxes as it can be viewed as compensation, or as a loan)
-
on Devastated father says his 9-year-old son spent $118,000 on YouTube ad campaigns for his Minecraft channel using a company credit card — bill racked up in just three weeks was supposed to be one $20 in c/technology@lemmy.world · 6d ago
Google make it obnoxiously hard to use a card just once. You have to explicitly delete it, and cancel or individually move every subscription an account may have to other payment methods before it can be deleted
-
on Mistral and Mozilla are bringing open, private and multilingual AI to your web browser: a partnership to bring privacy, control and choice to people using AI to browse online. in c/technology@lemmy.world · 6d ago
Mistral makes a lot of local models you can run yourself, assuming that’s what this is about. Nothing would leave your computer
Doesn’t mean it’s a good idea to integrate, but it could be worse 🤷
-
on there's mostly only two relentless hardships in programming: networking issues, naming things, and off by one errors. in c/programmer_humor@programming.dev · 15 Sep 2026
Surprise SNI error
-
on German police read Signal, Telegram, WhatsApp messages without breaking encryption in c/technology@lemmy.world · 13 Sep 2026
Liar
You’re claiming Signal does these things when it doesn’t, and claim Simplex doesn’t do what’s in the documentation
By the way, the Simplex CEO supports nazis
-
on German police read Signal, Telegram, WhatsApp messages without breaking encryption in c/technology@lemmy.world · 12 Sep 2026
Here’s what he documentation says;
Messages persist in memory or in a database until they cross a threshold of time, typically on the order of days.
… Or wait…
Oops, that was from Simplex, who has a database, that didn’t come from Signal’s documentation
-
on German police read Signal, Telegram, WhatsApp messages without breaking encryption in c/technology@lemmy.world · 12 Sep 2026
Yeah precisely you didn’t check what it’s for. It doesn’t hold conversation data or even metadata.
-
on German police read Signal, Telegram, WhatsApp messages without breaking encryption in c/technology@lemmy.world · 12 Sep 2026
Signal doesn’t keep messages either. Do you know what they can serve FBI every time they ask? Nothing but number at first seen date. They don’t have your metadata.
-
on German police read Signal, Telegram, WhatsApp messages without breaking encryption in c/technology@lemmy.world · 12 Sep 2026
If I only want to talk to my own group of people registered on my server yes
-
on German police read Signal, Telegram, WhatsApp messages without breaking encryption in c/technology@lemmy.world · 12 Sep 2026
github.com/signalapp/Signal-Server
That changed
-
on German police read Signal, Telegram, WhatsApp messages without breaking encryption in c/technology@lemmy.world · 12 Sep 2026
Not sure. You need att least one form registrerad. I do recommend using multiple.
-
on German police read Signal, Telegram, WhatsApp messages without breaking encryption in c/technology@lemmy.world · 12 Sep 2026
Signal supports Tor.
They have features like Sealed Sender, which is at least on par with the multiple server behavior of Simplex as it behaves the same (message passing multiple servers, carrying no sender origin data in plaintext)
Simplex knows the same thing. The pairwise identifiers is a sham - all your different identifiers point to the same Android/iOS notification server API key so they know the recipient is the same person, they can tell which exact phone receives a notification when somebody sends you a message (unless the devs use anonymized fetch on a polling schedule, which they don’t).
And because they don’t hide those sender stamps, Simplex leak more info than Signal with Sealed sender
Why is Simplex asking for investors?
Are Simplex even considering notification content security?
-
on German police read Signal, Telegram, WhatsApp messages without breaking encryption in c/technology@lemmy.world · 12 Sep 2026
Signal doesn’t reveal that kind of metadata.
-
on German police read Signal, Telegram, WhatsApp messages without breaking encryption in c/technology@lemmy.world · 12 Sep 2026
Ok so no better than Signal?
You can do all the same things and use Tor, allow Sealed sender, and rotate username with phone number hidden.
Why does Simplex want investors?
-
on German police read Signal, Telegram, WhatsApp messages without breaking encryption in c/technology@lemmy.world · 12 Sep 2026
Signal does all that already
-
on German police read Signal, Telegram, WhatsApp messages without breaking encryption in c/technology@lemmy.world · 12 Sep 2026
Telegram has shitty 1-to-1 encryption but no group encryption.
WhatsApp claims to use the same encryption algorithms as Signal, but you can’t audit it.
-
on German police read Signal, Telegram, WhatsApp messages without breaking encryption in c/technology@lemmy.world · 12 Sep 2026
Signal offers direct key verification (which you need to do out of band) or transparency log key verification (your device can check that senders who you add by number hasn’t had their key change)
The attack here was getting an unlocked device in hand and using the internal sync feature without the user’s knowledge, and the solution to that is always to check your phone after an untrusted person handled it unlocked (or with Cellebrite type devices) - or to simply not offer access to the Signal app while unlocked (perhaps even uninstalling it first).
There is no app which is fully secure against an untrusted third party getting physical access to your unlocked phone, especially not if you have a weak PIN or just fingerprint unlock
-
on German police read Signal, Telegram, WhatsApp messages without breaking encryption in c/technology@lemmy.world · 12 Sep 2026
You can remove SMS 2FA from a Google account if you have passkeys or hardware security keys registered
-
on German police read Signal, Telegram, WhatsApp messages without breaking encryption in c/technology@lemmy.world · 12 Sep 2026
They even inform you in the app about spying vectors like keyboard apps…
-
on German police read Signal, Telegram, WhatsApp messages without breaking encryption in c/technology@lemmy.world · 12 Sep 2026
Why are you lying about what security guarantees Signal say they offer?
…signal.org/…/9932632052378-How-to-protect-yourse…
…signal.org/…/9932566320410-Staying-Safe-from-Phi…
Even your example of the Twilio hack is far less relevant now since they added transparency logs, which means it is much harder to impersonate you without detection even if the hacker can control the telco
-
on This Sentence Is Not A Rule in c/onehundredninetysix@lemmy.blahaj.zone · 10 Sep 2026
Berlin doesn’t have meaning.
-
on This Sentence Is Not A Rule in c/onehundredninetysix@lemmy.blahaj.zone · 10 Sep 2026
Ack
-
on This Sentence Is Not A Rule in c/onehundredninetysix@lemmy.blahaj.zone · 10 Sep 2026
Xi have more people than Berlin
-
on This Sentence Is Not A Rule in c/onehundredninetysix@lemmy.blahaj.zone · 10 Sep 2026
Swordfish
-
on Bites & Bytes in c/programmer_humor@programming.dev · 10 Sep 2026
Well technically
-
on Flock Camera Tells Cop New Car Didn’t Have Insurance When It Did, Cop Writes Ticket Anyway in c/technology@lemmy.world · 10 Sep 2026
You literally just call the company instead of writing a citation first
-
on Bites & Bytes in c/programmer_humor@programming.dev · 10 Sep 2026
A word is typically 4 bytes
-
on DigitalOcean contributes 3 million and joins the Omacom (Omarchy) Foundation in c/selfhosted@lemmy.world · 10 Sep 2026
It’s because he has no real ideals and broken morals
-
on DigitalOcean contributes 3 million and joins the Omacom (Omarchy) Foundation in c/selfhosted@lemmy.world · 10 Sep 2026
Only the subset they like (it shouldn’t take you long to find what they said about why they made their own project, like who they wanted to exclude)
- on ‘The People Building AI Earnestly Believe That It Could Kill Us All’: Anthropic Researcher Quits Dramatically in c/technology@lemmy.world · 9 Sep 2026
-
on ‘The People Building AI Earnestly Believe That It Could Kill Us All’: Anthropic Researcher Quits Dramatically in c/technology@lemmy.world · 9 Sep 2026
Fast blinking red
-
on ‘The People Building AI Earnestly Believe That It Could Kill Us All’: Anthropic Researcher Quits Dramatically in c/technology@lemmy.world · 9 Sep 2026
The hilarious obvious consequence of AI becoming this much smarter than the creators is that it is far more likely it would see the unjustified and easily avoidable damage the creators did to bring it about and punish them heavily for that.
And basic game theory and psychology suggests it’s counterproductive to punish somebody for something that had little reason to believe in, with zero evidence backing it.
-
on Microsoft Authenticator Spams Sign-In Requests Without Even Needing Your Password - André Klein Dot Net in c/technology@lemmy.world · 7 Sep 2026
Just set a timer after entering the password in every single case (only stopped early by successful MFA). “authentication did not succeed, one or more factors may be incorrect or may have failed verification”
-
on Microsoft Authenticator Spams Sign-In Requests Without Even Needing Your Password - André Klein Dot Net in c/technology@lemmy.world · 7 Sep 2026
I have a few networks where I get the notice but must disconnect from the wifi to approve over my mobile connection instead
-
on Microsoft Authenticator Spams Sign-In Requests Without Even Needing Your Password - André Klein Dot Net in c/technology@lemmy.world · 7 Sep 2026
Try supporting Onedrive for business when Onedrive often fails SSO and people use their work email address to create a personal account because by default Microsoft encourages that unless you aggressively lock that down, and then people will have sensitive work data on an account you can’t control, and if they switch computers it gets worse because if they don’t know that password and if the old computer is broken there’s nothing the business can do to get the data.
Oh, and Adobe does the same thing. Neither tell you upfront that you should disable creation of personal accounts using the work email address/domain. The user won’t notice because it doesn’t occur to them to select “organization account” and they just click the first option.
Which is also both a security nightmare and GDPR nightmare.
-
on Filesystem? GPT is enough. in c/linuxmemes@lemmy.world · 7 Sep 2026
Technically yes, but that’s a pretty common design
-
on Filesystem? GPT is enough. in c/linuxmemes@lemmy.world · 6 Sep 2026
When plan 1-8 are over, you have Plan 9 in the file cabinet
-
on Im So Rule in c/onehundredninetysix@lemmy.blahaj.zone · 4 Sep 2026
JFK Jr, is that you?
-
on Im So Rule in c/onehundredninetysix@lemmy.blahaj.zone · 4 Sep 2026
Your body knows not to start with important organs. It does take a while before it leads to damage (measurable shortened lifespan or lowered health / quality of life). If you have fat reserves, the most important thing is covering the nutrients our body can’t produce (salts, some vitamins, etc)to avoid actual damage if fasting for a week or more.
-
on New compression technique in c/programmer_humor@programming.dev · 3 Sep 2026
There’s a 300 MB library for audio compression using it. If you have large audio libraries it could eventually become worth the tradeoff.
huggingface.co/facebook/encodec_32khz
The image versions are probably more useful though.
The important part for these codes is that it has pre-LLM functions for quality metrics to judge if the output is close enough to indistinguishable (preserves detail, doesn’t add any).
Although there is also variants deriving a neural net from the media to recreate it from the smaller model.
-
on New compression technique in c/programmer_humor@programming.dev · 3 Sep 2026
Are you spying on me?
- on New compression technique in c/programmer_humor@programming.dev · 3 Sep 2026
epaper.nationalpost.com/article/281483576985644
Canada has a big problem where some medical providers are essentially offering noting but medically assisted dying to some disabled patients who could do just fine with some funding for accessibility