441 karma · joined December 1, 2014
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3991...
https://github.com/SAMA-Communications/sama-server/tree/main... https://github.com/SAMA-Communications/xmpp-adapter
Also I don't see anything about E2EE support
https://www.techtarget.com/whatis/feature/SolarWinds-hack-ex...
Password managers should be bound to hardware tokens and each password should be individually encrypted, as well and individually decrypted that also force physical tap.
Password Store is a perfect example of this. Physical password managers are also on the rise, see: Ledger and Mooltipass
This is solved using WKD. Thunderbird already supports this with enigmail enabled
This is built into modern browsers so you can use that as the basis for HMAC if you can't trust TLS or have something like an open URL for a lambda function that in theory should only be hit by someone's webhook (ie. Slack)
You're also now just sitting behind whatever ISP your VPN uses which knows everything you're doing and sells it back to who-ever.
If your not rotating your VPN services that still allows you to be tracked via that IP. At the end of the day all your data still belongs to someone and can be used for whatever. Until DNS over TLS is complete and rolled out across the board your metadata can still be used.
Not to mention all of the other things associated with this. Even being connected to a VPN via your phone will still leak information like your coarse location, wifi networks and bluetooth beacons nearby which all get sent to your primary phone carrier and whatever applications you use.