507 karma · joined November 23, 2018
https://github.com/DataDog/yubikey/blob/master/gpg.sh#147
This statement has no effect when using Yubikey - the PIN is cached by the key itself and it will remain unlocked indefinitely until it's physically unplugged. See https://dev.gnupg.org/T3362
There is so much more to privacy than is made apparent to the user as a few OS knobs to "limit" ad tracking.
Edit: the page loads for the first time after assigning a new IP in Tor, but subsequent loads throw the captcha. Odd system.
> 403 Forbidden: The server understood the request, but is refusing to fulfill it.
# echo "lladdr random" >> /etc/hostname.athn0How would keeping track of packets detect a compromised web cam absolutely? An SSL-encrypted connection to Amazon servers, for example, could easily be used to exfiltrate pictures, audio and even low-bandwidth recordings while still blending in with typical, expected Web traffic.
Considering the World Wide Web predates Javascript by many years, and the fact it's possible to create a functional, readable, and accessible Web page without Javascript altogether, this characterization is absolutely inaccurate.
Not only would a Raspberry Pi be severely under-powered for routing even a small home network, in no way does monitoring that "goes to and from your LAN" defend against an adversary Snowden warns about.
> Could also put in an entirely passive NIDS on a physical layer in-line with your network’s service entrance. Very difficult for anyone to defeat, when done right.
Again, I'm not sure what threat model you think this defends against, but certainly not a three letter agency intent on either tailored exploitation nor passive monitoring of your inbound and outbound network traffic by the same actor.
I don't follow. How is security equal to anonymity? If anything, security is what enables privacy, which could enable anonymity. There are plenty of circumstances where you need security, but not anonymity - for example a message to your partner. Of course if you do need anonymity, there's a lot more involved than simply installing a "secure app" or anything of that sort.
> Tying your identity to a phone number that can only be obtained by handing a telecom your government identity documents fails.
I don't know about that in the US. I was able to open a pre-paid T-Mobile account to use with my LineageOS Android device without identity verification. Perhaps it is different elsewhere now?
> And I don't know if anyone else has mentioned this, but uploading entire contact lists should also not be considered a natural feature of a secure mobile messenger.
That sounds troubling, is it what Signal does? Would like to read more about that - is there a Github issue for reference?
It would make a good feature, but anonymity is not a requirement for privacy. I want my connection to the bank's website to be private, but there's no need for it to be anonymous. Signal offers a lot of advantage over traditional SMS with familiar usability. It doesn't perfectly solve everyone's threat model for privacy and anonymity, and doesn't have to.