195 karma · joined November 13, 2020
The internet is unfortunately not user-centric enough, there is much more value in sending crap html emails "only 10 hours left 50% discount" and scanning your emails than there is to provide users with secure communications.
let's all sign our emails to raise awareness of google's & outlook shortcoming
P.S : we tend not to sign our emails since it is not the standard, standard is de-facto dictated by google and outlook now.
P.P.S : seeing an unsigned email would raise suspicion if the standard was the opposite, a filter could even classify between signed and unsigned
P.P.P.S : you would only bother to verify the identity for the emails you care for
P.P.P.P.S : if you think google does not dictate the standards, feel free to point to me the part of the rfc that mention that residential ips are not valid.
Even If I am fully vaccinated, I do not wish to send someone who have decided not to take the vaccine to the ER. Even if it was in my opinion a bad decision. I do not mind wearing a mask while we collect more data to have a more efficient response.
dig +dnssec nsa.gov
I believe peer to peer is the way to go and we tech people have a duty to inform and vulgarize technologies and outcomes to our close relatives.
This is the digital legacy we will leave to future generations.
related horror story: https://www.nytimes.com/2021/01/30/technology/change-my-goog...
it would be a real shame if an organised group of person would start posting programatically to these slander sites with material from https://thispersondoesnotexist.com/ and randomly generated names. Storing all these pictures will cost something afterall.
I do a simple rsync of my precious but not too sensitive data, daily.
and for the more sensitive stuff, gpg before sending daily as well, the copies will add up but I prefer it that way.
10/10 great business
about my temporary choice for aws:
the reason is explained here : https://temporary.chat/qa.html
"I dont like your dns, registrar etc : took amazon for the ease of use and because I am familiar with it, but it is not my final choice, my goal is to make this as portable as possible so it can be deployed in virtual machines, on personal computers etc. I will not start using amazon services even if they are dirt cheap and I know how to leverage them. I do not want this project to be locked on a specific cloud platform. "
Middlesex, GB??? - > i'm in montreal canada
about the source code: ansible playbooks have a structure, src folder is not gonna fly here. "split the client" -> there is no client
but I can probably improve the repository structure, yes.
And, if you want to be so "security hacker like nobody knows" > I have no such ambitions.
create fancy profile picture with no face > I don't see how if I choose to put my face online or not is relevant here.
Get a decent username no hash gabage > the hash garbage is a md5sum for the word "git", I don't have imagination.
Hide your WhoIs Information from the domain > On 17 May 2018 the ICANN Board adopted a Temporary Specification for gTLD Registration Data. https://www.icann.org/resources/board-material/resolutions-2...
Got I disapointed? Yeah > It is okay, I know the project is not quite secure it it's actual form (even if a put a bit of effort on the security side) it is a work in progress.
Would I trust this app even if the source code would be readable in any way > if you cannot read my source code, I highly doubt you'll be able to read the signal source code (which I looked at)
thanks for your comment.
you still having issue ending up in spam even when using mailgun? (based on the disclaimer on your site). I dislike how emails are now filtered by some close source algorithm, and that even if you respect all the RFC's you might end up in spam, effectively hurting your legit email.
HN loved it too much, running this on a 5$ machine with 1G ram :)
it's back now
thanks for your comment,
about my temporary choice for aws:
the reason is explained here : https://temporary.chat/qa.html
"I dont like your dns, registrar etc : took amazon for the ease of use and because I am familiar with it, but it is not my final choice, my goal is to make this as portable as possible so it can be deployed in virtual machines, on personal computers etc. I will not start using amazon services even if they are dirt cheap and I know how to leverage them. I do not want this project to be locked on a specific cloud platform. "
Middlesex, GB??? - > i'm in montreal canada
about the source code: ansible playbooks have a structure, src folder is not gonna fly here. "split the client" -> there is no client
but I can probably improve the repository structure, yes.
And, if you want to be so "security hacker like nobody knows" > I have no such ambitions.
Got I disapointed? Yeah > It is okay, I know the project is not quite secure it it's actual form (even if a put a bit of effort on the security side) it is a work in progress.
thanks for your comment.
preface : After my cellphone started having camera focus issues & fell in the river(with me), I got very annoyed with the QR code required by signal (I ended up resizing the QR code it in gimp, printing it out on paper, and scanning it with my half-dead phone to be able to re-link my computer to signal). I am still waiting for my Librem5 (yes I drank the cool aid).
going in the deep: I like to develop my own solutions in general instead of using existing technology (a.k.a i'm re-inventing the wheel)
My solution is not as good as signal and I know it. The two things that annoy me about signal is that [1]it requires a phone number and [2]it relies heavily on the domain whispersystems.org.
The good part about my app/server (I think) is that:
1 - you can host it at home and it does not even require a domain name. (you can deploy with bare ip)
2 - it is user friendly enough (GUI, pictures upload)
3 - encryption in transit is automatic (let's encrypt or self-sign)
4 - you can destroy conversations in one click
5 - you can choose many different modes of deployment (single room, multi room, per-room certificates, wildcard certificates etc(more to come))
6 - receiving notifications on PING only (more like slack with the @ or irc with the name... something signal lacks)
The bad parts about my app/server (I think) is that:
1 - notifications via rss are not ideal, but it is the best way I found to make that app/server as standalone as possible (no 3rd party api calls required after installation).
2 - I am a jack of all trades, master of none, so I am pretty sure you can point at everything I wrote in any language and find flaws (I don't consider myself a developper)
3 - everything in there is file based, so... speed, scale and inodes :)
4 - api is not complete nor nice at the moment (work in progress)
5 - real end to end encryption is not yet implemented (I will go with good ol' gpg here(not sure how yet, let's add more tuck tape)
6 - deployment process needs improvements. (I am the only one that deployed it so far but i'm sure it does)
Any feedback is welcome, you can also try to hack it and I will gladly provide assistance if you want to deploy your own instance.
I will probably need help to achieve this, but I would love to see this becoming a great product made by the people, for the people with little nodes all over the place.
Just like a phone number, you will know to reach your friend(s) at friends.domainx.com. with more savvy people hosting it for less savvy friends, so the data remains in the hands of people that know each others in real life instead of big corp$.
P.S : you can use the demo for quick file sharing and destroy the room after.
thank you for your time and (hopefully) interest!
https://www.theregister.com/2020/10/09/google_search_arrest/
the judge are not supposed to allowed fishing expeditions, but in this case, the lookup requested was quite narrow. they still requested a search warrant.
I started working on a personal project to create my own chat server (web based) that can be hosted pretty much everywhere (on ubuntu 20.04) (virtual machines, personal computers, public clouds, vps, bare metal at home, etc.) and that requires no client installation, just a browser.
it is now in beta but works for text and file sharing (up to 100M by default but you can change that)
the source code is here : https://github.com/ba9f11ecc3497d9993b933fdc2bd61e5/temporar... (see README.md and CONTRIBUTING.md )
deployments are done with ansible and 2 modes are available for now : single room and random rooms
rooms can be either public or password protected. All rooms are destroyable with a single click (a real destroy that actually remove the files.
Encryption is done by default either with let's encrypt (if you deploy on a domain or subdomain) or a certification authority where the key gets destroyed after the only certificate is created (if you deploy on an ip) (a helper page is created to show the fingerprint of the certificate and instruction per browser on how to install the cert)
I plan to add more deployment modes in the future (rooms with customized names, expert mode to submit gpg messages via an api)
screenshot of the chat page & landing pages can be found here :
or you can try it live at :
any enthusiasts that want to deploy one at home, any experts that want to point security flaws, any user that want to report a bug or a lack of features. Any UX experts that think I made a terrible job are more than welcome to comment. My mail address can be found in the repo.
Hopefully somebody else than me will see value in this project :)
thank you for reading!