I think at least some skepticism about independency is warranted when the board of directors is 3/4 Anthropic employees. Zulip is an awesome tool, and I want to assume good faith here, but it’s really hard to interpret this as anything other than acquihiring, especially given how industry is prone to using intermediary non-profits for things they actually control.
HN user
goldsteinq
I think this misses the point of LISP macros. LISP macros are just functions written in LISP, so here macros need to be functions written in Rust-but-LISP, but it is not so. In fact, I think this macro language lacks conditionals, so it’s not even Turing-complete.
Folks who manually enable our "Resist Fingerprinting" preference (which we don't officially support, and I don't generally recommend - but hey, you do you) are very loud on Bugzilla. VERY loud. To the point where I've had a lot of managers and executives come telling me "Everyone is complaining about this breaking stuff, we really need to disable this so people can't accidentally turn it on." Telemetry let me show that despite being SO LOUD they're still a minute portion of the population. Management's question "Should we block it?" became "No." You're welcome.
Telemetry shows that users who didn’t opt out of telemetry don’t care about fingerprinting. Who’d have thought.
It keeps missing the fact that BlueSky, as of today, is not decentralized in any meaningful way. If tomorrow bsky.app (and/or PLC registry) goes dark, the network is dead. There’re no public alternative AppViews. Most users use centralized PLC IDs, which depend on the centralized infra. An extreme minority of users uses external PDSes.
https://blue.mackuba.eu/stats/
https://arewedecentralizedyet.online/
We need to finish moving PLC into an independent org
Does not make it decentralized; instead creates a second centralized failure point.
large scale “appviews” — the aggregating backends of apps — are still a bit too expensive and a bit too difficult to write
Which is an architectural limitation, because AppViews must store the entire network, and will only get worse.
It’s really weird to say that BlueSky is an example of “practical decentralization” when all of its decentralization serves no practical purpose at all.
No “Submit Debug Logs” there, as far as I can see. Do I need to be on matrix.org homeserver for this to work or something?
https://photos.goldstein.lol/share/OIgowBN4Wmi4zlm8DmDP0s8jH...
I’m facing it on Element Desktop, but I’ll try to reproduce it on Element Web. I’ve tried to submit logs from Element Desktop, but it says that `/rageshake` (which I was told to do) is not a command. I’m happy to help with debugging this, but I’m not sure how to submit logs from Desktop.
Something like this happens basically every time I try to use Matrix though. Messages are not decrypting, or not being delivered, or devices can’t be authenticated for some cryptic reason. The reason I even tried to use Element Desktop is because my nheko is seemingly now incapable of sending direct messages (the recepient just gets infinite “waiting for message”).
Okay, sorry, not oss-security mailing list, oss-security _distros_ mailing list.
https://oss-security.openwall.org/wiki/mailing-lists/distros
Only use these lists to report security issues that are not yet public
To report a non-public medium or high severity 2) security issue to one of these lists, send e-mail to distros [at] vs [dot] openwall [dot] org or linux [dash] distros [at] vs [dot] openwall [dot] org (choose one of these lists depending on who you want to inform), preferably PGP-encrypted to the key below.
Say more. Plenty of people use Signal as a serious communication tool.
I did say more already. Maybe you believe in serious communication tools that can’t synchronize searchable history between devices, but I don’t.
They, and other communities that use GPG-encrypted emails are LARPing, and it’s only fine because their emails don’t actually matter enough for anybody to care about compromising them.
Are we talking about the same Openwall? Are you aware what Openwall’s oss-security mailing list is? Please, do elaborate how nobody cares about getting access to an unlimited stream of zerodays for basically every Unix-like system.
I’m definitely not “commiting malpractice” on account of not being a security practicioner. I’m talking from a perspective of a user.
It’s important to me — as a user — that a communication tool doesn’t lose my data, and Signal already did. Actual practicioners keep recommending Signal and sure, I believe that in a weird scenario where my encryption keys are somehow compromised without also compromising my local message history, Signal’s double-ratchet will do wonders — but it doesn’t actually work as a serious communication tool.
It’s also kinda curious that while the “email cannot be made secure” mantra is constantly repeated online, basically every organization that needs secure communication uses email. Openwall are certainly practicioners, and they use PGP-over-email: are they commiting malpractice?
Pros of Matrix: it actually has a consistent history (in theory); no vendor lock-in. Cons of Matrix: encryption breaks constantly. Right now I’m stuck in a fun loop of endlessly changing recovery keys: https://github.com/element-hq/element-web/issues/31392
Yes, if your only device is a single Android phone you can do that. You can’t, however, use that backup to populate your message history on other platforms.
I’ve already lost message history consistency because one of my devices was offline for too long. The messages are there on my other device, but Signal refuses to let me copy my data from one of my devices to another. Signal is, quite literally, worse at syncing message history than IRC — at least with IRC I can set up a bouncer and have a consistent view of history on all of my devices, but there’re no Signal bouncers.
You don't have to use it like "encrypted SMS"! You're free.
Using it as something more than encrypted SMS requires persistent message history between devices.
metric fuckton of messages
“More than 45 days” is a metric fuckton? Seriously?
If you want Signal to host the encrypted storage, that costs money. If you don't want to pay Signal money, they provide 45 days of backup for free.
I don’t want Signal to store my messages. I want Signal to not lock in my messages on their servers, so I can sync them between my devices and back them up into my own backups.
If you want to self-host your own backups (at your own cost), that's easy to do.
Except there’s no way to move it between platforms. I have more than one device.
Are you referring to MobileCoin? That feature isn't in the pipeline for sending messages.
I don’t want shady crypto company to hold my data hostage, and there’s no way to store it on my hardware and then move it between platforms. That’s my problem with signal.
A Synchronized Start for Linked Devices
It only properly transfers 45 days. You can’t have more than one phone. Phones are special “primary devices” and AFAIK you can’t restore your messages if you lose your phone even if you have logged-in Signal Desktop.
If you want a suggestion for secure messaging, it's Signal/WhatsApp. If you want to LARP at security with a handful of other folks, GPG is a fine way to do that.
I want secure messaging, not encrypted SMS. I want my messages to sync properly between arbitrary number of devices. I want my messaging history to not be lost when I lose a device. I want not losing my messaging history to not be a paid feature. I want to not depend on a shady crypto company to send a message.
According to the official Matrix website (https://matrix.org/ecosystem/clients/element-x/, https://matrix.org/ecosystem/clients/element/): threads, voice calls, spaces, SSO.
some Element users are still stuck on the Classic app, unaware that Element X exists
This sounds really arrogant. Element X _still_ lacks a lot of features, saying that the only reason to use classic Element is that you must be unaware of Element X completely ignores that. I wish “Element Creations Ltd” was as aggressive in creating Element X as they are in pushing it.
I wanted to make a more descriptive title, mentioning that Microsoft uses its own program for `curl` command, but ran out of characters.
Also, for OP: Do you mean "access to the system it runs on"? Because I'm pretty sure it doesn't run with "SYSTEM" access (as in privileged user).
Yeah, I mean “access to the system”. It’s not the same as using headless chrome, because it gives you ActiveX and you can shell out to an arbitrary command.
Equivalent of $5-6 monthly
I am subscribed to recurrent donations to Thunderbird.
I would pay for Firefox if it was focused on privacy and customizabilty, not telemetry and LLMs.
So the first scenario is also basically “automatic scanner bypass”? That answers my question, yes.
making a tar file that when inspected looks fine
Am I correct in understanding that manual inspection would reveal a nested .tar archive (so recursive inspection of nested archives should be enough)?
Is this LLM-generated? The style is somewhat off (long lists repeating the same thing over and over, calling random meta statements “theorems”), and the link to the repo is completely broken.
Hi! Could you elaborate on the first attack scenario?
Target: Python package managers using tokio-tar (e.g., uv). An attacker uploads a malicious package to PyPI. The package's outer TAR contains a legitimate pyproject.toml, but the hidden inner TAR contains a malicious one that hijacks the build backend. During package installation, the malicious config overwrites the legitimate one, leading to RCE on developer machines and CI systems.
It seems to imply that you’re already installing a package uploaded by a malicious entity. Is the vulnerable workflow something like “you manually download the package archive, unpack it with system tar, audit all the files and then run uv install, which will see different files”?
I’m still not sure how do you even compromise a key without also compromising message history. The keys are stored on-device, along with associated history. If attacker has access to the keys, they also have access to all the previous messages stored on the same device. Unless you’re using auto-delete with short period on all your messaging, which I would think is not common, it would seem that you gain nothing by ratcheting.
So non-browser clients have no feasible way of checking certificate revocation anymore.
In Firefox, I get a new permissions request every time I join a Jitsi call.
I’m not surprised that the number is that high, but I’m surprised they write it outright instead of hiding it in the “salaries” section.
It’s kinda hard to find out from this website who do you trust in this model. I think the answer is that you trust the hardware manufacturer: the initial attestation uses private key built into the hardware, and NVIDIA could, in principle, have a copy of that key.
A bigger question is where is the source code for enclave containers. They have a lot of repos on their GitHub, but it’s really not clear how to use it to reproduce their images.
ELI5: how is any of this legal? Let’s say my distro receives Firefox source code under the terms of MPL, builds it and distributes it to me under the same terms. At no point any of us agreed to any additional terms. Does this apply only to Mozilla-built binaries?
This means it has a known size (The same as a usize.)
Double that of a usize, since str is an unsized type and needs a fat pointer.
This class of attacks is not new. Spectre demonstrated this possibility in 2018, and Apple was previously targeted by speculation attacks, e.g. https://gofetch.fail/ or https://ileakage.com/.