• 0 Posts
  • 16 Comments
Joined 5 years ago
cake
Cake day: August 27th, 2019

help-circle




  • TovtoLeft PiracyWarning: Encrypted webmail Protonmail is a honeypot
    link
    fedilink
    arrow-up
    57
    arrow-down
    1
    ·
    edit-2
    4 years ago

    Protonmail even has an SSL cert for that onion address even though it’s completely unnecessary.

    The reason they have an EV TLS certificate is because it still authentifies the remote server as genuine. If their Tor private key were to be leaked, users would be able to see that an impersonating service is not serving the right certificate. This also allows for cert pinning and HSTS.

    When a user makes a new account with Protonmail on TOR they are re-directed from Protonmail’s “.onion” to “.com” address. This breaks your secure encrypted connection to their onion address, enabling your identification. […] the only other websites that operate like this are suspected NSA/CIA Honeypots.

    Redirecting to the clearweb from a Tor address does not break “your secure encrypted connection”. Accessing an onion-routed service is only marginally more “secure” than accessing a TLS-enabled clearweb service over Tor.

    Professor Nadim Kobeissi mathematically proved that Protonmail does not provide End to End Encryption. Meaning, Protonmail has the ability to decrypt their own user’s data.

    This issue is hardly mathematical, and the argument is simple: if they want to serve you a JS file that sends them the decrypted contents of your mailbox, they can. It can be helped by hosting their webclient yourself. Supply-chain attacks are hardly a reason not to use software since every single one of them is affected.

    I also doubt anyone here has read the entirety of the source code of the software they use, so why would you use Linux, of which entire components were originally written by the NSA, or Tor, which has its roots in US Navy research labs and DoD funds? How about the websites that use NIST-approved elliptic curves designed by the NSA? Surely, you agree that SELinux and Tor can be reasonably trusted. You probably visited hundreds of websites that use NSA Suite B ECs. In fact, privacy-watchdog.io uses the NSA-designed P-256 EC. It seems to me there is no reason to have particular distrust for the ProtonMail webclient.

    That is not to say ProtonMail is secure, all third-party hosted webmail services are vulnerable to the attack Kobeissi outlines in his paper. You may not trust any of them, but I also do not trust myself to correctly configure everything correctly, and I much less trust hosting services to keep my data secret. Overall, the e-mail ecosystem being as broken as it is, you’d rather not use it for secure communications.

    The other, non-technical points I can’t be bothered to investigate (as IMO they hardly matter). Point 6, EML files are standard. Point 10, am I supposed to care? Point 11 assumes “independence” is an attribute worth pursuing (“but small business owners!”), or that it even is possible to pursue at scale.





  • Tankism: the uncritical, unwavering support for any state aligned against the US, typically imperialist, anti-worker, authoritarian (former) socialist states.

    Yep, that’s totally what happens: critical support is indeed uncritical. I hoped to see a fresh take in this article and/or the pieces it writes upon, but I’ll have to revisit my expectations. I am sure the author could have made amazing use of the time they spent arguing a strawman.

    I especially dislike how they dismiss the concerns of MLs about the motivations of the protests as misplaced and then provide absolutely no reason to support the protests. If the article was meant to change minds, then it failed very hard by not providing actual arguments.

    Sometimes I really feel like some of today’s particularly unprincipled leftists would’ve supported the 1973 Chilean coup or other reactionary movements, especially after seeing their reaction to the recent attempted Venezuelan coup.


  • TovtoCommunismWe're getting brigaded right now from here.
    link
    fedilink
    arrow-up
    8
    arrow-down
    1
    ·
    5 years ago

    Fascism is when I get banned from communist websites, and the more accounts I create the fascismer it is.

    Yes, twentieth century society was very homophobic. Yes, twenty-first century society is still very homophobic. No, using The Gulag Archipelago as a source should not be accepted here.

    What point are you trying to make, Very Online Anarchist:trade_mark:?






  • TovtoLeftismMy LeftValues results
    link
    fedilink
    arrow-up
    2
    ·
    5 years ago

    The optimal values for ML in this test are 70% revolutionary, 80% scientific, 90% central, 60% national, 100% party and 90% industrial. Here ML is the ideology that has the greatest average distance from other ideologies (~7554, compared to ~4814 avg, a second highest DemSoc average distance at ~6473, an Ancom median at ~4497 and a Council Communist min at ~3208).

    A “conservative/progressive” value (with 12 additional questions) was just added and ML is considered 70% conservative with other ideologies between 20% and 50%, most being at 30%.

    These tests aren’t reliable to begin with, but it does make for a fun quiz. I like that SocDems aren’t included.