Debian Votes: A General Resolution torward an offical project statment has been initiated regarding the recent EU 'Cyber Resilience Act and Product Liability Directive' https://www.debian.org/vote/2023/vote_002
#Wireshark can now present some of the details of #EncryptedClientHello in #TLS streams, as of v4.2.0. For example, it can dissect the #ECH config data that comes from DNS. https://gitlab.com/wireshark/wireshark/-/merge_requests/12260
I have a teapot made by a ceramics company called Emma Bridgewater, so I searched if it was dishwasher safe. No 2 on the list is this #AI #LLM generated piece of trash: https://dishwashermanuals.com/is-emma-bridgewater-dishwasher-safe/
It includes this heading that only an LLM would generate: "Are Emma Bridgewater mugs, dishwashers, and microwaves safe?" Oops, it mixed up who is doing what to who. I think it is pretty clear that this AI wave is a repeat of #cryptocurrency: 99% of use cases make our world much worse.
@rakoo @pmroman "Dying Gazans Criticized For Not Using Last Words To Condemn Hamas" https://www.theonion.com/dying-gazans-criticized-for-not-using-last-words-to-con-1850925657
We have started the second round of our partnership https://defo.ie to ensure that the new #TLS standard called #EncryptedClientHello (#ECH) works for public interest use cases. We also are working to reduce the pressure towards #centralization inherent to the #privacy improvements of hiding the domain name. You can find more details in our project announcement: https://guardianproject.info/2023/11/09/defo-developing-ech-for-openssl-round-two/
F-Droid Alphas and good news for CJK users https://f-droid.org/en/2023/11/16/twif-enter-the-alphas.html
It seems like the #EU #DigitalMarketsAct is already having an effect on #GooglePlay: now that they might actually have some real competition, they seem to be ramping up efforts to clean up their app store:
@vitriolix the wealthy always have people who stash large chunks of money away for them. Sadly, I'm sure he's still rich.
One thing that most impressed me about the culture of Brooklyn was how after the September 11th attacks, mainstream culture rallied to protect its Arab and Muslim communities because we knew they would be unfairly targeted https://web.archive.org/web/20210712204925/https://www.baltimoresun.com/news/bs-xpm-2001-09-14-0109140289-story.html
Sadly, what I see now in Europe is the mainstream adopting the bigoted views of people like Netanyahu, Ben-Gvir, Likud, Shas, etc. and coding it nice sounding language. The #EU should protect and respect all of its citizens and residents equally.
New language: Arabic https://f-droid.org/en/2023/11/12/new-language-arabic.html
@colincogle @guardianproject you could use the same hostname for both the "public_name" and the SNI in the inner ClientHello. That works, but then "public_name" is clear text, so this setup would not protect the hostname. The "public_name' is generally the CDN, then the encrypted SNI would have the actual hostname. For example, public_name as cloudflare-ech.com and inner SNI as rte.ie.
We are looking for feedback about how to help interested devs start messing around with #TLS #EncryptedClientHello #ECH. What are your blockers and interests?
The first fully merged, audited and shipped bit of code from our https://defo.ie project is Hybrid Public Key Encryption (#HKPE RFC9180), it has been shipped by #OpenSSL https://www.openssl.org/blog/blog/2023/10/18/ossl-hpke/ It is a building block for #EncryptedClientHello #ECH and #MessagingLayerSecurity #MLS, providing standard methods for using public key cryptography to encrypt arbitrary blocks of data.
For anyone who is interested in implementing #TLS Encrypted ClientHello (#ECH), we have set up a new public room: https://matrix.to/#/#ech-dev:matrix.org or irc://irc.oftc.net/ech-dev
Mozilla is ringing the alarm bell on a dangerous EU regulation.
@calyxinstitute's #CalyxOS developers did some review of their #Android-based project and found no leaks:
https://gitlab.com/CalyxOS/calyxos/-/issues/1947
I wonder if #GooglePlay uses the deobfuscation data in the "mapping.txt" file in the app review process? It would bring the binary code a bit closer to being more readable like source code. Their documentation only mentions crash reports as a use case:
https://support.google.com/googleplay/android-developer/answer/9848633