@dymaxion definitely, but journalists and activists often want a public contact methods. So they should consider that publicly posting their Signal username could be as dangerous as posting their cell phone number.
The #Tor Project Seeks Rust Developer 🦀
"As a developer on the Network Team, you will be part of a small team that develops and maintains the networking software at the core of the Tor network, keeping it secure and improving it for the future." #FediHire
In this role, you will:
- Help design, develop, and improve Arti, our Rust implementation of the Tor protocol.
- Contribute to other free, open-source Rust projects
Interested? Read more 👇
The US data broker Bazze secretly obtains location and identity data about a hundred million people via smartphone apps, digital advertising and consumer records and sells it to the US military.
NSA-like global mass surveillance, but based on commercial data.
#Signal has a beta that makes it possible to chat without sharing your phone number with the others. This is an important development for privacy in use cases like journalists and activists that have to privately interact with people they do not know. Careful about using a public username for Signal, it could open you up to spam and targeted attacks like Pegasus.
Thanks @eighthave! IMHO by running an F-Droid repo (whether it builds from source or just offers binaries) intended to be used by others, one accepts responsibility. So one should take the best possible measures to make it as safe and as transparent as possible. I try my best here, and I won't stop where I'm standing now – but hopefully improve it even more. 🤞 @fdroidorg
One concrete example of the damage that #BigTech #gatekeeper companies like #Apple and #Google are doing to the mobile ecosystems is clear to see with media codec libraries. Right now, malware companies like #NSOGroup have maintained zero-click exploits in both #iOS and #Android for years. This is mostly via media exploits. iOS and Android have obscene profit margins, meaning both companies have plenty of cash for improving things. Yet where is the big outflow for fixing media codecs?
We have been running an #FDroid-compatible repository since 2012! Since then, the free software ecosystem on Android has blossomed, meaning @fdroidorg can be properly strict about #FreeSoftware. A couple of our apps still have a couple #proprietary blobs that are requirements. F-Droid no longer includes any third party repos by default, that means our repo is no longer there by default. It is still easy and safe to add it! Read on for more info:
Journalist Maurits Martijn is writing an article series on his search for a better internet. If that's what you're looking for you'll inevitably end up with free and open source.
In that light he wrote a portrait  of NLnet Foundation which financially supports #FOSS projects. Big thanks to Maurits  who has been working for many years to inform people about how the internet is broken and ways to make it better.
[In Dutch]  https://decorrespondent.nl/15131/deze-nederlandse-club-zorgt-voor-een-internet-dat-wel-voor-iedereen-werkt/14e4d369-934a-04ed-31ed-a3c67bca00e1
It’s finally happening — sideloading is coming to the EU!
We’ve started the process of becoming a legitimate “app marketplace”, allowing our European friends to download @delta and other AltStore apps officially for the first time ever!
See you in March ☘️
Now that we’re here, time for an #introduction!
We’re an open-source app store making it possible to #sideload apps that aren’t allowed in the iOS App Store. We’re just 2 people @rileytestut @shanegillio working on this full-time, alongside a great community that’s motivated to bring new experiences to iOS
We’re solely funded through donations with no interest in VC backing. If you like what we’re doing & want to support a FOSS project, consider joining our Patreon 💚 https://www.patreon.com/rileyshane
I wish the #AndroidSDK team would follow repository best practices and stop silently reissuing binary releases under the same name/version. #MavenCentral does not allow this, for example. The #FDroid transparency log shows the newest violation: two version of sources-34_r01.zip with the file name, version code, and metadata.
Last weekend I co-organised a "EU policy devroom" at #FOSDEM, marking the end of a wild 17 month ride in EU policy land working on the #CyberResilienceAct.
A blog I just published provides an overview of CRA #FOSDEM content, including my personal story starting #FOSS policy engagement in Brussels.
I hope it will contribute to a shared understanding of how the #CRA will most likely affect developers of #opensource software. Feedback welcome.
Think tank funded by Big Tech argues #AI’s climate impact is nothing to worry about - https://www.theregister.com/2024/02/07/ai_climate_impact/ it's the "cryptocurrencies don't use much energy" argument all over again...
As part of #ISRG's work towards memory-safe infrastructure for the internet, @cpu has opened a merge request that implements TLS ECH support on the client side:
We agree that "the ECH spec is very challenging to implement and required a lot of trial/error" and we are working with #DEfO to help implementers. Please reach out if that is you:
For people asking why Encrypted Client Hello is so important:
Even if you are using DOH (or ODoH), your ISP can see what websites your visiting (and then sell to NSA) by inspecting the certificate SNI field. Even with Encrypted SNI (ESNI), there are artifacts of the TLS session establishment leaked that can be used for TLS Fingerprinting - things like ALPN, and cipher suite.
Mozilla added scanning of data broker sites to its privacy protecting Mozilla Monitor
The White House just announced visa restrictions on those involved in spyware misuse. Are you a family member of someone misusing or facilitating spyware? You can be sanctioned as well! Great step to further delegitimise the highly invasive surveillance industry!
People, apps and code you can trust