Show more

has been moving more towards the deb.debian.org mirror which is provided by a single CDN company, . It works well, but also feeds an enormous amount of to a single company, and it can be used to track computers and maybe even people. And the privacy policy in effect is unclear. Fastly says the policy of the "subscriber" applies, but the privacy policy for deb.debian.org is not listed anywhere I could find. Anyone have any insight here?

The US data broker Bazze secretly obtains location and identity data about a hundred million people via smartphone apps, digital advertising and consumer records and sells it to the US military.

NSA-like global mass surveillance, but based on commercial data.

Forbes has now a report about it:
forbes.com/sites/sarahemerson/

Show thread

has a beta that makes it possible to chat without sharing your phone number with the others. This is an important development for privacy in use cases like journalists and activists that have to privately interact with people they do not know. Careful about using a public username for Signal, it could open you up to spam and targeted attacks like Pegasus.

social.librem.one/web/timeline

One down, three to go!

#Tiktok: we're not a #gatekeeper and this will expose our shady #surveillance business to the world mimimimi

Court of Justice: yeah whatever, no. 👏

#ECJ #DMA #digitalmarketsact #Competition
curia.europa.eu/jcms/upload/do

Thanks @eighthave! IMHO by running an F-Droid repo (whether it builds from source or just offers binaries) intended to be used by others, one accepts responsibility. So one should take the best possible measures to make it as safe and as transparent as possible. I try my best here, and I won't stop where I'm standing now – but hopefully improve it even more. 🤞 @fdroidorg

One concrete example of the damage that companies like and are doing to the mobile ecosystems is clear to see with media codec libraries. Right now, malware companies like have maintained zero-click exploits in both and for years. This is mostly via media exploits. iOS and Android have obscene profit margins, meaning both companies have plenty of cash for improving things. Yet where is the big outflow for fixing media codecs?

I installed #Orbot by @torproject roughly two weeks ago to help people circumvent #censorship. In that short time I already helped almost 400 people reach the #internet. You can learn how it works and how to help (it's a click of a button) here: snowflake.torproject.org/

We have been running an -compatible repository since 2012! Since then, the free software ecosystem on Android has blossomed, meaning @fdroidorg can be properly strict about . A couple of our apps still have a couple blobs that are requirements. F-Droid no longer includes any third party repos by default, that means our repo is no longer there by default. It is still easy and safe to add it! Read on for more info:

guardianproject.info/2024/02/2

Journalist Maurits Martijn is writing an article series on his search for a better internet. If that's what you're looking for you'll inevitably end up with free and open source.
In that light he wrote a portrait [1] of NLnet Foundation which financially supports #FOSS projects. Big thanks to Maurits [2] who has been working for many years to inform people about how the internet is broken and ways to make it better.
[In Dutch] [1] decorrespondent.nl/15131/deze-
[2] decorrespondent.nl/mauritsmart

It’s finally happening — sideloading is coming to the EU!

We’ve started the process of becoming a legitimate “app marketplace”, allowing our European friends to download @delta and other AltStore apps officially for the first time ever!

See you in March ☘️

Now that we’re here, time for an #introduction!

We’re an open-source app store making it possible to #sideload apps that aren’t allowed in the iOS App Store. We’re just 2 people @rileytestut @shanegillio working on this full-time, alongside a great community that’s motivated to bring new experiences to iOS

We’re solely funded through donations with no interest in VC backing. If you like what we’re doing & want to support a FOSS project, consider joining our Patreon 💚 patreon.com/rileyshane

I wish the team would follow repository best practices and stop silently reissuing binary releases under the same name/version. does not allow this, for example. The transparency log shows the newest violation: two version of sources-34_r01.zip with the file name, version code, and metadata.

gitlab.com/fdroid/android-sdk-

Last weekend I co-organised a "EU policy devroom" at #FOSDEM, marking the end of a wild 17 month ride in EU policy land working on the #CyberResilienceAct.
A blog I just published provides an overview of CRA #FOSDEM content, including my personal story starting #FOSS policy engagement in Brussels.
I hope it will contribute to a shared understanding of how the #CRA will most likely affect developers of #opensource software. Feedback welcome.

blog.nlnetlabs.nl/what-i-learn

Think tank funded by Big Tech argues #AI’s climate impact is nothing to worry about - theregister.com/2024/02/07/ai_ it's the "cryptocurrencies don't use much energy" argument all over again...

As part of 's work towards memory-safe infrastructure for the internet, @cpu has opened a merge request that implements TLS ECH support on the client side:
github.com/rustls/rustls/pull/

We agree that "the ECH spec is very challenging to implement and required a lot of trial/error" and we are working with to help implementers. Please reach out if that is you:
defo.ie/#contact

For people asking why Encrypted Client Hello is so important:

techcrunch.com/2024/01/26/nati

Even if you are using DOH (or ODoH), your ISP can see what websites your visiting (and then sell to NSA) by inspecting the certificate SNI field. Even with Encrypted SNI (ESNI), there are artifacts of the TLS session establishment leaked that can be used for TLS Fingerprinting - things like ALPN, and cipher suite.

#privacy #EncryptedClientHello #ECH

The White House just announced visa restrictions on those involved in spyware misuse. Are you a family member of someone misusing or facilitating spyware? You can be sanctioned as well! Great step to further delegitimise the highly invasive surveillance industry!

state.gov/announcement-of-a-vi

Show more
Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml