Show more

I elaborate on some ways to protect the digital supply chain while borrowing metaphors from the food industry in this post: puri.sm/posts/protecting-the-d

Show thread

This is why projects like Reproducible Builds are so important. Basing all of your security on a company's signature on proprietary code is too risky.

wired.com/story/barium-supply-

A animal with a history of abuse will often flinch when a well-meaning new owner tries to pet it. It takes a lot of time and effort to rebuild trust and security.

The emotional damage in the community from decades of abuse by exploitative companies isn't acknowledged nearly enough, and is hard to overcome.

Baby Shark is *just* different enough from Y'all Ready For This that it's technically a different riff.

"Most people want to opt-in to what they want to follow, be that a news feed, a celebrity, a friend, or family. Most people do not want to be force-fed a constant stream of manipulated content to catch and keep their attention."

puri.sm/posts/opt-in-no-ads-an

@phessler We hear you, and we are addressing your concerns.

@downey As a general rule we only run stable released upstream versions of things. This was a special case because we needed specific functionality.

We've published a blog post with all of the details of this morning's security bug in Librem Chat and our response. puri.sm/posts/underscoring-our

@rae As an update, we've fixed the bug and chat is back up. I am writing up a full report and will publish it after the development team is able to distribute a security patch of their own. Thank you for your responsible disclosure!

We have some exciting news! The team at Purism are thrilled to announce the launch of Librem One librem.one Private and secure email, chat, social and VPN. No ads! No tracking! No data sharing! Just the best end-to-end encrypted communication and social. Join the revolution today and take back control of your data and life

OK, so that's creepy: "The online tool allows everyday supporters to contribute to the campaign’s voter database by logging names and background information of anyone from a family member to a stranger met at a bus stop."
nbcnews.com/politics/2020-elec

This is arguably even more impactful than NIST's upgraded password policy recommendations, because far too many in IT ignore modern thought on password policy (among other things) and just apply the Microsoft recs. arstechnica.com/gadgets/2019/0

I used to be a sysadmin, I used to fool around
But I couldn't take the punishment and had to settle down
Now I'm in security, and my OS is rare
You might think I'm crazy, but I don't even care
Cuz Qubes can run apps in VMs

It's hip to be square.

Apple marketing: We take privacy very seriously.
Apple stores: We install facial recognition and file a court summons based on computer matches.

cnet.com/news/teen-hits-apple-

Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml