@nanont @aral Perhaps it would make sense to suggest #UngoogledChromium in that disclosure, assuming UC has fixed it.
@eff the whole point to the #HTTPSEverywhere db is to skip the lag of attempting a fetch that will potentially fail. This new version will require people to fetch the javascript file, execute it, then do another network fetch to check the site. How is that better than a browser that just tries HTTPS outright and reverts to http when it fails?
@eff I would much rather store locally a list of 10M IP addresses (that's easier to manage & faster to search than domain names), than to connect to #Microsoft every time an URL omits the "S". And I must say, for #DDG to call this mechanism "Smarter Encryption" is deceiving intellectual dishonesty. They know they didn't improve encryption, they just detected some malconfig'd sites.
@eff When a db of 10 million hosts is SHA-1 hashed, the 1st four can map to 64k choices. Perhaps that's sufficient with 10M sites for DDG to not have much certainty on which site we're visiting. But this assumes we accept this figure of 10 million HTTPS sites that are malconfigured to not redirect from HTTP to HTTPS. That's a bit hard to swallow. Are these 10M sites published anywhere?
@eff Yikes! So what you're saying is previously the db was included in HTTPS Everywhere, and now everyone will have to connect to #DuckDuckGo via #Microsoft Azure to run DDG #javascript that discloses to DDG the a hash of the host we're visiting, even when the browsing isn't from a search page. Would this change have anything to do with DDG donating 6 figs annually to #EFF?
@Mr_Teatime @zeh @jgoerzen Signal collects and retains everyone's mobile phone number, which is far more sensitive than Wire's collection of pseudonym & email address.
Anyone know if #USPS scans the backside of all envelopes, or just the front? https://www.nytimes.com/2013/08/03/us/postal-service-confirms-photographing-all-us-mail.html
@jgoerzen @zeh @Mr_Teatime Compare that to Wire, which does not impose whole systems of surveillance like that inherent with mobile phones. The metadata is not ideal, but usernames can be whatever you choose & IP address is not collected. The email address can trivially be a throwaway & normies are more inclined to use a throwaway email than go through the hoops getting a burner phone for Signal.
@Mr_Teatime @zeh @jgoerzen See https://github.com/privacytoolsIO/privacytools.io/issues/779. #Signal drags users into several surveillance systems needlessly. Mobile phones are tracked in the US & that data is openly sold. Most Europeans must register their SIM cards & show state-issued ID. Signal subjects people to Google's privacy abusing system by pushing users into Playstore & the code uses reCAPTCHA.
@Mr_Teatime @jgoerzen @zeh You've lost track of the thesis, which is that Signal is unsuitable for grandmas due to exclusivity. A lot of normies naively chose to use Signal without that consideration. I exclude options that unreasonably reduce security. The use of Signal excludes those unwilling to compromise security. So it's not exclusivity alone that's a problem; it's when it imposes /less/ security.
@strypey @eliasulrich David Nutt needs to change his last name in this line of work.
"#Psychedelic drugs have been exiled to the fringes of #medicine, dismissed as recreational drugs with limited #therapeutic potential. That changed with the #breakthrough therapy status granted last year to #psilocybin, the active compound found in magic mushrooms, for its ability to reverse treatment-resistant #depression. In our latest interview series, we discuss the potential of #psychedelics to revolutionize clinical #neuroscience with thought leaders in the field."
@jgoerzen @zeh @Mr_Teatime There are people who would like to reach me on #Facebook, but I exclude them deliberately. Giving people a way to reach me through FB is to facilitate FB. I will not do that. If they want to reach me, they must use a secure & free-world-respecting option. Signal is a non-starter; it brings in several forms of surviellance. My ethics & security needs are very different than grandmas.
@Mr_Teatime @jgoerzen @zeh well then why in your previous msg did you imply lack of desktop client? I had not said to that point that there was a problem with Signal not having a desktop client. The problem is the /exclusivity/ of it for the grandma use case. Wire works on a desktop & doesn't require a mobile phone (but doesn't exclude those with only a mobile phone).
@Mr_Teatime @jgoerzen @zeh I didn't even know that Signal lacked a desktop option. That would make it even more exclusive than requiring a mobile phone subscription, which further excludes those who might register with a burner phone and use the desktop post-registration. The exclusivity of Signal is the problem with saying "it's for grandmas". Signal fails the grandma test b/c grandma does not exclude ppl.
@Mr_Teatime @zeh @jgoerzen Inclusivity came up in the context of the grandma use case. I am not a grandma & with my wildly different situation with security parameters, I am very far from inclusive. I have a vm-fax-only # & a non-DID VOIP acct. Intl outbound is cheap w/the VOIP acct but only vm-fax is reachable from POTS/VOIP/GSM. Even if I had a DID it would only give cheap calls to initiators in 1 region.
vaccine thoughts
if we collectively decide that vaccine hesitancy in the USA is enough of a problem that we need to fix it, maybe we should stop raising our kids in a culture of unbridled me-first individualism.
@jgoerzen @zeh @Mr_Teatime She probably has a couple friends her age who have only a landphone & no desktop, only reachable by landphone. But landphone alone doesn't reach everyone. Landphones are pricey for overseas calls & calling me would be a hassle (she would have to leave a msg for me to call her since my # is v/m only, then I would have to call her back over a VOIP phone & hope she hears the ringer).
@Mr_Teatime @zeh @jgoerzen She didn't get everyone on Wire because she still reaches most people from her landline. She can't reach everyone with her landline though because overseas calls are still very pricey. If she had to use Wire for everyone, she could because unlike Signal, Wire excludes no one except those with neither a mobile phone or a desktop.