<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-06-02T21:41:27Z</updated>
  <generator>https://yabu.me</generator>

  <title>Nostr notes by René Mayrhofer :verified: 🇺🇦</title>
  <author>
    <name>René Mayrhofer :verified: 🇺🇦</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://yabu.me/npub1sarnu5yyxchvqwaxqvhu987xpyeklgnq2gy4dz5200v9qz9gje8ske3hha.rss" />
  <link href="https://yabu.me/npub1sarnu5yyxchvqwaxqvhu987xpyeklgnq2gy4dz5200v9qz9gje8ske3hha" />
  <id>https://yabu.me/npub1sarnu5yyxchvqwaxqvhu987xpyeklgnq2gy4dz5200v9qz9gje8ske3hha</id>
  <icon>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/292/400/036/690/273/original/db5f6fd41ae07cfe.jpg</icon>
  <logo>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/292/400/036/690/273/original/db5f6fd41ae07cfe.jpg</logo>




  <entry>
    <id>https://yabu.me/nevent1qqsf3z0lh65tvw6xhp5wd43y5g0xxne0gtw0mpp9kusv626lfymvwdczyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7zg7gr5</id>
    
      <title type="html">On a train to #Dagstuhl, I finally got to read the nice write-up ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsf3z0lh65tvw6xhp5wd43y5g0xxne0gtw0mpp9kusv626lfymvwdczyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7zg7gr5" />
    <content type="html">
      On a train to #Dagstuhl, I finally got to read the nice write-up about on-device local-web-to-app tracking: &lt;a href=&#34;https://localmess.github.io/assets/bridges-to-self-localmess-usenix-security-26.pdf&#34;&gt;https://localmess.github.io/assets/bridges-to-self-localmess-usenix-security-26.pdf&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;TL;DR summary: You might want to uninstall (or deactivate if pre-loaded) all #Facebook and #Yandex apps from your phone. That kind of behavior is pretty clearly malicious - not even just ethically wrong, but seems actually illegal (at least in the EU, though IANAL).
    </content>
    <updated>2026-04-19T10:05:32Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxxp3ae7jlhnav6zr0awlg7gkdm960fne33wjpstue6wu6nv67maczyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7gyuh9n</id>
    
      <title type="html">I just learned that a new release of the decentralized, open ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxxp3ae7jlhnav6zr0awlg7gkdm960fne33wjpstue6wu6nv67maczyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7gyuh9n" />
    <content type="html">
      I just learned that a new release of the decentralized, open source Android (and iOS, but that requires a centralized Apple service) key attestation library warden-supreme has landed. It explicitly supports alternative/custom roots of trust for the attestation chain now and comes with a test for &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1kwarc5z9lwhen05uknd2nuwhhthd4ws0cku3t9j3rchm0fcd6luslse0nj&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;GrapheneOS&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1kwa…e0nj&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; keys: &lt;a href=&#34;https://github.com/a-sit-plus/warden-supreme/blob/development/serverside/roboto/src/test/kotlin/GrapheneOsTests.kt&#34;&gt;https://github.com/a-sit-plus/warden-supreme/blob/development/serverside/roboto/src/test/kotlin/GrapheneOsTests.kt&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Nice! That&amp;#39;s a good match to our academic research direction on digital identity (&lt;a href=&#34;https://digidow.eu&#34;&gt;https://digidow.eu&lt;/a&gt;) - avoiding points of centralization for better resilience (against many types of threats). We&amp;#39;ll most probably use this for our prototype Android apps that require or benefit from key attestation guarantees and can&amp;#39;t/shouldn&amp;#39;t use Play Integrity (e.g., because they only communicate over Tor hidden services with each other, and having a Warden backend included on one side is much easier than coming up with a form of mixnet proxy service for querying central instances while retaining an unlinkability guarantee).
    </content>
    <updated>2026-03-24T20:47:14Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsykwevy027emevzx4a8933dx9tkul7lx3z2uq7qlc2lu9p2dhjz4gzyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7gvslz0</id>
    
      <title type="html">The #KeepassXC discussion about GenAI coding tool use seems a bit ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsykwevy027emevzx4a8933dx9tkul7lx3z2uq7qlc2lu9p2dhjz4gzyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7gvslz0" />
    <content type="html">
      The #KeepassXC discussion about GenAI coding tool use seems a bit too simplistic at the moment. &lt;br/&gt;&lt;br/&gt;There is room for nuance:&lt;br/&gt;&lt;br/&gt;1. Yes, LLM based code generators consume insane amounts of electricity and generate collateral environment damage. That&amp;#39;s bad, and we should talk much more about energy efficiency and reasonable use of resources.&lt;br/&gt;&lt;br/&gt;2. Yes, LLMs generate a lot of bad output that should never ever be used without cross-checking for any purpose that needs to work on facts instead of convincing fiction.&lt;br/&gt;&lt;br/&gt;3. No, using LLMs for coding work does not automatically mean all the resulting code (at the end of a multi-stage process) is bad or insecure. If the generated code is manually verified by human experts, that is not much different from code contributed by junior developers in such a domain. They also make mistakes and might not have the right mental model when writing code. That&amp;#39;s why production code - especially with security impact - *strictly requires* code review by senior developers. I still trust &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub16s62vtezdafz7mkqq9ynjssgus0vc3l569fjt0337pdxtzdh82vs7j2ny3&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Team KeePassXC&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub16s6…2ny3&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; developers to do that based on their track record.&lt;br/&gt;&lt;br/&gt;4. I have used LLMs for quicker coding myself, but so far only as autocomplete&#43;&#43; when I know the program structure I want to achieve and get some help for language syntax and standard libraries that I am not completely familiar with (hello to Rust...). However, I always review every single line of autocompleted code, and often correct/change it.&lt;br/&gt;&lt;br/&gt;5. With some of the recent research and industry practice I have seen, specific aspects of programming might actually be candidates for benefitting from LLMs as a tool because those tasks fall into the one niche problem category for which I believe these tools to help *and* where they can be used with limited risk: a) the problem domain actually being textual languages; b) with a huge potential solution space; c) coupled with the possibility for automated verification of the solution quality. LLMs can be used to generate solution *candidates* (potential source code) which are then rigorously checked (automatically through strongly-typed compilers, fuzzing, extensive unit and integration tests, etc., and manually through code reviews).&lt;br/&gt;&lt;br/&gt;6. It seems to become realistic to use much smaller, locally hosted LLMs instead of huge, cloud hosted ones. Yes, the quality difference is significant at the moment. No, that does not have to stay that way.&lt;br/&gt;&lt;br/&gt;While I personally remain quite skeptical about the benefits/risk balance of LLMs for many of the use cases they are currently applied to, I am going to watch this particular one very closely in the near future.
    </content>
    <updated>2025-11-08T23:25:44Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdu9dhhr7ah9r8dqmtkq40nt8lv0z0zy2xtatq44k0dwaj86khnxczyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7mnhjer</id>
    
      <title type="html">I could not in good conscience recommend Netgear at this point, ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdu9dhhr7ah9r8dqmtkq40nt8lv0z0zy2xtatq44k0dwaj86khnxczyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7mnhjer" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdk3ssy9nslsz7qwrjfr0n208xwahjhs0hwfc48ydwmh3snuz4f9chjzxqa&#39;&gt;nevent1q…zxqa&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I could not in good conscience recommend Netgear at this point, both in terms of hardware longevity and security track record. #OpenWRT is a good pick on devices that support it or come natively with it like &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub16u690uxawjt9nkxlv0upwe8m6cqgfhz3t43lq97x8cssw969jadqpl33yx&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Turris project&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub16u6…33yx&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;. If open source is not a priority but networking flexibility is, then &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1lu0a3d74swtlqzze92c7ednh9vyaj9js7mcwkfjlqupalganaufs3nq9t4&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;MikroTik&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1lu0…q9t4&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; are fairly impossible to beat in terms of features-per-pricepoint (and support old hardware with #RouterOS for basically forever). None of these require cloud registration, of course.
    </content>
    <updated>2025-10-31T17:50:39Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqst9qs904jyujvma9f8wgrxlegc59rn3tqfpfk88atjqghq4sl7dpqzyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7wgrpz3</id>
    
      <title type="html">Are OEMs classified as gatekeepers? Because they decide what goes ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqst9qs904jyujvma9f8wgrxlegc59rn3tqfpfk88atjqghq4sl7dpqzyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7wgrpz3" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsxlggmmusgw0e440rdvsdy3nehhch70ulvvuz8nqx4jegkyapq2hc5rshzq&#39;&gt;nevent1q…shzq&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Are OEMs classified as gatekeepers? Because they decide what goes into the system images.&lt;br/&gt;&lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub158wd2v30vsywf2scxes7v5snceuwgcl73hhd4sx2eyyc87f3p9vslap2m9&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Hans-Christoph Steiner&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub158w…p2m9&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;
    </content>
    <updated>2025-09-19T18:26:27Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqst47daufrtzhzvwta38epqqhpezrj6j4sntc6m2fah3rpvnjh5g2czyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7hkxh5m</id>
    
      <title type="html">Uninstalling is indeed technically impossible if an OEM bundled ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqst47daufrtzhzvwta38epqqhpezrj6j4sntc6m2fah3rpvnjh5g2czyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7hkxh5m" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvuvdvv9g23jqf99fhnsfhps4g5r6k53lqape06gpmhruqjrthxzs6lre85&#39;&gt;nevent1q…re85&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Uninstalling is indeed technically impossible if an OEM bundled the app into any of the (read-only, compressed, integrity protected) system/OEM/vendor partitions. Disabling is functionally equivalent with the only exception of the storage space not being freed. &lt;br/&gt;&lt;br/&gt;So the real option is only for OEMs not to pre-install these apps in the first place, but potentially only during first setup wizard.
    </content>
    <updated>2025-09-19T18:16:07Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqyvaseeej395l99v4tazzdcnwznztz9g7s0rc9qkdkw3v3s6zsqgzyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7nv9s55</id>
    
      <title type="html">I have been running my own personal/family email server since ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqyvaseeej395l99v4tazzdcnwznztz9g7s0rc9qkdkw3v3s6zsqgzyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7nv9s55" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvat35d3w73539cts7t8jvypqw0drhpcx7sxc5mwynlmc9qnsdugqgpuzsw&#39;&gt;nevent1q…uzsw&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I have been running my own personal/family email server since over 25 years ago and recently migrated from my last custom postfix/dovecot/rspamd setup to &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1zq8eamasqdm2vmp89wgk7lngrzlpwtwk0ycqaqfq964s45erzwws8k44y6&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;mailcow ✅&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1zq8…44y6&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;.&lt;br/&gt;Yes, occasionally Gmail erroneously puts my whole domain in a block (not even marking as spam, but SMTP receipt blocking) and I have to wait for months for it to be lifted again. And let&amp;#39;s best not talk about the various kinds of Microsoft email badness. #JKU has been running a local email service for even longer, and it still very much works. All the issues caused by big centralized email hosters are even more of an argument to keep servers decentralized and federated than to give up, from my point of view...
    </content>
    <updated>2025-05-16T15:14:57Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs8zuscfhzse5szxqwktu9c02pyutm4dma2s4w80dzazrxpfeugx3czyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty79fa4v0</id>
    
      <title type="html">Email is critical infrastructure in today&amp;#39;s digitalized ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs8zuscfhzse5szxqwktu9c02pyutm4dma2s4w80dzazrxpfeugx3czyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty79fa4v0" />
    <content type="html">
      Email is critical infrastructure in today&amp;#39;s digitalized world. Relying on foreign hosting is not a good idea for anybody at risk of political interference because of their profession.&lt;br/&gt;Hosting email locally is still very much possible, even if it gets more involved year of year. Email is the one federated protocol that we have for direct communication. Even with all of its deficiencies in security and privacy, it is the common denominator that connects people. Don&amp;#39;t give up control over your own, most basic digital communication channel. Use local hosting companies that you can still call in an emergency, ideally within your own (maybe extended, like EU level) jurisdiction.&lt;br/&gt;&lt;br/&gt;Context: &lt;a href=&#34;https://eupolicy.social/@bert_hubert/114511178410991783&#34;&gt;https://eupolicy.social/@bert_hubert/114511178410991783&lt;/a&gt;
    </content>
    <updated>2025-05-16T06:40:01Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqspedyqqaafndlsy074raat286wwdj5usf9vhx37u2pkrec8a5xveqzyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7lpkhgj</id>
    
      <title type="html">I co-signed this open letter ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqspedyqqaafndlsy074raat286wwdj5usf9vhx37u2pkrec8a5xveqzyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7lpkhgj" />
    <content type="html">
      I co-signed this open letter (&lt;a href=&#34;https://edri.org/our-work/technical-experts-call-on-virkkunen-for-a-seat-on-the-table-european-commissions-technology-roadmap-on-encryption/&#34;&gt;https://edri.org/our-work/technical-experts-call-on-virkkunen-for-a-seat-on-the-table-european-commissions-technology-roadmap-on-encryption/&lt;/a&gt;) from the academic side because I (still) do not believe that #messenger #surveillance (aka #chatcontrol) can be done in a safe manner. While the goals - at least as worded, maybe not always as intended - are worthwhile, the proposed measures simply do not work on a technical level, and laws cannot change that reality.
    </content>
    <updated>2025-05-05T15:02:20Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs2nsyrhcyenjvmy2pytksz90jv6lgg7hyag4xy28xa7pflnc2v45czyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7e4gx9n</id>
    
      <title type="html">If you are an #academic in the #US with a position comparable to ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs2nsyrhcyenjvmy2pytksz90jv6lgg7hyag4xy28xa7pflnc2v45czyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7e4gx9n" />
    <content type="html">
      If you are an #academic in the #US with a position comparable to tenured or associate professor and a solid research track record in a field related to computer science (treat this in a very broad manner) and are interested in relocating to beautiful, liberal, safe, #Austria, then please reach out to me. We&amp;#39;d love to welcome new colleagues in the Austrian academia!&lt;br/&gt;&lt;br/&gt;A couple of us are collecting profiles to potentially match with organizations that are looking to fund such opportunities. Full caveat: I don&amp;#39;t yet have concrete positions confirmed, but am trying to get the funding bodies into position to do so.&lt;br/&gt;&lt;br/&gt;Please boost!
    </content>
    <updated>2025-04-13T08:18:37Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgcllpd6e9r065taj2shclyqkg00722qz89g9837qq9v09wht0q4szyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7dfanwh</id>
    
      <title type="html">Sigh. We are, as a security community, making good progress on ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgcllpd6e9r065taj2shclyqkg00722qz89g9837qq9v09wht0q4szyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7dfanwh" />
    <content type="html">
      Sigh. We are, as a security community, making good progress on some old as well as some new topics. #Rust, #Go, and other memory safe systems languages are going well and having a real impact in reducing memory safety issues - which has been the most important security bug class for decades, and we are finally improving! Compartmentalization and isolation of processes and services have now become common knowledge and the minimum bar for new designs. Security and privacy by design are being honored in many new projects, and not just as lip service, but because the involved developers deeply believe in these principles nowadays. #E2EE is finally available to most end-users, both for messaging and backups.&lt;br/&gt;&lt;br/&gt;And again and again, we are forced into having discussions (&lt;a href=&#34;https://www.theregister.com/2025/04/03/eu_backdoor_encryption/&#34;&gt;https://www.theregister.com/2025/04/03/eu_backdoor_encryption/&lt;/a&gt;) about breaking all the progress.&lt;br/&gt;&lt;br/&gt;Let me be clear for Nth time: &lt;br/&gt;* We *cannot* build encryption systems that can only be broken by the &amp;#34;good guys&amp;#34;. If they are not completely secure, foreign enemy states, organized crime, and intimate partners will break and abuse them as well. There is no halfway in this technology. Either it is secure or it isn&amp;#39;t - for and against everybody.&lt;br/&gt;* We *cannot* build safe, government-controlled censorship filters into our global messaging apps that are not totally broken under the assumption of (current or future) bad government policies and/or insider attacks at the technology providers (&lt;a href=&#34;https://www.mayrhofer.eu.org/talk/insider-attack-resistance-in-the-android-ecosystem/&#34;&gt;https://www.mayrhofer.eu.org/talk/insider-attack-resistance-in-the-android-ecosystem/&lt;/a&gt;). Either one-to-one communication remains secure and private, or it doesn&amp;#39;t (&lt;a href=&#34;https://www.ins.jku.at/chatcontrol/&#34;&gt;https://www.ins.jku.at/chatcontrol/&lt;/a&gt;).&lt;br/&gt;* We *cannot* allow exploitation of open security vulnerabilities in smartphones in other devices for law enforcement. If they are not closed, they are exploitable by everybody. &amp;#34;Nobody but us&amp;#34; is an illusion, and makes everybody less secure.&lt;br/&gt;&lt;br/&gt;My latest recorded public talk on the topic was &lt;a href=&#34;https://www.mayrhofer.eu.org/talk/secure-messaging-and-attacks-against-it/&#34;&gt;https://www.mayrhofer.eu.org/talk/secure-messaging-and-attacks-against-it/&lt;/a&gt;, and nothing factual has changed since then. Policymakers keep asking for a different technological reality than the one we live in, and that sort of thing doesn&amp;#39;t tend to produce good, sustainable outcomes.&lt;br/&gt;&lt;br/&gt;CC [@epicenter_works](&lt;a href=&#34;https://chaos.social/@epicenter_works&#34;&gt;https://chaos.social/@epicenter_works&lt;/a&gt; ) &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1w4rdxzdfz2ex25a42d0hw347r3gdapdk7llq6pjk347v8yf09djs2r8cxz&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;EDRi&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1w4r…8cxz&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; [@suka_hiroaki](&lt;a href=&#34;https://chaos.social/@suka_hiroaki&#34;&gt;https://chaos.social/@suka_hiroaki&lt;/a&gt; ) &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub13tdmf4a620rqaw6cykc0klc0udpnkhtg0qadwczyygfc3hgv4vyqr7njnt&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;heise Security&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub13td…njnt&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; [@matthew_d_green](&lt;a href=&#34;https://ioc.exchange/@matthew_d_green&#34;&gt;https://ioc.exchange/@matthew_d_green&lt;/a&gt; ) &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1qda00z7usyqlcqhrq92v8279r2p5hk5muuj6vvmsmeyc2h2t2a9qqqwevs&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Jan Penfrat&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1qda…wevs&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;
    </content>
    <updated>2025-04-09T08:12:52Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswl6p4fqzju5mkfrmzeqwglfm0jj74g3s9m4s3s4vy4e93c9rf0sczyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7sq00yp</id>
    
      <title type="html">It is pretty much certain that, given the current situation, I - ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswl6p4fqzju5mkfrmzeqwglfm0jj74g3s9m4s3s4vy4e93c9rf0sczyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7sq00yp" />
    <content type="html">
      It is pretty much certain that, given the current situation, I - and supposedly many others - won&amp;#39;t be traveling to the US this year. This means not being able to attend 3 out of 4 of the main academic security conferences, because they all keep refusing even to consider moving outside the US. Looking at you, &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1a39j5x5h5gfruc4u9thage2ld786ge6vqdgznk4zx5jum4cyfr4q2yn3y2&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;IEEE S&amp;P&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1a39…n3y2&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;, &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1lq0qzz5d89qhrmxjz5tnlgf6hmmjj9qmurvp38v2rt4qqc375uvs2n0y9k&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;NDSS Symposium&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1lq0…0y9k&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;, and &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1grfqh3learffqzt769lt5fudjvcht7qcec8ls2u3h2aqazt2gl7sd39wxf&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;USENIX Security&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1grf…9wxf&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;. &lt;br/&gt;&lt;br/&gt;It is clear that this is hurting the global security research community. We need to talk about major conferences outside the US to again become more inclusive.
    </content>
    <updated>2025-03-26T14:21:33Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9keekxs8qqwre8l68mgt7u3ajngcpxazpue4k0jhvahcnskgvz5czyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty760xtjv</id>
    
      <title type="html">Because &amp;lt;reasons&amp;gt; in #Austria right now, we seem to again ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9keekxs8qqwre8l68mgt7u3ajngcpxazpue4k0jhvahcnskgvz5czyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty760xtjv" />
    <content type="html">
      Because &amp;lt;reasons&amp;gt; in #Austria right now, we seem to again have the debate about &amp;#34;chat surveillance&amp;#34; (#chatcontrol) on the (newly forming) government level...&lt;br/&gt;&lt;br/&gt;The arguments and facts have not changed, so I am just posting my last public presentation slides [&lt;a href=&#34;https://www.mayrhofer.eu.org/talk/secure-messaging-and-attacks-against-it/2024-08-29_Secure-Messenger-Attacks.pdf&#34;&gt;https://www.mayrhofer.eu.org/talk/secure-messaging-and-attacks-against-it/2024-08-29_Secure-Messenger-Attacks.pdf&lt;/a&gt;] and recording [&lt;a href=&#34;https://media.ccc.de/v/26cd6d27-247f-5cf3-8adb-54c87bc372b2&#34;&gt;https://media.ccc.de/v/26cd6d27-247f-5cf3-8adb-54c87bc372b2&lt;/a&gt;] again. Oh, and &lt;a href=&#34;https://www.ins.jku.at/chatcontrol/&#34;&gt;https://www.ins.jku.at/chatcontrol/&lt;/a&gt; is still unchanged as well.&lt;br/&gt;&lt;br/&gt;To our new (and old) policymakers: Maybe read/listen and then we can happily talk efficiently about any new ideas that might come up?&lt;br/&gt;&lt;br/&gt;CC [@epicenter_works](&lt;a href=&#34;https://chaos.social/@epicenter_works&#34;&gt;https://chaos.social/@epicenter_works&lt;/a&gt; ) [@suka_hiroaki](&lt;a href=&#34;https://chaos.social/@suka_hiroaki&#34;&gt;https://chaos.social/@suka_hiroaki&lt;/a&gt; ) &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1vmgfak7rgrj09n5svcp7wn89r39245nuqtumwe30ryjm0dlmuwjshfyk7t&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Erich M.&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1vmg…yk7t&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; [@isec_tugraz](&lt;a href=&#34;https://infosec.exchange/@isec_tugraz&#34;&gt;https://infosec.exchange/@isec_tugraz&lt;/a&gt; ) &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1p2phu7kdl540vs6a89du6agkce6p8xaxtf65g9r0w7ful9vlncls83hjzg&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Open Rights Group&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1p2p…hjzg&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;
    </content>
    <updated>2025-02-27T15:52:11Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswn7gd5gq2srcch72uq6nwjdhjnd02vv5dqjuumegj0dfe8euj99szyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7pkem6w</id>
    
      <title type="html">Google owner drops promise not to use AI for weapons ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswn7gd5gq2srcch72uq6nwjdhjnd02vv5dqjuumegj0dfe8euj99szyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7pkem6w" />
    <content type="html">
      Google owner drops promise not to use AI for weapons&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.theguardian.com/technology/2025/feb/05/google-owner-drops-promise-not-to-use-ai-for-weapons&#34;&gt;https://www.theguardian.com/technology/2025/feb/05/google-owner-drops-promise-not-to-use-ai-for-weapons&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;&amp;gt; Alphabet guidelines no longer refer to not pursuing technologies that could ‘cause or are likely to cause overall harm’&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/951/699/432/436/491/original/d26a4ddfe99cc194.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-02-05T14:15:45Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsr69epjpmjmnp8w3lg2jgfvzevpa8srqhrh5farpnc8x4v4ewpfdgzyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7rhxxzv</id>
    
      <title type="html">I did a talk at #hackmas on &amp;#34;Secure Messaging (and attacks ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsr69epjpmjmnp8w3lg2jgfvzevpa8srqhrh5farpnc8x4v4ewpfdgzyzr5w0jsssmzaspm5cpjls5lccynxmazvpfqj4523faas5qg4zty7rhxxzv" />
    <content type="html">
      I did a talk at #hackmas on &amp;#34;Secure Messaging (and attacks against it)&amp;#34; and the great organization team has already put the video recording online at &lt;br/&gt;&lt;a href=&#34;https://media.ccc.de/v/26cd6d27-247f-5cf3-8adb-54c87bc372b2&#34;&gt;https://media.ccc.de/v/26cd6d27-247f-5cf3-8adb-54c87bc372b2&lt;/a&gt;. Many thanks to the audience for so many insightful questions and discussions - it is rare that the audience is so engaged and aware of nuance! Slides are available at &lt;a href=&#34;https://www.mayrhofer.eu.org/talk/secure-messaging-and-attacks-against-it/&#34;&gt;https://www.mayrhofer.eu.org/talk/secure-messaging-and-attacks-against-it/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Abstract: Secure messaging apps are one of the most-used app categories on current mobile devices, and a significant subset of human communication is handled through them. This makes them an interesting target for forensics, surveillance, and general information collection for intelligence services and police institutions. In this talk, we will discuss various options for such surveillance and their respective difficulties, pointing out which options do not seem realistic given all the practical considerations.&lt;br/&gt;&lt;br/&gt;TL;DR: There is no good option for surveiling E2EE messenger apps; all of them are broken or practically unrealistic in various ways. I don&amp;#39;t see an option to do that without real, significant problems that make all of us less safe. Please stop claiming that it is possible without these nasty issues.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/056/292/041/282/310/original/754cf6ed7842109e.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2024-08-31T11:01:52Z</updated>
  </entry>

</feed>