Bonum Certa Men Certa

Regaining Control Over Infrastructure With Decentralisation and Trusted Encryption

Clown computing isn't about security but lack of it (you've been compromised the moment you migrated to 'the clown')

Cloud Mass / rain is coming



Summary: Considering some recent developments in the GnuPG project, there are growing reasons for concern; recently we've been studying what alternatives to it already exist and are sufficiently mature; there are other betrayals or cases of divergence from a strict trust model and the issue needs to be brought up a lot more often

SOME of ours readers are security folks. They mostly agree with what we've published about conflating "fake trust" (authorisation from monopolies) with the user's trust (in effect not outsourcing trust to some dodgy, military-connected firms) and the idea that encryption between node and server (e.g. Facebook user and Facebook servers) is somehow "privacy", never mind if Facebook abuses all the data it gathers and moreover sells this data. This isn't privacy. This is a joke. The media helps these monopolies mislead the public, leaving people utterly confused about what privacy even means. Google says it's improving GMail privacy/security while harvesting, scanning and sharing with governments contents of E-mails. Is that privacy? Microsoft puts back doors in Windows (there's evidence), but at the same time it claims to deliver "security updates". What does security mean in this context? National security? As in US access to all of the files and communications of innocent people? Even on their own desktop/laptop?



But that's where it gets even worse. Years ago the father of Linus Torvalds said very publicly that his son had been asked by the NSA to put back doors in Linux. Not only did the son not deny this; he turned a question about it into a joke, refusing to explain if he agreed or not. This is no way to establish or regain trust.

Bison comingRecently, in light of the Guix petition, we've received some mail alarming us about GnuPG (it is among the signatures there, in effect seeking the ousting of Richard Stallman from the GNU Project -- a project that he founded).

"GnuPG is showing signs of compromise by outsiders," a reader recently told us. "I think we need to start looking at alternatives before the spyware starts to (inevitably) creep in. If [Werner] Koch can accommodate Yubico, he can accommodate the NSA and friends."

The Yubico Authenticator is developed on Microsoft (NSA/PRISM) servers with proprietary software and the product itself isn't trustworthy; it's proprietary itself. Yubikey is expensive snakeoil which raises the access barrier, both technically and fiscally (how many in poor African countries would shed a grand or two for a bunch of glorified "keys"?). Who stands to benefit? Probably the deep-pocketed (state-subsidised) surveillance giants that have redefined "security" and "privacy" their own way (they want us to assume they're guardians of both, not agents or facilitators of digital imperialism).

In the coming days we shall be writing about, then exploring, a plethora of alternatives. They do exist, not many people use these, and the media certainly isn't giving them the publicity they deserve. A lot of media coverage is nowadays up for sale; those who raise more money can dominate publishers or even so-called 'influencers' in social control media (to get paid-for 'endorsements').

Recent Techrights' Posts

Advertisers and Their Covert Impact on Publications' Output (or Writers' Topics of Choice, as Assigned or Approved by Editors)
It cannot be trivially denied that sponsorship in the form of "advertising" impacts where publishers go (or don't go, won't go)
Terrible Year for Microsoft Windows in Cyprus
down from 86% to 72% since January
 
Links 25/12/2024: Hong Kong Attacks Activists During Holidays, Xerox to Buy Lexmark
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, December 24, 2024
IRC logs for Tuesday, December 24, 2024
Gemini Links 25/12/2024: Open Source Social and No Search
Links for the day
Brittany Day Connects Windows Ransomware to "Linux" Using Microsoft LLMs (FUD Galore, Zero Effort, No Accountability)
FUD and misinformation made by Microsoft LLMs again?
Links 24/12/2024: Labour Strikes and TikTok Scrambling to Prop Up Radical Politicians That Would Protect TikTok
Links for the day
Where the Population is Controlled by Skinnerboxes Inside People's Pockets (or Purses)
A very small fraction of mobile users practise or exercise freedom/control over the skinnerbox
[Meme] Coin-Operated Publishers (Gaming the Message, Buying the Narrative)
Advertise (sponsor) to 'play'
[Meme] How to Kill Unions (Staff on Shoestring Budget Cannot Afford Lawyers)
What next for the EPO? "Gig economy"?
The EPO's Staff Union (SUEPO) Takes Legal Action to Rectify the Decrease in Wages (Lessening of Purchasing Power)
here is what the union published
Gemini Links 24/12/2024: Deedum Gemini Client Gets Colour Support, Advent of Code 2024
Links for the day
Microsoft Windows Slides to New Lows in Colombia
Now Windows is at an all-time low
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, December 23, 2024
IRC logs for Monday, December 23, 2024
A Strong and Positive Closing for the Year's Last Week
In a lot of ways this year was a good one for Free software
Feels Too Warm for Christmas
Christmas is here, no snow in sight
Links 23/12/2024: 'Negative Time' and US Arms Taiwan Again
Links for the day
Links 23/12/2024: The Book of Uncommon Beings, Squirrels, and Slop Ruining Workplaces
Links for the day
Links 23/12/2024: North Korean Death Toll in Russia at ~1,100, Oligarch Who Illegally Migrated/Stayed (Musk) Shuts Down US Government
Links for the day
The World's 'Richest Country' Chooses GNU/Linux
This has gone on for quite some time
Richard Stallman on Love
Richard Stallman's personal website includes a section that lists three essays on the subject of love
Apple's LLM Slop Told Us Luigi Mangione Had Shot Himself, BetaNews Used LLMs to Talk About a Dead Linus Torvalds
They can blame it on some bot
Microsoft, Give Me LLM Slop About "Linux" and "Santa", I Need Some Fake Article...
BetaNews is basically an LLM slop site
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, December 22, 2024
IRC logs for Sunday, December 22, 2024