Bonum Certa Men Certa

Regaining Control Over Infrastructure With Decentralisation and Trusted Encryption

Clown computing isn't about security but lack of it (you've been compromised the moment you migrated to 'the clown')

Cloud Mass / rain is coming



Summary: Considering some recent developments in the GnuPG project, there are growing reasons for concern; recently we've been studying what alternatives to it already exist and are sufficiently mature; there are other betrayals or cases of divergence from a strict trust model and the issue needs to be brought up a lot more often

SOME of ours readers are security folks. They mostly agree with what we've published about conflating "fake trust" (authorisation from monopolies) with the user's trust (in effect not outsourcing trust to some dodgy, military-connected firms) and the idea that encryption between node and server (e.g. Facebook user and Facebook servers) is somehow "privacy", never mind if Facebook abuses all the data it gathers and moreover sells this data. This isn't privacy. This is a joke. The media helps these monopolies mislead the public, leaving people utterly confused about what privacy even means. Google says it's improving GMail privacy/security while harvesting, scanning and sharing with governments contents of E-mails. Is that privacy? Microsoft puts back doors in Windows (there's evidence), but at the same time it claims to deliver "security updates". What does security mean in this context? National security? As in US access to all of the files and communications of innocent people? Even on their own desktop/laptop?



But that's where it gets even worse. Years ago the father of Linus Torvalds said very publicly that his son had been asked by the NSA to put back doors in Linux. Not only did the son not deny this; he turned a question about it into a joke, refusing to explain if he agreed or not. This is no way to establish or regain trust.

Bison comingRecently, in light of the Guix petition, we've received some mail alarming us about GnuPG (it is among the signatures there, in effect seeking the ousting of Richard Stallman from the GNU Project -- a project that he founded).

"GnuPG is showing signs of compromise by outsiders," a reader recently told us. "I think we need to start looking at alternatives before the spyware starts to (inevitably) creep in. If [Werner] Koch can accommodate Yubico, he can accommodate the NSA and friends."

The Yubico Authenticator is developed on Microsoft (NSA/PRISM) servers with proprietary software and the product itself isn't trustworthy; it's proprietary itself. Yubikey is expensive snakeoil which raises the access barrier, both technically and fiscally (how many in poor African countries would shed a grand or two for a bunch of glorified "keys"?). Who stands to benefit? Probably the deep-pocketed (state-subsidised) surveillance giants that have redefined "security" and "privacy" their own way (they want us to assume they're guardians of both, not agents or facilitators of digital imperialism).

In the coming days we shall be writing about, then exploring, a plethora of alternatives. They do exist, not many people use these, and the media certainly isn't giving them the publicity they deserve. A lot of media coverage is nowadays up for sale; those who raise more money can dominate publishers or even so-called 'influencers' in social control media (to get paid-for 'endorsements').

Recent Techrights' Posts

Techrights' Statement on Code of Censorship (CoC) and Kent Overstreet: This Was the Real Purpose of Censorship Agreements All Along
Bombing people is OK (if you sponsor the key organisations), opposing bombings is not (a CoC in a nutshell)
 
GNU/Linux Reaches All-Time High in Europe (at 6%)
many in Europe chose to explore something else, something freedom-respecting
Patents Against Energy Sources That Reduce Pollution
this EV space (not just charging) is a patent mine field and it has long been that way
DARPA’s Information Innovation Office, Howard Shrobe, Values Compartmentalisation But Loses the Opportunity to Promote GNU/Linux and BSDs
All in all, he misses an opportunity
Wayland is an Alternative to X
the alternative to X (as in Twitter) isn't social control media but something like IRC
BetaNews, Desperate for Clicks, is Pushing Donald Trump Spam Created by LLMs (Slop)
Big clap to Brian Fagioli for stuffing a "tech" site with Trump spam (not the first time he uses LLMs to do this)
[Meme] Social Control Media Bliss
"My tree is bigger than yours"
Links 24/11/2024: More IMF Bailouts and Net Client Freedom
Links for the day
Gemini Links 24/11/2024: Being a Student and Digital Downsizing
Links for the day
[Meme] The Most Liberal Company
"Insurrection? What insurrection?"
apple.com Traffic Down Over 7%, Says One Spyware Firm; Apple's Liabilities Increased Over 6% to $308,030,000,000
Apple is also about 120 billion dollars in debt
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, November 23, 2024
IRC logs for Saturday, November 23, 2024
[Meme] GAFAMfox
Mozilla Firefox in a state of extreme distress
Google Can Kill Mozilla Any Time It Wants
That gives Google far too much power over its rival... There are already many sites that refuse to work with Firefox or explicitly say Firefox isn't supported
Free (as in Freedom) Software Helps Tackle the Software Liability Issue, It Lets Users Exercise Greater Control Over Programs
Microsofters have been trying to ban or exclude Free software
In the US, Patent Laws Are Up for Sale
This problem is a lot bigger than just patents
ESET Finds Rootkits, Does Not Explain How They Get Installed, Media Says It Means "Previously Unknown Linux Backdoors" (Useful Distraction From CALEA and CALEA2)
FUD watch
Techdirt Loses Its Objectivity in Pursuit of Money
The more concerning aspects are coverage of GAFAM and Microsoft in particular
Links 23/11/2024: Press Sold to Vultures, New LLM Blunders
Links for the day
Links 23/11/2024: "Relationship with Oneself" and Yretek.com is Back
Links for the day
Links 23/11/2024: "Real World" Cracked and UK Online Safety Act is Law
Links for the day
Links 23/11/2024: Celebrating Proprietary Bluesky (False Choice, Same Issues) and Software Patents Squashed
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, November 22, 2024
IRC logs for Friday, November 22, 2024
Gemini Links 23/11/2024: 150 Day Streak in Duolingo and ICBMs
Links for the day
Links 22/11/2024: Dynamic Pricing Practice and Monopoly Abuses
Links for the day
Topics We Lacked Time to Cover
Due to a Microsoft event (an annual malware fest for lobbying and marketing purposes) there was also a lot of Microsoft propaganda
Microsofters Try to Defund the Free Software Foundation (by Attacking Its Founder This Week) and They Tell People to Instead Give Money to Microsoft Front Groups
Microsoft people try to outspend their critics and harass them
[Meme] EPO for the Kids' Future (or Lack of It)
Patents can last two decades and grow with (or catch up with) the kids
EPO Education: Workers Resort to Legal Actions (Many Cases) Against the Administration
At the moment the casualties of EPO corruption include the EPO's own staff
Gemini Links 22/11/2024: ChromeOS, Search Engines, Regular Expressions
Links for the day
This Month is the 11th Month of This Year With Mass Layoffs at Microsoft (So Far It's Happening Every Month This Year, More Announced Hours Ago)
Now they even admit it
Links 22/11/2024: Software Patents Squashed, Russia Starts Using ICBMs
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, November 21, 2024
IRC logs for Thursday, November 21, 2024