this post was submitted on 28 Nov 2023
766 points (100.0% liked)

196

18051 readers
896 users here now

Be sure to follow the rule before you head out.


Rule: You must post before you leave.



Other rules

Behavior rules:

Posting rules:

NSFW: NSFW content is permitted but it must be tagged and have content warnings. Anything that doesn't adhere to this will be removed. Content warnings should be added like: [penis], [explicit description of sex]. Non-sexualized breasts of any gender are not considered inappropriate and therefore do not need to be blurred/tagged.

If you have any questions, feel free to contact us on our matrix channel or email.

Other 196's:

founded 2 years ago
MODERATORS
766
encrulepted (retr0.id)
submitted 2 years ago* (last edited 2 years ago) by masimatutu@nerdica.net to c/196@lemmy.blahaj.zone
 

retr0.id/media/bd23a2fb-c7a6-4…

alt text:

Goose chase meme. In the first frame, the goose asks "all the data is encrypted?" In the second, the goose chases a person, asking "encrypted how and with whose keys, motherfucker?"

@196

all 44 comments
sorted by: hot top controversial new old
[–] pohart@programming.dev 99 points 2 years ago (3 children)

I once had to work with a government agency that insisted they generate and provide my private key.

[–] peopleproblems@lemmy.world 41 points 2 years ago

At least they told you about the wire tap?

[–] 8ace40@programming.dev 28 points 2 years ago (2 children)

I'm migrating millons of encrypted credit cards from one platform to another (it's all in the same company, but different teams, different infra, etc).

I'm the one responsible for decrypting each card, preparing the data in a CSV, and encrypting that CSV for transit. Other guy is responsible for decrypting it, and loading it into the importer tool. The guy's technical lead wanted me to generate the pair of keys and send him the private key, since that way I didn't have to wait for the guy and "besides, it's all in the same company, we're like a family here".

Of course I didn't generate the key pair and told them that I didn't want to ever have access to the private key, but wow. That made me lose a lot of respect for that tech lead.

[–] IDontHavePantsOn@lemm.ee 15 points 2 years ago

So you wanna be key buddies? Respectfully.

[–] uis@lemmy.world 2 points 2 years ago

I know one municipal agency that does the same...

[–] joyjoy@lemm.ee 69 points 2 years ago (3 children)
[–] verdare@beehaw.org 31 points 2 years ago (1 children)

The fact that you have to enter your iCloud credentials directly into the app was a red flag.

Security PSA: Don’t enter passwords or other secrets for important accounts directly into a third party UI. This is why we have tokens and federated login. Third parties should never see your Google/Apple/whatever credentials.

[–] ALostInquirer@lemm.ee 6 points 2 years ago (1 children)

Security PSA: Don’t enter passwords or other secrets for important accounts directly into a third party UI.

By chance, would you (or some other passerby) happen to know how this is handled with the Lemmy apps/interfaces? I've been mixed on using them since I'm unclear how they're handling this info.

[–] verdare@beehaw.org 8 points 2 years ago* (last edited 2 years ago)

Hmmm, that’s a good point. I did type my Lemmy credentials directly into at least two different apps. I guess it would be better if it redirected to a login page provided by my instance (Beehaw). But I also don’t consider my Lemmy account to be very critical. It’s not a huge deal if it gets compromised, as long as it’s not associated with my real identity.

EDIT: Also, I use a password manager, so a leak of my randomly generated Lemmy password shouldn’t affect anything else.

[–] pineapplelover@lemm.ee 19 points 2 years ago (1 children)

Probably also whatsapp chat, imessage, and other proprietary encrypted messaging apps out there.

[–] joyjoy@lemm.ee 23 points 2 years ago (2 children)

Many chat apps actually use the Signal protocol for end to end encryption. This includes WhatsApp, Google Messages (RCS), Facebook Messenger, and Skype. iMessage doesn't seem to use it.

[–] LWD@lemm.ee 16 points 2 years ago* (last edited 2 years ago) (1 children)
[–] AVincentInSpace@pawb.social 3 points 2 years ago (1 children)

Why is end to end encryption a red flag???

[–] LWD@lemm.ee 15 points 2 years ago* (last edited 2 years ago) (1 children)
[–] AVincentInSpace@pawb.social 7 points 2 years ago (1 children)

oh, red flag for facebook, that makes sense.

but then if you care about privacy why touch anything Facebook has made at all?

[–] LWD@lemm.ee 6 points 2 years ago* (last edited 2 years ago)
[–] Lemongrab@lemmy.one 9 points 2 years ago

But we also can't check their process since they are closed source. Also, if they can decrypt in the browser or proprietary app, then they can still read your messages. Browser is vulnerable to other attacks.

[–] isVeryLoud@lemmy.ca 16 points 2 years ago

That's not even Nothing Chats' biggest problem: it's that it gets completely MITM'd by going onto some mac mini in some server farm somewhere.

[–] the_seven_sins@feddit.de 47 points 2 years ago (4 children)

I suggest we rename base64 to ’Military encryption’.

[–] lseif@sopuli.xyz 27 points 2 years ago

ITS NOT ENCRYPTION ITS ENCODING D':

[–] AlecSadler@lemmy.world 13 points 2 years ago

I love seeing ads touting "military grade" things, it basically means...it probably isn't worth buying.

[–] AnUnusualRelic@lemmy.world 7 points 2 years ago

Isn't that rot13?

[–] FrankTheHealer@lemmy.world 7 points 2 years ago

'Military GRADE encryption' *

[–] Sneptaur@pawb.social 37 points 2 years ago (1 children)

Looking directly at you, Telegram!!

[–] uis@lemmy.world 3 points 2 years ago

At least it has one-to-one E2EE and straight upgrade from vk.

[–] gmtom@lemmy.world 36 points 2 years ago

It's encrypted by changing the font to windings and making the text colour white before sending.

[–] Speiser0@feddit.de 31 points 2 years ago

Our website is using ssl, to keep you protected.™

[–] JackLSauce@lemmy.world 21 points 2 years ago (3 children)

Wow wow wow wow wow wow wow wow wow wow wow wow wow wow wow wow wow wow wow wow wow wow.... The data are encrypted

[–] pythonoob@programming.dev 13 points 2 years ago (1 children)

Ugh. This is one of the correct usages that actually bothers me.

[–] CoggyMcFee@lemmy.world 6 points 2 years ago (2 children)

Correct according to whom? The word has a long history of being used with a singular verb. The dictionary indicates it is usually used with a singular verb. Only a small number of people insist on trying to override this.

Who cares if it is plural in Latin? Once something moves into a new language, it’s not beholden to the old language. We don’t use a plural verb with “spaghetti”. Germans borrowed the word “party” from English and they pluralize it as “partys” — they don’t need to follow our rules for what is now also their word.

Don’t give in to these people who claim that “data” is supposed to be plural. They are treating a personal preference as a fact.

[–] bob_lemon@feddit.de 2 points 2 years ago

To be fair, German (and other languages) borrowing from Italian is a whole can of worms, but you're right: Borrowed words don't need to follow all the declination or conjugation roles from their original language.

See also: Two espressos. One zucchini.

[–] pythonoob@programming.dev 1 points 2 years ago

God I think I love you

[–] CJOtheReal@ani.social 9 points 2 years ago (1 children)
[–] quantenzitrone@feddit.de 2 points 2 years ago

that actually called encoded🤓

[–] SpaceCadet@feddit.nl 1 points 2 years ago* (last edited 2 years ago) (1 children)

So there's like a talking goose and your first thought is to criticize it on grammar?

[–] beebarfbadger@lemmy.world 17 points 2 years ago
[–] stebo02@sopuli.xyz 15 points 2 years ago

just a vigenere cipher because budget cuts

[–] CJOtheReal@ani.social 15 points 2 years ago

Encrypted by Lava_Lämp®

[–] cupcakezealot@lemmy.blahaj.zone 14 points 2 years ago

it's ok i'm always losing my keys anyway

but my couch cushions are pretty secure

[–] dipshit@lemmy.world 13 points 2 years ago

openssl and I created my own keys! suck it, verisign!

Now tell me all the {en,de}cryption points in your event sourcing.

[–] uis@lemmy.world 3 points 2 years ago

I'm a goose and I'm coming for yous!