"Forbidden communication" That's why ungovernable IMs are so needed. There will always be 31337 people who don't like this, don't like that, here and there, everywhere.
🔔 This profile hasn't been claimed yet. If this is your Nostr profile, you can claim it.
Edit
"Forbidden communication" That's why ungovernable IMs are so needed. There will always be 31337 people who don't like this, don't like that, here and there, everywhere.
So I understand they have to expose the controllers to the fucking internet, and can't use a vpn and an isolated lan? Srsly?
Snapshot Yo!
Any "TPM based" drive encryption is badly designed. You don't need to act on this information, all you need to do is to remember it.
Yes, you are right, checking if entropy is "proper" is a problem, I'm not aware of any methods available right now which could be used Maybe that's why some are so paranoid about joining multiple sources to be sure to some degree without a possible check
"Illegal" "underground" datasets go brrrr
We did. Look at Veracrypt, up to this day it's gathering entropy from mouse movements and mixes it with other sources. One of the biggest mistakes is using HSMs. And "trusting" hardware black boxes which claim they generate proper RND. Those are not cryptographically safe methods to store and generate key material. The same with "phone encryption" and the 16 chars limit for android password which goes only through an scrypt() is just fucking insane. And no. Phone HSM doesn't count here. One day it may turn out, all smart cards for "signatures" had bad RNGs. But maybe, only maybe, there is a push, for invalid HSMs, to weaken cryptography. Shorter keys, weaker algo, no new AES. I don't like that.
One word: censorship. He is proposing censorship and a rise to an LLM underground.
And it's possible only because the TV has a locked bootloader. Otherwise a simple modification would turn the feature off. Don't use devices with locked bootloaders - you will doom humanity this way. And yes, Apple already used a locked bootloader for purposes other than security. In particular for behavior control.
"First you climb, they ignore you, then you have to stand up, they laugh at you, then you jump, that's when they start to fear you"
Veracypt gathers entropy from mouse movements to encrypt your data. THiS METHOD IS THERE FOR 22 FUCKING YEARS. Guess why. Yet magically, people trust some closed-source hardware RNGs when it comes to even more important stuff like protecting money. Keep listening to google and apple that HSMs and hardware attestation is good and you will all end exactly like those who lost the money or even worse in multiple other cases. And NO. Server side HSMs keeping 6 digit pin for "X chat" are NOT GOOD. This is BAD IMPLEMENTATION. Phone HSMs are BAD IMPLEMENTATION. You are all shooting yourself in the foot.
He forgot to add it will be a censored genie. And will grant wishes which THEY approve.
One hardware entropy source it not enough. Stop being "one". Our universe doesn't limit us to use ONE. You can have multiple computers, you can have multiple phones, multiple pins, multiple RNGs, multiple friends. It's almost like a sickness. And I don't know why, or where from, and I don't care. But what I know - artificialy limiting yourself to one fucking password on a fucking phone is fucking illogical. Stop thinking "one".
That's why people were freaking out when NSA allegedly tampered with one RNG algo. If unsure, use multiple sources of entropy, DO NOT XOR THEM. DO. NOT. XOR. THEM. Join them and hash them.
That's how a locked bootloader ends: https://xdaforums.com/t/fix-found-enabling-developer-menu-on-2025-cricket-motos.4742662/ Don't use devices with a locked bootloader. Buy an unlockable phone and unlock it.
Broken is the wicked idea of HSMs. I'm fucking repeating this over and over and over: FUCKING CONCENTRATE PLEASE: HSMs DO NOT PROTECT KEY METERIAL CRYPTOGRAPHICALLY. To avoid another extreme fuckup, please fucking learn what a KDF is and how encryption fucking works. You need ENTROPY to protect your data. NOT HSMS. NOT TPM. NOT TEE.
"A man used a gun without knowing how it works, he shot himself in a hand", he no longer knows if he will belive in guns. Cryptocurrency doesn't have it's name because wind was blowing that direction, it's on purpose. Don't use tools if you don't know how they work. Learn how encryption works, not hardware tpms, not hsms or enclaves, because they are all almost a scam. YOU WILL FALL VICTIM OF A BAD PHONE ENCRYPTION IN THE SAME WAY, IF YOU WON'T LEARN WHAT THE ENCRYPTION IS.
You know earth is flat and this is just a giant plasma display, right?
This! That's why limiting US based AIs is dumb as fuck, it could find vulns sooner. Otherwise kimi k3 will find it in the worst possible moment and in the wrong hands because defenders have no hardware to run it.
Will people now understand why all crypto world freaked out when NSA allegedly tried to backdoor an RNG? Probably not.
WARNING. PGP private key S2K is outdated! It does not protect shorter passwords. Always check the KDF and use high entropy passwords.
I don't think people will understand randomness from a pair of dice. But they do understand a "long password" or "random words", feed this into a strong kdf and there you have it, a nice random value. Also 12 words it not enough. Move to 24 words. And don't rely on hsm. HSMs are physical devices, they don't protect data cryptographically. But I could write this on everyone's forehead and you will fuck it up anyway. It's like talking to fucking brick wall.