Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Marvin W

@larma@mastodon.social
mastodon 4.8.0-nightly.2026-10-06
  • Open on mastodon.social

@microg@fosstodon.org creator · @dino@fosstodon.org developer · @xmpp@fosstodon.org council member · @fsfe@mastodon.social supporter

1067 Followers
139 Following
48 Posts
Joined October 21, 2018
GitHub:
https://github.com/mar-v-in
Liberapay:
https://liberapay.com/larma
Open post
Marvin W @larma@mastodon.social
· 9mo ago
Replying to
@spipau@mastodon.social @tbernard@mastodon.social Thus, rather than forking Android, we'd be better advised not to build on top of AOSP and instead use the free software platforms we already have as a basis, making use of the huge amount of developer effort and research put into free software Linux distributions and apps running on them, and making that available to smartphones. @postmarketOS@social.treehouse.systems is laying the groundwork here and initiatives like @modal@mastodon.design are pushing to build the remaining pieces to have something that can compete.
70
3
35
0
Open post
Marvin W @larma@mastodon.social
· 5mo ago
Replying to
@Lilith Und wenn man unbedingt etwas ins Smartphone einbauen will, warum nicht genau das, was wir schon haben, nur halt in einer secure enclave auf dem Smartphone statt auf der Plastikkarte. Also so, dass wer das möchte einfach weiter die Plastikkarte nutzen kann und das für alle Abnahmestellen exakt genau so aussieht, als hätte er ein Smartphone genutzt.
9
0
0
0
Open post
Marvin W @larma@mastodon.social
· 9mo ago
Replying to
@spipau@mastodon.social At any point, Google can decide to stop updating AOSP. Stop publishing security patches and new major updates. Of course you can still use the old code that's already published today, but it will be a security nightmare in just a few months and will stop being able to run new apps in 3-5 years. @tbernard@mastodon.social
20
16
9
0
Open post
Marvin W @larma@mastodon.social
· 5mo ago
Replying to
@unnon89 @Lilith Ich habe schon ein Bankkonto mit dem ePerso eröffnet. Geht schneller und einfacher und ist datenschutzfreundlicher als dieser Video-Ident quatsch, und für die Bank auch billiger. Eigentlich ein Win-Win. Ich hab auch mal eine Meldebescheinigung online mit ePerso erzeugt, aber das geht leider längst nicht überall. Und aus irgendeinem Grund musste ich da zwischendurch eine unnötige Bund-ID erzeugen nur um die im Anschluss wieder zu löschen. Für das Bankkonto war das nicht nötig.
7
0
0
0
Open post
Marvin W @larma@mastodon.social
· 5mo ago
Replying to
@p3m @Lilith @fluepke Molly @mollyim https://molly.im/ ist ein alternativer Signal-Client ohne diese proprietären Module.
Molly
molly.im

Molly

Molly is an improved Signal app for Android

6
0
1
0
Open post
Marvin W @larma@mastodon.social
· 2mo ago
Replying to
@gnome@felipeborges.eu I wonder if macOS guest support is something on your horizon or if you would take contributions for it.
1
3
0
0
Open post
Marvin W @larma@mastodon.social
· 9mo ago
Replying to
@spipau@mastodon.social @tbernard@mastodon.social microG could be continued without me. There are other contributors and certainly enough developers that could contribute. But that is because microG is a free software community project. Android in contrast is exclusively developed by Google. AOSP is merely a code dump, it's almost impossible for non-Googlers to contribute to Android or AOSP. Even if you were to fork it, you won't have the necessary developer and security researcher power to compete.
14
4
2
0
Open post
Marvin W @larma@mastodon.social
· 6mo ago
Replying to

@kuketzblog

Für 6 Accounts wurde tatsächlich etwas geliefert: Erstellungsdatum und letzter Verbindungszeitpunkt.

Da hast du dich wohl verlesen: Es wurden in dieser Vorladung nur Erstellungsdatum und letzter Verbindungszeitpunkt abgefragt, geliefert wurde tatsächlich sogar nur das Erstellungsdatum.

Andere Daten die Signal hat (wie zum Beispiel Anzahl der Geräte, deren Betriebssystem und Push Tokens) wurden hier schlicht nicht angefragt und deshalb auch nicht geliefert.

6
3
1
0
Open post
Marvin W @larma@mastodon.social
· 5mo ago
Replying to
@berglerma @skaphle @p3m @Lilith @fluepke Ja, im Prinzip werden Teile statisch gelinkt. Häufig wollen diese Teile dann aber mit der Play Services App (die du bei GrapheneOS u.U. nicht hast) kommunizieren (über eine private IPC API) oder wollen Code draus nachladen - ist die nicht da, funktioniert vieles deshalb nicht, zum Beispiel die Push Notifications. Es ist dennoch so, dass auch auf GrapheneOS der in Signal eingebettete proprietäre Code ausgeführt wird, der bricht dann halt recht früh ab.
3
0
0
0
Open post
Marvin W @larma@mastodon.social
· 5mo ago
Replying to
@skaphle @p3m @Lilith @fluepke Mir ist bisher in Google's statischen Code aber auch noch nichts offensichtlich problematisches untergekommen. Bei dynamisch geladenem Code habe ich tatsächlich noch nicht intensiver reingeguckt, das wäre aber ohnehin irrelevant, weil ich ja nicht weiß, ob beim nächsten mal überhaupt noch der gleiche Code geladen wird.
3
3
0
0
Open post
Marvin W @larma@mastodon.social
· 5mo ago
Replying to
@skaphle @p3m @Lilith @fluepke In einer Webseite hat eine eingebettete Karte übrigens keinen Zugriff auf den Inhalt drum herum, dafür sind entsprechende Sicherheitsmechanismen eingebaut, weil es im Web vorgesehen ist, Inhalte von unvertrauenswürdigen Quellen einzubetten (*). Android hat derartige Sicherheitsmechanismen theoretisch auch, sie werden aber von Play Services nicht genutzt, den Google vertraut sich selbst ja. (*) Da gibt es ab und an Sicherheitslücken, aber das ist ein anderes Thema.
3
0
0
0
Open post
Marvin W @larma@mastodon.social
· 5mo ago
Replying to
@p3m @Lilith @fluepke Und falls du dir jetzt denkst, dass zumindest die Signal-Entwickler den Quellcode dieser proprietären Module gesehen haben oder diesen anderweitig geaudited haben, Pustekuchen. Es handelt sich um Module von Dritten und selbst wenn man diese auditen würde, würde man lediglich feststellen, dass sie dynamisch Binärcode aus dem Internet nachladen und somit sämtliche Audits witzlos sind, weil darüber gezielt abweichender Code ausgeliefert werden könnte.
3
17
1
0
Open post
Marvin W @larma@mastodon.social
· 9mo ago
Replying to
@spipau@mastodon.social Of course it can go even more proprietary. Major parts of what typically is part of a phone OS, like the Clocks or SMS app, have been proprietary for a while now. Android 16 QPR1 (the latest version) was released to various devices in September, but the source code was only published 2 months later. And security updates are already being delayed in AOSP by up to three months vs the proprietary version. @tbernard@mastodon.social
7
17
0
0
Open post
Marvin W @larma@mastodon.social
· 5mo ago
Replying to
@skaphle @p3m @Lilith @fluepke Ganz im speziellen zum zweiten Faktor: Der wird zumindest bei kompetenten Banken (*) im sicheren Bereich des Smartphones gespeichert, sodass nicht mal die App selbst Zugriff darauf hat, sondern diesen nur zum signieren für einzelne Transaktionen nutzen kann, die dann jeweils mit Fingerabdruck oder PIN geprüft werden. Da kann dann auch Google nichts machen. (*) Will hier kein Banken-Shaming betreiben, aber definitiv nicht alle deutschen Banken tun das richtig.
2
2
0
0
Open post
Marvin W @larma@mastodon.social
· 5mo ago
Replying to
@skaphle @p3m @Lilith @fluepke Man muss an dieser Stelle übrigens unterscheiden zwischen eingebettetem Play Services (wie Signal es nutzt) und der auf dem selben Gerät installierten externen Play Services Hilfs-App. Letztere kann nicht, nur weil sie auf dem selben Gerät installiert ist, auf den Speicher von Signal zugreifen. Android trennt da relativ sauber zwischen den Apps ab. Ohne die Einbettung als Modul wäre Google der Zugriff auf Signal-Nachrichten also erstmal nicht möglich.
2
2
0
0
Open post
Marvin W @larma@mastodon.social
· 5mo ago
Replying to
@skaphle @p3m @Lilith @fluepke Spezifisch zu Play Services: Verschiedene Module von Play Services nutzen unterschiedliche Methoden um eingebettet zu werden. Manche, wie zum Beispiel Maps, laden Code dynamisch nach. Andere sind statisch, das heißt der gesamte Binärcode liegt im Modul selbst. Dann kann man theoretisch auch bei einem proprietärem Modul diesem Code einem Audit unterziehen. Ich glaube aber nicht, das Banken das tun.
2
4
0
0
Open post
Marvin W @larma@mastodon.social
· 5mo ago
Replying to
@cdonat @Lilith Das ist zwar eine gültige Meinung, aber wir haben digitale Altersverifikation ja schon heute. Zum Beispiel an vielen Zigarettenautomaten. Der Vorteil das bestehende Verfahren zu benutzen ist ja gerade, dass dieses relativ unflexibel ist (da in Hardware auf physischen Karten), man also nicht ohne weiteres neue Nachweise oder Zertifikate einführen kann. Ob man Social-Media-Anbieter verpflichtet, die eID zur Altersverifikation zu benutzen, steht auf einem anderen Blatt.
2
20
0
0
Open post
Marvin W @larma@mastodon.social
· 6mo ago
Replying to
@f09fa681 @kuketzblog Unter den abfragbaren Daten sind übrigens "telephone or instrument number or other subscriber number or identity, including any temporarily assigned network address". Ob jemals (erfolgreich) versucht wurde auf dieser Basis Push Tokens abzufragen weiß ich nicht, aber "subscriber identity" könnte an dieser Stelle eventuell so interpretiert werden.
2
1
1
0
Open post
Marvin W @larma@mastodon.social
· 5mo ago
Replying to
@p3m @Lilith @fluepke Der landläufige Name davon ist "Play Services". https://github.com/signalapp/Signal-Android/blob/main/gradle/libs.versions.toml#L153-L156
GitHub

Signal-Android/gradle/libs.versions.toml at main · signalapp/Signal-Android

A private messenger for Android. Contribute to signalapp/Signal-Android development by creating an account on GitHub.

1
14
0
0
Open post
Marvin W @larma@mastodon.social
· 5mo ago
Replying to
@cdonat @Lilith Wie gesagt, das sind völlig unabhängige Dinge. Selbst beim alten Personalausweis konnte man Fotos verlangen und/oder Video-Ident nutzen, um das Alter zu prüfen. Und davor gab es mal Post-Ident, wo man zur Post gehen musste um sich online zu verifizieren. Ob die Prüfung "digital" oder "analog" erfolgt ist doch völlig nebensächlich. Wenn ein Gesetz kommt, dass Social-Media-Plattformen zur Altersprüfung verpflichtet, dann verhindern wir das nicht, indem wir gegen eID sind.
1
10
0
0
Open post
Marvin W @larma@mastodon.social
· 5mo ago
Replying to
@cdonat @Lilith Seit wann brauchen föderierte Open-Source-Plattformen wie Mastodon eine Altersverifikation? Du vermengst hier einfach völlig unzusammenhängende Dinge. Die Möglichkeit die eID zum Verifizieren zu benutzen gibt es für zugelassene Anbieter schon heute. Für Social Media fehlt dazu eine Rechtsgrundlage, deshalb nutzen Anbieter das auch nicht (sondern wollen wie Facebook stattdessen ein Foto vom Ausweis). Ich habe nie vorgeschlagen eine Rechtsgrundlage dafür zu schaffen.
1
14
0
0
Open post
Marvin W @larma@mastodon.social
· 5mo ago
Replying to

@cdonat @Lilith

in diesem Zusammenhang

Sorry, welcher Zusammenhang genau?

Wenn Apps oder Websites das Alter des Nutzers verifizieren um nur Nutzer über 18 den Zugang zu ermöglichen, brauchen sie dann halt dafür eine Zulassung vom Bundesverwaltungsamt und vom BSI zertifizierte Sicherheitssysteme. Und dann erfahren sie genau eins: Dass der Nutzer über 18 ist. Das war aber ja ohnehin Bedingung zum nutzen der Webseite, also kein Erkenntnisgewinn im Profil.

1
16
0
0
Open post
Marvin W @larma@mastodon.social
· 5mo ago
Replying to
@cdonat @Lilith Sorry, aber das sind zwei vollständig unterschiedliche Paar Schuhe: Man kann digitale Ausweise zur Altersverifikation nutzen. Das ist der Status Quo. Das Missbrauchspotenzial ist dabei relativ gering, da nur zertifizierte Anbieter darauf zugreifen dürfen und diese strengen Datenschutzauflagen unterliegen. Sonst würden die Zigarettenautomaten nämlich garantiert ein Profil über dich anlegen. Und mein Vorschlag ist alles genau so zu lassen. Das hat mit Web-Tracking nichts zu tun.
1
18
0
0
Open post
Marvin W @larma@mastodon.social
· 9mo ago
Replying to
@rangelovd@mastodon.ml @dantescanline@autonomous.zone We were talking about AOSP stopping to receive updates, not the proprietary Android version devices run officially. If the device offers 7 years of updates, sure, it will receive 7 years of *proprietary* updates. But I'm not aware of any device coming with 7 years of AOSP updates. Because device manufacturers offer those 7 years based on a contract they have with Google for their proprietary Android. And that doesn't cover AOSP.
2
1
0
0
Open post
Marvin W @larma@mastodon.social
· 7mo ago

@artway@mastodon.social what is it that you want to achieve with a _turn SRV record?

Conversations (both server and client) use XEP-0215 to resolve host, port and credentials for TURN.

mastodon.social

artway (@artway@mastodon.social) - Mastodon

1
1
0
0
Open post
Marvin W @larma@mastodon.social
· 9mo ago
Replying to
@rangelovd@mastodon.ml @dantescanline@autonomous.zone 8 years ago, Android 8.1 was just freshly released. Here's what Android Studio defaults to for the minimum SDK version for new apps. Even if some developers might change this, most won't, so most new apps simply won't work on Android versions older than 10.0. And that doesn't even consider that some apps will opt to even higher version requirements simply because they require or wish to use newer features (like secure key storage, specific hardware APIs or similar).
1
5
0
0
Open post
Marvin W @larma@mastodon.social
· 34mo ago
Replying to

@newstik@social.heise.de There is a bunch of metadata that is made available when Signal links your Signal account to your Google device ID (which is needed to send push notifications):

  • If your device has a Google account signed in (most do to install Signal from the Play Store) your Signal account will be linked to your Google account
  • If you connect your phone to any wifi network, your Signal account will be linked to that wifi's IP address, often revealing your exact location to authorities
6
2
2
0
Open post
Marvin W @larma@mastodon.social
· 26mo ago
Replying to
@QuaternionCats@sleeping.town @grinceur@fosstodon.org I was considering the same. Technically, sending MathML would be easy and a reasonable thing to do. The complexity kicks in when thinking about mixed content (when a math formula is mixed into a regular message and not standalone), legacy compatibility (how to deal with clients that don't support it) and input.
2
1
0
0
Open post
Marvin W @larma@mastodon.social
· 34mo ago
Replying to

@newstik@social.heise.de

  • If you have any other apps installed that use push notifications, those would be linked to your Google device ID and thus your Signal account as well. Authorities can then link any data they get from those other apps also to your Signal account (and thereby phone number and identity).
3
1
2
0
Open post
Marvin W @larma@mastodon.social
· 65mo ago
Replying to
@blue @dino of course they are compatible with Conversations. Also we can do DTLS encrypted calls with Movim and Siskin. And for legacy clients like Gajim or Empathy we even support calls without encryption.
6
1
1
0
Open post
Marvin W @larma@mastodon.social
· 26mo ago
Replying to
@grinceur@fosstodon.org We won't have something that allows to invoke a TeX engine with arbitrary input on the remote end (as TeX is turing complete, this would be bad). What could be a reasonable option would be to have an input for a subset of LaTeX that is converted to a Unicode equivalent before sending or alternatively an easy way to enter LaTeX, render it locally into an image and send that image as a file instead.
1
1
0
0
Open post
Marvin W @larma@mastodon.social
· 71mo ago
Replying to

@reinhard Name another one that

  • respects your freedom and privacy
  • is not a walled garden
  • uses an open protocol standardized by a recognized standards organisation
  • provides a great user experience.

There aren't that many that fulfill all of these properties.

2
0
0
0
Open post
Marvin W @larma@mastodon.social
· 77mo ago
Replying to

@syster @dino

  1. GSoC is for students that are new to open-source contributions and work on a project for 3 months straight. Students propose their project, with some suggestions provided by the project maintainers (which act as mentors throughout the summer).

Depending on what you include in the goal of enabling e2ee by default, it's either far less than 3 months of work or requires deep understanding of crypto which you can hardly expect from most students.

2
0
0
0
Open post
Marvin W @larma@mastodon.social
· 77mo ago
Replying to
@syster @dino RTT can be encrypted using omemo:1 (and should be if you want to protect against malicious servers). RTT instructions are batched into messages of fixed intervals (something like 1s), making it impossible for servers to see any pattern (other than ongoing communication between the two users). If you don't want to leak that you are currently typing to a user, you need to turn off RTT. Dino allows you to turn off the "is typing"-notification for the same reason.
2
1
0
0
Open post
Marvin W @larma@mastodon.social
· 77mo ago
Replying to

@syster @dino

  1. The feature will have to be enabled for each conversation, it is expected to be only enabled with contacts you trust.
1
3
1
0
Open post
Marvin W @larma@mastodon.social
· 5mo ago
Replying to
@nelfan@gotosocial.social bridges don't support end-to-end encryption. Many XMPP server operators consider it problematic to host cleartext versions of messages that users on at least one side of the connection (e.g. on WhatsApp, Signal, ...) expect to be end-to-end-encrypted.
0
1
0
0
Open post
Marvin W @larma@mastodon.social
· 26mo ago
Replying to
@QuaternionCats@sleeping.town @grinceur@fosstodon.org My best idea here would be to a) allow LaTeX-style input b) convert to a reasonable Unicode representation and put that in the message body for legacy clients c) create a new standard on how to insert MathML into a message while removing the legacy fallback. However, even with this probably being a good idea, I don't see a lot of clients implementing it due to its complexity. And the c) part being optional, we should probably start with a)/b) first and then improve.
0
0
0
0
Open post
Marvin W @larma@mastodon.social
· 6mo ago
Replying to
@pojntfx @hbons @tbernard @zeenix @jsparber Wondering if it's maybe related to fractional scaling? I remember a similar issue with GTK on Windows.
0
0
0
0
Open post
Marvin W @larma@mastodon.social
· 5mo ago
Replying to
@cdonat @Lilith Ich wiederhole mich nur ungern: Wir haben das Instrument. Seit 15 Jahren. Alles was ich sage ist, dass das bestehende Instrument gut genug ist, und wir nichts neues brauchen oder anstreben sollten. Wofür dieses Instrument genutzt wird ist eine andere Frage. Übrigens: Eine Altersverifikation geht auch komplett ohne eID. Wie bereits erwähnt verlangt Facebook schon heute ein Foto des Personalausweises. Und Video-Ident gibt es auch. Das ist also kein Grund gegen die eID zu sein.
0
12
0
0
Open post
Marvin W @larma@mastodon.social
· 5mo ago
Replying to
@cdonat @Lapizistik @Lilith "staatliches System" bedeutet nicht, dass der Staat beliebige Kontrolle darüber hat. Es könnte zum Beispiel so funktionieren, dass der Personalausweis einen solchen ZKP erstellen kann. Sobald ich einen solchen Ausweis habe, kann er, im Rahmen seiner Gültigkeit, diese ZKP erzeugen und da der Ausweis nicht identifizierbar ist kann er auch nicht blockiert werden. Wir nehmen die Infrastruktur also wortwörtlich selbst in die Hand, der Staat stellt sie nur zur Verfügung.
0
0
0
0
Open post
Marvin W @larma@mastodon.social
· 2mo ago
Replying to
@gnome@felipeborges.eu Well, the legal aspect of it is complicated. Just like with Windows, you do need a valid license. The only way to buy a license is to buy one bundled with an Apple device and their license terms say that this license only applies to Apple devices. However, just like it happened with Windows OEM licenses, that clause is probably invalid in some countries. I mean: Boxes also doesn't bother with the question of one having a valid Windows license, why would it be different for macOS?
0
2
0
0
Open post
Marvin W @larma@mastodon.social
· 5mo ago
Replying to
@blausand @Mer__edith Gerade bei Maps und Push Notifications müsste man den proprietären Code tatsächlich auch nicht benutzen. Für Maps gibt es OpenStreetMap-basierte Alternativen, die auch von vielen kommerziellen Apps genutzt werden, und für Push Notifications gibt es auch offene Implementierungen, um Google's Push Dienst anzusteuern (bzw. am besten direkt den WebPush-Standard nutzen, der sowohl von Google als auch von der freien Alternative @unifiedpush unterstützt wird).
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 22:37:42 UTC