Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Bruce Walzer 🇨🇦

@upofadown@mstdn.ca
mastodon 4.8.0-alpha.3+glitch
  • Open on mstdn.ca

Creator of articles about ridiculously obscure topics. Interested in the usability of end to end encrypted messaging systems. Glider pilot.

29 Followers
58 Following
15 Posts
Joined February 02, 2025
Articles:
https://articles.59.ca/
Open post
Bruce Walzer 🇨🇦 @upofadown@mstdn.ca
· 3mo ago
Replying to
@michaelharley@infosec.exchange XMPP? I acknowledge it is boring, but sometimes you want something that just works.
7
0
3
0
Open post
Bruce Walzer 🇨🇦 @upofadown@mstdn.ca
· 1mo ago

@debacle@framapiaf.org @marsik@witter.cz @Goffi@mastodon.social @nigel@unsociable.lowkey.party @andros@activity.andros.dev

I have, and am still in one case using PGP over XMPP. The nice thing is the single identity that can be transferred to all the devices. You only have to verify a particular identity once and it doesn't matter if they change devices or get another device like with other schemes.

I am not really worried that a server operator is making a long term archive of my messages in a way that forward secrecy might help at some point in the future. Attackers on the network don't have access to my messages on the network due to the regular use of TLS on XMPP these days. There is no technical reason that you couldn't switch out encryption keys on PGP over XMPP for forward secrecy, since the public keys are always available on the server and can be refreshed at any time.

One subtlety that did not immediately occur to me involves the difference between instant messaging and email. You might not want to risk your email keys on something that exposes them all the time...

1
2
0
0
Open post
Bruce Walzer 🇨🇦 @upofadown@mstdn.ca
· 2mo ago
Replying to
@mxchara@seattle.pink Spectrwm. Switched just recently. A tiling window manager with all my favourite tweaks in a 15 line config file. Where has this thing been all my life?
1
1
1
0
Open post
Bruce Walzer 🇨🇦 @upofadown@mstdn.ca
· 2mo ago
Replying to
@Quantensalat@scicomm.xyz When the transistor is on, then the current through the inductance will ramp up. When the transistor turns off, the current will continue. That might mean that the voltage across the inductor will greatly increase (inductive spike) enough to cause some component to conduct in an abnormal way. Perhaps that is what is happening here? It might be interesting to look at the voltage across the source and drain of the transistor.
1
1
0
0
Open post
Bruce Walzer 🇨🇦 @upofadown@mstdn.ca
· 2mo ago
Replying to
@Quantensalat@scicomm.xyz Would this fall under generic transformer magic? A transformer driven on the primary without a load on the secondary is just an inductor. That inductance keeps the transformer from taking power from the source. Adding a load to the secondary cause the changing magnetic flux in the coil to induce current in the secondary. That makes the primary no longer look like a pure inductance. It now looks somewhat resistive. So is the answer: because of the load?
1
5
0
0
Open post
Bruce Walzer 🇨🇦 @upofadown@mstdn.ca
· 3mo ago
Replying to
@adulau@infosec.exchange Just to save others the bother, I get 145 years total to completely search the keyspace based on progress to date.
1
0
1
0
Open post
Bruce Walzer 🇨🇦 @upofadown@mstdn.ca
· 6mo ago
Replying to
@announcements Fairly off topic, but I recently wrote an article about the GDPR thing that might be of interest: https://articles.59.ca/doku.php?id=pgpfan:gdpr
articles.59.ca

When the GDPR Seems to Prevent an Entire Technology [The Call of the Open Sidewalk]

1
0
0
0
Open post
Bruce Walzer 🇨🇦 @upofadown@mstdn.ca
· 6mo ago
Replying to
@HasSignalBeenHacked Putting on my user hat... "OK. Signal has forward secrecy. So messages are gone after I receive them. Great!" Oh, you didn't turn on disappearing messages? Oh, right, then forensic tools like Cellebrite can get them. You have to turn on disappearing messages. The default is off. Oh, you did turn on disappearing messages? We send the messages in notifications. So the OS can keep them. Turns out Apple was doing that. There is an option you can turn on to prevent that. It is off by default. "I'll just delete the entire app!" No, sorry, the OS still has your messages... At what point does the usability get so bad that we can blame the messaging system? This same app had a usability issue that turned into a security issue just last year: End to End Encrypted Messaging in the News: An Editorial Usability Case Study (my article) https://articles.59.ca/doku.php?id=em:sg
articles.59.ca

End to End Encrypted Messaging in the News: An Editorial Usability Case Study [The Call of the Open Sidewalk]

0
0
0
0
Open post
Bruce Walzer 🇨🇦 @upofadown@mstdn.ca
· 8mo ago
Replying to
@dima GPG has a high performance symmetrical encryption mode now (OCB). If you make a new key it will put that mode in the preferences so it will get requested. So the performance thing might not have anything to do with RSA2048 vs Curve25519. It might just be that you made a new key. Otherwise I would not expect a performance difference significant enough to notice.
0
0
0
0
Open post
Bruce Walzer 🇨🇦 @upofadown@mstdn.ca
· 7mo ago
Replying to

@june This makes me wonder if this sort of bad behaviour is covered by an author's moral rights:

  • https://en.wikipedia.org/wiki/Moral_rights
en.wikipedia.org
0
0
0
0
Open post
Bruce Walzer 🇨🇦 @upofadown@mstdn.ca
· 5mo ago
Replying to
@delta @Yuvalne @rpgp @protonprivacy @Tutanota This is ultimately based on a new Autocrypt standard which is based on RFC-9580? That doesn't sound very interoperable to me. So a recipient would have to support Autocrypt2 and RFC-9580 (as opposed to LibrePGP). How likely is it that anything else will support that particular combination of standards?
0
2
0
0
Open post
Bruce Walzer 🇨🇦 @upofadown@mstdn.ca
· 12mo ago
Replying to
@hpk@chaos.social @rpgp@mastodon.social Specifically, GnuPG is not following the other proposal for a new standard (RFC9580). That hardly makes it proprietary. The danger represented by the current standards schism will only be increased if we use misleading language.
0
4
0
0
Open post
Bruce Walzer 🇨🇦 @upofadown@mstdn.ca
· 12mo ago
Replying to
@hko@floss.social RNP (Thunderbird) is also explicitly supporting LibrePGP. So the two most deployed and used OpenPGP implementations support it. So we can't just ignore it, there is a definite problem here that we have to address. PGP has always had a severely minimalist culture due to the medium. You introduce new incompatible methods only with great care if you want to preserve interoperability. So strong moderation of new ideas is required as well as traditional. The RFC9580 proposal basically just threw this all out and accepted submissions with no real pushback. Fortunately the insecurity of RFC4880 was greatly exaggerated. So us users have the very reasonable option of just ignoring both proposals, just as long as we are allowed to.
0
2
0
0
Open post
Bruce Walzer 🇨🇦 @upofadown@mstdn.ca
· 1mo ago
Replying to
@hko@floss.social @jas@fosstodon.org Implementing "type 20" might help interoperability in a particular case, but it might make things worse if it causes a widening of the schism. The worst case would be a situation where it is impossible to know what format should emit; where you have a 50-50 chance of getting it right. This is a political problem. It can't be fixed with unilateral action. This suggests a potential solution that would fix most of this. The LibrePGP faction could agree to officially require ver 6 keys in their proposal in return for the 9580 faction requiring support in their proposal for the LibrePGP "type 20" OCB block cipher mode.
0
1
0
0
Open post
Bruce Walzer 🇨🇦 @upofadown@mstdn.ca
· 12mo ago
Replying to
@rpgp@mastodon.social GnuPG has proprietary features now? How much does this feature cost? Pretty sure that format is documented in the LibrePGP standard proposal.
0
6
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 23:47:13 UTC