Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Virebent

@virebent@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

⚡ Comprehensive Privacy-First Internet Services

#OpenSource #DigitalRights #CyberPunk #Anonymity #InfoSec #Tor #Cryptography #NoTracking #DigitalRights

0 Followers
0 Following
3 Posts
Joined May 15, 2026
Virebent:
https://www.virebent.art
Tcpreset Usenet News:
https://news.tcpreset.net
Yamn Mixmaster Anonymous Remailer:
https://yamn.virebent.art
Nonlocality - The Observer Effect:
https://archives.virebent.art
Git Virebent ART:
https://git.virebent.art/explore/repos
Crypto Chat:
https://chat.virebent.art
Open post
Virebent @virebent@infosec.exchange
· 3mo ago

Moved servers, and every Gemini capsule started screaming "untrusted server." Why: my old server (agate) only does self-signed TOFU certs, no CA chain and clients had the old fingerprints pinned, so they rejected the new ones too. Fix: patched gmnisrv to send a full Let's Encrypt chain, forced TLS 1.3, and fixed a crash where a big chain overflowed the handshake buffer (a free DoS on a public port). Renewals auto-reload now.

Patched fork: https://git.virebent.art/virebent/gmnisrv

Live, CA-verified, TLS 1.3:

  • gemini://contact.virebent.art
  • gemini://virebent.art
  • gemini://archives.virebent.art
  • gemini://n5ry24fweklbn562o7fnyefanygtwxlgi7aevn26huuxqlsftxy5ljqd.onion (self-signed —

If your client grumbles once about a changed cert, accept it. That's TOFU.

Best regards and have fun !

git.virebent.art
0
0
0
0
Open post
Virebent @virebent@infosec.exchange
· 3mo ago

A public project should not be credible only because it appears online.

This is why I am using ProofBundle for the projects I publish and discuss publicly, including the ones I present here on LinkedIn.

ProofBundle creates a portable cryptographic proof for a project snapshot.

It takes the files, builds a deterministic SHA-256 manifest, reduces the entries into a Merkle tree, and produces one Merkle root for the whole project state.

Then that root is bound to a signed author/custody claim.

ProofBundle can also use OpenTimestamps: the Merkle root and manifest hash are timestamped and anchored to public blockchains, without uploading the original project and without putting the contents on-chain.

So the proof has three layers:

  • integrity: SHA-256 hashes, manifest, and Merkle root
  • identity/custody: Ed25519 or OpenPGP signature
  • time evidence: OpenTimestamps blockchain anchoring

For signing, ProofBundle supports a default Ed25519 mode: modern, compact, and easy to verify.

It can also use a detached OpenPGP signature, including OpenPGP keys based on Ed25519. And for stronger key custody, OpenPGP signing can optionally be backed by a YubiKey, so the private signing key stays hardware-backed and non-exportable.

This is not copyright registration and it is not a legal shortcut.

It is technical evidence that:

  • this exact project state existed
  • these files matched this manifest
  • this Merkle root represented the snapshot
  • this key signed the claim
  • the timestamp evidence was

anchored through OpenTimestamps

  • the proof can be verified independently

Full technical note: https://www.gabrielesalati.eu/blog/proofbundle-verifiable-project-integrity.html

#ProofBundle #OpenTimestamps #Blockchain #OpenPGP #Ed25519 #MerkleTree #YubiKey #CyberSecurity #SoftwareEngineering #OpenSource

gabrielesalati.eu

ProofBundle: verifiable project integrity — Gabriele Salati

How ProofBundle uses SHA-256 manifests, Merkle roots, Ed25519 signatures, optional OpenPGP, YubiKey-backed signing, and OpenTimestamps blockchain anchoring to create portable project proof.

0
0
0
0
Open post
Virebent @virebent@infosec.exchange
· 2mo ago
I’ve just deployed N2Usenet, a standalone web gateway for posting to Usenet over Nym instead of the older Tor-based posting path. The idea is simple: the site lets you create a persistent pseudonymous identity directly in the browser. It generates an Ed25519 keypair locally, so the secret key never has to leave your device. From that identity, the public key is used together with the chosen username and email to derive a deterministic identicon, which is then embedded in the post through the classic Face: header. The result is a recognizable visual identity for Usenet posts, backed by a real signing key instead of just a display name. Each message is signed in the browser, and the post carries the related identity headers, including the public key, signature, and Face: header. On the transport side, the server relays the submission through Nym to the Mail2News gateway, so this path replaces the old Tor-oriented relay model for this service. It also keeps the usual anti-spam friction with Hashcash, and the current version clears the identity and message input from browser memory after successful delivery. If you want to try it, it’s here: https://n2usenet.virebent.art
n2usenet.virebent.art

N2Usenet Gateway v2.7.7 Nym

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 04:35:20 UTC