

I’ve been boycotting Nvidia for years, because their drivers suck, now I can add this and their insane prices to the list of reasons why.


I’ve been boycotting Nvidia for years, because their drivers suck, now I can add this and their insane prices to the list of reasons why.


US Sphere of influence includes Israel, not exactly great TBH.


It’s fine when I do it, but introducing this as default in Spotify will reduce the value of ad-reads, and I’m guessing Spotify won’t make up the difference to producers.
Kocialism is when you get your friend to install KDE
And when enough of your friends install KDE THATS Kommunism
~DicK Wolff


creating a backdoor to access plaintext messages is still very difficult if the app is well audited
Well audited is key, this attack likely works by doing something like adding Meta to the list of trusted devices, then hiding itself from the list (either because of code in the client or because it the meta device is only added for a moment), so the backdoor wouldn’t be send_all_messages_to_hq(), it would be in the code to list trusted devices, either explicitly hiding some devices or some sort of refresh timer that’s known so you can avoid being there when the UI is updated).
Or it works through the some other mechanism that still preserves E2E encryption.


People not understanding how security threats actually work is why everything is so broken these days.
If I encrypt a message with public key material for which the only private key material that can decrypt the message is in only my possession,
If you do it by hand sure.
If you put the message into an app then the app is trusted to not leak the message. What is described in the article is that Whatsapp can instruct clients to send a copies of the message from the app to their server.
There is nothing stopping any messaging app doing this, having decentralized servers and 3rd party clients wouldn’t stop this but it would make it much easier to protect yourself from the attack.


This shows you don’t understand the exploit being used.
Go hang out with Alice & Bob all you want, they aren’t breaking encryption.
I guess c/technology is the same as r/technology, full Smug fools that don’t read articles or understand real world security, but think they are 1337 hax0rm3n


Is the same not true of any app depending on centralized servers, e.g including signal?
And also Google & Apple can backdoor any app on any mobile device.
Oh well guess I’ll continue using streamio until I can be bothered to set up my jellyfin & friends