mutual_ayed

joined 21 hours ago
[–] mutual_ayed@sh.itjust.works 2 points 5 minutes ago

Right?! This is why I love the Fediverse and FOSS.

Have a good night/day

Hope you find new fun ideas as well!

[–] mutual_ayed@sh.itjust.works 1 points 33 minutes ago* (last edited 30 minutes ago) (2 children)

I think that's by design and the nature of the setup. Anyone with the URL can communicate.

If your other comms method is compromised this doesn't have much use. Which is a different problem all together. I think this would work great as something like a deadrop so two completely faceless people can communicate. I like it a lot.

[–] mutual_ayed@sh.itjust.works 1 points 54 minutes ago (4 children)

I don't know yet. It's more a thought experiment than anything else.

https://github.com/muke1908/chat-e2ee

Looks like the URL is part of the seed and salt which is cool.

Proving who you are is done in another stream. Like MFA.

You do a one time pad, generate the URL with that. Communicate what's needed, then the URL dies.

I'm still noodling with it.

[–] mutual_ayed@sh.itjust.works 0 points 1 hour ago

Just because I and my family benefit now, doesn't mean it'll stay that way. Also again, I don't want to support or platform an app that charges others, who are not me, to share their own collection.

If they want to charge for the Plex TV or Plex Movies they host, and leave the app free of cost for a person's own personal collection to be shared. That's fine.

I have no confidence that'll happen though.

[–] mutual_ayed@sh.itjust.works 1 points 2 hours ago* (last edited 2 hours ago) (6 children)

https://medium.com/sessionstack-blog/how-javascript-works-cryptography-how-to-deal-with-man-in-the-middle-mitm-attacks-bf8fc6be546c

I still don't see how

swap to a modified JS that exfiltrates the e2ee key or add additional keys

Wouldn't significantly change the recieved hash and break the stream thus ending comms. Also unless you're hosting and building it yourself you have to trust the recipient and the cloud host.

I agree if an attacker owns the server comms can be compromised. I thought that was the benefit of the ephemeral nature. It's for quick relay of information. Best practices would probably include another cypher within the messages themselves like a one time pad or some such.

https://www.itstactical.com/intellicom/tradecraft/uncrackable-diy-pencil-and-paper-encryption/

https://github.com/muke1908/chat-e2ee

[–] mutual_ayed@sh.itjust.works 15 points 2 hours ago

Cool, now they can correct the "mistake" made regarding Army Maj. Gen. Charles C. Rogers ....

https://www.opb.org/article/2025/03/18/pentagon-website-removes-then-restores-page-honoring-black-medal-of-honor-recipient/

[–] mutual_ayed@sh.itjust.works 0 points 3 hours ago

Yes, that's great for me and mine, but not for others. I don't like to support or platform/promote applications that require a subscription for any access at all.

The problem is Plex aren't Netflix in my usecase. I'm sharing my library with my friends.

Now if they'd like to charge for the content they host. Great more power to 'em, but I feel icky with a payment or subscription model that charges to deliver my collection to my friends and family.

So, like I said. I'll likely start migrating to jellyfin and start the conversation with people in how to get the jellyfin app on whatever device they have.

[–] mutual_ayed@sh.itjust.works 3 points 3 hours ago* (last edited 3 hours ago)

It has. Strangely enough they posted a code of conduct after that feedback and started weilding the ban hammer. However I cannot speak to outside forums like XDA or Reddit or even comms here. I tend to stick to their forums or github

https://discuss.grapheneos.org/t/general

https://github.com/GrapheneOS/os-issue-tracker/issues

[–] mutual_ayed@sh.itjust.works 0 points 3 hours ago (8 children)

Fragility is by design as it's ephemeral comms. Swapping the js decryption doesn't make sense as wouldn't the client just fail or refuse the message stream as the decrypt/encrypt changed? It's an interesting problem. Thanks for giving me something to noodle on.

[–] mutual_ayed@sh.itjust.works 24 points 4 hours ago

Fuck your pipeline

https://www.hcn.org/issues/54-9/indigenous-affairs-social-justice-questions-about-the-landback-movement-answered/

Also. there were demonstrations against DAP in 2008 way before Greenpeace got there.

[–] mutual_ayed@sh.itjust.works 2 points 5 hours ago (10 children)

Can you expand more on the key management? I thought https://chat-e2ee-2.azurewebsites.net/ passes a PSK Through the header and sets that as a cookie in the browser to sign further comms. I could be mistaken of course.

view more: next ›