ioc.exchange is one of the many independent Mastodon servers you can use to participate in the fediverse.
INDICATORS OF COMPROMISE (IOC) InfoSec Community within the Fediverse. Newbies, experts, gurus - Everyone is Welcome! Instance is supposed to be fast and secure.

Administered by:

Server stats:

1.6K
active users

After the article from The Atlantic, I've seen a lot of misinformation circulating among journalists. I'm not getting into the political side of things, but many are focusing on the fact that Signal was used, claiming it's "not encrypted" or "not secure." This really saddens me because it spreads the wrong message.

👊🇺🇸🔥

@stefano People just don't understand what Signal is designed to protect, and it's not yourself from your own incompetence.

@Avitus Exactly. I think I saw someone years ago phrasing it as "you might be having a secure conversation with the devil". An apt analogy.

End to end encryption is great, but you also need to have *some* idea of what the ends are, and what they can and should be trusted with.

@stefano

@mkj @Avitus @stefano I’m sure there are other variations, but this is the one from Scott Hanselman (Microsoft); applies just as well to Signal and E2EE, and whether one of your endpoints is who you think it is, or compromised.

@matt_garber That might very well be the one I had in mind earlier.

@Avitus @stefano

@peribotsarah Except it does mean "this is private", *for some values of private*.

To meaningfully discuss privacy, it's again important to start out by having an answer to: privacy from whom, and for what?

@matt_garber @Avitus @stefano