this post was submitted on 28 Nov 2023
762 points (100.0% liked)

196

17027 readers
720 users here now

Be sure to follow the rule before you head out.

Rule: You must post before you leave.

^other^ ^rules^

If you have any questions, feel free to contact us on our matrix channel.

founded 2 years ago
MODERATORS
762
encrulepted (retr0.id)
submitted 1 year ago* (last edited 1 year ago) by masimatutu@nerdica.net to c/196@lemmy.blahaj.zone
 

retr0.id/media/bd23a2fb-c7a6-4…

alt text:

Goose chase meme. In the first frame, the goose asks "all the data is encrypted?" In the second, the goose chases a person, asking "encrypted how and with whose keys, motherfucker?"

@196

you are viewing a single comment's thread
view the rest of the comments
[–] joyjoy@lemm.ee 69 points 1 year ago (3 children)
[–] verdare@beehaw.org 30 points 1 year ago (1 children)

The fact that you have to enter your iCloud credentials directly into the app was a red flag.

Security PSA: Don’t enter passwords or other secrets for important accounts directly into a third party UI. This is why we have tokens and federated login. Third parties should never see your Google/Apple/whatever credentials.

[–] ALostInquirer@lemm.ee 6 points 1 year ago (1 children)

Security PSA: Don’t enter passwords or other secrets for important accounts directly into a third party UI.

By chance, would you (or some other passerby) happen to know how this is handled with the Lemmy apps/interfaces? I've been mixed on using them since I'm unclear how they're handling this info.

[–] verdare@beehaw.org 8 points 1 year ago* (last edited 1 year ago)

Hmmm, that’s a good point. I did type my Lemmy credentials directly into at least two different apps. I guess it would be better if it redirected to a login page provided by my instance (Beehaw). But I also don’t consider my Lemmy account to be very critical. It’s not a huge deal if it gets compromised, as long as it’s not associated with my real identity.

EDIT: Also, I use a password manager, so a leak of my randomly generated Lemmy password shouldn’t affect anything else.

[–] pineapplelover@lemm.ee 19 points 1 year ago (1 children)

Probably also whatsapp chat, imessage, and other proprietary encrypted messaging apps out there.

[–] joyjoy@lemm.ee 22 points 1 year ago (2 children)

Many chat apps actually use the Signal protocol for end to end encryption. This includes WhatsApp, Google Messages (RCS), Facebook Messenger, and Skype. iMessage doesn't seem to use it.

[–] LWD@lemm.ee 16 points 1 year ago* (last edited 1 year ago) (1 children)
[–] AVincentInSpace@pawb.social 3 points 1 year ago (1 children)

Why is end to end encryption a red flag???

[–] LWD@lemm.ee 15 points 1 year ago* (last edited 1 year ago) (1 children)
[–] AVincentInSpace@pawb.social 7 points 1 year ago (1 children)

oh, red flag for facebook, that makes sense.

but then if you care about privacy why touch anything Facebook has made at all?

[–] LWD@lemm.ee 6 points 1 year ago* (last edited 1 year ago)
[–] Lemongrab@lemmy.one 9 points 1 year ago

But we also can't check their process since they are closed source. Also, if they can decrypt in the browser or proprietary app, then they can still read your messages. Browser is vulnerable to other attacks.

[–] isVeryLoud@lemmy.ca 16 points 1 year ago

That's not even Nothing Chats' biggest problem: it's that it gets completely MITM'd by going onto some mac mini in some server farm somewhere.