Avatar

Nia

read_deleuze@lemmy.ml
Joined
0 posts • 17 comments

queer, xenofeminist, anarchist rustacean. any pronouns

Direct message

Yes; Organisation du traité de l’Atlantique nord

permalink
report
parent
reply

Just because everything checks out in principle doesn’t mean it’s actually secure. First off, we have no certainty of the client code running; it’s open source, sure, but unless they ensure reproducible builds - which, given it’s on the Play store (and I assume Apple app store), they can’t be, since the binaries must be signed - we have no way of knowing whether the code actually being downloaded and run is actually the same as the FOSS version. Further, even if it is, it may have intentional subtle vulnerabilities meant to be used by the French govt (so would easily pass certification by having the ANSSI be instructed top-down to overlook certain things), or it may be that the server can trigger a known bug resulting in leakage of data. At an even more paranoid level, it’s possible that the encryption itself is faulty; the specification says it uses aes256 and ed25519 which is about as battle-tested as it gets, but the PRNG seems to be mostly their own innovation. It specifies a minimum of 32 bytes of entropy, which (though cryptography is not my expertise, so at this point I’m wildly speculating) is probably trivial to send or embed in some other communication with the server e.g. by ensuring the PRNG is deterministic after the first keygen and faulty in some known way and sending over a future result.

I wouldn’t trust the French government.

permalink
report
parent
reply

To be fair, nix would probably be a lot more intuitive if commands were in black speech instead

permalink
report
reply
10 points

cope and seethe, transphobe

permalink
report
reply

The IP seems to be in Norway, vaguely around Oslo, and owned by TerraHost. IANAL but I assume this means Lemmygrad could be taken down by either the hosting provider or Norwegian/EEA law. Someone more knowledgeable can probably answer how likely this is, but my guess is “not very”.

As for your other question, no matter where this was hosted, the government of said country could probably take it down if it so wanted. All clearnet domains are under jurisdiction of either a national government (for .ml, this would be Mali) or ICANN, and physical servers obviously can be raided.

I do, however, doubt the Norwegian government cares enough about some marxists on the internet to go through the process of judicial approval for seizure of the servers, and the folks in Mali definitely have more pressing matters right now.

permalink
report
reply
39 points

Nieuw-Amsterdam komt terug, het is slechts een kwestie van tijd

permalink
report
reply

Love how you just assume I’m from the west. I’m eastern european, my family is also, and we lived through everything - and I’ve yet to meet someone other than western investors and young kids who thinks things are good/better now

permalink
report
parent
reply

I’m deeply sorry that we don’t like supporting the oppression of marginalized groups here

permalink
report
parent
reply

Glad to have been informative :D and good luck on your laptop hunt

permalink
report
parent
reply

That’s correct, mea culpa; I’ve only seriously worked with qcom so entirely forgot that’s a thing. I’ll update my comment, thanks!

permalink
report
parent
reply