• Melody Fwygon@lemmy.one
    link
    fedilink
    arrow-up
    6
    ·
    4 months ago

    Wow.

    Even more shocking was the absolutely toxic reaction you got from sycophants.

    I love seeing your blogposts about cybersecurity; and I absolutely do appreciate that your blog isn’t just about cybersecurity.

  • SavvyWolf@pawb.social
    link
    fedilink
    arrow-up
    3
    ·
    4 months ago

    meanwhile, it is very unclear that any sidechannel attack on a libolm based client is practical over the network (which is why we didn’t fix this years ago).

    Wow… Uh, that’s certainly a thing for a developer to let slip out, huh?

    One thing I don’t get about Signal/Telegram/etc is that they claim to be secure and private… Yet also require you to prove your identity via a phone number? I don’t really get it.

    That would be a massive deal breaker to some people I want to push off Discord and is one of the reasons I haven’t tried Signal yet, but have tried Matrix.

  • AnanaceA
    link
    fedilink
    arrow-up
    1
    ·
    4 months ago

    Well, this has certainly caused quite a bit of drama from all sides.

    I’m curious about the earlier audit of libolm which happened many years back (and by a reputable company), it feels like it should’ve found any potentially exploitable issues after all - including timing attacks.