User avatar
AnarchoNinaWrites @AnarchoNinaWrites@jorts.horse
2y
Me: "You literally cannot trust your cellphone, obviously."

Friend: "That sounds kinda paranoid..."

Me, blinking: "I do not understand how you go through life, day after day, completely unaware of REPORTED reality all around you. It's truly incredible to me."
⭐1
5
1
0
1
User avatar
Océane @oceane@peculiar.florist
2y
@AnarchoNinaWrites I'd rather trust a device running fully free software, like my ThinkPad running GNU Guix, because I'm probably not worth a six-figures zero-day, and there's no proprietary software accessing to my personal data. Everything that runs on my computer is transparent, cannot be easily forged, and can be challenged anyway, by compiling each program and verifying it matches the substitutes' checksums.

I'd trust a phone running on the same principles, but no such thing exists ATM, the Replicant compatibility page is pretty scarce. And I don't even have a working wifi card on my laptop.

1/2
⭐2
3
0
0
2
User avatar
AnarchoNinaWrites @AnarchoNinaWrites@jorts.horse
2y
@oceane I mean I'm not gonna lie, even if such a thing existed, I'd have no idea how to trust it. Google "the Anom sting."

Now keeping in mind, the FBI and its sister organizations were using it to track drug dealers, like big time cartel guys, so I don't REALLY care - but that was the "safest" encrypted phone on the market... until it was revealed the whole thing was an FBI sting.

It's hard to escape a surveillance state; but let's not make it EASY on them by planning resistant on cellphones
1
0
0
0
User avatar
Océane @oceane@peculiar.florist
2y
@AnarchoNinaWrites There's a key difference here, which is that a criminal has developed software for criminals, while GNU Guix is software developed by comrades, for comrades. I'm not asking for that, but they'd still take a bullet for us.

Yes, there are flaws, because any package maintainer's private key could be cracked, and I've literally come to sleep yesterday by devising an hardware security scheme with an airgapped private key hosted on a Raspberry Pi, signing a Yubikey public key used to sign packages.

And then build farms, both ci.guix.gnu.org and where I live, bordeaux.guix.gnu.org, can be compromised, but because every Guix setup can be reproduced byte-perfect from its derivation Git hash, Guix users can challenge the servers' packages they've installed by building each of them, and checking their checksums. It isn't perfect, because a compromised sha256sum package could defeat this, but there are still more serious ways to do this than throwing a mere “guix challenge” and warming your choccy milk on your ThinkPad.

The GNU project is actually pretty serious on software reproducibility and verifiability, there are efforts to fully bootstrap your GNU operating system, so while being imperfect, I do trust my environment enough to keep unencrypted recordings of sociological interviews.
⭐1
0
0
0
1