• 0 Posts
  • 15 Comments
Joined 3 years ago
cake
Cake day: December 16th, 2021

help-circle





  • Possibly the source of any confusion here is when the encryption and when the compression takes place? Maybe some more details about how you are using xz and encryption would help.

    As far as I can tell, xz doesn’t do anything with signatures or encryption, but it does perform checksums like you stated, which is very cool and I’m glad you shared this.

    Edit: I am re-reading your post above. You are compressing with xz, then encrypting, got it. So yes, if any part of the payload is tampered with, then it would be detected by the decryption, depending on the algorithm, or by the decompression because of the checksums like you said. Sorry for the confusion! You’ve got it all straight lol.




  • Oh sure, I just didn’t want to reference every miracast project, I suppose it is worth throwing a link for miraclecast out there though, since that seems like one of the most popular. I believe the GNOME desktop environment also had an effort to support miracast standard.

    https://github.com/albfan/miraclecast

    I just wanted to point out that fcast seems to have done their own thing when there were some efforts already in play, which is totally fine. I was just surprised I didn’t see an entry in their FAQ like “How is fcast different from X?”.





  • The point is that the community asked multiple times and they only started allowing apk downloads so people would stop asking. The signal project is open source for auditing purposes only, they have voiced their lament of forks and threatened to ban/block anyone not using an official client and refuse to make it easy to install through a package manager of the user’s choosing. The version without Google cloud messaging has unreliable message delivery, even though there is unifiedpush as a standard that would allow people to register with any push notification service.


  • Beeper provides a free service to bridge all your chats into the same place, including traditionally secure applications like signal with end to end encryption. By using beeper, you are letting them decrypt all your signal chats and re-encrypt them on their servers. I wouldn’t trust a paid service with my privacy on this level, much less a free one. An alternative model could have installed the bridging and stuff directly on your device in the app, but from a usability standpoint that becomes less convenient especially when trying to port all the chat applications to all the platforms. They are just a hosting service for open source bridges with a nice closed source client.


  • Wow, this is really cool. Literarily just debt cards without the cards, or Apple/Google pay without the proprietary software. Also the option to pay friends like venmo. Open standard, open software and no reason other than capitalism to not use it.

    I wonder if Taler could follow an implementation path like Apple/Google pay, I’m not sure how those services even work (is Apple/Google considered a bank? A payment processor?), yet they have point of sale integration which everyone everywhere had to pay to upgrade their systems to support.