mstdn.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A general-purpose Mastodon server with a 500 character limit. All languages are welcome.

Administered by:

Server stats:

14K
active users

#airgapped

0 posts0 participants0 posts today

#GitOpsPlayground (GOP) version 0.11.0 finally facilitates running in air-gapped environments:

It can provide standardized #IDP​s,
even when are they are #airgapped,
even when they run on #OpenShift.
🥳

github.com/cloudogu/gitops-pla

The next big thing we are working on is the option to role out dedicated instances per tenant, that are managed centrally.

Kind of like an IDP as a Service (Is #IDPaaS a thing? 😅)

1/2

#servicetoot Am 31. März ist #worldbackupday #world #backup #day #weltdatensicherungstag
Und läuft deutlich entspannter wenn man bereits jetzt mit den Vorbereitungen beginnt 😉
Meine Checkliste muss ich dringend erweitern.
Das Wichtigste.
#1
#homeassistant Image in den #cloudspeicher
#2
#cloudspeicher #pcloud auf lokale #ssd für den #schrank #offline #airgapped
#3
#Smartphone meiner Mutter von #iCloud auf #pcloud umstellen. Kontingent 100GB 9,99€ für mich. #spass
Ich hoffe die Erinnerung hilft euch.

This is what innovation can do!

#AirGapped #Offline #PKI #PrivateKeys #TwoFactor- #2FA #Yubico #Yubikey

======

Vincent Bernat Turns Three YubiKeys and a Cheap Single-Board Computer Into a Secure Offline PKI
hackster.io/news/vincent-berna

---
Developer Vincent Bernat demonstrates how to turn three Yubico YubiKey USB two-factor authentication dongles into an offline public key infrastructure (PKI) using a low-cost single-board computer as an air-gapped host.

Replied in thread

@hisold OFC #Cheats are a way to learn how to "#hack" as in "What if I change the value at this address?"

And I still do recommend anyone interested in #IT and espechally #ITsec to build themselves their own #airgapped #HomeLab to "#FuckAroundAndFindOut!" safely within.

  • Kinda like a "Dojo" (something that costs $$ per hour in terms of a "remote lab" to even be given access in)...

And with #AntiP2W becoming mainstream as well as Players despising #P2W / #PayToWin / #Pay2Win (aka. #P2L / #PayToLoose / #Pay2Loose) as well as literal #gambling on some #Minecraft servers, I don't blame Kids that feel shafted (harder than #Millenials like myself back in the days of #HabboHotel) if they decide to fuck with servers rather than scamming other players

www.youtube.com- YouTubeEnjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.
Replied in thread

@dalias @lauren
@pixelschubsi

Also the blatant dismissal of absolitely basic #OpSec & #ComSec is just flabberghasting.

Only #decentralized, #OpenSource & #OpenStandards can actuall survive long-term and remain #secure.

It's the same reasons we use #PGPG/MIME & #SSH and not #X400 & #X25!

IOW: Think "How can you weaponize Signal?" and see what you csn do just holding key people in contempt...

The less #info a provider has, the less they can be forced to snitch upon customers.

"#JustUseSgnal!" is a form of dangerous "#TechPopulism" aimed at bamboozling #TechIlliterates who don't know better, abusing information asymetry to pull rank instead of investing the time and effort to *explain "how" and "why" this is indeed a good or bad idea.

The only ones that have a chance to beat that are @delta / #deltaChat but that's just #PGP/MIME #eMail in a nice UI...

  • You may now laugh at me and think my "#TinfoilHat sits too tight" but I'm shure sooner or later I'll be evidenced as correct...
Hachyderm.ioCassandrich (@dalias@hachyderm.io)@kkarhan@infosec.space @signalapp@mastodon.world @monocles@monocles.social @lauren@mastodon.laurenweinstein.org Very few systems promoted as Signal alternatives match the cryptographic privacy properties (see: ratcheting, etc.) of Signal. The claims about "located in the USA" and "Cloud Act" are all nonsense because the only threat to Signal users from this is availability (seizure and shutdown of the server infrastructure), not undetected breakage of privacy properties. There are presently no systems with superior privacy properties to Signal *and* level of functionality on par with what general public expects. There are a lot (like the XMPP stuff, *sigh*, and Matrix) that are worse in both regards. If you're happy with reduced functionality, Cwtch (and possibly some other similar Tor-based systems) or VeilidChat are stronger, but it's gonna be a while before you convince normies to use them, and in the mean time they're still going to be on insecure shit like WhatsApp, FB Messenger, Telegram, etc...
Replied in thread

@0xF21D OFC it's way worse as #NorthKorea is basically #airgapped and the average person there most likely doesn't even know what the Internet is.

  • And the few people who dare to speak in prearranged settings will say that they'd love to visit the CSR or GDR cuz they had worked with folks from there half a century ago...

Still, #Iran is well known for doing #HostageDiplomacy so having someone with a #US #passport do #journalism in #Tehran is kinda asking for trouble...

  • I guess they only got booted out because legally they had #journalist #visa but still, I don't see much gained from the trip and IDK any good ways to have extracted more that wouldn't have raised so many eyebrows that they would've likely been charged with "#espionage" and held in reserve for a swap...
Replied in thread

@gborn @MichaelD @Bundesligatrainer @Ihazchaos nein, eben nicht.

Dass #Windows10 [und besonders #Windows11] nicht #DSGVO- & #BDSG-konform sein können ist evidenzierte Tatsache und ich habe noch keine*n Anwält*in gesehen die etwas anderes behaupten und dafür im Zweifelsfalle auch die #Haftung übernehmen würden.

  • Wohingegen ich mir sicher bin dass @SUSE & @ubuntu mir im Zweifelsfalle sogar ne #Versicherung der #Compliance ab Werk anbieten würden, was #Microsoft aufgrund von #CloudAct inhärent nicht kann!

  • Außerdem verbietet sich das Procurement von Anbietern die in "illegaler Agententätigkeit" [u.a. #PRISM] involviert sind (!!!) schon aus oberflächlicher due diligence...

Von einfach ausnutzbaren #Govware - #Backdoors in der #CryptoAPI unter #Windows hab ich noch garnicht angefangen!

Replied in thread

@teajaygrey @halva @lynn @signalapp @deilann @monocles @Mer__edith @torproject

I remember #SLIC but sadly it never got traction.

  • Needless to say #XMPP with #OMEMO & #PGP/MIME nowadays has excellent support by clients for every relevant platform and there are various other options depending on the use case, threat model and scenario.

I do gladly advice clients/employers directly...

  • So far only #Tor and #Monero have reached a level of #decentralization that makes it basically impossible to shut them down even if (key) people working on it were to be arrested/forcibly disappeared/murdered (as had been the case!), with #SelfHosting-capable projects being close behind.

For example, #Briar as a "#airgapped" (or rather '#offline-capable') messenger may be the hottest thing if one needs to #chat with someone stuck exactly in the middle of North Korea and out of reach for Chinese, Russian or South Korean phone networks, tho that still relies on the local #SneakerNet (or rather #TrampingNet) to facilitate the transfer, which is rather common given the fact that #USB #flashdrives and #microSD cards are smuggled there en masse...

Version 0.8.0 of #GitOps playground #GOP is here:
github.com/cloudogu/gitops-pla

It brings us closer to fully support #airgapped, least privileged and namespace-isolated environments:

You can now enable image pull secrets for all tools, and our example pipelines can now be configured to run in airgapped envs.

We also started work on enabling network policies, that make GOP run on #OpenShift. We're working on extending #netpols support to complete namespace-isolation on all #k8s clusters.

1/2