Post #2129777
2026-01-24 14:43 UTC
My threat model includes government agents who sit in the bushes to log traffic.
Do they need people in those bushes that come out and catch you? Or can they have some automated receiving device that simply records some type of id that is put into a big gov database, to be used against people they catch later?
And it is so easy to make mistakes.
E.g., @lew authored the initial toot of this 🧵 in English, but its metadata says "German". Harmless. But goofs could be deadly elsewhere.
@pawka
Replies (1)
-
@lew@freeradical.zone 2026-01-24 15:15
@dj3ei @pawka To protect users in high-risk environments like Iran, a mesh protocol would need ephemeral rotating identities, encrypted announces using pre-shared group secrets instead of plaintext public keys, no persistent on-device storage of communication metadata, and a duress mode that presents a plausible decoy state when unlocked under coercion. It is quite a challenge to implement this in a way that the system stays usable. Especially for nontechnical users.