Elektrine
EN
Log in Register
Paige Chat Timeline Gallery Friends Lists Email Drive DNS Resolver Domains VPN Kairo Nerve
Remote

S1m

@S1m@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

FR/EN

Account dedicated to #Offsec/#Infosec/digital stuff

Involved in
#UnifiedPush #MollyIm

306 Followers
152 Following
24 Posts
Joined October 19, 2023
Github:
https://github.com/p1gp1g
Codeberg:
https://codeberg.org/s1m/
Liberapay:
https://liberapay.com/S1m/
Blog:
https://s1m.fr
Open post
S1m @S1m@infosec.exchange
· 2mo ago
I've published a temporary fork of Delta Chat for Android with UnifiedPush support: https://codeberg.org/s1m/delta-chaton It will be automatically updated, as there should not be much conflicts between releases. I expect to discontinue this fork once (if) the support is merged #DeltaChat #UnifiedPush #Android
36
0
17
0
Open post
S1m @S1m@infosec.exchange
· 4mo ago

Good to see a POC that shows how useless security-wise is the Play Integrity:

Android LPE using DRAM bitflip => https://bsky.app/profile/retr0.id/post/3mljtyauw322d

A requirement to get any security protection with the Play Integrity is that attackers can't bypass it on any device.

As soon as an attacker can bypass it, it is possible to distribute app clones (fake banking app) that proxy-pass the Integrity requests to a controlled device, defeating the Play Integrity.

On the other side, how many users are locked-out of critical services because of the Play Integrity? For legit users, any non-trivial workaround is a blocker.

Play Integrity is not about security, but about coercition, Google's tool to impose their conditions: eg. forcing OEM to preinstall their apps, some with privileges (Chrome, Youtube, Play Services, etc)

#Google #PlayIntegrity #Android #LPE

16
0
15
0
Open post
S1m @S1m@infosec.exchange
· 4mo ago

Nextcloud talk just merged UnifiedPush support! It will be available with Nextcloud 34

#Nextcloud #UnifiedPush

10
0
3
0
Open post
S1m @S1m@infosec.exchange
· 6mo ago

Start Alliances, Not Wars

> For our community to thrive and slowly build a movement, we need more alliances, not wars.

Really good article from @Em0nM4stodon@infosec.exchange, thanks !

https://www.privacyguides.org/en/activism/toolbox/tip-start-alliances-not-wars/

Em :official_verified: (@Em0nM4stodon@infosec.exchange) - Infosec Exchange

16
0
15
0
Open post
S1m @S1m@infosec.exchange
· 5mo ago
Replying to @Gaulix@mastodon.social
@Gaulix@mastodon.social @bfluzin@tldr.nettime.org @skynebula@mastodon.social @nastasiahadjadji@mastodon.social Si ça vous intéresse, c'est l'histoire de quelques minutes pour faire un pont matrix <-> discord. Ce pont est plutôt bien fait https://t2bot.io/discord/
1
0
0
0
Open post
S1m @S1m@infosec.exchange
· 6mo ago
Replying to @S1m@infosec.exchange
@epicenter_works@chaos.social And, the draft implementation of this wallet requires passing Play Integrity checks. The Play Integrity is one of the main anti-competitive tools developed by Google. The Play Integrity does mainly ONE thing: check if the OS is certified by Google. And one thing it doesn't do: preventing execution with a corrupted device. If all our critical services require a Google-certified system, the certification becomes a coercion mean: OEM must agree to all Google demands (like pre-installing Youtube, Google, Chrome etc.) if they want to have that certification It also prevents users to use alternative OS based on Android (/e/OS, GrapheneOS, Android emulator for Linux phones, like Jolla, etc), many of them being EU solutions
1
0
1
0
Open post
S1m @S1m@infosec.exchange
· 7mo ago
Replying to @S1m@infosec.exchange
The dev team seems very enthusiastic about this feature, which is really nice 👍
1
0
0
0
Open post
S1m @S1m@infosec.exchange
· 14mo ago
Replying to @privacyguides@mastodon.neat.computer
@privacyguides@mastodon.neat.computer Thank you, very good post 👏
1
0
0
0
Open post
S1m @S1m@infosec.exchange
· 5mo ago
Replying to @S1m@infosec.exchange
@filippo I need to figure out how to use a yubikey and a PQ key (in a file) for age/passage now :)
0
1
0
0
Open post
S1m @S1m@infosec.exchange
· 6mo ago
Replying to @S1m@infosec.exchange
@ludman1 @daniel @mactunag @j_r @joinjabber It won't be necessary anymore once this MSC is supported: https://github.com/matrix-org/matrix-spec-proposals/pull/4174
0
0
0
0
Open post
S1m @S1m@infosec.exchange
· 7mo ago
Replying to @ybon@amicale.net
@ybon @postmarketOS I just bought a bananaphone to play with it, I'll possibly contribute soon
0
1
0
0
Open post
S1m @S1m@infosec.exchange
· 7mo ago
Replying to @ybon@amicale.net
@ybon @postmarketOS Thanks ! Audio may be useful to get phone calls 😅
0
0
0
0
Open post
S1m @S1m@infosec.exchange
· 7mo ago
Replying to @pid_eins@mastodon.social
@pid_eins Problems with D-Bus 3.5: Polkit is only for privileged services => trying to sandbox a user service (e.g. ProtectSystem=strict, ProtectHome=read-only) is often useless This is why flatpak has to use the dbus-proxy. Proxy that can be avoided using cgroup extended attributes
0
0
0
0
Open post
S1m @S1m@infosec.exchange
· 4mo ago

Has #docker changed their pull limit? I don't see how I could reach the 100/6h so rapidly 🤔

0
3
0
0
Open post
S1m @S1m@infosec.exchange
· 2mo ago
I've finally finished my guide to using Yubikeys. If I had to set up my keys today, this is what I would do. If you're curious, here it is: https://s1m.fr/guide-yubikeys/ #Yubikey #Passkey
0
0
0
0
Open post
S1m @S1m@infosec.exchange
· 4mo ago
Replying to @GossiTheDog@cyberplace.social
@GossiTheDog@cyberplace.social @drm@mastodon.social Plus besoin de s'embêter à faire du TPM sniffing
0
1
0
0
Open post
S1m @S1m@infosec.exchange
· 4mo ago
Replying to @drm@mastodon.social
@drm@mastodon.social @GossiTheDog@cyberplace.social Toujours à la pointe les collègues. C'est pas un patch qui nécessite une mise à jour des certifs secureboot ça ? Le genre de mise à jour qui est toujours retardée
0
1
0
0
Open post
S1m @S1m@infosec.exchange
· 4mo ago
Replying to @nightdice@unfug.social
@nightdice@unfug.social Hey! Do you think you can send the logs on codeberg?
0
1
0
0
Open post
S1m @S1m@infosec.exchange
· 4mo ago
Replying to @nightdice@unfug.social
@nightdice@unfug.social You need to get it with ADB on a computer, that's not the most user friendly thing unfortunately Do you run Linux, MacOS or Windows ?
0
1
0
0
Open post
S1m @S1m@infosec.exchange
· 4mo ago
Replying to @nightdice@unfug.social

@nightdice@unfug.social Yes definitely available on non-rooted devices: you need to enable developers settings (that you'll be able to disable later).

ADB is usually available on most distrib with android-tools package. Then you need to run adb logcat --pid $(adb shell pidof org.unifiedpush.distributor.sunup)

If you struggle getting these logs, let me know. It it helps there is a matrix room for UnifiedPush

0
2
0
0
Open post
S1m @S1m@infosec.exchange
· 4mo ago
Replying to @nightdice@unfug.social
@nightdice@unfug.social Good to know you fixed it 👍
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)
  • Source code

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 17:06:44 UTC