Oddbean new post about | logout

Notes by SimplifiedPrivacy.com Podcast | export

 Leaked: Google Pixel 9 info

It's unclear if this is a real leak, or Google purposefully marketing their stuff (likely the 2nd).  From the leak, a random Russian websites got images and dimensions: [1]
Pixel 9: 6.24"
Pixel 9 Pro: 6.34"
Pixel 9 XL: 6.73"

The Verge is reporting the Pixel 9 will have AI scan screenshots similar to Microsoft's Recall.  Wiping this with a custom ROM may end this OS-level feature, although it's unclear yet if it will be integrated with the hardware. [2]  As a reminder, Google's newer models (8+) already include the "Find My Device".  This and price are why I recommend the 6a.

AndroidAuthority is reporting on the leak as well, saying there will be a price increase.  Vanilla models going up 100 euros in France. [3]

Sources:
[1] https://rozetked.me/news/33304-eksklyuziv-fotografii-vseh-modeley-google-pixel-9-ot-rozetked
[2] https://www.theverge.com/24196571/google-pixel-9-pro-xl-9a-fold-rumors-leaks-camera
[3] https://www.androidauthority.com/pixel-9-series-france-prices-3459857/
 
 BraveNewPipe just pushed an update!

I tested it and it works.  You can get it right now via Obtainium!

Beginner Q&A:
Q: What are you talking about?
A:  Youtube broke a lot of privacy frontend apps with an update.  This is the fix

Q: What is Obtainium?
A: An android app you can get via F-Droid that lets you install any other app via the developer’s Github, so you avoid having to wait for slow groups like F-Droid

Q: How do I do it?
A: First get Obtainium via F-Droid, then copy-paste the Github link:
https://github.com/bravenewpipe/NewPipe 
 not sure sorry 
 yeah they said on github today the fix is in the works 
 Two points:

1) Linux Mint's new version (22) will have Matrix/Element pre-installed.

2) NewPipe, an android app that's a front-end for Youtube, broke from Google's updates.  Now the devs just announced they are working on a fix to the issue.

Sources:
[1] https://www.linuxmint.com/rel_wilma_whatsnew.php
[2] https://github.com/TeamNewPipe/NewPipe/issues/11255#issuecomment-2221421523 
 I was debating Telegram vs Matrix groups with an Ethereum developer,
And he said "We use Telegram because Matrix hasn't lived up to democratizing things as promised"

You're mixing up democracy and decentralization.  To quote @LibertyImp,
"Democracy is literally a 51% attack on decentralization"

Ethereum switching to democracy (proof of stake) has not really brought about the speed or cost fixes promised.  But it has introduced the new issue of the KYC exchanges having majority staking power, so they could be forced by the government to censor or steal.

One day man, you'll wake up and see that democracy is bullshit, as your fundamental human rights shouldn't be subject to the mob's decisions.  But unfortunately that day may only come because the vote will be against you. 
 The official Eth foundation, as well as prominent influencers in the space did promise it, and the Shanghai Upgrade was supposed to be when those benefits could start being implimented.  Now did they bail on that promise? Quite possible.  The issue with rollups is who is a money transmitter from a legal risk 
 cool, tell that to Samarai prosecutors. he didn't have custody 
 Totalitarian Microsoft Censors More than China

New Research from University of Toronto’s Citizen Lab presents clear systematic evidence that Microsoft censors more than even the Chinese government through it's corrupt and manipulative search engine Bing inside China.

Quote from their study:
"The institute found that Microsoft censors its Bing translation results more than top Chinese services, including Baidu Translate and Tencent Machine Translation. Bing’s censorship rules in China are so stringent that even mentioning President Xi Jinping leads to a complete block of translation results."

The report analyzed 10,000 unique censorship applications, and compared Baidu, Tencent, NetEase, Alibaba, and others.  Yet the institute found without a doubt that Bing had THE most oppressive results.  This is on the back of Bill Gates pushing for mandatory global digital IDs.

Source: https://restofworld.org/2024/microsoft-bing-chinese-censorship/ 
 I can’t believe people actually use GoDaddy’s website hosting

GoDaddy buys vanity domains and then forces you to pay outrageous fees to buy it, and so the bulk of the good domains aren’t even used.  Like half the internet is “parked domain” signs.

If after buying that domain, you then turn around and buy hosting from them too, this is like paying the ransom to the kidnapper who took your child, to then after hire that guy for babysitting. 
 says the Bitcoin maxi who is hazing / fighting with other coins.  I gotta bookmark this meme and show it to you next time =) 
 Yeah whose CEO of Monero? 
 There is no logical connection between Nostr and Custodial Bitcoin Lightning, it's totally unrelated.  If anything, they are opposite concepts.  One is you own your private key to speak, and the other you don't even own your money.

Further, there's nothing "ironic" about a privacy website promoting a privacy coin, that’s what everyone would expect.  And trying to scold me for KYC coins is a complete divergence from reality and my writings.

Your insult banter is epic fail.  I question if you even speak english.  I'm not even reading your reply 
 Thanks Ben!  Freiheit für alle!

nostr:nevent1qqsgl02kme0uepjkq4euhmvnq6slk9xff80pxsk8tsgl887j64k688spzpmhxue69uhkztnwdaejumr0dshsz9mhwden5te0vf5hgcm0d9hx2u3wwdhkx6tpdshszyrhwden5te0v5hxummn9ekx7mp0c3a9te 
 If Elon Musk really gave the slightest shit about "climate change" then:

Why didn't he make Teslas just do electric, so everyone could afford to get one?

Why make all these fancy self-driving features, fancy auto-body, ect. that raise the price and reduce adoption?
These elites do not believe their own hype, and Tesla is the biggest privacy invader out there.

Next Twitter will become the same surveillance nightmare.  How is verifying people’s identities on X, really good for free speech? 
 New Hack Shows that:

Governments that force KYC make their citizens more vulnerable to crime.

Twillio is a VoIP/SMS provider for businesses doing 2FA and other corrupt and ridiculous security.

Now Twillio's Authy app has been hacked,
This hack exposed millions of phone numbers to now be sold on the darkweb and abused,
https://thehackernews.com/2024/07/twilios-authy-app-breach-exposes.html

Once again, I am repeating the messages of:

--Do not give your real number out to verify anything
--Use burner crypto services for corrupt dumb websites that demand government SMS
--Do not trust large companies
--Don't do 2FA with mobile
--Use KeePassXC with TOTP for 2FA

KYC is a scam to make you feel secure with a trusted large provider.  In reality, you expose yourself to scams, hacks, and abuse when these corrupt entities leak your data.  Evil Governments are willing to let you be abused in their lust for power, under the disguise of saftey. 
 Hi, please consider these lists/articles

Pro/Con of Phone Numbers/Services,
https://simplifiedprivacy.com/burners/

How VoIP works,
https://simplifiedprivacy.com/voip/

I can give you a JMP code for a free month if you like, DM me 
 Hi, thanks for reaching out, sorry for the delayed reply.
please see our articles on that subject:

Why to Avoid 2FA on Phones
https://simplifiedprivacy.com/why-to-avoid-2fa-on-phones/index.html

2FA on a PC: KeePass XC Tutorial
https://simplifiedprivacy.com/2fa-on-a-pc-keepass-xc-tutorial/index.html 
 Google Censors Freedom

This post presents evidence that Google promotes an agenda of centralized control through systematic censorship on its search, email, video, app store, and ad platforms of ideas promoting decentralized personal responsibility and anything critical of government power.

Political Bias

Google directly promoted the US military’s bombing operations in Syria in a positive light on the front page of its search engine before the user even types in a search query, while Google simultaneously scores lucrative cloud contract deals with the same military. [1]

Google isn’t just lobbying for deals, they’ve literally become the corporate extension of the government. Over 53 employees have been part of a revolving door between Google and Obama’s white house staff, which is more than any other company in the United States. With Google employees joining white house staff, or transitioning the other way after Obama’s term.

Are we honestly supposed to believe Google search is unbiased? In analysis from data firm Gotcha SEO, in a study of 50 controversial terms, only 5% of the results favored conservative websites. [5] With 63.8% Neutral, 31.8% Left, and only 5% Right websites, we are expected to believe that conservatives are just “bad as SEO”.
77% of conservative emails are labeled spam

But yet this censorship and bias is prevalent even in Gmail. Research published by North Carolina State University found clear bias in how Gmail decides what is spam. Their study created 102 fake email accounts and subscribed to 2 Presidential, 78 Senate, and 156 House candidates email lists. These researchers found that under 10.12% of left-leaning politicians’ emails were marked as spam, while as 77.2% of right-leaning ones were “spam” that never made it to the primary inbox. [8]

Despite Google having such clear support for Democrats, they are exceptionally skilled at tax avoidance. The Irish Times reported on Google avoiding paying tax on $75 billion in profits through complex offshore money transfers that avoid both US and EU tax, and thus Google’s effective tax rate on these profits is 0%. [4a] Reuters reports on an earlier similar abusive transfer of $23 billion sent to the tax haven Bermuda. [4b].

Even left-leaning researchers find clear evidence of Google’s email bias. The Markup did a study with extensive statistical analysis of 5,417 emails from 172 different political groups during election season. They found clear bias in the treatment of which campaigns’ emails got labeled spam or promotions. For example Tulsi Gabbard got a mere 2.22% of her emails in the primary inbox, while other candidates saw 12, 46, or 63%. Elizabeth Warren who is highly critical of Google’s monopolistic power, coincidentally did not get a single email in the primary inbox. [9]

The Verge reports on presidential candidate Tulsi Gabbard, who also promotes breaking up Google, faced similar censorship when her Google Ads account suddenly was suspended right as traffic to her website spiked immediately following a televised debate. This ended up depriving her campaign of millions of dollars in revenue from the organic traffic she was receiving. [14]

Tailored Propaganda

Google does not just censor equally for every user, but tailors their propaganda to the individual’s search and email history. Google through their Jigsaw division has partnered with Moonshot CVE to offer paid search engine manipulation services for the US government. If the Department of Defense is the client, then at a minimum using Google search to research anything related to foreign policy would be a direct conflict of interest. Moonshot CVE claims that this search engine manipulation is just to stop extremists which promote violence. [12]

However, from documents leaked to Wikileaks, we’ve learned that it’s secretly the US government that incites and strokes violent uprisings. For example the Syrian civil war, in which millions of people died, was sparked in part from the US government purposefully igniting tensions between Sunni and Shite Muslim ethnic groups to create instability that would overthrow the president of Syria Bashir Assad. According to leaked Wikileaks cables, William Roebuck, the US diplomat in Damascus, suggested the US should “stroke these tensions and play on these fears” when writing back to Washington right before the war broke out in 2006. [2]

But yet Google’s front page promotes an entirely different narrative on Syria as they put John Kerry’s statements below the search bar. And paints anyone who dares to question their narrative is labeled as a “conspiracy theorist”.

Not only does Google have an interest in manipulating the search results, but their partner Moonshot CVE openly admits to storing in a database the IP address and location of those searching for controversial information. These databases are then used to target redirection techniques to websites that the government has deemed to be “less extreme”. [12]

The idea of customized government propaganda administered through personalized monitoring should provide strong motivation for the use of a trusted VPN or Tor.  NSA Whistleblower Edward Snowden called Google search completely unuseable because of it’s anti-privacy stance. While Google’s CEO Sundar Pichai said that the company will develop machine learning and A.I. to combat “misinformation” shared by “low-information voters” and conspiracy theories. The issue is who gets to decide what is true and what defines a “conspiracy”? This pretext could be used to censor true information that Google’s paying customers (governments and large corporations) don’t want heard.

One example of this is the Federal Reserve creates money, which causes inflation and your salary to be worth less. But this banking system doesn’t affect everyone equally, because the banks and their wealthy clients get access to the freshly minted money first at lower interest rates, while the poor can not effectively hedge against inflation with assets that rise from printed money like stocks or real estate.

This is the type of criticism which was laid out in James Corbett’s ‘Century of Enslavement: The History of the Federal Reserve’, which got millions of views and rose to the top of Youtube’s search as the 1 video for the keywords “Federal Reserve”. At least it was on top of Youtube’s search, until MSNBC’s Chris Hayes tweeted out that this video was promoting “conspiracy theories” and the video was downgraded immediately from being the number one video for the search terms to not even showing up. [3] However, Chris Hayes did not provide a single argument as to why the video was wrong or inaccurate.

How much your content strays from Google’s view will determine how your emails are received. A different libertarian leaning news site found its email list delivery rate to be half for Gmail what it achieves sending to non-Gmail accounts. [10]

Cryptocurrency Banned

While Cryptocurrency offers a way to escape from the tyranny of central bank inflation, Google fundamentally disagrees. Forbes reports on Google overwhelming banning crypto apps and Youtube channels well beyond what it does for other industries. [15]

For example Google delisted apps for the popular cryptocurrency wallet Metamask from both the Google Play store and the Chrome web store. [16] Mobile App Daily comments on Google banning almost all crypto mining apps without any type of warning. [17] And industry leaders CoinTelegraph and CoinDesk both had their news apps removed from the Play Store. [18]

Many Crypto Youtube channels were suspended or banned even those that just promote basic Bitcoin education. Some of these had millions of views or subscribers and were done without warning. While some of these channels have been restored, it still damaged their fanbases to have outages. [19]

Locked Out of Accounts

Suspension can get you locked out of all accounts that use a Gmail. Jordan Peterson is a popular conservative Youtuber that some consider controversial including Google, who suspended his account without warning. While having his Youtube channel removed hurt his business, the real crippling part was his prior reliance on using the Gmail associated with that account. Peterson explains in an interview with the Daily Caller: “I’ve had that account for the last, say, 15 years. All of my correspondence is in that account. It’s hundreds of thousands of emails from people all over the world.” [6]

Not only did Peterson have a difficult time reaching out to his personal and business relationships, but all of his accounts like banking, medical, and other websites were linked to that email. This is the danger of using Gmail or other centralized email providers because then if they censor you, then you’re locked out of everything.

Cybersecurity Video influencer the “Mental Outlaw” points out that some listeners may think they are immune from censorship similar to what Jordan Peterson experienced because they aren’t public personas with a Youtube channel, but Google often suspends accounts for even posting comments and replies to videos that they deem inappropriate. Therefore Mental Outlaw warns it’s quite possible that you could get your email suspended over some comment or reply you consider to be relatively mundane and thus be locked out of all your accounts that used that email to verify. [13]

Conclusion

A reliance on Google products (including even Gmail) will curb your ability to access ideas, learn, and ultimately brainwash you to obey centralized authority which does not have your interests at heart. This trained obedience could lead to a direct decline in your finances, health, and ability to connect with others.

Sources:
https://simplifiedprivacy.com/google-censors-freedom/index.html
 
 Privacy Ranked:

I’m going to rank these least private to most, and explain why on each step.

Discord
Why: Discord is as bad as it gets.  It's not only completely unencrypted, but they maliciously sell your data and have such huge restrictions on VPN IPs and SMS VoIP verification.

SMS
Why: It’s going naked over the phone lines, but isn't heavily sold in such a rotten way as Discord.

VoIP
Why: VoIP is just as horrible as SMS, but separates your real physical location from the cell tower

Telegram
Why: Unlike VoIP, it does have end-to-end encryption, but only on mobile.  And with weak encryption that they made up, that hasn’t been properly reviewed [Source: Madaidans of Whonix]

Signal
Why: Telegram has no metadata protection, while as Signal has sealed sender.  Signal’s encryption is stronger and more thoroughly peer reviewed.  Also Signal has a good legal track record and isn’t strict on crypto VoIP burners like Telegram.   Having phone numbers isn't that big a deal if I paid $1 of crypto for a random VoIP burner in Cambodia without restrictions on Tor.  Btw, my Signal # is Cambodian: +855 68 504 905

Matrix
Why: Tucker Carlson’s Signal was hacked.  Also, academic papers have shown Signal’s sealed sender has flaws.  If you self-host Matrix, that's much more control than trusting Amazon's AWS, which is a CIA contractor.   Many open source projects use Matrix rooms.

Session
Why: Most Matrix users use Matrix.org which is Cloudflare with Gmail verifying the emails.  Setting up a Matrix server is more expensive and complex than just opening Session and hitting "create account".  Session’s onion routing, non-location based DNS, and decentralization is stronger than Matrix's Cloudflare-dominated network.

SimpleX
Why: Session lacks (by default) rotating keys and multiple identities. You can manually rotate keys using your blockchain name, and manually get multiple accounts at once via enabling it on Linux, but most won’t want to do this just to avoid government domain names (which most SimpleX users use).  Session is better for censorship of servers, SimpleX is better for end users being invisible.

Self-hosted Tor XMPP
Why: SimpleX is hiding from servers, but if you control the server, that’s stronger.  Even a self-hosted SimpleX server only picks half the conversation.  Also, XMPP has a longer proven track record, which is more eyes on the code.  Now if you DON'T self-host XMPP, it's way up on the list next to Matrix.

Self-hosted Tor XMPP w/ OTR
Why: OTR nukes the conversation when it’s done. It literally destroys the encryption keys.  Game over bro.

Conclusion:
Anything is better than Discord.  Now, let's play a game, pick a communication method I did not mention, and you tell me where you think it should rank on the list.  Then, we'll discuss.
 
 Briar is peer to peer via Tor. This has pros and cons.

Pro:
-Everything stays on your local device
-Uses Tor Onions to avoid government domains
-It can do bluetooth to bluetooth, for like an in-person protest for example

Con:
-UI sucks
-Other person has to be online
-You can use mailbox drops to host a server, but then it’s really just like XMPP over Tor
-Group chat user interface is horrible and confusing 
 thanks for posting. you thought the UI was too basic or more confusing? 
 What VPN? They usually ban spammer IPs, which turns into most of them 
 Why is Matrix any more or less pedos than other networks? 
 I'm going to write about Keet once they open source.

Keet is peer to peer UDP via holepunching. This has pros and cons.

Pro:
-Faster file transfers and video chat
-Less censored group chats or individual
-One of the few unstoppable group chats that doesn't rely on hiding the server.  There is no server
-Avoid government domains

Con:
-UDP packets won't work over Tor
-Not as easy to hide this networking style from global networking surveillance
-Not yet open source
-Other person has to be online for peer to peer

Comparison with others:
Session group chats are on a regular server, while as Keet is peer to peer, so it's more unstoppable for group chat than the other things on this list.  Keet also has the group video chats in a way that others do not.

But Keet requiring UDP from your home makes it less private than anything you can onion route.  So no Tor even on, or onion routing like Session. 
 I'm going to write about Keet once they open source.

Keet is peer to peer UDP via holepunching. This has pros and cons.

Pro:
-Faster file transfers and video chat
-Less censored group chats or individual
-One of the few unstoppable group chats that doesn't rely on hiding the server.  There is no server
-Avoid government domains

Con:
-UDP packets won't work over Tor
-Not as easy to hide this networking style from global networking surveillance
-Not yet open source
-Other person has to be online for peer to peer

Comparison with others:
Session group chats are on a regular server, while as Keet is peer to peer, so it's more unstoppable for group chat than the other things on this list.  Keet also has the group video chats in a way that others do not.

But Keet requiring UDP from your home makes it less private than anything you can onion route.  So no Tor even on, or onion routing like Session. 
 SimpleX conversations break it up into two servers to hide metadata.  There is debate over if this technique is good enough.  Under this system, they pick your send, you pick your receive

As we wrote here:
https://simplifiedprivacy.com/servers/index.html 
 you're welcome, thanks for tuning in 
 This was my initial criticism when comparing it to Session yes.  The hiding IPs feature improves this, but ideally fully rotating them would be ideal, I agree.

Btw, keep up your XMR posts =) 
 There’s a lot to digest in your points.  Let’s start with VoIP since it’s the easiest to explain.

If I have JMP.chat linking an XMPP account to a SMS phone number.  The SMS carrier does not know my physical location where I’m standing if using VPNs/Tors.  We outlined this here:
simplifiedprivacy.com/voip

Are you disputing this? 
 I am saying that the post has the same content as the website:
VoIP lets you do SMS with Tor/VPN, so it COULD separate physical location from the SMS.

Are you disputing this?  Perhaps I should have used the word “could” 
 OTR requires the other person to be online, so that's a deal killer for most people.
OMEMO has async time and does images.  But when we say "no longer recommended", by who? there is no authority.

The individual end clients don't like it.  And therefore the XMPP foundation doesn't like it.
But unless you can link me to evidence that it's encryption can be broken. 
 It's possible, I can't say for sure it's not.
But for a lot of low technical skill users, it is a decent first step. And good for non-controversial stuff.

We can agree it's better than SMS? Well the kind of people who are using SMS, aren't gonna switch to simplex or session. So this is how you get em 
 I think Signal is better than Protonmail. Signal is code on your device, while w/ proton you trust their web app in a browser. It could be switched up on you to get the password in a second. 
 Yea, consider this short animated video on XMPP from our team:

https://video.simplifiedprivacy.com/xmpp/ 
 Radical bro. Let's get pizza 
 So PGP PLUS Nostr? That'd be unstoppable breaking encryption wise, but Metadata issues remain 
 0xchat uses a similar system to Signal's sealed sender for the encryption, but this is changing. Last I heard all of the Nostr client devs were trying to upgrade to a v3 once it passes an audit.  Once they do so, there will be a big question of which relays will support this, which has metadata questions.

So we have to see on these changes 
 If the sender is wrapped in encryption, then it's protected.  And yeah Tor would help.
If it's a Tor Onion relay, even better.  Not sure if 0xchat supports that.
What you're describing with Tor + Nostr + sealed sender is basically how Session works 
 Best solution is if the relay is on the network too, be that onion services or i2p.
I know there are a few Onion nostr relays, not sure on i2p. If you find i2p ones, let me know 
 I like Briar in concept yes. But it's peer to peer, so the other person has to be online.
This has the potential to defeat the purpose or leak metadata if you reach out via a different channel 
 yes correct, but its only on mobile 
 As far as I know PGP to relay would have to be custom coded.  In my subjective opinion, you're better off whitelisting by nostr public key, since the metadata is on the relay anyway. 
 Yeah I've seen that, but you gonna store it on a VPS or your home? If it's a VPS, then it's basically XMPP w Tor Onions 
 Why is it so important for conservatives to get off Big Tech?

(Linux, degoogled phone, decentralized social, ect)

1) Your enemy controls your means of finding news and publishing your content

2) Your enemy oversees everything you’re doing and can later jail you.  Even if you think you're doing nothing wrong, some complex cryptocurrency transaction tax can be used years later to silence you.  Look at Roger Ver who was jailed a decade later for Bitcoin taxes, even after renouncing US citizenship.

3) You have lack the technical infrastructure to resist during a crisis.  The next "covid" situation will endanger you and your family because you can't get a fake vaccine passport without being watched.

4) You're a target to the woke radical left to get you fired because your political speech is tied to you.  Look at NixOS, he just got ousted by Transgenders just for saying "let's all be equal"

5) You're overpaying for new electronics.  Microsoft and Apple products have planned obsolescence, which is to purposefully force users to buy new products, by having them break down quickly.  While as Linux often allows older PCs to work longer.

6) You don't believe your own political beliefs.  If you really thought there was a deep state out to silence, kill, and control us all, then you wouldn't be blabbing about it on Twitter tied to your real name's family bank account with your life savings.

In summary, if you continue with Big Tech:
1) You're silenced
2) You're propagandized
3) You're fired
4) You're poor
5) You're a hypocrite, you don't believe your own positions.

Some people think Linux, DeGoogled Phones, or having your own VPS is complex or beyond them.  But I am here to tell you that it's not that different than what you’re already used to.  And the only real obstacle is in your mind.  Learn what you can from our site, and reach out for help if you need it.  Help me, help you. 
 Remember yankee, Fireworks are illegal

So don't get caught celebrating that you're supposed to be free 
 July 4 Special:
Pro/Con of the United States

Pro:

-Demonstrated to the world that free market capitalism produces wealth
-Economic freedom in the 1800s and 1900s lead to massive innovation and productivity to improve many people's lives
-Original focus on individual constitutional rights gave a philosophical framework for global liberty
-Lots of hotspots for innovation: Silicon Valley, Wall Street, New Orleans music, & more

Con:

-Consistent military empire
-The violent empire erodes many of the civil and fiscal liberties that once made the US great
-Fiscal slavery over foreign minorities through the World Bank and IMF
-Global taxation of income, even if US citizens work in a foreign country
-While the US doesn't have the most oppressive laws compared to some dictatorships, the enforcement and surveillance is the most sophisticated.  When this is combined with complex and vague laws, such as cryptocurrency, it becomes the least free place for Agorism.  
 Critical Security Vulnerability with Linux OpenSSH
(But don’t panic)

This affects most VPS servers with SSH:
Allows remote execution of code

Nicknamed "RegreSSHion", a play on words

Key points:
--Let’s not panic, it’s difficult to pull off
--No known wild exploits
--You should update your VPS asap, but don’t panic about it
--Attack takes 8 hours to complete [1]
--Attack may require up to 10,000 authentication steps [1]
--Attackers must also know the specific OS running on each targeted server. [1]
--No one has found a way to exploit 64-bit systems [1]
--Many distros have patches including Ubuntu [2][3]
--Update with the patches, you’ll be ok (Use Fail2Ban too)
--Affects OpenSSH server versions 8.5p1-9.8p1
--Palo Alto Networks was NOT able to pull it off in the wild [4]

Before you panic, read this from Palo Alto:

“While there is PoC code for this vulnerability, there is no known activity in the wild as of July 2, 2024. Our testing of this code suggests it is not functional in our testing environment. We have been unable to successfully exploit the CVE-2024-6387 vulnerability with this PoC to achieve remote code execution.” [4]

Bottom line: Update with the patches.

Sources:

[1]
https://arstechnica.com/security/2024/07/regresshion-vulnerability-in-openssh-gives-attackers-root-on-linux/
[2]
https://security-tracker.debian.org/tracker/source-package/openssh
[3]
https://ubuntu.com/blog/ubuntu-regresshion-security-fix
[4]
https://unit42.paloaltonetworks.com/threat-brief-cve-2024-6387-openssh/ 
 Linux distro NixOS kicked the founder out

They forced him to sign a letter giving NixOS "back to the community" because he supported treating everyone as equal.

The activists were furious he did not support Transgender rights, which means discriminating against non-trans for funding and power.

Source is Lunduke (which is behind Cloudflare btw, but I gotta link the original):

https://lunduke.locals.com/post/5819317/nixos-commits-a-purge-of-nazi-contributors-forces-abdication-of-founder 
 What? SEC can't regulate crypto anymore?

Yeah bro, the Supreme Court overruled a previous decision on the Chevron doctrine.
What this means in plain english, is:

BEFORE when the law was vague or unclear, the individual agencies would set policy based on their expertise.  So when Congress had not made the law clear, the courts would look to the agencies for guidance.  This was called the "Chevron doctrine" off an earlier case in 1984 (Chevron v. NRDC).

But NOW, the Supreme Court overruled that and agencies must seek the court's guidance when the law is not clear.  In other words, the SEC doing whatever they want with crypto is coming to end, as they no longer have power and authority unless the court grants it.

We could also word this as, the government is so hungry for power, that the only way to stop the madness coming from these unelected agencies, is for the Supreme Court to seize it's own power back.

To summarize the words of a professional educated expert and legal scholar, that I consulted on matters of the highest level of dignity, we could word this:

"Gensler, you lost you dumb assclown" 
 All Session messenger rooms are getting DDoS'ed with a flood of spam.

Our room is now in lockdown, no new posts.

Be advised simpleX could be a target next.  These anonymous messengers with zero credentials to make new burners can be easily flooded with bots.  Matrix and XMPP are tied to government domains, so it's easier to control where bots are coming from or verification on the big servers.

Here’s the key point:
The more control group owners have against DDoS of group chats, the less metadata protection the 1-on-1 chat users have. 
 maybe as an option on groups. but for mobile devices with 3 hops networking? takes the instant out of instant messages 
 This US Supreme Court Ruling is a big deal

It means the government CAN pressure social media companies to censor anything

You can use technology like Nostr to resist it, BUT,
Technology can’t help you stop the state’s violence.

Therefore,
Without the privacy to post anonymously, there is no free speech.

Fast key facts to know about the case:

1) It isn’t over, it just got sent to the lower courts
2) Supreme Court dismissed it that “plaintiffs lacked standing”
3) This doesn’t mean it’s done, it means they have to prove (again) that they were harmed in lower courts
4) Dissenting judges cited significant evidence in favor of the defendants

We lost the battle.  But the war can be won.

Full official text:
https://www.supremecourt.gov/opinions/23pdf/23-411_3dq3.pdf
 
 In a huge Supreme Court decision on Wednesday,

The court ruled 6-3 that the Biden administration didn’t do anything wrong when asking social media companies to remove posts of covid “misinformation”.  This had previously gone the other way in the lower courts, favoring the censored victims.

As State sponsored propaganda outlets like NPR puppet the narrative that “there was no proof” in the Twitter Files,

The real clue comes from Jack Dorsey abandoning not only Twitter, but also leaving top-down controlled BlueSky’s board, to come to Nostr.

Government: There is no pressure to censor
Twitter CEO: I must flee to Nostr where I can’t be held accountable 
 Comments posted by Vidar in the group chat, quote:

I agree it makes Zero sense to you or me. Though I can guess some potential motivating factors:

Assange public supporters aren't going down in numbers. I would guestimate there are more supporters now than 10 years ago, and there would have been more demonstrations. Growing public outrage.

The Deep State trying to make it look good for Biden before election. *See links

The USA prosecutors could see that their case was weakening as time continued, and they offered Assange a simple guilty plea Today, rather than lose the case completely after another 5 years.

his sources:
https://edition.cnn.com/2024/06/24/politics/julian-assange-plea-deal-biden-administration/index.html
https://www.bbc.com/news/world-us-canada-68784298


 
 These are solid arguements as well.  I don't have all the answers man.  However keep in mind the effects of some of these wikileaks, such as Arab Spring kicking out Pro-US puppets, or Hillary Clinton losing the election, or Citibank picking obama's cabinet being exposed 
 Hmm, you do have good insights.  Some of these statements I agree with, others are pushing it.

The first paragraph on trump I accept your arguments.  I'm just not pushing that as "the sole truth", as the arguments against it are logical as well.  Trump certainly picked deep state people in his cabinet/staff.

As far as the deliberate decline of the US empire, I disagree with.  In fact, I think most war/coups in the Middle East, South America, and even other places has been over the forced sale of oil in US dollars.  And actually Wikileaks has been some of the sources we've backed these claims up with. (such as Libya)

But even without Wikileaks, Iraq's timing and Venezuela coups are great examples of "sell oil in USD or die"

I agree with you that they want one world government, but I think the path towards that is dominance of the petrodollar empire & IMF/World Bank. 
 Yeah it's off. But the whole thing increasingly is. why would the US let Assange walk? This makes... 
 Comments posted by Vidar in the group chat, quote:

I agree it makes Zero sense to you or me. Though I can guess some potential motivating factors:

Assange public supporters aren't going down in numbers. I would guestimate there are more supporters now than 10 years ago, and there would have been more demonstrations. Growing public outrage.

The Deep State trying to make it look good for Biden before election. *See links

The USA prosecutors could see that their case was weakening as time continued, and they offered Assange a simple guilty plea Today, rather than lose the case completely after another 5 years.

his sources:
https://edition.cnn.com/2024/06/24/politics/julian-assange-plea-deal-biden-administration/index.html
https://www.bbc.com/news/world-us-canada-68784298


 
 Huge thanks to SimpleX's developer for coming through for the event!

Here's what he shared with us about the future of @simplex:

-Moving off Github this year
-Flatpak support is coming very soon, like 1 week
-iPad Support this year
-Group chat on-board with 2-3 other users will eliminate the need for the admin to be online
-Will be getting rid of the "connecting" on initial sync and increase speed of on-boarding

With the new feature to hide IPs, the user is first sending it to a server they trust, which passes it to the other server.  How do users know who to trust?

The app will soon be able to differentiate infrastructure operators in these ways:
-several preset providers in the app next year
-operators can self-identify with certs, it's optional - this year
-using servers of people you are friends with or know - very soon
-A user asked about a directory - but it is not coming due to privacy and trust concerns it would create

To make the network financially sustainable and provide the commercial incentive to the operators they are designing the concept of "infrastructure vouchers" that are planned for 2026.
These vouchers will:

-Will be on a private blockchain maintained by the approved operators together with the app developer(s)
-Work like gift cards, except:
-Vouchers won't be transferable from 1 user to another
-No refunds
-No wallet
-Stays in-app
-Can't be used as external money to avoid compliance requirements
-One can buy vouchers with Monero (or other cryptocurrencies), as long as XMR remains legal
-Government fiat can be used
-Voucher sellers may be different than server operators (collectors)
-It won't be just the SimpleX team selling vouchers, some decentralization

Here's more details on his commercial model:
https://github.com/simplex-chat/simplex-chat/blob/stable/docs/rfcs/2024-04-26-commercial-model.md

And if you haven't already seen the new version with slick UI, head over to https://simplex.chat 
 Because bitcoin has no binding contract functionality to enforce or do anything
 
 Signal has a flatpak.  In fact, you can use the official distro repo AND flatpak for two identities

flatpak install flathub org.signal.Signal

it will add to your start menu, but also could do:
flatpak run org.signal.Signal 
 hey @frphank it was a group Q&A in our simpleX chat.  I think me and you spoke in there earlier about IPFS not scaling.  And you were correct it does not.  I do still think there are some limited use cases and benefits to it, but IPFS will not be the mass adoption future at least in it's current form, I agree 
 Was a reference to the backgrounds on desktop and mobile being improved with the layout of the avatars/text 
 I believe codeberg was mentioned, but he can confirm this 
 I can not speak for the SimpleX dev on this, but @mister_monster may potentially have a comment on grin with chat 
 join our XMPP group =) 
 hit join group:
simplifiedprivacy@subscribe.simplifiedprivacy.is

Info:
https://simplifiedprivacy.com/xmppsub/index.html 
 Good morning.

Is there a way to de-google tablets?
#asknostr 
 Yes and we are selling them at discount rates.  far below Google's retail.  please DM me or check previous posts 
 Did you know on Signal, your deleted messages aren’t deleted?

Don’t believe me?  Cut Signal’s network permission on Android.  And go a long time with using it on desktop with disappearing messages on.  Then re-sync Android with network permission, and boy you’ll be shocked to see those messages flash back before your eyes!  They’re still on Amazon’s centralized servers even though they took it off your device.

This is even sadder when you think about how in centralized systems, it’s easier to force messages out.  But with decentralized systems, there’s issues.

SimpleX has unique plans to force messages to disappear on the other person’s device, but how’s he gonna implement it?  These are the types of questions to ask and hear at tomorrow’s event.
(if you live in Asia, it’s tonight)

nostr:nevent1qqsdawduqa7czztnjc7dnk4mwpm7j0dmdshkwa8apvhpf6jpgxlkkvcpzpmhxue69uhk2tnwdaejumr0dshszrnhwden5te0dehhxtnvdakz7qg7waehxw309ahx7um5wghxvmrpd45kuem094kkz6tv9e3k7mf0r906zz 
 The thing about these presidential debates is they never discuss the real issues.

Nobody says "hey maybe the issue with economics is the money itself is debt"

Nobody says "why fight the Taliban in Afghanistan for years, if it was Al-Qaeda that fled to Pakistan?"

They just keep taking jabs at each other.  And the sad thing is, most people will never realize these other ideas exist.

But there is good news, you can reject the system and join the parallel economy.  the parallel social media.  parallel tech.

Yes startups are rough.  Yes it has a learning curve.  But as Tom Edison once said "I have not failed. I've discovered ten thousand ways that don't work." 
 SimpleX Dev Q&A Event

Simplified Privacy’s group chat on SimpleX will have the lead developer Evgeny Poberezkin drop by to answer your questions.  Ask him upcoming features, technical questions, or the direction of the project.

Saturday June 29, 1 hour starting at:
2pm UTC
New York 10am
Hong Kong 10pm

It’ll be an open chat for you to pick his brain.  Join in advance, don’t wait for right before the event because the moderator has to be online for it to connect you, so we give options.

Here’s East EU & Asia timezone:

https://simplex.chat/contact#/?v=2-4&smp=smp%3A%2F%2FN_McQS3F9TGoh4ER0QstUf55kGnNSd-wXfNPZ7HukcM%3D%40smp19.simplex.im%2F-0fWTzXMJNobsaiaodOGLOfm0m9pq05I%23%2F%3Fv%3D1-2%26dh%3DMCowBQYDK2VuAyEAdfeJrGjuY_qKripG4E7xle6nTDWOWuBPtWmapW6pyEc%253D%26srv%3Di53bbtoqhlc365k6kxzwdp5w3cdt433s7bwh3y32rcbml2vztiyyz5id.onion&data=%7B%22type%22%3A%22group%22%2C%22groupLinkId%22%3A%22yhJzAfpfVkMynOUVxs412g%3D%3D%22%7D

West EU & Americas:

https://simplex.chat/contact#/?v=2-5&smp=smp%3A%2F%2FSkIkI6EPd2D63F4xFKfHk7I1UGZVNn6k1QWZ5rcyr6w%3D%40smp9.simplex.im%2FxPXefPbN7ZAkPyMKzJmQrFD_fv55R6w_%23%2F%3Fv%3D1-2%26dh%3DMCowBQYDK2VuAyEALLyynGdXLoWke3pIt1CrR00p62eT0ewpKEaWn542gWA%253D%26srv%3Djssqzccmrcws6bhmn77vgmhfjmhwlyr3u7puw4erkyoosywgl67slqqd.onion&data=%7B%22type%22%3A%22group%22%2C%22groupLinkId%22%3A%22n99NTwZLjeKwyI4lwMHB_g%3D%3D%22%7D

If you can’t make it and want to ask something, reply to the post here on RebelNet, and we’ll post the reply copied to you.
https://rebelnet.me/news/0xbf8079a69a15fd74ae
 
 The big news is he said flatpak is coming soon, like 1 week.  Regarding the battery said:

“We do something that reduces battery usage in almost every release - 5.8 had a notable improvement, and 6.0 will have it too.  Battery usage is not one big thing to work on, it's many small things each contributing a little bit.  User-visible server stats will also ship in 6.0 - it'll help a lot identifying battery drains.” 
 Repost this for Assange:

The criticism of Julian Assange being funded by the US government is bullshit.

This claim comes from Daniel Estulin's book, (which combined with his other works sold 8 MILLION copies), and his primary source is Peiter Zaitko, who works for Google, Twitter, and the US military.

If Assange really was big a psy-op, then wouldn't exposing that be a huge risk to one's life?  Wouldn't they KILL whoever was telling the truth?

So now you're gonna tell me, that Zaitko working for the US military and Google as a free man, while he's exposing the very same military's largest undercover propaganda of all time is perfectly fine…  All as Assange who supposedly "worked for the military" rotted in jail.  And all of this is in Daniel Estulin's for-profit book on Amazon, promoted on his website using USA-compliant Cloudflare, Bill Gates Microsoft emails, and malware Google analytics.

Only for a US dollar banking system paid book, shilled on Youtube, via the CIA contractor Amazon, can you tell me that Assange's non-profit Bitcoin donation website was government lies.  And you have zero presence on Nostr, IPFS, Arweave, Tor, Iceland servers, or anywhere that an oppressed truth teller would.

In fact, Estulin doesn't even have a doge coin donation address.  As you shill your other book on the banking system being corrupt, you're still less rebellious than autistic little girls buying doge coin with their tooth fairy bills.

You think you're beating the CIA?  Bitch please, I could kill you with a plastic hello kitty squeaky toy.

Repost this to help clear Assange’s name.  Maybe add your own shit talk! 
 Assange is alive because the whole world is watching and the blowback that illegally killing him would create. 
Also the CIA wanted to kill him according to some of his leaks, after he did the one showing their hacking of routers and killing via remote car shut offs. 
 I did not say he deserves it?

My arguement from before was less so that the hater would be killed, but more so that he was literally working for the US military while he was actively "exposing" their psy-op.  Can we agree this is a little off? 
 Hot special:

GrapheneOS Pixel Tablets CHEAPER THAN through Google.

Google sells these for $399
Our promo is $335.

Normally DeGoogled privacy providers charge more than the official stock retailers, but we got a promo special going on right now that's CHEAPER 

Plus it comes with a code for a free month of JMP Chat.
I only got 3 left in stock under this pricing, so you have to act quick.

-Brand New
-Still in original packaging
-Pay in Bitcoin or Monero
-You can choose to get it still sealed in original packaging, or have us open it and flash GrapheneOS
-Keep your name off hardware identifiers
-Keep your name off the cloud, buy it through encrypted chat
-Get a PGP signed receipt.
-1 Year Warranty from Google (to get a new one)
-1 Week Shipping Hardware Warranty from me (to get crypto back)
-Includes a code for a free month of JMP Chat
-Support the circular Nostr economy
-I'm grinding to raise money for original open source projects

Perfect for:
--Chilling on the couch or bed but get a larger screen
--Watch movies
--Navigating websites on phones sucks, but who wants to carry around a laptop?
--Get work done on the go
--Advanced security of GrapheneOS
--Tablets are the perfect blend of the convenience of mobile, with the ease of access from laptops

Hazel color
8 GB LPDDR5 RAM
128 GB UFS 3.1 storage
17.39 oz (493 g)
10.2 width x 6.7 height x 0.3 depth (in)
10.95-inch display LCD
2560x1600 resolution

Session ID: Support
Signal: +855 68 504 905
Matrix: SimplifiedPrivacy@HackLiberty.org
XMPP: XMPP@SimplifiedPrivacy.is
email: support [at] libertyoceanhorizons [dot] c o m
SimpleX:
https://simplex.chat/contact#/?v=1-4&smp=smp%3A%2F%2FZKe4uxF4Z_aLJJOEsC-Y6hSkXgQS5-oc442JQGkyP8M%3D%40smp17.simplex.im%2FjlgwnohJoxn1yz9bhJ_3m6JhanIbgOME%23%2F%3Fv%3D1-2%26dh%3DMCowBQYDK2VuAyEArsSD2oa0yAYYTXuSKj_3uw5uQo0LU77i3jeoXtK6kjU%253D%26srv%3Dogtwfxyi3h2h5weftjjpjmxclhb5ugufa5rcyrmg7j4xlch7qsr5nuqd.onion 
 “Why privacy? What do you have to hide?”

The question is not why am I hiding, it’s why are you for free submitting to their absolute surveillance over every word you say in chat and every thought you have through algorithmic AI monitored feeds that do custom propaganda?

Julian Assange paid a heavy price just to show us the tip of the iceberg.  And you want to send every thought going through your skull to them?!  Replace the word privacy with power. 
 What do I want?
Self-sovereignty over my life & Political Freedom

How do I express that?
Not by voting, but through depriving Governments of power with Technology

What defines tech freedom?
Encryption as Identity
Open Source
Permissionless
Decentralized

How do I live?
End-to-end encrypted messengers
Encryption based social media
Encryption based contracts
Linux
DeGoogled Android
Self-hosting my email
Self-hosting my website
Reject government money
Reject government domains

How do I reject government domains?
Nostr
Tor Onions
Session Bot (DM Simple. 200+ followers)
SimpleX Bot in future (I got some ideas w rotating burners)
Arweave (I'm Privacy.ar)
Eth push channels
IPFS (I'm SimplifiedPrivacy.sol)
Yes IPFS sucks, I'm working around the issues

How do I reject government money?
Point customers to easy crypto on-ramps,
https://simplifiedprivacy.com/crypto/index.html

What law do I follow?
PGP sign contracts, w/ deposits or multi-sig.

Core message:
The enemy is not the government, it's pessimism.
For all the tools you need are there, you just have to find the motivation to use them. 
 UK's Nigel Farage had his Google ads account suspended.

After many criticized censorship of an active election, Google gave it back.

He's praising this as a win.  But to me, it's a loss.  You're pouring more money into the lefties, to try to stop the influence of pro-authority lefties.

I know he's trying to reach as many people as he can, but you're telling me that's the only way to spend ad money?  You know, he could pay the relevant websites directly, and cut Google out.  Google's just a middle man.

It's more work to arrange this, but under the moral high ground of censorship, he would get replies… and votes. 
 Despite it being easier to self-host XMPP and less expensive on resources, Matrix is more popular.  Why?

The real reason Matrix is popular is because corporate and FOSS developers like the encrypted group chats for their internal use.  (XMPP is NOT encrypted group chats).  So then devs host a Matrix room to answer end-user questions, and having all these rooms encourages overall adoption.

The part that's not usually mentioned, is that only the devs usually use self-hosted Matrix servers, and the vast majority of the public uses Matrix.org which is on Cloudflare with Gmail verification.

In theory Matrix is decentralized, but in the real world, everyone gets Cloudflare metadata surveillance, and uses the same Element client.

Here's my core message:
Try to be Self-Sovereign with what you're doing.
If you're hosting a website, 1 core VPS for email, whatever.  Then host your own XMPP/Matrix.  XMPP uses so little resources, it's near free.

If a VPS is really not for you, even if you pay someone like me $100 to set it up:
https://simplifiedprivacy.com/email-cloud-combo/index.html

Then public SimpleX/Session servers are right for you.  That's fine.  This isn't about me trying to force you to use my favorite protocol.  It's about you not using Cloudflare (and Protonmail seeing your metadata) and thinking you're "doing privacy". 
 Nice, that's not the default though.  I'd be interested to see your setup.  Can you post a group link? 
 fair enough, can you post any public documentation on setting it up? like on prosody site. I didn't see it there when we did our MUC 
Event not found
 I am sorry, my post is redacted. The original sources were mistaken.

The pages went down due to high traffic on the servers following the release.  I just confirmed and I can view the DNC emails from podesta with Bernie sanders on Wikileaks.org

Other made the same mistake:
https://www.dailydot.com/debug/wikileaks-delete-dnc-emails-debunk-assange-plea-deal/ 
 I am sorry, my post is redacted. The original sources were mistaken.

The pages went down due to high traffic on the servers following the release.  I just confirmed and I can view the DNC emails from podesta with Bernie sanders on Wikileaks.org

Other made the same mistake:
https://www.dailydot.com/debug/wikileaks-delete-dnc-emails-debunk-assange-plea-deal/ 
 sorry post was redacted