Limit the (#curl) URL size more?
In Firefox we got bugs when we tried to limit it, because the hash would contain encoded data, or data URLs would encode images or video.
TODO: consider a multi-threaded #curl tool
GrapheneOS version 2025121000 released
This is our first non-experimental release based on Android 16 QPR2 after our initial experimental 2025120800 release.
The change to the style of notification backgrounds is an upstream regression rather than an intentional change to a more minimal style. It will be fixed in a subsequent release since we decided it isn't important enough to delay this.
Tags:
- 2025121000 (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, Pixel 9a, Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL, Pixel 10 Pro Fold, emulator, generic, other targets)
Changes since the 2025120400 release:
- full 2025-12-05 security patch level
- rebased onto BP4A.251205.006 Android Open Source Project release (Android 16 QPR2)
- disable promotion of identity check feature not currently present in GrapheneOS due to depending on privileged Google Mobile Services integration
- GmsCompatConfig: update to version 166
All of the Android 16 security patches from the current January 2026, February 2026, March 2026, April 2026, May 2026 and June 2026 Android Security Bulletins are included in the 2025121001 security preview release. List of additional fixed CVEs:
- High: CVE-2025-32348, CVE-2025-48641, CVE-2026-0014, CVE-2026-0015, CVE-2026-0016, CVE-2026-0017, CVE-2026-0018
2025121001 provides at least the full 2026-01-01 Android and Pixel security patch level but will remain marked as providing 2025-12-05.
For detailed information on security preview releases, see our post about it.
GrapheneOS security preview releases - GrapheneOS Discussion Forum
GrapheneOS discussion forumGrapheneOS Discussion Forum
Vojtux - Accessible Linux distro which is almost pure Fedora
Vojtěch Polášek has put together a technical preview of a version of Fedora that should work well for blind or visually impaired users. While his goal is explicitly to see these improvements and changes become part of Fedora itself, for now you can use this implementation based on the Fedora MATE spin. :)
➡️ freelists.org/post/orca/Announ…
#Vojtux #Fedora #Accessibility #a11y #Linux #OpenSource
[orca] Announcing Vojtux - Accessible Linux distro which is almost pure Fedora - orca - FreeLists
[orca] Announcing Vojtux - Accessible Linux distro which is almost pure Fedora, orca at FreeListswww.freelists.org
Peter Vágner likes this.
reshared this
C'est dimanche, c'est le #pfffitt !
Édition spéciale "blagues de l'Est communiste" !
"Tu veux vivre en RDA ? Ne pense pas. Si tu ne peux pas t’empêcher de penser, ne parle pas. Si tu ne peux pas t’empêcher de parler, n’écris pas. Si tu ne peux pas t’empêcher d’écrire, ne signe pas. Si tu ne peux pas t’empêcher de signer, ne t’étonne pas."
Un touriste occidental, sûr de sa supériorité, à un citoyen russe : « Nous en Occident, nous avons le droit de critiquer notre gouvernement. »
Le Russe, surveillant du coin de l’œil le mouchard de service : « Et alors ? Nous aussi, nous avons le droit de critiquer votre gouvernement ! »
RE: fosstodon.org/@arcanechat/1157…
There’s a vulnerability in Signal. You are developing an alternative. Do you:
- A: skim read the report, see it contains the phrase ‘phone number’, and shitpost about Signal, or
- B: Analyse the attack and see if it could be adapted to your protocol, then post about how you either were already protected or have deployed a mitigation?
If you chose option A, please don’t expect to be able to convince me that you are serious about security.
@arcanechat @ david_chisnall@infosec.exchange
It's obvious David doubled down on missing the point --thanks for the heads up
"Tool allows stealthy tracking of #Signal and #WhatsApp users through delivery receipts"
cyberinsider.com/tool-allows-s…
Another privacy vulnerability caused by the dependency on phone numbers.
In #ArcaneChat (and other #chatmail clients like #DeltaChat) you don't need a phone number (or any private data at all!) to register, so such attacks are simply impossible, keep your family safe, join arcanechat.me
Tool allows stealthy tracking of Signal and WhatsApp users through delivery receipts
A new tool named Device Activity Tracker exposes a privacy flaw in WhatsApp and Signal that lets attackers covertly monitor user activity.Alex Lekander (CyberInsider)
When you post something about a vulnerability in another messenger and completely misrepresent it, in a way that implies that you don’t understand the cause of it at all, it gives me no confidence in your system.
The root cause is nothing to do with phone numbers. It depends on two things:
- Being able to send messages to someone from some public identifier. Any messenger that doesn’t require an interactive flow for pairing devices (as some military systems do) has this feature.
- Receiving read receipts from messages. Signal allows you to turn off read receipts if you are concerned about information leaks from them.
If you actually wanted to convince people your system was better you would:
- Show that you don’t issue read receipts (which will put some people off because they are useful).
- Show how you mitigate this kind of attack, by rate limiting this kind of message, adding jitter to responses, and so on.
Email-based flows tend to not be vulnerable to this kind of attack because they do most of the processing on the server, so you’d only be able to probe the server. But you wouldn’t bother because email has so little metadata protection that you don’t need to bother with an attack like this. From what I know of DeltaChat’s group chat protocol, I suspect there is a way of triggering a similar attack by sending broadcast invalid messages and timing the error response. If you really wanted to convince people that your system is better, you’d show a security analysis that explains why I’m wrong, rather than just say ‘I don’t understand this attacks but the researchers who published it didn’t bother trying to attack the protocol I use and so I’m sure it is secure!’ That is exactly the attitude to security that makes me distrust DeltaChat.
Oh and before anyone jumps in with anything about XMPP: this attack is completely trivial on XMPP. Send an invalid iq stanza to the client’s bare JID and time the response. And this is impossible to fix without redesigning the protocol because unknown iq stanzas must be forwarded to the client to enable future extension and clients must respond with errors.
So there is no way for anyone to use a public identifier like an email address or similar to reach you?
What do you put on business cards or similar if you want people to contact you? An invite link?
#DeltaChat is for private chatting, so you normally don't put your link anywhere publicly, you could create a dedicated profile for public interactions tho, which, unlike in signal, it is super easy to do and you can have as many as you want,
and notice the use case I am talking here is family chat, not business and public interactions, that is why I said "keep your family safe" I am talking about family chat solution here
#DeltaChat is for private chatting, so you normally don't put your link anywhere publicly, you could create a dedicated profile for public interactions tho, which, unlike in signal, it is super easy to do and you can have as many as you want,
Okay, so your use case for 'private chatting' excludes journalists publishing contact information for whistleblowers? It excludes union organisation? It excludes protest organisation?
I guess that's fine, but maybe don't claim to be operating in the same space as Signal then.
and notice the use case I am talking here is family chat, not business and public interactions, that is why I said "keep your family safe" I am talking about family chat solution here
Then you need to learn about the concept of an anonymity set. If you have one mechanism for talking to your family and another different one for talking to your union rep, it's really easy for a passive adversary to track when you suddenly start using a different mechanism for high-value conversations.
@david_chisnall
what kind of passive adversary are you talking about here? server, provider, global?
Identifying whether you are using this or that chat profile is not necessarily trivial, especially since the 2.33 releases which introduced multi-relay profiles. A single chat profile can jump between using different relays/hosts.
FWIW we share the recommendation of @arcanechat to split between a public profile (invite link published etc.) and private ones (no publishing).
> Okay, so your use case for 'private chatting' excludes journalists publishing contact information for whistleblowers? It excludes union organisation? It excludes protest organisation?
> I guess that's fine, but maybe don't claim to be operating in the same space as Signal then.
the ArcaneChat slogan is "private chats for the family" I don't get why you jump angry into my thread to attack, I never said anything about "whistleblowers" whatsoever, please, calm down 😅
@david_chisnall
Sorry for jumping in as a random person here, but I think I have some relevant points.
First of all, you admittedly both missed the mark about the cause of the security issue Arcane posted. Delivery receipts are separate from read receipts, and turning off read receipts in signal does not mitigate this issue.
Now as per Delta Chat's FAQ: delta.chat/en/help#what-do-the…
It should have the same issue. Delta Chat claims to send "delivery" receipts, but as far as I can tell, there is no UI indication for the sender when a client receives the message (I tested both mobile and desktop). So unless there is an email sent that doesn't result in any UI indicator for the sender, I think Delta Chat is safe from this particular privacy issue. If it is the case that Delta Chat identified this bad decision and fixed it, please also update your FAQ to match!
The rest of y'all's argument seems to hinge on aspects of how delta chat and arcane chat are marketed/presented, rather than the technical details, so I'm not interested. But what I *do* find really interesting is the idea that "private" and "secure" chat programs would ever send automatic responses without user action. To me, it seems painfully obvious that "features" like this just create an attack surface for probing. Look... I use Signal (as well as Delta Chat), and I like it, and I'm not going to stop using either anytime soon. But it was disappointing to learn about this anti-feature. It *is* a legitimate criticism of Signal that needs to be addressed.
Also, while this issue had nothing to do with phone numbers, I think the fact that Delta Chat does not require phone numbers, and allows the creation of more identities than one might even *have* phone numbers, is an enormous advantage compared to Signal for people who want to protect the privacy of their identity and not just the contents of their messages.
Delta Chat: FAQ
What is Delta Chat? Delta Chat is a reliable, decentralized and secure instant messaging app, available for mobile and desktop platforms. Instant creation of private chat profiles with secure and i...delta.chat
@capitalthree ArcaneChat/DeltaChat doesn't have delivery receipts, only read receipts, the only automatic responses the app does in your behalf is to handle invite links, for that you first have to share invite link with the malicious contact, as side effect they also expose when they are online so if you go to your contact list and see them at the top with a green dot while not chatting with them often you can detect this, in thr future this might change
> rather than just say ‘I don’t understand this attacks but the researchers who published it didn’t bother trying to attack the protocol I use and so I’m sure it is secure!’ That is exactly the attitude to security that makes me distrust DeltaChat.
I don't understand why do you seem so upset, #DeltaChat has received several REAL PROFESSIONAL INDEPENDENT security audits, all listed here: delta.chat/en/help#security-au…
can you provide a similar list of REAL sec. audits for Signal?
Delta Chat: FAQ
What is Delta Chat? Delta Chat is a reliable, decentralized and secure instant messaging app, available for mobile and desktop platforms. Instant creation of private chat profiles with secure and i...delta.chat
I don't understand why do you seem so upset,
Because you're spreading misinformation to score marketing points and spreading misinformation about secure messengers gets people killed.
I don't understand why do you seem so upset, #DeltaChat has received several REAL PROFESSIONAL INDEPENDENT security audits, all listed here: delta.chat/en/help#security-au
So, none after this particular class of attack was discovered and therefore none that include this in the threat model?
Delta Chat: FAQ
What is Delta Chat? Delta Chat is a reliable, decentralized and secure instant messaging app, available for mobile and desktop platforms. Instant creation of private chat profiles with secure and i...delta.chat
Prevent silent probing of device online status
SecureJoin has two types of tokens: invite tokens and auth tokens. Currently SecureJoin invite token can be used to silently probe device online status. Auth token when successfully used results in...link2xt (GitHub)
I like on QR code "Scan to chat with adb"
I just type in terminal "adb --help" 👀
Delta(s). Your design -- separation of chatting logic from transport -- is what will allow to overcome this observation and correlation constructions.
You can swap to different transport, like ASMail from 3NWeb set, it is web-style federation, reducing metadata on servers, and correlations between servers.
And then clients and servers may sit on mixnet, like Nym (say hi to them at 39c3).
- Tempo (50%, 1 vote)
- Button (50%, 1 vote)
like this
reshared this
@ondrosik Thanks for publishing it online for all of us to enjoy and reuse. It's very important to see an example of real personal creativity these times when AI is dominating the space of background music, jingles and other short tracks.
Huge thanks!
Maybe even 6DD. I mean damn!...
RE: hear-me.social/@Onj/1156902183…
I've done what I set out to do by the end of the year. I made it to 180 tracks in the collection. I stopped at 171 in May of 2023, then I just couldn't focus on much music for the last couple of years which, as a composer, really depressed me, but this December I decided to really try and sit down to make a go of it, so I did.
It may not seem like much, but not being able to write, when it's what I've done for 30 years felt very stifling and depressing in ways I cannot express.
My next goal is to hit 200, so I'll start work on that, hopefully soonest.
I just want to thank every person that favourited, reposted or interacted with me on my self-assigned journey recently. You're all wonderful humans, even those that said they had no use for such a project, which is totally fine. They still shared it most of the time, and I respect that.
reshared this
Přede mnou poslední pracovní týden (? možná - si ještě skočím do práce 22. a 23. chystat nové nástupy).
Stihnout se toho musí jako obvykle tři prdele.
V pondělí IT večírek. V úterý reinstalace notebooku majitelky. Ve středu výměna notebooku. Ve čtvrtek další večírek. A v pátek, aby toho nebylo málo, naaaaa Vsetíně, tam je luka, seče jú syneček.... Od rána až do večera. To bude náročné.
A samozřejmě očekávám uživatele, kteří si podají požadavek 19. prosince a 5. ledna se zeptají, proč to ještě není hotové.
No, ale pak budou Velikonoce 2. - 6.4., neasi 😃 A to už je kousek do léta.
Taky funguju na solár, ale letos, jak není zima, jako že nemrzne, mi to vadí nějak méně.
Ale bylo by fajn, kdyby se přestal posouvat čas, to mi vadí stejně jako nedostatek světla.
Jsem tým letního času, ale budu spokojen, ať bude čas jakýkoli, když se s ním nebude hýbat.
TFW you try to find a spec for something and when you finally found it on the Wayback machine, since trillion dollars corps can keep URL alive, and you go to save it, you are told it's already there...
Yes I already had it. I just forgot.
Word is the new Canadian ambassador to the US is a banker.
The AI Research Sector Is Being Destroyed by Something Incredibly Ironic share.google/ZKLSNO6frU1btoX4h
AI “Research” Papers Are Complete Slop, Experts Say
As AI researchers churning out papers with AI models rise to the top, the entire field is becoming a rapid race to the bottom.Frank Landymore (Futurism)
On a more positive note, it's absolutely heartwarming seeing the number of patches and contributions from community members increasing in Thunderbird.
The massive undertaking of replacing old weird undocumented code with modern coding standards and languages, as well as increasing our documentation is slowly paying off.
Yes, we know, we accidentally broke a bunch of things in the process, sorry. This stuff is hard 🫠
Winter blue tardis
in reply to YourFavoriteAtheist🇨🇦 • • •YourFavoriteAtheist🇨🇦
in reply to Winter blue tardis • • •Winter blue tardis
in reply to YourFavoriteAtheist🇨🇦 • • •Winter blue tardis
in reply to YourFavoriteAtheist🇨🇦 • • •YourFavoriteAtheist🇨🇦
in reply to Winter blue tardis • • •Winter blue tardis
in reply to YourFavoriteAtheist🇨🇦 • • •