• 0 Posts
  • 7 Comments
Joined 1 year ago
cake
Cake day: July 1st, 2023

help-circle



  • Nowyn@sopuli.xyztoPrivacy Guides@lemmy.oneleaving google
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    NordLocker was part of Nord Security external ISO27001 audit in 2022. Of course, being closed-source software you can’t really know security fully. The biggest concern seems however to be the encryption model they use in addition to being closed source. However, for example, hosting my own cloud service while most secure really isn’t the option that would answer the reason I use cloud service.

    I am not saying use it. I am saying it often gets recommended. I really do think people should do their own research on if things are best fit for them. I am having a huge issue finding actually secure solutions that are not self-hosted and FOSS or at least open source. Nextcloud which is fully hosted by service or on your own bought server space has some concerns as well.



  • Pissing off entire nation state or at least people in power in that nation is unfortunately easy these days. And while the average person usually doesn’t run into these issues the shrinking spaces and criminalization of civil society even in countries you wouldn’t think are that far gone are at the level that surprising people might run into these issues. There are also some situations where you don’t need to piss off entire governments to get a lot of data from a person. Tech-savvy abusive spouse might be enough.

    We are not really disagreeing here. I just think that we need to be open about the vulnerabilities and strengths of software. The security of Signal and Matrix are absolutely great especially compared to things like WhatsApp. But they are not 100% secure. Very little is.


  • Of course use Signal or Matrix but please don’t think that makes your messaging entirely impenetrable. I am not saying their end-to-end encryption has been breached. But a compromised device is a compromised device. Signal might be secure at least for now, but is your keyboard?

    We do live in times of zero-click spyware and while the general public doesn’t necessarily have to worry about things like Pegasus atm, it is still used increasingly and not just against people who break the law.

    I do my best, although I do fail to be up to date every once in a while, to stay as secure as possible, but to think any communication is entirely secure is not a good policy.