<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: LWIRVoltage</title><link>https://news.ycombinator.com/user?id=LWIRVoltage</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 27 Jul 2026 20:56:35 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=LWIRVoltage" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by LWIRVoltage in "US citizen charged after GrapheneOS phone wipes during airport search"]]></title><description><![CDATA[
<p>A few things:<p>#1. The download and restore backup method would work- except it doesn't capture what people would need. Exmaple: I have some thermal cameras that rely on old 32 bit apps that do not run on anything android 12 onwards- If i wipe those old phones, and restore- the apps often wanted to reach out to a server for initial activation- they would fail upon reinstall and i'd be out of the apps that are required to control my cameras and related equipment,which is worth thousands and thousands and thousands. And it'd be all dead weight and rendered useless.<p>(and competitors today do not compete- for example try finding a 640*480  30 hz or better form factor thermal camera that attaches to phones - they dont exist anymore)<p>\The solution is imaging- but there isnt a way to fully image phones and restore backups today. There used to be it seems- but not really with the latest.<p>Veracrypt- The weakness of truecrypt and veracrypt, the hidden OS option only worked if you converted your computer to MBR, which means you can't have a hard drive too large. Making a UEFI hidden OS has not been done yet.<p>I am aware of Shufflecake attempting to make a solution.<p>And the Hidden Volume option- isn't 'as' useful, and of course, your OS might make a copy and put it somewhere, you have to be careful. Any time I open a file, using the software tool Everything to search and confirm this- you can easily see Windows makes copies and temp files and whatnot in randomly named locations-  that's the sort of behavior that would screw people over<p>We need fully image-backup capable Phones. I mean fully. Not just backing up some apps- as this refuses to backup apps you have that are no longer on app stores, or that Play Protect doesn't like, etc.<p>Next- Plausible deniability is a way forward- but you need multiple profiles, that are cryptographically indistinguishable, along with the phone being hardened so GreyKey /Cellebrite won't be able to exploit a way in. This needs to be built this way from the ground up ideally, eventually.<p>There has been research about making devices that treat all block space the same way so you can't tell if someone has 1, or 50 profiles or partitions, etc- and even stuff that overlaps. But nothing has come out - and especially, for phones.<p>After all, if you travel to a hostile country, you can tell them you have just one profile, and if they ask, you could theoretically mention a 2nd, and then show it- but you might have 3 more - and they'd all be immune to forensic inspection if the system is built right.(Yes, there's often issues you have to be careful of ,like setting this up so you dont destroy data when in other profiles,)<p>This is how you solve this problem -make computing devices impossible to analyze</p>
]]></description><pubDate>Mon, 27 Jul 2026 16:04:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=49071562</link><dc:creator>LWIRVoltage</dc:creator><comments>https://news.ycombinator.com/item?id=49071562</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49071562</guid></item><item><title><![CDATA[New comment by LWIRVoltage in "Ask HN: Who wants to be hired? (July 2026)"]]></title><description><![CDATA[
<p>Location: Central Florida region<p>Open to Remote: Yes<p>Willing to Relocate: Yes<p>Technologies: C, Java, Python, RHEL, Operations, Bash, Windows Server, Vmware, VirtualBox ,AIX, , RHEL, Debian ,Docker<p>Where I come from: I've worked for NASA , as a System Administrator and Operational Test Conductor,helping to run field ops as well as maintain security , provision and administer their launch systems.<p>I've helped run operations involving multiple sites and multiple groups around the Country to that involved testing aspects of space hardware ,software involving multiple various teams and groups.<p>I currently am part of the requirement testing process for NASA's Launch Control Software and help design tests,and ensure the software is up to spec , and validate requirements for Artemis 2 and 3 actually putting the software through it's paces.<p>I'm a team-orientated, friendly, detail focused technologist with a eye towards expanding and delving more into the development side of tech, leveraging my experience in administration and operations over, and getting a little deeper to working with the innards that make things tick and being able to tweak them,.<p>I can be reached at lwir.voltage385@slmails dot com</p>
]]></description><pubDate>Thu, 02 Jul 2026 12:59:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=48760846</link><dc:creator>LWIRVoltage</dc:creator><comments>https://news.ycombinator.com/item?id=48760846</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48760846</guid></item><item><title><![CDATA[New comment by LWIRVoltage in "Veracrypt project update"]]></title><description><![CDATA[
<p>.... This deserves it's own posts , on HN, just for awareness-<p>Aside from 
<a href="https://web.archive.org/web/20250914062843/https://portswigger.net/daily-swig/russian-doll-steganography-allows-users-to-mask-covert-drives" rel="nofollow">https://web.archive.org/web/20250914062843/https://portswigg...</a>
, there haven't been really many goes at going for plausible deniability with modern systems, and I see the segment about a Hidden OS feature in work as well.<p>Hoping this succeeds. Funny, eventually Shufflecake, after it gets fully capable on Linux, might have to look at making versions for Windows and Mac</p>
]]></description><pubDate>Wed, 08 Apr 2026 17:02:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=47693020</link><dc:creator>LWIRVoltage</dc:creator><comments>https://news.ycombinator.com/item?id=47693020</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47693020</guid></item><item><title><![CDATA[New comment by LWIRVoltage in "Veracrypt project update"]]></title><description><![CDATA[
<p>What sucks about this, is due to implementation,Windows is the only way to achieve some stuff in Veracrypt. For example: doing full system partition encryption, and the Hidden OS install that only Veracrypt can do- requires Windows with the computer set to MBR rather than UEFU. I had hoped we'd see more of the plausible deniability tech at the OS level<p>But aside from one or two experimental attempts, also presented at BlackHat
<a href="https://web.archive.org/web/20250914062843/https://portswigger.net/daily-swig/russian-doll-steganography-allows-users-to-mask-covert-drives" rel="nofollow">https://web.archive.org/web/20250914062843/https://portswigg...</a><p>- the consumer has nearly lost access to high end plausible deniability</p>
]]></description><pubDate>Wed, 08 Apr 2026 15:44:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=47691779</link><dc:creator>LWIRVoltage</dc:creator><comments>https://news.ycombinator.com/item?id=47691779</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47691779</guid></item><item><title><![CDATA[New comment by LWIRVoltage in "Bitchat – A decentralized messaging app that works over Bluetooth mesh networks"]]></title><description><![CDATA[
<p>Okay, this is neat! A true mesh networking bluetooth app- The other one that's notable,  Briar is super impressive - but i think it doesn't actually have proper mesh capability due to difficulties with how devices handle things<p>(See: <a href="https://old.reddit.com/r/Briar/comments/gxiffy/what_exactly_are_the_capabilities_and/" rel="nofollow">https://old.reddit.com/r/Briar/comments/gxiffy/what_exactly_...</a><p><a href="https://news.ycombinator.com/item?id=43363031">https://news.ycombinator.com/item?id=43363031</a>
}<p>Anyway,
-Question: I take it Murmur is end to end encrypted fully?
Also, just curious if this is open source?<p>This could become SUPER useful- having a actual mesh networking Bluetooth app , if it's open source/E2EE!</p>
]]></description><pubDate>Mon, 07 Jul 2025 04:59:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=44486896</link><dc:creator>LWIRVoltage</dc:creator><comments>https://news.ycombinator.com/item?id=44486896</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44486896</guid></item><item><title><![CDATA[New comment by LWIRVoltage in "Ask HN: Who wants to be hired? (June 2025)"]]></title><description><![CDATA[
<p>Location: Central Florida region<p>Open to Remote: Yes<p>Willing to Relocate: Yes<p>Technologies: C, Java, Python, RHEL, Operations, Bash, Windows Server, Vmware, VirtualBox ,AIX, , RHEL, Debian ,Docker<p>Where I come from: I've worked for NASA , as a System Administrator and Operational Test Conductor,helping to run field ops as well as maintain security , provision and administer their launch systems.<p>I've helped run operations involving multiple sites and multiple groups around the Country to that involved testing aspects of space hardware ,software involving multiple various teams and groups.<p>I currently am part of the requirement testing process for NASA's Launch Control Software and help design tests,and ensure the software is up to spec , and validate requirements for Artemis 2 and 3 actually putting the software through it's paces.<p>I'm a team-orientated, friendly, detail focused technologist with a eye towards expanding and delving more into the development side of tech, leveraging my experience in administration and operations over, and getting a little deeper to working with the innards that make things tick and being able to tweak them,.<p>Stripped version of my resume at <a href="https://ibb.co/tpqYm7nF" rel="nofollow">https://ibb.co/tpqYm7nF</a> I can be reached at lwir.voltage385@slmails dot com</p>
]]></description><pubDate>Mon, 02 Jun 2025 20:44:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=44162839</link><dc:creator>LWIRVoltage</dc:creator><comments>https://news.ycombinator.com/item?id=44162839</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44162839</guid></item><item><title><![CDATA[New comment by LWIRVoltage in "“Fewer Users” Warning Hurting Specialized and New Apps"]]></title><description><![CDATA[
<p>... These sorts of patterns do not help at all, and will hurt those who have critical need for apps without a lot of users.<p>Speaking as somebody, who owns some mid-grade thermal cameras that stopped production in the past few years after a decade run, that depended on and are solely controlled and run on apps that were removed from the app store or no longer can run on modern phones because they are in 32-bit format ; this sort of thing would further punish that type of software and only speed up its demise.<p>When you spend thousands and thousands and thousands and of dollars and resources into getting unique capabilities like that, that can only be controlled through Android apps often, and is the only way to get that capability for some (this will apply to multiple and I imagine with niche capabilities that only have one or two methods of Access)<p>- this hurts a lot of opportunity, and this type of dark anti-pattern is far too blunt</p>
]]></description><pubDate>Fri, 02 May 2025 15:28:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=43871078</link><dc:creator>LWIRVoltage</dc:creator><comments>https://news.ycombinator.com/item?id=43871078</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43871078</guid></item><item><title><![CDATA[New comment by LWIRVoltage in "Android phones will soon reboot themselves after sitting unused for three days"]]></title><description><![CDATA[
<p>A Veracrypt style hidden OS profile that is forensically invisible would be a better option - This would allow one to enter a password and give another "profile" or OS- that unlike current alternate profile stuff- would be solid against Cellebrite and GreyKey snooping into the device, and it'd be impossible to tell there was a hidden user/etc on it</p>
]]></description><pubDate>Sat, 19 Apr 2025 21:31:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=43739633</link><dc:creator>LWIRVoltage</dc:creator><comments>https://news.ycombinator.com/item?id=43739633</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43739633</guid></item><item><title><![CDATA[New comment by LWIRVoltage in "How to lock down your phone if you're traveling to the U.S."]]></title><description><![CDATA[
<p>Does obtaining Global Entry minimize the chance of them deciding to harass a citizen crossing the border, I wonder? It is at the cost of your biometric - but data on your devices might be worth more, and as I note elsewhere in this thread, you can image a computer and back it up fully, but not a phone without some data loss, unfortunately. [ TWRP possibly can do it right perhaps, but it requires unlocking the bootloader (which wipes the phone), and once bootloader is unlocked, it's more vulnerable to Cellebrite and company, to my understanding, ]<p>seeing the latest (leaked?) Cellebrite info from 2024 Summer- BFU State[Before First Unlock state] after posting on, modernimoPuxelsiPhones on the latest OS, and graphene devices see moto be the hardest to get into.<p>Anyway- ,  with computers - this was a solved problem from a technical standpoint- Yes I'm talking Truecrypt then, and today  Veracrypt. The Hidden Container feature is impressive- but the Hidden OS feature allows for a truly hidden OS behind the scenes that can't be found at all. However, there's a unfortunate weakness that makes this hard to use today- it's limited to MBR , not UEFI [GPT]systems- so unless you like your computer not being able to have more than 2 Tb - and only 4 partitions (so good luck If you do a lot of stuff from dualbooting to other whatnot) 
We need a Veracrypt Hidden OS equivalent for UEFI systems that's truly undetectable.(That also will work for Linux and maybemeMac not just Windows as Veracrypt currently does - you can only make the Hidden Volumes on the non Windows versions of VC)
 There was one project to do it - and there were articles and a black hat presentation on 'Russian Doll Steganogrpahy" for a OS- but it didn't go anywhere from what I can tell, and everyone is now wide open .... Unless you have a MBR system. I also think I've heard UEFI is more easily secured  than MBR in general and for the foreseeable future...<p><a href="https://portswigger.net/daily-swig/russian-doll-steganography-allows-users-to-mask-covert-drives" rel="nofollow">https://portswigger.net/daily-swig/russian-doll-steganograph...</a><p><a href="https://i.blackhat.com/eu-18/Thu-Dec-6/eu-18-Schaub-Perfectly-Deniable-Steganographic-Disk-Encryption.pdf" rel="nofollow">https://i.blackhat.com/eu-18/Thu-Dec-6/eu-18-Schaub-Perfectl...</a></p>
]]></description><pubDate>Wed, 09 Apr 2025 21:09:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=43638022</link><dc:creator>LWIRVoltage</dc:creator><comments>https://news.ycombinator.com/item?id=43638022</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43638022</guid></item><item><title><![CDATA[New comment by LWIRVoltage in "How to lock down your phone if you're traveling to the U.S."]]></title><description><![CDATA[
<p>This annoys me to no end and is a serious problem in my own use cases...<p>This is an issue I face- I have a collection of thermal cameras that use apps to control them- after every install onto a phone, they then reach out t oa server to authenticate.<p>Here's the issue- though I have a few older phones- these apps are 32 bit ones, so no modern phone after Android 13 will run them. And they are all now not on the app store anymore,as they all came out about around 2016. i did use a APK extractor to pull the APKs to store them - but the native backup functionality wouldn't capture that authorization in the future, I might rob myself of my ability to use some extremely expensive, and long-term invested capable hardware, by backing up and restoring-<p>I suspect a full image would solve this problem, but I don't think one can do that outside of things like TWRP- but that requires unlocking the bootloader, and if you do that it wipes your device- AND is more vulnerable to Custom's usage of Cellebrite and etc, to my undertanding.<p>I don't have this issue with laptops ,as I can fully image them and wipe and restore ahavend have a perfect replica/ no issues. But my thermal cameras do not run off of PC and th eform factor wouldn't work if they did</p>
]]></description><pubDate>Wed, 09 Apr 2025 20:56:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=43637883</link><dc:creator>LWIRVoltage</dc:creator><comments>https://news.ycombinator.com/item?id=43637883</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43637883</guid></item><item><title><![CDATA[New comment by LWIRVoltage in "How to lock down your phone if you're traveling to the U.S."]]></title><description><![CDATA[
<p>Veracrypt. It's successor, keeps this feature - of allowing for a truly hidden OS- but there's a HUGE flaw everyone missed- it requires your laptop to be setup as MBR-= which only allows for 4 partitions, and you can't have more than like 2 TB of filespace on it total.<p>We need a similar solution for UEFI- that allows for truly hidden, foolproof hidden OS installs.</p>
]]></description><pubDate>Wed, 09 Apr 2025 20:54:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=43637849</link><dc:creator>LWIRVoltage</dc:creator><comments>https://news.ycombinator.com/item?id=43637849</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43637849</guid></item><item><title><![CDATA[New comment by LWIRVoltage in "How to lock down your phone if you're traveling to the U.S."]]></title><description><![CDATA[
<p>This is something no on discusses but I've wondered heavily- GRUB can be made to not show a menu and then boot up Windows automatically, in like a second or two with no one the wiser. [There is an obnoxious welcome to grub message that pops up now but I see a public project out there that solves this very easily called GRUB shusher]<p>I don't know if other bootloaders outside GRUB have a silent/hidden  start option, as well in a similar vein that would require you to hit a key in that first second to get the menu to appear, or else it just boots up normally<p>I wonder about the other approach, just going into the BIOS nad changing the order so Windows boots first, which should be doable in some setups. Lock the BIOS with a password, and you're in not bad shape. (Not sure if Secure Boot being enabled could also help here -  probably couldn't hurt)</p>
]]></description><pubDate>Wed, 09 Apr 2025 20:51:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=43637814</link><dc:creator>LWIRVoltage</dc:creator><comments>https://news.ycombinator.com/item?id=43637814</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43637814</guid></item><item><title><![CDATA[New comment by LWIRVoltage in "How to lock down your phone if you're traveling to the U.S."]]></title><description><![CDATA[
<p>I am in a similar pickle.<p>This is an issue I face- I have a collection of thermal cameras that use apps to control them- after every install onto a phone, they then reach out t oa server to authenticate.<p>Here's the issue- though I have a few older phones- these apps are 32 bit ones, so no modern phone after Android 13 will run them. And they are all now not on the app store anymore,as they all came out about around 2016. i did use a APK extractor to pull the APKs to store them - but the native backup functionality wouldn't capture that authorization in the future, I might rob myself of my ability to use some extremely expensive, and long-term invested capable hardware, by backing up and restoring-<p>I suspect a full image would solve this problem, but I don't think one can do that outside of things like TWRP- but that requires unlocking the bootloader, and if you do that it wipes your device- AND is more vulnerable to Custom's usage of Cellebrite and etc, to my undertanding.<p>I don't have this issue with laptops ,as I can fully image them and wipe and restore ahavend have a perfect replica/ no issues. But my thermal cameras do not run off of PC and th eform factor wouldn't work if they did</p>
]]></description><pubDate>Wed, 09 Apr 2025 20:42:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=43637719</link><dc:creator>LWIRVoltage</dc:creator><comments>https://news.ycombinator.com/item?id=43637719</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43637719</guid></item><item><title><![CDATA[New comment by LWIRVoltage in "How to lock down your phone if you're traveling to the U.S."]]></title><description><![CDATA[
<p>This is an issue I face- I have a collection of thermal cameras that use apps to control them- after every install onto a phone, they then reach out t oa server to authenticate.<p>Here's the issue- though I have a few older phones- these apps are 32 bit ones, so no modern phone after Android 13 will run them. And they are all now not on the app store anymore,as they all came out about around 2016. i did use a APK extractor to pull the APKs to store them - but the native backup functionality wouldn't capture that authorization in the future, I might rob myself of my ability to use some extremely expensive, and long-term invested capable hardware, by backing up and restoring-<p>I suspect a full image would solve this problem, but I don't think one can do that outside of things like TWRP- but that requires unlocking the bootloader, and if you do that it wipes your device- AND is more vulnerable to Custom's usage of Cellebrite and etc, to my undertanding.<p>I don't have this issue with laptops ,as I can fully image them  and wipe and restore  ahavend have a perfect replica/ no issues. But my thermal cameras do not run off of PC and th eform factor wouldn't work if they did</p>
]]></description><pubDate>Wed, 09 Apr 2025 20:41:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=43637700</link><dc:creator>LWIRVoltage</dc:creator><comments>https://news.ycombinator.com/item?id=43637700</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43637700</guid></item><item><title><![CDATA[New comment by LWIRVoltage in "Tailscale has raised $160M"]]></title><description><![CDATA[
<p>I just this past weekend was looking into setting up a personal networking solution- and looked hard at TailScale and their competitors. I do not like- that Tailscale has chosen to only allow SSO sign-in - as that forces one to have a Microsoft,Github[MS], Google,  or Apple account- and I presume that leaves one at the mercy of those companies for the free option.<p>I will probably eventually cave and use my main account from one of those companies since creating true secondary accounts can be difficult(they end up tied back to your main account on the backend usually, So if something happens to one or the company does something- it'll affect everything and building separation is not easy.)  - But I dislike that sort of design.</p>
]]></description><pubDate>Wed, 09 Apr 2025 06:09:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=43629346</link><dc:creator>LWIRVoltage</dc:creator><comments>https://news.ycombinator.com/item?id=43629346</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43629346</guid></item><item><title><![CDATA[New comment by LWIRVoltage in "U.S. national-security leaders included me in a group chat"]]></title><description><![CDATA[
<p>AI spotted those comments on reddit- note: those were not my words about Eve(which i'm unfamiliar with!)<p>Point taken though , the commenters who said that were ...obviously..anecdotal, -though possibly still more the norm...)</p>
]]></description><pubDate>Sat, 29 Mar 2025 05:43:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=43513072</link><dc:creator>LWIRVoltage</dc:creator><comments>https://news.ycombinator.com/item?id=43513072</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43513072</guid></item><item><title><![CDATA[New comment by LWIRVoltage in "U.S. national-security leaders included me in a group chat"]]></title><description><![CDATA[
<p>This is true absolutely<p>One would hope indeed- I do wonder on that ......<p>There's another observation though- Salt Typhoon compromised wiretap infrastructure - before Signal, there's no doub't some stuff like this occured over text messages-
Because of everyone's efforts to go to Signal- even if it's for the message disappearing- with this, with military branches pushing it hard- with Sweden's Miltary pushing it, etc(for non sensitive stuff)- there's so much of that , that the attack surface overall is massively reduced. In short, if there's going to be stuff outside of vetted systems- running that sort of stuff Signal- likely still helps. 
(I'm reminded again, of the JD Vance interviews where he let slip that he'd been targeted ,and was informed about it by agencies- but that he was good because of his Signal usage. Now, I don't know what measures he takes to avoid zero day exploits and whatnot- the TLAs would inform him of that- but from what he was saying, it sounds like they were sure he wasn't compromised by that.)<p>(I'm aware a serious targeted effort would be more intricate than Salt Typhoon/ Trying to use the country's own general Wire tapping capability to target the VP)<p>Edit: Also, this reveals a bit about psyche- J.D.Vance somewhat ribbed the president- there is probably pressure TO use Signal, so a record of him criticizing the President can't be found out by the President or those more allied with the President who could then start retribution- I imagine dynamics like that, which are human behavior- -ultimately are what absolutely drive all of this.</p>
]]></description><pubDate>Mon, 24 Mar 2025 20:45:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=43465232</link><dc:creator>LWIRVoltage</dc:creator><comments>https://news.ycombinator.com/item?id=43465232</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43465232</guid></item><item><title><![CDATA[New comment by LWIRVoltage in "U.S. national-security leaders included me in a group chat"]]></title><description><![CDATA[
<p><tangent opening line of my comment> From people on Reddit: Something that blows my mind- but is fully true
"Hell, I've been in fucking EVE Online alliances that had better opsec than this."
"I'll raise you one: I've never been in any EVE alliance that didn't have better opsec than this."<p>..I noted Board Games(Secret Hitler, for example) require better opsec. So do card games- it's mindblowing to note this too...<p>[Main comment by me - technical outlook]
This is not a surprise at all- there were reports that the first Trump administration was using Signal to communicate, and that it was a a risk as messages can be totally wiped and not kept for records keeping.<p>-From an infosec standpoint- this is more notable than I think people are giving it credit- the fact that the Vice President(Well, maybe not him, he notably admittted in interviews during the presidential campaign, that he'd been briefed by three letter agencies on Salt Typhoon tageting him, but that he was secure because he used Signal)   - the director of national intelligence- and several others- use Signal.<p>it's one thing for Congress, Sweden's Military, and apparently our own military branches to push Signal heavily for non-sensitive stuff-<p>But when those around three letter agencies -and the groups that would be interested in finding compromises- are using it, that screams to me that it's considered not that easy to attack- which is a point towards Signal<p>So then the final thing to secure are the endpoints- and of course the risk is a zero day exploit targeting someone. As for subtle push app updates by Signal themselves being a vector- i'd think the Open Source nature of the app prevent that - if the infrastructure for pushing updates is open source as well especially.<p>Again though- if the White House is using Signal- they likely KNOW most of what their own Three Letter agencies can and can't do(to a point)- so when people in the know are using it- that is telling.<p>A lot of it may be for the auto disappearing messages, admittedly- but that's notable. And yes, I'm aware Mark Zuckerberg has been known to move conversations off of WhatsApp, to Signal - again, maybe for the disappearing messages(and lack of a report function which would send part of a convo to FB/Meta to my understanding)- but possibly, for the security and lack of meta data being better from a attack surface standpoint</p>
]]></description><pubDate>Mon, 24 Mar 2025 19:28:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=43464565</link><dc:creator>LWIRVoltage</dc:creator><comments>https://news.ycombinator.com/item?id=43464565</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43464565</guid></item><item><title><![CDATA[New comment by LWIRVoltage in "Briar: Peer to Peer Encrypted Messaging"]]></title><description><![CDATA[
<p>It worked well! Most messages did go through! The caveat- I don't think anyone was also using Bluetooth headphones<p>500 feet outside was the test i did with a clear sightline- the inside of the plane was not quite as far, but the messages did go through - and we couldn't have passed the phone around when one family member was 5 seats behind me, the next was about 20 rows in front of me</p>
]]></description><pubDate>Sat, 15 Mar 2025 00:03:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=43368611</link><dc:creator>LWIRVoltage</dc:creator><comments>https://news.ycombinator.com/item?id=43368611</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43368611</guid></item><item><title><![CDATA[New comment by LWIRVoltage in "Briar: Peer to Peer Encrypted Messaging"]]></title><description><![CDATA[
<p>I recently took a flight with family- on a budget airline that did not have Wifi, so we could not hop on WiFi and message each other using Signal. I wondered what other options there would be in the air- and remembered Bluetooth Communication apps- and had everyone install Briar- it came in haandy!<p>I like the built in Bridge option as well, (when the app communicates over the internet) to help avoid revealing the traffic is Tor traffic.<p>I have been impressed by the range of Briar- with a clear line of site, easily hundreds and hundreds of feet- i tested it to well over 500 outside- and on the plane , my family was scattered, but that was no issue at all. (More recently though i've detected my own Bluetooth MotoTag trackers from my luggage in Cargo holds while on planes, so Bluetooth indeed works well on planes.)<p>-I have heard of but have never used BridgeFy, which I know was a well known famous Bluetooth app that competed with Briar in the past. To my understanding it isn't quite as secure or open source.<p>There is a informative post here
<a href="https://old.reddit.com/r/Briar/comments/gxiffy/what_exactly_are_the_capabilities_and/" rel="nofollow">https://old.reddit.com/r/Briar/comments/gxiffy/what_exactly_...</a>
where a developer noted Briar's capabilities at that time- it seems due to some changes on the OS/phone Hardware end, and whatnot- and due to the phones only passing messages to contact nearby - Briar is not a true mesh networking app. It is a shame- i feel a true Bluetooth mesh networking app would be unstoppable in availability -though it might be a bit of a battery drain.<p>It is a shame Briar isn't on iOS also -<p>I also wish Signal would eventually consider communicating over any medium accessible- they would probably run into similar issue Briar has.<p>What will it take to get a Peer-to-Peer capable Bluetooth/Wifi/Celluar network using/(more possibly in the future)- proper optional mesh networking, Tor capable, VPN friendly, wholly end to end encrypted ,perfect forward secrecy including,  fully open source App  providing messaging (with the 'accounts' that Briar uses?), for Android and ios?(And Let's throw in PC Mac and Linux, so laptops could have a extremely user friendly user accessible way of doing this as well.)<p>Better yet, add Calling capability- i don't know how rough doing video calls would be over some methods like modern day Bluetooth- but even a rough capability would be used a little and be worth adding to the collection of things one could do(Briar is only Messaging at the time of this post- which is something notable for sure,as very few apps let you transmit solely thru Bluetooth<I have not heavily looked into the shared Wifi communication abilities of Briar at this point in time> - but more could be added in some form...I observe apps do exist that allow for Bluetooth calling or act like "Bluetooth" Walkie Talkies)</p>
]]></description><pubDate>Fri, 14 Mar 2025 18:52:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=43365922</link><dc:creator>LWIRVoltage</dc:creator><comments>https://news.ycombinator.com/item?id=43365922</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43365922</guid></item></channel></rss>