Ignore the downvotes. That's a fair question to ask, but one that does have answers. Signal is FOSS, has E2EE and was audited several times, so we know that
it did not contain any backdoors at the time of the audit
it will not for the foreseeable future (they'd be visible in the client code)
I need not trust the server code since messages are E2EE
Thus, while mistakes do happen and can open up severe vulnerabilities, cf. Heartbleed, there's reason to assume that Signal is relatively secure. Signal's centralisation of server infrastructure is a valid concern, but not for security, but rather for
privacy (they might capture metadata, although it appears they don't; nation-state actors trying to subpoena user data have so far only gotten "date of registration" and "last online", which appears to be all they're storing; that's as close to "zero knowledge" as you get)
availability (as the recent AWS outage has shown, which took out Signal as well)
Follow-up: I added the Guardian project repo to FDroid. Turn out: once FDroid has the repo, it can "take over" and do updates, even if Signal was originally installed from the Play Store / Aurora. That pretty much solved my primary issue here. (I'll look into Molly at a later point anyway, just for the sake of curiosity.)
Now that's a smart solution that might just work for me. I completely forgot that they were packaging Signal for their repos too! For anyone interested: Here's the link to their repo.
I've got a second deployment of immich that also got stuck somewhere on v1.x. May I ask how you upgraded to the most recent version? Did you just go for 3.0, or did you do "baby steps" in between? (e.g. 1.138 > 2.0 > 3.0)
I'll reply to you since you first brought it up, but it's a question to anyone here recommending Molly: what makes you cofident that Molly is secure (i.e. they're not fucking up Signal's cryptography by accident) and maintained by trustworthy people. Signal does get audits from time to time, Molly doesn't.
Mind you, I'm not trying to shit all over Molly; Unified Push looks great. I'm trying to approach this with due caution though.
Obnoxious Windows 10 "upgrade" nag screens on Win 7. If you think you can push me, I'll push back harder. That, and Snowden showing the world that American tech is backdoored all the way to hell and back.
There are no issues with DKB on degoogled Android.Commerzbank have recently started claiming non-Google phones were "rooted" (which is bullshit) and refuse app-to-app pushTAN communication. One must work around that using a (PC-based) browser and photoTAN. Motherfuckers.
I do still read the changelogs and compare compose files thoroughly on every major update. With that in place, Immich has not once broken down on me, and I've been here from almost the very start.
Aurora is all I use. We're still trusting Google not to inject anything malicious into the app, which they'll do in a heartbeat if the feds come knocking.
I've been a great fan of the project and used it as my daily driver for >5 years. It was stable as heck and the devs were super responsive, even adding in neat features at users' request.
That said, I've lost trust in the project and moved on to GrapheneOS. The departures of Chirayu Desai and Nick Merrill smell weird from miles away. The latter left without any words of farewell explaining why he'd abandon his own project from one day to the other. I won't engage in speculation as to what happened behind the scenes, but there are enough red flags here to keep my distance.
Man, your basement has the weirdest carpet I've ever seen. Also, much too bright for my taste. If you can see the keycaps without backlight, you're doing the lighting wrong.
unless you rip the movie out into a single file first
I don't see the problem with that. It's what I've done with every single disk I own. Why would I bother with badly-written menus, pointless extra content and tons of ads and copyright warnings I need to sit through before I can watch what I paid for?
You patched the annoying "crash-on-start" bug! 😍 I was collecting diagnostics to help nail it down, but you guys were faster. Keep up the great work! 👍👍👍
Qwant is nice, but it keeps blocking my VPN and locks me out if I happen to use a non-European exit node ("We're not offering Qwant in your region"). And I'm not pulling down my mask for a fucking search engine.
Thank you! While that does allay most security concerns, it does beg the question how useful such a vulnerability tracker is if it doesn't actually show any relevant vulnerabilies and you constantly have to second-guess what it says. Warning signs that aren't actually warnings because it's "just a false alarm" quickly teach personell to not take warnings seriously - unti, onel day, it's not a false alarm...
To make that happen, the attacker must [...] already have access to the server to upload and process the file, which means that security has already failed.
Do I correctly assume that by axis you mean shell or even root level access? If not, any of my regular users (turned rogue...) could upload a poisoned raw file which nextcloud would process to, for instance, generate a thumbnail.
Ignore the downvotes. That's a fair question to ask, but one that does have answers. Signal is FOSS, has E2EE and was audited several times, so we know that
Thus, while mistakes do happen and can open up severe vulnerabilities, cf. Heartbleed, there's reason to assume that Signal is relatively secure. Signal's centralisation of server infrastructure is a valid concern, but not for security, but rather for