noc.social is part of the decentralized social network powered by Mastodon.
This instance is focused on technology, networking, linux, privacy, security, infosec, engineering, but open to anyone. Civil discourse, polite and open. Managed by the noc.org / trunc.org team.

Administered by:

Server stats:

677
active users

Learn more

I think #Microsoft have given themselves enough rope with #Recall. For Reasons, running anything like it would be flat out, no discussion, illegal in my org. As #CISO I’m sensitive to such things… :)

Sure we run a MSFT shop, and sure they theoretically have access to all that data anyhow - can’t [viably yet] process ciphertext, they see all the cleartext at some point.

The rope part is that argument. If MSFT argues that they see all data *anyway* so why not Recall, they burst our collective hallucination that various #GDPR agreements are actually worth a damn [Narrator: They’re not].

And then, my #infosec friends, I get to eject Microsoft - and coincidentally all other #US #cloud services as well as collateral damage - and finally build a full scale Linux/FOSS environment.

It’ll be more fun than I can #recall!

Find daily new #GDPR decisions from across Europe for free on GDPRhub.eu!➡️ Read and edit this decision from Spain at gdprhub.eu/index.php?title=AEP 📥Thousands of experts also signed up to our free newsletter already: newsletter.noyb.eu/pf/433/5gqtL #DSGVO

ALT: New decision from Spain: An employer was fined €120,000 for failing to protect the identity of the complainants and the accused in a workplace harassment complaint in violation of Article 5(1)(f) GDPR.

#discord IS LITERALLY THE PROBLEM!

It's worse than any #IRC, #Mumble or even the old #TeamSpeak & #Skype for that matter.
It combines the disadvantages of #Forum, #paywalled #documentation, #chat and #voicechat with 0 redeeming qualities (unlike #Zulip & Mumble & #XMPP+#OMEMO) it's just an #InformationBlackhole!

I'm shure fecking #dread has better moderation and I'd rather use #MicrosoftTeams + #Slack cuz those at least have proper #moderation tools.

And I'd rather subscribe to the #LKML and see my inbox getting hosed than using any shitty #SaaS!

Case in point: I'd rather #SelfHost all my comms infrastructure than to ever use something like Discord or any other #GDPR-violating SaaS that is just enshittification.

I'd rather recommend people to instead choose a tool that does everything but horrible to go with multiple smaller & good tools

Public Chat? IRC!
Group Voicechat? Mumble.
#Documentation? #mkDocs-material.
1:1 Chats? XMPP+OMEMO.
E2EE Group Chats? #deltaChat.
E2EE Calls? #WebCall.
Filehosting? #IPFS, #BitTorrent, oshi.at, etc. ...

Check @alternativeto and @european_alternatives for options.

Je comprends @aeris et pense qu'il est inutile que l'UE assouplisse le RGPD, vu comment ça se passe déjà :

* Une société me démarche par e-mail
* Je leur demande quelles sont les info qu'ils ont sur moi
* Il me répondent qu'ils n'en n'ont aucune
* Je leur réponds que quelqu'un de chez eux m'a envoyé un e-mail
* Ils reconnaissent et suppriment mes données (ce que je n'avais pas demandé)
* Je leur re-demande d'où viennent ces données et avec qui les ont-ils partagées
* Ils me disent les obtenir de Cognism et que je peux voir avec eux pour faire valoir mes droits 😩

Cognism ne serait pas très fiable : olssonm.medium.com/cognism-the

#rgpd #gdpr

Cognism — the premium supplier of spam and fake dataMedium

The #cat has a microchip registered with #Identibase. After moving home I tried to update my address on Identibase, but they said that I needed to pay an annual subscription fee to do so...

My address is my personal data, and therefore comes under the #UKGDPR, so I submitted a Article 16 "right to rectification" request asking them to update the out of date personal data. Per Article 12(5) they have to do this for free.

And it worked! Identibase have updated my address for free.

#GDPR

@marczz

Why you should use full-disk encryption

If any of the arguments I make below apply to you, you should use full-disk encryption. I am pretty sure the first argument applies to everyone. The second argument applies at least to everyone in the EU and the US state of California. The third argument applies to everyone again.

You will fail to delete drives properly

Storage media get lost. Most people do not know how to properly delete hard disk content before selling them, or they forget it. In the case of flash drives, or SSDs, standard tools like shred don't work. hdparm may do the trick, but this is not well known. If you are lucky, the manufacturer of you SSH provides a Windows app that lets you delete it securely. Your server does not run on Windows of course.

The law demands it

#GDPR and similar data protection and privacy laws require you to store no #PII (personal data) permanently. You have to anonymize PII or delete it after a few weeks. IP addresses are PII. All servers store IP addresses by default. The GDPR also demands that you use state-of-the-art technology to protect sensitive data. Full disk encryption is the state of the art.

Law enforcement makes "mistakes"

I'm a board member of @Artikel5eV, an organisation that runs relays on the Tor network, including exit relays. Running Tor relays is perfectly legal in Germany. Nevertheless, law enforcement agencies have raided the homes of Artikel 5 e.V. board members twice. Illegally so, as a court confirmed recently. I won't run Tor relays in my home, but there is a good chance that my home will be raided one day unless all police officers and prosecutors decide to obey the law.

There is also a possibility that the rule of law might collapse in your country sooner or later. We are just witnessing it in the USA.

You already mentioned that ordinary thieves can also be a problem.

Encryption is available for free

So what is your case against disk encryption? It is obvious that it alone does not solve all IT security issues, but it is an important building block. #LUKS is reliable free and open-source software for HD encryption. If you are not using Linux, check out #VeraCrypt. The Raspberry Pi 5 comes with hardware acceleration for AES, so there no longer is a noticeable performance penalty for encryption.

#storageEncryption #hardDiskEncryption #encryptAllTheThings

Find daily new #GDPR decisions from across Europe for free on GDPRhub.eu!➡️ Read and edit this decision from Belgium at gdprhub.eu/index.php?title=C._ 📥Thousands of experts also signed up to our free newsletter already: newsletter.noyb.eu/pf/433/5gqtL #RGPD

ALT: New decision from Belgium: A court reduced a fine against a telecom provider from €100,000 to €5,000. The fine related to the late response to a data subject’s access request.

PGO's: Agema liegt dat zij barst

Nb. een PGO is een "Persoonlijke Gezondheids Omgeving" (meer hierover in pgo.nl).

Volgens security.nl/posting/883501/Min zei minister Agema m.b.t. een failliete PGO-aanbieder:

"Je gegevens zijn van jezelf en die blijven bij de bron. Op het moment dat de app weg is, zijn de gegevens ook weg".

In security.nl/posting/883670/PGO beargumenteer ik waarom minister Agema op maar liefts drie aspecten liegt:

1) Gegevens van/over jou zijn (juridisch gezien) niet van jou. Het verkopen van "jouw" gegevens kan een "gerechtvaardigd" belang zijn van "ondernemers". Vooral van (bijna) failliete. Wie zou je daarna aan moeten klagen?

2) Met een PGO blijven jouw medische gegevens *niet* uitsluitend bij "de bron". De kans dat de PGO-aanbieder daar een kopie van op haar (cloud) servers heeft staan, schat ik in op bijna 100%.

3) De kans dat het verwijderen van een app (op jouw smartphone of tablet) ertoe leidt dat al jouw gegevens bij een (failliet gaande) PGO-aanbieder worden verwijderd, schat ik in op ca. 0%.

Trap niet in de leugens van suf-gelobbiede (en mogelijk corrupte) -en vaak het bedrijfsleven ondersteunende- politici!

#PGO #Agema #Volksverlakkerij #Meldpunt #EHDS #AVG #GDPR #AP #AutoriteitPersoonsGegevens #Privacy #Risicos #PrivacyRisicos #KNLTB #GerechtvaardigdBelang #Datalek #Phishing

Update: Account successfully deleted. Tried again after a few days and it just worked™ without errors. I'm still uncertain why this happened or why there would be a time limit in the first place.

Original post: Trying to delete my #Firefox account via accounts.firefox.com gives me this. Appeared the first time i tried, re-appeared after a 15 min. wait and still appears an hour later. Any hints would be greatly appreciated. #mozilla #gdpr #dsgvo