Egregoros

Signal feed

Paco (2026: New) Hope

@paco@infosec.exchange

Amateur professional #selfhost sysadmin. Professional amateur #cloud #security at #AWS. Also fond of #cats, #cigars, #whiskey and #pipes. I like board games and some video games. I am #covid cautious and I still #wearamask. Opinions are my own, but they can be yours too. 100% Organic:,No artificial colors, preservatives, or intelligence added.

Posts

Latest notes

[CW]

Content warning

re: long tech rant (disney, hulu, amazon)

Show

@ava When older folks, like parents, complain that all technology sucks, I just solemnly nod.

I feel your pain. I've done stuff like this for my parents and in-laws. It always leaves me scratching my head: "They think normal people can understand all this shit?"

@evacide#Microsoft says it will provide encryption keys for Windows PC data protected by BitLocker where it has access to them and it's received a valid warrant.”

The word “valid” sure is doing a lot of work there. This is the most corrupt DoJ and FBI in generations. One that ignores court rulings that it disagrees with. So what way is the warrant “valid”? Syntactically? Grammatically? Because if we get any deeper, like morally or ethically, the argument gets harder to make.

This silly statement from #openai about #security drives me crazy. People talk about this all the time as if it means something.

‘files in ChatGPT as a whole are "encrypted by default at rest and in transit"’

What attack does that encryption at rest defeat? What hacker says “darn it! I would have gotten the data if it hadn’t been for that pesky encryption at rest?”

Think it over. Go ahead. I’ll wait.

Physical theft of hard drives/storage. That’s it. Encryption at rest at OpenAI, or any cloud, defeats the same singular attack that it defeats when you encrypt the hard drive on your laptop: if someone physically steals the device, they don’t get the data.

They can sell your data. They can store it (encrypted at rest) on a web site that has a vulnerability or incorrect security, and bad people can download the unencrypted data. They can share it with “partners” who misuse it. Encrypting at rest is NOT an important protection. Literally every other protection is more important.

https://www.darkreading.com/remote-workforce/chatgpt-health-security-safety-concerns