tails best edits

This commit is contained in:
anarsec 2023-11-14 03:19:03 +00:00
parent 11a8bd8da3
commit b3aeac2777
No known key found for this signature in database
5 changed files with 22 additions and 104 deletions

View file

@ -284,7 +284,7 @@ A company that sells spyware to governments has a product called JASMINE that is
>
>The JASMINE documentation also explains that by analysing encrypted traffic “events” for a whole country in mass interception mode JASMINE has the ability to correlate and identify the participants in encrypted group chats on messaging apps.
A similar product would not work against Cwtch, because it uses Tor by default. Without Tor, an adversary can see that you are connecting to Signal servers which is what enables this type of timing correlation attack.
A similar surveillance product would not work against Cwtch because it uses Tor by default. Without a Tor or VPN proxy, an adversary can see that you are connecting to Signal servers which is what enables this type of timing correlation attack. Although it is possible to configure Signal to use a VPN or Tor, it is opt-in so will always be a minority of users.
Signal was designed to bring encrypted communication to the masses, not for an anarchist threat model. Because it's very difficult to register for Signal anonymously, and because you must first install Signal on a phone to use it on a computer, **we recommend prioritizing Cwtch over Signal for text communication with other anarchists, and using SimpleX Chat or Signal for voice and video calls.** For the same reasons, Signal is not well-suited for anonymous public-facing projects.
@ -394,7 +394,7 @@ If a project has multiple members, all of them should be able to access the same
>**Note**
>
>PGP is used for another purpose outside of communication: verifying the integrity and authenticity of files. For this use case, see our [explanation](/posts/tails-best/#appendix-3-gpg-explanation).
>PGP is used for another purpose outside of communication: verifying the integrity and authenticity of files. For this use case, see our [explanation](/posts/tails-best/#appendix-gpg-explanation).
<br>