pending anonymous user

  • 13 Posts
  • 216 Comments
Joined 1 year ago
cake
Cake day: August 7th, 2023

help-circle






  • umami_wasabi@lemmy.mltoSelfhosted@lemmy.worldPaid SSL vs Letsencrypt
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    5
    ·
    edit-2
    7 days ago

    I didn’t say it isn’t legit nor I distrust automation, but I would like to see anyone operating an online shop paid for a cert to show they are honest and won’t diappear in thin air not delivering. Am I going to get back what I paid, properly not, but a basic DV cert isn’t expensive either for a business.



  • umami_wasabi@lemmy.mltoSelfhosted@lemmy.worldPaid SSL vs Letsencrypt
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    16
    ·
    edit-2
    7 days ago

    Personally, I distrust any ecommerce site that uses any free cert. I see paid cert as a commitment to do honest business, as they need to have some records on the CA.

    But for a blog or anythings other than ecommerce is totally fine by me.

    Note: It is not about security, nor automation, but a show commitment (i.e. buying a cert), largely psycological.








  • That scanner is simply looking for high entropy data, and then report to its operator. It wouldn’t care if it is a drive or a volume or a file. If the entropy is high, flag it.

    All random data have high entropy, same for encrypted data. The officer can see you have high entropy data then start throwing questions at you.

    This community need better understanding of cryptography and how it translates to real world. Deniable encryption exists and does work on paper, but only on paper.





  • The point is they don’t have to proof if a piece of random data is indeed an encrypted blob.

    Imagine you passing border security and got selected for search. They found a piece of data on your device with high entropy without known headers in the wrong place. You can claim you know nothing about it, yet they can speculate the heck out of you. In more civil nations, you might got on to a watch list. In a more authoritive nations, they can just detain you.

    They don’t have to prove you hiding something. The mere fact of you have that piece of high entroy data is a clue to them, and they have the power to make your life hard. Oh you said you deny them for a search? First congrats you still have a choice, and secondly that’s also a clue to them.

    For more info, read cryptsetup FAQ section 5.2 paragraph 3, 5.18, and 5.21. It is written by Milan Brož who is way more experienced than me on this matter.