all 23 comments

[–]yetanotherone_sigh 7 insightful - 1 fun7 insightful - 0 fun8 insightful - 1 fun -  (1 child)

Thank you for the transparency.

[–]magnora7[S] 5 insightful - 1 fun5 insightful - 0 fun6 insightful - 1 fun -  (0 children)

No problem, happy to be of service.

[–]DffrntDrmmr 4 insightful - 3 fun4 insightful - 2 fun5 insightful - 3 fun -  (0 children)

"They" made you say that, didn't they.

[–]Spud 5 insightful - 1 fun5 insightful - 0 fun6 insightful - 1 fun -  (1 child)

I appreciate this. Thank you.

[–]magnora7[S] 3 insightful - 1 fun3 insightful - 0 fun4 insightful - 1 fun -  (0 children)

You're welcome

[–]Drewski 4 insightful - 1 fun4 insightful - 0 fun5 insightful - 1 fun -  (9 children)

Would like to see these posted with a GPG signature.

[–]magnora7[S] 3 insightful - 1 fun3 insightful - 0 fun4 insightful - 1 fun -  (8 children)

I don't think that increases authenticity or security at all imo, as they're extremely easy to fake.

[–]Drewski 2 insightful - 1 fun2 insightful - 0 fun3 insightful - 1 fun -  (7 children)

Of course you have to trust that you're getting the public key from a legitimate source initially, but after you've added a public key to your keychain AFAIK there is no known way to fake a signed message unless I'm missing something.

[–]magnora7[S] 2 insightful - 1 fun2 insightful - 0 fun3 insightful - 1 fun -  (6 children)

I guess I don't understand how's it any different from me simply posting or not posting the thing in the first place? I just don't understand the benefit I guess. The fact the magora7 account is posting the canary on saidit, is the signature. What security does a GPG signature add beyond this already-existing proof of identity?

[–]Drewski 5 insightful - 1 fun5 insightful - 0 fun6 insightful - 1 fun -  (4 children)

Right, so we're initially trusting that you are who you say you are when you share your public key. After that though, we can verify messages signed by you as being authentic (as long as you protect your private key sufficiently). If anything were to happen to Saidit, or if your account were compromised, you could verify your identity with a signed message. It would also prevent the possibility of modifying a past post or canary because of the timestamp. Also you could use it to communicate securely, in case anyone needed to send you an encrypted message. It's not foolproof, but it does provide some additional security backed by strong cryptography.

[–]magnora7[S] 2 insightful - 1 fun2 insightful - 0 fun3 insightful - 1 fun -  (3 children)

Interesting, but I feel as though if I was in a situation where my saidit account was compromised, then my key would also probably be compromised. The idea about it being useful to verify who I am if I have to change accounts is interesting. What software is required to make it work?

[–]Drewski 4 insightful - 1 fun4 insightful - 0 fun5 insightful - 1 fun -  (1 child)

If you're on linux, most distros have it built in with GnuPG. For Windows, there's Gpg4win. It can be used via the command line or the GPA front end.

[–]magnora7[S] 2 insightful - 1 fun2 insightful - 0 fun3 insightful - 1 fun -  (0 children)

Thanks, maybe I'll give it a go

[–]magnora7[S] 3 insightful - 1 fun3 insightful - 0 fun4 insightful - 1 fun -  (0 children)

Past canaries are all visible in the Saidit Canary sub here: https://saidit.net/s/SaiditCanary/

[–][deleted] 3 insightful - 1 fun3 insightful - 0 fun4 insightful - 1 fun -  (4 children)

I have a request regarding further canaries:

Could u/magnora7 divide it in several numbered points? Like this:

1- We have had 0 (zero) gag orders, National Security requests, FISA orders, injunctions, super-injunctions, publication bans, nor any free-speech prohibiting sanction against:

a) d3rr or magnora7, nor against any other contributor to saidit,

b) saidit,

c) any signed-in user of saidit, or any guest user of saidit.

2 We have not been contacted by:

a) the NSA, nor by the FBI, nor by the CIA, nor by the DOJ, nor by the FCC, nor by any other three-letter governmental. agency

etc...

Doesn't have to be exactly along those lines, but something similar making it easier to keep track.

[–]magnora7[S] 5 insightful - 1 fun5 insightful - 0 fun6 insightful - 1 fun -  (0 children)

Sure I can do that in the future

[–]thefadd 3 insightful - 2 fun3 insightful - 1 fun4 insightful - 2 fun -  (1 child)

That’s not entirely how it works. A lot of these things are illegal to disclose. So the whole canary dies.

[–]magnora7[S] 2 insightful - 1 fun2 insightful - 0 fun3 insightful - 1 fun -  (0 children)

What if we had like 5 different canaries, each for a different topic?

[–]m68k 2 insightful - 1 fun2 insightful - 0 fun3 insightful - 1 fun -  (0 children)

Note that it can't be said if any orders were made, but rather you can say that you never got any orders, which is why the past canaries are available. ;) ;) -wink- -wink-

[–]thefadd 2 insightful - 1 fun2 insightful - 0 fun3 insightful - 1 fun -  (1 child)

What about the people you have banned? Or the subs you’ve shut down?

[–]magnora7[S] 4 insightful - 1 fun4 insightful - 0 fun5 insightful - 1 fun -  (0 children)

What about them? I don't see what that has to do with the canary

[–]GothFvck 2 insightful - 1 fun2 insightful - 0 fun3 insightful - 1 fun -  (1 child)

This is good news! But how long can we expect this to stay up for? If we don't see a new one posted by X date, we should assume there's been a compromise.

[–]magnora7[S] 3 insightful - 1 fun3 insightful - 0 fun4 insightful - 1 fun -  (0 children)

Just posted a new one, thanks for the reminder