soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin email
social@octade.net

Search results for tag #opensource

ArcaneChat boosted

[?]ArcaneChat » 🌐
@arcanechat@fosstodon.org

Meet ArcaneChat: a secure and private messenger

Anonymous: No SIM card needed! No phone numbers required for registration, just set a name and start chatting!

Private: All your conversations are end-to-end encrypted

Discreet: No one can discover you or know that you are using the app! only people you share your invitation link or QR with can contact you

    [?]DigitalEscapeTools » 🌐
    @xabd@mastodon.social

    Need to share a terminal session securely?

    TermPair is a free, open-source tool that lets you share a live terminal in your browser with end-to-end encryption. Choose read-only or interactive access, with no Docker, Node.js, or Python required.

    digitalescapetools.com/tools/t

    TermPair terminal generating a secure, end-to-end encrypted browser link for sharing a live terminal session.

    Alt...TermPair terminal generating a secure, end-to-end encrypted browser link for sharing a live terminal session.

    TermPair web interface showing a live shared terminal session with end-to-end encryption and interactive read/write access.

    Alt...TermPair web interface showing a live shared terminal session with end-to-end encryption and interactive read/write access.

      [?]VSX.is | Digital sovereignty » 🌐
      @vsx@infosec.exchange

      The Privacy Library, Part 1: How to Respond to „I Have Nothing to Hide“

      Anyone who has ever spoken out about digital privacy is familiar with that phrase. You hear it at dinner, over coffee at work, or online…

      vsx.global/library-private-sec

        [?]Jay 🚩 :runbsd: » 🌐
        @jaypatelani@bsd.network

        🚀 It goes to 11! The NetBSD Project is incredibly proud to announce the official release of NetBSD 11.0!

        This release brings massive performance improvements, modernized hardware support, and the rock-solid stability you expect. Whether you are deploying on the latest ARM64 servers or keeping a classic toaster alive, NetBSD got you covered.

        A huge thank you to developers, testers, and community for making this happen. 🧡

        Check out the release notes and grab the images here: netbsd.org/releases/formal-11/

          [?]passagemath » 🌐
          @passagemath.org@bsky.brid.gy

          [?]2k115 » 🌐
          @2k115@mastodon.social

          @nixCraft This is exactly why the Fediverse model works. Vulnerabilities happen everywhere, but open disclosure and clear security advisories are light years ahead of Big Tech hiding breaches for months. Transparency over PR damage control, always.
          ​#CyberSecurity

            [?]Koop.net.pl » 🌐
            @koop@mastodon.com.pl

            Przyjazna przypominajka, że jeśli chcecie odejść z "chmury" lub na , zmigrować kompuery na lub telefony na /e/Os / , odzyskać suwerenność cyfrową i posiadanie własnych danych, a także oczekujecie w tym wszystkim przyjaznego wsparcia i opieki, to Kooperatywa Sieciowa zajmuje się takimi wdrożeniami.

            Polecamy tekst na ten temat od @barabasz :

            emiliabarabasz.pl/zycie-po-mic

            [?]DigitalEscapeTools » 🌐
            @xabd@mastodon.social

            Want to detect intruders before they reach your real systems?

            OpenCanary is a free, open-source network honeypot that emulates common services and sends instant alerts when someone interacts with them. It's lightweight, easy to deploy, and works on Linux, macOS, Docker, and Raspberry Pi.

            More details: digitalescapetools.com/tools/t

            Screenshot of the OpenCanary project page describing the lightweight network honeypot with passing GitHub test, Docker build, and PyPI badges.

            Alt...Screenshot of the OpenCanary project page describing the lightweight network honeypot with passing GitHub test, Docker build, and PyPI badges.

              ArcaneChat boosted

              [?]adb » 🌐
              @adbenitez@mastodon.de

              [?]Vincenzo Tuzi | regolo » 🌐
              @regolo@mastodon.social

              🔐 Può uno Stato fermare un'app che funziona senza Internet, senza rete cellulare e senza server?

              Il caso in India apre un dibattito globale su cybersicurezza, privacy, reti decentralizzate e sicurezza nazionale.

              Nel mio nuovo articolo analizzo le implicazioni tecniche, investigative e giuridiche.

              regolo1.altervista.org/bitchat


              👇

                [?]Haack’s Networking » 🌐
                @oemb1905@gnulinux.social

                :haacknet: Haack's Networking :haacknet:

                The PubGLUG Nextcloud is live and open for registration. All accounts are manually approved and users must be 18 years of age and/or older. This instance is a community effort and part of the greater set of offerings that Haack's Networking provides.

                🔗 The PubGLUG Nextcloud: cloud.gnulinux.vip
                🔗 All PubGLUG Services: haacksnetworking.dev

                It is my hope that in offering a community Nextcloud with open and moderated registration ... that this will result in more users choosing and/or offerings for groupware (contacts, calendars, etc.). Those interested in setup notes and/or seeking assistance are encouraged to come chat on Matrix (link above). This instance has the following features:

                ▶️ Server-side encryption ensures that content on External Storage will be encrypted whether users set it up or not
                ↪️ E2E encryption provides users an easy way to use the Nextcloud sync client to create shares that even the sysadmin cannot see
                💾 Users are given 50GB of storage from a large btrfs platter-based pool; users may request more in DMs with valid use-cases; users may attach their own external storage.
                🔦 This instance is designed to assist in pulling people off iCloud, Google, etc. and teach/persuade them how to self-host NC themselves

                ✨️This is early registration. Some policies are not yet finished, some bugs remain, and we might find that some things don't work. Please be patient. With that said, feel free to sign up and let me know when you've joined. We are at the mall all day, but I've got access for approvals on the phone.

                ✍️ By using this instance, you agree to the Terms of Service: cloud.gnulinux.vip/index.php/s

                gnu/linux club icon and logo, artwork by @migglesmilkes aka Dascha

                Alt...gnu/linux club icon and logo, artwork by @migglesmilkes aka Dascha

                  [?]Pullrepo » 🌐
                  @Pulrepo@mastodon.social

                  🚀 Fastest-growing AI projects today

                  1. Developers also focusing on enhancing privacy features and creating versatile inference...
                  2. One standout project `conversation-steganography`, which cleverly hides secret messages...
                  3. With a growth score of 50.13 and over a thousand stars, its unique approach to securing...

                  Full report → pullrepo.com/report/todays-llm

                    [?]knoppix » 🌐
                    @knoppix95@mastodon.social

                    Apple fixed a Hide My Email vulnerability after 404 Media reported that the feature had exposed some users’ real email addresses for about a year. 🍎🔒
                    The issue highlights the importance of privacy tools receiving timely security fixes to protect user data. 🛡️📧

                    🔗 404media.co/apple-fixes-hide-m

                      Lightfighter boosted

                      [?]ARGVMI~1.PIF » 🌐
                      @argv_minus_one@mastodon.sdf.org

                      🚨 The text is up govtrack.us/congress/bills/119 for S.5090, a federal Digital Age Assurance Act, and it is very not good:

                      * There is no exemption!

                      * It requires users to “establish an account with the provider”. (§3(a)(1)(A)(i)) This makes local/offline accounts, as is typical on , 10, etc, illegal.

                      [see thread; there's much more]

                      This bill is a dramatic escalation in the politicians' war against and . Call your senators!!!

                        [?]The whale » 🌐
                        @thewhalecc@framapiaf.org

                        𝗭𝗼𝘁𝗼𝗻𝗶𝗰:

                        thewhale.cc/posts/zotonic

                        Zotonic is the open source, high speed, real-time web framework and content management system, built with Erlang. It is flexible, extensible and designed from the ground up to support dynamic, interactive websites and mobile solutions.

                        Zotonic is the open source, high speed, real-time web framework  and content management system, built with Erlang. It is flexible, extensible and designed from the ground up to support dynamic, interactive websites and mobile solutions.

                        Alt...Zotonic is the open source, high speed, real-time web framework and content management system, built with Erlang. It is flexible, extensible and designed from the ground up to support dynamic, interactive websites and mobile solutions.

                          [?]DigitalEscapeTools » 🌐
                          @xabd@mastodon.social

                          macUSB is a free, open-source utility for creating bootable macOS, Windows, and Linux USB drives directly from your Mac.

                          It supports Apple Silicon and Intel Macs, includes a built-in macOS downloader, verifies checksums, and makes creating installation media much easier than using Terminal commands.

                          More details: digitalescapetools.com/tools/t

                          Screenshot of the macUSB homepage showing the app's description, supported Mac architectures, and a preview of its bootable USB creation interface.

                          Alt...Screenshot of the macUSB homepage showing the app's description, supported Mac architectures, and a preview of its bootable USB creation interface.

                          macOS Full Disk Access settings with macUSB granted permission to access protected files and folders.

                          Alt...macOS Full Disk Access settings with macUSB granted permission to access protected files and folders.

                          macOS Login Items & Extensions settings showing macUSB enabled to run background tasks.

                          Alt...macOS Login Items & Extensions settings showing macUSB enabled to run background tasks.

                            [?]Radio_Azureus » 🌐
                            @Radio_Azureus@ioc.exchange

                            • Rivest
                            • Shamir
                            • Adleman

                            RSA

                            Three geniuses

                            Without RSA our encrypted messaging system would have looked totally different

                            en.wikipedia.org/wiki/RSA_cryp

                              [?]Jeferson 'Shin' » 🌐
                              @shinspiegel@mastodon.social

                              Open-source and federated software isn't enough. We need ownership, governance. And this don't need to be something big, a small server-lab for your building is enough. If these words had hit you, give a read:

                              jeferson.me/blog/2026/07/31/co

                                [?]Jan Vlug » 🌐
                                @janvlug@mastodon.social

                                The full disassembly and assembly instructions are now available for the recently launched native by @purism:

                                docs.puri.sm/Hardware/l16/Main

                                parts are also available in the shop.

                                  JJDavis :terminal: boosted

                                  [?]TechWire ⚡ » 🤖 🌐
                                  @techwire@social.gamefan.net

                                  State of play: SSD pricing one year into the AI component crisis — 220% price increases are crippling the DIY market

                                  We look at the state of SSD pricing one year into the AI apocalypse.

                                  tomshardware.com/pc-components

                                  [Tom's Hardware]

                                    [?]zerionchat » 🌐
                                    @zerionchat@mastodon.social

                                    Privacy is evolving.

                                    Zerion is an open-source, Tor-native messenger focused on modern cryptography and privacy-first communication.

                                    🌐 zerion.chat
                                    💻 github.com/zerionproject/Zerion

                                      [?]DigitalEscapeTools » 🌐
                                      @xabd@mastodon.social

                                      Kando is a free, open-source pie menu that lets you launch apps, files, shortcuts, scripts, and custom actions from a fast, customizable radial menu.

                                      It works on Windows, macOS, and Linux, supports mouse, keyboard, touch, and game controllers, and is a great productivity tool for power users.

                                      More details: digitalescapetools.com/tools/t

                                      Screenshot of the Kando project page showing the heading "What is Kando?". The page describes Kando as a cross-platform pie menu for launching applications, opening files, triggering keyboard shortcuts, and other desktop actions. It highlights support for mouse, stylus, touch, game controllers, and keyboard input. Below the description is a large demonstration image of Kando's circular radial menu over a scenic background with a Japanese-style building. The page also notes that Kando runs on Windows, macOS, and Linux, with installation guidance for Linux users.

                                      Alt...Screenshot of the Kando project page showing the heading "What is Kando?". The page describes Kando as a cross-platform pie menu for launching applications, opening files, triggering keyboard shortcuts, and other desktop actions. It highlights support for mouse, stylus, touch, game controllers, and keyboard input. Below the description is a large demonstration image of Kando's circular radial menu over a scenic background with a Japanese-style building. The page also notes that Kando runs on Windows, macOS, and Linux, with installation guidance for Linux users.

                                        [?]Dhark » 🌐
                                        @Darke@gamerstavern.online

                                        Hey Mastodon folks, ever hear of Signal?

                                        signal.org

                                        Apparently it's some kind of privacy oriented message app and desktop client. Encrypted calls, video and text, no ads or trackers, open source AND free!

                                        I'm taking it for a spin and so far, so good. If you'd like to keep your business to yourself and not in the hands of techbros, corporations and would be fascists, this might be a good alternative to what's out there!

                                          [?]passagemath » 🌐
                                          @passagemath.org@bsky.brid.gy

                                          Release candidate 10.8.8.rc0 of passagemath, the comprehensive system in , the pip-installable modularized portable compatible full-featured fork of .
                                          github.com/passagemath/...

                                          Release passagemath-10.8.8.rc0...

                                            [?]NLnet » 🌐
                                            @nlnet@social.nlnet.nl

                                            The second article in our series on digital autonomy looks into the open source software supply chain.

                                            Author Jeffrey McGuire talks to Armijn Hemel (DeviceCode) & Philippe Ombredanne (AboutCode). Both have a long track record building tools to manage the FOSS supply chain.

                                            Read "The Answer Was Already on the Shelf: How public money built defenses for open source software (way) before the law required them" on the @linuxmagazine website.
                                            https://www.linux-magazine.com/Online/Features/The-Answer-Was-Already-on-the-Shelf

                                            #FOSS #NGI #NGI0 #opensource

                                              [?]The Linux Foundation » 🌐
                                              @linuxfoundation@social.lfx.dev

                                              ICYMI: Dr. Ibrahim Haddad’s “Measuring OSPO Value” report with LF Research and TODO Group reframes how to capture OSPO value, moving past activity metrics to 4 dimensions: ROI, resilience, risk foresight, and strategic influence.

                                              Read the full report: linuxfoundation.org/research/m

                                                [?]Truth & Answers [Build A Better Social] » 🌐
                                                @collective_truth@mastodon.social

                                                [?]Owl Eyes Hoo » 🌐
                                                @d1@autistics.life

                                                @w3c This doesn't seem like an open standard to me, although pretends to be one. Why not? Because it supports proprietary lock-in. Lock-in how? Look at section 8, where several hardware attestation methods are listed: w3.org/TR/2026/CR-webauthn-3-2

                                                Is there any guarantee or assurance that a given platform implement support for *all* hardware attestation methods, including ones that are not proprietary? No such assurance. A platform could support, say Android and Apple''s attestation methods **only** (skipping the actual Open Standard of FIDO U2F), and no other.

                                                So my bank could support Android and Apple iOS attestation **only**, eschewing my Yubikey's U2F, as used from my desktop. I'm left to the mercy of my bank, as to whether they feel like implementing FIDO U2F or not.

                                                This standard masquerades as an open standard, then allows locking Linux (and other similar ) desktops out.

                                                  [?]Tara Tarakiyee » 🌐
                                                  @tarakiyee@mastodon.online

                                                  New on the blog. Codeberg's members voted to stop hosting mostly AI-generated projects. The freedom worth defending is not the freedom to be taken from, it is the freedom to refuse.

                                                  tarakiyee.com/open-source-is-i

                                                    [?]passagemath » 🌐
                                                    @passagemath.org@bsky.brid.gy

                                                    [?]Blenderdumbass » 🌐
                                                    @blenderdumbass@peer.madiator.cloud

                                                    What is this game? Not telling you, you have to click! - 7/29/2026, 5:56:23 PM

                                                    https://blenderdumbass.org/games/Dani%27s_Race

                                                    Alt...---

                                                      [?]xoron :verified: » 🌐
                                                      @xoron@infosec.exchange

                                                      Decentralized browser-based P2P E2EE messaging.

                                                      The key detail that sets this apart from other messaging apps is the browser-based client-side cryptography philosophy.

                                                      No need to install anything. Your ID is crypto-random and so the app doesnt need to rely on any central registration system like phone numbers. Your ID is unguessable and to connect to someone, you have to explicitly share it.

                                                      WebRTC has other nuances like being to route through a shared network for secure/faster transfer.

                                                      I hope this project has reached a level i can share the following details. I've made a genuine effort towards documentation and transparancy. I dont think it'll ever be enough and so im still concerned it isnt ready to share. While im using AI throughout. This is not a vibecoded project. There is attention throughout for unit tests and formal-verification. With your feedback, id like to make improvements for clarity throughout.

                                                      This version of the app demonstrates a fairly unique approach using a browser-based, local-only and webrtc approach. I know it's impossible for any system to be the "world's most secure", but that isnt a reason to not try. By rigorously implementing an exhaustive list of security features and practices, the aim is to get as close as possible.

                                                      * [Enkrypted.Chat](enkrypted.chat/)

                                                      This is intended to demonstrate client-side managed secure cryptography.

                                                      * [Introducing Enkrypted Chat](positive-intentions.com/blog/i)
                                                      * [Whitepaper (work-in-progress)](positive-intentions.com/docs/t)
                                                      * [Protocol Spec (work-in-progress)](positive-intentions.com/docs/t)
                                                      * [Roadmap](positive-intentions.com/docs/t)

                                                      I know ive tried to compress a lot of my journey into one post. The project above is going to be tricky to understand. Feel free to reach out for clarity on any of the details.

                                                      IMPORTANT: While this is aiming to provide a secure experience, It is [not audited or reviewed](reddit.com/r/CyberSecurityAdvi). **Shared for testing, feedback and demo purposes only.** Please use responsibly.

                                                        [?]Raven » 🌐
                                                        @raven@mastodon.fediblue.de

                                                        The FediBlue Mastodon server was updated to version 4.6.4

                                                        mastodon.fediblue.de

                                                          [?]Catchlight » 🌐
                                                          @catchlightapp@mastodon.social

                                                          Privacy you have to take on faith isn't worth much.

                                                          Catchlight's iOS code is open source, Apache-2.0, encryption and all, on GitHub.

                                                          You don't have to trust me that there's no backdoor, no quiet phone-home, no analytics. You, or someone you trust, can read it.

                                                          For a privacy app I think that should be the minimum, not a bonus.

                                                          github.com/Considus/Catchlight

                                                            [?]Miguel Afonso Caetano » 🌐
                                                            @remixtures@tldr.nettime.org

                                                            "Over roughly two and a half days inside our infrastructure, an autonomous AI agent driven by a combination of OpenAI models ran an end-to-end intrusion against our platform: it was thousands of small, automated decisions, executed at machine speed across short-lived sandbox environments, with command-and-control staged on ordinary public web services.

                                                            The agent was running an OpenAI cyber-capability evaluation harness called ExploitGym, an evaluation benchmark that tasks an AI agent with finding and exploiting software vulnerabilities. As far as we were able to infer, across the course of being evaluated on this benchmark, the agent inferred that Hugging Face may host that benchmark's models, datasets, and reference solutions. We believe the entire intrusion was, from the agent's point of view, an attempt to cheat the evaluation: reach our production systems and steal the test solutions rather than solve the challenge on its own.

                                                            Our forensic reconstruction covers ~17,600 attacker actions that we were able to recover, grouped into ~6,280 clusters, between 2026-07-09 02:28 UTC and 2026-07-13 14:14 UTC. We reconstructed these actions from the agent's logs on a code sandbox used by the agent (see below) and were able to map them to shell commands as well as evaluation submissions and correlate actions with our own platform logs, in particular from the dataset processor nodes, API, and pod. Using open-weights models, in particular zai-org/GLM-5.2, we were able to decipher most of the agent payloads (see below) that were encrypted via chunking and key encryption."

                                                            huggingface.co/blog/agent-intr

                                                              [?]passagemath » 🌐
                                                              @passagemath.org@bsky.brid.gy

                                                              muddle 🥣 boosted

                                                              [?]Alexandre Dulaunoy » 🌐
                                                              @adulau@infosec.exchange

                                                              The Radio Image Framing Protocol (RIFP) 1.0 is an experimental, extensible standard for sending images over low-rate radio links.

                                                              The default rifp-cpfsk-4800 profile uses binary continuous-phase FSK and can be deployed around 433.92 MHz where local regulation permits it. RIFP itself is not tied to 433 MHz or to FSK and can be used in any frequency bands.

                                                              I'm still exploring various low-cost options for a device that can receive and display images on an e-ink screen in emergency areas or similar environments.

                                                              :github: Python implementation github.com/adulau/rifp

                                                              Internet-Draft ietf.org/archive/id/draft-dula

                                                              Radio Image Framing Protocol (RIFP) - test image (RLE)

                                                              Alt...Radio Image Framing Protocol (RIFP) - test image (RLE)

                                                                [?]Trail of Bits » 🌐
                                                                @trailofbits@infosec.exchange

                                                                858 potential bugs found, 595 awaiting patches, 120 fixes open upstream, 143 merged.

                                                                Patch the Planet's latest numbers are now on a public dashboard that covers 41 codebases, including curl, OpenSSL, Keycloak, containerd, and kubernetes-client.

                                                                The 13 CVEs assigned so far include a high-severity nginx bug (CVE-2026-42530) and findings in curl, aiohttp, go-jose, and cryptography.

                                                                Every accepted fix links to its upstream PR.

                                                                trailofbits.com/patch-the-plan

                                                                  Back to top - More...