







After 8 years, I’ve decided to transition from my original GPG key and replace it with one that uses a stronger master key that meets NIST guidelines. Over 8 years ago–probably while lounging in my tiny dorm room in engineering school–I decided that I wanted the ability to communicate with my friends & family privately. I decided that I wanted the ability to encrypt my emails. I decided to generate a gpg key. In 2009–4 years before Edward Snowden unveiled that the US government was violating their own constitution by collecting & storing the internet activity of hundreds of millions of innocent US citizens–I generated & published my first gpg keypair. Since those teenage years, I graduated college with degrees in Computer Science and Secure Computing & Networking, worked for major tech firms, and begun working for the best independent journalism outlet in the US–Democracy Now! Though my colleagues, friends, & family infrequently used my gpg key in the past (don’t tell the NSA!), I finally work with a great team of people that take security seriously, and I’m using gpg to sign & encrypt my daily work emails. Unfortunately, my original master key was generated using gpg’s defaults . . . → Read More: GPG Key Transition Statement
Permanent record
"In 2013, twenty-nine-year-old Edward Snowden shocked the world when he broke with the American intelligence establishment and revealed that the United States government was secretly pursuing the means to collect every single phone call, text message, and email. The result would be an unprecedented system of mass surveillance with the ability to pry into the private lives of every person on Earth. Six years later, Snowden reveals how he helped to build this system and why he was moved to expose it. Spanning the bucolic Beltway suburbs of his childhood and the clandestine CIA and NSA postings of his adulthood, Permanent Record is the account of a bright young man who grew up online - a man who became a spy, a whistleblower, and, in exile, the Internet's conscience."--Jacket

Keytrace — One identity, many proofs.
Link your GitHub, domain, and other accounts to your internet handle. Cryptographically signed, user-owned, and portable.
How do we pay for privacy?
If you haven’t read Julia Angwin’s excellent profile of GnuPG’s lead developer Werner Koch, now would be a great time to check it out. Koch, who single-handedly wrote GnuPG in 1…

Bill C-22’s Groundhog Day: Why the Government’s Dismissal of Signal, Apple and the U.S. Congress Concerns Runs Back the Disastrous Online News Act Playbook - Michael Geist
Secure messaging service Signal yesterday became the latest company to warn that Bill C-22, the lawful access bill, could force it to leave the Canadian market rather than comply with provisions it says would compromise its end-to-end encryption and create new cybersecurity risks. Signal vice-president Udbhav Tiwari told the Globe and Mail that the company “would rather pull out of the country than be compelled to compromise on the privacy promises we have made to our users.” The comments are part of a steady stream of similar warnings from Apple, Meta, the Canadian Chamber of Commerce, the Cybersecurity Advisors Network, and the chairs of the U.S. House Judiciary and Foreign Affairs Committees. Despite growing concern, the government’s response has been to launch a misleading social media campaign and repeatedly insist that the experts and companies are mistaken.

Microsoft handed the government encryption keys for customer data
Microsoft complied with a warrant to hand over BitLocker recovery keys to the FBI, and privacy advocates are worried.

Introducing ONCE
Once upon a time you owned what you paid for, you controlled what you depended on, and your privacy and security were your own business. We think it’s that time again.

Chat Control & Going Dark: The war on encryption is on the rise. Through a shady collaboration between the US and the EU.
After Snowden’s whistleblowing in 2013, large parts of the internet became encrypted, enabling private and secure communication. Not everyone has welcomed this change. Most notably, the FBI and other U.S. government agencies have fought what is often called the “crypto wars”, the war on encryption. In recent years, they have been joined by the European Commission. Under the slogan “what about the children,” they try to introduce total mass surveillance of all EU citizens — first through the proposed Chat Control legislation, and later via the Going Dark and ProtectEU initiatives. The goal is to legally mandate spy tools on every European smartphone and computer. The forces behind these efforts have turned out to be American tech companies and intelligence agencies.

The Lawful Access Two-Headed Surveillance Monster: How Bill C-22 Went Off the Rails - Michael Geist
The government’s plans for lawful access have gone off the rails. In recent days, Signal has warned it would pull out of the Canadian market rather than comply with Bill C-22. Windscribe, the Toronto-headquartered VPN provider, has said it would relocate its headquarters out of Canada and NordVPN has warned it would consider following suit. Apple and Meta have both raised public concerns about the bill’s effect on encryption and cybersecurity. The Canadian Chamber of Commerce, the Cybersecurity Advisors Network, civil liberties groups, and a long line of legal and security experts have all called for changes. The chairs of the U.S. House Judiciary and Foreign Affairs Committees have written to Public Safety Minister Gary Anandasangaree warning that the bill threatens U.S. national security and the integrity of cross-border data flows. Even the bill’s own oversight body, the National Security and Intelligence Review Agency, has told the SECU committee it does not have the access it needs for effective oversight. If the government thought it could push through the bill largely unnoticed, it has been proven painfully wrong as there are now trade frictions with the U.S., the prospect of leading companies exiting the Canadian market, and weaker cybersecurity protections for ordinary users. How did Canada’s lawful access plan go awry so quickly?

Revisiting Keyed-Verification Anonymous Credentials
This summary was generated using automated tools and was not authored or reviewed by the article's author(s). It is provided to support discovery, help readers assess relevance, and assist readers from adjacent research areas in understanding the work. It is intended to complement the author-supplied abstract, which remains the primary summary of the paper. The full article remains the authoritative version of record. Click here to learn more.

Keytrace takes ideas from Keybase and Keyoxide and brings them to the decentralized web.
AI Wants Your Life: Tech Boss Meredith Whittaker Says No | The Mishal Husain Show
Secret Manager
Securely store API keys, passwords, certificates, and other sensitive data with Google Cloud’s Secret Manager.
Kiss your online privacy goodbye with Bill C-22, Canada
Civil liberties groups, legal experts and the Canadian Chamber of Commerce have been sounding the alarm for months on the privacy and cybersecurity issues contained in the Carney government’s Lawful Access Act, or Bill C-22. In a not-so-surprising twist, American lawmakers have now also added their voice to those warning about the bill.

Keybase Book
Use Keybase for end-to-end encrypted chat messaging, file sharing, and team collaboration. Get the free app for iOS, Mac, Android, Windows, and Linux.
Keybase Book
Use Keybase for end-to-end encrypted chat messaging, file sharing, and team collaboration. Get the free app for iOS, Mac, Android, Windows, and Linux.