• Duress PIN, Mixfit and PlugMate

    From Ch1ffr3punk@ch1ffr3punk@gmail.com to alt.privacy.anon-server,alt.cypherpunks,sci.crypt on Fri Aug 7 19:25:19 2026
    From Newsgroup: sci.crypt

    Hi all,

    isn't it nice to use Mixfit with PlugMate and an additionally set Duress
    PIN with it, when for example traveling? Try that with QSL or OmniMix...

    https://github.com/Ch1ffr3punk/Mixfit
    https://plugos.net/plugmate
    --
    https://oc2mx.net
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Nomen Nescio@nobody@dizum.com to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Sun Aug 9 15:07:55 2026
    From Newsgroup: sci.crypt

    isn't it nice to use Mixfit with PlugMate and an additionally set Duress
    PIN with it, when for example traveling? Try that with QSL or OmniMix...

    https://github.com/Ch1ffr3punk/Mixfit
    https://plugos.net/plugmate


    A USB flash drive with a virtual Linux, a mail client, Tor Browser and
    OmniMix costs a fraction of that. No reason to trust an Android device.

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Ch1ffr3punk@ch1ffr3punk@gmail.com to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Sun Aug 9 13:45:03 2026
    From Newsgroup: sci.crypt

    Nomen Nescio wrote:
    isn't it nice to use Mixfit with PlugMate and an additionally set Duress PIN with it, when for example traveling? Try that with QSL or OmniMix...

    https://github.com/Ch1ffr3punk/Mixfit
    https://plugos.net/plugmate


    A USB flash drive with a virtual Linux, a mail client, Tor Browser and OmniMix costs a fraction of that. No reason to trust an Android device.


    But you have no Duress-PIN for border control and no hardware sandbox,
    like we have with PlugMate, which can also be used with Windows or macOS
    and does not require a hobby student OS like Linux with it's many bugs.

    Privacy in modern times cost money, which mature adults can afford and
    no UX nightmare OmniMix and it originates from Eurasia for security
    reasons, which non-professional westerns hate.
    --
    https://oc2mx.net
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Nomen Nescio@nobody@dizum.com to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Sun Aug 9 17:27:58 2026
    From Newsgroup: sci.crypt

    Nomen Nescio wrote:
    isn't it nice to use Mixfit with PlugMate and an additionally set Duress >>> PIN with it, when for example traveling? Try that with QSL or OmniMix... >>>
    https://github.com/Ch1ffr3punk/Mixfit
    https://plugos.net/plugmate


    A USB flash drive with a virtual Linux, a mail client, Tor Browser and
    OmniMix costs a fraction of that. No reason to trust an Android device.


    But you have no Duress-PIN for border control and no hardware sandbox,

    Irrelevant with an encrypted USB drive holding a hidden container.

    like we have with PlugMate, which can also be used with Windows or macOS
    and does not require a hobby student OS like Linux with it's many bugs.

    A hobby student OS like Linux? OMG! You're as stupid as can be, in
    each and every respect on the wong side of history and technology.


    Privacy in modern times cost money,

    Claas, you're just a criminal trying to fleece uninformed people.

    which mature adults can afford and
    no UX nightmare OmniMix and it originates from Eurasia for security
    reasons, which non-professional westerns hate.

    OM is nothing short of the proverbial quality of German workmanship. Its perfection is the only reason why you struggle with it from day one. But
    no matter how hard you try your hacks will never reach that level.

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Ch1ffr3punk@ch1ffr3punk@gmail.com to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Sun Aug 9 16:38:35 2026
    From Newsgroup: sci.crypt

    Nomen Nescio wrote:
    Nomen Nescio wrote:
    isn't it nice to use Mixfit with PlugMate and an additionally set Duress
    PIN with it, when for example traveling? Try that with QSL or OmniMix...

    https://github.com/Ch1ffr3punk/Mixfit
    https://plugos.net/plugmate


    A USB flash drive with a virtual Linux, a mail client, Tor Browser and OmniMix costs a fraction of that. No reason to trust an Android device.


    But you have no Duress-PIN for border control and no hardware sandbox,

    Irrelevant with an encrypted USB drive holding a hidden container.

    like we have with PlugMate, which can also be used with Windows or macOS and does not require a hobby student OS like Linux with it's many bugs.

    A hobby student OS like Linux? OMG! You're as stupid as can be, in
    each and every respect on the wong side of history and technology.


    Privacy in modern times cost money,

    Claas, you're just a criminal trying to fleece uninformed people.

    which mature adults can afford and
    no UX nightmare OmniMix and it originates from Eurasia for security reasons, which non-professional westerns hate.

    OM is nothing short of the proverbial quality of German workmanship. Its perfection is the only reason why you struggle with it from day one. But
    no matter how hard you try your hacks will never reach that level.


    It is funny how LEA people like you try to defend old shit like OmniMix.

    Sure you have a mission and that is to falsify facts so that people
    believing you guys can be caught. Your methods in anonymity circles
    are known to professionals.
    --
    https://oc2mx.net
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Ch1ffr3punk@ch1ffr3punk@gmail.com to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Sun Aug 9 17:42:32 2026
    From Newsgroup: sci.crypt

    Nomen Nescio wrote:

    But you have no Duress-PIN for border control and no hardware sandbox,

    Irrelevant with an encrypted USB drive holding a hidden container.

    I desperately hope that people reading your dangerous nonsense do a search... --
    https://oc2mx.net
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Radio Eriwan@bounce.me@radio-eriwan.ru to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Sun Aug 9 21:58:05 2026
    From Newsgroup: sci.crypt

    Ch1ffr3punk wrote:
    Nomen Nescio wrote:

    But you have no Duress-PIN for border control and no hardware sandbox,

    Irrelevant with an encrypted USB drive holding a hidden container.

    I desperately hope that people reading your dangerous nonsense do a search...

    -E-+-|-C-+-|-#-+-a-i, -+-U-+-#-|-+-+-+ -|-|-+-+-|-C-#-e-i, rCo -U-#-+-i-| -#-+-+-i-e-+-| -+-|-|-a-i -+-# -i-e-+-| -+-+-#-+-|-e-|.

    1. The Hidden Container vs. the Duress-PIN (The Human Factor)
    They claim a hidden container makes the Duress-PIN unnecessary. This is dangerously naive.

    The hidden container is designed for plausible deniability of the data. The Duress-PIN, however, is designed to protect you from physical/psychological coercion, lengthy detention, or denial of entry.

    Even if your hidden container is mathematically perfect, modern forensic tools at border control check more than just free space. They analyze filesystem metadata, access timestamps, and the entropy pattern of the outer volume. If your outer volume looks completely unused or filled with random garbage, trained agents will spot it immediately.

    Without a Duress-PIN that opens a believable, actively used outer system, you have no way to satisfy the officer in a stressful situation. The hidden container alone does absolutely nothing to stop the rubber-hose (coercion) attack. Ignoring the human factor is a rookie mistake.

    2. The Hidden Container vs. the Hardware Sandbox (The Kill Shot)
    This is where their claim becomes outright dangerous and technically absurd. They say a sandbox is irrelevant because the drive is encrypted. That is fundamentally wrong.

    The hidden container protects Data-at-Rest (the stored files on the drive). The hardware sandbox protects Data-in-Use (the active decryption process).

    The moment you plug your drive into an untrusted computer at the border and enter your hidden container password, that foreign machine decrypts the data directly into its RAM.

    If that host lacks a hardware sandbox (or is compromised), it can easily run malware that:

    Captures your password via a keylogger before it even reaches the drive.

    Extracts the decrypted files directly from the system's RAM (via Cold-boot or DMA attacks) while the container is mounted.

    Injects malicious code into your USB drive's firmware (an Evil-Maid attack), which will then exfiltrate your password the next time you plug it into your own trusted computer at home.
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Yamn3 Remailer@noreply@mixmin.net to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Sun Aug 9 22:43:11 2026
    From Newsgroup: sci.crypt

    Ch1ffr3punk <ch1ffr3punk@gmail.com> wrote:
    Nomen Nescio wrote:
    Nomen Nescio wrote:
    isn't it nice to use Mixfit with PlugMate and an additionally set Duress
    PIN with it, when for example traveling? Try that with QSL or OmniMix...

    https://github.com/Ch1ffr3punk/Mixfit
    https://plugos.net/plugmate


    A USB flash drive with a virtual Linux, a mail client, Tor Browser and >> > > OmniMix costs a fraction of that. No reason to trust an Android device. >> > >

    But you have no Duress-PIN for border control and no hardware sandbox,

    Irrelevant with an encrypted USB drive holding a hidden container.

    like we have with PlugMate, which can also be used with Windows or macOS >> > and does not require a hobby student OS like Linux with it's many bugs.

    A hobby student OS like Linux? OMG! You're as stupid as can be, in
    each and every respect on the wong side of history and technology.


    Privacy in modern times cost money,

    Claas, you're just a criminal trying to fleece uninformed people.

    which mature adults can afford and
    no UX nightmare OmniMix and it originates from Eurasia for security
    reasons, which non-professional westerns hate.

    OM is nothing short of the proverbial quality of German workmanship. Its
    perfection is the only reason why you struggle with it from day one. But
    no matter how hard you try your hacks will never reach that level.


    It is funny how LEA people like you try to defend old shit like OmniMix.

    Sure you have a mission and that is to falsify facts so that people
    believing you guys can be caught. Your methods in anonymity circles
    are known to professionals.

    Mixmaster, yamn and tor are distributed networks run by volunteers not interested in making any money, and their flawless methods of
    anonymizing messages are well-known and analyzed multiple times by
    experts. There's no need for a profit-driven company in this sector.

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Fritz Wuehler@fritz@spamexpire-202608.rodent.frell.theremailer.net to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Mon Aug 10 00:21:59 2026
    From Newsgroup: sci.crypt

    Ch1ffr3punk <ch1ffr3punk@gmail.com> wrote:
    Nomen Nescio wrote:

    But you have no Duress-PIN for border control and no hardware sandbox,

    Irrelevant with an encrypted USB drive holding a hidden container.

    I desperately hope that people reading your dangerous nonsense do a search...

    You really think border guards are less suspicious when they get
    hold of your PlugMate device? Oh boy, what a funny guy you are!

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Anonymous@nobody@yamn.paranoici.org to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Mon Aug 10 00:09:08 2026
    From Newsgroup: sci.crypt

    Claas spreads FUD:
    Ch1ffr3punk wrote:
    Nomen Nescio wrote:

    But you have no Duress-PIN for border control and no hardware sandbox, >> >
    Irrelevant with an encrypted USB drive holding a hidden container.

    I desperately hope that people reading your dangerous nonsense do a search...

    ??????????, ???????? ?????????, rCo ????? ??????? ????? ?? ???? ???????.

    1. The Hidden Container vs. the Duress-PIN (The Human Factor)
    They claim a hidden container makes the Duress-PIN unnecessary. This is dangerously naive.

    The hidden container is designed for plausible deniability of the data. The Duress-PIN, however, is designed to protect you from physical/psychological coercion, lengthy detention, or denial of entry.

    Even if your hidden container is mathematically perfect, modern forensic tools at border control check more than just free space. They analyze filesystem metadata, access timestamps, and the entropy pattern of the outer volume. If your outer volume looks completely unused or filled with random garbage, trained agents will spot it
    immediately.

    Any proof? I don't think so. That's just another FUD attack.


    Without a Duress-PIN that opens a believable, actively used outer system, you have no way to satisfy the officer in a stressful situation. The hidden container alone does absolutely nothing to stop the rubber-hose (coercion) attack. Ignoring the human factor is a rookie mistake.

    And a Duress-PIN helps in that situation where the simple presence of a PlugMate computer indicates that you have something to hide? That's the
    exact opposite of plausible deniability. Furthermore, can you imagine
    how LEAs react when you offer them a PIN that clears your device? Good
    luck with it.


    2. The Hidden Container vs. the Hardware Sandbox (The Kill Shot)
    This is where their claim becomes outright dangerous and technically absurd. They say a sandbox is irrelevant because the drive is encrypted. That is fundamentally wrong.

    The hidden container protects Data-at-Rest (the stored files on the drive). The hardware sandbox protects Data-in-Use (the active decryption process).

    An isolated hidden OS on a hidden device is a sandbox.


    The moment you plug your drive into an untrusted computer at the border and enter your hidden container password, that foreign machine decrypts the data directly into its RAM.

    Who would do that? Only you, Claas, come to my mind.


    If that host lacks a hardware sandbox (or is compromised), it can easily run malware that:

    Captures your password via a keylogger before it even reaches the drive.

    Extracts the decrypted files directly from the system's RAM (via Cold-boot or DMA attacks) while the container is mounted.

    Injects malicious code into your USB drive's firmware (an Evil-Maid attack), which will then exfiltrate your password the next time you plug it into your own trusted computer at home.

    Yes, the party is over when your PlugMate device has to access
    peripherial devices of its host system like its touch screen.

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Ch1ffr3punk@ch1ffr3punk@gmail.com to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Mon Aug 10 07:52:31 2026
    From Newsgroup: sci.crypt

    Fritz Wuehler wrote:
    Ch1ffr3punk <ch1ffr3punk@gmail.com> wrote:
    Nomen Nescio wrote:

    But you have no Duress-PIN for border control and no hardware sandbox,

    Irrelevant with an encrypted USB drive holding a hidden container.

    I desperately hope that people reading your dangerous nonsense do a search...

    You really think border guards are less suspicious when they get
    hold of your PlugMate device? Oh boy, what a funny guy you are!

    I guess you fail to understand the difference. When border guards
    check the USB stick and it is encrypted the person must give his
    password to decrypt and so this is useless. When giving the Duress-PIN
    the device is wiped and border guards have nothing to see.

    Additionally, I put all my software as (Windows) binaries on GitHub,
    so once a person enters the USA without PlugMate or an encrypted
    USB stick, he can without any device go to a public library or
    Internet Caf|? etc. and download and use my software within the
    United States.
    --
    https://oc2mx.net
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Ch1ffr3punk@ch1ffr3punk@gmail.com to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Mon Aug 10 08:20:12 2026
    From Newsgroup: sci.crypt

    Yamn3 Remailer wrote:
    Ch1ffr3punk <ch1ffr3punk@gmail.com> wrote:
    Nomen Nescio wrote:
    Nomen Nescio wrote:
    isn't it nice to use Mixfit with PlugMate and an additionally set Duress
    PIN with it, when for example traveling? Try that with QSL or OmniMix...

    https://github.com/Ch1ffr3punk/Mixfit
    https://plugos.net/plugmate


    A USB flash drive with a virtual Linux, a mail client, Tor Browser and
    OmniMix costs a fraction of that. No reason to trust an Android device.


    But you have no Duress-PIN for border control and no hardware sandbox,

    Irrelevant with an encrypted USB drive holding a hidden container.

    like we have with PlugMate, which can also be used with Windows or macOS
    and does not require a hobby student OS like Linux with it's many bugs.

    A hobby student OS like Linux? OMG! You're as stupid as can be, in
    each and every respect on the wong side of history and technology.


    Privacy in modern times cost money,

    Claas, you're just a criminal trying to fleece uninformed people.

    which mature adults can afford and
    no UX nightmare OmniMix and it originates from Eurasia for security reasons, which non-professional westerns hate.

    OM is nothing short of the proverbial quality of German workmanship. Its perfection is the only reason why you struggle with it from day one. But no matter how hard you try your hacks will never reach that level.


    It is funny how LEA people like you try to defend old shit like OmniMix.

    Sure you have a mission and that is to falsify facts so that people believing you guys can be caught. Your methods in anonymity circles
    are known to professionals.

    Mixmaster, yamn and tor are distributed networks run by volunteers not interested in making any money, and their flawless methods of
    anonymizing messages are well-known and analyzed multiple times by
    experts. There's no need for a profit-driven company in this sector.


    What experts? You should run a Mixmaster or YAMN remailer by yourself
    and learn about the deficiencies Type II technolgy with smtp(s) usage
    has, when not properly used with the Nym Mixnet...
    --
    https://oc2mx.net
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Ch1ffr3punk@ch1ffr3punk@gmail.com to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Mon Aug 10 09:41:21 2026
    From Newsgroup: sci.crypt

    Anonymous wrote:
    Claas spreads FUD:
    Ch1ffr3punk wrote:
    Nomen Nescio wrote:

    But you have no Duress-PIN for border control and no hardware sandbox,

    Irrelevant with an encrypted USB drive holding a hidden container.

    I desperately hope that people reading your dangerous nonsense do a search...

    ??????????, ???????? ?????????, ??? ????? ??????? ????? ?? ???? ???????.

    1. The Hidden Container vs. the Duress-PIN (The Human Factor)
    They claim a hidden container makes the Duress-PIN unnecessary. This is dangerously naive.

    The hidden container is designed for plausible deniability of the data. The Duress-PIN, however, is designed to protect you from physical/psychological coercion, lengthy detention, or denial of entry.

    Even if your hidden container is mathematically perfect, modern forensic tools at border control check more than just free space. They analyze filesystem metadata, access timestamps, and the entropy pattern of the outer volume. If your outer volume looks completely unused or filled with random garbage, trained agents will spot it
    immediately.

    Any proof? I don't think so. That's just another FUD attack.


    Without a Duress-PIN that opens a believable, actively used outer system, you have no way to satisfy the officer in a stressful situation. The hidden container alone does absolutely nothing to stop the rubber-hose (coercion) attack. Ignoring the human factor is a rookie mistake.

    And a Duress-PIN helps in that situation where the simple presence of a PlugMate computer indicates that you have something to hide? That's the exact opposite of plausible deniability. Furthermore, can you imagine
    how LEAs react when you offer them a PIN that clears your device? Good
    luck with it.


    2. The Hidden Container vs. the Hardware Sandbox (The Kill Shot)
    This is where their claim becomes outright dangerous and technically absurd. They say a sandbox is irrelevant because the drive is encrypted. That is fundamentally wrong.

    The hidden container protects Data-at-Rest (the stored files on the drive). The hardware sandbox protects Data-in-Use (the active decryption process).

    An isolated hidden OS on a hidden device is a sandbox.


    The moment you plug your drive into an untrusted computer at the border and enter your hidden container password, that foreign machine decrypts the data directly into its RAM.

    Who would do that? Only you, Claas, come to my mind.


    If that host lacks a hardware sandbox (or is compromised), it can easily run malware that:

    Captures your password via a keylogger before it even reaches the drive.

    Extracts the decrypted files directly from the system's RAM (via Cold-boot or DMA attacks) while the container is mounted.

    Injects malicious code into your USB drive's firmware (an Evil-Maid attack), which will then exfiltrate your password the next time you plug it into your own trusted computer at home.

    Yes, the party is over when your PlugMate device has to access
    peripherial devices of its host system like its touch screen.


    What you fail to understand, VeraCrypt usage, like you propose with
    a hidden container, can easily been spotted by Border Control, so
    that you have to reveal your password.
    --
    https://oc2mx.net
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Ch1ffr3punk@ch1ffr3punk@gmail.com to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Mon Aug 10 10:59:23 2026
    From Newsgroup: sci.crypt

    Ch1ffr3punk wrote:
    Anonymous wrote:
    Claas spreads FUD:
    Ch1ffr3punk wrote:
    Nomen Nescio wrote:

    But you have no Duress-PIN for border control and no hardware sandbox,

    Irrelevant with an encrypted USB drive holding a hidden container.

    I desperately hope that people reading your dangerous nonsense do a search...

    ??????????, ???????? ?????????, ??? ????? ??????? ????? ?? ???? ???????.

    1. The Hidden Container vs. the Duress-PIN (The Human Factor)
    They claim a hidden container makes the Duress-PIN unnecessary. This is dangerously naive.

    The hidden container is designed for plausible deniability of the data. The Duress-PIN, however, is designed to protect you from physical/psychological coercion, lengthy detention, or denial of entry.

    Even if your hidden container is mathematically perfect, modern forensic tools at border control check more than just free space. They analyze filesystem metadata, access timestamps, and the entropy pattern of the outer volume. If your outer volume looks completely unused or filled with random garbage, trained agents will spot it
    immediately.

    Any proof? I don't think so. That's just another FUD attack.


    Without a Duress-PIN that opens a believable, actively used outer system, you have no way to satisfy the officer in a stressful situation. The hidden container alone does absolutely nothing to stop the rubber-hose (coercion) attack. Ignoring the human factor is a rookie mistake.

    And a Duress-PIN helps in that situation where the simple presence of a PlugMate computer indicates that you have something to hide? That's the exact opposite of plausible deniability. Furthermore, can you imagine
    how LEAs react when you offer them a PIN that clears your device? Good luck with it.


    2. The Hidden Container vs. the Hardware Sandbox (The Kill Shot)
    This is where their claim becomes outright dangerous and technically absurd. They say a sandbox is irrelevant because the drive is encrypted. That is fundamentally wrong.

    The hidden container protects Data-at-Rest (the stored files on the drive). The hardware sandbox protects Data-in-Use (the active decryption process).

    An isolated hidden OS on a hidden device is a sandbox.


    The moment you plug your drive into an untrusted computer at the border and enter your hidden container password, that foreign machine decrypts the data directly into its RAM.

    Who would do that? Only you, Claas, come to my mind.


    If that host lacks a hardware sandbox (or is compromised), it can easily run malware that:

    Captures your password via a keylogger before it even reaches the drive.

    Extracts the decrypted files directly from the system's RAM (via Cold-boot or DMA attacks) while the container is mounted.

    Injects malicious code into your USB drive's firmware (an Evil-Maid attack), which will then exfiltrate your password the next time you plug it into your own trusted computer at home.

    Yes, the party is over when your PlugMate device has to access
    peripherial devices of its host system like its touch screen.


    What you fail to understand, VeraCrypt usage, like you propose with
    a hidden container, can easily been spotted by Border Control, so
    that you have to reveal your password.


    And consider this rookie, border control can if they don't like your face format your VeraCrypt USB stick properly, so that you can't use your hidden software and then you loose your oudated OpenPGP secret key(s), nym aliases
    and other outdaded anonymous software settings, like from OmniCrap etc.
    --
    https://oc2mx.net
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Anonymous@nobody@yamn.paranoici.org to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Mon Aug 10 14:04:12 2026
    From Newsgroup: sci.crypt

    Claas wrote:

    And consider this rookie, border control can if they don't like your face format your VeraCrypt USB stick properly, so that you can't use your hidden software and then you loose your oudated OpenPGP secret key(s), nym aliases and other outdaded anonymous software settings, like from OmniCrap etc.

    In case you missed it, there's a general tendency towards
    backup devices stored in safe remote places.

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Ch1ffr3punk@ch1ffr3punk@gmail.com to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Mon Aug 10 14:26:42 2026
    From Newsgroup: sci.crypt

    Anonymous wrote:
    Claas wrote:

    And consider this rookie, border control can if they don't like your face format your VeraCrypt USB stick properly, so that you can't use your hidden software and then you loose your oudated OpenPGP secret key(s), nym aliases and other outdaded anonymous software settings, like from OmniCrap etc.

    In case you missed it, there's a general tendency towards
    backup devices stored in safe remote places.


    Do you mean with "safe" = remote (cloud locations)... when entering the
    United States, or a backup at home in a *safe* place, which you can't
    access, when traveling in the United States...
    --
    https://oc2mx.net
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Anonymous@nobody@remailer.paranoici.org to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Mon Aug 10 15:43:24 2026
    From Newsgroup: sci.crypt

    Claas wrote:
    Anonymous wrote:
    Claas spreads FUD:

    Even if your hidden container is mathematically perfect, modern forensic tools at border control check more than just free space. They analyze filesystem metadata, access timestamps, and the entropy pattern of the outer volume. If your outer volume looks completely unused or filled with random garbage, trained agents will spot it
    immediately.

    Any proof? I don't think so. That's just another FUD attack.

    Why don't you answer that key question?

    Let me guess. VeraCrypt hidden volumes are indetectable and secure and
    you presented us just one more lie.



    The moment you plug your drive into an untrusted computer at the border and enter your hidden container password, that foreign machine decrypts the data directly into its RAM.

    Who would do that? Only you, Claas, come to my mind.



    What you fail to understand, VeraCrypt usage, like you propose with
    a hidden container, can easily been spotted by Border Control, so
    that you have to reveal your password.

    It's you who has absolutely no idea. When they ask for my VeraCrypt key
    I'd offer them the password for the host volume and not the hidden one.
    But Claas, YMMV. ;-)

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Ch1ffr3punk@ch1ffr3punk@gmail.com to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Mon Aug 10 15:50:56 2026
    From Newsgroup: sci.crypt

    Anonymous wrote:

    It's you who has absolutely no idea. When they ask for my VeraCrypt key
    I'd offer them the password for the host volume and not the hidden one.

    C'mon rookie, If border guards see that you use VeraCrypt and give them
    your password, they know that stupid VeraCrypt users, like you, are most
    like using hidden volumes and simply format your OmniCrap etc. on your
    USB drive and then you look really stupid.

    Do you think that borders guards are that stupid when they search
    people and see VeraCrypt usage?
    --
    https://oc2mx.net
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Ch1ffr3punk@ch1ffr3punk@gmail.com to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Mon Aug 10 16:37:35 2026
    From Newsgroup: sci.crypt

    Ch1ffr3punk wrote:

    Do you think that borders guards are that stupid when they search
    people and see VeraCrypt usage?

    And if you use for passwords, NFT tags, hidden in a book etc.,
    US law enforcement has devices to destroy them.
    --
    https://oc2mx.net
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Chris M. Thomasson@chris.m.thomasson.1@gmail.com to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Mon Aug 10 12:55:41 2026
    From Newsgroup: sci.crypt

    On 8/10/2026 1:20 AM, Ch1ffr3punk wrote:
    [...]
    What experts?

    You know, an expert like you, right?


    You should run a Mixmaster or YAMN remailer by yourself
    and learn about the deficiencies Type II technolgy with smtp(s) usage
    has, when not properly used with the Nym Mixnet...


    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Chris M. Thomasson@chris.m.thomasson.1@gmail.com to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Mon Aug 10 13:00:07 2026
    From Newsgroup: sci.crypt

    On 8/10/2026 9:37 AM, Ch1ffr3punk wrote:
    Ch1ffr3punk wrote:

    Do you think that borders guards are that stupid when they search
    people and see VeraCrypt usage?

    And if you use for passwords, NFT tags, hidden in a book etc.,
    US law enforcement has devices to destroy them.



    https://fractallife247.com/test/hmac_cipher/drmoron/?ct_hmac_cipher=a9ae4e441c91717cb594c5065bea43a9ef2a45d343800638cb97552840fbabaf1c2083b389c112816d8ec0877563b4762fb9854f5d85e1dd3907236ddc5c3bd821439c8c8c9f9ae1171b3037bab211ce475fbb45150b617fe9

    Password is in the name. oh well, let me give it to you moron
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Anonymous@nobody@yamn.paranoici.org to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Mon Aug 10 22:19:16 2026
    From Newsgroup: sci.crypt

    Claas wrote:
    Anonymous wrote:
    Claas wrote:
    Anonymous wrote:
    Claas spreads FUD:

    Still no reply to

    Even if your hidden container is mathematically perfect, modern forensic tools at border control check more than just free space. They analyze filesystem metadata, access timestamps, and the entropy pattern of the outer volume. If your outer volume looks completely unused or filled with random garbage, trained agents will spot it
    immediately.

    Any proof?

    Why don't you answer that question though that's essential for your
    reasoning? Tell us!

    It's you who has absolutely no idea. When they ask for my VeraCrypt key
    I'd offer them the password for the host volume and not the hidden one.

    C'mon rookie, If border guards see that you use VeraCrypt and give them
    your password, they know that stupid VeraCrypt users, like you, are most
    like using hidden volumes and simply format your OmniCrap etc. on your
    USB drive and then you look really stupid.

    Do you know what backups are? And there aren't many VeraCrypt users
    aware of hidden volumes or even using them.

    But now imagine the reaction of border guards confronted with your
    impertinence of offering them the erasure PIN for your PlugMate device
    while they asked for the access passphrase. Good luck facing the legal consequences of tampering with evidence.

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Ch1ffr3punk@ch1ffr3punk@gmail.com to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Tue Aug 11 06:42:18 2026
    From Newsgroup: sci.crypt

    Anonymous wrote:

    But now imagine the reaction of border guards confronted with your impertinence of offering them the erasure PIN for your PlugMate device
    while they asked for the access passphrase. Good luck facing the legal consequences of tampering with evidence.

    Border guards have an eye for whom they check, if you understand what
    I mean. And the ones they check are then (how comes) VeraCrypt users,
    while normal mature adults, who carry PlugMate, are not checked. That
    is how things work.
    --
    https://oc2mx.net
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Jan Panteltje@alien@comet.invalid to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Tue Aug 11 07:06:27 2026
    From Newsgroup: sci.crypt

    Ch1ffr3punk <ch1ffr3punk@gmail.com>wrote:
    Ch1ffr3punk wrote:

    Do you think that borders guards are that stupid when they search
    people and see VeraCrypt usage?

    And if you use for passwords, NFT tags, hidden in a book etc.,
    US law enforcement has devices to destroy them.


    Anybody been swallowing micro-sdcards?


    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From address@address@is.invalid (LucLan) to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Tue Aug 11 07:13:39 2026
    From Newsgroup: sci.crypt

    In alt.cypherpunks Jan Panteltje <alien@comet.invalid> wrote:
    Ch1ffr3punk <ch1ffr3punk@gmail.com>wrote:
    Ch1ffr3punk wrote:

    Do you think that borders guards are that stupid when they search
    people and see VeraCrypt usage?

    And if you use for passwords, NFT tags, hidden in a book etc.,
    US law enforcement has devices to destroy them.


    Anybody been swallowing micro-sdcards?


    No. Why?
    --
    Luc
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Jan Panteltje@alien@comet.invalid to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Tue Aug 11 07:26:12 2026
    From Newsgroup: sci.crypt

    address@is.invalid (LucLan)wrote:
    In alt.cypherpunks Jan Panteltje <alien@comet.invalid> wrote:
    Ch1ffr3punk <ch1ffr3punk@gmail.com>wrote:
    Ch1ffr3punk wrote:

    Do you think that borders guards are that stupid when they search
    people and see VeraCrypt usage?

    And if you use for passwords, NFT tags, hidden in a book etc.,
    US law enforcement has devices to destroy them.


    Anybody been swallowing micro-sdcards?


    No. Why?

    Put you secret messages and data on it,
    swallow it and then pass through customs?
    Make sure you carry a big smartphone with lots of OK stuff
    to distract security?
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Anonymous@nobody@yamn.paranoici.org to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Tue Aug 11 08:29:20 2026
    From Newsgroup: sci.crypt

    Anonymous <nobody@yamn.paranoici.org> wrote:
    Claas wrote:
    Anonymous wrote:
    Claas wrote:
    Anonymous wrote:
    Claas spreads FUD:

    Still no reply to

    Even if your hidden container is mathematically perfect, modern forensic tools at border control check more than just free space. They analyze filesystem metadata, access timestamps, and the entropy pattern of the outer volume. If your outer volume looks completely unused or filled with random garbage, trained agents will spot it
    immediately.

    Any proof?

    Why don't you answer that question though that's essential for your reasoning? Tell us!

    Why?

    Because Claas is a liar, a mudslinger, an enemy of free speech,
    of free societies, a fascist, Putin's asset.

    But his lies are exposed, secure free anonymity tools prevail,
    Putler's terror state is defeated with Russia up to the hilt in
    debt and most Russian companies teetering on the brink of
    bankruptcy. Kaboom!

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Alexander Schreiber@als@usenet.thangorodrim.de to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Tue Aug 11 10:35:56 2026
    From Newsgroup: sci.crypt

    Jan Panteltje <alien@comet.invalid> wrote:
    Ch1ffr3punk <ch1ffr3punk@gmail.com>wrote:
    Ch1ffr3punk wrote:

    Do you think that borders guards are that stupid when they search
    people and see VeraCrypt usage?

    And if you use for passwords, NFT tags, hidden in a book etc.,
    US law enforcement has devices to destroy them.


    Anybody been swallowing micro-sdcards?

    Sound like a great recipe for a pain in the ass.

    SCNR,
    Alex.
    --
    "Opportunity is missed by most people because it is dressed in overalls and
    looks like work." -- Thomas A. Edison
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Ch1ffr3punk@ch1ffr3punk@gmail.com to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Tue Aug 11 10:33:49 2026
    From Newsgroup: sci.crypt

    Anonymous wrote:
    Anonymous <nobody@yamn.paranoici.org> wrote:
    Claas wrote:
    Anonymous wrote:
    Claas wrote:
    Anonymous wrote:
    Claas spreads FUD:

    Still no reply to

    Even if your hidden container is mathematically perfect, modern forensic tools at border control check more than just free space. They analyze filesystem metadata, access timestamps, and the entropy pattern of the outer volume. If your outer volume looks completely unused or filled with random garbage, trained agents will spot it
    immediately.

    Any proof?

    Why don't you answer that question though that's essential for your reasoning? Tell us!

    Why?

    Because Claas is a liar, a mudslinger, an enemy of free speech,
    of free societies, a fascist, Putin's asset.

    But his lies are exposed, secure free anonymity tools prevail,
    Putler's terror state is defeated with Russia up to the hilt in
    debt and most Russian companies teetering on the brink of
    bankruptcy. Kaboom!


    You are such an idiot! Russia has no problems and BRICS and
    de-dollarization rises, while my tools are modern and much
    better than OmniCarp etc.
    --
    https://oc2mx.net
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Jan Panteltje@alien@comet.invalid to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Tue Aug 11 12:06:55 2026
    From Newsgroup: sci.crypt

    Alexander Schreiber <als@usenet.thangorodrim.de>wrote:
    Jan Panteltje <alien@comet.invalid> wrote:
    Ch1ffr3punk <ch1ffr3punk@gmail.com>wrote:
    Ch1ffr3punk wrote:

    Do you think that borders guards are that stupid when they search
    people and see VeraCrypt usage?

    And if you use for passwords, NFT tags, hidden in a book etc.,
    US law enforcement has devices to destroy them.


    Anybody been swallowing micro-sdcards?

    Sound like a great recipe for a pain in the ass.

    SCNR,
    Alex.

    Could perhaps get stuck in your appendix?



    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Alexander Schreiber@als@usenet.thangorodrim.de to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Tue Aug 11 15:43:43 2026
    From Newsgroup: sci.crypt

    Jan Panteltje <alien@comet.invalid> wrote:
    Alexander Schreiber <als@usenet.thangorodrim.de>wrote:
    Jan Panteltje <alien@comet.invalid> wrote:
    Ch1ffr3punk <ch1ffr3punk@gmail.com>wrote:
    Ch1ffr3punk wrote:

    Do you think that borders guards are that stupid when they search
    people and see VeraCrypt usage?

    And if you use for passwords, NFT tags, hidden in a book etc.,
    US law enforcement has devices to destroy them.


    Anybody been swallowing micro-sdcards?

    Sound like a great recipe for a pain in the ass.


    Could perhaps get stuck in your appendix?

    That doesn't sound like much fun either.

    Kind regards,
    Alex.
    --
    "Opportunity is missed by most people because it is dressed in overalls and
    looks like work." -- Thomas A. Edison
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Chris M. Thomasson@chris.m.thomasson.1@gmail.com to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Tue Aug 11 14:34:34 2026
    From Newsgroup: sci.crypt

    On 8/11/2026 1:35 AM, Alexander Schreiber wrote:
    Jan Panteltje <alien@comet.invalid> wrote:
    Ch1ffr3punk <ch1ffr3punk@gmail.com>wrote:
    Ch1ffr3punk wrote:

    Do you think that borders guards are that stupid when they search
    people and see VeraCrypt usage?

    And if you use for passwords, NFT tags, hidden in a book etc.,
    US law enforcement has devices to destroy them.


    Anybody been swallowing micro-sdcards?

    Sound like a great recipe for a pain in the ass.
    ROFL!!!!!!!!!!
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Ch1ffr3punk@ch1ffr3punk@gmail.com to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Wed Aug 12 09:52:30 2026
    From Newsgroup: sci.crypt

    Jan Panteltje wrote:
    address@is.invalid (LucLan)wrote:
    In alt.cypherpunks Jan Panteltje <alien@comet.invalid> wrote:
    Ch1ffr3punk <ch1ffr3punk@gmail.com>wrote:
    Ch1ffr3punk wrote:

    Do you think that borders guards are that stupid when they search people and see VeraCrypt usage?

    And if you use for passwords, NFT tags, hidden in a book etc.,
    US law enforcement has devices to destroy them.


    Anybody been swallowing micro-sdcards?


    No. Why?

    Put you secret messages and data on it,
    swallow it and then pass through customs?
    Make sure you carry a big smartphone with lots of OK stuff
    to distract security?

    Probably a better way would be to carry no devices at all
    and only purchase an emtpy USB stick at arrival, when you
    download all your goodies from public repositories and
    only need to remember the passphrase you exchanged with
    your loved ones.

    That's how MicroCrypt works and additionally you can
    receive/transfer files with NymX over the Nym Mixnet,
    so that third-parties do not know with whom you do
    files transfers.

    https://github.com/Ch1ffr3punk/MicroCrypt
    https://github.com/Ch1ffr3punk/NymX

    HTH!
    --
    https://oc2mx.net
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Ch1ffr3punk@ch1ffr3punk@gmail.com to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Wed Aug 12 09:58:57 2026
    From Newsgroup: sci.crypt

    Ch1ffr3punk wrote:
    Jan Panteltje wrote:
    address@is.invalid (LucLan)wrote:
    In alt.cypherpunks Jan Panteltje <alien@comet.invalid> wrote:
    Ch1ffr3punk <ch1ffr3punk@gmail.com>wrote:
    Ch1ffr3punk wrote:

    Do you think that borders guards are that stupid when they search people and see VeraCrypt usage?

    And if you use for passwords, NFT tags, hidden in a book etc.,
    US law enforcement has devices to destroy them.


    Anybody been swallowing micro-sdcards?


    No. Why?

    Put you secret messages and data on it,
    swallow it and then pass through customs?
    Make sure you carry a big smartphone with lots of OK stuff
    to distract security?

    Probably a better way would be to carry no devices at all
    and only purchase an emtpy USB stick at arrival, when you
    download all your goodies from public repositories and
    only need to remember the passphrase you exchanged with
    your loved ones.

    That's how MicroCrypt works and additionally you can
    receive/transfer files with NymX over the Nym Mixnet,
    so that third-parties do not know with whom you do
    files transfers.

    https://github.com/Ch1ffr3punk/MicroCrypt
    https://github.com/Ch1ffr3punk/NymX

    HTH!

    P.S. Prior depature, one can sign-up with https://atomicmail.io/
    without providing any credentials, so that your loved ones have
    your email address, when using MicroCrypt.
    --
    https://oc2mx.net
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Jan Panteltje@alien@comet.invalid to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Wed Aug 12 12:38:20 2026
    From Newsgroup: sci.crypt

    Ch1ffr3punk <ch1ffr3punk@gmail.com>wrote:
    Ch1ffr3punk wrote:
    Jan Panteltje wrote:
    address@is.invalid (LucLan)wrote:
    In alt.cypherpunks Jan Panteltje <alien@comet.invalid> wrote:
    Ch1ffr3punk <ch1ffr3punk@gmail.com>wrote:
    Ch1ffr3punk wrote:

    Do you think that borders guards are that stupid when they search >> > > > > > people and see VeraCrypt usage?

    And if you use for passwords, NFT tags, hidden in a book etc.,
    US law enforcement has devices to destroy them.


    Anybody been swallowing micro-sdcards?


    No. Why?

    Put you secret messages and data on it,
    swallow it and then pass through customs?
    Make sure you carry a big smartphone with lots of OK stuff
    to distract security?

    Probably a better way would be to carry no devices at all
    and only purchase an empty USB stick at arrival, when you
    download all your goodies from public repositories and
    only need to remember the passphrase you exchanged with
    your loved ones.

    That's how MicroCrypt works and additionally you can
    receive/transfer files with NymX over the Nym Mixnet,
    so that third-parties do not know with whom you do
    files transfers.

    https://github.com/Ch1ffr3punk/MicroCrypt
    https://github.com/Ch1ffr3punk/NymX

    HTH!

    P.S. Prior depature, one can sign-up with https://atomicmail.io/
    without providing any credentials, so that your loved ones have
    your email address, when using MicroCrypt.


    --
    https://oc2mx.net
    Interesting,
    https://oc2mx.net/am.html

    I will be 80 in a few month this year, been on internet since it started, used Win 3.1 and Trumpet Winsock,
    when Billy The Gates said 'internet is not that important'.
    Bill Gates stated that he saw "little commercial potential for the internet for the next 10 years"
    during a Comdex trade event in 1994.
    Additionally, in his 1995 book "The Road Ahead,"
    he described the internet as a novelty that would eventually be replaced by something better.

    Before that in 1980 we had 'Videotex' (Viditel in the Netherlands where I am now)..
    Have my own website ever since...
    https://panteltje.nl/index1.html
    Sometimes ran the server at home when I had a fixed IP address (cable) now web hosting outsourced.

    Started using Linux when SLS Linux came, end of MS windows for me.

    Anyways these days US will also want to know about your online activities for a Visa ..
    So not expecting to get a Visa from them, I refused to join CIA many years ago too.

    As to transferring encrypted stuff, there are so many ways...
    With memory things getting smaller and smaller and having more and more capacity,
    hiding something, even in your watch, becomes easier and easier.
    Drones... Radio... Satellite..
    Played with it all.

    Or you can just post your encrypted stuff on Usenet and thousands will read it...

    There is more to it...
    I tramp keeps going maybe after the nukes try Morse and smoke signs?




    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From John Gotti@nobody@domain.invalid to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Wed Aug 12 15:46:19 2026
    From Newsgroup: sci.crypt

    Jan Panteltje wrote:
    Ch1ffr3punk <ch1ffr3punk@gmail.com>wrote:
    Ch1ffr3punk wrote:
    Jan Panteltje wrote:
    address@is.invalid (LucLan)wrote:
    In alt.cypherpunks Jan Panteltje <alien@comet.invalid> wrote:
    Ch1ffr3punk <ch1ffr3punk@gmail.com>wrote:
    Ch1ffr3punk wrote:

    Do you think that borders guards are that stupid when they search >>>>>>>> people and see VeraCrypt usage?

    And if you use for passwords, NFT tags, hidden in a book etc.,
    US law enforcement has devices to destroy them.


    Anybody been swallowing micro-sdcards?


    No. Why?

    Put you secret messages and data on it,
    swallow it and then pass through customs?
    Make sure you carry a big smartphone with lots of OK stuff
    to distract security?

    Probably a better way would be to carry no devices at all
    and only purchase an empty USB stick at arrival, when you
    download all your goodies from public repositories and
    only need to remember the passphrase you exchanged with
    your loved ones.

    That's how MicroCrypt works and additionally you can
    receive/transfer files with NymX over the Nym Mixnet,
    so that third-parties do not know with whom you do
    files transfers.

    https://github.com/Ch1ffr3punk/MicroCrypt
    https://github.com/Ch1ffr3punk/NymX

    HTH!

    P.S. Prior depature, one can sign-up with https://atomicmail.io/
    without providing any credentials, so that your loved ones have
    your email address, when using MicroCrypt.


    --
    https://oc2mx.net
    Interesting,
    https://oc2mx.net/am.html

    I will be 80 in a few month this year, been on internet since it started, used Win 3.1 and Trumpet Winsock,
    when Billy The Gates said 'internet is not that important'.
    Bill Gates stated that he saw "little commercial potential for the internet for the next 10 years"
    during a Comdex trade event in 1994.
    Additionally, in his 1995 book "The Road Ahead,"
    he described the internet as a novelty that would eventually be replaced by something better.

    Before that in 1980 we had 'Videotex' (Viditel in the Netherlands where I am now)..
    Have my own website ever since...
    https://panteltje.nl/index1.html
    Sometimes ran the server at home when I had a fixed IP address (cable) now web hosting outsourced.

    Started using Linux when SLS Linux came, end of MS windows for me.

    Anyways these days US will also want to know about your online activities for a Visa ..
    So not expecting to get a Visa from them, I refused to join CIA many years ago too.

    As to transferring encrypted stuff, there are so many ways...
    With memory things getting smaller and smaller and having more and more capacity,
    hiding something, even in your watch, becomes easier and easier.
    Drones... Radio... Satellite..
    Played with it all.

    Or you can just post your encrypted stuff on Usenet and thousands will read it...

    There is more to it...
    I tramp keeps going maybe after the nukes try Morse and smoke signs?

    Your NewsFleX sucks mate.
    Today as in the 80s.

    Path traversal in the downloader.

    Command injection: URLs and group names end up in shell commands executed with popen().

    Memory corruption in NNTP, SMTP, and FTP responses: with a line exactly READSIZE long, the terminator is written beyond the buffer.
    Crash and possible stack corruption caused by a malicious server.

    HTML parser without size checking: temp_pos grows without checking the buffer limit.

    Insecure credentials: NNTP password saved in clear text and sent via AUTHINFO PASS over a TCP socket without TLS.

    The OTP is cryptographically insecure: it generates the key via rand(), without secure initialization.
    Predictable keys and possible reuse of the pad, so the promised confidentiality is unreliable.
    The filter password uses crypt() with a fixed salt of "P8".
    The hash is easily attackable and the same for identical passwords.

    Verdict: I would not use it on the Internet, with real credentials, or on the main system.
    Above all, it should never be run as root, despite the README explicitly recommending it.
    For historical testing, only in a dedicated VM, as a non-privileged user, without a shared home and without personal data.

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Ch1ffr3punk@ch1ffr3punk@gmail.com to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Wed Aug 12 16:21:14 2026
    From Newsgroup: sci.crypt

    Jan Panteltje wrote:
    Ch1ffr3punk <ch1ffr3punk@gmail.com>wrote:
    Ch1ffr3punk wrote:
    Jan Panteltje wrote:
    address@is.invalid (LucLan)wrote:
    In alt.cypherpunks Jan Panteltje <alien@comet.invalid> wrote:
    Ch1ffr3punk <ch1ffr3punk@gmail.com>wrote:
    Ch1ffr3punk wrote:

    Do you think that borders guards are that stupid when they search
    people and see VeraCrypt usage?

    And if you use for passwords, NFT tags, hidden in a book etc.,
    US law enforcement has devices to destroy them.


    Anybody been swallowing micro-sdcards?


    No. Why?

    Put you secret messages and data on it,
    swallow it and then pass through customs?
    Make sure you carry a big smartphone with lots of OK stuff
    to distract security?

    Probably a better way would be to carry no devices at all
    and only purchase an empty USB stick at arrival, when you
    download all your goodies from public repositories and
    only need to remember the passphrase you exchanged with
    your loved ones.

    That's how MicroCrypt works and additionally you can
    receive/transfer files with NymX over the Nym Mixnet,
    so that third-parties do not know with whom you do
    files transfers.

    https://github.com/Ch1ffr3punk/MicroCrypt https://github.com/Ch1ffr3punk/NymX

    HTH!

    P.S. Prior depature, one can sign-up with https://atomicmail.io/
    without providing any credentials, so that your loved ones have
    your email address, when using MicroCrypt.


    --
    https://oc2mx.net
    Interesting,
    https://oc2mx.net/am.html

    I will be 80 in a few month this year, been on internet since it started, used Win 3.1 and Trumpet Winsock,
    when Billy The Gates said 'internet is not that important'.
    Bill Gates stated that he saw "little commercial potential for the internet for the next 10 years"
    during a Comdex trade event in 1994.
    Additionally, in his 1995 book "The Road Ahead,"
    he described the internet as a novelty that would eventually be replaced by something better.

    Before that in 1980 we had 'Videotex' (Viditel in the Netherlands where I am now)..
    Have my own website ever since...
    https://panteltje.nl/index1.html
    Sometimes ran the server at home when I had a fixed IP address (cable) now web hosting outsourced.

    Started using Linux when SLS Linux came, end of MS windows for me.

    Anyways these days US will also want to know about your online activities for a Visa ..
    So not expecting to get a Visa from them, I refused to join CIA many years ago too.

    As to transferring encrypted stuff, there are so many ways...
    With memory things getting smaller and smaller and having more and more capacity,
    hiding something, even in your watch, becomes easier and easier.
    Drones... Radio... Satellite..
    Played with it all.

    Or you can just post your encrypted stuff on Usenet and thousands will read it...

    There is more to it...
    I tramp keeps going maybe after the nukes try Morse and smoke signs?

    I am 64 now and been online since the Atari 800XL came out. I will not
    travel to the USA, as we have beautiful Eurasia to discover many nice
    places.

    I do all this privacy stuff mostly for eldery, non-tech and people with
    a disabilty, because Linux nerds are mostly selfish and only use outdated OpenPGP crap etc. which I do not trust.
    --
    https://oc2mx.net
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Jan Panteltje@alien@comet.invalid to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Wed Aug 12 16:31:25 2026
    From Newsgroup: sci.crypt

    John Gotti <nobody@domain.invalid>wrote:
    Jan Panteltje wrote:
    Ch1ffr3punk <ch1ffr3punk@gmail.com>wrote:
    Ch1ffr3punk wrote:
    Jan Panteltje wrote:
    address@is.invalid (LucLan)wrote:
    In alt.cypherpunks Jan Panteltje <alien@comet.invalid> wrote:
    Ch1ffr3punk <ch1ffr3punk@gmail.com>wrote:
    Ch1ffr3punk wrote:

    Do you think that borders guards are that stupid when they search >>>>>>>>> people and see VeraCrypt usage?

    And if you use for passwords, NFT tags, hidden in a book etc., >>>>>>>> US law enforcement has devices to destroy them.


    Anybody been swallowing micro-sdcards?


    No. Why?

    Put you secret messages and data on it,
    swallow it and then pass through customs?
    Make sure you carry a big smartphone with lots of OK stuff
    to distract security?

    Probably a better way would be to carry no devices at all
    and only purchase an empty USB stick at arrival, when you
    download all your goodies from public repositories and
    only need to remember the passphrase you exchanged with
    your loved ones.

    That's how MicroCrypt works and additionally you can
    receive/transfer files with NymX over the Nym Mixnet,
    so that third-parties do not know with whom you do
    files transfers.

    https://github.com/Ch1ffr3punk/MicroCrypt
    https://github.com/Ch1ffr3punk/NymX

    HTH!

    P.S. Prior depature, one can sign-up with https://atomicmail.io/
    without providing any credentials, so that your loved ones have
    your email address, when using MicroCrypt.


    --
    https://oc2mx.net
    Interesting,
    https://oc2mx.net/am.html

    I will be 80 in a few month this year, been on internet since it started, used Win 3.1 and Trumpet Winsock,
    when Billy The Gates said 'internet is not that important'.
    Bill Gates stated that he saw "little commercial potential for the internet for the next 10 years"
    during a Comdex trade event in 1994.
    Additionally, in his 1995 book "The Road Ahead,"
    he described the internet as a novelty that would eventually be replaced by something better.

    Before that in 1980 we had 'Videotex' (Viditel in the Netherlands where I am now)..
    Have my own website ever since...
    https://panteltje.nl/index1.html
    Sometimes ran the server at home when I had a fixed IP address (cable) now web hosting outsourced.

    Started using Linux when SLS Linux came, end of MS windows for me.

    Anyways these days US will also want to know about your online activities for a Visa ..
    So not expecting to get a Visa from them, I refused to join CIA many years ago too.

    As to transferring encrypted stuff, there are so many ways...
    With memory things getting smaller and smaller and having more and more capacity,
    hiding something, even in your watch, becomes easier and easier.
    Drones... Radio... Satellite..
    Played with it all.

    Or you can just post your encrypted stuff on Usenet and thousands will read it...

    There is more to it...
    I tramp keeps going maybe after the nukes try Morse and smoke signs?

    Your NewsFleX sucks mate.
    Today as in the 80s.

    Path traversal in the downloader.

    Command injection: URLs and group names end up in shell commands executed with popen().

    Memory corruption in NNTP, SMTP, and FTP responses: with a line exactly READSIZE long, the terminator is written beyond the
    buffer.
    Crash and possible stack corruption caused by a malicious server.

    HTML parser without size checking: temp_pos grows without checking the buffer limit.

    Insecure credentials: NNTP password saved in clear text and sent via AUTHINFO PASS over a TCP socket without TLS.

    The OTP is cryptographically insecure: it generates the key via rand(), without secure initialization.
    Predictable keys and possible reuse of the pad, so the promised confidentiality is unreliable.
    The filter password uses crypt() with a fixed salt of "P8".
    The hash is easily attackable and the same for identical passwords.

    Verdict: I would not use it on the Internet, with real credentials, or on the main system.
    Above all, it should never be run as root, despite the README explicitly recommending it.
    For historical testing, only in a dedicated VM, as a non-privileged user, without a shared home and without personal data.


    Well, I have been using it since I moved to Linux with SLS Linux in 1992 or so I wrote it because there was no 'Free Agent' for Linux.

    It has been working perfectly here for me as root since that day (I am always root), and now also runs on my Raspberry Pi4 8 GB.
    raspberrypi: ~ # uname -a
    Linux raspberrypi 5.15.32-v7l+ #1538 SMP Thu Mar 31 19:39:41 BST 2022 armv7l GNU/Linux

    The nice thing is that I have a Usenet database with postings and articles I liked and kept going back to the late nineties.

    Problems?
    Problems came when the maintainer of libforms made some changes, dropped middle and right mouse button support for example,
    reported it, I think he fixed it.
    But I use an old version of libforms.

    As to crashes, and other problems you seem to have, no :-)
    It's not perfect but few software works that well.

    But if you are too dumb or lazy to install it or improve it :-) keep with the stuff you like,

    It is nice to have a database going back decennia and a search function in it. And of course you can search with 'locate' and 'grep' etc etc too.

    I noticed a lot of panic by 'news reader clans when they hear about NewsFleX. That is it because it is a zillion times better than most crap showered upon you poor guys.

    BTW I no longer use the html function, html has no place in Usenet (or email) IMNSHO.

    But wise cracker, write a better one!
    If you can ;-)






    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Jan Panteltje@alien@comet.invalid to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Wed Aug 12 16:56:11 2026
    From Newsgroup: sci.crypt

    Ch1ffr3punk <ch1ffr3punk@gmail.com>wrote:
    Jan Panteltje wrote:
    Ch1ffr3punk <ch1ffr3punk@gmail.com>wrote:
    Ch1ffr3punk wrote:
    Jan Panteltje wrote:
    address@is.invalid (LucLan)wrote:
    In alt.cypherpunks Jan Panteltje <alien@comet.invalid> wrote:
    Ch1ffr3punk <ch1ffr3punk@gmail.com>wrote:
    Ch1ffr3punk wrote:

    Do you think that borders guards are that stupid when they search
    people and see VeraCrypt usage?

    And if you use for passwords, NFT tags, hidden in a book etc., >> > > > > > > US law enforcement has devices to destroy them.


    Anybody been swallowing micro-sdcards?


    No. Why?

    Put you secret messages and data on it,
    swallow it and then pass through customs?
    Make sure you carry a big smartphone with lots of OK stuff
    to distract security?

    Probably a better way would be to carry no devices at all
    and only purchase an empty USB stick at arrival, when you
    download all your goodies from public repositories and
    only need to remember the passphrase you exchanged with
    your loved ones.

    That's how MicroCrypt works and additionally you can
    receive/transfer files with NymX over the Nym Mixnet,
    so that third-parties do not know with whom you do
    files transfers.

    https://github.com/Ch1ffr3punk/MicroCrypt
    https://github.com/Ch1ffr3punk/NymX

    HTH!

    P.S. Prior depature, one can sign-up with https://atomicmail.io/
    without providing any credentials, so that your loved ones have
    your email address, when using MicroCrypt.


    --
    https://oc2mx.net
    Interesting,
    https://oc2mx.net/am.html

    I will be 80 in a few month this year, been on internet since it started, used Win 3.1 and Trumpet Winsock,
    when Billy The Gates said 'internet is not that important'.
    Bill Gates stated that he saw "little commercial potential for the internet for the next 10 years"
    during a Comdex trade event in 1994.
    Additionally, in his 1995 book "The Road Ahead,"
    he described the internet as a novelty that would eventually be replaced by something better.

    Before that in 1980 we had 'Videotex' (Viditel in the Netherlands where I am now)..
    Have my own website ever since...
    https://panteltje.nl/index1.html
    Sometimes ran the server at home when I had a fixed IP address (cable) now web hosting outsourced.

    Started using Linux when SLS Linux came, end of MS windows for me.

    Anyways these days US will also want to know about your online activities for a Visa ..
    So not expecting to get a Visa from them, I refused to join CIA many years ago too.

    As to transferring encrypted stuff, there are so many ways...
    With memory things getting smaller and smaller and having more and more capacity,
    hiding something, even in your watch, becomes easier and easier.
    Drones... Radio... Satellite..
    Played with it all.

    Or you can just post your encrypted stuff on Usenet and thousands will read it...

    There is more to it...
    I tramp keeps going maybe after the nukes try Morse and smoke signs?

    I am 64 now and been online since the Atari 800XL came out. I will not
    travel to the USA, as we have beautiful Eurasia to discover many nice
    places.

    I do all this privacy stuff mostly for eldery, non-tech and people with
    a disabilty, because Linux nerds are mostly selfish and only use outdated >OpenPGP crap etc. which I do not trust.

    Yes.. I take it these days those who listen in know about everything about me.. and everyone else.
    But you can use that to your advantage too :-)
    AI will suck it up and ..
    I remember that discussion with AI where I told it I had died and went to heaven, but the guy at the door there did not
    let me in because I did not have the required 4 COVID shots.
    So I went down below and the boss there did not let me in as he wanted no competition.
    So I am stuck here, in the middle with you.
    So now, if AI sucks that in, would be fun how it sees 'heaven' etc ... and recommends COVID shots for those wanting to go there...'.

    I guess now it is trained on Adam and Eve and no life on other planets.
    But that was a few years ago, maybe AI is better now, not the AIs posting here for sure :-)
    Looks like Elon or his boss is letting AI post here trying to make it destroy Usenet so people need to go to X,
    where he can control them.
    Usenet is likely one of the last free discussion places online.
    As to selfish ,. open sourcing stuff is not a selfish thing.
    Deliberately making and selling ever more bloated operating systems and application to force people to buy ever
    more expensive hardware while holding shares in hardware companies like microsoft does, is selfish,
    But selfishness is the US disease and the US tramp contaminates his people with it.
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Ch1ffr3punk@ch1ffr3punk@gmail.com to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Wed Aug 12 17:26:23 2026
    From Newsgroup: sci.crypt

    Jan Panteltje wrote:

    Usenet is likely one of the last free discussion places online.

    Yes and Bitmessage before it was heavily spammed.

    As to selfish ,. open sourcing stuff is not a selfish thing.
    Deliberately making and selling ever more bloated operating systems and application to force people to buy ever
    more expensive hardware while holding shares in hardware companies like microsoft does, is selfish,
    But selfishness is the US disease and the US tramp contaminates his people with it.

    I do not mean the authors of Open Source Linux software, but the endusers,
    like OpenPGP users which think this outdated crap is superior, but these dummies will never have family, friends and co-workers convinced to use
    this crap, because they are mature adults having better things to do than playing with that crap.
    --
    https://oc2mx.net
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Arditi Popolo@antifa@yamn.actions to alt.cypherpunks,alt.privacy.anon-server,sci.crypt on Thu Aug 13 12:41:49 2026
    From Newsgroup: sci.crypt

    The real issue is operational leakage,filesystem metadata, repeated snapshots, backups, flash wear-leveling, and traces left by the host system.

    VeraCryptrCOs plausible deniability is conditional, not absolute.

    A PlugMate duress PIN is a separate vendor feature, not cryptographic proof that all traces can be erased.

    If, after being caught with a PlugMate, you offer a duress PIN instead of the password they requested, border officers will likely interpret it as a deliberate attempt to destroy or conceal evidence, not as cooperation.

    A duress PIN is not proof of guilt for whatever crime is being investigated.

    At most, offering or activating it may be treated as circumstantial evidence of an attempt to conceal or destroy data.

    Whether that creates a separate offence depends entirely on the jurisdiction and the circumstances.

    This post isn't for or against anyone.
    It's called collaborative discussion, kids!

    --- Synchronet 3.22a-Linux NewsLink 1.2