Extraordinary fast, review and publishing by the AlternativeTo team! 👍😀
Blaine Hines
@blainehines.bsky.social
It sec manager at aither . Working with building a safer universe for all. #osint https://aitherapp.github.io/ethos/
We enforce security through reproducible builds. By generating cryptographic hashes (SHA256SUMS) and release manifests for every deployment, we ensure the binary running in your browser is identical to the audited source code. If a single bit is altered, the chain of trust breaks.
We patched postcss to version 8.5.23 to resolve a moderate-severity vulnerability (CVE-2026-69153). An attacker-controlled CSS file could bypass path-traversal guards when the from option was omitted, allowing unauthorized read access to arbitrary .map files on the build machine.
On every update we, check the code for vulnerabilities and patch them. Last week we patched this high severity bug in PostCSS. Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure.
The EU has extended the temporary “Chat Control 1.0” until April 2028, which allow major tech companies voluntarily scan private messages, emails, and files for child sexual abuse material . A key limitation remains: end-to-end encrypted services like WhatsApp and Signal are exempt from scanning .
The Privacy vs. Protection Paradox The tension between individual privacy and collective security is one of the defining dilemmas of the digital age.
Google has released a Chrome update to address 382 security bugs across desktop and mobile platforms, including Critical and High-severity flaws tied to sandbox escape and code execution risks.
A European politician probing spyware got hacked by that same spyware—twice. Stelios Kouloglou, a Greek MEP, served on the EU committee investigating Pegasus abuses.
Starting with V3.1.55 we have added a separate staging deployment path so new builds can be tested before production promotion. Changed production deployment to run only from explicit release promotion instead of every main branch push.
ETHOS - Encrypted Messaging Without Accounts
Private browser-based chat, groups, and file transfer with no account, no phone number, and no plaintext fallback.
aitherapp.github.io
Secure communication isn't just about personal privacy—it's crucial for a functioning society. It protects democracy, builds collective power, and enables collaboration. Here's why it matters for all of us:
Microsoft just exposed 119 Edge extensions that had been hiding malicious code inside images and fonts for five years — all tied to a single threat actor behind the "StegoAd" campaign, active since at least 2021 .
A VPN is not enough to protect your privacy. Fingerprinting collects information directly from your device and browser: · Device specifics · Browser details Combining these attributes often creates a unique identifier for your device .
If you have an issue with ETHOS you can offcourse post it on GitHub with a detailed report including your log. github.com/aitherapp/et...
Issues · aitherapp/ethos
ethos main build. Contribute to aitherapp/ethos development by creating an account on GitHub.
github.com
We’re releasing Ethos on the web first to keep our iteration speed high. For the desktop app, we’ve decided to ditch Electron in favor of Tauri + Rust. This gives us a massive win in security and binary size, without sacrificing development velocity.
If you have problem with anything don’t hesitate to connect on our community at matrix.to#/%23ethos-ap...
Matrix - Decentralised and secure communication
You're invited to talk on Matrix. If you don't already have a client this link will help you pick one, and join the conversation. If you already have one, this link will help you join the conversation
matrix.to