My little blog can’t be this cute!
<li>git: Make sure <code>commit.gpgSign</code> isn't set. (system-wide: <code>git config --system --get commit.gpgSign</code>, user-wide: <code>git config --global --get commit.gpgSign</code>, repo-wide: <code>git config --local --get commit.gpgSign</code>). To strip existing commits run <code>git filter-branch</code> on the repositories.</li> <li>Email: Disable OpenPGP Signatures in your client if you did (also avoid Protonmail), make sure DKIM is non-existent, you may have to self-host your email</li> <li>Fediverse: With Mastodon 2.7.0 (upcoming release as of 2019-01-09) you should use non-public statuses by default (See <a href="https://github.com/tootsuite/mastodon/pull/9659">Pull Request #9659</a>). Otherwise you can use Pleroma which doesn't have JSON-LD Signatures.</li> - <li>XMPP: Not sure, I'll check later on how OTRv3/v4 and OMEMO works</li> + <li>XMPP: Do not use OpenPGP or OX, OMEMO seems to have good deniability. I'm not very sure about OTRv3 as <a href="https://whispersystems.org/blog/simplifying-otr-deniability/">Simplifying OTR Deniability</a> (referenced on <a href="https://conversations.im/omemo/">OMEMO's page</a>) doesn't mention the version.</li> </ul> <h2>Why?</h2> <p>It's something that weirdly doesn't seems very popular in cryptonerds circles. Long-term signatures in a computer world basically is that everything that you send can and will be used against you and people you interacted with or wrote about and there is absolutely no deniability about it.</p>