• 0 Posts
  • 52 Comments
Joined 2Y ago
cake
Cake day: Jun 16, 2023

help-circle
rss

I believe the Pixel 9a is also available. You might snag that one instead of an 8a just to give yourself another year of support.


I think once you give your IP to the satellite, the deapsea cables will start tracking all jellyfin packets


Seeing as RCS with encryption based on the MLS standard hasnt been deployed yet, can you show exactly what metadata is leaking?


Actually RCS has encryption in the new spec now, and we could see encrypted RCS messages implemented on iOS and Android within a year.

But even so, use Signal.


Not entirely true. There is other sandbox software out there (such as firejail, distrobox, docker, chroot, any VM products, etc) although they should also be cautious about claiming to be more secure. Flatpak, however, is not considered a sandbox by some.



If your distro doesn’t work unless you use Flatpaks, then stick to flatpaks ig. Its your system.


There are quite a few reasons to avoid flatpaks tbh.

  • You have no control over the dependencies. A flatpack can include a very old dependency and there is nothing you can do about it. You are at the mercy of the developer.

  • Many Flatpak applications available on flathub are not effectively sandboxed by default. Do not rely on the provided process isolation without first reviewing the related flatpak permission manifest for common sandbox escape issues.

  • Running untrusted code is never safe; sandboxing cannot change this. It can be a false sense of security.

  • It is generally not a good idea to run unattended updates via systemd, as the applications can get new permissions without the user aware of the changes. See this blogpost for examples

  • Flatpak does not run on the linux-hardened kernel unless you do additional kernel modifications that could have negative security implications.


What are the benefits of flatpacks? Like why not just install the actual Tor browser on your system? The one that is released and maintained by The Tor Project?

[edit] Looks like the Tor Project does support this flatpack. Im a silly goose.



GrapheneOS has the profiles that you are asking for. Configure them how you want.

GrapheneOS- Features


Mullvad has obfuscation settings that will make your VPN traffic look like regular video calls. This can be used to get around ISPs blocking access.



Proton Mail --> Mail-In-A-Box

Proton Calender --> Mail-In-A-Box

Proton Drive --> Mail-In-A-Box

Proton VPN --> Mullvad VPN

Proton Pass --> Bitwarden/KeePass+Mail-In-A-Box

Proton Wallet --> Stick with your cryptos base wallet app. Never give your private keys to any service.



Yea this is not feasible or sustainable lol May as well track every bird on planet earth.


I don’t think ive heard about any privacy issues regarding modems. They convert your data into the Level 1 format so that it can be moved to the next hop. There isn’t really anything to spy on, and its very hardware dependent (hence no open source software that can standardize across each device). There might be open source modems out there, but your ISP probably doesn’t support them.


As you wish. But maybe open up to some new perspectives.


What does a healthy opinion of F-Droid look like though? Lol


Well, then its still 2FA. Something you are and something you have.


The website has to build in support for them. Youll start seeing it more over time.


To be fair, you cant use the passkeys unless you are logged into your password manager, which requires a password you “know”.



Yes, verified boot will have out-of-bands alerts for you by design. Without the online component, you will risk not being able to detect tampering.


If the hardware is tampered, it will not pass the attestation test, which is an online component. It will fail immediately and you will be alerted. Thats the part of verified boot that makes this so much harder for adversaries. They would have to compromise both systems. The attestation system is going to be heavily guarded.


Compromised hardware doesn’t know the signatures. Math.


If the hardware signatures don’t match, it wont boot without giving a warning. If the TPM/Secure Enclave is replaced/removed/modified, it will not boot without giving a warning.


Thats correct. Thats one of the many perks.


Its more about protecting your boot process from malware.


Why exactly am I re-reading your post? Im in complete agreement with you? Should I not be?



Having Signal fill in gaps for what the OS should be protecting is just going to stretch Signal more than it already does. I would agree that if Signal can properly support that kind of protection on EVERY OS that its built for, go for it. But this should be an OS level protection that can be offered to Signal as an app, not the other way around.


If your device is turned on and you are logged in, your data is no longer at rest.

Signal data will be encrypted if your disk is also encrypted.

If your device’s storage is not encrypted, and you don’t have any type of verified boot process, then thats on you, not Signal.


Feel free to submit a pull request. We could use your help.


You can get an Apple TV, which is an external device you connect to your TV if you’re already in the apple ecosystem. You can use your iPhone as a remote for it.

There is also the Nvidia Shield option, which is a solid Android TV option.

And of course, you can just use any pc as an input device and use that.

The firmware thats actually on the “smart tv” might be tough to replace with an open source solution. Im sure there are some TV modders out there, but its probably very niche. Best to get an external device of your choice imo.


There was a lawsuit to remove Windows Explorer? Did you mean to say Internet Explorer?


Each developer will have to be authorized by Apple to switch engines “after meeting specific criteria and committing to a number of ongoing privacy and security mitigations,”

Now they can babysit other browsers and make sure they’re secure too, ig. Might as well throw that responsibility on the trillion dollar company. At least the browsers will end up more secure once the apple security team audits them.


The lack of updates to old devices might be exactly why apple doesn’t want to be compatible with them. It’s a HUGE attack surface. They can’t babysit every device’s downfall.



Sure. An ex-boyfriend doesn’t take the breakup from his girlfriend well, and decides to locate her. He remembers his phone used to be paired with hers, and decides to use that to find her.

As much as you want to fight me and make fun of me for this, this is a serious concern.