• 3 Posts
  • 118 Comments
Joined 2Y ago
cake
Cake day: Dec 28, 2023

help-circle
rss

Thanks for the hint :) probably going to switch from SimpleX to this one :)


opened in assigned Firefox containers

Is there any kind of automate way to do that? Because if you have always to think what account goes in what container :/ This is a lot of brain overheat !


I like rethinkDNS :) but their wireguard implementation Is? Was? Kinda broken :/


Tech literates people tend to be more aware, but people who don’t even know what OS means/is…

I’m the only person in my family that has some IT knowledge and believe it or not, everyone in my family things that way… While swipping, scrolling, posting on GAFAMs and publicly exposing all their life ^^. In my friends circle it’s the same… Those who don’t know what an OS is respond the same way.

So it’s mostly the lack of knowledge of what privacy is, in the digital world… Because in real life most people put curtains behind their windows, so people won’t snoop on your hidden secrets.


Sorry, you've been blocked. Your IP address has been flagged for abuse.

Please enable JavaScript to continue.

Something went wrong, and we couldn't create your account. Please start over.

Your account has been flagged as spam.

My god how many times have I been through this… Living with debloated phone, hardened browser, VPN, Linux, sure isn’t easy every day :/// !

I totally agree, It shouldn’t be soo hard to value your own data/privacy and sometimes it feels like I’m fighting the wind.


How so? I’m not doubting your info but how does a browser provides more security than a native app?

Seeing all those upvotes, this must be true somehow… However I was certain that native apps are more secure than webapps.

Do you have any reputable ressource to backup your claims?


Ugh… Movin Facial recognition, what a joke. I put them on the same level of stupidity as those who put Tesla’s AI chip in their brain.

Sad days for privacy and anonymity enthusiasts 😮‍💨😮‍💨


Yeah… After a user here on Lemmy pointed out that the AdGuard app on mobile made a lot of strange requests to ads services, I gave it a try myself with PCAPdroid and seeing all thoses requests made by only opening the app made me think twice about AdGuard…

Removed all their services from my network and a happy piHole + quad9 user since !


It’s not 1 way sync. Please look up what you’re talking about before speaking.

Yeah it’s not, however you can configure syncthing as a 1way sync solution and I was emphasizing that this still isn’t a cloud solution.

Don’t get me wrong, syncthing is great and I use it everyday, but syncthing is not a cloud solution.


Syncthing is not a cloud solution though… Rather a sync solution. What’s the difference? If you delete the file on 1 device it gets deleted on every device who shares the directory…

While a Cloud solution, your file is on a central server and you can download/delete that file on your device without affecting the server.

Cloud service ≠ Sync service but have a similar purpose.

Edit: And doin’ 1 way sync is still not a cloud service !


Not addicted but I love to show those low numbers from my degoogled android or Linux system compared to Windows and Apple 😁 !

It’s hard to explain what DNS is, but numbers everyone can understand them !

“You see all those number go up? In 1 day your device makes more blocked requests than my devies did in 1 month !”


But as in every field it’s hard to teach even the basic stuff to others without deeper understanding of the field.

That’s so true, but even more true in IT… It changes so rapidly and things don’t stay the same over time… It’s not like a degree in Biology where things you learn stay relatively the same !

IT is 5 inches deep but miles long ! (Something like that!)


Yeah, this is so fucked up ! When you archive reddit pages, those are over 20 fucking MB for just a conversation ! That’s fucking insane…

I can reduce it to less than 500KB with alternative frontends, but still… This makes absolutely no sense and I’m scared to find out what they are hiding in between all those lines of code !


Not only that… The meat industry is poisoning the animals with antibiotics, GMO cereals… they live in 1m2 of space/cow, and living in hell 24/24, feel anger, hate, sadness and treated like shit and pure pain while beaten by humans… It’s horrible !!

And all these things are digested by our body… Ugh ! It’s similar to a concentration camp but for animals…


Yeah, some consider a room in a Prison a luxury resort 🤷‍♂️!


Not a dev here so I have to trust what I’m hosting on my server…

I do check the issue section and base my opinion on how healthy a repo is and how long it hasn’t been update.

Based on popularity also helps a bit? Check how san their docker-compose is and how complicated and what closed source thing they integrate in the image, but that’s it !

However, on android I do some app analysis with PCAPdroid to check what strange communications is happening behind the scenes.



The iPhone is also a viable option

🤭


Yeah… People are like this… It’s All fake news until it isn’t anymore and than everyone is Pikachu Faced…

After all they have done and still doing… I can ASSURE and GUARANTEE you with 100% certitude that they would NEVER do that… They are not that kind of evil. /s

Sigh 😮‍💨😮‍💨


Hey thanks for asking I had the same question !!

A solution I would like is an automated way to poison my old data and edit all my old post, change image and edit all my comments with something non related and totally false.

After some digging, their api is very limited and doesn’t allow such thing very easily. My programming skills beeing very limited I gave it a try with AI (yeah I know this is kinda “hypocrite” but we have to fight their empire with their own weapons…) and found out about a very cool tool you can selfhost and give instruction to execute this kind of operation in an automated way with AI !

It’s called browser use and it’s the open source alternative to ChatGPT operator. I haven’t tried it yet so I can’t give you any feedback but If that’s something you have the horse power for you can give it a try to slowely poison and edit all your facebook data without hitting their limit or their alert !


Haha, yeah It seems so…

Another option and a more long term solution would be to go back to the roots and relearn the basics of living !

How to grow a garden, How to hunt, How to build a small wooden house, how to make fire and then rebuild the technology but only the needed ones.

If we grew things and dug together the rare ores to make solar panels together, build small wind turbines, waterwheels as a community hands by hands… We would probably profit more and enjoy ourselves way more than ever…

Regardless we prefer being held hostage by our own limitations and technology constraints… Not blaming anyone here except myself, It’s just a sad though we could all live happy in a more green state without this mass nonsense technology…

But hey… What’s better than living for ourselves and hard earned money? Huh? Our day to day routine on Netflix, YouTube, Lemmy, twitter Facebook… 7-16 day to day job we all hate thinking we are going to enjoy life when we are old and retired? Emotionally dead gifts bought on Amazon, eBay, temu…

Without saying… Life sucks ! And If you enjoy this kind of life, What can I say… :/ I either envy you for being a brainless sheep or hate you like I hate myself for not burning down this system all together !

Pick your poison !

/Rant off


Yep… Snowden, Chelsea* Maning, Assange and an older whistleblower who died recently but I forgot his name… They also forgot what Cambridge Analytica was about. They just need to throw some bread and games at us and we go one living as nothing ever happend.


There’s also a third possibility most people ignore for what ever reason…

Speech-to-text and send to servers. No need for heavy CPU usage that way and don’t need to send MBs of Audio files…

With the technology we have today it’s easier than ever before… “colgate” and give you right into your face an ad for toothpaste !

No need for audio or complex processing. All new models come even with AI processor units… Haha ! What a joke !


But they do want to spy on your dick pics… That’s the real purpose here ! They don’t care on the war of drugs anyway.

Dickfingerprinting !


Yeah individually your data is approximately worth 200$/year (that’s a real estimation I read somewhere, not something I spit out of my ass).

So yeah not much worth you’re right. But if you stop being selfish for a moment and think as a community and take that portion for 1 billion people on earth, how much is that worth? Yeah you guessed it… It’s a huge amount of money ^^ !

So stop thinking only for your self and start to think how we are all involved in this shit and should fight back as much as possible…


Ohhhh ! Docker container are awesome. If you have an old spare laptop lying around (or you know someone who has) give it a try it’s fantastic ! It similar to a virtual machine but different ! It solves the big issue virtual machine have: fast, portability, lightweight, memory efficient… It shares the underling OS !

I have a 10 years old laptop which is going strong with over 21 docker containers which couldn’t be possible with VMs ! You can host any imaginable service (if available as docker image) in seconds, behind a reverse proxy and access it through your LAN (or externally over a Wireguard connection).

Let’s take a media workflow example, if you want to get rid of something like YouTube music, spotify, deezer… and maintain your music library and own your music:

You can self-host:

  • Navidrome to maintain your music library
  • MeTube to download YouTube music (yt-dlp frontend)

Install NewPipe (Hope you’re on Android :s) and HTTP-shortcuts to glue everything together ! HTTP-shortcuts allow to communicate with your self-hosted MeTube service via POST/GET requests and send directly your files to your MeTube instance via NewPiped. You can than have a background script on your server which: Removes and changes the pesky YouTube metadata, send your files to your Navidrome service !

This is a rather “complex” workflow but just to say it’s possible. Sure depending your skills with your OS it will take some time to get accustomed to docker containers and the like ! It took me approximately 1 year to really get accustomed to all this new workflow (and get the hang of linux), but now it’s only a matter of minutes !


Another use case for your phone: encrypted backup for docker containers ! Nowadays they come with a lot of spare space (over 120 GB). Encrypted, scrambles file/directory names and archived !

I wouldn’t backup any critical data this way though ! It’s more an “in case” emergency backup for docker database and config volumes !


Same thought here ! Wireguard being based on private/public key, even if the port is open every request that doesn’t have a valid private/public key gets dropped !

From a bot’s perspective this means the port is closed !

I’m not an export in the field but there’s also a way to only use key-based connection with SSH, but I’m not sure how good/secure it is compared to wireguard.

As you said, I’m also too scared to let a open SSH server running on my small home lab 😅 !


That’s some crazy stuff ! Being able to completely change/repair every part is something every smartphone should be capable off…

We are in a buy/throw away generation amidst a big climate change issue/rare ore depletion… That’s depressing.


A better example to show that SMS’ are insecure are the Signalling system 7 protocols.

While it is possible to incerpte SMS, phone calls and 2FA (kinda scary…) it comes with a high cost (14k) and some technical skills.

However, if you are a vulnerable target, just don’t use SMS or any smartphone. Geotracking is also possible !


[Discussion] Veritasiums: Exposing the flaw in our phone system.
YouTube link: https://youtu.be/wVyu7NB7W6Y Invidious link: https://inv.nadeko.net/watch?v=wVyu7NB7W6Y Sorry for the formatting... Tried to remove the URL for better readability, but there seems some kind of bug. --- TLDW - hack phones remotely just knowing it's phone number - Intercept 2FA sms - Intercept phone calls - Reroute phone calls - Geolocation of a target --- I dunno if it has already been posted/discussed here but this kinda blew my mind ! Sorry there's a lot of clickbait but the general subject is interesting... I never heard of SS7 and have actually no idea how the whole phone system communication works but that's kinda scary... Yes we are probably not the first target with this "hack" nor is it as easy as exposed in this video and nor do we have 14k $ to spend on this, but that's not out of reach for some people. I mean it's not as expensive as Pegasus and people with the mean and some good stable income can probably misuse this system for targeting specific vulnerable people (example in the video).
fedilink

I get you ! And you’re right. It’s never to late though, until it is. We/they have been betrayed more than once by big tech and monopoly, so I think it’s justified to feel a bit anxious when something out of bound to user’s privacy/consent is implemented in the only real alternative we have right now…

I mean, sure Firefox is the only last bastion against big tech’s monopoly and all forks are depending on Firefox… So that’s not truely a real long term solution as alternative (If something is going to happen…). But as a long term Firefox user, I also have the feeling they are slowly following a dark/uncertain path.

Sure, right now it’s not that of a big deal, but what if in 3 years it becomes a big deal? Imagine a scenario where all web browsers become controlled by one single entity? Wouldn’t it be good to have an alternative? (Yeah there is Tor already) This is only possible in this kind of “hysteria” where some people take the lead before it’s too late, otherwise we will be stuck for years without any working solution, while depending on big data’s scrapper/hoarder riddled with ads and privacy invasive browsing…

Hope it make sense and that my arguments are somehow comprehensible? Not my first language so giving my best haha !

Edit: It’s not a matter of if, but when (but I hope that doesn’t apply to Firefox)

Edit2:

Just think about the Linux kernel, right now it’s the only best alternative to Windows/MacOS and everything is perfect. But what will happen in a few years when Linus steps down? Will it still be as good as today? Will big tech take a step into the kernel? Will it become the next Windows/MacOS? Who knows… That’s why alternatives are always a good thing to have before it’s too late !!


Or you can stay on a sinking ship convince yourself “It’s fine !” until it’s too late?

Whatever chose your poison 🤷


LibreWolf is great ! Coming from ArkenFox, I found LibreWolf’s override cfg a bit easier.

They also have a pacdiff cfg to see what changes from version to version without the need to roam arkenfoxes github repo for hours to find what changed or what to change.

I installed it yesterday to see how it goes :) If it doesn’t fit, will go back to Arkenfox.


No sponsors, no ads, customizable and watch YouTube videos without a premium account?

Edit1: Lighter UI

Edit2: There’s a way to use a VPN and split tunneling but didn’t dug that far right now. So it’s still possible to have the privacy feature if that’s against your threat model/privacy concerns.


I think the best thing to do is selfhosting your own instance :/ piped is doing a great job with their script to install with docker ! Yes I know this takes away the privacy feature allowing google to get your public IP and other annoying metadata… However all the rest works as expected !

It has some quirks right now though… But they are very close in solving the issue (already done with LibreTube ).


Most of the telemetry can be disabled in the Firefox settings. Some of the web services depend on some Mozilla domains so blocking all Mozilla domains will probably break a few things here and there?

Other than that, with the current situation, I would already think to switch to a Firefox fork or other alternative.

Firefox is walking a very dark path right now and you can see/feel how they are slowly rolling the enshitification path :/


I tried belenaEtcher once on my Mac… And it seemed to me more like a spyware than an actual software, I was a bit confused and never used it again.


The thing is…you can’t ! This is more or less a personal “enlightenment” ! You can forward your arguments, say what you know and why one is better than the other, but it always comes to personal experience ! If you’re not ready to change, you’re not ready, even with the best argument in the world, people tend to always change when they personally experience something.

Don’t push yourself or others, this will only cause frustration and anger. Do what you can but don’t expect others to change/think the same way you are…

I know this is very vague and doesn’t solve your actual issue, but that’s the best you can do :)


I have a strange bug where RethinkDNS wireguard session keeps failling after a while if my phone is not used for a while.

I have to reconnect my wireguard session or it just doesn’t work. I need to ADB and check the logs to see what’s happening and write some kind of bug report to rethink’s DNS bug tracking support.

It’s not the first time they have some kind of misbehave with their firewall and wireguard tunnel. Other than that, RethinkDNS rocks !!


Yeah :) piped self-hosting !

However, we have to wait until they merge the poToken and visitor data issue. Something invidious has already implemented.

Still it’s very strange you have to restart your container every hour :/ I’m sure I’m to stupid to understand the backend/code to make any sense out of it, but piped instances never had to restart anything.


Sharing my personal Firefox user.js based on arkenfox’s privacy policies.
Hi everyone :) For those interested, I share my just finished personal Firefox `user.js`. It's based on the latest arkenfox and has the same privacy features, with some personal tweaks to fit my workflow. And also easier to read 😅. https://github.com/KalyaSc/fictional-sniffle/blob/main/user.js --- ## KEEP IN MIND Except for the privacy focused entries, some are personal choices for an easy drop-in Firefox preferences backup. This is what I consider a good privacy model and some entries could break YOUR workflow, especially if you don't have self-hosted alternatives ([Vaultwarden](https://github.com/dani-garcia/vaultwarden), [Linkding](https://github.com/sissbruecker/linkding), [Wallabag](https://github.com/wallabag/wallabag)). I'm not an expert, but most of those entries are the same as [Arkenfox's user.js](https://github.com/arkenfox/user.js/blob/master/user.js). I really encourage you to read their file for better understanding on what each entrie does. While my file is easier to read, one downside is the lack of documentation for each entries. Also, this is not just a COPY/PAST. It took a lot of effort, time, reading, testing and understanding. I kept a similar naming scheme for cross referencing. I learned a few things and hope that you also will enjoy, edit, read and learn new interesting things. Happy hardening ! --- ## Features - Automatic dark mode theme (Keep in mind you still need [Dark Reader ](https://darkreader.org) or similar plugin for web pages in dark mode.) - Deep clean history on every Firefox quit. Only cookies as exception are kept. I need them for my self hosted services. - Disable password/auto-fill/breache. Vaultwarden takes care of everything. - All telemetry disabled by default except for the crash reports. To also disable the crash reports, comment the begining of the following lines with `//`: ``` user_pref("breakpad.reportURL", ""); user_pref("browser.tabs.crashReporting.sendReport", false); user_pref("browser.crashReports.unsubmittedCheck.enabled", false); user_pref("browser.crashReports.unsubmittedCheck.autoSubmit2", false); ``` - DoH disabled (got my personal VPN with DoH enabled) ``` user_pref("network.trr.mode", 5); ``` - Disable WebRTC. If you need it for video calling, meetings, video chats: Comment the following line: ``` user_pref("media.peerconnection.enabled", false); ``` Uncomment the following (arkenfox default, it will force WebRTC inside your configured proxy) ``` //user_pref("media.peerconnection.ice.default_address_only", true); //user_pref("media.peerconnection.ice.proxy_only_if_behind_proxy", true); ``` - FIxed Width and Height (1600x900) (Finger print resistant) arkenfox's default - Resist Fingerprinting (RFP) which overrides finger print protection (FPP) - Alot of other tweaks you can discover while reading through the file. ## How to use/test this file ? Open firefox, type `about:profiles` and create a test profile. Open the corresponding root folder, put in the `user.js` and launch profile in a new browser. After testing and happy with the result, `BACKUP` your main Firefox profile somewhere safe and put the `user.js` in your main profile to see if it fits your workflow. ## Room for improvement / TODO. Alot of the settings in the 5000 range form arkenfox's user.js need further testing and investigation, because they could breake and cause performance/stability issues. - JS exploits: ``` - javascript.options.baselinejit - javascript.options.ion - javascript.options.wasm - javascript.options.asmjs ``` - Disable webAssembly - ... TODO - Disable non-modern cipher suites - Control TLS versions - Disable SSL session IDs [FF36+] Also those settings are another beast that needs further testing/investigation on how they work. ## The user.js file https://github.com/KalyaSc/fictional-sniffle/blob/main/user.js ## WARNING Arkenfox advise agianst addons who scramble and randomize your fingerprint characteristics (like [chameleon](https://addons.mozilla.org/en-US/firefox/addon/chameleon-ext/)). WHY? Because resist fingerprint takes care of most things. See [4500: RFP (resistFingerprinting)](https://github.com/arkenfox/user.js/blob/master/user.js) in arkenfox user.js. ``` [WARNING] DO NOT USE extensions to alter RFP protected metrics 418986 - limit window.screen & CSS media queries (FF41) 1281949 - spoof screen orientation (FF50) 1330890 - spoof timezone as UTC0 (FF55) 1360039 - spoof navigator.hardwareConcurrency as 2 (FF55) FF56 1333651 - spoof User Agent & Navigator API version: android version spoofed as ESR (FF119 or lower) OS: JS spoofed as Windows 10, OS 10.15, Android 10, or Linux | HTTP Headers spoofed as Windows or Android 1369319 - disable device sensor API 1369357 - disable site specific zoom 1337161 - hide gamepads from content .... Very long list ! ``` ## Final words I'm open for any constructive criticism or any constructive comment that could help me out to improve or understand something new or something I misunderstood. Sure that's not 100% my work, but as I said it took a lot of time, testing, searching, reading... Please don't be a crazy Panda... ## Credits [https://github.com/arkenfox/user.js](https://github.com/arkenfox/user.js) [https://github.com/pyllyukko/user.js/](https://github.com/pyllyukko/user.js/) [https://wiki.archlinux.org/title/Firefox/Privacy](https://wiki.archlinux.org/title/Firefox/Privacy)
fedilink

AdguardVPN sketchy DNS requests.
After the discussion in the following [post](https://lemmy.ml/post/13144346) I dug a bit deeper the rabbit hole. While I mostly relied on [Exodus](https://github.com/exodus-privacy/exodus) to see if an app has trackers in it... I was baffle to see all the sketchy requests it made while dumping the DNS requests with [PCAPdroid](https://github.com/emanuele-f/PCAPdroid)... Over 200 shady requests in a few seconds after login... here's a preview: ![](https://lemmy.ml/pictrs/image/2f5823c3-880a-4d71-9728-115f7c9f1a82.png) While I don't use AdguardVPN, I have Adguard Home as my DNS server in my homelab... I think It's time to switch to pi-hole ! Edit: VPN pcapdroid ![](https://lemmy.ml/pictrs/image/626369ed-874b-4c5c-b878-727a5e1d526a.jpeg) ![](https://lemmy.ml/pictrs/image/0ec9993f-3757-4132-9f22-529d9e1d7a33.jpeg)
fedilink