• 66 Posts
  • 512 Comments
Joined 4Y ago
cake
Cake day: Jun 07, 2020

help-circle
rss

I like AdGuard, but any decent provider is going to be fine except for Google/Cloudflare or western Big Tech ones.


The amount of leaks iOS intentionally does, let alone the part where they tell you to use their own (not so) Private Relay feature, is enough to stick around on Android.


I think the problem is Reddit user (who Mullvad cites) not knowing that the Private DNS feature in AOSP/Android defaults to Google or Cloudflare DNS, and that you need to set a custom DNS of your choice to prevent this.

AdGuard provides a whole list of DNS providers to pick from. Pick a hostname from DNS-over-tls row for any provider, remove the “tls://” part and enter the rest in Private DNS custom option.

https://adguard-dns.io/kb/general/dns-providers/



Wow, what an excuse to not do workouts. Equipment is cheap if you want to workout in privacy. As long as you have a small room worth of space at home, it is doable.


The sole reason for getting an iPhone when you get a “job” is to appease colleagues using this fake societal status currency and to show the world that you have “levelled up” in life. There is no longevity or battery life reasoning for it. It is all sugarcoating nonsense. My friends and family do not even have iMessage needs in India, and this is exactly what goes on. Your “fuck XYZ” is also just posturing to hide that fact, like it or not. The moment all your “important” colleagues have newer iPhone models, you will sell this one and get new shiny one to try and keep up with the Joneses.


As a Tor user since over a decade, I do know that I think. What I also know is Firefox is not one bit safe for Tor usage. Use the official Tor Browser or TailsOS.


Apple is a honey trap. You cannot exit out of Apple ecosystem once you get into it. However, it is very easy to go from Android to Apple. There are plenty other problems with Apple known well here. But the biggest one folks like you will hate to admit is you want to appease other people socially with this fake currency called iPhone. It is shallow, and you willfully encourage it because you do not want to be “left behind”. How do I know this? Every single “job” person that scrambles money to get an iPhone does it for this reason, no exceptions. And that includes people in my family and friend circle.

No, I have no interest in inventing fake respect for people that want to appease and encourage consumerism. Battery life and longevity are not the reasons you got an iPhone for. I guarantee this. You are going to charge an iPhone before the next morning you head out of the house, same way as Android.


And Firefox is not very secure for Tor usage. Tor Browser and TailsOS are the only proper tools to use Tor onion network.


Apple is a garbage company. If you buy their phones for anything other than iMessage cult needs, it is on you. Buy the cheapest worst iPhone as secondary and keep a main Android phone, if your social life has such a requirement, otherwise respect yourself and buy Android phones.



Tor and I2P have nothing to do with clearnet. And if you want to use Tor, use it through official Tor Browser or TailsOS.


I did not know mocking people is serious instead of mere contribution to discussion. Is that not what you are doing with the whole defeatism thing? I did not remove your jab comment at privacy initiative, why remove their little jab?


Doxxing who? Is this not just a discussion? Your comment was reported yet not removed.



You must enable always-on VPN killswitch in Android VPN settings, and put Invizible in VPN or root mode, instead of proxy mode.

Rethink dev has spoken to me multiple times. He has made a very good app, even incorporated changes I recommended, but it can stop functioning at times abruptly, according to a fellow friend who tested it thoroughly. Invizible is more stable, so I am yet to change recommendation, since I recommend Invizible for heavier, hardcore setup and NetGuard for easier, relaxed setup. I am currently off of Invizible after 3ish years and daily drive testing NetGuard to see how well it is working.


My well known non root smartphone hardening guide is based on the long term trustworthiness and capabilities of Invizible Pro (and NetGuard). I never recommend or touch projects that will go defunct unexpectedly, or have garbage persons developing behind it. Invizible is an amazing project which has had no equivalent for years now, FOSS or not. And it itself is FOSS, made out of other FOSS projects.


What nonsense is this? It is an amalgamation of NetGuard, I2pd and Orbot, along with a lot of additions to it. Nothing competes with it at all, and has not since years, even though it is FOSS and made by one person. I thoroughly test and use it, and my non root smartphone guide is based on it, that is how great it is.


One party scares you dumb people into believing Russia interferes with your elections, the other scares you into thinking China interferes. Meanwhile, all the interference is going on within USA by white house and Congress terrorists.

The reasons China banned US platforms is not the same as ones US is using to do vice versa.


Do you even know the problem with Steam? It reads DNS cache from storage to spy on users’ personal Internet browsing habits. Filesystem sandboxing solves that problem. If your problem is game analytics, then you may have much bigger problems on your hands. OP might not be as tech savvy or paranoid as you. And if OP is, consider providing good, non malware 🏴‍☠️ sources to OP via a link or comment from elsewhere.


Ukrainians made their own choice in 2014. There was no US “coup”.

Ever heard the leaked call between Victoria Nuland and Geoffrey Pyatt? Or is that leaked call Russian propaganda too?


So democracy is now worse than US coup dictatorship? Decide if you want to call Ukraine sovereign or not. US puppet means Ukraine is not sovereign.



Ukrainian self determination ended with CIA coup in 2013. Ukraine was no longer a sovereign state from that point when Yanukovich, the democratically elected president, was forced to flee his country. CIA’s coup in 2003 failed and Ukraine was still sovereign until 2013.

Honestly, you should be scared that Zelensky has said twice that he wants Ukraine to be the new Israel, and begged for WW3 last year.


Work profile sandboxing. Quick, simple and sure way to be safe. Use Island or Shelter from F-Droid.


I am the moderator, just in case you forgot. Funny insult to double down on western nationalism, right?


Can you provide documentation that says AppOps is not standardised part of AOSP? Last I checked, it was part of Android since Android 4.3 beta and baked into 4.4 Kitkat.

I use both ADB and Shizuku based permission manipulators on Android, and the “ignore” option just defaults to “ask every time” or “deny” instead of “allow”, in case it does not work. I have not yet observed a failure upon extensive testing.


And yeah really, try to convince your wife girlfriend to use signal instead. Or hell, even whatsapp is miles ahead.

It is interesting that you promote Facebook over WeChat in a privacy community, even though you have a Chinese wife. Just how far is racism embedded in your head to go through hoops saying things like this? Is it objective analysis to claim WeChat (China) is worse than Facebook (USA)? Or that Signal, something based in USA, using USA servers, promoted by Elon Musk and using a shady MobileCoin crypto system, is so great?

Encryption of messages is not a thing on WeChat, but then neither is WeChat being used to extract meta data and use it to commit genocides or bomb countries, like USA based messengers do.


Please be just a little less aggressive. Lemmy users do not need to stoop down to Redditor tier levels. With a higher standard comes better behaviour responsibility. Remember, most of us came from Reddit because it became shit.


Use. Lockdown. On. Your. Phones. It is easy and prevents legal shitbags from literally forcing your hand.


Read the paper by Ken Thompson, co-creator of Unix and C, on why we should be able to trust the developer and NOT the code. https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_ReflectionsonTrustingTrust.pdf

I do not trust Mull’s developer if he does not have a spine against the threats of scum developers like Daniel Micay. Today he caved to Micay, tomorrow feds? Simple as that. And it is not like it is much different than Firefox with uBO medium mode + uBO filters.


User agent is constant, and fingerprints stay similar on average. Privacy Browser is not so much… private. It is just a wrapper for Android Web view.


I am afraid to tell you that it has an extremely unique user agent that serves to fingerprint exactly the few of you that use Stoutner’s Privacy Browser. Avoid using it. I used to use it quite a bit once upon a time, and that is how I know about it.



It was okay until Daniel Micay, in DivestOS’ XMPP chatroom, was accusing me of the typical “harassment ringleader campaign” BS, and ordered DivestOS/Mull developer that if I was not banned immediately, DivestOS and him would face social media targeted harassment campaign and DivestOS will have to forcibly pull off any borrowed GrapheneOS code. DivestOS developer dusted his hands off me, since unlike Micay, I am not a witch hunting crybully asshole, so it is safer for him to cave in.

https://i.imgur.com/Al65uTZ.jpg

https://i.imgur.com/mT8W9pa.jpg

I stopped using Mull, and switched to Firefox with uBlock Origin medium mode. No issues.


GrapheneOS is pure snake oil with a disgusting sole developer that believes in pushing corporate Big Tech propaganda, harassing and witch hunting any critics, having a little social media army with sockpuppets to do this, abuses mentally challenged by hiding behind “autism” label (Louis Rossmann has a nice video), falsely claims he was swatted without giving evidence or coverage in local Canadian media and blames everyone from redditors to community mods to YouTubers and so on.

I covered this disease for about 5 years, and it emanates from the same sewer that “security” clowns like Brad Spengler and madaidan do in Linux community. All they do is either push their bullshit solutions or push corporate Big Tech propaganda and hate any FOSS project they think will not worship them.

You can read my documentation of this lore here.

https://old.reddit.com/r/privatelife/comments/ug9qnc/writeup_criticism_of_rprivacyguides_grapheneos/

https://old.reddit.com/r/privatelife/comments/13teoo9/grapheneos_corporate_foss_loving_witch_hunting/

Most of the security measures in Graphene are something you can take with lots of Android devices, and is nothing exclusive to Pixel/Graphene fairy tales. Micay and his minions just love selling that combo as the only solution, and I frankly hate it as it has no basis in reality.

Please read the paper by Ken Thompson, co-creator of Unix and C, on why we should be able to trust the developer and NOT the code. https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_ReflectionsonTrustingTrust.pdf


I do not think trusting closed source for networking/mobile devices is a very smart idea. This is why I never recommend Pixels or iPhones either. Go OpenWRT or bust. The lesser and more common closed source hardware/software layers are, the safer, but still not safer than open sourcing.


Separate web browser or browser profile with no logins, just uBO medium mode, and no Big Tech bullshit. This means any Chromium browser is ruled out.


Your table is wrong. It should be Demorepublicrat party only.


I was observing this issue personally, as I prefer Proton to Gmail/Outlook duopoly. A sigh of relief.
fedilink


Firefox 115 can silently remotely disable my extension on any site [Jeff Johnson’s blog]
I stan Firefox but I am scared about this to the point not much discussion exists on this.
fedilink

Please report bad behaviours in accordance with Lemmy rules and Code Of Conduct! Here to cushion the
lock
pin
Lemmy is not going to be Reddit. It will not inherit the reactionary behaviours. Ensure civillity and disengage if uncomfortable. Have a good time!
fedilink


Energized GitHub has been unmaintained since few months, and is showing 404 error on HOSTS files. He
cross-posted from: https://lemmy.ml/post/830873 > The HOSTS ruleset has been not maintained for a while, and that is not very helpful. This is a copy of Energized Ultimate from April 2022 that I am still using just fine. https://www21.zippyshare.com/v/qRxZ0lp9/file.html > > The various lists that Energized project used in combination can still be referenced. https://i.imgur.com/yZRDVAl.jpg > > I think **1Hosts PRO** is a good replacement, but try Lite or Pro whichever you prefer. https://github.com/badmojr/1Hosts You may try combining other HOSTS lists with this if you want to, and are technically adept enough. > > Another good option is **AdAway**, but you might need to combine other lists with it to have competent blocking compared to Energized. > > You also need to reference, download and merge spam and phishing lists manually if you want extra protection, unless you want to rely solely on DNS providers. I prefer having both HOSTS ruleset systemwide and a DNS provider, then whatever network firewalling/tunnelling is needed.
fedilink




[X-post] [WRITEUP] Criticism of r/privacy, r/PrivacyGuides and GrapheneOS communities, moderators an
The purpose is only for this to reach more audiences. I have documented this over many years.
fedilink

r/PrivacyGuides restored citation-less slander post as facts, and GrapheneOS community sockpuppet th
cross-posted from: https://lemmy.ml/post/143981 > Mod statement: https://np.reddit.com/r/PrivacyGuides/comments/rxf02a/theanonymousjoker_false_privacy_prophet/hs1dxux?context=3 > > https://i.imgur.com/LahmNkO.jpg > > dng99/dngray has branded a citation-less slander post as facts. These are the "community standards" of r/PrivacyGuides. Always remember this. > > u/trai_dep, the record stands corrected once again > > Moreover, my theory about GrapheneOS community using sockpuppets is true, as confirmed by... > > https://np.reddit.com/r/fdroid/comments/rxtc14/came_across_this_thoughts/hs1o6no?context=3 > > https://i.imgur.com/JX6uTpx.jpg > > Tommy_Tran = B0risGrishenko (OP of slander post). Thanks for confirming my GrapheneOS community sockpuppet theory.
fedilink

r/PrivacyGuides is allowing a personally targeting post with my name in post title currently, slande
https://teddit.net/r/PrivacyGuides/comments/rxf02a/theanonymousjoker_false_privacy_prophet/ This is one of key GrapheneOS community members doing it, and r/PrivacyGuides has the same moderation team as r/privacytoolsio before, and the main moderator of r/privacy is also same. Has anyone seen this kind of behaviour in overall privacy community? Edit: https://ghostarchive.org/archive/ttkkU reddit post archived
fedilink

100% FOSS Smartphone Hardening non-root Guide 4.0
https://lemmy.ml/post/128667 Crosspost but the guide body is so long, I had to break it into 5 parts.
fedilink



[TINY GUIDE] How to stay safe from Pegasus and most social engineering malware these days
cross-posted from: https://lemmy.ml/post/74540 > Hello! I think it is a nice time to re-mention some 101 tips of IT security for folks here, that I also practice. Pegasus malware investigation will be big news for a good while, so the more awareness it helps spread, the better. > > # RULE 1 > > DO NOT CLICK ON RANDOM SMS AND EMAIL LINKS. Please, do not do this, ever. Just do not do it. Do not do it. Do not do it. Do not do it. > > Yes, that is how many times I repeated that line. That is how important this rule is. > > Also, do not download random email attachments. > > Phishing is such a common tactic that one would think this problem has been solved by now, but it has not. > > # RULE 2 > > Keep OFF auto download of photos, videos, documents and so on on WhatsApp, Signal and such apps. > > Drive by downloads being self executable surprise bombs is not a new thing. Basically, this rule is similar to keeping off AutoPlay for external USB sticks on Windows computers. > > # RULE 3 > > Avoid using popular software too much. > > I get it, this is a hard rule to workaround considering how much we need to use WhatsApp, Signal, Telegram and so on, so it is a lot better to compartmentalise your activities among multiple messengers. > > Pegasus and a lot of specialised malware uses zero-days to be able to design zero click deployment tricks, which is what these government surveillance tools are good at reserving. They use their millions of dollars of funding and R&D properly, so you have to be careful. > > As an example, try to keep WhatsApp internet turned off most of the times via NetGuard, and turn it on only when needed, a good method I have earlier suggested as well in my smartphone hardening guide. > > # CONCLUSION > > Those were some thoughts on the top of my head, before I go to sleep. Stay safe against surveillance! And feel free to ask whatever you want to!
fedilink


[Belarus, Russia] How ProtonMail Lost the Public Trust it Needs to do Business [Moon Of Alabama]
cross-posted from: https://lemmy.ml/post/67987 > A fellow sent this to me, providing proof of how ProtonMail is vulnerable to state actors and for any activism or non-regular activities.
fedilink


[PDF] Apple Transparency Report: Government and private party requests [Apple]
cross-posted from: https://lemmy.ml/post/60334 > Summary > > Out of 170K device requests, USA made ~56% (82% complied), Germany made ~11% (81% complied), China made ~8% (94% complied), Brazil made ~5% (85% complied) and Japan, South Korea, Hungary and Sweden made ~2% (~84% average complied). > > Total compliance rate is 80% according to Apple. > > For 85% of 31K iCloud accounts, user data was provided by Apple upon requests. 58% of these came from USA.
fedilink


Comment section for 100% FOSS Smartphone Hardening non-root Guide 3.0 (for normal people) ft. some a
Guide: https://lemmy.ml/post/54596 I locked that post due to Lemmy limitations for post word limit, and commenting on post would have spoiled the rest of guide put in comments as a hack.
fedilink

Check if your email leaked https://cybernews.com/personal-data-leak-check/
fedilink






Apple is an anti privacy company, but these nutrition label things are nice for marketing. Worth a look.
fedilink

[WRITEUP] Dissecting MASSIVE WhatsApp privacy policy change w.e.f February 8, 2021, explanations and
If teddit does not work, use Libreddit. Post direct link: https://old.reddit.com/r/privatelife/comments/krr7gf/writeup_dissecting_massive_whatsapp_privacy/
fedilink






[2020 SPECIAL] The good, the bad and the ugly - My outlook on the privacy community (My r/privateli
Shared Teddit URL, if Teddit does not work then use this old Reddit URL: https://reddit.com/r/privatelife/comments/k7vngo/2020_special_the_good_the_bad_and_the_ugly_my/ Lemmy has a 5000 letter limit, and my writeup is 11000 letters, hence the direct linking.
fedilink