• 0 Posts
  • 10 Comments
Joined 1Y ago
cake
Cake day: Sep 25, 2025

help-circle
rss

Self-hosted isn’t as unstable because you don’t end up getting blocked by throttling as often if you’re the only user. Public instances tend to get hammered by bots and LLMs these days. Just put it behind a reverse proxy with a login or a VPN to keep others out. I use keycloak SSO in Traefik on a VPS, but pangolin works well for my web apps in my home. That said, it requires setup and maintenance. But no tracking since you own the server.

But TBH no generalized search engines are really good these days. They all mostly all overrun either by monetization schemes and ads or have been manipulated by SEO, so rarely give good results. I’ve been exploring lots of alternatives, but not many are any good.


That’s odd, never had that issue and I’ve used it a long time. Even for my own domains changes propagate as quickly as any other DNS server I’ve used. Were your changes propagated to google, cloud flare, and the rest? Anyway, very weird since DNS propagation is pretty automated usually unless something is not propagating to any DNS server.


Quad9 is only a DNS server and I do use that for all of my servers as do many others. It doesn’t provide domain registration, domain dns configuration, proxies, tunnels, etc, that Cloudflare does.


I was doing a little more complex math than just the 1 in 122.7m. That seems to be unique browsers not unique human users. I added some calculations based on how many browsers are used by humans vs bots and various other nonhuman users. It’s extreme rough with a lot of guesstimation and rounding based on some googling. But that’s beside the point.

I was trying to figure out the difference between fingerprinting a Mozilla Firefox browser from the play store and the IronFox browser from Fdroid. I had expected it to be significantly reduced accuracy since it’s explicitly set up to be more resistant to fingerprinting than vanilla Firefox.

When I did some digging and looking at other sites. The biggest factor seems to be the combination of it reporting Firefox as the agent and having the DNT flag and the global privacy flag or whatever it is called. Since only Germany has been able to enforce those legally and only in a single case against LinkedIn, but no cases against the bigger tracking companies that aren’t user facing and thus wouldn’t even care about legal stuff since proving standing with that many layers would be difficult, Mozilla decides to remove those a couple of years ago as many people weren’t setting them and so it made people who were setting them more susceptible to fingerprinting since they were more unique. IronFox has argued that the settings should stay on because it’s legally enforceable in Germany and maybe some day will be I’m other places. But IMHO that doesn’t help people getting fingerprinted now or for the next many years. And now since IronFox is basically the only one doing it, the combination of Firefox agent and that header flag means it narrows you down to IronFox users almost exclusively other than maybe some people using really old versions of Firefox, but you could add some criteria that gibe you the version, too, and how many of those are there in the world. A very small percentage of all internet users. And combine that with UTC offset and if you live somewhere like UTC-1 I bet you’re the only user. LOL.

But even in other less tech savvy areas of the world it would be pretty small and a few more data points could easily get you a unique user. People in places like UTC+2 or mainland US, probably there are a lot more privacy thinking folks using IronFox or any other.

Anyway, I changed those settings manually in about:config based on feedback from the IronFox dev that it was set on purpose. But I haven’t had a chance to see how much less unique it made me yet.


I know IronFox and some other forks have a setting to change your timezone to UTC-0. But you’ll have to live with remembering to convert time on most websites unless you log in and your profile sets the timezone. Not a huge deal, but it trips me up more than I’d like to admit. Especially since I avoid sites that require logins. I have heard that you can get a browser plugin to change the time locally, but you’d have to trust the plugin since it will need access to all content on all sites.


I mean “1 in 122.7 million browsers look like” mine meaning it got me down to one out of about 2% of all internet users globally. I’d say it’s still pretty difficult to target anything at that many people and have it be relevant. Just knowing my location and that it’s a weekend basically gets down to that many or maybe fewer people on it’s own since fewer than that live in my city permanently, and adding tourists/visitors and people who work on weekends, that might be about right for how many devices are online in my city right now. And that was browsing with my less locked down browser on my phone.

Actually, looking with ironfox, though, actually reduced that to about 112m. I think part of that is that ironfox apparently still seems to enable the “do not track flag” even though it was removed from Firefox because it actually made people more easy to track and no sites who track are ethical so they are not going to obey something like that. So now it’s rare and makes for a really good tracking point. Need to figure out how to remove it from ironfox I guess.


I assume they mean compromised by apps that are installed on one or more devices that can access the keys to the conversations or even cracked versions of Signal itself planted during mostly illegal searches.

That’s not Signal being compromised, that’s the phone and is true of all apps running on compromisable phones. If not, I’d love to see the problem and they can point to the place in the app code where it exists since it would have to be the app and it’s open source. The server doesn’t have the keys for the messages. Unless they’re saying a standard encryption algorithm has a backdoor. Governments have been attempting that for decades, and I wouldn’t be surprised, but also not just affecting Signal since these are standards. And this should be especially shown as it could affect everything from banking to corporate VPNs and any backdoor is available to black hat hackers as well as government. Anything else is scaremongering from sources that are well known for doing just that and not afraid of outright lying, or “alternative facts”, not just manipulating actual facts for their purposes, which they also do on a regular basis.

Signal is not private since metadata is required for routing and reducing spam and falsifying identity. It’s a compromise of all e2ee messaging apps. And unavoidable without significant inconvenience in routing and no control over spammers/scammers, or 100% trust in the middleman servers.

But it is secure unless evidence is given and it would be super easy to provide evidence since all encryption and decryption happens on devices and no keys are shared to the server by the apps themselves as shown by said code.


It already is. In China if you access information on the Tiananmen Square massacre it has gotten you flagged for ages. In the US, if you access pro-Palastine information or abortion information, these things are then used to prove you are antisemitic or trying to get an abortion where it’s illegal, etc. The easier it is to link that access to an individual through a registry, the more commonly it will be used.


But in most cases, it is, because most adults are not that technically inclined to get around the logins. Sure there are some tech savvy ones who will bypass it. And maybe a few kids who will use their parents’ accounts rather than just bypassing the logins but it’s still the family accessing the information, but for the majority, it does work as a registry. And though it’s only on a few categories of sites now, the categories inevitably will expand. It’s not just porn, but info on reproductive and gender healthcare, LGBTQ+ dating, and many other subjects that “children must me protected from”, but really they want to know who’s gay, looking for abortions or transgender healthcare or information about whatever other rights their government is trying to force them to give up.


Creating a registry of adults and what content they access is exactly the point of these laws. Always has been. “Protecting children” is just the easiest excuse to make it seem more urgent to violate people’s rights. Just like removing trans healthcare started with children and is now targeting adults.