not much

  • 30 Posts
  • 205 Comments
Joined 2Y ago
cake
Cake day: Dec 08, 2022

help-circle
rss

Thing is that searx.be has been remarkably good for my use case since a long time. With other instances YMMV.


The mentioned server side changes (e.g. A server move you mentioned but could also be server settings, provider settings, etc).

I guess that is the case. According to https://searx.space/ the searx.be server is in Austria but might use some proxy to talk to Google and similar to avoid quick blocking. The maintainer of searx.be also maintains yewtu.be and that one uses proxies (The proxy names can be seen when blocking auto play of videos in Tor browser).

Also getting results in Russian here since a few days. Usually it is either Swedish or Dutch. Never German.


Been using searx.be for a bit now and they had many results in Dutch and German, which can be expected for a site based in Belgium.

Belgium is in the domain name. You can check where the server is located :

https://searx.space

Austria AT NETCUP-AS netcup GmbH, D

Though I’m using Tor with searx.be searching I do get results in Russian since a few days. Usually it is either Swedish or Dutch. Never German. I can imagine the searx.be maintainer is rotating IP addresses at the part which does the talking with Google and other search engines to prevent quick blocking of the instance. yewtu.be (same maintainer) does use proxies (that is visible when blocking auto-play of videos).


Indeed. I tried on mobile with LibreTube and with Mull and both fail. And also fails now in Tor browser. The list is getting shorter.


Now I’ve tried almost all of them in the Piped instances list (Several domain name for sale and server not found errors) and only the smnz.de one works for me. :( I am wondering whether a freshly installed self-hosted private Piped video instance will work fine.


Works for me still (Using Tor browser. I’m Europe located).


The instances list is not up to date :

https://piped.smnz.de/watch?v=bBhDWTZDH9c

There’s probably more working instances.

Plan B : I guess running your own Piped instance and not sharing it with a lot of people could be worth considering.

Personally I’m sticking to https://wiki.archlinux.org/title/Yt-dlp#Faster_downloads for the video downloading I do.


Was about to post the great blog post from my bookmarks, but another commenter beat me to it (t y !). Here’s comments on that blog post on Lobsters and HN :


Tested playing a video with an Invidious instance right now and it worked. Did you try another instance ?


That’s because you’re using it for a purpose it wasn’t intended. I2P isn’t designed to be used to browse the regular internet, for that it’s better to use TOR. However for anonymous torrenting or accessing i2p-sites, it’s quite fast imho.

Okay, good.


There’s more to it. The mono-culture is one thing, but rolling out the update to millions of computers on the same days sounds like a bad idea.

Fun fact in 2008, with nuclear submarines, the mono-culture was not that bad yet.

It’s interesting to note the UK went with a Windows XP variant and not Windows Vista, which is marketed as the more reliable OS. The USA never made the same calculations: The American Navy runs on Linux.


I guess the important thing is in the unique versus total in for example 200 fonts and 150 unique metrics found.



Tor has noscript automatically enabled no?

There’s three security settings via NoScript in Tor browser. The default has JS enabled.


Disable javascript, trying to get around fingerprinting with javascript enabled is an exercise in futility, and is especially risky with something as heavily monitored as tor.

I like disabling JS myself for some web browsing but this can make fingerprinting easier because most people do enable JS, and I’ve read that with JS disabled certain things still can be detected through CSS files.


For web browsing i2p is still much slower for me than with Tor these days.



Jailbreaking RabbitOS: Uncovering Secret Logs, and GPL Violations
cross-posted from: https://infosec.pub/post/14981035 But as I and others looked closer, and thought about it more deeply, things became concerning. These logs include: Your precise GPS locations (which are also sent to their servers). Your WiFi network name. The IDs of nearby cell towers (even with no SIM card inserted, also sent to their servers). Your internet-facing IP address. The user token used by the device to authenticate with Rabbit's back-end API. Base64-encoded MP3s of everything the Rabbit has ever spoken to you (and the text transcript thereof).
fedilink

This looks like old news to me. Years ago I’ve read that three letter agencies can access phones without getting the access code or bio-metrics from the phone owner.


And we’re cheering it on because X is seen as a political opponent.

I’m cheering this on among others because the shadow-banned person wrote something important about a sick EU law proposal that tried to break E2EE.


Strongly agree but lots keep using X, in fact it seems to get worse :(


Here’s a take by a Mozilla employee :

  • Mozilla has been ad funded since 2005
  • Browser development is not sustainable by just donations
  • Transparency is most important

https://fosstodon.org/@gabrielesvelto/112779506156690032


X (former Twitter) lost court-cases about shadowbanning after critical post about EU and CSAM
cross-posted from: https://piefed.social/post/163062 > Last year Danny Mekić wrote this article : [https://dannymekic.com/202310/undermining-democracy-the-european-commissions-controversial-push-for-digital-surveillance](https://dannymekic.com/202310/undermining-democracy-the-european-commissions-controversial-push-for-digital-surveillance) which was published in a newspaper and then the author got shadow-banned on X. Today the same Dutch newspaper reported that Mekić won two court-cases about this. > > * Dutch article about the verdict - paywall : [https://www.volkskrant.nl/tech/x-mag-gebruikers-niet-meer-zomaar-shadowbannen-oordeelt-amsterdamse-rechter\~befb7fd0/](https://www.volkskrant.nl/tech/x-mag-gebruikers-niet-meer-zomaar-shadowbannen-oordeelt-amsterdamse-rechter~befb7fd0/) > * Archived copy : [https://archive.ph/ckW2a](https://archive.ph/ckW2a) > > * tl;dr English translation : > > X is not allowed to shadow-ban users easily the judge said. Only during the court-case X explained why the account of Meki was shadow-banned : He had shared an article about the CSAM law on X. "I still > do not understand why X this only said in the court hall, rather than telling me right away when I > asked about it" Mekić said. > > * Mekić on Mastodon : [https://mastodon.social/@DannyMekic](https://mastodon.social/@DannyMekic) > * The author's username on X : DannyMekic > * Article from last year by WIRED : [https://www.wired.com/story/csar-chat-scan-proposal-european-commission-ads/](https://www.wired.com/story/csar-chat-scan-proposal-european-commission-ads/)
fedilink



I did lots of reading about this and am still wondering why someone would want to opt for catch-all domains over aliases. Catch-alls seem highly susceptible to spam and while I haven’t actually done any email aliasing yet,

I’m using catch-all since years and no spammer has ever made up a new email alias to spam me.

it doesn’t seem to take much effort to make a new alias if you have a plan with unlimited aliases.

That depends. The moment you are in a shop without your phone/email and they really want an email address you can simply write down their_company_name@your_email_domain_name for them without having to compromise anything.


GMaps WV as mentioned in another comment : https://f-droid.org/packages/us.spotco.maps/ Last updated, June 2024.

This is a restricted WebView wrapper for accessing the web version of Google Maps. Intended for use when OpenStreetMap isn’t enough.


Yeah, that’ll be hard. I’m trying to use Peertube but network effect is big on YT (not sure if that’s the right expression here, noone is using Peertube, everyone is on YT).

There was a time “noone” was on YouTube.


Twitter had a TOR service last time I checked, I haven’t seen a single Mastodon instance available as TOR service.

TIL Mastodon can be run as tor service : https://docs.joinmastodon.org/admin/optional/tor/


I think you need to take a break and get some perspective.

Besides, the Twitter link was already posted by the OP, why would it need to be posted again?

Posting exTwitter links without a screenshot in a privacy community feels like a kind of oxymoron to me, especially after exTwitter made API changes and what not which made third party apps and software like Nitter kind of useless.




  • Skiff = Notion now, I doubt that it will be open source, but happy to see source code.
  • Lavabit open source ? Where’s the code ?
  • Roundcube is webmail software, not a webmail provider.
  • Mailpile is email software for desktops, not a webmail provider.


Shoelace: Alternative frontend for Instagram’s Threads
cross-posted from: https://slrpnk.net/post/9961019 > Hello Lemmy! Yesterday I released the first version of an alternative frontend for Threads: Shoelace. It allows for fetching posts and profiles from Threads without the need of any browser-side JavaScript. It's written in Rust, and powered by the spools library, which was co-developed between me and my girlfriend. Here's a quick preview: > > ![A screenshot of Shoelace's homepage, showing the logo on top, the title "Shoelace", the subtitle "an alternative frontend for Threads", an input bar with the tooltip "Jump to a profile...", and at the bottom three links: "hub", "donate", and "v0.1".](https://slrpnk.net/pictrs/image/017d0ceb-7c3f-453a-93bb-58e8549454df.webp) > > ![Mark Zuckerberg's profile on Shoelace, showing three posts: One showcasing columns on the official Threads frontend, another congratulating himself for 1.2M+ downloads in his company's new AI software, and the glimpse of a post related to the "metaverse"](https://slrpnk.net/pictrs/image/a4b4d14e-0213-4cac-ab0c-a5b6540bb6d5.webp) > ![Post by münecat on Shoelace, announcing the release of a video essay criticizing the field of evolutionary psychology](https://slrpnk.net/pictrs/image/b9335b5c-f796-4835-bdd8-258f65ce68d8.webp) > > The official public instance (at least for now) is located at https://shoelace.mint.lgbt/, if y'all wanna try it out. There's also instructions to deploy it inside the docs you can find in the README. Hope y'all enjoy it!
fedilink

Waterfox has had some bad press. I don’t remember details but here’s something to read :

I prefer to stick to the no nonsense LibreWolf and when some things don’t work fall back to Firefox :


You can look at something like https://www.deviceinfo.me/ to see what just a browser can identify.

At the Keys Pressed (Live) it can see my arrow up and arrow down key presses 😱


Is this because I am using a free tier VPN? so it’s not functioning properly etc…

  • Does Proton not have a page to check your IP address and check for DNS leaks (Mullvad does : https://mullvad.net/en -> Check for leaks) ?

  • Did you look up your IP address by other means ?

  • On the desktop with Linux you can check the content of /etc/resolv.conf and ip a (Your local IP) and ip r (Gateway address).

Else google fixed my location based on my previous location history? I used my google applications without VPN for many years, I am just learning & following privacy tips recently.

Are the sessions from your last login ? With some applications (Dunno about Google) you can delete older sessions from the overview.


lol i thought you EU boys’ government was so amazing and cared so much about privacy! lol!

You will not hear me bragging or applauding about EU except that the GDPR did bring about some positive changes. And if you ask me I wonder what is happening with all the millions of money from the fines that EU gave to Big Tech companies. EU basically claims that they have no money to keep a Fediverse server running. Puzzling.


If you’re in the EU you can vote and help to make some of them go away with the coming elections which are pretty soon.




I think most FOSS zealots simply despise capitalism in general, they want everyone else to be poor like them. Kinda like socialism.

One well known exception to your comment is Linus Torvalds. He didn’t mind moving to the USA to make some good money after being a student who could afford a whopping 386! And unlike some people believe, the GPL does not restrict a programmer to make money.



Many people probably won’t be bothered by these things, but I am. I don’t want to pay full price for something that I don’t truly own. I miss the familiarity. I miss the reliability. I miss feeling like it’s mine. Dependable. Trustworthy.

Picking my old guitar up again has never looked so appealing. I think I want to go back to investing more time, money, and energy into things that aren’t connected to the internet

Upvoted.


Yup.

Buy any domain name, doesn’t matter what.

Suggested to OP and others that self-hosting email is easy and reliable is a bad idea in my opinion.

Instead I suggest the OP to let go of the “free” requirement. There are at least three email providers that provide email for 1 Euro a month including a few email aliases. Another option is to find a web hosting company that also provides email with web hosting. For example Gandi used to do that though I read they made some changes with their hosting options.


By the way, the earlier posted article https://restoreprivacy.com/protonmail-discloses-user-data-leading-to-arrest-in-spain had an update starting at the paragraph with title *Update: Statement from Proton and additional commentary*
fedilink

What’s up with added EXIF data by gThumb ?
- Make a screen shot of your desktop - Check with a viewer and see no EXIF data - Load it in gThumb to use its crop feature, crop and save - Check again with a viewer and see that gThumb added EXIF data including the gThumb version In the mean time I've started to use other software to crop screen shots but I am still puzzled why gThumb always adds EXIF data ?
fedilink



> Large part of USA citizens may have had their private medical > data stolen :( UnitedHealth says files with personal information that could cover a “substantial portion of people in America” may have been taken in the cyberattack earlier this year on its Change Healthcare business. The company said Monday after markets closed that it sees no signs that doctor charts or full medical histories were released after the attack. But it may take several months of analysis before UnitedHealth can identify and notify people who were affected. UnitedHealth did say that some screen shots containing protected health information or personally identifiable information were posted for about a week online on the dark web, which standard browsers can’t access. The company is still monitoring the internet and dark web and said there has been no addition file publication. It has started a website to answer questions and a call center. But the company said it won’t be able to offer specifics on the impact to individual data. The company also is offering free credit monitoring and identity theft protection for people affected by the attack. UnitedHealth bought Change Healthcare in a roughly $8 billion deal that closed in 2022 after surviving a challenge from federal regulators. The U.S. Department of Justice had sued earlier that year to block the deal, arguing that it would hurt competition by putting too much information about health care claims in the hands of one company. UnitedHealth said in February that a ransomware group had gained access to some of the systems of its Change Healthcare business, which provides technology used to submit and process insurance claims. The attack disrupted payment and claims processing around the country, stressing doctor’s offices and health care systems. Federal civil rights investigators are already looking into whether protected health information was exposed in the attack. UnitedHealth said Monday that it was still restoring services disrupted by the attack. It has been focused first on restoring those that affect patient access to care or medication. The company said both pharmacy services and medical claims were back to near normal levels. It said payment process was back to about 86% of pre-attack levels. UnitedHealth said last week when it reported first-quarter results that the company has provided more than $6 billion in advance funding and interest-free loans to health care providers affected by the attack. UnitedHealth took an $872 million hit from from the cyberattack in the first quarter, and company officials said that could grow beyond $1.5 billion for the year. Minnetonka, Minnesota-based UnitedHealth Group Inc. runs one of the nation’s largest health insurers. It also runs one of the nation’s largest pharmacy benefits management businesses, provides care and offers technology services. Company slipped nearly $3 to $488.36 in midday trading Tuesday while broader indexes climbed.
fedilink


It was at the Securedrop website. How did I end up there ? I read something about Sequoia and encryption and then wanted to see what Securedrop entailed. Meanwhile I've raised the security settings. Still, today someone in this community (?) mentioned that Tor browser does not protect the remote to check for the OS, and now this. Color me surprised.
fedilink


When will Proton Mail be in F-Droid ?
EDIT : Option to vote for Official F-droid Repository https://protonmail.uservoice.com/forums/945460-general-ideas/suggestions/47173612-official-f-droid-repository
fedilink


Proposed FTC Order will Prohibit Telehealth Firm Cerebral from Using or Disclosing Sensitive Data fo
Under the proposed order, filed by the Department of Justice upon notification and referral from the FTC, Cerebral will also be required to pay more than $7 million over charges that it disclosed consumers’ sensitive personal health information and other sensitive data to third parties for advertising purposes and failed to honor its easy cancellation promises.
fedilink

![](https://lemmy.ml/pictrs/image/51faa0ca-2b47-4eba-bc8c-d9edabba5ca9.png)
fedilink



Alcohol Addiction Treatment Firm will be Banned from Disclosing Health Data for Advertising to Settl
According to the complaint, the company contradicted its privacy promises. From 2020-2022, the company allegedly disclosed users’ personal information, including their health information, to numerous third-party advertising platforms via tracking technologies, known as pixels and application programming interfaces (APIs), which Monument integrated into its website. Monument used the information to target ads for its services to both current users who subscribe to the lowest cost memberships and to target new consumers, according to the complaint. Monument used these pixels and APIs to track “standard” and “custom events,” meaning instances in which consumers interacted with Monument’s website. The FTC says that Monument gave the custom events descriptive titles that revealed details about its users such as “Paid: Weekly Therapy” or “Paid: Med Management,” when a user signed up for a service. Monument disclosed this custom events information to advertising platforms along with users’ email addresses, IP addresses, and other identifiers, which enabled third parties to identify the users and associate the custom events with specific individuals, according to the complaint.
fedilink

Why I Lost Faith in Kagi
https://hackers.town/@lori/112255132348604770
fedilink



Fan of Libredirect browser add-on here. This one looks useful. https://github.com/libredirect/frontends_manager By the way, My favorite Teddit instance was taken down by its owner, claiming that Teddit is no longer maintained and Reddit was rate limiting the instance. Now [Redlib](https://github.com/redlib-org/redlib) recommended. Very few instances but it works fine for me.
fedilink

Nitter is over - It’s been a fun ride
cross-posted from: https://lemmy.ml/post/11962108 > What to do now? > > Don't trust corporations, especially those where one egomaniac has all the power. Use open-source and community driven solutions if you can (like Mastodon).
fedilink

cross-posted from: https://lemmy.world/post/11797575 > Walmart, Delta, Chevron and Starbucks are using AI to monitor employee messages::Aware uses AI to analyze companies' employee messages across Slack, Microsoft Teams, Zoom and other communications services.
fedilink

Best privacy friendly, reliable and affordable domain name extension ?
Question after reading this new article : https://www.dutchnews.nl/2024/01/criticism-as-dutch-domain-registry-plans-move-to-amazon-cloud/ My current preferences : - Not more expensive than two euros a month - Whois information cloaking - Not profiting from some Pacific Island money deal - Privacy friendly Edit : Found a spreadsheet by EFF from 2017 which gives some insights : https://www.eff.org/wp/which-internet-registries-offer-best-protection-domain-owners
fedilink


Beginning in the second half of the 1970s, the world witnessed the birth and affirmation of so-called Big Tech – the five largest companies that operate in the field of information technology, which are also known today as “GAFAM” (Google, Apple, Facebook, Amazon, and Microsoft). In the roughly 50 years since then, these companies have been able to build empires of intellectual property of technologies and systems – primarily through acquisitions of other companies both small and large, which allowed them to center technological innovations within their walls. “The GAFAM Empire”, a project developed by DensityDesign Lab and Tactical Tech, collects the information of more than 1,000 acquisitions made by these companies, in order to look back on the history of the industry through the limited data publicly available on the web. The information visualizes a landscape of acquisitions to identify common interests, which are then broken down into a deep analysis of GAFAM’s history. The project visualizes the data in different shapes and through different focuses, allowing the reader to understand a complex system of relationships that is constantly evolving and that is redefining the concepts of competition and monopoly.
fedilink