Alas Poor Erinaceus

(Not as scary as I look, I promise)

  • 16 Posts
  • 50 Comments
Joined 7M ago
cake
Cake day: Dec 18, 2024

help-circle
rss


Oh, sorry 🙁. Are you on mobile or desktop?



cross-posted from: https://lemmy.ml/post/30717996 > Amazon and PayPal being out of the running of course. FWIW, I think Mullvad uses Stripe . . . 🤔
fedilink



Could you explain/elaborate to a know-nothing (me) on the following from your link?:

Caveats of federation: Metadata leaking

When using federation, Matrix’s room states (containing a lot of Metadata) get replicated and stored indefinitely on every homeserver any user connects with or connects to. While this is a feature for enabling distributed chat rooms, it comes at a serious privacy cost.

To avoid this, you can either disable federation, or make sure that your users signed up with no linkable identifiers other than their user names.


Last time I tried SimpleX, you had to scan a QR code to go from Desktop to mobile and vice versa, any chance of them changing that? Otherwise it did look promising.


If I set up Filen to sync my home folder to the cloud and I change VPN countries while it’s syncing, is that likely to cause any technical or security problems?

EDIT: My tests would seem to indicate not, but what does everyone else think? Best practices?


This is looking pretty promising so far, thanks to all who responded 👍


Thanks! They claim to have zero knowledge and E2EE . . . does End 2 End Encryption mean that my data is encrypted “in transit” as well as “at rest?” Was never quite clear on that.


Hey, if I cross post this to proton@lemmy.world, maybe Andy Yen will see it, it will light a fire under their collective asses, they’ll drop everything else they’re working on, labor long and hard, night and day, until the Linux client for Proton Drive is ready! Whaddaya think? 😉


While I'm waiting for the Linux desktop client for Proton Drive . . . does anyone have any experience with Filen? https://alternativeto.net/software/filen/about/ https://tosdr.org/en/service/6820
fedilink



If I had a phone set up like that, and, say, ICE or TSA took it, what would they be able to get from it? And I know that legally they can’t make you give up your PIN, but what’s to keep them from just beating it out of you? Cops of any stripe rarely if ever face consequences for their actions, especially in the US.



Is that one a paid service? Have heard good things about it but never tried.


What search engine(s) besides DuckDuck have !bangs?
SearXNG does, I think...any others? Looking around for other engines that aren't US-based, though I guess DDG is still considered acceptable for LibreWolf's default engine. Bangs are incredibly useful!
fedilink

Thank you very much! Will definitely take a look. 🙂


Yeah, I couldn’t find anything much there either! Oh well.


Well, ignoring anything else, cozy lacks the encryption proton drive has.

Do you by any chance have a reference for that? I believe you, I’d just like to read a little more about it. Of course then there’s also Cryptomator if the host doesn’t properly protect your stuff . . .

I can make use of Proton Drive, but using the web client only, which is extremely cumbersome. There is rclone, but I’m not smart enough to understand how to set it up. 🤕 IIRC, of all the Proton Apps, Drive is the only one lacking a Linux client.


I’m not hocking anything—notice the question mark at the end of the title. I don’t have any association with Cozy; I know nothing about them. Also, I’m referencing someone’s blog post, not endorsing it or necessarily agreeing with it. Like I said, Andy Yen’s comments aside, Proton Drive doesn’t have a desktop client for Linux which is why I’m looking for a replacement anyway. I’m keeping my other Proton stuff, for now at least. Maybe read a little more closely next time?


Cozy.io as a replacement for Proton Drive?
Joan Westenberg mentioned this in her "[Trump-proof tech stack](https://www.joanwestenberg.com/american-tech-is-compromised-heres-my-replacement-stack-2/)" post; anyone have any experience with this? It says it's [open source](https://github.com/cozy), self-hostable, and based in France. Unfortunate Andy Yen comments aside, a big plus is that [cozy](https://cozy.io/en/) actually has a Linux desktop client (!), unlike Proton.
fedilink
23
Cozy.io as a replacement for Proton Drive?

Ok, duh, you’re both right of course; late night/early morning brain fart here 🧠💨



LibreWolf is to Firefox what BetterBird is to Thunderbird?
Had never heard of this before today. Anyone tried it? **EDIT:** "[Being a fork of Mozilla Thunderbird, the software collects some data about the user, less than the original Mozilla Thunderbird, as outlined in Thunderbird's privacy statement. No data is submitted to Betterbird, some data may be submitted to Mozilla. No telemetry and no crash reports are submitted, however, add-on updates and blocklists are downloaded from Mozilla sites. Betterbird offers a product Start Page which processes access data as described above](https://www.betterbird.eu/legal/index.html)."
fedilink

They have several apps on F-Droid, which is usually a good sign . . . **EDIT:** But try to sign up and they want your name, address, and phone number. Forget it!
fedilink




Yes, I got:

Good signature from "Tor Browser Developers (signing key) <torbrowser@torproject.org>" [full]

Does that mean it’s ok? Maybe Mullvad just needs to update their website?


Thank you for taking the time to write all that! I did do what you described, but the RSA key I got at the end was different from what Mullvad’s webpage says, which is the same as what you put, I think: 6131 . . . etc.


Why why why don’t they just do like Wikipedia or the Internet Archive does and just come out and ask for donations instead of trying to sneak all this advertising shit into things?

EDIT: Another idea, which I’m sure they’ll never consider, is to host actual @thunderbird.net email addresses which could be paid for. People at this very minute are looking for Proton Mail replacements, and this could be one of them . . .


That’s kind of what I figured, although after following Mullvad Browser’s instructions for verification, I did get two different RSA keys, if that means anything . . .



How important is it to verify a signature (of say Mullvad Browser)?
Because it's kind of hard! Even if I follow their instructions. Maybe I'm just dumb . . . 🙁
fedilink


So is Firefox mobile or Fennec actually better in this regard?



Which is best at mitigating browser fingerprinting? Firefox (with or without arkenfox)? Librewolf? M
Tor is off the table for me because it's so slow. If you can point to some test sites or documentation that supports your choice, please include!
fedilink



I didn’t have an issue with fireballs either, thankfully, because I made my saving throws before they got to me.🔥😉


Am I right tho about having to scan QR codes to go back and forth between desktop and mobile on SimpleX, or am I just 😵‍💫?


Selfhosting is kind of hard and labor intensive for some of us; had a lot of trouble trying to set up NextCloud on my QNAP (if that counts as selfhosting), and finally gave up.


Grr! Ok, but damned if I could get that to work! It seems like you can’t use the desktop and mobile client at the same time! You have to scan a QR code to switch between them! And it has issues with firewalls and VPNs! Old and clueless here, maybe part of the problem. 🙁




Erg, after all this fuss, Element is kind of hard to use and not very intuitive 🙁


Yeesh, doesn’t sound too good on their part. An interesting story, thanks for taking the time to write all that. I will now go ahead and cross Beeper off my list.


I’ll take a look at those, thank you. Using one of these is preferable to going the Matrix/Element bridge route, you think? I really like the idea of Matrix, but it was a real pain to get everyone on Signal, and bridging that to Matrix/Element seems kind of complicated and quite possibly less secure (although Signal has its own issues of course) than just using Signal by itself.


Sorry, on Linux Mint 22.1. I’m not a big fan of KDE stuff in general, since it seems like you have to download tons of other stuff just to use one of their apps, but I suppose I could give it a look . . .


What do you think about using Beeper just for SMS?
It would be nice if I could get SMS 2FA-type notifcations on my desktop without having to use my phone. I probably wouldn't use Signal with it, since Beeper's own page seems to suggest that sending Signal messages with it would be less secure! And, I guess, SMS isn't secure to begin with . . . If I download and install Element, and then look at the SMS bridges available on Matrix's website, the recommended bridge instructions sends me over to Beeper, since I don't have my own server. Old and confused here . . .
fedilink