Pantherina

joined 3 years ago
MODERATOR OF
[–] Pantherina@feddit.de 6 points 1 year ago

VPNs are not meant for privacy. The concept is clunky, as is the concept of our internet.

Tor or I2P are made for privacy, but the interactions with the clearnet have the same problems, you need a legal entity hosting the server, IPs are known and can be blocked etc.

Hosting your own VPN does not anonymize you anymore but is very unlikely to get blocked.

[–] Pantherina@feddit.de 5 points 1 year ago* (last edited 1 year ago) (10 children)

All Android phones have Google malware installed by default, as system apps, which means those apps can do whatever they want.

So every piece of data you put on there is possibly tracked and collected.

Then there are 2 more problems

  • the software is proprietary and cannot be externally wiped clean
  • the software is outdated

This makes it vulnerable to Pegasus attacks and others. There are tons of secure practices to avoid getting it, like LTE-only, HTTPS only, encrypted and trustworthy DNS, sandboxed processes, blocked javascript execution from unknown websites...

But still if the phone is outdated there are unpatched and publicly known security issues. Just spamming them at all phones is likely to succeed as so many people run vulnerable versions, as vendors suck.

Then if you have pegasus, the only way for security is to reflash the A/B partitions, both. Factory reset is not secure as it will keep what is already in the system partitions.

The firmware is protected and signed by the vendors, so it is likely clean.

But Pegasus installs itself to the phone storage.

If you A cant obtain factory images or B cant flash the phone at all, you cannot wipe it clean.

So a good activism phone needs

  • trustworthy and minimal system apps / stock software
  • modern software updates
  • possible to reflash whole device externally
  • nice to have: ability to verify checksum of system partition, like GrapheneOS Attestation

This makes them poorly pretty expensive. I think a slightly outdated GrapheneOS phone is okay though.

[–] Pantherina@feddit.de 5 points 1 year ago (15 children)

Burner phones are a strange concept. If you want to store sensitive data on it, you shouldnt use some cheap android phone or even a dumbphone without encryption support.

[–] Pantherina@feddit.de 4 points 1 year ago (3 children)
  1. Good that only you do this, as a whole company setup is complex
  2. Pop_OS is currently not that well maintained afaik, their GNOME desktop is quite outdated.

Just using their OS for the hybrid graphics support is a valid point, but should not be the only one.

Having a well managed OS is crucial, but I disagree that Ubuntu base is the best here.

For stability, a centrally managed Fedora Atomic would be better I think. Way more stable, image-based, all peolple would have exactly what they need.

You could build images locally and take care of the exact updates like that. Or you just share specific configs for each role, like preinstalling different software.

But having things like specific policies, any files, hardening etc. is totally possible during image creation.

[–] Pantherina@feddit.de 2 points 1 year ago

Nice for the paranoid people, but this means false errors when there simply are no updates.

[–] Pantherina@feddit.de 6 points 1 year ago

Wormhole ftw

[–] Pantherina@feddit.de 2 points 1 year ago

Very nice tool for usage and development!

[–] Pantherina@feddit.de 5 points 1 year ago (1 children)

Like.... the Intel ME?? And no BIOS seems to allow the switch to disable it, even though that was literally required after the NSA sued Intel?

[–] Pantherina@feddit.de 1 points 1 year ago

Same on Thinkpad T495

[–] Pantherina@feddit.de 5 points 1 year ago

There is no existence or Harambe anymore 🥲

[–] Pantherina@feddit.de 26 points 1 year ago (7 children)

Do gorillas kill babies of other animals, monkeys or humans?

I just dont really believe that Harambe would have done anything to that baby.

 

I am again deleting old mails. And I have inboxes with like 200 of them, it is hell.

I would like to autodelete mails that contain a date. If there are multiple dates, take the latest one. If that date is older than x days from today, delete the mail.

Is there something like that? Or some regex possible in native filters?

 

I try to crosspost sometimes to reach more people.

I dont get it.

"Share permalink" copies some weird clone of the post on my homeserver.

And someone told me I should crosspost, but this is not available.

Shouldnt "share post" be a link on the server of the community? Would that be a crosspost?

Thanks people! Jerboah is the best Lemmy app but this is very strange.

 

There are big wishes for Signal to adopt the perfectly working Flatpak.

This will make Signal show up in the verified subsection of Flathub, it will improve trust, allow a central place for bug reports and support and ease maintenance.

Flatpak works on pretty much all Distros, including the ones covered by their current "Linux = Ubuntu" .deb repo.

To make a good decision, we need to have some statistics about who uses which package.

 

RutheniumOS is a fork of GrapheneOS with very broad claims and also accusations toward GrapheneOS.

They throw around claims that are not true, which is a common (Brax, Punkt) but ugly practice.

Dont use it Guys!

 
view more: ‹ prev next ›