Most people haven’t, till they have.
- 3 Posts
- 117 Comments
For security, Vanadium (only available on GrapheneOS. For privacy, Tor. Most everything else falls between on the scale.
FutileRecipe@lemmy.worldto
Privacy@lemmy.ml•ProtonVPN or Mullvad? Why would you choose one over another?
4·2 months agoWhen was that, apparently I missed that.
A quick search says November 2019.
The sheer volume of communication data is far too large to monitor everything.
By people, sure. Run it through a magical analytical algorithm that flags stuff for people to look? Or if that’s still too much everywhere, they could focus it on a certain area’s towers and process that data. Will it catch everything or not generate false positives? No, it’s not perfect, but I could see it helping them and being done.
I doubt an agency like this would just hoard the info and not proactively use.
Even a lot of offices have moved to VoIP.
I would like something in between…BTW I’m installing Bazzyte on another PC.
If you’re somewhat familiar with uBlue, Bazzite, and immutables, I’d go with Bluefin (Gnome) or Aurora (KDE). All three are uBlue / based off Fedora, so you don’t have to learn a 2nd OS while working on your current OS (Bazzite).
FutileRecipe@lemmy.worldto
Privacy@lemmy.ml•Revolut, McDonald's, and Authy have banned the use of GrapheneOS.
3·1 year agoHow about the ~100 Grammer? Or even just “100 G” if you’re trying to be “hip.”
FutileRecipe@lemmy.worldto
Privacy@lemmy.ml•Revolut, McDonald's, and Authy have banned the use of GrapheneOS.
4·1 year agoBut when did you set Authy up? I don’t recall when Authy made the change, but it wouldn’t kick you out. It would, however, prevent you from signing in a new device. So if you lose your phone, you might lose access to those tokens…
Fennec and Mull 129.0.2 in F-Droid.org repository have 42 known security issues
Ref: https://forum.f-droid.org/t/fennec-vulnerability-recommended-to-uninstall/
I’m sometimes super slow at the start of self checkout. If the bags are stuck together, not open, and if I didn’t bring my own, sometimes it takes me 2 minutes just to open a plastic bag. I’m trying my hardest!
or randos on the internet then?
I mean isn’t that practically everyone on the Internet that you don’t know personally? Or do you actually know the Firefox and/or Librewolf team, and audit their code as well?
If no to both…sounds like you are putting some measure of trust into “randos on the Internet.” Which is not abnormal. Trust is required at some point in most processes.
My thing against Firefox/Librewolf is lack of security…unless it’s improved?
Avoid Gecko-based browsers like Firefox as they’re currently much more vulnerable to exploitation and inherently add a huge amount of attack surface. Gecko doesn’t have a WebView implementation (GeckoView is not a WebView implementation), so it has to be used alongside the Chromium-based WebView rather than instead of Chromium, which means having the remote attack surface of two separate browser engines instead of only one. Firefox / Gecko also bypass or cripple a fair bit of the upstream and GrapheneOS hardening work for apps. Worst of all, Firefox does not have internal sandboxing on Android. This is despite the fact that Chromium semantic sandbox layer on Android is implemented via the OS isolatedProcess feature, which is a very easy to use boolean property for app service processes to provide strong isolation with only the ability to communicate with the app running them via the standard service API. Even in the desktop version, Firefox’s sandbox is still substantially weaker (especially on Linux) and lacks full support for isolating sites from each other rather than only containing content as a whole. The sandbox has been gradually improving on the desktop but it isn’t happening for their Android browser yet.
FutileRecipe@lemmy.worldto
Asklemmy@lemmy.ml•Are there any occupations you uniquely oppose the existence of?
181·1 year agoThe Human Cannonball? He got launched out of the cannon and did one flip before getting caught by the net.
That’s what it looks like to the untrained eye. But they’re not really going to fire a person out of a cannon. That’s not safe. So he just huddles in the cannon, they light a decoy fuse, it makes a bang (with no projectile), and he spring out and jumps that distance by himself. Requires a lot of core and leg strength.
FutileRecipe@lemmy.worldto
Privacy@lemmy.ml•Open Source Everything: A curated list of the best open source software
2·1 year agoYour data has monetary value to google. Giving them access, without getting any money from them (or even knowing what ways it will be used) is not something you must do.
To be fair, while you may not be getting money in its direct form (cash, bank deposit, etc) from Google, they are providing you a service which costs them money for free. So they are providing something of monetary value.
Only the individual can determine if their data is worth that free (to the individual, not free to Google) service. I’m assuming that most people in a privacy community would be against that, though.
Anker Prime Charger (250W, 6 Ports, GaNPrime): $169.99 but there’s a $30 code that shows up for me, which brings it to one penny below your $140 too steep threshold.
FutileRecipe@lemmy.worldto
Privacy@lemmy.ml•Why I am not convinced that Graphene OS is as good as people claim
8·1 year agoI don’t even use proprietary apps so most if the “security features” aren’t even useful to me
So only proprietary apps may have malware? Malware aside, only proprietary apps may have bugs that can be exploited? And all nonproprietary apps are perfectly safe? But seriously, there is so much wrong with that thinking.
Apps aside, GrapheneOS protects the actual OS and is kept up to date, much quicker than pretty much any other variant.
It is overly complex for no benefit to me.
What’s overly complex? Contact and storage scope I mentioned? You don’t have to use it. Separate profiles for work I mentioned? Again, don’t have to use it. GrapheneOS is one of the closest OSes to AOSP that I’ve seen. You could even just install the Play Store (which is in a sandbox by default, with no root, and you don’t have to do anything to specify that), only use the owner profile, and you get all of the security benefits with no extra work. You introducing F-Droid and using all nonproprietary apps is more complex than GrapheneOS out of the box.
FutileRecipe@lemmy.worldto
Privacy@lemmy.ml•Why I am not convinced that Graphene OS is as good as people claim
6·1 year agoGraphene sucks the life of android in my humble option.
What’s not “fun” or lifeless about it? It’s a phone. I use it exactly as I would a normal Pixel, with the exception of having the convenience of Google Wallet.
Everything is about security with anything else being second.
Would you rather it be all about fun/having life with everything else being second? That doesn’t sound safe. And I’m still confused about you saying it having no life.
I will say what I do differently vs a normal Pixel, is I use the storage scopes and lock certain apps to certain folders as well as contact scopes to lock certain apps to only see certain people. I don’t use my phone for work, but if I did, that would be a separate profile/user.
FutileRecipe@lemmy.worldto
Privacy@lemmy.ml•Is Shelter the best way to isolate apps on Graphene?
10·1 year agoWith Graphene, the recommended way is to use separate profiles, not Shelter or similar apps. Check out the official Graphene account on their forum:
https://discuss.grapheneos.org/d/12503-shelter-versus-native-gos-app-isolation-tradeoffs/10
They are expensive
Sometimes you get what you pay for, and…
I don’t want to give money to Google
I get that, but your purchase (the entire Pixel department, to be honest) is a drop in the ocean to their profits. They won’t notice you not buying one at all. You’re handicapping yourself in the mobile security arena (not being able to install GrapheneOS) to take the high ground and not effect a tech giant.
That aside, if you really don’t want to give Google, buy one from a reseller and not from the Google Store.



Using one only because it’s super well known? Sure. It can be well known and scummy. But it can also be well known, trusted, vetted, etc.
And you also probably don’t want to use one that is barely known as there’s the lack of trust, getting, who runs it’s, etc.