• 53 Posts
  • 10 Comments
Joined 6 months ago
cake
Cake day: April 3rd, 2024

help-circle

  • Unfortunately, Tinder doesn’t work and that is helpful to get in touch with the ladies. That app is too hell bent on location data which GOS handles more privately.

    NFC should work, it is just scheduled to be deactivated after 3 months if not used for security reasons.

    I think GOS is very user friendly and has many positive privacy and security enhancements. I would like to see if they can surpass sandboxed Google Play and officially support other repositories and updaters like Accrescent. Also, a standard way of securing traffic beyond encrypted DNS would be good such as a tor client like Orbot.

    Looking into the Veilid ecosystem might also be a source for further development ideas.



  • tor (TBB) doesn’t work for everything and most people want something fast and convinient that only takes clicking a few buttons to get working. They will think it is too much work.

    I recommend Brave browser which can use tor in private browsing mode but also has a regular browser with encrypted DNS (cloudflare, https strict, and shields) for things like banking, shopping, and online accounts (that might help to have a password manager for).

    Also, Tor browser does not have any passthrough for security keys but Brave based on chromium does. Tor browser does not have a password manager.

    Firejail should work on a profile for Brave as sandboxing is always helpful. TBB can be sandboxed easily, however.

    This “multi-tiered” approach would be better for most people who aren’t just accessing a handful of onionsites that replace or are in opposition to an entirely different set of services than those usually accessed on the conventional internet (online banking, social media, a few publication sites, and a search engine).


  • Don’t use Discord. That is a major vector for attack. Seen it happen myself.

    Even Sandboxed Google Play has problems.

    I don’t think there is any equivalent of Graphene for Mac hardware. With Pegasus and Predator software around, phones are very hard to secure.

    Rely on tor browser and torrifying where you can with Orbot (Guardian Project).

    Instead of Telegram, how about Signal and Briar? We just heard about how Telegram’s executive got hit and may now have to bow to pressure. Signal has kept its design integrity as far as we know.

    Minimal apps are better than many to reduce attack surface. Maybe try accessing some of those services on other devices instead of on your personal tracking device.




  • Ah, that must be it. 2FA is still a very good security feature to have.

    But there is nothing only you know that is still useful because a secret must be shared in order to be useful (unless you just have full disk encryption and then when it is unlocked and network connected, it is still vulnerable). In short, admins could change your password since you are not the sole admin of your own server but then you would have to have mass appeal to be “useful”, i.e. popular.

    In theory, Tim Cook might have a keybearer who could usurp the throne with all the proprietary OEM crypto keys that only the Company knows, but everyone knows who the CEO is and the keybearer could get in big trouble unless he had an army…

    Things can be changed on the server side and the network is not the same as the device: these are technology truths some people refuse to ever understand.




  • Do you want to show us what that looks like in assembly, ASCII from machine code? …ha, ha, ha, no!

    Depends on the device, I know. Such a pain without the higher level languages.

    What would it look like for ARM android touch screens? Just for one character…

    But if some characters go missing or are exchanged for others for no discernable reason, then might that be an exploit on a EC or assembly level?