This profile is from a federated server and may be incomplete. Browse more on the original instance.

Genghis,

The desktop security model is insecure in general. Phone OSes are much more secure.

Reasonable desktop OS to use is Qubes, Fedora, MacOS, ChromeOS, or Windows pro/enterprise (hardened)

Phones are much more secure especially the Pixel 8/pro with MTE immensely reducing remote exploitation. GrapheneOS is the only distro that enables MTE by default and recently implemented it in their Vanadium browser.

Secure phones (secure elements are important): IPhones and Pixels (GrapheneOS or stock)

Also yes, Chromium is much more secure on Linux than Gecko based browsers because of its great internal sandboxing and site isolation. Firefox on Windows is catching up though, but still bad on desktop Linux and android.

This all doesn’t matter if you’re running an EoL device. Make sure your receiving official security and firmware updates.

that’s about it

Genghis,

A lot of the security work on Linux is being done by Google. It’s highly unlikely they are putting backdoors in their products.

My internal fight over what device to buy

Hello there! This is my problem: I’m going to buy a new smartphone, and I’d really like to degoogle myself as much as possible. The idea would be to buy a device compatible with LineageOS, but… Supported devices are usually older models, and often there are newer devices with better specs for the same price, that does not...

Genghis,

I recommend you purchase a Google Pixel 6a or above (minimum security support ends July 2027) and flash GrapheneOS. (Pixel 8/pro preferred)

Aurora Store doesn’t avoid Google since a lot of the apps from the play store include Google’s SDK and libraries. microG also doesn’t avoid Google as it is still running proprietary Google code and has more privacy/security weaknesses

Sandboxed Google Mobile Services is a much better implementation which is featured in GrapheneOS. The services are not privileged and is treated like any other app. They don’t downgrade privacy or security unlike the other alternatives.

There are much more privacy and security benefits using GOS. Here is a 3rd party comparison between different mobile OS.

Genghis,

microG runs Google Play code just like Aurora Store. It is not fully open source. Here’s more information.. It is still connecting to Googles propriety servers.

microG requires Signature Spoofing and alternative OSes usually ship with microG as a privileged system app. This increases the attack surface as it is not confined by the regular sandbox rules.

Now you’re using a privileged component, which downloads and executes Google code in that privileged unprotected context, and which talks to Google servers because otherwise, how would FCM work for example?

Despite doing both of those things, MicroG doesn’t have the same app compatibility as Sandboxed Google Play despite the extra access it has on your device. Even in some magical universe MicroG worked without talking to Google servers or running Google code (again, in a privileged context), the apps you’re actually using it with (the apps depending on Google Play) have Google code in them.

Genghis,

You can always connect a USB stick or card reader with an SD card via USB-OTG

I will recommend you do use a phone that still receives security updates (Not EoL) because I don’t want you to lose out on security just to deGoogle.

If you are strict on having an SD card slot and your phone is still receiving support, you should use StockOS to receive firmware updates as soon as possible. If the phone you decide to get is EoL, the least bad option would be DivestOS (fork of LineageOS)

Again, I would advise not using an EoL phone.

Genghis,

The only secure phone operating systems are either grapheneOS or stock. All the others usually are behind security updates.

For migration, I would just use a USB C drive and transfer files.

Genghis,

AOSP does get security updates first because GrapheneOS is based on unmodified AOSP. They are quick to port over updates though and they have extra features like hardened malloc and better user profile support.

Non pixel phones aren’t secure because GrapheneOS doesn’t support them. They aren’t secure because they either don’t have secure elements, broken verified boot, or don’t properly support alternative operating systems. This makes phones like OnePlus, Fairphone, etc not secure enough for GrapheneOS.

DivestOS I would say is the least worst option when it comes to supporting EoL phones. They’re at least honest about what they do and don’t provide unlike what other OSes do. On their website, they tell you they aren’t a secure OS and they can only try their best to reduce harm on an EoL device. DivestOS Security.

Genghis,

Please do not tell me you use Mull over Vanadium

Genghis,

Passkeys are replacing MFA and passwords.

Genghis, (edited )

Have you tried enabling the Exploit protection compatibility mode on the PF app setting info page?

Genghis,

Element for matrix is actually cheeks

Genghis,

I just use the AOSP messenger. If I used google play services, I would switch to Google messages because of RCS and it looks much nicer.

Graphene OS on Pixel 6a?

Has anyone used it? What was your experience with install/performance? I’m thinking of getting one because it has decent specs for $250. I don’t need banking apps or anything like that, and the only social media app I need is snapchat (I know that sort of defeats the purpose, but I just want better privacy, not perfect).

Genghis,

End of Life date was 4 weeks ago 😔

I wonder how many fires have been started because people left the pizza box in the oven while trying to keep it warm

I’ve seen a few people put their delivered pizza in the oven after everyone grabs a piece to keep it warm. I’ve also seen a lot of those people forget the pizza is in there and either have to throw it out or only noticed after they preheated their oven.

Genghis,

I’m not sure about pizza but I’ve heard a guy putting a casserole in his oven and forgot about it because his coworker was begging him to hang out with him. When he walked back home, his house was burned down to the ground and the firefighters told him “Some knucklehead left a casserole in the oven.” He was super devastated after that.

Genghis, (edited )

This app isn’t fully ready yet but Accrescent is a secure and private app store for Android. It aims to be a better alternative app store on Android rather than using the Google Play Store. It currently has 11 apps right now and more to come soon.

Highly recommend to check out and support this project cuz this appstore is the best out there right now security and privacy wise.

Genghis,

F-Droid has many security vulnerabilities and has many issues such as:

  1. Hosting an outdated APK client.
  2. Utilizes an obsolete installation method.
  3. Does not take advantage of modern appstore features.
  4. Has no moderation.
  5. Has no old app deletion.
  6. Has an arbitrary FOSS only rule.
  7. Does all building and signing themselves.

If you want more details about these issues read this:

privsec.dev/posts/…/f-droid-security-issues/

Genghis,

2 - Manual installation methods can be insecure because a lot of people don’t update their apps all the time. Obviously rooting a phone is insecure, but having no auto updates in 2023 is crazy.

4 - It is very true, having zero quality control on new apps. The flagging of apps with problems is just following the FOSS philosophy. Any FOSS app can be added to F-Droid.

5 - Not sure why you would want to install abandoned apps on F-Droid, let alone use an EOL device. A lot of people don’t check if apps are maintained because they trust their app store.

6 - FOSS doesn’t automatically mean its secure or private. Also, why is it that I have to install proprietary apps only on the Google Play Store?

7 - FDroid signing keys isn’t an advantage because it requires an extra layer of trust. I’m already trusting the developer by installing their app, so the developer should be signing the keys. This is a reason why Signal is not on F-Droid.

Genghis, (edited )

This is why Accrescent is amazing. It has automatic updates for Android 12+. Also leaving the bootloader unlocked is a security risk. Using stock or GrapheneOS (better option) on Android is best because you can lock the bootloader.

I don’t mind Fdroid being around. If you’re okay with the security risk, I have no problem. I’ve explained to you the security issues and the misinformation that people give that FDroid is secure. I was just explaining their security vulnerabilities and explaining why Accrescent is a much better option for installing apps.

Signal is Flawed, Why XMPP is Amazing! (new animated video) (monero.town)

Some will curse me out for discussing decentralization and freedom. I am NOT saying the average person should be concerned with CIA spying. What I’m saying is that one should promote decentralized internet infrastructures that empower the individual over corrupt institutions, even though this threat model likely does not apply...

Genghis,

lmao please give us another chance

Genghis,

If your referring to GBoard with network perms disabled, its highly unlikely that its using IPC as keylogger. There would be way too much useless data to store and not useful. Theoretically if they were to be a keylogger, the user would have to be in a super high threat model bracket for them to do this, but there no evidence of Google ever doing this.

Also OpenBoard hasn’t been updated since August 2022. I recommend using the OpenBoard Fork.

Genghis,

There’s no evidence of them actually doing this and if they were to do it, its most likely detectable via reverse engineering.

Keep in mind setting the internet permission on gboard then giving other google apps internet access is privacy theatre. This applies to Google certified devices as well because Google Play Services are privileged.

Genghis,

The Google Play Store is more secure.

Genghis, (edited )

Why Fdroid is not secure:

  1. Hosts an outdated APK client.
  2. Utilizes an obsolete installation method.
  3. Does not take advantage of modern appstore features.
  4. Has no moderation.
  5. Has no old app deletion.
  6. Has an arbitrary FOSS only rule.
  7. Does all building and signing themselves.
Genghis, (edited )

Here is a more detailed explanation: privsec.dev/posts/…/f-droid-security-issues/

Accrescent is a new appstore that fixes all these issues but its still in alpha stage and has 11 apps right now.

I replaced fdroid with Obtainium that pulls apks from github,gitlab,fdroid,etc and it has support for auto updates. It’s a little better than Fdroid but still has its own issues.

Was there a Mullvad DNS outage today?

I’ve recently changed from dns.adguard.com to extended.dns.mullvad.net as it generally seems more privacy friendly, but it seemed to go dead for a while today. Anyone else see this or was it a me problem? I can deal with a slightly flaky service but I can’t recommend one to non-techies who just need a working adblocker.

Genghis,

It was working fine for me today.

Genghis,

I actually just installed Arch on my gaming PC a few days ago. I’ve been testing out many games with it and I’m very happy with it. I was hesitant to switch from Windows because I wasn’t sure if the game support would be an issue, but thanks to Proton, I finally switched.

No issues using an Intel CPU and Radeon GPU as of now, except the archinstall wasn’t working for me so I had to do it the normal way.

Genghis,

Lol, I did update it and still wasn’t working :(

Genghis,

Firefox isn’t as secure as Chromium browsers due to its internal sandboxing and site isolation being substantially weaker (especially on Linux). If you are on a Linux machine, I recommend you use Brave with no ad blocking extensions because first, it comes with an ad blocker by default. Also, the more extensions you have, your attack surface increases.

If you are on Windows, you should be using Microsoft Edge paired with UBO Lite as it offers the highest security and UBO Lite doesn’t have access to the site data. If you are concerned about the telemetry of using Edge, you can turn it off and if you’re still paranoid, you will have to switch to Linux at this point.

Genghis,

Been using this open source app for a while now. AirGuard

Genghis,

I haven’t been using Firefox for Android because I heard they don’t have a WebView Implementation so the firefox browser has to be used beside the Chromium WebView meaning there’s an attack surface of two browser engines. I also heard that the Firefox sandboxing and site isolation isn’t very good between websites.

I’ve been using Vanadium WebView and browser because of that.

Genghis,

Android System Webview allows apps to display browser windows in the app rather than taking you to your web browser app. On Android, chromium is used for webview. If you use Firefox as a default browser, the remote attack surface increases because they’re two different browsers with different security issues.

Site isolation enforces security boundaries around each site using the sandbox by placing each site into an isolated sandbox. Firefox doesn’t have that feature so they’re vulnerable to attacks like Spectre.

anybody have a solution for a legitimate caller ID and spam blocking service for android phones?

Hi all, through my experience, the third party apps that are supposed to do this a pure trash. I mean true caller was pretty decent, but it was packed with ads and trackers of course and the overbearing permissions that constantly tries hijacking my set SMS and dialer apps… I don’t think using a third party app is the right...

Genghis,

I’ve been using this app for about a year. Its been working well so far, but I frequently don’t receive spam calls.

Using stock Android w/o Google account/ Play Store worth it?

I hope this is not considered a low-effort post, but I wanted to ask if using stock Android without signing in to your Google account/ using Play Store is worth it. It should be more private, right? I’m planning on buying the cheapest Samsung phone there is (probably the A14). I currently have a stock Android Oneplus phone. I...

Genghis,

How is GrapheneOS overkill? Its identical to the stockOS but hardened for privacy.

Genghis,

You cant change the OS on Samsung devices

Genghis,

Yeah a lot of substantial improvements have been made to GrapheneOS in the last couple of years to expand app compatibility. There’s Sandboxed Google Play now, as well as things like the exploit protection compatibility mode toggle so that people can use apps with memory corruption bugs which are caught by hardened_malloc if they wish to. Back in the day, apps with memory corruption would crash and there would be no way to use the until they fixed their app. They now have a toggle to disable hardened_malloc per app when you want to use it regardless.

Genghis,

Is there an email client that can sort emails by Primary, Social, and Promotions like how the Gmail client does? Also when using another client to send an email, all the email contacts don’t get autofilled like how gmail has it.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • uselessserver093
  • Food
  • aaaaaaacccccccce
  • test
  • CafeMeta
  • testmag
  • MUD
  • RhythmGameZone
  • RSS
  • dabs
  • KamenRider
  • TheResearchGuardian
  • KbinCafe
  • Socialism
  • oklahoma
  • SuperSentai
  • feritale
  • All magazines