umami_wasbi

joined 1 year ago
[–] [email protected] 6 points 15 hours ago

Utill you're no longer live in the US. I can't find Ptivacy alternatives after moved out.

[–] [email protected] 3 points 1 day ago

I wish it can be installed as PWA

[–] [email protected] 2 points 1 day ago

Unfortunately, the work profile is already used up.

[–] [email protected] 6 points 2 days ago

When it allow screenshotting

 

(Rant)

At somepoint, HSBC decided KDE Connect installed via F-Droid is less secure.

Photo of the HSBC UK app urging I install KDE Connect via GPlay or Galaxy Store

Then it decide non-whitelisted keyborads are a security risk. Only Gboard and Samsung Keyboard is confirmed within the whitelist.

Photo of the HSBC UK app telling me to switch input method citing security risk


I understand the point that risk can be introduce at various points, yet this is simply too much. Yeah there are people phone infected by malware but from Play Store. Not a single time I heard one ever happened on F-Droid distributed apps, at least not from the official repo. Also, I will put more trust on an open source keyboard than any proprietary keyboard.

Furthermore, I'm shocked that an app can read my app list, and current keyboard (introduced in Android 14). This just make building a profile much easier as I belive everyone almost have an unique set of apps they like. I don't think any apps need such functionality. Why the f it needs to care what input devices I uses? This make me worry more about untold (aka burried deep in Privacy Policy) data collection.

[–] [email protected] 8 points 2 days ago (1 children)

Unless you want to game. Anti-cheats are notorlessly anti-virtual machines.

[–] [email protected] 17 points 3 days ago (1 children)

So use what browsers? Chrome sounds more secure (I didn't read previous post), yet I don't want an advertising company looking at my browsing habbits, nor supporting them dominating the browser market share and have a powerful influence on every web standards.

[–] [email protected] 1 points 3 days ago (1 children)

Maybe. I'm not in the loop but I believe you would need to gain some solid trust from the core team to get that access. It won't be a knowledge just flows in the scene up for any newly join members to grab.

[–] [email protected] 3 points 4 days ago (1 children)
[–] [email protected] 2 points 4 days ago* (last edited 4 days ago) (3 children)

So posts from a blocked instance to a subscribed community on another instance is blocked? This is what I want but I don't see it do anything.

24
submitted 4 days ago* (last edited 4 days ago) by [email protected] to c/[email protected]
 

There is "block instance" under "settings > blocks" but what does it do? I added a few onto the list but it seems does nothing to remove contents links to the instance.

What I want to achieve is to block all users post from specific instances when spams are high.

[–] [email protected] 2 points 4 days ago* (last edited 4 days ago) (3 children)

AFAIK, L1 are hardware backed using Trusted Execution Environment like ARM TrustZone. Unless you can find an exploit to exfil the key from the chip, you have no luck. It was done before and published, but I believe it is patched already. Anyone holding such exploit would keep close to their chest to avoid it beimg patched.

 

How come this wasn't getting more attention?

 

There are reports in Registar's comment section that Malaysia didn't only redirect DNS traffic, but took active measures to block VPN, and MITM DoH where Cloudflare's DoH returns local ISP certificate.

In fact, some ISPs like Maxis and Yes were already blocking VPN (I see a lot of complains on Lowyat.net about Maxis blocking VPN, and I was using Yes WiMax and experienced the blocking firsthand. I couldn't connect to PPTP endpoints and L2TP endpoints caused the modem to disconnect from the network and reboot).

They were outright trying a MITM redirect attack on those using DOH. Many reported error messages saying that Cloudflare's DOH server were practically returning the certificate for Telekom Malaysia's DNS servers.

Even with many new technologies, I ralized that I not as safe and free as I want to be, maybe you too.

 

If $70 +$10/mo can get me through all those annoying CAPCHAs, I will gladly pay. Of course, if cheaper or even free solutions exists, I will use it. My only requirement is it work 90%+ of the time.

 

tl;dr: only applies to NY Eastern District, and likely only US citizen can enjoy

5
submitted 3 months ago* (last edited 3 months ago) by [email protected] to c/[email protected]
 

I want to check if my Lenovo T480 is afftected by the recent PKFail, but have no idea how to extract the bios firmware for validation. Can someone detail the steps? Thanks.

38
submitted 3 months ago* (last edited 3 months ago) by [email protected] to c/[email protected]
 

Just wonder what if my mail server went offline for some periods, and the sending party couldn't deliver.

Will there be any consequences except I don't get the mail? I tried searching but they all in the perspective of a sender and get a bounce, rather the other way around.

18
submitted 3 months ago* (last edited 3 months ago) by [email protected] to c/[email protected]
 

Saw they have promotion £1/mo without setup when paid for a 12mo contract for the lowest end VPS. Anyone use it before?

Just planning to run frp on it. https://github.com/fatedier/frp

 

LOL

view more: next ›