Welcome to Incremental Social! Learn more about this project here!
Check out lemmyverse to find more communities to join from here!

Pantherina

@Pantherina@feddit.de

This profile is from a federated server and may be incomplete. Browse more on the original instance.

Pantherina ,

Discourse is awesome. Just needs federation.

As a mod, it is lovely to work with, extremely well indexed, has tags, categories, roles and everything you want.

Everything should be done there. Matrix or Discord make no sense, its just chatting into nirvana, nobody every finds it again

And people... dont... use... threads! They just spam everything in a single chat which makes it unusable

anders , to Memes
@anders@sharkey.world avatar

Data storage vs backup storage

@memes

Pantherina ,

"Let me my freedom"

Pantherina ,

Literally a KDE setting. In the GUI.

And nobody needs that, otherwise there would be a plasmoid.

Pantherina ,

Yes, "because one of their council is leftist pro censorship"

Like this crap

Pantherina ,

Dont use "stable" software people.

Gimp 3 is already very nice! Use it exclusively.

Pantherina ,

I mean I already reported 2 issues, but it still works. I can use it without big problems, I use the beta Flatpak (as explained in my flatpak remotes list).

Using Wayland too, Idk about any problems but if it wouldnt work I would just disable Wayland for the Flatpak and the app automatically runs through XWayland

Pantherina ,

Burner phones are a strange concept. If you want to store sensitive data on it, you shouldnt use some cheap android phone or even a dumbphone without encryption support.

Pantherina ,

All Android phones have Google malware installed by default, as system apps, which means those apps can do whatever they want.

So every piece of data you put on there is possibly tracked and collected.

Then there are 2 more problems

  • the software is proprietary and cannot be externally wiped clean
  • the software is outdated

This makes it vulnerable to Pegasus attacks and others. There are tons of secure practices to avoid getting it, like LTE-only, HTTPS only, encrypted and trustworthy DNS, sandboxed processes, blocked javascript execution from unknown websites...

But still if the phone is outdated there are unpatched and publicly known security issues. Just spamming them at all phones is likely to succeed as so many people run vulnerable versions, as vendors suck.

Then if you have pegasus, the only way for security is to reflash the A/B partitions, both. Factory reset is not secure as it will keep what is already in the system partitions.

The firmware is protected and signed by the vendors, so it is likely clean.

But Pegasus installs itself to the phone storage.

If you A cant obtain factory images or B cant flash the phone at all, you cannot wipe it clean.

So a good activism phone needs

  • trustworthy and minimal system apps / stock software
  • modern software updates
  • possible to reflash whole device externally
  • nice to have: ability to verify checksum of system partition, like GrapheneOS Attestation

This makes them poorly pretty expensive. I think a slightly outdated GrapheneOS phone is okay though.

Pantherina ,

I think 3a is already too old. I think 4a is a better minimum, but this is still insecure of course.

Pantherina ,

Yes I know, and I want to try DivestOS one time. But they do incomplete patches.

They cannot update the kernel themselves or even worse the firmware. The kernel needs to be built and patched for the specific hardware, GrapheneOS relies completely on Google here. And the firmware needs to be signed by the vendors, so no chance either.

And especially baseband, cellular stuff has extremely many vulnerabilities in the code.

Pantherina ,

Not sure if VPN eliminates all risks with 2G and 3G, maybe it does.

Sandboxing, javascript

Vanadium has sandboxing but its javascript blocking is useless (no granular control)

Mull has no process isolation at all, but support for UBO and Noscript. Bad situation

it's a walk in the park for it to modify any of the partitions

These cannot be written without TPM verification or stuff, ask GrapheneOS devs about that, I dont know. The firmware signing is required, the verification will not be done inside the OS, that would be totally flawed.

If they have the firmware signing keys, they can fuck you. If they dont, they can only write to the system partition, and Attestation can see that.

Reading data has nothing to do with that. They likely can, but that doesnt matter.

My 6 years old phone still receives LOS updates

This will not include firmware and likely even the kernel.

Pantherina ,

Yes that is one definition.

But what if you get it back? Or if you just keep it?

There is a chance that you have Pegasus on there, and I wouldnt want a phone without the detection of this.

GrapheneOS can likely detect pegasus with their Attestation and if you have it, use an external device to reflash it.

Pantherina ,

Not sure but GrapheneOS has an "LTE only" mode, stock Android only has preferred Network afaik.

visiting only known websites is not a scaleable option, a browser needs to be secure. Kiwix is the browser that basically runs desktop Chromium on Android, so it has Addon support. But that is also soon manifest v3 restricted, and likely pretty insecure.

of course the user data partition is not checked, but every other important one. I have not tested what would happen when it is modified though.

I dont know what magisk did, but I think that is only about Google Play adding their "safety" scanning to the OS. Nothing regarding boot. But yes, likely there could, can or should be OS components scanning things too.

Googles stuff is pretty insecure, for example the latest SafetyNetFix simply disabled hardware cryptography, as they still support insecure phones.

For sure this is very complex and there are always vulnerabilities found in Android and GrapheneOS.

Pantherina ,

The Best Secure Email Providers in 2024 (blog.thenewoil.org)

Like it or not, email is a critical part of our digital lives. It’s how we sign up for accounts, get notifications, and communicate with a wide range of entities online. Critics of email rightfully point out that email suffers from a significant number of flaws that make it less than ideal, but that doesn’t change the...

Pantherina ,

Mailbox.org missing, pass

Pantherina ,

What, source?

How would you block an OS?

And btw there are some reasons why GrapheneOS may be criticised

Pantherina ,

Thanks! TLDR spamhaus (a big spamlist provider) has them on their spamlist, or maybe not, and they are using some fancy CDN.

It is VERY likely just a technical error.

Pantherina ,

I dont get why people would care for influencers

Pantherina ,

Do gorillas kill babies of other animals, monkeys or humans?

I just dont really believe that Harambe would have done anything to that baby.

Pantherina ,

There is no existence or Harambe anymore 🥲

Pantherina ,

For sure...

Pantherina , (edited )

Software that doesnt store private metadata

  • grapheneOS cam
  • opencamera (not by default!)
  • KDE spectacle
  • android GrapheneOS screenshots
Pantherina ,

For sure, edited it. GrapheneOS screenshots have no metadata afaik

Pantherina ,

VPNs are not meant for privacy. The concept is clunky, as is the concept of our internet.

Tor or I2P are made for privacy, but the interactions with the clearnet have the same problems, you need a legal entity hosting the server, IPs are known and can be blocked etc.

Hosting your own VPN does not anonymize you anymore but is very unlikely to get blocked.

Pantherina ,

Like.... the Intel ME?? And no BIOS seems to allow the switch to disable it, even though that was literally required after the NSA sued Intel?

Pantherina ,

Very nice tool for usage and development!

Pantherina ,

Any system app on Android, the captive portal login and more CAN all bypass a VPN in "block all other connections" mode.

Android is really problematic and having as little system apps as possible is the only fix.

Based on a true story (lemmy.world)

My OS is on a 512gb M.2 drive, but the main storage on my laptop was a 1TB HDD, it started making noise about 2 weeks ago so I backed everything up onto a 1TB SanDisk USB SSD. This afternoon it got very clicky when I booted it up after work and icons for a few games I had stored on it, like KSP and YUZU, disappeared from the...

Pantherina ,

This. Androids permission toggles combine multiple ones. GrapheneOS actually adds more of these toggles, as some things like Network and various sensor permissions are always on (wtf Android). But even those are combined toggles.

You can also display more permissions on the permission page, top right.

Pantherina ,

There’s long been a very strong, racist tendency in the liberal environmentalist movement to blame ecological harm on the number of human bodies that exist. They want us to believe that earth’s degradation would cease if there were fewer people available to consume the fruits of industry and especially agriculture (which is where we get into nitrogen’s domain). We’re exposed to white men who rant about the “population explosion,” or the “population bomb,” phrases which draw easy but still potent double-meanings in the context of nitrogen. Obviously, these writers are stooges of the regime, pushing our discourse away from the real issues. They should be systematically ignored.

Yes, the total number of humans that exist at any one time has increased over the time of the reign of the dead god, and that’s not a coincidence or accident. But animal bodies, whether human or bovine or chicken, can create only so much ecological damage on their own: pre-industrially, they created none, as the ecosystem re-absorbed the ammonia from their shits. What matters is the subjecting of bodies, not just bovine but also chicken and fish and human, to ecological shortcuts and industrial expediencies of scale that arise from the capitalist imperative. What matters most of all is the amount and type of exosomatic energy that is applied to the means of production. What matters is energy in calories and kilowatt-hours. That’s what mattered when all energy was labor, and still matters today in the exosomatic regime.

It’s important to remind ourselves of scale, for which we can use Buckminster Fuller’s concept of “energy slaves.” Somewhere after Fuller, an energy slave was defined to be the energetic equivalent to a human working 24 hours a day, 365 days a year. In fact, Fuller adopted the less-stupid standard of a healthy individual working 40 hours per week. That amounts to 3 kilowatt-hours (kWh) per week—it did then, and it does now; human bodies have not changed all that much. The American oil industry produces about 9 billion kWh per week, or about 3 billion energy slaves. (Never count consumption; always count production.) There’s no reason to divide that up per capita, since it’s the oil industry and not citizens producing all that energy. But if you did, it would work out to nine energy slaves for every human body, just from oil, not counting coal and gas. Unlike living bodies, these energy slaves are actually jinn that live within pollutant molecules and that bring pestilence upon our cities in one form or another.

Nonetheless, the population has increased, and that is because coal oil and gas could be mobilized to synthesize ammonia (NH3) without organic input, which is why this precedes an essay about Nitrogen.

Pantherina ,

Until its known by people that actually know stuff, avoid it

Email service that integrates well with Thunderbird?

I hope I'm not annoying you kind folks too much with my ongoing Tutamail woes, but, in the long slow process of divorcing myself from them (and returning to Thunderbird), I'm looking for an email host/provider that integrates well with TB, meaning that it can sync mail, contacts, calendars, and tasks between the Linux desktop...

Pantherina ,

Mailbox.org is nice and has calendar which works with TB. They also have tons of aliases in the 3€/mo plan, temporary addresses, enforced TLS encryption domain etc.

Pantherina ,

When Elon didnt want to path the xz backdoor so you get remote-rickrolled

Pantherina ,

It is not, it requires a private key to be used.

Pantherina OP ,

Social= contact with people you want to contact

Privacy= the stuff you share is not sent to random people but only who you want to

It uses the Matrix protocol which is kind of a red flag because of performance, but its encrypted.

Pantherina OP ,

Nice, own Gitlab instance with locked registration (?) so I cannot report this bug:

https://feddit.de/pictrs/image/bca9b7c5-03f4-46b9-852b-5ec7df356b58.png

Pantherina OP ,

Oh nice, its from their repo not f-droid

Aurora Store on GrapheneOS: Server not found? (lemmy.today)

I'm running the latest GrapheneOS with no VPN and yesterday it was failing and saying "if you're using one, try disconnecting from proxy/VPN" and today it's saying server not found. This happens regardless whether I click on Anonymous, or Anonymous (insecure)....

Pantherina ,

It is default

Pantherina ,

Yes. It is only needed for /storage/emulated/0/Android/obb which is legacy afaik and GrapheneOS has a specific toggle just for this.

Pantherina ,

This is awesome!

mkdir Git && cd Git
git clone https://git.nixnet.services/DUOLabs333/Photopea-Offline.git
python3 -m http.server --directory www.photopea.com 8080
xdg-open http://localhost:8080
Pantherina ,

I installed Zorin in a VM. The install crashes when testing in live mode and then installing.

Apart from that, its really no better or less messy than GNOME with some extensions.

‘Mamma Mia!’ Stage Star Sara Poyzer Replaced By AI On BBC Show To Recreate Voice Of Dying Person — Update (deadline.com)

The BBC has issued a statement that offers important context to Sara Poyzer’s viral social media posts. The British broadcaster said it is using AI technology in a “highly sensitive documentary” to represent the voice of a person who is nearing the end of their life....

Pantherina ,

"Recreating the voice of a dying person" is such a weird phrasing. They want to show the voice that a dying person had in the past.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • incremental_games
  • random
  • meta
  • All magazines