

One example is on GrapheneOS, programs can’t touch system files due to no root access, and they also can’t access data files for other programs.
Mastodon: @sudoer777@matapacos.dog


One example is on GrapheneOS, programs can’t touch system files due to no root access, and they also can’t access data files for other programs.


I’m not very good at securing Linux, but from what I’ve seen, NixOS leaves a lot to be desired. It doesn’t officially support SELinux and requires a lot of work to make it function properly. It supports other mandatory access control programs, which I’m not really sure how they compare. The store being world readable is another problem. The most obvious issue with that is if you’re doing business work with two clients on the same computer where infrastructure needs to remain confidential, where one client’s programs can read the store and see information about the other clients, even on separate user accounts.


More secure OSes limit what social engineering attacks can take place and what damage they can do.


Reddit is how I got into my self hosting hobby in my teens


Maybe I should start investing in my PC more
Nothing, I suck at sleeping and now I gave up and am browsing Lemmy


50501.chat blocked lemmy.ml, but who cares
DAB + ListenBrainz looks so awesome


The switch to permissive licensing is terrible for end-user software freedom given that corporations like Apple and Sony have leeched off of FreeBSD in the past to make their proprietary locked-down OSes that took over the market. Not sure what would happen if RedoxOS became usable in production, but if it turns out to function better than Linux enough to motivate corporations to shift their focus to it, open source versions for servers would probably still exist, but hardware compatibility on end-user devices would be at higher risk than before as vendors switch their support and stop open sourcing stuff. Or they keep focusing on Linux for server stuff due to the GPL license and the fact that their infrastructure is already on it.


Yes this is the video I watched lol. Also I use powder detergent


I use a dishwasher, but half of the dishes either don’t get cleaned or aren’t dishwasher safe so I have to wash by hand. I tried cleaning the filter, using detergent in the prewash, and running the water until it’s hot before starting the dishwasher, and none of it did shit.


I have all of my open source apps in my main profile, a Shelter profile for proprietary apps (which I hardly use nowadays), a user profile for apps needed for my university, and another user profile for apps needed for a certain gig I’ve been involved with


I use Passkeys with Bitwarden in desktop Firefox, but for some reason I can’t get them to work in GrapheneOS/Vanadium even though I have Bitwarden set as my password provider
Buying a domain and using that is a good idea, and you can also do a catch-all so you can give each service their own address and see which ones leak your data
I think they have some sort of critical security flaw regarding spoofing that hasn’t been resolved in years and they had a forum thread about it


I’d go with SimpleX Chat.
Matrix, XMPP, Cwtch are also contenders


If you want something free, Spotube has a plugin system now so you can use ListenBrainz (FOSS-friendly and knows more tracks than Qobuz, IMO recommendation system is also more interesting) for the library data, which uses a yt-dlp/Newpipe backend (they have adding alternative backend platforms on their radar). It’s buggy right now though.
I have a problem where copying from one application and pasting in another application randomly doesn’t work (using the correct key combo) but triple mousepad click to paste does work (I use Niri)


although its incorrect, i’d say their are better things to worry about
Yes, but I never said you won’t get pwned. I said that it would limit how it could be done and what damage it could do.
For instance, if you click a link and download something shitty, it can’t just steal your auth tokens on GrapheneOS because all of that is isolated to only the program that uses them. Meanwhile on Windows/Linux there are tons of Python scripts that do that. It would take extra steps on GrapheneOS for someone to use social engineering to hack someones Discord/Bank/etc account, which could be enough to prevent it for some people.