• 40 Posts
  • 465 Comments
Joined 2 年前
cake
Cake day: 2023年11月27日

help-circle







  • If you are in the US, take a look at Fidelity or Vanguard. They haven’t required the use of a smartphone app.

    Using a phone with Android 8 isn’t best practice for security by any means, but unless you are being targeted or going around downloading shady apps, it’s more likely it will run into app incompatibility issues in the coming years than anything else.

    For sites where I’m making a low-value, one-off purchase and never coming back, I’ll use a pseudonym alongside a prepaid gift card, or failing that, a privacy.com virtual card. Not quite a sustainable strategy with eBay or Amazon, especially if the package needs a signature, so I’ll just use a privacy.com virtual card and supply a P.O. Box address

    Mostly accepted that it is the way it is for these things. If the privacy-friendly option is giving up a few conveniences, I’ll take it. But if it’s keeping me from reaching certain goals, I’ll tolerate a compromise. I don’t think I’m being targeted either, so it’s all tolerable in my personal threat model.


  • I did once while abroad. None of the shoe stores had the style I wanted in wide, so I went on Amazon and found a pair which reviewers tended to say fit well. Particularly that the listed size matched their expectations when they tried the actual shoe on. Ordered the size I thought would fit me and it did in fact fit me perfectly. It lasted about a year until it started leaking at the glued seam, which to be fair, wasn’t too disappointing for a 48-Euro no-name pair.

    Granted, that was for men’s hiking shoes, can’t really speak for finding good high heels online. Other than for that one-off occasion, I’ve only shopped for shoes and clothes in-person.







  • In my opinion, the reward for rooting LineageOS is pretty limited for having to risk one of the more important aspects of the Android security model, since the base system is already decently clean. If you want to go the extra mile, you could try installing the LeOS GSI, which strips out the remaining pings to Google servers (see LineageOS column of the table).

    Definitely double check if the build you use has anything weird configured, but modern LineageOS (and Android in general) should already have good encryption by default. Not sure if LineageOS already has a way to toggle per-app network access, but if not, take a look at RethinkDNS, does a fine job without root.

    Not much you can do about the unlocked bootloader, but as long as you aren’t being targeted by some agency, sticking to trusted sources like F-Droid for apps will go a long way. I have a similar approach with two phones and minimal personal data stored on each, so I’d personally approve of those elements.

    Faraday cage might be of interest with regard to the iPhone since those can still function as their own AirTags even when powered off. But modern phones are surprisingly sensitive to signals so the slightest imperfection, especially in cheap Faraday bags, could give you away. While you’re at it, make a threat model to see if Faraday cages are necessary for your needs.



  • I was thinking something on those lines the other day. We like to say that Linux revives old computers, and I wouldn’t for a second consider putting Windows back on them, but I also have a case of hardware support so close, yet so far. I’ve two old laptops with nvidia chips from before the days of Optimus switiching, so you are forced to use the dGPU. Believe me, I wasted a whole weekend trying to make them use only integrated graphics. It was fine while they were supported under the proprietary nvidia driver, but as soon as support ended, nouveau became the only option and it absolutely crippled 3D performance, even on very old titles. Meanwhile, Windows still supports the old 340 driver needed for those graphics chips.

    Mostly comes down to hardware vendors not bothering with Linux support and open-source in general. Which leaves support for affected devices down to volunteers having time to reverse-engineer a driver from scratch. To be clear, I don’t blame nouveau at all. It must have been a ton of work to even get the nouveau driver to its current state.




  • Back in the early 2010s, I bought a new PC with Windows 8 on it. Hated the way it looked and the way it worked. I wanted my Start menu and Aero and Classic themes back. Led me to learning about Linux. But uxTheme and Classic Shell kept me happy for a couple more years.

    Then I got a laptop with Windows 10. Felt my heart rate spike as I went through the settings and found out how much more hostile to user choice and privacy Microsoft had become. When the semi-annual updates kept undoing all my hard work debloating Windows, I decided it was time to begin using Linux in earnest.

    At first, I had a dual-boot setup and jumped around between Ubuntu, Deepin, Arch, etc. Found myself booting into the Windows partition less than once a month, at which point I moved it out onto its own drive. Distro-hopping went on for about a year, after which I decided that Debian met all of my needs. Continued DE-hopping for about another year until settling on XFCE with Chicago95. Brought me enough joy to make a standardized setup in a VM, which I have since cloned to all of my computers except for the Windows laptop I keep around for work.


  • Mixed bag. I’m lucky enough that most of my work can be done on a Linux machine. Workplace does require us to bring our own devices, but the policy is extremely lax, no need to install any monitoring software or the like. Which lets me have a Linux desktop chilling on my desk.

    But I do have to keep a laptop with Windows around. We sometimes have to work with overcomplicated Office documents that break on alternatives like LibreOffice or the occasional piece of proprietary software that needs direct USB access, which Wine cannot yet provide.