My Keyoxide Idendity:

aspe:keyoxide.org:TJXAWXPMSAG6VPARJQRWNB2TPA

  • 5 Posts
  • 31 Comments
Joined 5M ago
cake
Cake day: Apr 11, 2024

help-circle
rss

Yes, I also dont understand why Peertube works so badly. It is one of the platforms with the most quality content, but its decentralization really makes it require an app.

sepiasearch.org helps here, to connect all instances and index them




Grayjay and Freetube are both fine but different.

For some reason, Freetube currently works well, Grayjay needs iOS fallback and barely works.

Grayjay follows the bigger, already implemented idea of combining multiple platforms. This is a great UX and smooth fallback when Youtube blocks again, or permanently.

Accounts can link multiple platforms, so switching is easier.

It also allows commenting, livechat, on the platforms and has on the polycentric protocol, connecting all others.

Also, it has Sponsorblock integration.





Why wont you get caught torrenting then? If this hasnt got anything to do with encryption 😉

It is safe if you use DNSSEC and TLS-only connections.

Otherwise, your ISP could still see that traffic. When using custom DNS, that server could see it.

A danger would only occur when an adversary would host a honeypot site, which is likely illegal.

Was really interesting to understand why Torrenting is so easy to discover.

I2P for everyone then?


Update your browser I guess

Maybe they are talking about Edge Webview

Use christitus winutil. It had a 3rd party script integrated that is able to remove edge. Afterwards, reinstall edge webview, otherwise a bunch of stuff is broken.

Webviews are really cool, better than Electron garbage for sure, but they tie you to the OS. at least on windows I guess you could build a hardened chromium as webview, but never heard of anyone doing that



I mean it is likely also safer as it is encrypted?

Using a VPN service and installing qBittorrent is pretty easy though


That sounds like a very strange model comparing to how empowering and decentralized real torrenting is.

There even us btfs which allows to mount filesystems over bittorrent and access on demand.

And I am sure that bittorrent over Javascript on a Website would be possible.

Like Snowflake runs as a browser extension and people connect over WebRTC




Yes Aria does torrent download and has support for an “upload” notification and finding good seeders. But I have to see if it supports seeding.


Aria2 is just for download right? biglyBT is updated more recently and also opensource for a long time, so I trust it more. But the UI sucks.


Why jshelter? Used it but dont remember the use case. I use UBO and Noscript, together with “Cookie autodelete” (as mobile has no support for allowlist websites delete all others), Bypass Paywalls Clean


Pixel 6a, GrapheneOS. Soon EOL, I would buy a 8a if you dont have a Pixel.

Novacustom Laptop with Coreboot and Fedora Kinoite.

Browsers: Mull on Android (DivestOS repo), Firefox RPM + Arkenfox on Fedora.

Torrent apps: BiglyBT on Android (seems to be the only one reasonably updated with support for seeding?) and the legendary qBittorrent Flatpak on the Laptop

I have 2TB of storage on the Laptop NVME but my VPN stopped providing port forwarding, so seeding only works to people with open ports. Nonetheless, I seed until share ratio 5 and then often delete the stuff.

Not on the phone, as I have storage issues 🥲 128GB is NOTHING





Questionable if this is only about movies, and not about any Bittorrent traffic.
fedilink


Howto unlock KeepassDX with your Secure Element
Google Pixel phones, especially with GrapheneOS, are worlds more secure than other technologies. Every user account is decrypted with a key generated by the secure element, and the pin is just used to unlock that key. But the secure element is rarely used in other applications. Here is how to unlock your [KeepassDX](https://github.com/Kunzisoft/KeePassDX) Storage with it: 1. Create a password storage with a very secure and long password. Length is especially important, prefer to use tons of nonsense words, over hard to remember symbols 2. In [KeepassDX](https://github.com/Kunzisoft/KeePassDX) Settings, under "unlock settings" enable "use system unlock" 3. Enter the password for the password storage. 4. Instead of pressing Enter, press on the button in the bottom left to register the password in the Android Keystore. From now on you can unlock your password storage using all the security that your device offers. The only weakness is the password, so make it as long as possible. To copy-paste passwords relatively securely, you can use [Florisboard's](https://github.com/florisboard/florisboard) internal clipboard. Enable "sync from system clipboard", and disable "sync to system clipboard". If you copy things using the button on Florisboard, it will only be saved in Florisboards internal app storage, not your system clipboard, which is accessible to all input devices (keyboard apps) and foreground apps. To delete things from the system clipboard (which only holds one entry) you can use [apps like this one](https://github.com/amnesica/ClearClipboard) I recommend [Obtainium](https://obtainium.imranr.dev) to get the latest versions of these apps. [Here is a list of available app configs](https://apps.obtainium.imranr.dev/)
fedilink

“Privatephoneshop” and “Myntex” are scam, selling insecure devices, and harrassing a GrapheneOS developer
## Background & Licensing How comes GrapheneOS people find themselves in situations like these often? Their software is all permissively licensed, allowing vendors to make it proprietary. Mainly though, they allow them to restrict user freedoms by not allowing to install another OS than GrapheneOS (which is the most secure OS anyways). Cryptographic verification of the OS can be done with the Auditor, you dont need to reinstall to verify it is not malware. Still, they contact stores that sell end of life or insecure phones, to stop doing this under their name. PrivatePhoneShop sold devices as old as the Pixel 4a with GrapheneOS. ## Is an EOL phone not secure? I have a pixel 4a and GrapheneOS is awesome, I still get security updates at least as frequent as normally on LineageOS. But it is end of life, meaning Google and the hardware suppliers dont support it anymore. This means - firmware issues of any kind will not be fixed (the vendor needs to sign the firmware, this is not possible for anyone else) - the kernel, specificically patched for this device, will not be upgraded to the next LTS kernel, thus losing support in a while. This would be possible, but is immense efford without Google doing it upstream in AOSP. ## "privatephoneshop" Following the Mastodon post, you can see "privatephoneshop"s selection. They sell devices that are not cheap, but pretty cheap. ## Ease of Installation by yourself You can buy a used Pixel 7 for that price and flash GrapheneOS easily, using [the webinstaller](https://grapheneos.org/install/web), even from another Android phone, with zero Terminal knowledge needed. ## CalyxOS and LineageOS PrivatePhoneShop sells devices with CalyxOS, which is a lot less secure in its architecture, and delivers slower security updates. It is less secure, because their webview is not as hardened, they dont use hardened_malloc, they preinstall random 3rd party apps etc. LineageOS is not privacy hardened at all. It may now be degoogled, after GrapheneOS's effords to replace every connection to Google, even for Widevine DRM or A-GPS (SUPL) with at least their selfhosted proxy servers, stripping sensible data. Only DivestOS can be assumed as reasonably secure, implementing sandboxed microG and other important architectural security measurements. GrapheneOS recommends DivestOS if your device is EOL or not supported. So the store is selling phones with insecure software, that are also past or near the end of support by upstream. ## Background on Android updates There is no phone company that supplies as fast and complete security updates as Google. Google publishes recommender AOSP security patches, and a complete set. Pixel phones get all of them, while most other cheaply made devices struggle to even get the recommended ones. GrapheneOS has updates about once a week, which is insanely good. Btw, Fairphone plays in the same bad league as the cheap manifacturers, getting only the minimal amount of updates. ## Hardware Google Pixel phones are not just a choice because GrapheneOS devs love Google. They are the only phones that [meet their security requirements](https://grapheneos.org/faq#future-devices) Since they expanded their security fixes, like implementing a way to disable the USB port (which involved a ton of lowlevel work and is more secure than what Android ever shipped), this list is a bit long. But even the minimum requirements are not fulfilled. Samsung is close, but security features like verified and measured boot are arbitrarily blocked for external operating systems. ## Debates & Harrassment I only focus on this case now. GrapheneOS transparently asked them to stop selling EOL devices under their name. Maybe they also asked to stop selling CalyxOS and LineageOS devices along with them, but "privatephoneshop" didnt give any evidence for that. As a response, "privatephoneshop" posted [this joke explanation](https://privatephoneshop.com/why-we-no-longer-sell-phones-with-grapheneos/) > While GrapheneOS remains a top choice for security and privacy, we feel the toxic nature of its founder (and specifically his attacks on our business) no longer make GrapheneOS a viable choice. For YOU, because you scam people. LOL > Early in November, GrapheneOS sent us a message on X (fka Twitter) stating they did not approve of our selling older phones such as the Pixel 4a with GrapheneOS, nor did they approve of our offering CalyxOS as a choice. > Having previously seen how a typical conversation with GrapheneOS goes (more on that below), we blocked them. Wow. Does this need any explanations? But it gets better: > Why we sell older phones like the Pixel 4a > - Not everyone can afford a newer phone. You sell outdated devices for up to 650$. People can buy used Pixel 7 phones on eBay for like 200$. You can do that too. Sell refurbished ones, better than insecure ones. Repairing pixels is easy (in contrast to repairing OnePlus phones, wtf OnePlus). > - Not everyone wants a phone made by google. LOL. I think I explained why this is not some fanboy choice. > - Not everyone wants a 5G phone. What? You can just disable 5G in the settings to my knowledge. Also, WIFI is always using something similar to 5G. These are fake arguments, hiding behind esotheric misinformed people. > - Not everyone wants a large phone. Very understandable, I miss my (honestly underpowered) Pixel 4a, also for the headphone jack. But this is a tradeoff, if you sell "privacy phones". There is no privacy if you can get hacked. > - Everyone has a right to the level of privacy and security that they desire. So, sell refurbished phones or upload instructions yourself on how to do it yourself. ## Thoughts I honestly think GrapheneOS should switch to a license that actually gives them some teeth. Bitching around back and forth on "social media" sounds like a pretty annoying thing to do ***apart from delivering the most secure OS on the phone market***. I am also very unhappy about Louis Rossman and Techlore for spreading bad opinions on them. Yes, the devs can be harsh, yes they are sometimes a bit annoying. But [look at their Github issues!](https://github.com/GrapheneOS/os-issue-tracker/issues), 500 open, over 2,5k closed! They do ***free Software*** that helps anyone to be as private and secure as possible. They are a blessing for our world. Please donate to them, as they are doing an incredible job. Btw, they are also against Nazis.
fedilink


True, you lose all encoding. I didnt try but I think Firefox on Linux with Wayland does not block screencasting. But dont tell netflix that


Unexpected and supercool editor’s note subtitles
I watched Star Wars Episode VII I think and on the start scene, suddenly there was random talking in the subtitles. Then I found out that was George Lucas, talking through the entire movie, transcribed as subtitles. Was super fun and interesting, nice work! Stuff you only see when getting Torrents XD
fedilink



If you do interesting stuff, use a good VPN. But those will also have to either delete their logs (Wireguard is actually worse here) or be brave.

Or Tor…


Nobody asking themselves how they got all these details of that person?

Reddit doesnt require a full name.





This is so fucked up.

We need to use other methods than voting. We are so close to a complete surveillance dystopia in Europe. And it is already really bad.