Genghis

@Genghis@monero.town
0 Post – 31 Comments
Joined 1 years ago

anyone know the name of this case? asking for a friend

2 more...

Nostr must be a bigger tree

Been using this open source app for a while now. AirGuard

I'm not sure about pizza but I've heard a guy putting a casserole in his oven and forgot about it because his coworker was begging him to hang out with him. When he walked back home, his house was burned down to the ground and the firefighters told him "Some knucklehead left a casserole in the oven." He was super devastated after that.

3 more...

Nostr is awesome. I'm hoping it grows much further.

Aurora Store isnt needed because of Graphene's Sandboxed Google Play Services.

Obtainium app is best for installing APKs from github, fdroid, etc because of the auto updates.

My favorite feature of GOS is the scopes for contacts, storage, and MTE support on Pixel 8

1 more...

Passkeys are replacing MFA and passwords.

security theater

Element for matrix is actually cheeks

1 more...

pls buy a new phone lol

We go to sleep and it clears

Lol, I did update it and still wasn't working :(

I actually just installed Arch on my gaming PC a few days ago. I've been testing out many games with it and I'm very happy with it. I was hesitant to switch from Windows because I wasn't sure if the game support would be an issue, but thanks to Proton, I finally switched.

No issues using an Intel CPU and Radeon GPU as of now, except the archinstall wasn't working for me so I had to do it the normal way.

2 more...

carti

Thom Yorke 🔥

Is there an email client that can sort emails by Primary, Social, and Promotions like how the Gmail client does? Also when using another client to send an email, all the email contacts don't get autofilled like how gmail has it.

Thats so wack

Android System Webview allows apps to display browser windows in the app rather than taking you to your web browser app. On Android, chromium is used for webview. If you use Firefox as a default browser, the remote attack surface increases because they're two different browsers with different security issues.

Site isolation enforces security boundaries around each site using the sandbox by placing each site into an isolated sandbox. Firefox doesn't have that feature so they're vulnerable to attacks like Spectre.

I just use the AOSP messenger. If I used google play services, I would switch to Google messages because of RCS and it looks much nicer.

I haven't been using Firefox for Android because I heard they don't have a WebView Implementation so the firefox browser has to be used beside the Chromium WebView meaning there's an attack surface of two browser engines. I also heard that the Firefox sandboxing and site isolation isn't very good between websites.

I've been using Vanadium WebView and browser because of that.

1 more...

I think your thinking im against FOSS but you're not understanding. Many people in the FOSS community only care about privacy and ignore security. A developer can implement security benefits to FOSS but many people don't care to do it.

Accrescent is FOSS and it has much higher security benefits than F-Droid. Accrescent allows both open and closed sourced apps because there's no benefit being exclusive to having FOSS apps in their catalog.

If the user chooses to not use proprietary apps on Accrescent, they don't have to install them.

This is why Accrescent is amazing. It has automatic updates for Android 12+. Also leaving the bootloader unlocked is a security risk. Using stock or GrapheneOS (better option) on Android is best because you can lock the bootloader.

I don't mind Fdroid being around. If you're okay with the security risk, I have no problem. I've explained to you the security issues and the misinformation that people give that FDroid is secure. I was just explaining their security vulnerabilities and explaining why Accrescent is a much better option for installing apps.

The desktop security model is insecure in general. Phone OSes are much more secure.

Reasonable desktop OS to use is Qubes, Fedora, MacOS, ChromeOS, or Windows pro/enterprise (hardened)

Phones are much more secure especially the Pixel 8/pro with MTE immensely reducing remote exploitation. GrapheneOS is the only distro that enables MTE by default and recently implemented it in their Vanadium browser.

Secure phones (secure elements are important): IPhones and Pixels (GrapheneOS or stock)

Also yes, Chromium is much more secure on Linux than Gecko based browsers because of its great internal sandboxing and site isolation. Firefox on Windows is catching up though, but still bad on desktop Linux and android.

This all doesn't matter if you're running an EoL device. Make sure your receiving official security and firmware updates.

that's about it

2 more...

A lot of the security work on Linux is being done by Google. It's highly unlikely they are putting backdoors in their products.

Watch this in a dark home theater

https://youtu.be/Zgg7BgaFG1s

2 - Manual installation methods can be insecure because a lot of people don't update their apps all the time. Obviously rooting a phone is insecure, but having no auto updates in 2023 is crazy.

4 - It is very true, having zero quality control on new apps. The flagging of apps with problems is just following the FOSS philosophy. Any FOSS app can be added to F-Droid.

5 - Not sure why you would want to install abandoned apps on F-Droid, let alone use an EOL device. A lot of people don't check if apps are maintained because they trust their app store.

6 - FOSS doesn't automatically mean its secure or private. Also, why is it that I have to install proprietary apps only on the Google Play Store?

7 - FDroid signing keys isn't an advantage because it requires an extra layer of trust. I'm already trusting the developer by installing their app, so the developer should be signing the keys. This is a reason why Signal is not on F-Droid.

4 more...

I would use Firefox on Android but I'm waiting until the security is on par with Chromium such as having internal sandboxing and site isolation.

Also since Firefox doesn't have a WebView implementation, it has to be used with the Chromium based one so it doesn't make sense for me to use two browser engines.

F-Droid has many security vulnerabilities and has many issues such as:

  1. Hosting an outdated APK client.
  2. Utilizes an obsolete installation method.
  3. Does not take advantage of modern appstore features.
  4. Has no moderation.
  5. Has no old app deletion.
  6. Has an arbitrary FOSS only rule.
  7. Does all building and signing themselves.

If you want more details about these issues read this:

https://privsec.dev/posts/android/f-droid-security-issues/

6 more...

Why isn't it possible for a creator to exist?

1 more...

This app isn't fully ready yet but Accrescent is a secure and private app store for Android. It aims to be a better alternative app store on Android rather than using the Google Play Store. It currently has 11 apps right now and more to come soon.

Highly recommend to check out and support this project cuz this appstore is the best out there right now security and privacy wise.

8 more...

Why is a windows computer not my computer? makes no sense

1 more...