There’s a good write up on grc.com about it, or maybe security now ep.
You can do it for sure, but it’s a fight.
There’s a good write up on grc.com about it, or maybe security now ep.
You can do it for sure, but it’s a fight.


I’m a big fan of gpl everything, but when sudo was getting installed in everything the argument that “this great security technology needs to be permissively licensed so there will be no reason for companies to not make its use standard practice” held a lot of weight!


Another stupendous reason to gpl uutils so that the decades of experence of hundreds of system programmers can be leveraged in the rewrite.


op, if you can’t see any spyware it’s probably fine.


Brb heading to the local group home to retrieve my r-word pass


Another poster said there’s lots of ways to get past doh/dot and they’re right. The goal is to run your ech packet safely to your dns server. To that end, make your vpn server connection first then ask for ech from your trusted doh/dot server.
If you’re dealing with dpi you gotta fuck up your packets a bunch to get them through. It makes things slow.
A good way to avoid dpi is to just not deal with it. Often dpi systems are at border crossing points so if you connect to your trusted vpn endpoint inside the borders of the place you’re trying to obfuscate from you can make it out to a dot or doh.


If you say that you gotta strap it down first for safety.


Slap the top of the pc and exclaim “no spyware in this thing”.
My “I don’t need to save space, I want it for a different purpose” tee shirt is raising a lot of questions answered by my “I don’t need to save space, I want it for a different purpose” tee shirt.


To your last question there’s a technology called encrypted client hello intended to solve that problem.
Ahh, let me be clear: systemd is bad. Age verification is maybe bad.
The age verification added to systemd is a field in the userdb json that the administrator can set. It’s intended to comply with California law that requires the device attest when queried.
If that isn’t clear enough: it’s a plaintext field in a text document set by the administrator.
If that still isn’t clear enough: the California law lets you lie and the systemd implementation is designed to accommodate that allowance.
Op should use devuan to not have systemd though, that shit sucks.


We say african american solar panels now 😤


Lots of stuff breaks when you block cloudflare so a better way to avoid its data collection is to use a vpn and clear your browsing data.


We need to bring back calling people slurs on the internet.


I cannot stress enough how bad of an idea it is to try and use a boot or portable apps usb.
Schools and companies are generally very alert about that kind of thing due to many many high profile incidents of malware, ransomware, data exfiltration etc, and also all the movies and tv shows.
Bring your own device is the only way. Bring your own network is often a necessity, so be prepared to tether your phone to your device for internet access.
You also probably want to look normal too. Swallow your pride and use a mac when you do this and no one will bat an eye. Break out the duct taped together thinkpad at your own risk.
If you use Debian, even the simple “package popularity contest” is a default “no” in the installer.
That said, your personal conception of privacy is gonna be different than lots of other people’s.


Micro form factor corporate “desktops” are the easy and cheap answer here. More expensive but also easy are the n100 lil boxes. You may need to disable or cover a bunch of gamer leds.
Weirdly cheap but with one hidden cost is appletv 4k, you gotta either pay monthly or one time to the infuse (jellyfin client) app developer to unlock dolby decoding. TBH I don’t mind paying one time for software, it’s the subscriptions that bug me also it’s what we still use so that’s why it makes the list.
After all the stuff about super/bad box started getting around I haven’t been able to really trust android set tops, which sucks because the price is right on those little fuckers.
Also I often found awful support environments for safely using android tv boxes, lack of lockable bootloaders, undocumented memory for blowing the original install back in, weird variants of weird socs.
It made me do the Seinfeld at the movies gif, ymmv.


Yes the unverified apps thing will affect you no matter what. It’s not getting better any time soon. There are a lot of reasons for that.
You can’t “de-google” if you are 100% married to googles navigation service. It’s gonna become much harder to avoid play services (the google play store and all its telemetry) if you need a banking app and teams even if they seem to work now because the “reasons” above.
Other people have said that “privacy is a spectrum” in response to the following unconventional advice, and that’s true! Your conception of privacy may simply be getting away from the default apps and keeping the play store! Just keep that in mind:
If you’re actually gonna do any of the things we consider phone stuff on your phone, in terms of privacy and security it goes graphene > appropriately configured ios > a big gap > everything else.
Maybe consider switching. There isn’t a big cost difference anymore.
Speaking from experience with both android and ios platfoms including many custom roms and the alternative repos/app stores, it’s much, much easier to stay as private and secure as possible on ios.


Not pictured: subwoofer, shogun wing, underglow
You’re overthinking it.
Post whatever you found and just don’t use the banking app.