privacy

This magazine is from a federated server and may be incomplete. Browse more on the original instance.

scytale, in Proton domains blocked as disposable in disposable filter

I saw the other day Tuta complaining that Outlook has been sending emails from tutanota.com straight to junk/spam. What’s surprising is tuta.com emails were fine. So not sure if their domain change had anything to do with it, or if MS is doing the same thing as in the OP.

privacyfighter,
@privacyfighter@discuss.online avatar

Look. Outlook, Yahoo, ICloud, even Gmail provides temp mails solutions, but nobody complains or blocks them.

Also you can use something like this that will create disposable Gmail every time. So blocking Proton is totally useless

Pantherina, (edited ) in Librewolf but like... for chromium?

Ironically for Browser you shouldnt use Flatpaks if you trust the browser and you care about security.

…github.io/firefox-chromium.html

What Distro are you on? I use Firefox and Brave, both as RPM now. I actually switched for convenience (keepassxc extension works, plasma extension works etc) but they are actually more secure.

Native Chromium is poorly way more secure than Firefox. When using the Browsers through Flatpak you need to remove the sandbox, so process isolation and memory stuff is gone, and replace the specific sandbox with bubblewrap.

Bubblewrap is good, but doesnt support isolated Tabs.

There are CSS exploits, but to my understanding just using Noscript in “block all by default” mode is best for security AND privacy.

I would like to like Brave, as it is more secure, but it sucks a lot. Very bloated, tab management worse, missing extensions, damn Chromium webstore and the addon not working so no updates. It is not bad, and I want to write a hardening config soon, to remove and disable all that bloat permanently.

I would not recommend Librewolf if you are advanced. For one it is a Flatpak, ironically (didnt know this a few weeks ago too) less secure. Also it lacks behind in updates a bit, not much, but this may become a problem.

github.com/…/Arkenfox-softening

I am working on this tool, should work, that keeps your Arkenfox config up to date and sets a few switches to soften it. So you add that to Firefox and dont need Librewolf anymore.

On Fedora all you need is libavcodec-freworld from rpmfusion to get everything working. But ublue.it images work best out of the box.

Edit

Why are you downvoting this? Doesnt it fit your opinion? I also dont like Chromium, but its more secure. I also didnt know that Flatpak browsers are less secure, but thats a fact.

DangerousInternet,
@DangerousInternet@lemmy.world avatar

deleted_by_author

  • Loading...
  • Pantherina, (edited )

    I mean sandboxes are just pretty complex. Chromium relies on user namespaces for process isolation. Flatpak browsers are isolated but have no internal isolation of processes (one tab could attack another tab). At the same time the Flatpak sandbox itself relies on user namespaces, while the flatpakked browser cannot use the namespaces internally.

    Then there is the hardened kernel which disables user namespaces for security reasons, on the other hand people say running the Sandbox as suid means if there is a vulnerability processes get root access.

    Flatpak browsers put less trust in the code, but more in the maintainer that has to keep them as updated as possible.

    Its complex as fuck

    Antiochus,

    Can you say more or provide a source on why you shouldn’t use a browser as a Flatpak? Is it just because the sandboxing is potentially weaker?

    Pantherina,

    The Chromium sandbox needs to be removed and something like Zypak needs to be used.

    This means that the internal Browser sandbox is weaker and tab isolation. I could not find the source for that yet.

    flatkill.org

    Even though pretty old and probably outdated, some points are for sure true. Some apps like Onionshare are horribly outdated, and unless every app has at least one packager responsible for it, best official and paid, its a total mess.

    Chromium on Flatpak stable for the first time - GNOME blog post

    Firefox Snap vs. Flatpak

    Flatpak Browser Sandbox Challenges

    These where not the sources I refer to, and it is pretty complex. Secureblue disables user namespaces and uses bubblewrap-suid for security, but after madaidans statement that would mean a hole in bubblewrap allows the app root privileges.

    Antiochus,

    Thanks for the additional reading and information. Maybe it’s just me, but I feel like I hear about a security vulnerability in “processor microcode” or packages or other software basically every day. As a relatively non-technical user, it’s always very difficult to tell how much these things actually matter for normal users. Flatpaks are incredibly convenient because they “just work” and are easily compatible with immutable distributions. For better or worse, I suspect many people are not going to be dissuaded from using them by hypothetical/abstract security risks.

    Pantherina, (edited )

    Flatpaks are more and less secure. Their Sandbox improves 99% of apps security as other sandboxes are hard to setup and thus nearly nonexistent.

    Browsers have their own, so just dont use Flatpaks there.

    I am not sure about microcode, but processes running as root are maybe more critical, but it sounds like any process could have exploits if microcode is a problem. Also, RiscV or even ARM will be waaay better here, as their instruction set is not dozens of years old and extremely bloated.

    As we get our apps from secure repos, with projects keeping track of every Git commit etc, we just had no malware really.

    The only problem is that Flatpaks, like appimages, “just work” and dont have to evolve like the rest of the OS will. Their main goal is to work everywhere, and Devs always choose convenience over security.

    For example Portals are not implemented in most old big projects like Libreoffice, Gimp, Inkscape etc. Scribus is even X11 only. But developers will not remove the filesystem=host permission and replace it with “just all the media locations”. This will still be a problem, but at least apps could not read Kernel logs etc anymore.

    Also as they “just work” its easy to abandon them and dont update. The “outdated Runtime” Warning is a veeery good indicator of a project using old and probably insecure libraries. But afaik there is no automatic CVE patching in flatpak-builder which is a huge problem.

    LainOfTheWired, in Are Phones and Smart Speakers Listening to You? Cox Media Group Claims They Can | Cord Cutters News
    @LainOfTheWired@lemy.lol avatar

    Of course they do. It’s just they’re no longer afraid of telling us they are

    Railcar8095, in Proton domains blocked as disposable in disposable filter

    It’s a rare treat to see somebody raise a concern while at the same time doing something (PR + discussion). Kudos to you!

    I’ve seen other similar lists with the same issues (c7 I think?).

    This is going to be a mesh if all private email providers are blocked.

    privacyfighter,
    @privacyfighter@discuss.online avatar

    We fighted it out from 7c filter. Now only this and this lasts. Thank you for kind words. Only community can change this bad practice!

    uriel238, in UK porn watchers could have faces scanned
    @uriel238@lemmy.blahaj.zone avatar

    Can face scans be tricked by pictures or videos?

    soggy_kitty,

    No they need to match your ID

    taladar,

    That is not what they were asking. They were suggesting you use someone else’s ID (say, your parent’s) and a picture or video of the person the ID belongs to.

    soggy_kitty,

    Inb4 it says “you already have an account, here enter your existing password”

    uriel238,
    @uriel238@lemmy.blahaj.zone avatar

    Hi… my… name… is… Werner Brandes… my… voice… is my… passport?.. verify… me.

    digdilem, in UK porn watchers could have faces scanned

    Isn’t there already a website that shows cum faces?

    tigeruppercut,
    wyzim,

    Now, this is the type of content I browse Lemmy for

    Zahille7,

    Now that’s actually kinda fun

    Xer0,

    lol

    RmDebArc_5, in YSK - Siri Forces Your Web Searches thru G♾️gle
    @RmDebArc_5@lemmy.ml avatar

    Isn’t this illegal in the EU? They just forced MS to offer alternative search providers for their search, so this is basically the same thing?

    cheese_greater, (edited )

    I guess we’ll find out 😈 U wanna make the call?

    Waluigis_Talking_Buttplug, in UK porn watchers could have faces scanned

    Torrents are always waiting with open arms

    thevoiceofra,

    For those you’d need to scan your dick in UK.

    lorez,

    Which I’d gladly do.

    ShortN0te, in EU regulation and oculus quest

    It is. Thats also the reason why the quest is jot available in germany. (Or at least the quest 2)

    DessertStorms, in UK porn watchers could have faces scanned
    @DessertStorms@kbin.social avatar

    Good, might stop the creepy fuckers watching it in parliament..
    https://www.independent.co.uk/news/uk/politics/neil-parish-banged-up-tractor-porn-b2439583.html (I also remember and was going to link an earlier and unrelated report that was done about MPs watching porn in parliament, but that one story has drowned out all other results and it's too early for me to dig deeper)

    In all seriousness, this is obviously a terrible idea for many reasons.

    tankplanker,

    They would just exempt themselves from it as they did with both reporting on people accessing porn using the HoP network and with the investigatory powers bill.

    When they did report on it, it was a shockingly high number for a place of work: theregister.com/…/mps_binge_on_smut_theyre_trying…

    DessertStorms, (edited )
    @DessertStorms@kbin.social avatar

    Oh, of course they will, was mostly just pointing out the hypocrisy..

    And I think the report I was thinking of was more recent, but yeah, the gist is exactly the same.

    RovingFox, in YSK - Siri Forces Your Web Searches thru G♾️gle
    @RovingFox@infosec.pub avatar

    I personally believe that trusting Apple with your privacy or preferances is naive. That wasn’t and will never be their focus.

    auf,

    Still better than non-degoogled android devices though

    RovingFox,
    @RovingFox@infosec.pub avatar

    Doubt, I am not saying it is worse, but not better either.

    inson1, in Just received my Torproject Donation Merch!

    @Pantherina from what materials is the t-shirt?

    Pantherina,

    Cotton. Probably child-labor / Uigur neoslavery bs…

    euphoric_cat, (edited )
    @euphoric_cat@lemmy.blahaj.zone avatar

    wait that is a shirt? can we see it a bit better?

    edit: holy shit they have a hoodie as well? but DAMN its $500… :c

    Pantherina,

    Maybe if I am motivated I post a pic with me in a week or so haha

    ugh, in UK porn watchers could have faces scanned

    The headline is very misleading. Porn companies are considering facial recognition as an option for validating age. Governments are putting more pressure on porn websites to keep minors away from the content, but it’s very hard to thoroughly prove your identity online. A government issued photo ID is useless if you have nothing to compare it to visually. That’s why many websites use bank/credit card info as opposed to an ID.

    It is definitely a privacy concern if you worry about it being known that you watch porn, but I don’t think it’s right to fault the company.

    CrypticCoffee,

    Company? It’s the UK communications regulator, Ofcom.

    They found that many on low incomes don’t have photocard ID when they rolled out voter ID despite opposition.

    Considering no one seems capable of withholding data from motivated hackers, this could be quite horrific.

    Cwilliams, in Just received my Torproject Donation Merch!

    Tor merch is fire 🔥

    Pantherina,

    No shit I believe FOSS projects investing in PR and corporate Design like that are on a very good path. Things need to look shiny today, KDE & Opensuse icons, wallpaper contests, this is so nontechnical but attrackts lots of attention.

    Efwis, in MS Outlook Blocking Tutanota Emails As Spam

    This is just another attempt by Micro$uck to make everyone use their email services. Micro$uck doesn’t want any competition, they want to rule the computer world

    maxprime,

    I wonder if this is anticompetitive or anti-privacy. I doubt that Microsoft is even remotely concerned about the “competition” that tuta poses.

    Efwis,

    You’re right, it is probably an anti-privacy thing. God forbid they can’t do the telemetry and other nefarious that they do

  • All
  • Subscribed
  • Moderated
  • Favorites
  • privacy@lemmy.ml
  • localhost
  • All magazines
  • Loading…
    Loading the web debug toolbar…
    Attempt #