BearOfaTime

@BearOfaTime@lemm.ee

This profile is from a federated server and may be incomplete. Browse more on the original instance.

BearOfaTime, (edited )

I assume when you say externally you mean via Tailscale, but without running Tailscale on each container/service?

What I currently do is run Tailscale on a few workstation-type devices, but everything else in my network doesn’t run the Tailscale client (partly because things like printers, outers, etc can’t run the client, and it’s less convenient for things like servers).

Those type of devices can be accessed by running one Tailscale node as a Subnet Router. This device is then able to route traffic to it’s subnet. Currently I use a Raspberry Pi for this.

My Pi also runs PiHole and acts as my DNS server, so it can name resolve local resources, though I don’t think this is required, because Tailscale has its own DNS resolution called Magic DNS. So your Subnet Router should be able to resolve those names anyway (going off memory here, so be sure to check the docs, I may be misremembering how it works since I use the same device for DNS).

You don’t even need Tailscale on a remote device to access your LAN - if you enable the Funnel service, you can provide an inbound encrypted path to specified resources.

BearOfaTime,

Oh, slick!

Now you given me yet another thing to sink time into, haha.

Thanks!

BearOfaTime,

I’d say locking it down is a feature of being managed, not necessarily what it does.

When managing devices, you can enable users to have as much control as you’d like.

It’s more about being able to manage devices from a single place, similar to what business does with workstations and servers (e.g. MS SCOM.

Plenty of users still have admin rights even with SCOM being used. It still really helps from a support perspective.

BearOfaTime,

You should still be able to run your own router with it treating their router as the next hop.

BearOfaTime,

It’s $1/day. I’ve done the math a few times

BearOfaTime,

Nothing to be done. It’s old. Only fan to adjust is cpu, and I can tell when the cooler is getting dirty because the fan stays at higher speeds.

Otherwise there’s one large, slow rpm fan in the case, always on low speed.

what are your recommendations for a good privacy friendly sms app?

Hello, currently I use qksms but its very problematic and lacks basic fetures. One of those issues being you cant send videos, and sending and recieving media is pixalated or blurry because of a commpresion issue. I’ve already tried adjusting the compresion options in settings to find out it doesn’t work....

BearOfaTime,

Or just put a power test attentuator on the antenna output.

It essentially absorbs the RF from the antenna and radiates it as heat. Since cell is pretty low power (1/2 watt max, IIRC), and a cell radio will stop trying to transmit after a while (though it will try again), I don’t think it would cause any problems.

But I’m not an RF engineer.

BearOfaTime,

And some cars have it built into things like the head unit/heater control/mapping, does everything box.

BearOfaTime,

Use Tailscale with the Funnel option.

It provides a fully encrypted connection for external devices that don’t have the Tailscale client. Pretty impressive.

Similar to using Cloudflare tunnels but easier to setup.

Self-hosted VPN that can be accessed via browser extension

Currently I set up Tailscale in my Synology NAS and I can access selfhosted services on my phone using the Android app. I want to use some services in my work PC too but I’m blocked from installing any software. So my question is, is there any solution that allows me to connect to selfhosted VPN via browser extension? (Just...

BearOfaTime,

Configure the Funnel feature in Tailscale.

Funnel enables non-Tailscale clients to access specified resources in your Tailscale network via an encrypted tunnel provided by Tailscale.org.

BearOfaTime,

And those mini desktops generally idle within a few watts of the later RPi.

BearOfaTime,

Apple hasn’t shut down any other iMessage system, not the original bluebubbles.

BearOfaTime,

Wow, good for them!

BearOfaTime,

They haven’t blocked any other third party apps using iMessage.

I don’t really think they want to. It’s kind of like pirating - more people are using the service.

BearOfaTime,

I’d be shocked if Apple’s leadership hasn’t contracted a hitman yet.

Hahahahaha

It’s definitely shining a light on the limitations of iMessage, especially how imperfect it’s encryption is, so yea, that’s the kind of thing that hits a little close to home.

Next smartphone I buy, which one do you recommend?

Things that make me angry about my current smartphone Samsung Galaxy S21Ultra on a Verizon plan is the mandatory software updates in which they install WITHOUT MY PERMISSION stupid apps like Netflix and addictive gambling games and stacking block games and Candy crush. God knows what else they install without my permission. I...

BearOfaTime,

Its not hard to flash a rom these days, unlike ten years ago.

Now developers post instructions for each device type. Look at Lineage, Graphene, DivestOS. Very good instructions from all of them, including installing ADB on Windows or Linux.

Of the dozens (hundreds?) of times I’ve flashed over the years, I’ve bricked 1 device, and that was from experimenting and not following instructions, I knew it was risky.

And with Pixel it’s about as straightforward as it gets.

BearOfaTime,

This is the privacy community, I wouldn’t consider iOS appropriate here at all, since you really can’t do anything to limit the data collection. Especially not for a “what phone should I get” question. If someone already has an iPhone, asking what you can do is a good question (“not much” is the answer you’ll get).

Is it better out if the box than most Androids? Probably, maybe, depending on how that’s defined. But I can quickly make most Androids far better than iOS, even ones with a lot of vendor bloat.

For example, I recently cleaned up a Verizon Samsung just using the Universal Android Debloat Tool. This is stuff I used to do manually with ADB.

Then adding a VPN and I could restrict apps calling home and bypass Google DNS.

You can even disable google services, play, etc, and just don’t use a google acccount on the phone.

github.com/0x192/universal-android-debloater

BearOfaTime, (edited )

You nay be able to disable the installer that reinstalls those apps.

Check out Universal Android Debloater

github.com/0x192/universal-android-debloater

BearOfaTime,

How does DivestOS compare to Graphene in your opinion?

Divest is based on Lineage, which isn’t as secure as Graphene (by a significant margin), but my understanding is Divest has done some things to improve sscurity/privacy.

I realize since we’re talking a Pixel here, Graphene is the security/privacy answer. I have other phones in my “support circle” that can use Lineage or Divest, and I’d like to advise people appropriately.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • localhost
  • All magazines
  • Loading…
    Loading the web debug toolbar…
    Attempt #