Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
oil25
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
oil25
7y ago
That's the best solution - improved privacy and sometimes even reduced gas prices when using cash.
2.
▲
by
oil25
7y ago
What's the penalty? It ought to be equivalent to a DUI, given the impairment is similar if not worse from phone distraction at the wheel.
3.
▲
by
oil25
7y ago
That's too bad, looks like I'll have to stick with GSuite Gmail to have browser-based, non-Javascript access to my email.
4.
▲
by
oil25
7y ago
Sincere question - why is JavaScript required to sign up for Fastmail? Is it for browser fingerprinting? If so, what data is collected, how is it used and how long is it retained? No specific mention of it in the privacy policy. If I sign u
5.
▲
by
oil25
7y ago
Curious how you are managing disk encryption for all those devices, if you are at all.
6.
▲
by
oil25
7y ago
Same here, but I have found wireless performance to be subpar. Ended up double-NAT'ing a second APU with Debian to use 802.11. Still plenty happy with OpenBSD though.
7.
▲
by
oil25
7y ago
> For usability while balancing security, cache PIN for at most a day. https://github.com/DataDog/yubikey/blob/master/gpg.sh#147 This statement has no effect when using Yubikey - the PIN is cached by
8.
▲
by
oil25
7y ago
Anyone disillusioned by the thought that Apple values privacy would be well served by reading iOS, The Future Of macOS, Freedom, Security And Privacy In An Increasingly Hostile Global Environment - https://gist.github.com/io
9.
▲
by
oil25
7y ago
I tried again and now get the Incapsula crap - maybe related to IP address (which changes often on Tor)? Edit: the page loads for the first time after assigning a new IP in Tor, but subsequent loads throw the captcha. Odd system.
10.
▲
by
oil25
7y ago
Characterizing this software feature as an "attack" or "backdoor" is pretty hyperbolic. In order to abuse multiplexing, the adversary needs local code execution ability, by which point you've already lost.
11.
▲
by
oil25
7y ago
Works fine here, even over Tor - Firefox 70.0.1 with javascript.enabled=false in about:config.
12.
▲
by
oil25
7y ago
I'm happy with LineageOS running on a Pixel, no Play Services and only open source applications installed over adb.
13.
▲
by
oil25
7y ago
California Consumer Privacy Act takes effect next year - https://en.wikipedia.org/wiki/California_Consumer_Privacy_Ac...
14.
▲
by
oil25
7y ago
I doubt it's possible. I think Google uses the device browser (SFSafariViewController) to do OAuth, so users aren't asked to sign in in every application. No doubt they think this is a feature. Why not simply use Google Maps in an
15.
▲
by
oil25
7y ago
Can someone post a TLDR? Twitter blocks Tor exit nodes, so the content is unavailable: > 403 Forbidden: The server understood the request, but is refusing to fulfill it.
16.
▲
by
oil25
7y ago
MAC address of your radio, plus the BSSID of every wireless network you've ever connected to and saved.
17.
▲
by
oil25
7y ago
On OpenBSD: # echo "lladdr random" >> /etc/hostname.athn0
18.
▲
by
oil25
7y ago
I agree completely. These efforts to "break" end-to-end encryption seem entirely ineffectual so long as open source alternatives exist - they are plenty and well proliferated. Banning the use of unapproved software is impractical,
19.
▲
by
oil25
7y ago
I also experienced the gigabit performance issue (Debian 9 and 10, APU4C4); estimate a bandwidth cap of about 400 Mbps, too. I don't actually have a need to exceed that speed on my home network, so I'm still happy. But also curiou
20.
▲
by
oil25
7y ago
I've been using the APU2 platform for a home network router and can strongly recommend it. I especially like the open source firmware (coreboot) with frequent, signed releases. Wireless performance on OpenBSD was lackluster, so I'
21.
▲
by
oil25
7y ago
By far the biggest tracking offender is Javascript. Enabling it could reveal your operating system, cpu/gpu architecture, screen resolution, draw a precise and unique canvas fingerprint, etc. There are also mutable browser headers like
22.
▲
by
oil25
7y ago
> The poster was concerned about video being hacked. This would be hard to hide, at least for being owned in real-time, if one were keeping track of the packets coming and going. How would keeping track of packets detect a compromised we
23.
▲
by
oil25
7y ago
> The web is made from HTML, CSS and Javascript. Considering the World Wide Web predates Javascript by many years, and the fact it's possible to create a functional, readable, and accessible Web page without Javascript altogether, t
24.
▲
by
oil25
7y ago
> Instead of assuming you could lock down your internet pipe. Use a RPi as a security appliance with strong whitelisted firewall policy. At least have some insight into what traffic is going to and from your LAN. Not only would a Raspber
25.
▲
by
oil25
7y ago
What a poorly designed site. Nothing but a spinning circle with Javascript disabled - Firefox reader mode doesn't work, either. Completely unacceptable from a privacy and usability perspective.
26.
▲
by
oil25
7y ago
It was asked in good faith and I did explain my reasoning for why anonymity and security are different concepts. Have you got a citation for the claim that Signal "uploads entire contact lists" or was this just FUD?
27.
▲
by
oil25
7y ago
> For some of us, security == anonymity. I don't follow. How is security equal to anonymity? If anything, security is what enables privacy, which could enable anonymity. There are plenty of circumstances where you need security, but
28.
▲
by
oil25
7y ago
> A private messenger should be usable anonymously, shouldn't it? It would make a good feature, but anonymity is not a requirement for privacy. I want my connection to the bank's website to be private, but there's no need
29.
▲
by
oil25
7y ago
For most users, I think maintaining exclusive ownership of a phone number is much easier than securing their email account or a traditional username+password credential, so posit it's a natural fit for a secure mobile messenger.
30.
▲
by
oil25
7y ago
I use Signal because the most important thing to me about a messenger is security and privacy. Other features notwithstanding, iMessage simply does not offer the same guarantees as Signal so long as Apple manages encryption keys vs the user
More ›