[-] solrize@lemmy.world 1 points 14 hours ago

Tools:preferences, about:config, file downloads, form prefills, remember password, etc. yes you can try to lock everything but it's too easy to miss something. And then there are outright RCEs. There's just too much attack surface.

[-] solrize@lemmy.world 7 points 15 hours ago

There's no way to srsly prevent a full-bloat browser from messing with its environment. Make a static VM image and reboot it at the beginning of every session.

[-] solrize@lemmy.world 5 points 1 day ago

It's easier now that there are some control headers for it. At the time I tried a lot of things like bouncing through javascript opening a new window. Results varied by browser. The simplest way was to inconvenience users a bit by supplying text urls for them to paste into the nav bar, instead of clickable links.

[-] solrize@lemmy.world 25 points 1 day ago* (last edited 1 day ago)

I had some private pages a while back that linked to unrelated pages on other sites. I had to go somewhat crazy to stop the private urls from leaking to the external sites through referer headers when my users clicked on the links.

If chrome is sending people's browser histories to Google that is invasive.

[-] solrize@lemmy.world 9 points 1 day ago

Old but classic.

[-] solrize@lemmy.world 3 points 2 days ago

What does that even mean? But yes lots of us run Linux on servers. Just ssh in. Or even just wipe the VM and launch a new one if you want to upgrade.

[-] solrize@lemmy.world 4 points 3 days ago* (last edited 3 days ago)

A classic. Klaatu barada necktie!

[-] solrize@lemmy.world 2 points 3 days ago

You can get right angle 3.5mm connectors that help with the cable durability, but yeah, serious full sized wired cans use 1/4" or XLR connectors still, I think. There are some lightweight bluetooth headphones that might not be BIFL but could hold up pretty well, especially compared to those silly airpod-like buds. You probably have more experience with those than I do though.

https://www.adafruit.com/product/1700

[-] solrize@lemmy.world 3 points 3 days ago

Oh I see. The Sansa Clip is an old school device where you transfer files by USB. There are certainly Android phones with 3.5mm jacks though.

There are what I'd call BIFL blueotooth headphones but they are full sized cans, not earbuds. I wouldn't want to ride a bike wearing them.

[-] solrize@lemmy.world 6 points 3 days ago

SanDisk Sansa Clip is the size of a matchbook. Not fancy but not a brick. Get the model with the micro SD slot and you have unlimited storage. With Rockbox it might even support sdxc so you can use a 2tb card. Otherwise 32gb limit.

It still has an internal battery (I hate those) but people have managed to replace it.

[-] solrize@lemmy.world 4 points 3 days ago

Use wired earbuds and a player with a 3.5mm jack. BIFL for that stuff is kind of difficult though. Just buy cheap and replace now and then.

5
41
submitted 2 weeks ago by solrize@lemmy.world to c/android@lemmy.world

People keep mentioning GraphineOS as a reason to buy a Pixel, but in other regards the Pixel hardware doesn't seem so great. If you get a different phone that can run Lineage, is Graphene really better? Thanks.

115
submitted 3 weeks ago by solrize@lemmy.world to c/news@lemmy.world
124
submitted 1 month ago* (last edited 1 month ago) by solrize@lemmy.world to c/android@lemmy.world

Samsung Galaxy XCover Pro 4G. From 2022 but there are newer models. So stop saying HUR HUR WATER RESISTANCE when people ask for phones with swappable batteries. This shows it can be done.

Edit: was $120, now sold out.

275
submitted 1 month ago by solrize@lemmy.world to c/science@lemmy.world

Many voters are willing to accept misinformation from political leaders – even when they know it’s factually inaccurate. According to our research, voters often recognize when their parties’ claims are not based on objective evidence. Yet they still respond positively, if they believe these inaccurate statements evoke a deeper, more important “truth.”

33
submitted 1 month ago by solrize@lemmy.world to c/privacy@lemmy.ml

Is it ok? Is there something else you recommend instead? I tried nextcloud talk and it was pretty bad. Jitsi was ok but self hosting it looked complicated. FOSS only, of course.

132
Is Telegram really an encrypted messaging app? (blog.cryptographyengineering.com)
submitted 3 months ago by solrize@lemmy.world to c/privacy@lemmy.ml

Blog post by crypto professor Matthew Green, discussing what Telegram does (I wasn't familiar with it) and criticizing its cryptography. He says Telegram by default is not end-to-end encrypted. It does have an end-to-end "secret chat" feature, but it's a nuisance to activate and only works for two-person chats (not groups) where both people are online when the chat starts.

It still isn't clear to me why Telegram's founder was arrested. Green expresses some concern over that but doesn't give any details that weren't in the headlines.

143
submitted 3 months ago by solrize@lemmy.world to c/technology@lemmy.world

Basically more everything. 2x Cortex M33 cores with floating point, 520KB ram, more PIOs, bunch of secure boot stuff (I have mixed feelings about this), and can boot to a mode with risc-v cores instead of the M33s.

372
38
submitted 4 months ago by solrize@lemmy.world to c/degoogle@lemmy.ml

I get spammed by them all the time but have so far resisted and stayed with my crappy, slow, and expensive ADSL provider out of principle. But the ADSL provider just raised prices on me AGAIN and it's ridiculous.

What do I do? Is Google Fiber as invasive as other Google stuff? What if I just use it to tunnel a VPN to a non-Google endpoint?

This is sure annoying. It occurs to me that Comcrap might be available here as an alternative, but that must be as evil as Google. At least the ADSL company is reasonable about privacy, as such companies go.

Thanks for any thoughts.

42
submitted 4 months ago by solrize@lemmy.world to c/fediverse@lemmy.world

It's a pain that search results on lemmy show by default ordered by some useless relevance ranking. I can't think of a single time I didn't want newest first. I couldn't find a preference to request that. It would be great if there was one.

The suggestion on c/support on lemmy.world was to make this kind of request on github, but it seems anti-FOSS to me to require a Microsoft account for a fediverse request, so I'm posting here and hoping for the best.

Thanks for any consideration!

6
submitted 7 months ago* (last edited 7 months ago) by solrize@lemmy.world to c/voyagerapp@lemmy.world

Voyager 2.3.1 on Android. I visit a community and select "hide read posts" and those posts disappear a they should. But there is no apparent way to undo this. The pulldown still has "hide read posts" instead of "unhide" them.

view more: next ›

solrize

joined 1 year ago