Skip Navigation

User banner
Posts
120
Comments
3,420
Joined
3 yr. ago

  • Yeah know that deleting post fun. Jerboah is very good at recovering them.

    Bubblejail just got an update that should fix DNS on Fedora! Just has to arrive in Secureblue (rusty-snakes fedora-extras, qoijjjs fork, COPR)

    If you use your GPU that model is fingerprintable through WebGL stuff. There is a firefox addon that spoofs random values though. Same for screen size.

    Yes, secure projects are nice, if they do something then right.

    Yes a Pixel is less trackable than some random phone. But still, trackable. Letterboxing and software rendering could be needed by people.

    Secureblue does not implement privacy over security, but if patches make a browser stay just as securely I think that would be fine.

    The thing is, for example we had some arguments about manifest v2 extensions (which can download stuff they then use, i.e. no control by Google and thus "less secure"). If Chromium does things like Connect to Google for security stuff like Safe Browsing, this will totally not be removed.

    Also you can install any browser you like, just not Firefox (as that is override-removed). I have a PR open to make Librewolf work with hardened-malloc, hope they react soon...

    Secureblue is not GrapheneOS too. It is just a (huge) compilation of patches and patched images. Basically every Desktop with Wayland support, currently 86 (!!!!) images.

    Doing something like hardened degoogled Chromium with sync capabilities would happen outside of the project.

  • Its overcomplex. For sure I could get used to it and maybe this is the way to go.

    But you could wrap this tedious process in a function.

    Fedora has a distro upgrade command (that totally sucks but okay) since many years, while on Debian I needed to follow some random Guide to get on the hyped Debian 12.

  • Probably I got none, just this "do you want to use the maintainers version" which is always a bit confusing. VirtualBox also gave issues but just dont use that crap.

  • Really cool! How is the database stored, can it be encrypted using the masterpassword, or a different one? Can it be only loaded into RAM?

    On traditional desktops like any app can read your browser data, which would be very problematic.

  • No it doesnt, it is a password and a secret stored on that device. A password might get stolen on the database, or entered on a fishing website, but with 2FA that would be useless.

    It goes against ONE idea of 2FA, that phones are more secure (thanks Android) and your Browser might get hacked.

  • Thanks a lot! I selectively keep cookies for login sites, which is not a good solution.

    The threat is websites escaping the browser sandbox and reading stuff. I dont know if this is really that realistic though.

  • I think what Brodie showed at the end was already really great. I know a graphics designer and number 1 rule is to never use black and white.

    But of course this only works if you have full control over all apps, libadwaita? Dont theme my apps? Damn Electron?

  • What does "block nazis on his profile" mean, like block comments?

  • That techlore guy just confused furry art with CSAM and dropped that in a video as if it was nothing.

    Chris Titus did a really stupid video about that too.

    I dont remember Brodie actively harassing them. But of course that whole thing was not nice.

  • I like Brodie and click on every video lol, the thumbnails are funny

  • Nobody watched the video lol, dark themes are an easy fix but not the best solution. But very interesting, thanks for sharing

  • Even having dark grey saves power on OLED, pure black is not needed.

  • I would be interested in automatic updates on NixOS!

  • Why is there apt-get and apt? Also on regular updates there are sometimes package conflicts that need manual configuration. Maybe -y deals with some.

  • Yep, and thats all cloud-first I suppose. It sounds cool but you need to create an ignition file (which sounds very possible) but then you need to get that to a server that doesnt yet have a user account.

    I dont understand anything of that. I dont think mounting a drive with that file is possible everywhere, and how do you setup LUKS?

    Just no. I see if IOT is actually atomic but normal.

    Like, just use a cli installer that can load a file to automate it. Or have a backup user password. There is an issue that addressed this, its old and closed, yeah.

  • And they link everything in that directory to access it. So those are not real files

  • I want a server haha.

    And yes, atomic ftw.

  • I am completely confused about ublue currently, (okay all they did is remove the image list, its the same on Github)

    Debian is old and crusty with all its tooling. Apt sucks, automatic updates are strange, there are no snapshots afaik, it uses ext4, its like Fedora was 10 years ago