kixik

joined 3 years ago
 

cross-posted from: https://slrpnk.net/post/17370625

I've been a user of Librewolf for a about a year now, and it's always served me pretty well as a nice easy way to get a hardened Arkenfox Firefox.

However, recently I was curious why Librewolf wasn't recommended on PrivacyGuides, and took a look through their reasoning on their forum. That thread spans multiple years, and for the most part I thought their reasons for not including it were a bit unfair, especially after Librewolf started offering automatic updates.

But towards the end of that thread in October, a Privacy guide team member posted a link to the Arkenfox github issue tracker, where a Librewolf team member reveals how the project appeared to have lost steam after a critical member left, and they are struggling to keep it up to date with the latest Arkenfox updates, despite putting out new releases.

I'm not sure if those problems have been resolved since that time. One of the maintainers did mention they're still short staffed in this topic on taking over maintaining Mull.

After considering the arguments for and against in the PrivacyGuides thread, I think their conclusion for not recommending it was ultimately correct. Using Librewolf adds an additional layer of trust, not only to not be malicious (which I don't suspect they are) but to also be able to adequately fulfill what they set out to do reliably.

Another big part of them not recommending it was the existence of the Mullvad Browser, which I didn't realize was in fact a very well hardened version of Firefox (essentially the Tor browser without the Tor part), and is far more effective for private browsing compared to Librewolf or an Arkenfox'd firefox.

Ultimately you'll have to come to your own conclusion, but personally I'll be switching back to Firefox as my convenient daily browser full of addons, alongside the mullvad browser for (more) private browsing.

 

cross-posted from: https://lemmy.ml/post/22214348

Some weeks back apkupdater stopped being able to download/upgrade/install from apkpure, but now a days I see issues with apkmirror as well (I see way less apps when searching for them). There was an initial issue about not being able to install from apkpure, but it seems more than that.

Agreed there's aurora store, but to be honest, I pretty much prefer avoiding the Google Play store at all, and I haven't found an issue with apkpure.

There was apkgrabber, but it was not working since so long, and finally it got archived on github.

Is there some FLOSS app similar to apkupdater, other than aurora store?

Anyone experiencing issues with it? Issues are not meant to be status reports once filed, but it seems not many have even noticed about the referred issue.

 

Darn, and I just got Librewolf upgraded to 131.0, meaning needing to wait further for 131.0.2.

 

Is this total cookie protection something embedded, not requiring any user intervention? I know with librewolf we get the strict enhanced cookie protection mode, but I don't know if for this total protection there's something required, if not turned on by default...

Greetings !

[–] [email protected] 3 points 6 months ago* (last edited 6 months ago) (1 children)

Just a minor suggestion. When looking for something different than what you're currently familiar with, do so in very open minded way, hopefully no looking for clones to what you were used to, but willing to experience and learn new stuff (there's no failure, just something new that had to be learned and experienced).

I know it's easier saying than doing...

Looking for advice on giant communities is sort of hard, and in the end you won't know what works better for you if you don't try it. The open mind needs to come with some time to be able to play, and enjoy during the play, so it's not a whole series of frustrations.

On this same forum (different threads/posts/converstions) I've read very different recommendations. Even though Manjaro has been recently getting a lot of bad reputation because of letting some certs expire, it's still considered an "introductory" gnu + linux distribution. I've also read Mint is a pretty good "introductory" gnu + linux distribution as well, specially now that ubuntu has finally shown its inclination towards its snap store, rather than the good and solid dpkg + apt, which allowed it to grow on users to where it's currently at.

I myself prefer rolling release models for distributions, and being as vanilla as possible, to be closer to upstream as possible. However I dislike systemd, which is just a personal taste, so I don't have a specific recommendation. It used to be Manjaro offered openrc, but they dropped it, and the distributions I know are Artix (it has gui installers if that's considered "introduction" level distribution, but one still need to handle the configuration mismatches with upgrades as with Arch), Gentoo (I wouldn't say it's not for starters, but for sure it has its learning curve, but more importantly you need to be aware that it's a source based distribution), and Void. If you don't really care, rolling release distributions, which might have an easy ramp up might be Manjaro as mentioned, and now I believe openSUSE Tumbleweed. maybe even fedora come close... Rolling release models might come even easier for newcomers, in my opinion, since there's no need to think on what happens on major updates, but rather one needs to keep updating periodically, but hopefully the distribution helps supporting the safest and saner configurations natively so the user, and particularly newcomer to the distribution don't have to deal a lot to get such safe and sane configurations, at least to start with. And that's to me the important part to call it "introductory" distribution, easy installation might be part of it, but it's hardly the majority of it, and this is perhaps the sad part of what I like about being as vanilla as possible, some distributions even take that as a mantra for configurations, and upstream developers don't always have the safer, or the saner configurations by default. I believe Manjaro and some others take that into account to make things smoother to start with. Maintaining the distribution, keeping it up to date, being able to install stuff, has it's learning curve, no matter the tools/frameworks to do so, and it might be harder if one has to deal with how to make things work because the software doesn't work as it should (configuration required upfront), and it's not hardened enough as well so the user needs to know that and do additional configuration upfront as well.

 

Hello !

I'm wondering if there's some blogging mechanism which would allow some sort of unique digital signature (PGP perhaps) to prevent personification, but which allows non traceable and fully anonymous author. Not looking for blockchain like stuff (apart from the layer Monero adds, blockchains are totally transparent, traceable and non anonymous). Not looking for bigotry, attacking people or anything like that.

The idea is to be able to share ideas, even corporate related, without being afraid of retaliations whether at work, corporations or governments. Expressing something at pubic might bring unexpected consequences, particularly if not aligned by the corporation one works on if that's the case, or might provoke AI, bots, or paid/unpaid people looking around, to include anyone in a particular list, without even warning the writer about it.

So I was looking if such thing is possible, and if it exists. Social networks of course wouldn't be an option, they're not anonymous, and at contrary can be used to cross-reference and trace people.

If such solution doesn't exist, I'm wondering if something based on gnuNet might get close, although gnuNet is not meant to make users anonymous. Or perhaps something based on i2p.

Of course the digital signature should be used exclusively for the blog posting, and can't be associated to any real email, host, or whatever...

Feedback on the blog posts should also be allowed to anonymous people with their own unique digital signatures. But this is harder, since depending on the technology, not sure if moderation would be allowed, or even if it would make sense, in which case, no blog feedback should be allowed, though no feedback is really a down side for blog posts. Maybe allowing just the original post to remove feedback. Some other down side, but that's unavoidable, is the lack of non on thread feedback, meaning giving feedback through email or any other medium, since if that was available would make the writer non anonymous...

If such thing is not available, and eventually based on something like gnuNet or i2p, most probably clients would be needed to write blogs but another one that would offer some sort of RSS/atom functionality for the blog to be accessible from current RSS/atom readers.

[–] [email protected] 3 points 10 months ago

What is implied with alacritty not being customizable, what is then .config/alacritty/alacritty.toml meant for? That said, I'd argue kitty has hard coded what fonts can be used with it, though some might think this is good, but in my mind it's a limitation.

At any rate, this is a matter of taste. I use alacritty with screen. Some might argue kitty is better because of tabs supports, and if that's a thing for them, then that's fine...

At any rate, again, terminal emulators are a matter of taste...

 

Just wondering, as the reasons to move here are gone, can the community go back to lemmy.ml? There are quite some posts over lemmy.ml, so going back there would be useful I believe, and also moving the few posts here over there would be just great (perhaps not the comments)...

Just an honest question, not to provoke flame wars or anything like it...

Greetings !

 

Anyone aware of a conversations fork with support for unified push notifications? Or a similar xmpp android app with omemo (just the same as conversations' support) and unified push notifications support, available through the official f-droid repor or a f-droid repo if not available from the official ones?

BTW, I noticed [email protected] community was locked. Any particular reason for that?

Also, Converstions requests to set unrestricted use of battery, to use battery under background without restrictions. So it seems unified push notifications would help, though this github issue sort of indicates unified push notifications wouldn't help, so it just tells me there's no intention to include support for it on Conversations, but not that it wouldn't help save battery.

1
submitted 1 year ago* (last edited 1 year ago) by [email protected] to c/[email protected]
 

https://disroot.org provides several decentralized federated services, as email and xmpp, besides other cloud services as well... But not sure if asking here is right or not, but don't know anywhere to ask either...

Is it having a license issue, does anyone know about it? Any status updates?

Websites prove their identity via certificates. LibreWolf does not trust this site because it uses a certificate that is not valid for disroot.org. The certificate is only valid for p1lg502277.dc01.its.hpecorp.net.
 
Error code: SSL_ERROR_BAD_CERT_DOMAIN

But also:

disroot.org has a security policy called HTTP Strict Transport Security (HSTS), which means that LibreWolf can only connect to it securely. You can’t add an exception to visit this site.

The issue is most likely with the website, and there is nothing you can do to resolve it. You can notify the website’s administrator about the problem.

I also tested with ungoogled chromium and pretty similar thing...

Anyonea aware, and also about disroot saying on this?

Edit (sort of understood already, no issue with disroot at all): The issue only shows up under the office VPN. It seems like disroot is not recognizing the office's cert...

Edit: Solved. Yes it's the office replacing the original cert with its own, as someone suggested. Thanks to all.

[–] [email protected] 5 points 1 year ago

I recommend you to explore sourcehut as well, if you're not afraid of something different to gitlab/github workflows.

view more: next ›