Skip Navigation
InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)TA
Posts
11
Comments
51
Joined
3 yr. ago
  • Usually they're normal x86 PCs with nothing unusual about them so just your Linux/BSD distro of choice. You can look up the processor model to see what crypto acceleration it can do, or see if there's any wireguard benchmarks available.

    Some have interesting processors like PowerPC, or other strange hardware, but avoid them unless interesting is what you're after.

  • You have the pi, give it a go.

    If it's inadequate then i'd recommend a used fanless thin-client type PC, such as a Wyse 5070, just make sure it comes with PSU and a few GB of RAM and SSD. And check reports of how much power it uses at idle.

  • Ok, it's beginning to look like bad UI design on accounts.firefox.com:

    If I click sign in at monitor.mozilla.org, it redirects me to an oauth process hosted on accounts.firefox.com which prompts me for my password then sends me back to monitor.mozilla.org.
    The settings page at accounts.firefox.com then lists Mozilla Monitor under "Connected Services - Everything you are using and signed into" along with all my browser/device instances. But it doesn't disappear when signed out from monitor.mozilla.org in the same way that a browser instance disappears when signed out from sync browser-side.

    I'm supposing that list does not indicate what has access to sync data, which as far as I understood uses its own strong private keys browser-side which are never shared with the servers.

  • Yes, I was aware of that at the time, and I probably assumed that my browser would be hashing each piece of data (e.g. each email address or username) before sending it to Mozilla Monitor or haveibeenpwned.

    What concerns me is Mozilla Monitor appearing in the list of devices/browsers synced, each of which is implied to have cleartext access to all the data I decide to sync (bookmarks/history/tabs in my case, logins+passwords and more for many other people).

  • Privacy @lemmy.ml
    tavu @sopuli.xyz

    Mozilla/Firefox sync - why does "Mozilla Monitor" appear with signed in devices?

    I use the built-in sync service in various Firefox forks to sync bookmarks/history/tabs, using the default Mozilla servers.

    When I went to "Manage Account" to review and prune the devices ("services?") linked with Mozilla Sync down to what I'm actively using currently, and noticed "Mozilla Monitor" in there.

    I can't find any info on why Mozilla Monitor required sync credentials, and I don't remember Mozilla Monitor telling me it would be gaining access to my sync data, nor can I find any way to review what data "Mozilla Monitor" has access to.

    Any ideas?

    For now I'm signing out that entry, while I consider other sync options.

    Edit: changed title from 'Mozilla/Firefox sync - why is "Mozilla Monitor" a signed in device?'

  • Most mass-marketed VPN services (the type marketed for accessing the internet) allow you to VPN into their private subnet where the thing you can access is their gateway router (which you use in place of your home gateway router/modem for connecting to the internet). You don't need a VPN service to use VPN software between two points you control.

  • Permanently Deleted

  • If you're using Mozilla's level of endorsement as a metric, note this prominent disclaimer on the addon's page:

    ⚠️ This add-on is not actively monitored for security by Mozilla. Make sure you trust it before installing.

  • Yep. It works and it's awesome. I use conversations on android devices and dino and gajim on desktops, various family members use siskin on iOS.

    With zero app or server-software or provider lock-in, and an actual in-practice diversity of apps and providers, the whole thing seems pretty immune to enshittification.

  • [alt-text for the vision-impaired] Image appears to be a twitter post from Craig Murray posted on 2023-10-14: "To be entirely plain. I have always viscerally opposed war. I have dedicated my life to conflict resolution and reconciliation. But in the coming Gaza genocide, every act of armed resistance by Hamas and Hezbollah will have my support. If that is a crime, send me back to jail."

    Hmm. Could be seen as a rather outlandish thing to say in the immediate aftermath of 2023-10-07, but in hindsight with what we know now in terms of what atrocities the Israeli military forces have brought upon the people of Gaza since that attack on Israel, it seems a reasonable statement to support armed resistance against the coming episode of genocide which indeed materialised and continues today.

  • World News @lemmy.ml
    tavu @sopuli.xyz

    Worse Than You Can Imagine - Craig Murray

    www.craigmurray.org.uk Worse Than You Can Imagine - Craig Murray

    Governments cannot take big decisions extremely quickly except in the most extreme of circumstances. There are mechanisms in all states that consider policy decisions, weigh them up, involve the various departments of the state whose activities are affected by that decision, and arrive at a conclusi...

    Worse Than You Can Imagine - Craig Murray

    The coordinated decision of the Western nations to fast track famine by stopping UNRWA funding was announced within an hour, following the ICJ ruling that Gazans were at immediate risk of genocide, and drove from the media headlines the adverse ruling against Israel.

    Australia @aussie.zone
    tavu @sopuli.xyz

    Nick Powell speaks up about Bunnings

    Just like colesworth suppliers, plant nurseries and other suppliers suffer the same way as highlighted in recent news and inquiries into the supermarket sector.

  • Well within the budget of a private investigator or burglar or peeping-tom or abusive ex-partner.

    No need to scale; plenty of privacy/security incursions don't require mass-surveillance.

    That said, I'd suggest that the attack does scale economically . Think war-driving but with one of these setups -- cruising around in a van through a dense neighbourhood collecting short clips of cctv footage looking for something of interest.

  • [...] the attack is an extremely expensive nation state level operation that doesn’t scale.

    About $250 at most. Quoting the linked page:

    Below is a list of equipment we used for the experiments.

    • (1) Software Defined Ratio (SDR): Ettus USRP B210 USRP, ~$2100.
    • (2) Low Noise Amplifier (LNA): Foresight Intelligence FSTRFAMP06 LNA, ~$200.
    • (3) Directional Antenna: A common outdoor Log-periodic directional antenna (LPDA), ~$15.
    • (4) A laptop, of course.

    Note that the equipment can be replaced with cheaper counterparts. For example, USRP B210 can be replaced with RTL-SDR that costs ~$30.

    To reproduce the attack: our GitHub repository provides the codes and instructions for reproducing and understanding the attack. We have prepared a ready-to-use software tool that can produce real-time reconstructions of the eavesdropped videos with EM signal input from the USRP device.

  • Privacy @lemmy.ml
    tavu @sopuli.xyz

    EM Eye: Electromagnetic Side-channel Eavesdropping on Embedded Cameras

    EM Eye investigates a cybersecurity attack where the attackers eavesdrop on the confidential video data of cameras by parsing the unintentional electromagnetic leakage signals from camera circuits. This happens on the physical/analog layer of camera systems and thus allows attackers to steal victim's camera data even when perfect software protections (e.g., unbreakable passwords) are all in place. Exploiting the eavesdropped videos, attackers can spy on privacy-sensitive information such as people's activities in an enclosed room recorded by the victim's home security camera. [...]

    Paper.

    Fuck Cars @lemmy.ml
    tavu @sopuli.xyz

    A ubiquitous tire rubber–derived chemical induces acute mortality in coho salmon

    In U.S. Pacific Northwest coho salmon (Oncorhynchus kisutch), stormwater exposure annually causes unexplained acute mortality when adult salmon migrate to urban creeks to reproduce. By investigating this phenomenon, we identified a highly toxic quinone transformation product of N-(1,3-dimethylbutyl)-N′-phenyl-p-phenylenediamine (6PPD), a globally ubiquitous tire rubber antioxidant. Retrospective analysis of representative roadway runoff and stormwater-affected creeks of the U.S. West Coast indicated widespread occurrence of 6PPD-quinone (<0.3 to 19 micrograms per liter) at toxic concentrations (median lethal concentration of 0.8 ± 0.16 micrograms per liter). These results reveal unanticipated risks of 6PPD antioxidants to an aquatic species and imply toxicological relevance for dissipated tire rubber residues.

    Humans discharge tens of thousands of chemicals and related transformation products to water (1), most of which remain unidentified and lack rigorous toxicity information (2).

    Privacy @lemmy.ml
    tavu @sopuli.xyz
    kitklarenberg.substack.com Signal Facing Collapse After CIA Cuts Funding

    On November 16th, Meredith Whittaker, President of Signal, published a detailed breakdown of the popular encrypted messaging app’s running costs for the very first time. The unprecedented disclosure’s motivation was simple - the platform is rapidly running out of money, and in dire need of donations...

    Signal Facing Collapse After CIA Cuts Funding

    On November 16th, Meredith Whittaker, President of Signal, published a detailed breakdown of the popular encrypted messaging app’s running costs for the very first time. The unprecedented disclosure’s motivation was simple - the platform is rapidly running out of money, and in dire need of donations to stay afloat. Unmentioned by Whittaker, this budget shortfall results in large part due to the US intelligence community, which lavishly financed Signal’s creation and maintenance over several years, severing its support for the app.

    Never acknowledged in any serious way by the mainstream media, Signal’s origins as a US government asset are a matter of extensive public record, even if the scope and scale of the funding provided has until now been secret. The app, brainchild of shadowy tech guru ‘Moxie Marlinspike’ (real name Matthew Rosenfeld), was launched in 2013 by his now-defunct Open Whisper Systems (OWS). The company never published financial statements or disclosed the identiti

    Privacy @lemmy.ml
    tavu @sopuli.xyz

    Google docs infects html exports with google tracking redirects.

    fosstodon.org Joe :fedora: :debian: :ferris: (@[email protected])

    Today I found out that google docs infects html exports with spyware, no scripts, but links in your document are replaced with invisible google tracking redirects. I was using their software because a friend wanted me to work with him on a google doc, he is a pretty big fan of their software, but we...

    @[email protected] wrote:

    Today I found out that google docs infects html exports with spyware, no scripts, but links in your document are replaced with invisible google tracking redirects. I was using their software because a friend wanted me to work with him on a google doc, he is a pretty big fan of their software, but we were both somehow absolutely shocked that they would go that far.

    Australia @aussie.zone
    tavu @sopuli.xyz

    Government to overhaul privacy laws, including opting out of advertising, a right to be forgotten, and new rules for small businesses

    Privacy @lemmy.ml
    tavu @sopuli.xyz

    Government to overhaul privacy laws, including opting out of advertising, a right to be forgotten, and new rules for small businesses

    Australia @aussie.zone
    tavu @sopuli.xyz

    Energy $prices DOWN! Who's looking forward to the massive drop in the cost of their next electricity bill?

    Following the "unprecedented price rises" in the past year for retail electricity rates across Australia, it looks like we have some "unprecedented price drops" just around the corner!

    I'm not sure whether I need to end this post in a /s or not.

    Alt-text: Line graph of annual avg wholesale electricity prices in NSW/QLD/SA/TAS/VIC over F.Y. ending 2010-2024. 2022,2023 show an increase of 100~130% compared to 2021; 2024 shows a return to ~2021 prices (except SA).

    Data source: https://aemo.com.au/energy-systems/electricity/national-electricity-market-nem/data-nem/data-dashboard-nem

    Fuck Cars @lemmy.ml
    tavu @sopuli.xyz

    Pedestrians and cyclists implicated for their own mortality by Victoria Police in road safety education campaign. #australia

    Excerpt from article:

    “We all play a role in keeping our roads safe and Crime Stoppers Victoria is offering vulnerable pedestrians the tools they need to use our roads safely,” she [Crime Stoppers Victoria Chief Executive Stella Smith] said.

    “We have seen 175 pedestrians killed on our roads over the last five years, and a significant number of those have been in 60 km/h zones.

    “We hope with more education and awareness we can reduce the number of injuries and most importantly, deaths on our roads.”

    As part of the campaign, Crime Stoppers Victoria will hit the streets to actively engage with high-risk pedestrians to educate them on how they can help keep our roads incident-free.

    I guess that means police will be out in force handing out fines to pedestrians and cyclists. "Job done!"

    Archived: https://archive.md/UOcHu