FutileRecipe

joined 1 year ago
[–] [email protected] 3 points 2 weeks ago

And hopefully does something about. Disciplinary for the poor OPSEC and/or better resources to avoid it and/or better laws to stop this unfettered data collection and/or better training to avoid it in the future. Here's hoping. Holds breath

[–] [email protected] 13 points 1 month ago

or randos on the internet then?

I mean isn't that practically everyone on the Internet that you don't know personally? Or do you actually know the Firefox and/or Librewolf team, and audit their code as well?

If no to both...sounds like you are putting some measure of trust into "randos on the Internet." Which is not abnormal. Trust is required at some point in most processes.

[–] [email protected] 2 points 1 month ago (3 children)

My thing against Firefox/Librewolf is lack of security...unless it's improved?

Avoid Gecko-based browsers like Firefox as they're currently much more vulnerable to exploitation and inherently add a huge amount of attack surface. Gecko doesn't have a WebView implementation (GeckoView is not a WebView implementation), so it has to be used alongside the Chromium-based WebView rather than instead of Chromium, which means having the remote attack surface of two separate browser engines instead of only one. Firefox / Gecko also bypass or cripple a fair bit of the upstream and GrapheneOS hardening work for apps. Worst of all, Firefox does not have internal sandboxing on Android. This is despite the fact that Chromium semantic sandbox layer on Android is implemented via the OS isolatedProcess feature, which is a very easy to use boolean property for app service processes to provide strong isolation with only the ability to communicate with the app running them via the standard service API. Even in the desktop version, Firefox's sandbox is still substantially weaker (especially on Linux) and lacks full support for isolating sites from each other rather than only containing content as a whole. The sandbox has been gradually improving on the desktop but it isn't happening for their Android browser yet.

Ref: https://grapheneos.org/usage#web-browsing

[–] [email protected] 2 points 1 month ago

old system of writing them down on paper

That's harder to steal/hack by someone across the globe.

[–] [email protected] 2 points 2 months ago* (last edited 2 months ago) (1 children)

Your data has monetary value to google. Giving them access, without getting any money from them (or even knowing what ways it will be used) is not something you must do.

To be fair, while you may not be getting money in its direct form (cash, bank deposit, etc) from Google, they are providing you a service which costs them money for free. So they are providing something of monetary value.

Only the individual can determine if their data is worth that free (to the individual, not free to Google) service. I'm assuming that most people in a privacy community would be against that, though.

[–] [email protected] 37 points 2 months ago (1 children)

CalyxOS relocks the bootloader and they supported the FP5 right after launch.

CalyxOS is not a hardened OS, and GrapheneOS requires more than than just relocking the bootloader.

Fairphone's devices do not meet basic security requirements for hardware, firmware and the software device support including drivers. Please look at the hardware requirements at https://grapheneos.org/faq#future-devices and check for yourself how many of those are provided by the Fairphone. Even the Fairphone 5 has a CPU core from 2021 without even PAC and BTI.

Ref: https://discuss.grapheneos.org/d/7208-8y-security-updates-on-fairphone-5-will-the-devs-consider-porting-grapheneos

[–] [email protected] 22 points 2 months ago (2 children)

You can still be part of a project without being lead, to be part of the "we." Did he contribute and/or is he part of GrapheneOS, yes? So he's part of the "we."

Or does only the lead developer get the "we?" Wouldn't that make it more of an "I" instead?

 

TL;DR

  • The Android 15 source code will be released next week, according to multiple sources.
  • The source code will allow Android platform developers to build modified versions of Android 15.
  • Major OEMs have already had access to Android 15’s source code, giving them a head start on preparing updates.
[–] [email protected] 5 points 2 months ago (2 children)

We've heard this one in 2016.

He was a convicted felon who had the Supreme Court in his pocket who granted him immunity as well as an attempted insurrection in his honor and he saluted hostile generals?

I don't remember if he promised to be a dictator on day one or had already praised dictators back then, so I'll grant you that one out of...everything else he's done since then which was not covered in 2016.

[–] [email protected] 8 points 2 months ago (4 children)

It's a game of chicken now.

And if you're not scared of a convicted felon who promises to be a dictator on day one and has the Supreme Court in his pocket who granted him immunity as well as a cult like following who stormed the Capitol to attempt an insurrection yet who also praises dictators and salutes their generals and has nothing to lose getting ahold of the Presidency then I don't know what to tell ya. But sure, let's play chicken with the saner and lesser of the two evils and help MAGA win.

[–] [email protected] 2 points 2 months ago (1 children)

Why do people phish, dumpster dive, or social engineer? So they can snoop and grab anything of value.

 

TL;DR

  • Efforts like Graphene OS face increasing pressure from apps that refuse to run on non-standard Android.
  • The custom ROM project characterizes Google’s approach to device attestation as incomplete and flawed.
  • Graphene OS is prepared to take legal action if Google won’t let it pass Play Integrity checks.
 

Apple has announced that its Messages app will support the RCS messaging standard in iOS 18. RCS offers more advanced features compared to traditional SMS, including higher-quality media, typing indicators, and end-to-end encryption. This move will improve messaging between iOS and Android devices, which currently rely on the less capable SMS protocol. Apple's decision to add RCS support likely comes in response to pressure from Google, Samsung, and European regulators who have pushed for better cross-platform messaging. Overall, this change will bring the iPhone's messaging capabilities more in line with the Android experience.

Kagi's Universal Summarizer: Summarize anything in a jiffy!

61
submitted 7 months ago* (last edited 7 months ago) by [email protected] to c/[email protected]
 

This announcement is from the Lawnchair Discord:

Lawnchair 14 has arrived!

After about 2 years, we're delighted to announce that Lawnchair 14 has finally arrived!

Based on Launcher3 from Android 14, this release works with QuickSwitch from Android 10 to Android 14! You won't need to use an older version to integrate with the system.

Some major highlights:
• Search your phone, the web, and more with our new Global Search — no root needed!¹
• View flight info, see surrounding traffic, and keep an eye on your data usage with Smartspacer — all integrated within Lawnchair.²
• Want to further control your icons? Fret not, We now support custom icon packs for themed icons, alongside some new icon options.³
• Themers rejoice — you can now hide the Dock for a cleaner home screen. You can also change even more colors, fonts, and padding.
• Are you tired of Lawnchair crashing because of widgets? We've fixed that issue; you won’t need to do some hacky workaround to add them.⁴

Alongside that, we have a new partnership with Startpage — searching with Startpage (via the dock search bar or App Drawer search) helps support Lawnchair’s development.

We still have more things to share! See the announcement on our website for more information.

¹ Experimental feature, requires opt in Lawnchair Settings.
² Requires Smartspacer and respective plugins.
³ Requires a supported icon pack .
⁴ May still persist depending on the device.

 

cross-posted from: https://poptalk.scrubbles.tech/post/567593

Haier hits Home Assistant plugin dev with takedown notice

I'm not really big on "let's make a movement", but this independent dev has been hit with a cease-and-desist from making a FOSS Home Assistant addon for their Haier air conditioners.

Haier claims that they are losing out on millions of dollars due to this plugin which... lets you control their air conditions from home assistant. They haven't bothered to explain how that's possibly worth millions of dollars - they're just claiming it.

So of course they hit the Streisand button and are demanding that he takes it down. He of course is complying... in a couple of days. Maybe you see where this is going.

It would be an absolute shame if any of you just happened to create a fork, or clone the code, or mirror it in your own instance. An absolute shame.

Just so everyone here knows which repositories NOT to clone or fork, here are the two links:

and please, don't repost this anywhere, or share it in other communities, or anything like that. It's a shame that so many people already know and are making clones. I'm just letting you know so you don't do anything like telling others who may make their own copies.

(sidenote: Haier owns GE Appliance, so for our American folks it may affect you folks too)

view more: next ›