ChallengeApathy

@ChallengeApathy@infosec.pub

This profile is from a federated server and may be incomplete. Browse more on the original instance.

ChallengeApathy,

I hadn’t, my apologies for missing that.

ChallengeApathy,

I suppose there’s not really a crucial reason but I just like to do so when I can. More peace of mind that way.

Linux on old School Machines?

Hi all, the private school I work at has a tonne of old windows 7/8 era desktops in a student library. The place really needs upgrades but they never seem to prioritise replacing these machines. Ive installed Linux on some older laptops of mine and was wondering if you all think it would be worth throwing a light Linux distro on...

ChallengeApathy,

Zorin OS has a lite version, you could test that and see if it works. Besides, it’s one of the best distros for people used to Windows so it wouldn’t require much work to help people to figure out how to use it.

How is everyone handling the 2FA requirement for GitHub? (docs.github.com)

Just wondering what people are using to meet the 2FA requirement GitHub has been rolling out. I don’t love the idea of having an authenticator app installed on my phone just to log into GitHub. And really don’t want to give them my phone number just to log in....

ChallengeApathy,

This hate for 2FA is bizarre to me. Sure, it’s not as convenient but in this day and age, with all the threats out there, there’s no real excuse for not using it.

ChallengeApathy,

I do agree but Steam’s app isn’t bad. It’s great if you use Steam’s social features and it makes secure login a total breeze.

ChallengeApathy,

Sure, I don’t disagree, it shouldn’t be a requirement but because the app is good and makes the process easy, I don’t have a problem with it.

ChallengeApathy,

Video player? Absolutely. However, it leaves a lot to be desired when it comes to music. I use Strawberry for music, personally, as I like the added metadata features it offers.

ChallengeApathy,

It’s almost as if communism is an atrocious idea, it’s not like they always turn into dystopian dictatorships or anything 🤔

ChallengeApathy,

I’ve experienced no such issue. I use hardened Firefox for some stuff including Twitter, never encountered this.

ChallengeApathy,

I switched to Strawberry from a lifetime of Winamp usage purely because I wanted an open source music player, so this is amazing news!

ChallengeApathy,

I like Audacious but it lacks the Winamp features of later builds. Went for Strawberry instead when I migrated to FOSS.

ChallengeApathy,

Sounds like someone is mad that security experts would rather trust a tried-and-true encryption standard over Telegram’s encryption which is known to not be anywhere near as secure as the Signal protocol.

Pavel resorting to outright slander to promote Telegram is not something I expected to see.

ChallengeApathy,

As unfortunate as it is, the only way privacy search engines will survive is by adding AI. Brave recognized this early on and implemented it very well, so I’m glad to see DDG seems to be implementing it well also. Hopefully Startpage catches up because even though I almost exclusively use Brave Search, I do enjoy Startpage as a secondary source.

ChallengeApathy,

As is Startpage now.

ChallengeApathy,

Brave Search. At this point, I almost never need a different one. They also have optional AI but they’re doing so in a way that preserves privacy.

ChallengeApathy,

I agree somewhat. I know how to use a search engine, I don’t need AI. The main problem is that, sadly, AI is going to be required to stay competitive.

I will say Brave’s AI is very useful, though.

ChallengeApathy,

And DDG is on record for censorship and caving to Microsoft. They also both provide results based off MS and Google results.

Neither are ideal. It’s why only use them as a fallback. Brave Search all the way.

ChallengeApathy,

I very, very strongly disagree.

ChallengeApathy,

Looks great! I’ve been rocking Strawberry for a little while now since I decided to finally retire Winamp, but this looks like it might be better in terms of the UI!

ChallengeApathy,

Because it’s a centralized system owned by a sociopath billionaire gathering unchanging, personal details about swaths of the population using ye olde “for the greater good” adage as the justification. You’d have to be a special kind of fool to go along with it.

ChallengeApathy,

Just don’t use biometrics. Bad idea in general. A 6+ digit PIN or password is just fine, especially if you set your phone to factory reset after a certain number of failed unlock attempts.

ChallengeApathy,

Right… that’s what I’m saying. Under the fifth, they can’t compel you to unlock your phone if it’s protected by a PIN or password and if you set it to factory reset after a bunch of failed attempts, they can try but it’s unlikely they’ll break the PIN/pass in a few attempts.

ChallengeApathy,

It’s protected under the fifth. Even so, requiring a warrant to get your passcode is far better than not requiring a warrant to demand biometrics. Either way you slice it, passcode > biometrics.

ChallengeApathy,

There have been instances where judges ruled in favor of them being protected which sets a legal precedent. The SCOTUS probably won’t get involved unless a major lawsuit or federal-level case occurs.

Either way, passcodes are superior. Not sure why you’re arguing this.

ChallengeApathy,

Were not in a court of law.

ChallengeApathy,

It’s actually rather stunning to see just how hard they’re attacking privacy in these final months of the disastrous dumpster fire that is the Biden administration. This is exactly why I believe centralized cloud and CDN infrastructure is massively dangerous.

Make the web decentralized again.

ChallengeApathy,

I didn’t mention the others. It’s simply that this current “administration” has been a disaster in literally every way so it’s not surprising they’re trying to end our constitutional rights.

ChallengeApathy,

Almost nothing. I sometimes use it to rephrase a question or answer. I refuse to become dependent on AI or contribute to it more than I already unwittingly have.

ChallengeApathy,

I don’t like big government but I have zero sympathy in this case. TikTok is the greatest cancer on modern society and I will not change my mind on that.

ChallengeApathy,

I agree but TikTok is worthless in general. The content it serves people is literal brain rot. Also, I don’t want it to sell, I just want it to die and never come back.

ChallengeApathy,

Not that long ago, they drastically improved their privacy policy, consent and opt-out capabilities. Is it perfect? No but it has never been better.

How do you handle your passwords?

I rely on Bitwarden (slooowly migrating from… a spreadsheet…) and am thinking of keeping a master backup to be SyncThing-synchronized across all my devices, but I’m not sure of how to secure the SyncThing-synchronized files’ local access if any one of my Windows or Android units got stolen and somehow cracked into or...

ChallengeApathy,

Proton Pass. If you’re comfortable with cloud E2EE managers, it’s far more worth it than Bitwarden, since you get unlimited email aliases. Better for privacy and even security. Plus, I trust Proton, they have a phenomenal track record in terms of security and encryption.

ChallengeApathy,

Every company would. They’re not going to go out of business over one customer. What’s important is that they weren’t able to give any important information.

Under the FISA expansion, what exactly should I worry about, how do I manage privacy?

Hello everyone, with the unfortunate passing of the FISA expansion, I was left with a few questions. I tried to research it, and to me, it seems like they are beefing up surveillance with routers and ISPs (correct me if I’m wrong.) Aside from having businesses stalk you when you use their WiFi (connected with ISPs.)...

ChallengeApathy,

Source on this? It’s very unlikely. It would be hard to crack down on VPNs given the fact that businesses need them, especially now with the prevalence of remote work.

ChallengeApathy, (edited )

I’d say just keep doing what you would have done before to protect your privacy. Switch to privacy tools, especially encrypted communications services, and use both trustworthy VPNs and Tor for different use cases. Also, I heard (can’t verify) that this effectively lets the government legally co-opt regular people to essentially function as spies under gag orders, so I’d just keep an eye out if you ever need to let some sort of professional into your home.

ChallengeApathy,

Honestly, Bluetooth sucks. I’m incredibly sick and tired of everything trying to use ancient technology for far more than it was ever intended. Besides, it never works the way it should anyways.

ChallengeApathy,

Clock You. The You suite has some great apps, I use almost all of them. Not only are they libre but they have attractive and very useful GUIs.

ChallengeApathy,

Best weather app I’ve used. FOSS but unlike most FOSS weather apps, it doesn’t FEEL like your typical FOSS alternative.

ChallengeApathy,

They have a search engine…

ChallengeApathy,

Yeah, and? It’s one of the best options for privacy. I’m referring to their search engine though.

ChallengeApathy,

Better privacy, better UI not cluttered by excessive and unnecessary options, and a fantastic feature set… but I’m referring to their search engine in this context.

ChallengeApathy,

I’m sorry that not everyone from my instance believes that Firefox is the only option 🙄

ChallengeApathy,

The AI is intrinsically linked to the search engine if I’m not mistaken. Brave has AI built into their search engine and their browser, but it’s very well done and pro-privacy.

ChallengeApathy,

Because it objectively IS. It passes privacy tests in so many areas where others fail and I’m not just talking about those privacy test sites, I’m talking tests we can run ourselves. It’s fine if you don’t like Brave but don’t let your emotions get in the way of the fact that it is, by default, the best option for privacy out of the box. Sure, you CAN harden Firefox or use Librewolf but even those don’t always succeed in passing those tests like Brave does.

ChallengeApathy,

It IS. It’s a fact. You can run the tests yourself.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • fightinggames
  • All magazines