Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
SubzeroCarnage
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
SubzeroCarnage
5y ago
F-Droid maintainers are solely a volunteer effort. The CI helps a lot. The biggest slowdown in the chain is the manual offline signing step. You can see here the history https://gitlab.com/fdroid/fdroiddata/-/
2.
▲
by
SubzeroCarnage
5y ago
The Core 2 line of processors has not received any microcode updates since 2015. "Products not planned": https://www.intel.com/content/dam/www/public/us/en/documents...
3.
▲
by
SubzeroCarnage
5y ago
I am not sure how systemless root interacts with verified boot. I've never tried it myself.
4.
▲
by
SubzeroCarnage
5y ago
Verified boot is only enforcing on -user builds. Lineage ships -userdebug builds. Furthermore Lineage's official root addon writes to /system. You can't have any additional changes to system or else verified boot won't b
5.
▲
by
SubzeroCarnage
5y ago
That is a limitation of Lineage only because they choose to cater to users who want root (which usually modifies /system) and to support flashing Google Apps.
6.
▲
by
SubzeroCarnage
5y ago
Silence is sadly no longer maintained, but it still seems to work for now. I will eventually replace it. Re Mozilla: I do state on my browser comparison page that Chromium browsers are more secure. Also the Bromite repository is included in
7.
▲
by
SubzeroCarnage
5y ago
Most things simply aren't in their scope. I do send occasional patches to Lineage if they are in-scope and am in contact with some of them reasonably frequently. The big blocker is that their Gerrit instance requires a Google account t
8.
▲
by
SubzeroCarnage
5y ago
Long press the app in your launcher, App Info, Mobile data & Wi-Fi, Allow network access
9.
▲
by
SubzeroCarnage
5y ago
I have a few apps on F-Droid and I also maintain a list of recommended apps from F-Droid here: https://divestos.org/index.php?page=recommended_apps
10.
▲
by
SubzeroCarnage
5y ago
Unlike GrapheneOS (which I recommend you use if you can) and CalyxOS, my project https://divestos.org is tested working on 30+ devices.
11.
▲
by
SubzeroCarnage
5y ago
My https://divestos.org project, while not as secure as GrapheneOS, provides lots of security to many older devices.
12.
▲
by
SubzeroCarnage
5y ago
Slight OT: the malware indicators of compromise that Amnesty International released have no license, thereby prohibiting use in other projects as far as I understand. https://github.com/AmnestyTech/investigations/i
13.
▲
by
SubzeroCarnage
5y ago
A whitelist/allowlist approach doesn't work for all programs, see this discussion about it: https://github.com/netblue30/firejail/issues/2070
14.
▲
by
SubzeroCarnage
5y ago
Sandboxing is a huge issue that plagues desktop operating systems. And sadly is it only one piece of the puzzle. Android for example additionally has detailed SELinux policies and extensive compile time hardening. You can sandbox the majori
15.
▲
by
SubzeroCarnage
5y ago
Late reply, but when I was setting up WPA3 a few months ago I used Android 11 as a reference and that is what it spits out from the Settings share screen. Without it iirc, it would search and search and never connect.
16.
▲
by
SubzeroCarnage
5y ago
Offline updates via dnf and packagekit are handled via systemd afaik. gnome-software never directly calls dnf, it is solely a frontend for packagekit (and flatpak and fwupd).
17.
▲
by
SubzeroCarnage
5y ago
Of extra note, X uses more memory then Wayland (as long as you have no X apps open), and classic is enabled through the use of shell plugins which also uses more memory compared to regular.
18.
▲
by
SubzeroCarnage
5y ago
Fedora 34 Workstation (GNOME) with only gnome-software and packagekit removed idles at 650MB. This is because the Fedora repositories are very large due to all their extra metadata and the inefficiencies of the yum packagekit backend. GNOME
19.
▲
by
SubzeroCarnage
5y ago
For WPA3 WIFI:S:SSID;T:WPA3;P:PASSWORD;;
20.
▲
by
SubzeroCarnage
5y ago
> user-mode builds of LineageOS My ROM leads on that front https://divestos.org Other ROMs that support locking are https://grapheneos.org and https://calyxos.org but have limited device compatibility
21.
▲
by
SubzeroCarnage
5y ago
> Assuming our guest can get full unrestricted access to any MSR (which is only a question of timing thanks to init_on_alloc=1 being the default for most modern distributions) Can someone elaborate on how init_on_alloc would be helpful t
22.
▲
by
SubzeroCarnage
5y ago
Hi HN! I started on this project in mid 2017. It was loosely based on similar projects, but I made the results actually boot and cranked it up to 11. It is soley meant for use on device kernels that will never see mainline support, such as
23.
▲
Show HN: Automated Linux Kernel CVE Patching – Tested Booting on 30 Devices
(github.com)
3 points
by
SubzeroCarnage
5y ago
|
1 comments
24.
▲
by
SubzeroCarnage
5y ago
Midori has been overhauled and is Electron based now. old [0] new [1] See also this extensive list of browsers [2]. [0] https://github.com/midori-browser/core [1] https://gitlab.com/midori-web/mido
25.
▲
by
SubzeroCarnage
5y ago
While most Flatpaks by default aren't all tuned up, you can easily set overrides for them, see `man flatpak-override`. There also exist `Flatseal` which is a GUI for doing so. AppImage can be used with Firejail. Firejail use is trivial
26.
▲
by
SubzeroCarnage
6y ago
My project DivestOS supports bootloader locking, verified boot, and OTA updates for many more legacy devices. https://divestos.org
27.
▲
by
SubzeroCarnage
6y ago
So they can take you to small claims/civil court if you or your insurance doesn't pay up.
28.
▲
by
SubzeroCarnage
6y ago
I have a much more up-to-date and comprehensive GPL-3.0 package called 'brace' available here: https://github.com/divestedcg/brace Supports Fedora, Arch, Debian, and openSUSE. Has GNOME, Firefox, kernel cmdli
29.
▲
by
SubzeroCarnage
6y ago
Hello HN! This is a project I've worked on for a few years now. It lets you quickly provision a Linux distro with more usable defaults. The two main parts are the package installer to install recommended packages that cover what most a
30.
▲
Show HN: Brace – A system hardening package with usability first
(github.com)
2 points
by
SubzeroCarnage
6y ago
|
1 comments
More ›