Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tholdem
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
tholdem
2y ago
I am not talking about Google's Android. I am talking about GrapheneOS and in Google's blog post they mention that this is coming to AOSP.
32.
▲
by
tholdem
2y ago
Probably over 90% of what I use my personal laptop for is browsing the web, watching videos, listening to music, and writing notes. In a general purpose OS, I value security above all else. Privacy is a close second, and of course stability
33.
▲
by
tholdem
2y ago
Can you post the eink smartwatch you got? I miss my Pebble and haven't found any good alternatives. I just want to see the time and notifications easily.
34.
▲
by
tholdem
2y ago
All adversaries are just humans and humans do stupid mistakes. Opsec and maintaining it is really hard. Just one mistake is enough. It's astounding to read about the really stupid mistakes adversaries do to get caught. But there is of
35.
▲
by
tholdem
2y ago
You can check by creating a Word Canary and check what's inside. I renamed it from .docx to .zip and it seems there is an external image referenced in the footer. I'm not sure how modern Word handles external images, but I believe
36.
▲
by
tholdem
2y ago
One thing that steered me away from QubesOS was that the templates used for all VMs were not hardened at all, instead, the Qubes Fedora template for example were less secure than a normal Fedora install. The template uses passwordless sudo
37.
▲
by
tholdem
2y ago
I'll judge a tech project on it's technological merits and developers by their technical skills. GrapheneOS is by far the superior choice.
38.
▲
by
tholdem
3y ago
I don't see how privnote.com is the same as this. Privnote seems to use a database and the links themselves should be treated as secrets as anyone with the link can read the note.
39.
▲
by
tholdem
3y ago
I mentioned China because there Apple's e2e encryption does not apply.
40.
▲
by
tholdem
3y ago
Sorry my reply was poorly written. Like with anything, there will be vulnerabilities and techniques that allow for verified boot bypass, which most are not trivial and which need to be fixed, but that does not mean verified boot isn't
41.
▲
by
tholdem
3y ago
Modern smartphone security relies on verified boot which cryptographically verifies various components in the boot process all the way to the kernel and beyond to make sure they have not been tampered with. This not only protects against ph
42.
▲
by
tholdem
3y ago
This is awesome. Hardened_malloc and JITless Chromium OOTB. It's hard to find hardened desktop linux distro, this might be it.
43.
▲
by
tholdem
3y ago
Imagine being in China and finding this out after an update. I used an iPhone a few years ago and when setting it up, I made sure to turn off all iCloud stuff. When it was time to get a new phone, I noticed all my pictures were in iCloud. I
44.
▲
by
tholdem
3y ago
Not sure what you mean with "lighter", but the reason some browsers feel heavier is the security features that introduce a performance penalty or take up more resources, like jitless mode and process isolation for example. Firefox
45.
▲
by
tholdem
3y ago
I'd be interested to hear more about the security/privacy overstatements.
46.
▲
by
tholdem
3y ago
Lineageos is also less stable than GrapheneOS and of course far less secure than GOS. It’s also less secure than stock Pixel OS or any other Android OS that supports verified boot.
47.
▲
by
tholdem
3y ago
Is sad how much misinformation there is about GrapheneOS. If you can, just try it. Their sandboxed play services implementation is far superior to any other solution. Compared to any other mobile OS, there is no compromise software wise on
48.
▲
by
tholdem
3y ago
Agree. Not long ago, Apple used to sue people reporting vulnerabilities to them. Imagine punishing people doing free work for you. Not a good look.
49.
▲
by
tholdem
3y ago
I believe madars meant app/process sandboxing which is different to what I think you mean with Firefox containers. Chrome is safer and has stronger sandboxing and exploit mitigations.
50.
▲
by
tholdem
3y ago
I strongly believe that GrapheneOS is one of the most important projects at the moment for several reasons. Nowadays it's almost impossible to live without a smartphone, it's one of the most used pieces of hardware that people use
51.
▲
by
tholdem
3y ago
Apple has been kind of forced into the open source model by tools like Corellium[1] and some source code leaks. This means that the black box advantage that iOS has had is no longer as significant. Apple's move with the Security Resear
52.
▲
by
tholdem
3y ago
I have been wondering what's the actual status of iOS updates outside of the US, or in countries where nobody uses wifi? I just checked that my SO's iOS was on 16.3.1, over 2 months old iOS version. Apple has decided that iOS shou
53.
▲
by
tholdem
4y ago
Correct me if I'm wrong, but the way FDE is implemented in Librem 5 means that it is only effective when the phone is turned off? The disk is decrypted when you type in your LUKS passphrase and after that, it stays decrypted until you
54.
▲
by
tholdem
4y ago
What about AOSP or GrapheneOS? Those also lack all tracking. Not to mention the security, and can you really have privacy without security?
55.
▲
by
tholdem
4y ago
How does the Librem 5 support verified boot? What about user data encryption? Those are the first, most basic security features I am expecting from a smartphone. How about app sandboxes and strict MAC policies?
56.
▲
by
tholdem
4y ago
If that is true, why Android 0-days are more expensive than iOS?
57.
▲
by
tholdem
4y ago
I would participate in the Proton Charity Fundraiser. You can buy tickets which would allow you to win Proton lifetime account and at the same time, you would support really cool FOSS projects, such as: GrapheneOS, Qubes OS, Tor Project. Pr
58.
▲
by
tholdem
4y ago
One reason why mainstream web browsers are slow and "bulky" and use a lot of RAM is that they use all sorts of different exploit mitigation and hardening techniques. One can only wonder what these alternatives do when they claim t
59.
▲
by
tholdem
4y ago
Yeah most definitely because of VM. I'm on Silverblue and on Security Level 1. Level 2 would require IOMMU.
60.
▲
by
tholdem
4y ago
Not a data breach, but scraped and aggregated data that is already availavle by design.
More ›