Your friendly neighbourhood sh.it.head

Gamer, book and photography nerd, francophile // Gamer, geek des livres et de la photographie, francophile

  • 13 Posts
  • 49 Comments
Joined 3 years ago
cake
Cake day: June 12th, 2023

help-circle
  • I think I started back in the day with Ubuntu Gnome, with some dabbling in Manjaro and then Arch.

    But since then I have used Fedora Workstation, and then Fedora Silverblue / Fedora Kinoite (immutable versions of fedora, with the past several years on Kinoite [kde] over Silverblue [gnome])

    On the server side of things, I am using Debian (with everything running in podman containers).

    If I were to consider migrating, it would be to migrate my laptop to secureblue (likely, rebasing the OS image rather than clean-installing) and migrate my Windows 11 desktop to bazzite. Both of these are still based on Fedora’s immutable base, albeit with changes to the base OS image. At some point in the future, I would also consider migrating my server to an immutable OS, however, which one remains to be seen.


  • As of now I am currently using FreshRSS, although before I properly deploy this to other users in my family / friends I might give Tiny Tiny RSS (tt-rss) a shot as well. I don’t think the differences will matter for end-users as the majority of mine will likely all be using it through the API via a mobile app (e.g NetNewsWire (ios & mac), FluentReader (desktop), CapyReader (android) etc. etc.)., however the main difference that will dictate which one I stick with is the filtering capabilities and the ease of setup of article-collection with readibility / mercury to remove extrenuous content / ads.

    I am also quite interested in miniflux, although it is quite intentionally bare bones. It lacks a plugin api (a potential security improvement), and instead natively supports many of the things people would use plugins for (native youtube-nocookie embedding / invidious embedding, integrations with readlater services like instapaper and wallabag, etc., integrated article fetching and parsing with readibility [and can change user agent / cookies to bypass bot protections]). It also seems to have a bit better security stance (supporting modern web browser features like passkeys, content sanitization, sanitizing url parameters in share links automatically etc.).

    Miniflux definitely feels like the best ratio of ootb functionality + security, but the UI of FreshRSS feels more natural if you envisage less techy users to use it (and in my case I see one person using the website over an app).


  • That is what it seems like based on what I have read :/

    I guess the best option in my case then is likely to add them as a non-admin user to my tailnet. The only concern I have is with the potential of one user deactivating the VPN connection unkowingly, which is probably where Funnel comes in as a better option, but I would prefer to avoid serving stuff on the web when possible. (It is specifically a FreshRSS instance for now)


  • Yes, there is two ways you can go about this. The way that you are thinking of (and the way that I would ideally like to go about this) is as listed on this help article. This is perfect for sharing a home server to some friends, and letting them access a given service without seeing any of your personal devices.

    The other option is to have just one tailnet, but having multiple users as detailed here. Notably this can be a security regression (if you don’t limit access on a per-user basis with ACLs), but is ideal for sharing access to your entire network with your spouse / older children within the context of self-hosting.


    For example, I have a friend who has shared a minecraft server with me and that is an ideal example of sharing one node to a seperate tailnet. I am an admin of the server, and can manage the docker container for it + the backup sidecar and the SMB share, but that is where my access to his network structure ends.

    This contrasts the situation with my partner for example, where we share a tailnet (with seperate user logins) to make things like gamestreaming just that much easier to setup. Hypothetically I can use ACLs to limit access to stuff like the Cockpit web-management portal, or block the SSH port, but I don’t feel like I need to in my specific case.


    Addendum: I also think sharing the device out strips it of its subnet routes + services, which is part of the problem I am running into where I do want it to strip subnet routing (my elderly parents DO NOT need access to my printer), but I ideally want to be able to still use tailscale serve + services + https certificates to be able to share my self-hosted RSS feed reader for them (ad-free, no AI slop, much better for my one parental figure with early-onset dementia).


    Addendum 2: I highly recommend exploring tagging + ACLs if you are looking into personal usage / seperation of networks. It is just a much easier approach of seperating devices that are owned and operated by the same person. I would only explore multi-tailnet option when it is different users and you want to share a very limited scope of your network.



  • I still think a syncthing client of some form is ideal. As someone else mentioned there is the option of using the Syncthing Tray devs experimental android build. To avoid issues with sync-conflicts / maintain high-availability access to the most recent file, I sync the databse to a raspberry pi with the encryption option selected (not that the pi is untrusted per se, but it is a device that doesn’t need access to the file, it just serves the most recent changes to other devices since often my laptop / phone / desktop are not all on at the same time).


  • I’m going to suggest an alternative to Samsung Internet or Firefox : https://github.com/uazo/cromite

    Out of the options I’ve tried, it’s probably the best bet for reducing tracking, fingerprinting & increasing security without turning to Tor browser (which while it is more anonymous, is frustrating for general browsing)

    For clearing cache, there are two options. There’s a dedicated clear browsing data button in the hamburger menu, it can also be configured to “sanitize on close” (similar to Firefox on desktop, or Brave on desktop / mobile) [In cromite, this can be found under Security > Clear the data at open]

    I can’t recommend Firefox on Android in good faith, until site isolation (fission) is enabled on the platform. This is a major security regression compared to desktop Firefox, or chromium based browsers on Android

    Edit: It seems like Iron Fox (continuation of Mull / fork of Firefox) has site isolation enabled - but it is still buggy and does not have all features enabled e.g no isolated process SELinux labels.



  • One of the advantages of Relay is that it is agnostic of your email provider, making it easier to switch providers without having to change the email on every account that has an alias.

    Considering this, I’d be tempted to go with Addy.io instead of ProtonMail / SimpleLogin (subsidiary of Proton AG).

    If you’re concerned with having to trust a third-party to process your emails however, Proton may be the better option with built-in aliasing. Mailbox.org is another option recommended by privacy guides with built-in aliasing.

    If you’re concerned with Mozilla’s TOS change however, you may also be concerned with the Proton CEO implicitly supporting the current Trump presidency, believing that the Republicans will do a better job reigning big tech in (While I’ll agree that the democrats are not anti-corp, that died with Bernie, I think it’s foolish to believe the republicans will be better). They also pulled their entire media presence on Mastodon, and recently integrated Zoom despite explicitly stating that it has privacy issues in their blog.

    I think some people are being a bit extreme in their characterization of Proton AG right now, but it definitely feels like they’re making some peculiar choices when looking at their guiding mission of privacy / security.


  • Passwords I would recommend Bitwarden or KeePass (both of which are in the PrivacyGuides wiki, particularly usefull for KeePass where there are different clients depending on OS)

    Email / contacts / calendar I am still struggling on to be quite honest. I am debating right now on Mailbox.org + EteSync OR just using Posteo.de (while it has some security regressions compared to Mailbox.org, it has encrypted contacts and calendar). To be quite honest though the options available in this space are quite frustrating, it is really hard to find a solution that allows for interoperability / data portability as well as E2EE / elevated security.


  • I would say the only potential “benefit” is if the account contains non-public facing personal information - you are reducing the chance it gets leaked via data breach (assuming, of course, they actually erase your data properly)

    But I would say it is at least worth it to reduce that potential risk, but you should also go into it assuming that anything that was publicly accessible has been archived / saved by someone.










  • I think it’s important to see these types of efforts, while I’ll never go out and buy a MacBook the effort isn’t wasted since it gives current users more freedom and future people buying used laptops more options for Linux compatible hardware.

    Without a project like this, that hardware will end up being e-waste a lot sooner than it should be, when Apple drops support. At least to me I see an ethical and moral imperative for projects like this, but I also understand people’s grievances with Apple.


  • Whooping_Seal@sh.itjust.workstoAndroid@lemdro.idMake android kinda dumb
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    1
    ·
    2 years ago

    You have a few options on what you can do to limit your child’s usage of a device.

    NextDNS has some interesting features for parental controls, as well as some options to try and prevent bypassing it (i have yet to try it though). On iOS it can be installed as a device profile and you can prevent them from being uninstalled, I’m not sure how to go about this on android but I’m sure there’s a way of limiting the child’s access to changing the settings.

    Otherwise the built in parental control features on Android and iOS seem to be very useful as well, since you can limit what your child can install, set screen time limits, etc. I am pretty sure you’d want a more recent version of Android however to get all of the features here which may not be possible depending on the budget.

    If you just want the ability to call / text then perhaps a dumb phone is a good first step? But a smart phone may be more useful if they’re older.