• 0 Posts
  • 84 Comments
Joined 1 year ago
cake
Cake day: July 17th, 2025

help-circle
  • (/j)

    In all seriousness though, this sums it up quite well: It is a few years old, but most of the problems still apply https://madaidans-insecurities.github.io/firefox-chromium.html

    I said measurably because I do remember seeing benchmarks somewhere about the browser security, but as of now I can’t find them. That said, while Firefox is worse, from a security standpoint, than chrome, it’s generally more private (letterboxing, resist fingerprinting, etc.) but for me, the security tradeoff isn’t worth it.

    I know a lot of people probably won’t believe me when I say this, but I do like Firefox (a lot more than Chrome and its derivatives) but when you can’t sandbox browsers without significantly weakening the browser’s sandbox (a little unintuitive), I choose to put security and browser integrity above personal preference.

    If you or anyone else wants to use firefox, it’s not like you’re instantly going to compromise your machine. Firefox just lacks a lot of the security that chrome has, and thus has a greater potential for exploitation.




  • Because you can’t run multiple accounts at once? Either I’m misunderstanding what you’re saying, or you’re missing the point of a signal backup.

    OP is referring to the GrapheneOS feature, well really the android feature heavily enhanced by GrapheneOS, that allows you to run the OS as another user with their own apps and files. OP is asking for help running signal (Molly) in both profile A and profile B as one account. This is technically possible but realistically infeasible because of the way profile switching works on android. I explained why in a different comment.


  • Bad advice. Signal has its drawbacks, and yet you managed to avoid listing all but one of them. Impressive.

    Signal has released an update recently that allows multiple devices (up to 10 I believe). Yes you still need a phone number, but newer commits suggest that is soon to change. Signal has local backups on android, and I haven’t heard of any issues restoring from them. Signal is far from perfect, but they are very trusted, battle tested, and overall a better service than what most people are using anyways. By all means, if you have a better service that works for you, go for it, but advising against using signal outright with no alternative is kinda weird.


  • I’ll start this by saying I do like and use proton, but their insistence to provide a hundred different services (and force you to pay for every single one in your subscription) really hurts the service. For example:

    The 2FA had an issue that leaked every single service you used by connecting to their icon server over insecure http, for a month I believe and then downplaying the severity. This wouldn’t have happened if they focused on being an email provider and pointed users to existing services like Ente Auth, instead of pushing poorly tested software to production as fast as possible. You should never store 2FA with your password manager anyways, even if it’s stored in seperate apps, so I think their choice to make a 2FA app is quite silly.

    They continue to prioritize building new services such as meet and lumo over compatibility with Linux (drive sucks, and only 9 years later do they support a buggy CLI. The VPN client is buggy as hell, and if you’re not careful could leak your VPN when it crashes for the hundredth time (crashes are less common on Gnome, which is technically the only DE it’s built for, but that doesn’t change the fact that it lacks critical features that exist exclusively on MacOS and Windows) (the killswitch works as far as I can tell, but with how poorly made the client is, you should bind it in the OS itself as well)).

    They require the use of Google Play services, arguing that they don’t want to waste people’s battery by running websocket based notifications. It’s a stupid defense as people who don’t have Google play services wouldn’t mind the extra battery usage for notifications. Not to mention, they can use unified push since they already encrypt their notifications anyways (Proton says they don’t need to add unified push, the users just need to use Google Play because the notification are encrypted, completely disregarding the invasiveness of Google Play and the metadata leakage from using them for push notifs).

    The UI for simplelogin has not changed since acquisition from what I can tell, and continues to look like it’s from 2014. Rather than adding features to simplelogin, as you would when you purchase an entire company, they almost exclusively add features to their password manager and email client instead.

    They basically force their crappy photo storage down your throat on mobile, despite being offered to join an alliance with privacy services (including Ente, an amazing photo storage service) and rejecting the offer. That’s actually a whole issue on its own. For what reason, other than greed, would a privacy company choose not to join an alliance with very respected privacy services? Is it because Tuta joined? That would be dumb and petty.

    Overall, I like and use many proton services, and I think a lot of the political controversies people like to throw at proton are FUD and/or blown out of proportion. That said, if a company could do what proton does for email (tuta is nowhere close to proton imo) and exclusively does email (fun fact, tuta is exploring the cloud drive space, because I guess people never learn) I would switch in a heartbeat. If proton separated their plans so you only pay for what you need, and let me use notifications on my phone, that would be basically all my gripes in my day to day dealt with.


  • Lytia @lemmy.todaytomemes@lemmy.worldCome on
    link
    fedilink
    English
    arrow-up
    23
    arrow-down
    17
    ·
    28 days ago

    Maybe an unpopular opinion, but compared to everything else big tech has been doing recently, Google almost doesn’t feel like a bad guy. They’re still invasive as hell, but compared to any other mainstream AI, search, email, cloud storage, VPN, etc. provider, they almost feel closer to Apple levels of evil rather than removing “don’t be evil” from your moto levels of evil. Crazy how humanity continues to outdo itself.


  • Lytia @lemmy.todaytoPrivacy@lemmy.mlGraphineOS and other possibilities
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    2
    ·
    edit-2
    29 days ago

    If you have a pixel, I’d highly recommend avoiding custom OSs other than GrapheneOS unless you cannot use GrapheneOS for whatever reason. That said, in most cases running stock with modified settings can preserve the base android security while giving you more privacy.

    If you can, you mention having a Samsung, avoid using Samsung with a 10 foot pole. Their security is laughably bad for a major OEM, and once you begin customizing anything with the phone, you’ll encounter bug after bug after bug.

    If you want a handful of reasons to avoid non GrapheneOS custom OSs, here are some of the biggest offenders (if you want more, you could ask in various GrapheneOS chatrooms (such as on matrix or discord) and they’ll be happy to give you more reasons (be warned, some people will be very blunt)):

    Most other custom OSs use privileged MicroG, as opposed to sandboxed Google Play which is mostly unique to GrapheneOS, as well as their own privileged serviced to provide things like parental controls or deeper app customization.

    They’re also very lacking in security, being no better than stock android when faced against Cellebrite or Graykey.

    Their updates tend to take weeks, if not multiple months in some cases, while also not updating when new vulnerabilities are found unless it’s patched upstream.

    Most don’t support locking the bootloader due to the way they support devices (this is part of the reason GrapheneOS is pixel exclusive) which means your phone is vulnerable to having parts of the boot process modified potentially maliciously to allow an attacker access to your data.

    User privacy on custom OSs is often really theater, promising privacy because they’ve removed Google Play Services by replacing it with a less secure, more vulnerable, and less user friendly version called MicroG.

    Finally the /e/OS devs, an operating system recommended to you by another reply, straight up said they’re intentionally not making their OS any more secure, because only pedophiles need to worry about their privacy (the video is in French, and I don’t have it saved, but I can find it if you want).

    All said, if you just want to avoid Google but don’t care about any other Tom, Dick, and Harry accessing your private information, custom OSs are great. If you care about other people, especially other companies, not having access to your private data, and you’re already getting a new phone anyways, I strongly recommend buying a pixel and slapping GrapheneOS on it. Sideofburritos is a great source of information for GrapheneOS, he even made a video trying to brick GrapheneOS during the install process (spoiler: he couldn’t) in case you’re worried about damaging the pixel in the process.

    Disclaimer: I’m not associated with the GrapheneOS project, I’m just a user who cares a lot about their digital security. If it sounds like GrapheneOS is too good to be true, I’d be happy to include some drawbacks of the OS. There really aren’t many, as every news outlet that reviews the OS can agree, but there are a few.