• 0 Posts
  • 21 Comments
Joined 1 year ago
cake
Cake day: July 8th, 2023

help-circle
  • If you use Google’s Play Services and/or other Google proprietary apps and services (they are standard on all commercial Android phones), then your battery will be drained slightly more due to it having spyware (euphemism: “telemetry”) integrated. The Google Play services app, for example, does transmit at the minimum this data roughly every 20 minutes to Google:

    Phone #
    SIM Card #
    IMEI (world-wide unique device ID)
    S/N of your device
    WIFI MAC address
    Android ID
    Mail Address of your  logged in Google account
    IP address
    

    And that is just if you have disabled ALL telemetry in ALL of the options, even the most hidden ones. So this is the minimum amount they are always gathering from every Android user, no matter what you selected. To make matters worse, the Google Play services is typically installed as a “system critical app” which means you as the owner of the phone can’t even uninstall it or reduce some of its permissions.

    (If you have an iPhone instead, and think you’re safe from this, no you aren’t. Apple also collects a minimum amount of telemetry data which you cannot ever completely disable, it just does it slightly less frequently (IIRC, it was like every hour or so, compared to Google’s every 20min at the minimum).

    And then there’s also the advertisement ID, a world-wide unique identifier set in all commercial Androids as well as iOS, for apps to track you. You can only reset it to a new random ID but never disable it fully.

    To stop all of this bullsh!t, and also to stop the additional battery/resource drain caused by this, I recommend getting a Pixel phone and replacing the proprietary stock Android OS with GrapheneOS and then not installing any Google apps/services on top of it. You can get apps via F-Droid, Obtainium, Aurora store (those are the convenient methods). You can use ntfy as an alternative to the Google firebase messaging (notification) service that you won’t have access to when not having Google Play services running.


  • MI is great, I played 1+2 when they were new (in the 90s), they were brilliant back then. These days, they’re probably still good point&click adventure games. There were some special editions or remasters which probably make them play well on modern machines. They belong to a long list of awesome LucasArts point&click adventures during the 90s and early 2000s. Most of these games are great. You should definitely try them out, especially if there are remasters available. But you can also play the originals using ScummVM most likely. Ron Gilbert is like the mastermind behind the series. He still creates adventure games to this day. And they’re all pretty good, but the genre is kind of niche these days. It wasn’t niche back then. It was just as big as action or soulslike games are today. The Monkey Island titles were probably the most successful or popular ones of the bunch. But there are some others which are equally good. Adventure games are rare these days but basically they are like puzzle games where you have to solve certain situations by combining items, finding items in the first place, trying different approaches, and so on. You kind of know once you’ve overcome a challenge when you were able to progress further in the game. There’s little to no handholding, but also little to no handholding needed. There’s one timing-based riddle in the original Monkey Island which I never liked that much, but it’s still a funny one. It’s not hard but it doesn’t really fit the genre well because nothing else is timing-based. It does fit the game’s art, setting and humor well though. The soundtrack is nice indeed. This is probably the most well-known track: https://invidious.nerdvpn.de/watch?v=FoT5qK6hpbw




  • Well this whole area is mostly based on deceit. Like if they claim they MAY do something they will absolutely do it all the time, if they claim they aren’t getting anything from it, it just means they aren’t getting anything directly, but indirectly instead, or from a different involved party. I also like the message at the top of the page: “Under certain circumstances, you have rights under data protection laws in relation to your personal data.”. Under some circumstances you have rights. Which is weirdly accurate. Because in most circumstances, they will just sh*t on data protection rights. Which is also evident by everything being opt-out, rather than opt-in. And then, most likely, even when you disable everything, data will still flow somewhere. Then again, it’s an industry-wide problem. Not specific to Jagex.



  • Well, they’re only doing what they announced already like 1-2 years ago. So we knew it was coming. This is also accompanied by Google making YouTube more restrictive when viewed with adblockers. Google is (somewhat late, to be honest) showing its teeth against users who block ads. I always expected it to happen but it took them quite some time. Probably they wanted to play the good guys for long enough until most users are dependent on their services, and now their proprietary trap is very effective.

    On the desktop, you should switch to a good Firefox fork right now. Firefox can also be used but needs configuring before it’s good. The forks LibreWolf or Mullvad Browser are already very good out of the box. There’s the potential issue of the forks not being updated fast enough, but so far these two have been fast. Mullvad shares a lot of configuration with the Tor Browser, so using it may break some sites. LibreWolf might be “better” for the average user because of that, but otherwise I think Mullvad is the best Firefox fork overall.

    On mobile, Firefox-based browsers aren’t recommended, because on Android, the sandboxing mechanism of Firefox is inferior to that of the Chromium-based browsers. And on iOS, all browsers (have to) run on Apple’s proprietary Webkit engine anyway, but well this is Apple we’re talking about so of course it’s all locked-down and restricted. It’s one of the reasons I don’t even like talking about Apple that much, just be aware that as an iOS user, your choice doesn’t mean as much when it comes to browsers, and your browser might not behave like you think it does on other platforms.

    So on mobile, I’d suggest things like Brave, Cromite or Mull. Or Vanadium (GrapheneOS). If the browser doesn’t have built-in adblocking capability which sidesteps the MV3 restrictions, make sure to use an ad-blocking DNS server, so your browser doesn’t have to do it. But you still need it. Adblocking not only helps you retain your sanity when browsing the web in 2024, but it also proactively secures you against known and unknown security threats coming from ads. So adblocking is a security plus, a privacy plus, and a sanity plus. It’s absolutely mandatory. As long as the ad industry is as terrible as it is, you should continue using adblocks. All the time. On every device and on every browser.

    The ad industry is itself to blame for this. There could in theory be such a thing like acceptable ads, but that would require ads to be static images/text, not fed by personal data, and not dynamically generated by random scripts which could compromise your security, and not overly annoying. Since that is probably never going to happen, you should never give up using adblockers. Since they basically fight you by reducing your security and privacy, you have a right to defend yourself via technical means.



  • I hope that our courts in western democracies are strong enough to stop these developments, but I fear they ara not. Once this kind of stuff is being attributed to (even completely unproven) “higher security” or “national security”, and once secret services run the software and identification routines, it will land in the same extra-legal space as internet mass surveillance already lives in: “No no, we’re not doing that. Okay, you got us, we’re doing it, but only in limited scope. Okay, you got us, we’re doing it on everyone, but it’s important for national security and we can’t disclose anything else”. And that’s usually when nothing can be done anymore about this, and laws and ethics will be outmaneuvered.


  • Long-time GrapheneOS user here.

    Can’t say anything about Motorola gestures.

    Banking apps MIGHT not all work on GrapheneOS, if unsure check first, or ask on the GrapheneOS forum. I forgot the reasons but it’s probably something stupid like the banking app blocking any non-“Google-sanctioned” Android versions via the Play Integrity DRM kind of feature. It sucks, especially because GraphneOS is way more secure and private than any commercial Android, but what can you do, bad decisions are being done all the time.

    GrapheneOS is my recommendation, it’s easy to install and can be used by tech-illiterate people as well because almost none of its security and privacy enhancing features require any special configuration work from the user or require advanced knowledge, it all happens mostly in the background with good default settings. Even for tech-savvy people this has the advantage of not requiring any tinkering or maintenance work, it feels like using any proprietary Android, just hardened and much more privacy-friendly.

    You should still maybe be aware of these potential minor issues:

    • Some apps might refuse to work on any “unsanctioned” Android version via the Play Integrity thing, but so far this seems to be very rare (thankfully). If you find any, make sure to tell the developers that they should stop doing that.

    • Some apps might simply require Google Play services to be installed. On GrapheneOS, you can install them via the “Apps” app, and they will be slightly less terrible than they are on any other Android because they won’t run with full system rights, but instead they’ll be sandboxed and can be completely shut down by using the standard permissions system, which the user is blocked from doing on proprietary Android systems. But then again, if you must use them, then of course they’re going to require Network permission and they’ll use that to phone home to Google, as they always do on standard Androids as well. So it’s not recommended to install any proprietary apps from Google on top of GrapheneOS. Even though on Graphene, the amount of things an app is allowed to do is more limited compared to the huge amount of data an app can read and phone home on a propreitary Android system.

    • Some apps include certain widgets like Google maps which, again, require the respective app or Play services app to be installed as well. Depending on how these apps are written, they might simply fail completely when this dependency is not there. But so far, I’ve had luck, and some apps I’ve used which integrate a Google maps widget still worked without it. So it depends on the app and the quality of its developers.

    • When not having the Google play services installed (default), you won’t have access to Google’s push notification system in the cloud. Some apps, even some privacy-respecting apps like Signal, rely on that. Signal will work without, but then it uses a power-inefficient alternative based on websockets instead, which means Signal without Google play services drains your battery faster than it would otherwise. There are ways around this by using the Molly fork of Signal (Signal is open source and there is at least this one fork often being used as well) with the open source app “ntfy” and an either self-hosted or a privacy-respecting ntfy server instance somewhere to go along with it, which will then act as your own push notification server in the cloud. So you don’t need to contact Google’s stuff for that, and less connections overall to Google equals more privacy overall.

    • If you do decide to install the Google play services app on Graphene, make sure to allow it to run in the background. But, again, it’s not recommended to use any proprietary Google apps/services.

    • Once you have Graphene installed, be sure to use its integrated browser called Vanadium (a hardened Chromium fork) to download and install an “app store” of your choice. When I first started out, I installed the F-Droid apk first, then from within it Aurora as a Play Store client. Giving me access to a lot of open source and Play Store apps, respectively. F-Droid unfortunately has some potential disadvantages, which is why I recommend using Obtainium instead of the F-Droid client (you’ll still access the F-Droid repository sometimes because some APKs of open source apps are only hosted there, but at least you’ll avoid potential issues with the F-Droid frontend application then). Using Obtainium instead of F-Droid will be slightly more work at the beginning when compiling your needed open soruce applications, but afterwards it’s just as easy.

    • Make sure to configure a privacy-friendly and ad/tracker-blocking DNS server, as well as something like RethinkDNS or NetGuard Pro to control which apps are allowed to contact which hosts/IPs. Otherwise, while Graphene itself won’t violate your privacy, many apps will still do that (especially proprietary apps often contain several trackers).

    • If you need tutorial videos on how to install or initially configure Graphene, or Obtainium, watch the youtube channel “Side of Burritos”, excellent content.

    If any of that sounds scary, it shouldn’t be. Most of these issues are really minor and it’s unlikely that you’ll be too negatively impacted by any of it, so give Graphene a try without Google services. There are great open source apps out there for all sorts of functionality. Just felt I should mention any potentially small pitfalls.

    Other Android variants or ROMs are inferior to GrapheneOS in terms of security and privacy, unfortunately, so it’s best to buy a cheap Pixel (8th generation recommended due to strong hardware-based security) and install Graphene on it. Otherwise you’ll miss out on Graphene’s very strong security and privacy features. There are some other privacy and security oriented Android variants like Calyx or /e/OS or things like that, or even LineageOS, but they all, again, don’t reach up to Graphene’s level of security and privacy.

    HTH


  • Clickbaity titles on videos or news sites is the new standard. I watched it. The point he’s making is basically that music was harder to make/produce some 50 years ago, so there was more incentive to “make it worth the effort”, compared to today. And the 2nd point he makes is that music consumption is now so easy as well (listen to whatever you want instantly) compared to when you could only listen to something when you bought the physical album, that there’s also less incentive for the listener to really get involved into some albums.

    Personally I think these are valid points on the surface but they are not “the answer” to this kind of multi-faceted question. They’re at best a factor but we don’t know how big these factors are. Also I think one big reason he thinks that way is because he grew up in that environment and so he has a bias for “owning physical copies of albums”.

    I also think music hasn’t gotten worse, the market is just simply over-saturated because there’s just way too much music, you’ll never be able to listen to it all. And there are absolutely hidden gems or really good bands/artists forming even today, it’s just much harder to find them. Generally a problem of today’s age: it’s likely that what you’re looking for already exists, you just have to find it within a whole ocean of content.

    If you’re looking for innovative or non-standard stuff, you can always look at smaller artists or the indie scene, same is true for movies, games, music. The big producers always have a tendency to stick to what works and what’s proven to be popular so everything becomes similar. But smaller artists do not have to care about such things, they are ready to risk much more and in doing so, you might just create a real gem or something that was never or almost never tried before.



  • Check out SyncThing for a peer2peer (device to device) solution which doesn’t necessarily need a server, but having an always-on device like a server is still great for using Syncthing as well. It’s easy to use, only slightly more involved than setting up Nextcloud or Dropbox or whatever. But all done via a web-based GUI. It works surprisingly well, stable and conflict-free for the complex syncing it has to do all the time. Basically you install SyncThing on all devices you want to keep in sync, and they will find each other via their IDs when they are online, and automatically sync all their directories which should be synced. Of course it’s open source and cross-platform too.



  • Well, ever since Win8 or Win10 I stopped having much sympathy with Windows users. They deserve things like that, when they still remain on that ship. Since these things are being introduced in small portions (salami tactics), the users will slowly become familiar with these things and just accept them because they can’t change anything anyway, thus slowly incorporating a defeatist’s attitude towards all the bloat, ads and spying. AKA, learned helplessness. In a couple of years, Windows will be absolutely horrible, but people will be used to it. I’ll just say this: Windows used to NOT have this kind of crap integrated.


  • Yes. Even though not using all this crap may sometimes feel like you’re missing out on certain stuff, it is still the right thing to do. I don’t support abusive behavior, bloatware and spyware, so companies doing that will not receive any money from me if I can help it.

    We’re basically just one step ahead of the general population, who basically (still) eats up anything that’s being served by big tech corporations, without any second thoughts or hesitations. The general population IMHO is currently at the stage that nerds were like 25 years ago, in that they tend to be naively enthusiastic about every new piece of tech. But nowadays, tech can be abusive towards their users, and so it’s important to choose the right tech. The general population hasn’t made that realization yet (or they don’t care, which also must change).

    The media is also partly to blame for this, for example almost every new review of any Samsung or Apple phone is usually very positive, usually just reporting about the advancements in hardware and UI, without even mentioning any of the downsides these have on the software side. And so when reviews don’t even mention downsides anymore, there’s a lack of information available.

    And it’s not even that regular users don’t like the alternatives. For example I convinced a friend to move from a regular spyware-infested Samsung Galaxy phone (which he was using all the time, and he even wanted to buy a new one) to a Pixel with GrapheneOS. He’s not missing anything, even though his transition wasn’t super smooth, overall he’s happier now, and he mentioned that he likes the OS being so clean and unencumbered. He doesn’t particularly care about the privacy and security improvements which he now also enjoys, which is a bit sad, but at least he’s happy with the lean and unmodified Android (open source) experience.

    So, as usual, information/knowledge is power. People need to know that alternatives exist and that some alternatives are actually really, really good. And they need to know what the problems are with the “default stuff everyone uses”, so that they can make better informed decisions in the future. They also need to become less dependent on big tech companies. The alternatives have little to no PR and thus little public visibility in comparison, except via word of mouth, so we need to make the most out of that.


  • Yes, though since it’s closed source, contains other proprietary libraries and probably was never properly audited (by a 3rd party) it’s possible (even likely, considering it’s Meta we’re talking about) that they keep a copy of the private key(s) and the messages, so that they’re able to decrypt them, and so still be able to gather the content, in addition to everything else, while they can publicly claim it’s all Signal’s protocol so everything’s “E2E”. And yes, the app also gathers a lot of other data (actual and metadata) besides the content of the messages (which Meta can’t supposedly see since it’s E2E, but I never trust anything from Meta). A Meta app (or Google, or MS, for that matter) should generate the same sort of privacy outrages and media/politics attention like TikTok does, but somehow they don’t. “Same shit, different country” was never so fitting.

    Here’s a very good messenger comparison: https://www.messenger-matrix.de/messenger-matrix-en.html