Jump to content

Nokiamies

Member
  • Posts

    651
  • Joined

  • Last visited

  • Days Won

    12
  • Donations

    0.00 USD 
  • Country

    Finland

Everything posted by Nokiamies

  1. Librewolf does as far as I am aware. It is Firefox without all nasty stuff and includes more privacy features like addon firewall (control addon traffic)
  2. what really bothers me is that one article there states SystemD to be good for standardising init and other systems. SystemD is horrible and limits user freedom for choosing system to use. Also when SystemD had bug Redhat developers were very unprofessional with their responses and made Linus Torvalds mad and he stated that would not contribute for Redhat anymore. Also statement that automatic forced updates are good for security. Those has been used to abuse and caused system failures at worst. Second thing bothering me is statement there is no more secure distros and that there has not been breaches on linux users. or faster or more customiable linux distros and all are equal. I disagree with that. If that is case something like Qubes OS does not do anything to improve security by virtualising all processes to containers. Also some distros includes ssh or vnc on by default that can be security risk. And should I mention Openssl library had vurneability that allowed hacker download small amount of data from victim machine? Some distros with same desktop are faster by default since they include less background clutter that makes stuff crawl. Lets compare my default Devuan with XCFE vs Xubuntu and Devuan is faster on slow hw and uses less ram since it wont have automatic updates, telemetry or other junk. Also some distros limit customiability. What is I want change my init system? Too bad that most systemd distros wont allow it while Devuan allowed pick it during setup or could do it afterwards too. And third and worst was this is that article written by some intelligent agency or just by dumb person? Let start with the obvious. If I configure my linux distro for miminal how it will be less private than Windoze 10 64bit? Also TOR identification sure is possible but if you configure browser correctly it is less likely. You should set slider to safest mode on browser so it will block all js by default. Also if you are super worried from fingerprinting use Whonix or Tails linux. Does that person even know how Tor or VPN works. VPN that refers to so called "anonymity service" is just using VPN protocol to route your traffic trough different IP that is usually logged. And VPN is not designed for anonymity. VPN was originally designed for secure remote access for corporate network. It is still used for that atleast on my workplace. If I work from home I need use VPN to access some data. Where did this VPN for anonymity came from? TOR in other hand routes data trough 3 nodes run by volunteers before exiting to network or reaching either internet or onion service. First node can see your ip but not traffic. Last node can see reguested data but not your IP. Sure there is ways to sniff that traffic with malicious nodes or try fingerprint browser but those are not always the case. So that article states that is is more private to use Windoze 10 with keylogging and other features with Google Chrome spyware or Firefox which nasty issues I mentioned here https://msfn.org/board/topic/183138-mozilla-has-turned-into-evil-mitigate-problems-or-go-to-alternatives/ Windows got your MAC address and real ip and keylog all strokes to Microsoft and you wont block JS while trying be anonymous and that is safer and more private than linux? Just use spyware to be private that went bit long rant but that site deserves worst contect overall award from me . I have seen way more professional artcles that lists real issues with linux and one I cannot find right now at says at the end "there is lot better things on linux compared to Windows but problems are usually overlooked" that is true and still addresses main issue unlike any article on that site. I started moving into Linux when Windoze 8 came out. I never liked from MS making UI looks like tablet. Also somewhere around that time GNOME on Ubuntu took same approach but guess what great thing I learnt that day? On linux I HAVE THE CHOICE OF UI. I was able swap out for XCFE and that was great. Also found Mate desktop that is great too. Then I started explore other distros and I was hooked. I had all keys for control and was able break my setup few times but hey atleast it allows me to do anything I want for OS. Also I got plenty of hw that cannot run Windoze 10. For example my EEEPC 900 with 16gb ssd (now 256gb). When had 16gb I was able use Devuan with 4gb install footprint including programs I needed. On other hand Windows 10 takes that 16 and even more for bloat. For me question do I want use linux or Windows answer is both. I like to use older Windows for gaming and it very reliable softwares and use Linux for some other things like banking. While I like linux Windows before Windoze 8 got special place on my heart.
  3. graphics cards sucks. Get rid of them and use system headless with ssh There is also Web Browser (palemoon fork) for linux that works great. Problem is I had issues getting all depencies under Devuan linux yet so only made it work on other test machines. Here is source of it if want try compile it. I have been planning give salix a shot but linux biggest issue is depencies and if some package is not available on other distro you need to compile it and will have depency hell. That is biggest slowdown on changing distro compared changing windows version where there is usually some version
  4. I need something someone could search so those wont work. Figured out anyway. But first one would have been but as you said would not pass moderation . Edit I changed name. If this is find by too many people on internet I will get lot new haters. Liked or not that title is still true Interesting is my install of Mypal or Webbrowser did not do those requests with either MITMPROXY with snooping cert (decrypts all) or Prcoess hacker. did you mitigate palememe?
  5. I cannot even say who they are with due their holiday shopping guide that is definitely not honest opinion. Microsoft is one of last companies I trust with anything
  6. I forget to link that file and good that you added to that mitigate part but I still stay behind this Mozilla had made me mad enough already. And feels pointless to even see any effort with it anymore...well librewolf was recommend by me for reason security is sorta two pipe thing to me (means it is sorta both). More simple and smaller codebase and less features increases security too. Palemoon lacks webrtc and EME for example that are commonly used on exploting along with WASM (palemoon got it on toggle setting tab and no need use about:config) and JS. On other hand memory hardening and isolation increase security but remember that Mozilla previously whitelisted some trackers so I cannot see reason for them not to add backdoor for protection for those trackers. PS. Fun to actually have some counter arguments with actual arguments. If I would say same on any other place would be eaten alive by mozilla fans
  7. Yeah I know that title is not best in the world, but could not get better one into my head. And now it may feel bit clickbait too This board has not have yet any topics about Mozilla/Firefox problems and I decided to make one. This topic purpose is not to shill some firefox alternative like brave or say anything based on gecko engine is bad rather address real problems related Mozilla corporation. I used to be huge firefox fan but lot been going wrong since it. lets start with first and biggest one which is false claims. Mozilla is not people first not profit like they claim. Mozilla foundation sure exist but behind it is mozilla corporation that does profit with marketing deals and also they laid off 250 developers around same time when Mozilla ceo took himself nice paycheck (someone look article from that since was not able find it on quick search anymore). Also Mozilla pretends to be against Google and care from you privacy BUT website privacy policy says against it. so they implemented google invisible recaptcha and google and yahoo trackers on their site. That is caring from privacy right? Also firefox uses google as default search engine Now lets move to browser itself. I wont put tons of stuff here but if someone wants read more Spyware watchdog got good article about it. First issue is Firefox uses google analytics on browser (source) and developers ignored that saying they wont use it for datamining. Sure I trust google about not doing it. Then there is pocket feature which according privacy policy does allow insert personalised ads into stories saved to pocket. Also you need firefox account to use it. Then there is Google safebrowsing which make browser to download address database from Google servers. I explained on other thread why that feature is useless in real life and is only privacy threat. Also Firefox advertises addons during browsing by default By default Mozilla collects telemetry from following I think there is enough from Mozilla privacy issues and time to move for other issues. First one is addon blocking which Mozilla admit they wont care from your choice and want "protect" you https://extensionworkshop.com/documentation/publish/add-ons-blocking-process/ Then there was dropping XUL addons in favor of Webextensions. Problem with webextensions is they are way more limited than XUL addons were. Take example from Classic theme restorer developer if wont believe my word on it again they want limit what you can do and are ready to ignore what users want. Then there is issues related UI changes. Mozilla has been renewing firefox UI multiple times without giving option to go back old look. I absolutely hate new Bloatfox theme. It takes too much screen space for no good reason and removal of most icons on menu makes it harder to navigate. Before you were able to fix it but Mozilla killed XUL addons so not anymore Sure someone will pull you can disable them but why bother fixing something that turns more spyware on every update? Some alternatives I would recommend: Palemoon based browsers. I cannot recommend using vanilla Palemoon for multiple reasons that most here likely know but codebase of browser is solid and Newmoon/Mypal on Windows and webbrowser on linux. Those are best if you need lightweight browser without webrtc or other. Those forks also runs down to vanilla Windows XP Also Basilik is pretty good browser. I recommend disable addon blocklist on both of those If you really want to use latest Firefox based browser: Librewolf which is firefox with telemetry and propieraty blobs removed. Problem with that is they are depent on Mozilla and code grows all the time so it will be uphill battle If you want to use latest Chromium based browser Ungoogled Chromium which removes Google stuff from Chromium. That like librewolf is they are in uphill battle If you want to use chromium on XP: I cannot say anything here since only used goanna based browsers so @ArcticFoxieand @Dixel who got experience can help me out with this one Honorable Mention: Seamonkey I have been using that for while on linux to see how good it is and have to say it is very decent browser and not done by paid Mozilla Employees. It UI makes sense, support classic addons and theming. If you plan use it please follow mitigation guide for maxium privacy. That is way better than firefox on default options, but I recommend still do tweaks Browsers I cannot recommend at all. Waterfox: While it claims to support your privacy it spies on you as much or more as firefox and if that wont convince you it was sold to advertising company Brave: That gotta be absolutely worst out of all options analysis. It has fake cryptocurrency system that needs personal information, it got lot of telemetry, it offers it own "privacy respecting ad platform" which injects ads into webpage. Also it is shilled way too often and you should NEVER trust shilled products. If you want secure and private pick one that does actually well pick one that is as minimal as can and select your own addon set (tampermonkey, umatrix, ublock origin, noscript, decentraliseye) and you got pretty good setup Please add any findings or alternatives I missed
  8. Soon there will be only HTTPS as option and companies wont allow you to access http sites to "protect you". One thing Mozilla fails to protect me from though is from burning nerves when launch firefox with new bloat ui. That is horrible to use on small laptop. It is like mozilla showing middle finger and saying "I do not care from your opinion or if you want functional UI" Ok now to the topic of this artcile. I did some correction and I also tested it on my lab pc that and it indeed block me from reading actually informative site that just happened to lack HTTPS. Good job keeping me on wallen garden. HTTP does not equal malware sites. Most malware sites got HTTPS these days so that tells nothing. it wont on me on either cases since I wont let browser scan files I download but when scanned files using local antivirus it infected executable. I recommend block scripts overall by default. HTTPS does not mean js cannot do harmful things to your machine. All it takes is one link to land on infected site. Also if I modify CDN or other provider site uses I can use that to load bad script no matter if got HTTPS or not If you feel like my purpose is to mean for you, it is not. I am not any casual with safety. I have done lot of pentesting and test runs of exploits and know how they work. I can grab nice amount from victim system with javascript only. Point why I keep saying false protection is because they assume everyone are equally stupid and wont give advanced user option to choose. We made web disaster it is now and try patch around without actually adminitting core mistake, browser running unauthorised program code on cpu is horrible idea. And there is need for encrypted connection for sure on sites like banking and others but not every single simple site. There is many older and embedded systems that cannot do TLS and are locked out from internet for that. I also enforce HTTPS whenever can but sometimes cannot. If HTTPS is not issue why does frogfind search engine exist that cripples it along with other bloat? Also when I say victim I mean my own virtual machine or person who asked me to do the testing on isolated lab network, not someone unknown. I don't abuse my computer knowledge
  9. Correct, Norton speedisk is paid software. I got it since had few cd of norton systemworks that had it. Most of utils were useless to me but windoctor and speeddisk were very useful. I am not sure if norton bundled it seperately. That suite got Norton antivirus and I hate norton antivirus. Luckily can opt out. Norton 2003 internet security was decent but 2006 was nightmare. Well so was avast 4.7 before bloatvast 5.0 came out, best could be maybe set up own fileserver. I have been thinking do so some point on future. Then could ftp files there. Biggest things is find good vps, good domain provider and hope wont get DDOS:ed. that brought back memory from last year. I was working on modchipping my original xbox when found mentions from fire hazard on Foxlink psu (foxconn owned company). Later found it was due cold joint on power plug that caused short circuit. MS way fix it was not replace faulty psu rather send you cord with circuit breaker. Mine was close to hazard so was good I applied some fresh (leaded) solder to it and been good so far. Also fun fact is that xbox was comparable to desktop computer on parts for the era. It had Pentium 3 with half of cache, 64mb ram and Geforce 2 based gpu and Windows 2000 kernel. It was popular in modding for that reason.
  10. Forced protections like automatic updates without ability to opt out, blocking addons, safebrowsing are false security/privacy features. I do not want browser treat me like baby and recist what I can do with it. If I want will load all possible adware and spyware plugins and only visit phishing sites I should be allowed do so. It is not browser vendor problem if user that stupid. For me privacy and security are hand to hand. If privacy is lost so is security. Lets say you enable feature than pings to company all the time to protect you from "bad sites" (sure they wont harm you with that data) and company gets breached and all of your browsing data with IP address and mac address they have collected is leaked there goes security.... I wish browsers would be as recistive limiting developers from doing whatever they want with browser. That would actually help for security. "Hey lets make program language that allow web browser do stuff without user consect since I can see zero abuse risk on that". Most of web browser security issues are self caused by adding stuff that DOES NOT BELONG to be web browser. For me problem on those protections is someone else decides what is safe and what is not safe for me and caused biased opinions many times. For example Palememe blocks Noscript because Moonchildish devs got mad to noscript devs for no good reason. And reason to be blocked is it breaks sites. It sure breaks sites but that is because sites got too much js and noscript like name suggest is script blocker
  11. for me 1.8l DOCH engine feels like bare minium since I will use highway a lot. SOCH is fine if got Variable Valve Timing, but 99% town driving you wont need any of those yeah all we now needed was more rapidly pushed nosense. How we get needed energy without using wood or peat? Nuclear power or should I say nucdirty power? Sure that is 100% safe and not like soviet or japan taught us how safe it is and definitely did not lead to disasters. Why we have to cut our energy independence to "save climate"?
  12. I recommend what @Dixelrecommend. I have been cleared smart alert on some disks. Sometimes bad blocks are not remapped by controller when should be i recommend same too. I generally had bad experience with seagates. WD blue (7200rpm 1tb model with idle parking off) and wd black never let me down. Funny that my 20gb seagates from early 2000 got zero issues while had plenty of issues with newer ones
  13. well remember that mozilla says they respect user freedom but mozilla also said this https://extensionworkshop.com/documentation/publish/add-ons-blocking-process/ so they admit "protecting" is more important than allowing user have freedom. that was just slightly scratching surface from mozilla issues and agree belongs to it own thread
  14. Well Ford and Dell got some in common. Both used to do high quality stuff but since then started cut corners and turned into unreliable short lifespan products. Dell uses cheap caps on mainboard and their cases are propieraty so no way change case easily. I hope you and your machine will have long lifespan together . PS. that desktop is interesting looking still. It looks like mix of Windows XP and Windows 7 to my eye
  15. imagine that being only checkout and you would be in hurry to buy food
  16. Well you should not use cloud to store important data anyway. There is no cloud just other people computers and by sending data there you trust unknown entity with all private and possibly classified data. Use external hard drives combined with cd-r/dvd-r/dvd-r DL/Bluray to backup and do offsite backups. Optical media is secondary backup and hdd primary Also if you do not want go to win10 to avoid spyware features but install newer ms software like office 365, you made it poitnless. Office loads quite bunch of stuff to your machine and phones home from everything. Latest office I use is 2007 and after that libre office or openoffice
  17. Here another RTL-SDR related software that I found to work on XP. adsbSCOPE V2.7 with ADSB# V1.0.11.1 works on XP and displays aircrafts around me. I tested and all maps and built in downloader works without issues under 32bit Windows XP with POS ready TLS patch. That program is also less bloated than virtual radar server (why does it need web server while this wont) and runs all inside client. Earlier I mentioned some other RTL-SDR related utils that been confirmed to run on XP. You do not need newer Windows to do SDR stuff
  18. Security is illusion many times and used by marketing teams to sell products. Words like secure and private are common Lets take three examples of persons Person 1. Uses Windoze 11/MacOS with some "super secure" (read super bloated) antivirus, Microsoft Edgy, or Google chrome and think is unhackable since memory protections and got all updates installed. And lets ignore fact companies have likely backdoored those protections to whoever asks it. Person 2. Uses fully libre thinkpad with FreeBSD or QubesOS and uses hardened firefox thinking they are unbreakable and safe from hackers because that is what everyone said from them. Well that is harder to break but FreeBSD got vurneabilities too and Qubes OS uses hypervisors that got vurneabilities. Also what if someone just break into your house while laptop is on and prevents you from locking it while copying all of your data out or do other physical intrusion? Person 3. Uses whatever his personal preference is. Does not run after latest "security" trends. Takes time to research and patch any holes can on system, but despite that does not trust to be hacker or virus proof and is careful and uses common sense. Which of those persons is least likely get hacked or get attacked by virus? I would say person 3 because that he/she is not too arrogant to think to think he/she is safe from hackers. Point of this is not say all safety is useless and you will get hacked rather is never trust to software or hardware blindly and not fall into every single marketing word. Person 1 fell totally fell into marketing lies without doing any research at all, Person 2 sure did good steps like removing backdoored bios and disabling hardware backdoor, but fell into arrogance that can ruin all effort. I actually needed /p i flag on my main Pentium 3 Windows 98 pc because ACPI issues. ACPI seemed to make whole thing unstable and when forced to apm and then disabled APM was stable. Windows 98SE sucks on power management even it is good other ways. on machines I got HDD installed I like to use Norton Speeddisk for defrag. For 98SE/ME non lite, 2k and XP i use 2003 version. It seems do better than Windows defrag. Fun fact Windows defrag and scandisk are crippled Norton Speedisk and Norton Disk doctor. MS licenced their limited versions from Symantec. What I am not sure if Symantec reduced their performance on purpose to sell their own product but feels like it. Windows 9X dirty fixes like copying files from working install fixed things many times. It was way more simple and mostly cared from registry. Also if 98SE hoses up, I can still access dos mode and use scanreg and others without needing emergency boot floppy unless boot partition is broken
  19. There simple reason. Back in day devs were not able to get away for making horribly optimised code so easily (internet exploiter is expection). Back then RAM and hdd space was relatively pricey and internet access was over modems for most. Broadband access was new and it purpose was not download bloated page rather have faster speed for stuff like download/stream music and video. Making site load slowly like today if wont have bleeding edge connection was saying "f**k you I do not want to do business with you.". Today normies got fast enough connection to make it possible push unoptimised junk acceptable with "most users got good connection" excuse. Sure I do have 100mb/s cable modem connection but only because apartment offered 10 euros per month. I took it to have better connectivity to server and file transfer use. And most sites download relatively quickly. BUT that does not make accept bloated contect. I am lucky to enjoy such luxury, but not all does have that. Pretty sure many on this board have even capped data connection and speeds way below that. Most modern sites look flat and ugly and got useless stuff like text done with js, hamburger menus etc. everywhere. Back in day dynamic web pages did something cool actually and were not just to track you. Making static site is impossible unless using web tools unless use something like old Dreamweaver or do all HTML with text editor since they all are just web frameworks now. Best way to classic internet is to do simple personal site and use XHTML since that is much more strict and actually standard. I currently do not have website but somepoint will setup one when got time though I wonder how long it takes until my domain is suspended or site ddosed for stating opinions from these problems and someone found it went to reddit or twatter causing outrage among fanboys (yes I hate those services). That is huge thing to do considering chromium changes all the time more bloated and you would have to rewrite all code more efficent while keeping all those broken standards. I would want web browser that purpose is to download documents over network and render them onto your screen and not some application platform. Palememe is closest to it along with retrozilla and netsurf
  20. it is since most see more potential on dos than Windows 9x. For most Windows 9x is obsolete and vurneable and insecure. What is funny pure DOS is even more insecure than Windows 9X on some ways. For example I can use internal tools to wipe boot hdd clean inside dos while windows 9x does not permit it that easily. Sure you can ruin windows 98 many ways but dos is not magically more secure. Also win9x is running top of DOS Benefit of dos is that it allows tap directly to hardware without using API. That is why many programs are faster on dos than Windows 9X, but downside is you can indeed tap directly to hardware and do all type of not so fun stuff
  21. perhaps I worded it bit too roughly. My issue with javascript is that atleast newer one does not have so strict limits what it can do to please developers and that is making it unauthorised code executed on cpu in my point of view. Webassembly which is javascript makes it even worse and upcoming webgpu well time will tell. Also javascript is not standard at all. Google and Microsoft keep creating their own code with it causing major headache to someone who does not want bleeding edge browser all the time rather prefer long term support. Atleast flash and java had standardised plugins and dynamic contect was able to work on firefox or opera and not just internet exploiter back in day. Sure those had vurneabilities, but so does webassembly and js. Anytime web browser runs unauthorised code you risk machine to those vurneabilities One of js abuse is ability to read your nic mac address which can be used for fingerprinting in future or deanonymise TOR users unless they use mac address randomisation. Question is one point activex fell out of use in favor of Javascript and everyone look how stupid idea it was to give web browser that much power. And even today some suffer from it consuquences. Enterprise environments still got tools made with active x that cannot be dropped out of use since nobody full knows how it works since person who coded it left place long ago. Vendor lock in. So how bad side effect will be once JS issues gets addressed? Yes if coders would be required use something actually optimised and not just wrap js bloated webpage to electron and call it program. I have been studying C for last few years. It is very complex, but can write very efficent code. I am tired of Microsoft teams used to communicate with workmates sucking 2gb of ram, when basic function is exactly same as older messaging softwares with too much fluff
  22. i think was bit unclear. Windows 9x and Windows 3x share same things under the hood. Both are programs in top of dos (even though got own drivers) and purpose was to exit windows 98 to dos mode using shortcut that loads custom config.sys and autoexec file then unloads those once close and reboots to windows 98
  23. Luckily I can still control it for most parts. For email I use mailnews client and last time I logged into webmail was to enable IMAP support, news I read from teletext or rss, both are bloat free. For teletext I only need any TV with digital tuner or digital tuner with end device. that is mostly true in my case. I like to use online news via RSS sometimes but mostly use newspaper and teletext. YLE teletext main page got anything important I need to know like emergency alerts or warnings if need "bleeding edge information"
  24. Seems WTTR.IN now forces HTTPS for website since someone whined we need HTTPS only. For now it works on roytam1 ff2, but for future need look alternative since some point TLS 1.2 support will be dropped and TLS 1.3 (for now) wont work on Windows 9X I mean really? Site is literally just weather using ASCII symbols. Why do you need strong encryption in order to do it? Script injection excuse is stupid. If you are too stupid to block JS on untrusted site it is your own problem. User should be responsible on own security and should not be treated like babies. And HTTPS does not mean site cannot harm your machine or someone cannot inject code. That site for example uses adobe assets and twatter and if one of those is compromised site can do nasty stuff. That site was perfect until now. I was able check weather using my 486 with netscape navigator 3, check in older PDA and even check weather on Nokia phone with 128x128 display, but now all are broken to "protect" me . Time to look for alternative online weather service that force stuff like that.
×
×
  • Create New...