Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Do you accept suggestions of links? #1

Open
jermanuts opened this issue Jul 21, 2022 · 76 comments
Open

Do you accept suggestions of links? #1

jermanuts opened this issue Jul 21, 2022 · 76 comments

Comments

@jermanuts
Copy link

https://wonderfall.dev/fdroid-issues/
https://cronokirby.com/posts/2021/06/e2e_in_the_browser/

@beerisgood
Copy link
Owner

Sure!
First link is already included in https://github.com/beerisgood/Smartphone_Security

I will check your second one 🍺

@jermanuts
Copy link
Author

@beerisgood
Copy link
Owner

I added all but last one.
Thanks! Your name is also listed in these new commits 🍺

If you don't have more stuff, i would close this issue for now.

@jermanuts
Copy link
Author

jermanuts commented Aug 1, 2022

@jermanuts
Copy link
Author

(An Antivirus does not improve your security)

Most of these links are dead and not technical but rather opinion based, maybe in future add archive.org or arhive.ph link when referencing a tweet.

@beerisgood
Copy link
Owner

(An Antivirus does not improve your security)

Most of these links are dead and not technical but rather opinion based, maybe in future add archive.org or arhive.ph link when referencing a tweet.

Only first link is dead. @Zanthed @terezipyrope

But yeah they’re not technical.
will check your other links. Thanks

@beerisgood beerisgood reopened this Aug 1, 2022
@beerisgood
Copy link
Owner

I added most of it and also mentioned you again in the commits.
Thank you!

@jermanuts
Copy link
Author

Thanks, glad you liked them.

@jermanuts
Copy link
Author

https://www.bejarano.io/sms-phishing/
https://mega-awry.io/ (mega.nz flaws, don't trust encrypted storage clouds use cryptomator to upload your files to the cloud)
https://mjg59.dreamwidth.org/59479.html (The Freedom Phone is not great at privacy)

@beerisgood
Copy link
Owner

@jermanuts
Copy link
Author

jermanuts commented Aug 12, 2022

https://tonyarcieri.com/4-fatal-flaws-in-deterministic-password-managers
https://www.ietf.org/archive/id/draft-nottingham-avoiding-internet-centralization-05.html
https://pseudorandom.resistant.tech/federation-is-the-worst-of-all-worlds.html
https://krausefx.com/blog/ios-privacy-instagram-and-facebook-can-track-anything-you-do-on-any-website-in-their-in-app-browser
https://rohanrd.xyz/posts/why-you-should-start-self-hosting/

EDIT: do you think the last 2 links fit/related to security?

Not related.
Do you have any way of contacting? Might invite you to servers where you meet like-minded people or for discussing some topics.

@beerisgood
Copy link
Owner

Password manager link added. Thanks 👍

I read about Meta the other day, but since Meta itself is a problem in itself, i don't see the point of recording individual things about it.
Regarding the other links i have no use.

I am only active on GitHub. All other community platforms are always crap from the users or even from the moderation and i don't want that anymore

@jermanuts
Copy link
Author

jermanuts commented Aug 12, 2022

Thanks for replying,
I was going to recommend #grapheneos:grapheneos.org and https://matrix.to/#/#privacyguides:matrix.org anyway privacyguides is probably not as aggressive as grapheneos when it comes to moderation.

What about #1 (comment) https://www.hardenize.com/ , https://mxtoolbox.com/ they seem to be more accurate than the ones recommended in this repo

guardianproject/haven#454 (haven is broken)
Tox has a severe vulnerability since 2017 and has yet to be fixed as of July 2022 where messages are spoofable.
https://blog.invisiblethings.org/2011/04/23/linux-security-circus-on-gui-isolation.html

Mind changing the antivirus part in this repo with https://privsec.dev/knowledge/badness-enumeration/#antiviruses instead as we discussed #1 (comment)

@beerisgood
Copy link
Owner

GrapheneOS is already listed in my Smartphone repository.
PrivacyGuides isn’t that good.

Will check your newest links 👍

@beerisgood
Copy link
Owner

What about #1 (comment) https://www.hardenize.com/ , https://mxtoolbox.com/ they seem to be more accurate than the ones recommended in this repo

while they're nice, both doesn't provide any further information or are even bloated with too much different stuff.

added other ones 🍺

@CompSciFutures
Copy link

CompSciFutures commented Sep 15, 2023 via email

@beerisgood
Copy link
Owner

most of the things he writes are old and have been discussed many times

If you have details why the technical research in that article is wrong, i'm open for links.

have little impact on the user and can be disabled, in short, it's not a relevant article from my point of view.

abusing an browser for own suspicious crypto shouldn't be activated in any way. No matter if you can disable it or not
Also we have (an already solved) discussion: #4

@jermanuts
Copy link
Author

jermanuts commented Sep 15, 2023

most of the things he writes are old and have been discussed many times

Agree

If you have details why the technical research in that article is wrong, i'm open for links.

It's more politically motivated and all his points were already discussed before. Take a look yourself https://www.spacebar.news/p/expressvpn-is-sponsoring-far-right/ and several replies from privacyguides community https://discuss.privacyguides.net/t/why-recommend-brave-browser-on-android-and-not-mull/13957/2

abusing an browser for own suspicious crypto shouldn't be activated in any way. No matter if you can disable it or not Also we have (an already solved) discussion: #4

What about Pocket in Firefox?

@beerisgood
Copy link
Owner

What about Pocket in Firefox?

Firefox did and do other suspicious crap and isn't recommend anyway.

@jermanuts
Copy link
Author

@beerisgood
Copy link
Owner

Thanks I add both 🍻

Good luck with your collection!

@beerisgood
Copy link
Owner

thanks I added some.

@CompSciFutures
Copy link

Your Messages on Telegram Are Not Encrypted, the Platform Is Not as Private as You Think
Telegram claims to be private and encrypted, but that isn’t really the case.

https://medium.com/secure-words/your-messages-on-telegram-are-not-encrypted-the-platform-is-not-as-private-as-you-think-d14a6342928d

Takeout: only Secret Chat's are e2e encrypted. Everything else is cleartext.

@CompSciFutures
Copy link

CompSciFutures commented Feb 25, 2024 via email

@beerisgood
Copy link
Owner

Thanks.

@jermanuts
Copy link
Author

jermanuts commented Apr 13, 2024

https://educatedguesswork.org/posts/public-wifi/ public wifi security (clears all FUD about public wifi VPN marketing)

Nextcloud E2EE broken

EDIT: Adding quantum resistance to Signal double ratchet algorithm SimpleX Chat 😎

@CompSciFutures

This comment was marked as spam.

@beerisgood
Copy link
Owner

https://educatedguesswork.org/posts/public-wifi/ public wifi security (clears all FUD about public wifi VPN marketing)

Nextcloud E2EE broken

EDIT: Adding quantum resistance to Signal double ratchet algorithm SimpleX Chat 😎

Thanks. I added this and also another new post about VPN.
Found also the Nextcloud think in Mastodon a new days ago 🍺

@jermanuts
Copy link
Author

https://words.filippo.io/dispatches/telegram-ecdh/ (THE MOST BACKDOOR-LOOKING BUG I’VE EVER SEEN)

TokTok/c-toxcore#426 (https://blog.tox.chat/2023/03/redesign-of-toxs-cryptographic-handshake/)

@beerisgood
Copy link
Owner

Thanks! I added both 🍻

@wldasf
Copy link

wldasf commented May 18, 2024

Sorry for hijacking this issue but https://ynwarcs.github.io/Win11-24H2-CFG

@beerisgood
Copy link
Owner

Sorry for hijacking this issue but https://ynwarcs.github.io/Win11-24H2-CFG

Sounds like a good thing for user.

@jermanuts
Copy link
Author

https://palant.info/2024/07/15/how-insecure-is-avast-secure-browser/

@beerisgood
Copy link
Owner

Thanks. Added 🍺

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

6 participants