Post ADwOXqhFUXBDES1eNM by RTP@fosstodon.org
(DIR) More posts by RTP@fosstodon.org
(DIR) Post #ADwGwIfcL2M5J8PWrI by rootbsd@distrotoot.com
2021-11-30T21:23:08Z
0 likes, 0 repeats
What's even a good use for tor-browser? Video sites don't work on it, and logging in to social media or shopping sites defeats the purpose, that's not anonymous. Turning off javascript just only lets you read articles or blogs. Do the glowies really care about what I read? This privacy thing breaks down when you really look at π€
(DIR) Post #ADwHuihwf01bR8JHYu by 10leej@distrotoot.com
2021-11-30T21:34:04Z
0 likes, 0 repeats
@rootbsd it's for those that access websites that don't require logging in.So....Search engines
(DIR) Post #ADwI3ltiAblzw586Hw by rootbsd@distrotoot.com
2021-11-30T21:35:42Z
0 likes, 0 repeats
@10leej Yeah, but I already use DDG for everything, they say they don't track you π€
(DIR) Post #ADwI9WummvkvCnNV1k by adeepa@distrotoot.com
2021-11-30T21:36:44Z
0 likes, 0 repeats
@rootbsd use it to visit onion sites.
(DIR) Post #ADwIlg5t6osUg5lGAy by rootbsd@distrotoot.com
2021-11-30T21:43:38Z
0 likes, 0 repeats
@adeepa 90% are all criminal sites tho. Nothing of interest to me personally.Four main sites I useYoutubeDistrotootSoundcloudopenbsd.orgeverything else is sporadic at best π€·ββοΈ
(DIR) Post #ADwItqAJY14iELiwKG by rootbsd@distrotoot.com
2021-11-30T21:45:07Z
0 likes, 0 repeats
@adeepa 90% are all criminal sites tho. Nothing of interest to me personally.Five main sites I useYoutubeDistrotootSoundcloudgitlabopenbsd.orgeverything else is sporadic at best π€·ββοΈ
(DIR) Post #ADwIzuv6mZv0iMVcSu by 10leej@distrotoot.com
2021-11-30T21:46:12Z
0 likes, 0 repeats
@rootbsd That doesn't mean they don't keep connection logs in /var/log
(DIR) Post #ADwJ9FuQ7EOqPtdkHI by rootbsd@distrotoot.com
2021-11-30T21:47:54Z
0 likes, 0 repeats
@10leej So basically you would need to have both tor-browser and regular browser open at the same time to actually enjoy the internet and get more privacy?
(DIR) Post #ADwJxvcJJwpqFbKeGm by 10leej@distrotoot.com
2021-11-30T21:57:03Z
0 likes, 0 repeats
@rootbsd would seem so
(DIR) Post #ADwMWoDn0bVpMEcfD6 by anonymoose@fedi.club
2021-11-30T22:25:45.970785Z
0 likes, 0 repeats
@rootbsd @adeepa Then host something cool there. Be the change you want to see!
(DIR) Post #ADwNUhXKzWLg05KCfo by RTP@fosstodon.org
2021-11-30T22:36:34Z
0 likes, 0 repeats
@rootbsd @adeepa EX: You can watch youtube: as hidden service.Not everyone is going to care about privacy. But it is absolutely doable if it interests you.And there are ways to isolate accounts and other things.In my mind we don't know how the data/history w/be used in future.Goes deeper than today's social media background checks. Our data can lead to election interference, social movement manipulation, division.If interested in viewing YT as hidden service: https://politictech.wordpress.com/2021/08/17/howto-most-private-way-to-browse-twitter-youtube/
(DIR) Post #ADwO5K1zLbf1oV7jbU by RTP@fosstodon.org
2021-11-30T22:43:09Z
0 likes, 0 repeats
@rootbsd @adeepa At the least watch youtube/others selectively as a tor hidden service.I enjoy working on privacy. It's an interest/passion- a game. I enjoy studying it, researching, experimenting, writing new concepts/scriptsCorporations/ad companies track our foot movements (ex: Jenovice)& Journalists/activists really are targeted by pegasus, etc.Sure, some may take it "too far"... Like one guy who accused me because I recommended tor but NOT recompiling it from scratch. π€£
(DIR) Post #ADwOXqhFUXBDES1eNM by RTP@fosstodon.org
2021-11-30T22:48:19Z
0 likes, 0 repeats
@anonymoose @adeepa @rootbsd Tor hidden services aren't just about anonymity/privacy. There are amazing security benefits to hosting onions such as the end to end encryption between tor clients.Clearweb still vulnerable to MITM. One doesn't have to be a 'criminal' to become a victim. especially if compromise or PC preinstalled certs like 'Superfish'Not too difficult. While they are a pain to remember π started a little script to save the ones I use in terminal: http://gg6zxtreajiijztyy5g6bt5o6l3qu32nrg7eulyemlhxwwl6enk6ghad.onion/RightToPrivacy/onionmemory
(DIR) Post #ADwSDID2P8AwISLe8O by GreenLeaderFanClub@distrotoot.com
2021-11-30T23:29:28Z
0 likes, 0 repeats
@rootbsd what do you mean? You can use it for anything you don't want easily connected to your real identity. For example, if I was more worried about it, I'd only access mastodon via Tor. Plus there's all the .onion sites; some of those are quite interesting.I use TB regularly, but not, as you implied, for things whose risk I've accepted.
(DIR) Post #ADwSQ66QjAfeVtMa4O by rootbsd@distrotoot.com
2021-11-30T23:31:47Z
0 likes, 0 repeats
@RTP @anonymoose @adeepa Couple questions - do you log into mastodon over tor?Is logging into your regular services like email (protonmail, mastodon, soundcloud) a good idea because then there's identity correlation.Also the OpenBSD build of tor-browser is limited. Video playback in browser does not work except for youtube(ie Odysee & Invidious). But youtube denies access most of the time citing, "suspicious activity". And when youtube does let me play an embed link, no gpu acceleration.
(DIR) Post #ADwTszkfWG4nAUWmci by rootbsd@distrotoot.com
2021-11-30T23:48:12Z
0 likes, 0 repeats
@GreenLeaderFanClub @RTP Honestly I just need to get a new email since Ive gotten lazy and all my accounts are linked to one which is linked to my real identity.Do we have an email service we can trust or are they all compromised in some way?
(DIR) Post #ADwU4KySxFp6ArOEEK by RTP@fosstodon.org
2021-11-30T23:50:14Z
0 likes, 0 repeats
@rootbsd @anonymoose @adeepa I use Tor Browser for mastodon, since the day this account was started actually. Out of principle (I think fosstodon guys are trustworthy, but since I run my twitter inside tor browser, it's easier to mastodon as well.I have long used alias' online.But of course I have bank + real name/fam/friend contact accts. I simply use those in a dedicated different browser. Entirely different fingerprint this way. And manageable w/out much headache.
(DIR) Post #ADwUOl0hrXqmiQAtUG by james@distrotoot.com
2021-11-30T23:53:57Z
0 likes, 0 repeats
@rootbsd @GreenLeaderFanClub @RTP Host your own email. That's what I do, and I even use GPG!
(DIR) Post #ADwUW0QmvYV8ZKpYye by rootbsd@distrotoot.com
2021-11-30T23:55:15Z
0 likes, 0 repeats
@james @GreenLeaderFanClub @RTP Seems like a lot of work though πMy freetime is limited.
(DIR) Post #ADwUkfP7O4HFhO2Z4i by RTP@fosstodon.org
2021-11-30T23:57:41Z
0 likes, 0 repeats
@rootbsd @GreenLeaderFanClub But I have really no "need" for privacy outside belief that the more we give away, the more w/will be taken advantage of & worse things w/get w/data collection. give an inch they take a mile kind of thing.And it's used to emotionally manipulate.Personally use tutanota. Not because I think it's "fullproof" (no webmail is), but because the more ppl w/use encryption, the more w/add hay to the haystack. And that protects those w/need encryption.Just my thought.π
(DIR) Post #ADwVdVvcJsUgElOWlk by RTP@fosstodon.org
2021-12-01T00:07:49Z
0 likes, 0 repeats
@rootbsd @GreenLeaderFanClub W/it comes to email providers, I feel it's less about w/we use, more about who we don't use for personal email. π Gmail for example: every email is known scanned, sold for advertiser & w/ever else. Depending on usage, can give pretty good imprint of your mindset, strengths, weaknesses.Don't get me wrong I use gmail- for youtube & related. But personal email, I have others. Onionmail is nice too. :tor: I think important to keep things simple w/we can. :)
(DIR) Post #ADwW4IuIq9NbfgYQpE by GreenLeaderFanClub@distrotoot.com
2021-12-01T00:12:39Z
0 likes, 0 repeats
@rootbsd @RTP hosting your own is a PITA to do correctly. Who's your threat model? If you're worried about the US, go with a Russian provider. The other is compartmentalization. Think about what pieces of metadata about you, combined, would reveal too much and split them up to different providers.I still like protonmail, even after the oof with the French recently. You can access them via a hidden service and don't have to give them your real info.
(DIR) Post #ADwYyYQyUwVHx6mojI by RTP@fosstodon.org
2021-12-01T00:45:14Z
0 likes, 0 repeats
@rootbsd @anonymoose @adeepa Ah I understand limitations, running T420 from 2011ish. Some sites r heavy.But I enjoy doing w/I can.And can do most things.I do think you would like that addon I shared in my blog post (previous reply): 'privacy-redirect'Browser plugin automates front end redirection (including tor onions :tor: if installed on tor browser). You can hit 'off' anytime you need to login to youtube. it covers wiki, maps, twitter/YT & more.Great to have. :ablobcatneon:
(DIR) Post #ADwl0AGkVqC12FXOqW by rootbsd@distrotoot.com
2021-12-01T02:59:59Z
0 likes, 0 repeats
@RTP @anonymoose @adeepa No, I have a fast desktop PC too running OpenBSD, this is not a hardware limitation but a port limitation. Some features just dont work and the privacy-redirect is not implemented yet (the port maintainer is working on it for future releases?). My laptop is not my only machine, I own 9 computers.And believe it not my laptop can take a heavy load for as old as it (it just gets kinda hot).
(DIR) Post #ADwlIH1K9O7ZBbxRDM by rootbsd@distrotoot.com
2021-12-01T03:03:16Z
0 likes, 0 repeats
@GreenLeaderFanClub @RTP My threat model is zero, my viewers are more privacy minded so I trying to be open minded and learn this stuff for the channel. That protonmail account is linked to my real identity though. Maybe Ill start another tutanota account.
(DIR) Post #ADwwDDEbtgaXUcxfou by lethe@post.letsdecentralize.org
2021-12-01T04:00:38.668612Z
0 likes, 0 repeats
@rootbsd>90% are all criminal sites thoughyou sure? most of the ones I've seen are just personal pages. not to self-promote but I maintain a list on my site https://letsdecentralize.org/rollcall/tor.html@adeepa
(DIR) Post #ADwwDDsfUkdBUrhfG4 by rootbsd@distrotoot.com
2021-12-01T05:05:35Z
0 likes, 0 repeats
@lethe @adeepa When I went on a dark web directory listing of onion sites it was all shady shit, not free speech, privacy stuff. Maybe I was just looking in the wrong places π€·ββοΈ
(DIR) Post #ADwxt5PbTJuvLddO3E by 10leej@distrotoot.com
2021-12-01T05:24:23Z
0 likes, 0 repeats
@rootbsd well for the ultimate on privacy you want a hardened browser, a VPN and the toe browser.You use the VPN browser for anything you login to while you use tor for everything else.
(DIR) Post #ADx4HiQwdpX32wOBjE by adeepa@distrotoot.com
2021-12-01T06:36:03Z
0 likes, 0 repeats
@rootbsd @GreenLeaderFanClub @RTP honestly, you don't have many options to choose when you need an email not tied to the real identity. Tutanota is a good option. AFAIK, it's the only option. You won't find a good anonymous email service provider on tor land. Even if you found a one, chances are, almost all the clearnet services already marked that service provider as a spammer.
(DIR) Post #ADx4e1lfRCrXNhilXM by rootbsd@distrotoot.com
2021-12-01T06:40:05Z
0 likes, 0 repeats
@adeepa @GreenLeaderFanClub @RTP The issue is more due to my laziness over the past year that my real identity is linked with that email, which is linked with distrotoot, youtube, google, etc. I could fix this by setting up another email and migrating a lot of what I do to be connected to that email. While the old one can just be for IRL stuff.
(DIR) Post #ADx55qSV4vUmPn1JeS by adeepa@distrotoot.com
2021-12-01T06:45:07Z
0 likes, 0 repeats
@rootbsd @RTP @anonymoose I don't log into online accounts on tor and I don't see a reason to. You can hide the fact that you watch youtube videos from google but that's an overkill for me. You can maintain a completely seperate identity on tor (if you want to be an anonymous activist etc.). Tor is most of the times to much useful for typical users. Good VPN + hardened browser should work for the most cases if you enemy is the big tech.
(DIR) Post #ADx5ICPpGkV3zJezpY by anonymoose@fedi.club
2021-12-01T06:47:21.175177Z
0 likes, 0 repeats
@adeepa @rootbsd @RTP VPN is fighting the last battle against big tech. Tor is fighting the next one.
(DIR) Post #ADx5Y57o8wMC0fo0zw by rootbsd@distrotoot.com
2021-12-01T06:50:13Z
0 likes, 0 repeats
@adeepa @RTP @anonymoose Haha, some of the backlash to my rant video has got me thinking about these things. I personally don't care as much as some of my viewers. But I understand their concern and just want to be more open minded about the subject. I just want to come up with a good strategy for privacy + security w/ OpenBSD that's practical and doesn't take away from productivity too much. I thought I had one, but it's not good enough apparently. π I follow the K.I.S.S. philosophy.
(DIR) Post #ADx5wLQFCYkrVNzyXg by rootbsd@distrotoot.com
2021-12-01T06:54:36Z
0 likes, 0 repeats
@adeepa @RTP @anonymoose Apparently using Chromium is a no-no for privacy, but it's more secure than firefox, so it's a trade-off I suppose. Not everything is so black and white in this area, there are trade offs no matter what I do and someone will always find a criticism. That was kinda the gist of the first half of my rant.
(DIR) Post #ADx6NPX025CG4G442K by anonymoose@fedi.club
2021-12-01T06:59:29.924053Z
1 likes, 2 repeats
@rootbsd @adeepa @RTP to be clear, I donβt object to you not using tor if it doesnβt suite your use-case. I just take issue with the idea that it has no value because itβs useful to criminals. Soon many people with wrong opinions or no 5th booster shot will be happy someone was building and maintaining that infrastructure.
(DIR) Post #ADxIAwFqFvcTF5rHe4 by RTP@fosstodon.org
2021-12-01T09:11:41Z
0 likes, 0 repeats
@rootbsd @adeepa @anonymoose Unfortunately I'd think OpenBSD's commonly heard "reputation for security" would attract critical viewers no matter what tbh. I'd ignore them as we never can please everyone.And some people will give all channels a hard time.I say use what works well on OpenBSD, what runs well. π
(DIR) Post #ADxILH0PxT9WUsZW64 by rootbsd@distrotoot.com
2021-12-01T09:13:34Z
0 likes, 0 repeats
@RTP @adeepa @anonymoose Thanks man! I just found your channel and blog, very cool stuff. π
(DIR) Post #ADxLAUj0uSQhivz1Gq by RTP@fosstodon.org
2021-12-01T09:45:13Z
0 likes, 0 repeats
@rootbsd Thank you! π