Live data from Hacker News

On privacy and control

toidiu.com

121–130 of 132 posts

Re: On privacy and control

#121
post #113

Earlier quoted context omitted.

> how it actually lowers Android's security, especially compared to desktop OSes that are usually rooted, like Linux or MacOS Mobile OSes are notoriously more secure than desktop ones, precisel because of the security model.

Okay, but could you give me some examples? How is Android or iOS more secure than Linux or Qubes?

Android/iOS do sandbox user apps by default, for instance. When you run a script on Linux, it has access to everything your user has.

Access control is also more advanced, e.g. apps need to request permissions to the user. Not saying that desktop OSes are not making progress, but they are behind.

I don't know if Qubes qualifies here. Qubes runs Linux instances in VMs to compartmentalise them, but then each Linux instance has the Linux security model.

Re: On privacy and control

#122

> I use Cloudflare's DNS because I trust them more than other companies; purely based on their business and how their incentives align The author fails to mention that they are currently working at Cloudflare, I think that should be made clear otherwise I see it as misleading to the reader, like so many pointed it out, Cloudflare is just a corporation like any other corporation out there...

Thank you for reading!

I had the disclaimer in the Domain section but also added it to the DNS section, along with a list of other DNS providers folks can choose to use instead.

Re: On privacy and control

#123

For you - WhatsApp is an exception For others - Google is an exception

I agree and its unfortunate that there i. For a long time I went without WhatsApp but realized that connecting to family was more important to me. I don't have a good alternative for this one.

Re: On privacy and control

#124

The only thorn in the opine is Cloudflare. Everything looks reasonable but CF. I get that DNS is free, it is OP's employer and registry being offered sans margin but it doesn't make up for the fact that CF is on its way to become the biggest gatekeeper and strangle the freenet if it wishes to do so.

Thank you for reading!

I added a disclaimer to the DNS section along with a list of other DNS providers folks can choose to use instead.

I made these choices before I was employed by Cloudflare and personally like how transparently they operate as a company. They have earned my trust but I don't expect others to feel the same way.

Re: On privacy and control

#125
post #9

Agree that "control" is a much better framing, since it doesn't suggest a need for secrecy and therefore embarrassing/unacceptable/untoward behavior that needs to stay behind drawn window blinds. I'm also fond of "agency" and "digital self-sovereignty" as alternatives. But fine, I'll be the one to say it: Cloudflare isn't one of the good guys here and as an entity it shouldn't be trusted. It doesn't matter how pure t…

Thank you for reading!

I added a disclaimer to the DNS section along with a list of other DNS providers folks can choose to use instead.

I made these choices before I was employed by Cloudflare and personally like how transparently they operate as a company. They have earned my trust but I don't expect others to feel the same way.

Re: On privacy and control

#126

I agree. Keeping your data private is just not a big enough motivation. For me though the big issue is making sure one keeps access to their data forever. It’s so easy these days to use everything from one vendor and then get access shut off with no recourse. That is IMO the biggest fear everyone should have these days. Yes, the only solution is self-hosting and yes it requires being your own sysadmin and it’s hard a…

Hey, I remember seeing this like two years ago when researching Nixarr. Glad to see others focusing on NixOS for self-hosting stuff. I need to look into it again properly when I have time.

Re: On privacy and control

#127

Earlier quoted context omitted.

That example of Ford knownig you're speeding wouldn't change their mind. In fact I'm not sure it I have a problem with it. You already need a license to drive. Given how bad drivers are getting I actually feel like I wish all cars were tracked and tickets given out. Bad driving risks other people's lives. On the other hand, it's likely the traffic violations will go down as self driving car usage increased. Though of…

If you are trying to convince people to care about their privacy etc, you’re doing a lousy job. They also know when you’re having sex in the car, but I didn’t mention it out of politeness.

HN has already voted even they don't care. The majorty were happy they could have sex in Waymos and downvoted anyone who thought that was not ok.

But that still wouldn't convince my family. None of them are having sex in cars.

Re: On privacy and control

#128

Earlier quoted context omitted.

If you are trying to convince people to care about their privacy etc, you’re doing a lousy job. They also know when you’re having sex in the car, but I didn’t mention it out of politeness.

HN has already voted even they don't care. The majorty were happy they could have sex in Waymos and downvoted anyone who thought that was not ok. But that still wouldn't convince my family. None of them are having sex in cars.

Just an example. "I don't care about the Bill of Rights, because I'm not doing any of those things." Sadly, not an uncommon take. But one day you'll realize how wrong it was, and you had power to push back.

Re: On privacy and control

#130
post #121

Earlier quoted context omitted.

Okay, but could you give me some examples? How is Android or iOS more secure than Linux or Qubes?

Android/iOS do sandbox user apps by default, for instance. When you run a script on Linux, it has access to everything your user has. Access control is also more advanced, e.g. apps need to request permissions to the user. Not saying that desktop OSes are not making progress, but they are behind. I don't know if Qubes qualifies here. Qubes runs Linux instances in VMs to compartmentalise them, but then each Linux inst…

I agree with the sandboxing and permissions points, but is that related to the OS not being rooted? This is a genuine question - I'm not trying to make a point here, but to learn.

I think Qubes qualifies from a practical point of view, as modern hardware is powerful enough for it, so it's viable to run Qubes on desktop instead of a baremetal OS. I'd even go further and say there's no excuse not to run Qubes if you're familiar with Linux and can afford a compatible desktop or laptop.

Per-app sandboxing or per-OS compartmentalization is pretty similar with regards to security. There are some security and usability trade-offs, but I like the per-OS isolation model, as it's easier for several apps to share everything within a VM - that way you isolate a whole "project" more easily, as everything inside a VM is only related to that project and you assume all the apps would need access, anyway.

Post reply on HN