Shelly also has static analysis for AUR packages that looks for all the common, shifty ways a pkgbuild might try to give you something bad.
HN user
Caboose8685
To clarify, the packages in the CachyOS repo from the AUR are manually reviewed by a team member before inclusion and updates.
CachyOS takes the default arch repos and re-builds packages targeting CPU generations and their instruction sets. There are no proprietary repos. Cachy has their own personal repo where some packages not in arch repos are built.
Gaming stuff is NOT installed by default, but there is a button in the Hello app new users can click that installs 2 meta packages that install almost everything one might want for gaming. Take a look at it in a VM and see for yourself.
The performance increases from their kernel + optimized packages are small but noticeable to me. Give their wiki a read-through: https://wiki.cachyos.org/
The silk road guy was got on conspiracy for attempting murder and not drug or human trafficking charges
Actually, the murder stuff was not part of his sentencing or what they tried him for.
A system where the whole populace votes on everything isn't the only kind of democracy. The US is a representative democracy.
I mean just read through the link above. You'll find no exemption for personal use when it involves bypassing DRM. Which I don't think any DVD or blu-ray anymore lacks.
I'm also reasonably sure that "3. Proposed Class 6: Audiovisual Works—Space-Shifting" in the above link would cover personal archival and that was explicitly rejected.
Don't get me wrong, I'm still all for it, but it's not permitted anymore like it used to be.
Unfortunately not. The exemption dropped some years ago.
Personal archival isn't exempt anymore, that dropped some years ago. The only archival exemption now is for "qualifying institutions".
FWIW, I've been using an Omada switch and 2 APs for over a year with the controller in a docker container without any issues. I have preferred OPNSense as my router/firewall for years and it works well for me with omada gear.
Could potentially Faraday cage it if you can find the exact spot it's at.
I wholly agree with your sentiment, but as someone who cares to actually take action for my privacy this kind of onerousness is par for the course, unfortunately.
I think an argument should be made against normalizing this, which could then lead to OEMs building in internet assisted data export functionality in new cars and people won't know until a lawsuit (likely) starts years after the fact and the harm is done.
Bitwarden is fantastic IMO, vaultwarden if you like to self host.
Out of an abundance of caution, it would be prudent to change the passwords for the most critical accounts in your life initially. Things like your bank, email, Google. Accounts that losing control of would immediately make you go "oh shit, I can't do X that I need for daily life". Then slowly over time change the less critical ones.
That's possible, but those services most likely offer another form of 2FA. Getting away from using SMS 2FA everywhere you can is best.
Consider porting the number to something like Google voice or jmp.chat and get a random number you don't care about for your SIM.
This isn't really true last I checked. They merely make their testing repo, what's effectively in line with normal arch release, available for 2 weeks then rely on someone telling them something is wrong in their forum. They don't do much, if any, testing themselves.
I rented one for a while and it was far better than 'not great'. Only downside really was the noise from the air circulator located inside, otherwise it was pretty much a normal 3 bed 2 bath small home.
I highly recommend Neo Store. It's a drop-in replacement for f-droid that leverages the newer Android API for seamless updates. Been using it for months happily.
SMB signing is only on by default for servers. I've done quite a few pentests where that's been leveraged to dump the SAM hashes of workstations that happen to have the Domain admin stored.
I moved from lastpass to bitwarden about 2 years ago, then to self hosting vaultwarden about 6 months ago. Bitwarden wasn't as feature-full as lastpass at the time, but I liked it a lot. My father was using lastpass in the meantime and I saw it devolve into an unpleasant mess UX wise and these days, ignoring the elephant of the hack, am confident bitwarden is a much better experience overall compared to lastpass.
Not only phishing, but too many people have the terrible habit of using the same password everywhere. So with public breach data, it's not a stretch to think bad actors would try, and probably be successful way too often, to use said credentials on bank sites.
Graphene certainly looks impressive by all accounts, but are there any 3rd party audits? I can't find any.
I've learned to expect that from FOSS software that has any kind of security claims and purports to help me be more private or secure. Particularly since I don't have the necessary skills/knowledge to do so myself.
Free doesn't mean cost.
Did you try Ravio OTP? I've seen good things said about it by FOSS people.
It's worth noting that UGC has some significant security regressions
On the flip side, this process can be abused by people who don't actually intend on leaving to get better rates/prices. I've done it a few times over the years to deal with rising costs of an ISP when I don't have any good competitor to actually switch to.
It should be fairly obvious that I'm referring to the institution of journalism as a whole.
Motherboard has not independently verified the letter
This _should_ be a basic requirement before releasing a story. No wonder institutional trust is so low.
That's odd, I've been using cryptomator on arch for like 2 years now with no issue.
Where is this stated in their rules or whatever? Something I can reference if I need to try this and the person pushes back.