Agree. Peoples are trusting App with unknown source code & delivery path, infrastructure controlled by 3rd party. Application cannot protect against OS and OS cannot protect against HW. Too many known unknowns. Seek the arguments how and why OTF got re-funded last time.
HN user
exfil
Where you connect to your "cash obtained" VPN? That IP has your name on it.
You cannot offer service for money with user anonymity. Your legal knows that.
Yes. But your cash gets attributed by your origin IP address. Which you pay with your identity available.
These VPN's for privacy are so bad. You give your credit card (verified identity), default gateway and payload to foreign soil and feel safe. On top of that your packets clear text metadata verifies you with cryptographic accuracy.
In today's internet you just cannot have exit IP which is not tied either into your identity, payment information or physical location. And don't even mention TOR, pls.
Add backup and out-of-band communication into your portfolio and you're good.
I am happy that my project is pushed also to codeberg.
Yes. They use them like that.
I run my RPi's 24/7 from initramfs. I can even remove card after boot.
"Don't roll your own crypto..."
It's not 'Linux Phone' problem.
Problem is that Cellular is most surveilled domain in the world.
You're right. Probably pricing is justified. Just hate to give email details for login.
When I see 'pricing' on top of page and sign on requiring email & password, it's better to close tab.
Part of the 3GPP standardization process is to ensure law enforcement stays efficient. So this IMSI change is totally futile. Sorry guys. If that 'co-founder' wants to speak, dm.
I have macsec (L2) separation for my dev hosts and out-of-band keying with Nitrokeys. So lateral movement in my LAN cannot reach my dev station on IP level. Don't trust my router (zyxel) Chinese firmware.
What would be best way to evaluate randomness quality? This is something I've been thinking a lot. Yes, there are 'ent' and others, but I am more after trend of randomness quality over weeks and months.
I really would like to see Syncthing which is not built using Go. Plain C implementation would be more usable in various environments.
Most of the nations have global TLS transparency solution in place. And CA's sign those intercept certificates by law.