N0x0n

@N0x0n@lemmy.ml

This profile is from a federated server and may be incomplete. Browse more on the original instance.

N0x0n, (edited )

Hey :) may I suggest rethinkDNS to have a more granular control over your installed application? Also it’s possible to block everything except the apps you trust while still being able to use your own DNS/wireguard VPN/proxy…

Also If you want a more in depth overview of every connection your phone attempts to make, give Pcapdroid a try !

N0x0n, (edited )

Hey :)

Wait, I thought the “downside” of this app was that it used your VPN connection.

https://lemmy.ml/pictrs/image/da00e95d-744e-44a1-9cdd-4f13a46164aa.jpeg

It does, but if you have a VPN that let’s you send your traffic through wireguard (like protonVPN, don’t know about others :/) it will send all your traffic through that tunnel.

https://lemmy.ml/pictrs/image/09b06a1e-ea08-4205-8c68-9214a591a35c.jpeg

Also, there was a recent update which uses your wireguard’s DNS instead of rethink’s hardcoded internal DNS. That was the awaited updated I needed to fully switch to rethinkDNS.

There are still some quirks in the interface and a few strange behavior with wireguard when waking the phone up, but nothing that causes leaks in my experience, because if my wireguard tunnel isn’t working rethink isn’t able to make any requests !

Hope it helps :).

N0x0n,

Same here 👋 still i’m a bit sad I had to move on from VLC… It was always one of the first software I would install on my setup… But that was mostly on windows.

On linux/macos, MVP seems to work way better. I’m very thankfull for all these years of service, but everything has an end and like ICQ ended recently, VLC will probably die off in a few years…

Except if they make a come back? Who knows !

Do you have a more complicated shell history scheme than the distro default?

I’ve used distrobox more and more and am at the point where I need to start saving and integrating history differently. Or like, when I’m installing and building something complicated, I need to start saving that specific session’s history. I am curious what others might be doing and looking for simple advice and ideas.

N0x0n, (edited )

Genuine question, I see alot of people concerned by losing their shell history, any specific reason why?

I mean I keep mine to default and auto-delete every shell history after logout :/ And I never seemed bothered, I never go up more than 10 lines anyway… Whats the point/use case of keeping a whole shell history over time?

I deleted my Google account…

… And damm it feels good! Before starting this step, I had to migrate to a better browser that respects privacy (Brave, because🖕Firefox, I mean Mozilla at this point doesn’t even want you to be safe on the web anymore!) And a better “Google-style” ecosystem (Proton is the best they have an email service, a calendar, a...

N0x0n,

More importantly though, Mozilla has a female chairwoman. A lot of tech savvy people would rather stick with Brave, whose CEO they can relate to.

Woaw… If that’s a thing, I really feel sorry for them :/

N0x0n, (edited )

That’s not the point, eat what ever you think is good for you. We are not going into arguments that’s out of context. That was just an example out of my memory on how they pass things without our consent or when they see any benefit for their own agenda not for the common good. (Still personal opinion, think whatever you want)

But whatever… I’m just a random on the net 🤷

N0x0n, (edited )

👍✌️

Edit:

I shoud have left that part out:

So right now we will propably have meat and vegetables full of GMO’s, pesticides, and meat fully loaded with antibiotics, vaccines…

That’s was maybe a too personal opinion were the conversation can easily get heated quickly (where ever your stand is on that subject) and is out of the scope of the actual post !

So sorry about that :/.

N0x0n,

Hummm, does TTIP and CETA rings a bell? If not, let’s just say that during the covid pendamic the EU parliments signed CETA behind ours backs allowing transporting good between canada and EU. Sure TTIP itself was not signed (yeahhhi thats a win… Or not?)

But that doesn’t matter because the only thing they wanted was a trade deal with the American continent It’s TTIP with extra steps…

So right now we will propably have meat and vegetables full of GMO’s, pesticides, and meat fully loaded with antibiotics, vaccines…

So If I where you I wouldn’t count to much on

“They look like they want change, and they then blame too many votes on “not themselves” that it didn’t pass.”

They wan’t changes when it benefits them and their agenda ^^.

Is it safe to open a forgejo git ssh port in my router?

Hello all! Yesterday I started hosting forgejo, and in order to clone repos outside my home network through ssh://, I seem to need to open a port for it in my router. Is that safe to do? I can’t use a vpn because I am sharing this with a friend. Here’s a sample docker compose file:...

N0x0n,

You’re right, but only if you are an experienced IT guy in enteprise environnement. Most users (myself included) on Lemmy do not have the necessary skills/hardware to properly configure and protect their networking system, thats way I consider something like wireguard way more secure than opening an SSH port.

Sure SSH key based configuration is also doing a great job but there is way more error prone configuration with an SSH connection than a wireguard tunnel.

N0x0n,

Opening ports on your router is never safe ! There’re alot of bots trying to bruteforce opening ports on the web (specially ssh port 22)

With SSH I would disable the password authentication a only used key based authentication. Also disable root access. (Don’t know how it works with forgero though)

I would recommend something like wireguard, you still need to open a port on your router, but as long as they don’t have your private key, they can’t bruteforce it. (You can even share the wireguard tunnel with your friend :))

Also use a reverse proxy with your docker containers.

There are a lot of things you could do to secure everything, but If you relatively new to selfhosting, there’s a steep learning curve and a lot of time needed to properly secure everthing up. You could be safe by doing nothing for a few months but as soon as someone got into your system, you’re fucked !

But don’t discourage yourself, selfhosting is fun !

N0x0n, (edited )

I will just answer that question even though it doesn’t make sense because we are in this shit together…

We wouldn’t have to treat cancer if we haven’t been so stupid in the past… Back to the roots with less plutonium, uranium, 4G, 5G, wifi 4,5,6, processed food, poluted water… You name it !

Maybe it’s time to find a solution for the root cause and not a solution for the symptoms…

That’s the difference !

N0x0n, (edited )

If humans would treat nature and themself better we wouldn’t need any “beauty” products or even any medication in the first place. Just to artificially look “better” or live longer?

Everything that happens to us, is because our own selfishness ego to think we are the “alpha” product who owns everything, while we are just dumpshit animals with no respect for nothing.

You wan’t to test some product? Go test it on criminals and leave those poor animals alone. But no, testing on non volunteer human is not ethical correct??

Oh yeah that’s where we draw the line.

N0x0n,

Never got into TF2 was more a day of defeat guy (what a banger !!). But still doing my part !

N0x0n,

Is this because I am using a free tier VPN? so it’s not functioning properly etc…

Nope ! I use the free tier on all my devices and nothing is leaked based on all tests I did.

If you are on linux you need to check your /etc/resolv.conf and see if your home’s router/ISP DNS is in there.

Check also if networkManager hasn’t your ISP’s dns configured.

There are other locations where your home router’s DNS could be hidden on linux after a DHCP configuration.

If it’s on windows :/ sorry can’t help there.

N0x0n,

That’s right !!! That was just a starting point for OP if he was on Linux and lacking that info I gave him just some pointer where to look at.

Anyway, most of the time it gets overwritten from other configuration files, nothing harmful. He could even have resolvconf installed on his system, who knows.

N0x0n,

Long time I haven’t booted into windows, so can’t help there.

But rest assured that the free tier hides your real IP the same way as the paied tier.

N0x0n,

Linkding is great ! I love it ! With the new local copy as html file thats a banger !!

Except one thing I hate about it… It can get really messy quickly If you don’t overthink your tags… This can get time consuming in the long run !

N0x0n,

Hey :) would you kindly share your tagging methodology? It’s the second time I nuke my linkding docker istance, because everytime it gets so messy that I lose sight of my bookmarks ://

Thank you 👐

N0x0n,

That’s a nice workflow :) except for KOReader, I do the same combo Miniflux + wallabage + linkding.

Wallabag + miniflux for articles to read and Linkding for important stuff (mostly github stuff).

What’s cool about that workflow it can be automatically send through each other with their API.

N0x0n, (edited )

Not OP, but thanks for the write up !

Regarding macvlan’s with docker, I tried to use them in the past and while I liked the idea of having every container on it’s own mac /ip address in the home network space, I couldn’t get the host to communicate directly with them.

Everyone on the LAN could talk to my containers, except the host itself. IIRC there was/is some tricky part where you have to change the default route and create new iptables to make it work that way, but It seemed rather hacky and not secure at all.

Now that I’m a bit more experienced with docker and all, do you know if this is possible or still one of the downside of macvlan’s?

Edit: reference. I see he updated his post in 2023, maybe worth a new shot !!

N0x0n,

I’m not able to copy/past my changes from my phone’s about:config but here is a great tutorial and most of the parameters I changed:

wiki.archlinux.org/title/Firefox/Privacy

Keep in mind that to use about:config on mobile phone you have to use the beta, dev or nightly version of firefox.

Also this could and will break some sites, I don’t know how much you want to harden your firefox but here are the addons I use with Firefox:

+AdGuard home at the DNS level.

You can test all your changes on: browserleaks.com

  • All
  • Subscribed
  • Moderated
  • Favorites
  • anitta
  • thenastyranch
  • magazineikmin
  • everett
  • InstantRegret
  • rosin
  • Youngstown
  • slotface
  • love
  • khanakhh
  • kavyap
  • tacticalgear
  • GTA5RPClips
  • DreamBathrooms
  • megavids
  • modclub
  • mdbf
  • tester
  • Durango
  • ethstaker
  • osvaldo12
  • cubers
  • ngwrru68w68
  • provamag3
  • normalnudes
  • Leos
  • cisconetworking
  • JUstTest
  • All magazines