• 48 Posts
  • 80 Comments
Joined 1 year ago
cake
Cake day: September 29th, 2025

help-circle


  • Start here to get an overview of advantages. It misses some factors, so I also suggest this thread.

    I want to stress the idea of taking load off the exit nodes – which the first link to torproject misses. It not only directly improves the speed for users of the repo, it also gives a better balance to the whole Tor network.

    The reddit thread is decent enough to share but I have to correct something: someone said “Onion services are about protecting the server rather than the user.” They neglected to realise that using an exit node potentially exposes users to DNS leaks. Onion links are immune to DNS leaks and DNS shenanigans (recent events with Autistici being an example of DNS creating vulnerability to bad actors like one particular orange menace).

    The linked sources are a good start but they miss some other factors:

    • Promotion of Tor. The Tor community is severely marginalised because it’s small. Small groups are easy to oppress. Tor needs promotion. Onion links help promote Tor by increasing awareness.
    • The clearnet is under constant attack including burdens added by Microsoft’s copilot and AI bots. The clearnet is generally quite enshitified in part due to self-defense measures. Onion sites tend to not need (and not deploy) the extent of full-blown defensive posture that makes the clearnet UX shit.
    • MS Copilot is probably not harvesting onion forges. Which means the clearnet variant could easily be hardened against it by (e.g.) bluntly blocking all MS IPs, as the onion would still be reachable to humans that have an MS IP for some reason.
    • An onion site /can/ optionally be implemented as a fully redundant server, so when the clearnet host goes down the onion continues offering availability. Two benefits: increased availability and also promotes Tor when it happens. (Not sure if gitea/forgejo or gitlab is better in that config).






















  • I will say I find it interesting you are calling my use of mildlyinfuriating@lemmy.world as not being open/the problem, but isn’t the isolation (setting as private) infosec.pub more of a walled-garden and less open?

    Infosec.pub is not making a value judgement that permanently discriminates against demographics of people. It’s the difference between an oppressive US corporation arbitrarily systemically singling out groups for marginalisation to save a buck for the corporate as it bullies over 30% of the world’s web territory, and a small charitable volunteer instance with limited resources doing what is necessary to protect itself from an onslaught of attacks.

    I can freely share the link of the community post I made even if it is hosted through cloudfare.

    Of course. You can share Facebook links too. And those who are in the excluded groups will just waste their time on an unusable link. If you are going to be a pragmatist and not give shit about politics, it’s unclear why you are in the fedi as opposed to Twitter and Facebook.

    I imagine mildlyinfuriating@thelemmy.club didn’t exist when I subscribed to lemmy.worlds community or maybe there were only 3 people in it. Surely the expectation is not to keep monitoring all my communities and check if a better version of said community pops up.

    Subscribing is about /reading/, not /writing/. When deciding where to post, I often search communities because it’s a changing landscape with new communities emerging daily. Moderately advanced folks would do that by visiting lemmyverse.net which happens to have a filter you can use to filter out Cloudflare instances. I personally use a script instead which queries on lemmyverse’s dataset. If I were to make a post as you did, I would search the terms: infuri shitif shittif asshol dark%pattern (each token is an SQL “like” query surrounded with wildcards). So that gives:

    🏰zerobytes.monster🌩|amitheasshole “Am I the Asshole?”
    🏰zerobytes.monster🌩|assholegonewild “Gone Wild; Asshole Style”
    🏰zerobytes.monster🌩|mildlyinfuriating “jukmifgguggh”
    🏰pawb.social🌩|AITA “Am I The Asshole?”
    🏰lemmynsfw.com🌩|asshole “Asshole”
    🏰lemmynsfw.com🌩|assholebehindthong “Asshole Behind Thong”
    🏰lemmynsfw.com🌩|godasshole “GodAsshole”
    🏰lemmynsfw.com🌩|pulsatingasshole “Pulsating Assholes”
    🏰lemmy.world🌩|actually_infuriating “Actually Infuriating”
    🏰lemmy.world🌩|aitah “AmITheAsshole”
    🏰lemmy.world🌩|amitheasshole “Am I the Asshole”
    🏰lemmy.world🌩|asshole “asshole”
    🏰lemmy.world🌩|assholebehindthong “Asshole Behind Thong”
    🏰lemmy.world🌩|assholedesign “AssholeDesign”
    🏰lemmy.world🌩|assholegonewild “Asshole Gone Wild”
    🏰lemmy.world🌩|assholegw “Asshole Gone Wild”
    🏰lemmy.world🌩|bassholes “bassholes”
    🏰lemmy.world🌩|darkpatterns “darkpatterns”
    🏰lemmy.world🌩|enshittification “Enshittification”
    🏰lemmy.world🌩|enshittify “Enshittification”
    🏰lemmy.world🌩|godasshole “godasshole”
    🏰lemmy.world🌩|mildlyinfuriating “Mildly Infuriating”
    🏰lemmy.world🌩|mildyinfuriating “mildy infuriating”
    🏰lemmy.world🌩|notinfuriating “Not Infuriating”
    🏰lemmy.world🌩|qualia “Qualia: Living Ad-Free and Breaking Away from Dark Patterns, Hidden Fees, and More”
    🏰lemmit.online🌩|AmItheAsshole “Am I the Asshole?”
    🏰lemm.ee🌩|amitheasshole
    🏰sh.itjust.works🌩|amitheasshole
    🏰sh.itjust.works🌩|furiouslyinfuriating
    ↑ Kingdoms under the imperial Cloudflare empire ↑

    ⚠lemmy.ml/c/aita “Am I the Asshole?”
    ⚠lemmy.ml/c/assholedesign “Asshole Design”
    ⚠lemmy.ml/c/mildlyinfuriating “Mildly Infuriating”
    ⚠lemmy.ca/c/amitheasshole “AITAH?”
    🥧 fedinsfw.app/gaping_assholes “Gape”
    🧺 thebrainbin.org/deshittification “Deshittification”
    🗽☯ thelemmy.club/c/Mildlyinfuriating (39/0) “Mildlyinfuriating”
    🗽☯ discuss.tchncs.de/c/amitheasshole (125/1) “Am I the Asshole? ”
    🗽☯ sopuli.xyz/c/enshitification (40/2) “enshitification (not only enshittification)”
    🗽☯ infosec.pub/c/assholedesign_web (92/5) “Asshole Design (web edition)”
    🗽☯ slrpnk.net/c/asshole_crappy_design (49/12) “Asshole Design and Crappy Design”
    🗽☯ slrpnk.net/c/enshitification (942/710) “Enshittification”
    🗽☯ lemmy.cafe/c/disenshittify (147/37) “Disenshittify”

    It lists the shitty Cloudflare places first because those are the least interesting and tend to scroll off the terminal screen. Then it lists non-CF nodes that are still centralised due to their sheer disproportionate size which is indicated with a “⚠”. The “🥧” means piefed and “🧺” means kbin (which the db unfortunately has no Cloudflare flags for, thus ethics is a crapshoot and needs a deeper look). Finally, it lists known open free world places using “🗽☯” to indicate freedom and balance. The paranthesis indicate (subscriber count / active users in a month) to give an idea of activity. Those who realise this decision is inherently political and who want to promote an open free world would choose one of the last 7 in the list. I will sometimes choose the /least/ active among them and then crosspost from there so subscribers in the more active groups can see that another interesting group exists – thus encouraging subscriptions that help improve the balance. Of course in the case at hand, we know infosec.pub is closed as it is under attack, so it would not be a good link to share.

    Also, as an end user that is on Lemmy because I want a non techbro place to read news topics/share crap going on when appropriate

    You can of course choose to be low-tech if you want, but you should know your bubble will be shaped by others on your node. The in-app search on the instance is limited in scope to content and communities based on subscriptions of others on your node.

    If you want to expand your bubble help shape it, it’s useful to grok lemmyverse. I block Cloudflare nodes in my settings and I subscribe only to free world communities (“🗽☯”) to do my part in shaping the bubble for a more balanced decentralised space with minimal boot-licking.

    W.r.t. “non techbro place”, I guess you mean to refer to a place that is not for tech experts. It’s worth noting that many read “techbro” as “tech millionaires”, such as the CEO of Cloudflare, Twitter, etc.

    , like yesterday this type of stuff explains very clearly why Lemmy is and will continue to be a ghost town in comparison.

    Lemmy is not a single town. It’s a vast collection of many towns and a good number of those towns are ghost towns. Network effect is a global problem that Lemmy /tried/ and failed to correct. The devs simply assumed that having a federation of instances would automatically counter network effect. There are several oversights and defects in the software which actually exacerbate network effect.

    Lemmy certainly needs to improve but I doubt it will make much headway. It’s more likely that a different software package will emerge one day that fends off walled gardens and network effect.

    The barrier to entry/understanding is up there which is not welcoming imho.

    The dumb users pile onto the Cloudflare nodes. I doubt the tech is too over their heads to give a bad UX. The refined sophisticated users avoid the centralised instances and their understanding improves. The fact that there is more to learn does not create a “barrier to entry” AFAICT. You can get started and function without understanding the evils of Cloudflare and centralisation. You can make adjustments as your knowledge and wisdom improves.


  • I lost the link but the research was done by: Douglas J. Leith, School of Computer Science & Statistics, Trinity College Dublin, Ireland, 25th March, 2021 in a paper titled “Mobile Handset Privacy: Measuring The Data iOS and Android Send to Apple And Google”.

    Every Android device owner is a Google spy. Every iOS device owner is an Apple spy. They don’t know it, generally. Android and iOS devices constantly¹ harvest the radio data of their surroundings and they send the data home to their respective mothership. This is hard-wired into the platforms and has nothing todo with accounts. An arbitrary person randomly walks/drives by your house with their iPhone or android powered on, and it collects your SSID, MAC, GPS position, etc and sends it to Google or Apple, unwittingly, because people are oblivious as to what’s going on.

    ¹ The phone user may need to have location services enabled for the phoning-home to occur… not sure if turning on location services enables the data sharing in both directions or just one. Guess I need to re-read the research.





  • Normally I would say the best link for sharing is that of the host for the community, not the host of your account. But in this case you posted in Lemmy.world, which is jailed in the exclusive walled-garden of Cloudflare™. I highly suggest not posting in Cloudflare. It’s a centralized walled garden by an oppressive US-based tech giant. Might as well use Facebook at that point.

    There is one open free-world “Mildlyinfuriating” community: !Mildlyinfuriating@thelemmy.club. I suggest posting there first, and then share that link. If you cannot stomach the idea of less reach/engagement or cannot resist the urge to use LW, at least make your first post in the free world and crosspost into the walled gardens so the ignorant walled-gardeners at least learn about the existence of free world communities.

    Now to answer your question, the infosec.pub admin is also the fedia.io admin. This post could¹ give some insight:

    https://fedia.io/m/fedia/t/2188602/Fedia-io-performance-issues-and-blocking-anonymous-access

    That is, anonymous access to infosec.pub could have been blocked for the same sort of reason.

    ¹ But you may need to create an account on fedia.io to read that… LOL.

    copy of linked post

    Hi all. Fedia.io has for a long time been subject to ddos attacks, including many that are “accidental”, caused by myriad scrapers constantly hammering the site. I gave up on trying to play whack-a-mole with blocking them based on IP address (they do not honor robots.txt and do not use a conspicuous user agent string) since I was inadvertently blocking some legitimate users. So, I’ve restricted access to the content of fedia.io to only those that are logged in. That will mean we don’t show up in search engines and whatnot, which for some will considered a good thing and will likely cause others to leave.

    There is a remaining problem related to the login form. Calls to the login page are breathtakingly expensive, computationally speaking, and so I also have a script that monitors unusual numbers of calls to that form and blocks at the firewall any offenders. I strongly suspect I’m catching some legitimate users with this too, and so I continue to try to tune it, but it’s maddening, y’all.

    These issues have been causing performance problems for everyone (despite the fedia.io app running on a dedicated 96 core, 256GB server with nvme disks), and became unavailable for certain people that accidentally tripped various thresholds. I’m hoping most of this is resolved now.

    Thanks for the patience.

    update

    Found this: https://infosec.pub/post/45546187

    I erroneously assumed you would have already looked in !infosecpub@infosec.pub so I did not initially look myself.


  • I’m glad that opting out is available, but there is no practical, technical enforcement.

    What sort of technologically-enforced mechanism might you envision that does not rely on legal enforcement?

    Lately I practice the only tech-enforced option I know of: wholly pull the plug on wi-fi. Indeed, this means I only have ethernet in my house and wifi radios are disabled. It also means for my smartphone to reach the cloud, I am reverse tethering over USB. Try getting a crowd of people to do that. I will praise you if you can get 10 people to do that.

    There is such a thing as bluetooth routers. So a middle ground would be to pull the plug on wi-fi and use bluetooth instead. Though it’s a compromise because we cannot¹ be certain that Google does not also harvest bluetooth. But at least the limited range would mean fewer cases where the signal reaches the street. Of course you would have to be okay with the slower speed.

    If Google violates their own policy, it’s legally actionable. So if you are going to run wi-fi you can do your part in helping grow the legal liability that Google has signed up for. I see no good excuse for not appending _nomap to the end of your SSID. It’s just pure lazyness not to.

    ¹ well strictly speaking, we might know from the location data whether Google uses bluetooth. But if it’s not part of the location data it would not be an absolute indicator that it’s not collected.



  • They are microprocessors embedded within the microprocessor. Intel’s IME enables remote access (by intel’s own admission). If you are not a corporation who manages a fleet of machines, the backdoor can only be used against you. AMD’s variant called the PSP is similar but closed-source. We don’t really have a complete picture of the extent of the compromise with AMD because of the opacity of it (as AMD proactively denied a request for source code). What we don’t know /can/ hurt us, as we already got stung by a defective driver for the AMD’s PSP.

    Even if the spychips were to be hypothetically designed to be aligned with the interests of non-corporate individual consumers, there is no such thing as bug-free software. They have added complexity that works against us and brings vulnerabilities. And we also cannot dispense of the deliberate design whereby some remote actor decides for the user what software is or is not “authorised” to execute. I alone should decide what is authorised on my PC.

    So the fix is to use an AMD processor made before ~2014 (roughly speaking), or a pre-2009 intel. AMD chips were behind intel in terms of performance, but probably not 5 years behind. So I figure 2013 AMDs are the most interesting. But we only have a fuzzy idea of which AMD chips are spychip-free.


  • Well, @passenger@sopuli.xyz mentioned that it’s on the google page. But then when I chose some of the brands under “Find specific steps for your access point”, it’s a bit useless because manufacturers web admins have no sense of discipline or self-control. They cannot resist the urge to rearrange their website which broke Google’s links. But further below on Google’s page are some general instructions. I would try to follow those. And if you get stuck, maybe try posting a support request in !homenetworking@selfhosted.forum.

    (update) I just had a closer look at the general instructions to do a quick sanity check. Google’s instructions for linux are bad at the 2nd step. That is, running ifconfig as a linux user can be tricky… might need to run /sbin/ifconfig instead. And even if it runs, it does not give the gateway anyway.

    If you’re on linux, run ip route instead, which will say something like default via 192.168.1.1. Whatever IP address is the default gateway, that is what you need for the next step. Note I am only talking about linux. Google’s instructions are probably fine for other platforms.