Show more

@sheogorath But will Grub password protect from evil maid attacks such as this one? github.com/nyxxxie/de-LUKS

Because the main problem is that in Ubuntu the bootloader is loaded from an unencrypted partition, which can be modified off-line...

@kravietz Set a grub password!

Use OpenSCAP Workbench with the proper profile for Ubuntu, Fedora or CentOS to check compliance.

Full set of instructions (one might want to select just a few, but still):

access.redhat.com/documentatio

I guess that should already help a lot :)

3) When there's choice between .deb and Snap/Flatpak version available (there is for Firefox, Brave and many other popular programs) always go for Snap/Flatpak version as it runs in a much more effective sandbox.

This doesn't come completely free either because with Snaps your profile file move to the sandbox but it's quite a simple operation.

Show thread

2) Always run the latest available Linux distro - so in case of Ubuntu go for 19.10 - and always have all updates installed.

Show thread

My answers in random order:

1) Make sure you have Secure Boot enabled in BIOS, and BIOS password set.

That's pretty much all you can do to prevent backdooring & keysniffing of your bootloader today when someone covertly gets physical acces to your laptop.

If this is a viable threat, go for QubesOS, but be aware of its limitations (e.g. inability to access GPU by the operating system, so no games or 3D graphics)

Show thread

Just had an interesting question from a colleague who has a notebook and works remotely from random places:

> I've got full-disk (FDE), what else I can do for ?

One reason why 's 1.1.1.1 resolver is so fast is that it seems to be making a tradeoff between speed and freshness of responses. Specifically it seems to cache RRs for as long as allowed, while other public resolvers will recheck much earlier.

@mhamzahkhan Ok, I get it - I've eventually started using it on like 3rd attempt or so, but now can't live without it :)

LOL a nice list of names preferred by weirdos from different countries, for example "1000-jaehriges-reich", whose registration is blocked in .eu eurid.eu/en/register-a-eu-doma

At "Internet Consolidation: What Lies Beneath the Application Layer?" panel in Chatham House in London.

Starts with the question about .org sale...

" EU unveils €3bn research fund to develop batteries

Seven member states to invest in the project which is set to run until 2031"

amp.ft.com/content/53a92e68-1a

*Came home and checking email*
*WiFi keeps dropping out*
*Checks conn...”

Why’s there a freakin CAST IRON PAN on the router?!?

“It was on the table, but I was cleaning up. So I left it in your room”

ON THE ROUTER??!??!!

“Oh...”

For sale: Slightly used dimwit of a roommate

After months of work, we have a new stable release series.

Tor 0.4.2.5 is the first stable in the 0.4.2.x series. This series improves reliability and stability and includes several stability and correctness improvements for onion services. blog.torproject.org/new-releas

Medicare chief asked taxpayers to cover stolen jewelry.

Seema Verma requested $47,000 for items taken from an SUV that took her to a speech. politico.com/news/2019/12/07/m

Show more

kravietz 🦇's choices:

Mastodon 🔐 privacytools.io

Fast, secure and up-to-date instance. PrivacyTools provides knowledge and tools to protect your privacy against global mass surveillance.

Website: privacytools.io
Matrix Chat: chat.privacytools.io
Support us on OpenCollective, many contributions are tax deductible!