ranok

joined 1 year ago
MODERATOR OF
[–] ranok@sopuli.xyz 2 points 3 months ago (1 children)

The Intel ones are quite a bit easier, but still not as easy as a PC. You need to disable some FW security settings to allow for a non Apple kernel to boot.

[–] ranok@sopuli.xyz 7 points 11 months ago

Supernote is the alternative I went with. They have a pretty responsive dev team and the cloud integration is optional, you can push stuff over the local WiFi network.

[–] ranok@sopuli.xyz 3 points 11 months ago

I returned my Remarkable 2 after a couple of days for a Supernote. Can do local network file transfer, and wifi screen sharing.

[–] ranok@sopuli.xyz 2 points 1 year ago

This is pretty misleading due to its brevity, an attacker on the same network can determine what website you're going to but not the content being exchanged. A VPN moves the threat of having your browsing destination determined to the VPN provider from the local network.

That said, modern WiFi encryption does prevent other devices on the network from eavesdropping, so the attacker would have to employ a more involved attack (e.g. ARP spoofing) in order to even see the destinations.

[–] ranok@sopuli.xyz 4 points 1 year ago

I'm surprised not to see https://cryptpad.fr/ here, a FOSS, self-hostable E2EE web based office suite. Not as feature rich as GDocs but offers the basics in a more secure manner.

[–] ranok@sopuli.xyz 1 points 1 year ago

He has been stepping back from Signal over time.

[–] ranok@sopuli.xyz 2 points 1 year ago (1 children)

Do you listen to risky.biz?

[–] ranok@sopuli.xyz -1 points 1 year ago

While Chromium itself is a very solid platform, and correspondingly Chrome is a hard exploitation target, it's quite easy to screw up a fork of it. Comodo Secure Browser was a chromium fork that was fixed to an old version of the renderer with known security issues and was built to disable the sandbox. It also added libraries that were compiled without ASLR that worsened security for every application that loaded them.

Chrome has an enormous security team behind it in addition to P0, so bounties on Chrome exploits are around $500k. FF bounties are a fifth of that, which is probably a portion of less security, and a portion of lower target market. Brave could be doing terrible things that without an audit would be unknown. Web3 code is pretty terrible on the whole, so adding that to a secure base may not be great...

[–] ranok@sopuli.xyz 3 points 1 year ago

ZipPy is much less robust to defeat attempts than larger model-based detectors. Earlier I asked ChatGPT to write in the voice of a highschool student and it fooled the detectors. The web-UI let's you add LLM-generated text in the style that you're looking at to improve the accuracy of those types of content.

I don't think we'll ever be able to detect it reliably enough to fail students, if they co-write with a LLM.

 

I made this and thought you all might enjoy it, happy hacking!