The 8232 Project

I trust code more than politics.

  • 32 Posts
  • 44 Comments
Joined 3 years ago
cake
Cake day: February 25th, 2024

help-circle

  • How do you handle apps that refuse to run on rooted/jailbroken phones or on devices without Google Play Services? Can microG, Xposed, or other tools help in practice? (F*ck Play Integrity and “Google Play license check”). Can I bypass those restrictions without rooting?

    The best thing you can do is leave feedback so that the developers fix it themselves. Rooting is not advised for security reasons.

    Have you ever rooted your phone? Any practical advice for someone considering it? I don’t have a phone I know is compatible with alternative ROMs (e.g., LineageOS), so I’m leaning toward rooting and would appreciate recommendations or warnings.

    No. I was fortunate enough to be able to flash GrapheneOS on a Google Pixel. You should know that you can debloat stock using something like Universal Android Debloater Next Generation. That provides more privacy without compromise to much of the security. Rooting gives you full control but is a major security regression because you have full control.

    How often do you need to show ID where you live (hospitals, government offices, large transactions, etc.)? For example, in my country I always have to show ID (or use face ID) at places like hospitals or when making large transactions.

    I’ve opted out of most institutions in the United States, but the most frequent times I show my ID are for employment, cashing paychecks, and any government-related things (e.g. obtaining a driver’s license, opening a post office box, etc.)

    How is eID implemented in your country? Does your government require or strongly encourage using eID apps? Are they widely adopted? (I know the EU’s planned age‑verification app is a form of eID—or not really. Real examples are Germany’s AusweisApp and Vietnam’s VNeID. Anyway, that age‑verification law should not exist).

    eID hasn’t been widely adopted here, at least not yet.




  • We should not hold those ignorant to privacy accountable.They simply don’t know any better. Instead, we should only hold those actively opposing privacy accountable. We should try to educate those ignorant to privacy and show them the alternatives that exist. I bet if these content creators could switch without major loss (e.g. a major chunk of subscribers lost) most of them would be more than happy to.
















  • A brief internet search shows that surprisingly, hosting Jellyfin on OpenWRT should work…

    I still find it hilarious that since dd-wrt and OpenWrt are just… Linux, you could install Super Mario Bros on there. I checked, nobody seems to have tried.

    I’ve never used tailscale, I’m afraid. Normally I would say: just use whatever seems easier to set up on your device/network; however, note that tailscale needs a “coordinate server”. No actual traffic ever goes through it, it just facilitates key exchanges and the like (from what I understand), but regardless, it’s a server outside your control which is involved in some way. You can selfhost this server, but that is additional work, of course…

    Ah, that make sense. Is Wireguard P2P?

    Glad I could help, after being so unhelpful yesterday :)

    Don’t beat yourself up, you were fine. Because I’m big on privacy, when I ask for help I have a bad habit of leaving out the “why” behind my choices, so it’s understandable that people weren’t happy with what I needed.

    Eh… Marriage is not really common in either of our families. We agreed to go sign the papers if there ever is a tax reason, lol. Sorry if that’s a bit unromantic :D Nice rings though ^^

    I need to go make a petition to raise taxes then! /s

    You both are perfect for each other, so don’t screw it up!





  • Hi again.

    Hi there!

    Set up ProtonVPN on the raspberry pi.

    I’m actually surprised nobody suggested simply using the Pi with OpenWrt as my own router. Though, that would make it hard to host Jellyfin.

    Nots that this requires you trusting the pi to the same degree that you trust your phone.

    For the most part, I trust the security of my Pi. I can hold it in my hand and see every line of code, after all!

    Devices which you take with you, like your phone, unfortunately will loose internet connectivity when you leave your home until you switch off Wireguard, and switch on Proton, and not be able to connect to Jellyfin when you return home, until you switch them back.

    I plan to post a tutorial about how to securely host Jellyfin. Another user gave a solution to this problem that I absolutely love, and I’ll showcase it there. I don’t want to spoil it :)

    Could you explain Wireguard vs. Tailscale in this scenario?

    Thank you all so much for your help! This is likely the solution I will go with, combined with another one, so again thank you so much!

    P.S. I don’t care if you wrap an ethernet cord around her finger, get going!


  • OP, I have been facing the same situation as you in this community recently. This was not the case when I first joined Lemmy but the behaviour around these parts has started to resemble Reddit more and more. But we’ll leave it at that.

    I’ve noticed that behavior is split between communities. Lemmy gets a bit weird because communities are usually hyper-specialized, and sometimes instances themselves cultivate different cultures (e.g. lemmy.ml is usually for privacy enthusiasts, since that’s where c/privacy is hosted). That, with the addition of specific idols for each community (e.g. Louis Rossmann for the selfhosted community) affects how each community behaves. That’s my theory, anyways.

    I am interested in the attack vector you mentioned; could you elaborate on the MITM attack?

    Basically the “this website is not secure” popup you see in your browser is sometimes due to the website using a self-signed cert. There’s no way to verify that that cert is from the website itself or from an attacker trying to inject their own cert, since there’s no CA attached to the cert. If an attacker injects their own self-signed cert, they can use that to decrypt your HTTPS traffic (since your browser will be encrypting using their cert) and then forward your traffic along to the real website so that from your perspective (minus the warning screen) nothing is wrong. I’m oversimplifying this, but that’s basically how it works.

    Unfortunately, if you don’t have control over your network, you cannot force a DNS server for your devices unless you can set it yourself for every individual client.

    I forgot to mention in this post, but because of browser fingerprinting reasons I don’t want to use a custom DNS. Thanks for the suggestion though!


  • Thank you for this!

    Is OPNsense like dd-wrt or OpenWrt?

    The thing is (and this is by no means a knock on you) if you are doing pen testing then you definitely need to increase your knowledge on networking.

    I have background in Wi-Fi hacking and LAN attacks, and I understand the structure of networking (LAN, WAN, layers of the internet, DNS, CAs, etc.). My head starts to hurt when RADIUS is involved, ad hoc networking (which I understand the concepts of, just not how it works. I want to learn this first), mDNS, and other complicated topics. I’m trying to push past those mental roadblocks and learn as best I can, but it’s a tricky topic!

    https://wiki.freeradius.org/

    There’s something to check out just to get some concepts. You can do plenty of things to harden your security that could give you the comfort you need without defaulting to encrypted connections over LAN.

    Thank you! I’ll definitely check this out. You’ve been a huge help!






  • For real though, if you think someone is (or might be) listening in on your local network, i.e. have physical access or compromised one of your machines, then the Jellyfin traffic is the least of your problems. Pick your battles. What’s the worst that could happen here - someone gets to know your favorite show?

    A bad router + bad ISP combo means I get ratted out for copyrighted material (that I don’t have… I only host creative commons videos on my Jellyfin server, of course…)


  • This is fair, and does solve the problem. I didn’t explicitly state that I needed it to be convenient, so you’re right. Having one network that is LAN only and switching to it to use Jellyfin, and having a second network that is WAN only and using ProtonVPN there would probably be the most secure setup. Unfortunately, it still doesn’t solve the issue of encryption in transit over the LAN, but that might be fixable with Tailscale. The LAN could even be ethernet-only, to mitigate wireless attacks.

    That makes me wonder if there’s a way I could simply plug an ethernet cord from my phone to the airgapped Pi and use it that way. Is that possible? Surely it is. Could ProtonVPN be used on the phone even while the phone is connected physically to the Pi?


  • Just out of curiosity, why is your network not a trusted party?

    Part of my threat model is essentially “anything that can connect to the internet poses a security risk”. Since networks are the literal gateway to the internet, it is reasonable not to trust them. Routers don’t run as secure operating systems as Qubes OS, secureblue, or GrapheneOS. If a malicious party found a way to connect to the network, all unencrypted activities can be intercepted. If the router itself has malicious code, any unencrypted traffic can be sent to a third party. Those are just the basics, but trying to put band-aid solutions on a fundamentally broken system is a losing battle.

    GrapheneOS distrusts networks as much as possible, so I do too. Even if I own the network, I am not a network engineer, so the chances of fault are high. In the simplest case, the network is a gateway to all activity that happens on the LAN, and it only takes one zero day to make that happen. The best mitigation is proper encryption and no self-signed certificates (where possible).