• 1 Post
  • 28 Comments
Joined 4 years ago
cake
Cake day: March 6th, 2021

help-circle







  • Also worth noting that #Ubuntu and #Mint both moved substantial amounts of documentation into Cloudflare (the antithisis of the values swiso claims to support). I have been moving people off those platforms.

    BTW, prism-break is a disasterous project too. You know they don’t have a clue when they moved their repo from Github.com to Gitlab.com, an access-restricted Cloudflare site. There are tens if not hundreds of decent forges to choose from and PRISM Break moved from the 2nd worst to the one that most defeats the purpose of their constitution.

    It might be useful to find dirt on various tech at prism-break, but none of these sites can be trusted for endorsements.

    The prism-break website is timing out for me right now. I would not be surprised if they were dropping Tor packets since they have a history of hypocrisy.





  • StreetComplete shows me no map, just quests on a blank canvas. OSMand shows my offline maps just fine, but apparently StreetComplete has no way to reach the offline maps. I suppose that’s down to Android security – each app has it’s own storage space secure from other apps.

    In principle, we should be able to put the maps on shared SD card space and both apps should access it. But StreetComplete gives no way in the settings of specifying the map location. And apparently it fails to fetch an extra copy of the maps as well in my case.




  • I’m on the edge of quitting protonmail. The issues:

    • #CAPTCHA hell. At least for Tor users.
    • no app in f-droid
    • API shenanigans and/or CAPTCHA breaks hydroxide (the foss bridge)
    • protonvpn: you can no longer fetch all the configs in one download. You have to click “download” >120 times now to get all the configs
    • account locks if you do not login frequently enough (i think every 6 months)
    • if you supply your login creds but get a CAPTCHA and say fuck this, and walk, it does not count as a full login needed to reset the expiration clock
    • the CAPTCHAs are graphical which forces you to enable images in your browser; but when you do that you get images that junk up your screen and waste bandwidth
    • no public keyring. Hushmail was better in this regard. An advanced user could upload their PGP public key to Hushtools and then encryption just worked for hushmail users contacting that person. After Hushmail started charging, I would tell the normies who need comms w/me to get a gratis Protonmail account. But then I have to send them my public key and they have to figure out how to attach it to my profile in their phonebook. It’s a show-stopper in many situations.

  • I would say mostly true.

    I moved to a region where my lifestyle (accounting for wages, tax, cost of living) was effectively cut in half. Yet it was still the right move. My initial thinking was I will live anywhere for a year to get a different experience - I can always bounce back if I don’t like it… if the pay reduction bothered me. I ended up staying ~10 years.

    A big factor is where you are in life. Fresh out of university, it’s important to gain ground right away and perhaps get the house paid for, or nearly so. But once you’re a senior dev and at a point of calling yourself “privileged class" with a decent sized 401k built up (which is great to convert to a Roth while abroad), you’re only cheating yourself out of life experiences by continuing to chase the money. Some research concluded around ~10 yrs ago that people’s overall happiness improves as income increases up until the $55k/year mark. Beyond that, income doesn’t matter much. Of course that would be a little higher now with inflation but I guess the OP has cleared that figure.

    I think it was around 15 years ago I started researching typical incomes around the world and I noticed that Japan paid SWEs double the US average. Cost of living was about 50% higher in Japan but it still worked out that a US→Japan move would have been a lifestyle upgrade. So there are some rare exceptions.


  • I think you would benefit most by moving abroad. Staying in one country your whole life is very one-dimensional. If you move to another country, esp. overseas, you will look back on your current boredom as wasting your life and you will regret not having done it sooner. Go for just one year. You can always return if you don’t like it. You might be someone who says “I went for 1 year, but stayed 5”.

    But first move to a purple swing state like GA or PA for just a month or two, then move your stuff into mini storage. Two reasons: you get to experience a different part of the US, briefly, and you can register to vote in a place where your future votes will count the most. Because that’s the state you will vote in while abroad. OTOH, isn’t Texas on the edge of being a swing state? It’s probably not a bad place to vote from.


  • I’m not looking to be proven right. The purpose of the tangent discussion was to substantiate whether or not bank creds are exposed to CF. If banks are actually protecting consumer creds from CF, then it requires a bit of analysis because banks don’t even disclose the fact that they use Cloudflare. They make the switch to CF quietly and conceal it from customers (which is actually illegal - banks are supposed to disclose it but it’s not enforced in the US). AFAICT, CF’s role is mostly useless if the SSL keys are held by the site owner.

    In the US, the financial system is quite sloppy with user creds and user data. There are even a couple 3rd-party services (Yodlee / Mint) that ask customers for their banking creds at all the places they bank. This service then signs on to all the banks on behalf of the customer to fetch their statements, so customers can get all their bank statements in one place. IIRC some banks even participate so that you login to a participating bank to reach Yodlee and get all your other bank statements. Yodlee and Mint are gratis services, so you have to wonder how they are profiting. The banks are not even wise enough to issue a separate set of read-only creds to their customers who use that Yodlee service. In any case, with that degree of cavalier recklessness, I don’t envision that a US bank would hesitate to use CF in a manner that gives the bank the performance advantage of CF handling the traffic directly. But I’m open to convincing arguments.



  • I’m well aware that Cloudflare holds the TLS keys. I’m also well aware that that does not equal having access to credentials.

    Can you elaborate? I believe the hashing must be done on the server side not the user side, so Cloudflare would see the creds before hashing. I know it’s possible to subscribe to an enterprise package where you hold your own SSL keys, but it’s unclear why CF would even be used in that scenario. If CF cannot see the traffic, it cannot optimize it as it all has to be passed through to the original host anyway. AFAICT, CF’s only usefulness in that scenario is privacy of the websites ownership - something that banks would not benefit from.

    Banks certainly can not outsource willy nilly. Or well, I suppose they may in some jurisdictions, but the context here is Europe, where the banks actually are regulated.

    US banks (esp. credit unions) outsource with reckless disregard for just about everything. Europe is indeed different in this regard. But European banks have no hesitation to outsource email to Microsoft or Google and then to use email for unencrypted correspondence with customers. That crosses a line for me.

    European banks will also outsource investments to JP Morgan (one of the most unethical banks in the world), and they tend to be quiet about it. I boycott JPM along with other similar banks in part due to investments in fossil fuels and private prisons. This means banking in Europe is a minefield if you boycott the upstream baddies.


  • Cloudflare holds the keys. They decrypt all traffic that reaches their reverse proxy. It’s legal. Banks can outsource anything they want and they do so willy nilly. Their privacy policies cover this… they can share whatever they need to with their partners.

    BTW FWiW, I have caught banks breaking a few laws and reported it to regulators. Regulators don’t care. Everyone thinks consumer banks have a gun pointed at them to comply with the law because it periodically makes a big splash in the media when they’re caught not enforcing AML rules. But when it comes to consumer protection, anything goes to a large extent. There’s very little pressure to do right by consumers. One regulator even had the nerve to say to me “why don’t you change banks?” (in response to a report of unlawful conduct).