

That’s if they use Google’s push notification backend on firebase. FOSS apps from F-droid usually don’t.
Tl;Dr install F-droid damnit


That’s if they use Google’s push notification backend on firebase. FOSS apps from F-droid usually don’t.
Tl;Dr install F-droid damnit
I use Librewolf and TBB. Both have NoScript enabled and JS turned off by default. I never turn on JS on TBB obviously, and for the few sites that I frequent on Librewolf, I tweaked it by hand. It’s not that hard.
I will look to also use Mullvad browser alongside Librewolf maybe, not sure which one of them is more private since Mullvad browser comes straight from the TOR project and has their security settings.


It’s a coincidence, I was thinking about a PiKVM myself, although with much more modest hardware (a Raxda/Banana Pi Zero at best - I wonder if these can actually hold up). I’m not very familiar with PiKVM setup; do I need to compile the repository from source on whatever I run on these machines? Is there a minimum requirement for specs?


I’m still baffled at how good Ollama is on working on paltry hardware like ARM and small VMs. Give it GPUs and it’s amazing.
The next step should be to encrypt information at Transit and rest to as to purchase GPU power from the cloud but maintaining client-side encryption throughout. That’ll bring even more power to the masses: imagine giving Ollama a Cloud endpoint to remote GPUs which it can compute on without the consumer purchasing any hardware.
How does having those 3 keys on the right help?
Very nice read, I look forward to posts with detailed explanations of realistic privacy setups!
With that said, here we go:
That was a lot. Thanks for reading!


You are very good looking


Very interesting, thanks!


On a serious note, if the only reason a person might bring kids into this world is because they are bored; they are going to be, and make the kids equally, miserable.


SafetyNet is deprecated on newer versions of Android


As far as lock out, you create a break glass on everything. Emergency account with non rememberable ridiculous password, saved in a safe place.
This is such a great and a simple idea. Thanks.
I think I followed your setup at a high level, but because I don’t have hands-on experience with AD I didn’t quite catch the scope of it. Thanks for letting me know, I’ll get some reading done when I get the time!


This is the first time I’ve come across Elastiflow, thanks for mentioning it. Seems like an intriguing service to add.
I was considering using Suricata/installing Security Onion to do IDS from the certificate from a private CA. Sophos firewall seems pretty good too.


Thanks, I’d like to know more about your public-facing setup using cloudflare


I didn’t know MS exchange could be used as a WAF. Will need to read more about that.
Can I host Intune completely on-prem?
What do you mean by “My Sophos is self-contained”?
Does your Cisco router get updates? My problem with these companies is that they build backdoors in their firmware for agencies to use. Are you monitoring the network usage of your Cisco gateway?
Using AD/RADIUS on-prem is an intriguing idea. I didn’t consider it because if my AD server goes down I’m essentially locked out of my services. I need to think more on this. Thanks.


Do you use a KVM to interact with machines that can access the Internet?


Would you have to compromise on your security according to your threat model if you ran VMs rather than dedicated devices? I’m no security engineer and I don’t know if KVM/QEMU can fit everyones needs, but AWS uses XCP-ng, and unless they’re using a custom version of it, all changes are pushed upstream. I’d definitely trust AWS’ underlying virtualisation layer for my VMs, but I wonder if I should go with XCP or KVM or bhyve.
This is my personal opinion, but podman’s networking seems less difficult to understand than Docker. Docker was a pain the first time I was reading about the networking in it.
Really like your setup. Do you have any plans to make it more private/secure?


Thanks, never thought of that before. I’ll certainly try it, great way to help the network!


You seem to have a great setup. Since this comment touches on slightly advanced topics, I’ll ask this here:
Your measures seem to be focussed more on security than privacy - which is great! It’s my fault for not specifying it in the post, but I’d definitely like to know if you have done anything specific to keep your network private as well as secure.
Thanks for your wonderful comment - saved!


That is very interesting, thanks!
Which distro does she have installed?