Open-source tool to enforce privacy/security best-practices on Windows, macOS
github.com
github.com
The only thing one could argue for in a privacy oriented manner is the signature validation with OCSP checks since it somewhat leaks what signature owners you're trying to check. But without it you'll never be able to find out if a signature was revoked, including self-signed signatures.
if a certificate was revoked
(Just to prevent confusion. Someone might think that it’s possible to revoke individual signatures.)
It's good that things with security ramifications are separated, but they must be used with care.
There's SCAP https://en.wikipedia.org/wiki/Security_Content_Automation_Pr... then a popular set of tools that implements it, for example: https://www.open-scap.org/tools/ However the rulesets "profiles" are flexible, one popular one is CIS.
https://docs.microsoft.com/en-us/powershell/dsc/quickstarts/...
I'm glad other people are working on tools, but you'll probably realize sooner or later that a few registry edits are not sufficient to maintain privacy, and policies are really the better approach.
How does disabling Gatekeeper, File Quarantine or automatic updates make a MacOS system safer? It looks like the opposite !
Those features are not disabled in their "standard" preset which they present as "recommended for everyone".
To disable gatekeeper, you need to use the "strict preset" which they describe as "not designed for daily users, it will break important functionalities".
Gatekeeper performs online checks to verify if an app contains known malware and whether the developer's signing certificate is revoked. Gatekeeper, file quarantine etc. are security features also designed for data collection to learn about the files and applications you have in your computer (built in anti-malware on macOS and Windows provide them a perfect excuse to harvest all your file name and file hashes to know more about you). When automatic update is enabled macOS phones Apple periodically, leaking info like your geolocation and network etc.
I also can't figure out what the "REVER" option does on some entries.
Resizing the window doesn't seem to do anything, the program is fixed in the middle at a certain size.
It's not JS either.
Glibly pretending it ain't so isn't making Linux better.
First, agreed re: untrusted apps.
And, yeah, maybe I should have been more clear, as you note, they are usually an option, not the standard. Full disk encryption is the standard on MacOS. With Linux, like so many things, you never know what you're going to get. Secure boot took some work to setup on Ubuntu, but works relatively flawlessly. Immutable root filesystem is something you can do with Fedora Silverblue and a few other distros, but it's nowhere near the standard it is on MacOS.
And that's what I mean by years behind, sure you can do basically anything on Linux, but, if it's not the standard, is it even practical enough to be workable? Linux, for lack of a better word, bigots (and I'm a huge Linux fan!) may call MacOS is a toy OS, but, for a laptop, how much work does it take to get Linux to the point where Linux's practical security is similar to MacOS? Lots, and lots, and lots.
- more likely to be blocked by web filtering
- the TLD is intended for "risqué content" according to the registrar
- the TLD is more expensive due to the novelty, a novelty which negatively impacts the reputation as indicated here by some.
Social reasons: - It can lead to awkward situations when browsing or sharing with others if people assume the content to be related to the URL.
etc..I mean, do whatever, but there's a certain irony to something which is about privacy and security forcing you to pollute your search history with the word 'sexy' in a way that you cant control locally.
It's just my opinion anyway.
EDIT: This is according to the HN guidelines: “Please don't complain about tangential annoyances—things like article or website formats, name collisions, or back-button breakage. They're too common to be interesting.”.
Thank you.
It is just a word. A word that carries far more weight than it really should in our society.
I kinda like the idea of "privacy is sexy" which is how I read it.
The only possible issue is I can see some companies blocking it due to "Sex" but that's their issue with way too strong rules.
If it should or shouldn't carry the weight is irrelevant, "Sexy" does carry weight so surely the problem is obvious.
Besides, speaking from first hand experience, historically 'sexy' content on the internet usually came with a Malware/Virus, not a good association when the intention is to run scripts that make significant changes to your computer configuration, all for a novelty that lends nothing to the product.
With that being said, I have no issue with it personally.
1. Arousing or tending to arouse sexual desire or interest.
2. Highly appealing or interesting; attractive.
3. Having sexual appeal; suggestive of sex.
While #2 might be the intent, there are much better alternative choices for links that I could
* send to my 10 year old niece who is interested in tech
* share with co-workers or on company forums
* use without hassle from automated filtering/proxy/scanning tools for a TLD that is associated with adult content
- Privacy is sexy
- Don't let Microsoft kill privacy
The answer probably depends where you live. Stereotypically, Americans are afraid of sex, and Europeans are afraid of violence - for example many video games released in Germany were modified to have green blood.
My take: both sides of the pond need to lighten up
https://news.ycombinator.com/newsguidelines.html
All we get out of generic tangents like this is a tedious, offtopic subthread that often ends up being much larger than the on-topic discussion, and usually descends into flamewar after a while—perhaps because the mind resorts to indignation to amuse itself in the absence of anything interesting (https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sor...).