Digital Hygiene
karpathy.bearblog.dev
karpathy.bearblog.dev
Gandi used to be a decent domain provider but have been bought out and are putting up prices.
You can lie, of course, but if they find out you lied, that's grounds for immediate revocation without notice or refund.
You also can’t set a 90 day message expiration in Signal. 4 weeks is the maximum.
It’s insane to me that someone is talking about digital privacy hygiene and still using gmail. This basically invalidates the entire argument.
Protonmail also is a major UX downgrade; I recommend selfhosting an IMAP server for long term mail storage and using a service like Fastmail for your inbound email to replace gmail. Periodically move everything from your email provider to long term storage in your selfhosted IMAP server.
There are probably valid situations for self hosting, but a bit like prepping, it is not a method of sustaining civilization, but an attempt to survive it's fall; suitable for only low numbers of people.
What's suspicious about being general-purpose?
> This is significantly better than storing TOTP private keys on other (software) authenticator apps, because again you should not trust general purpose computing devices.
If you can't trust your own PC, a Yubikey doesn't help much.
The PC is what generates the request to the Yubikey and presents the UI where you approve it, so an attacker in control of your PC could for example replace the intended request with one that transfer all your Bitcoins to the attacker. Or it could replace the recipient in whatever transaction you're approving. You would need a separate trusted screen on the Yubikey to verify the details of the request if you don't trust the PC.
The PC is also what actually processes the data (or at least mediates access to it if it's processed on the server side), so an attacker in control of the PC can modify any data you view or submit, regardless of what authentication method you use.
It baffles me whenever I see someone’s personal email open on a work machine. Seems like that’s putting a lot of unwarranted trust in your employer.
Would it be “just” learning the password and making a screenshot of the inbox and any open emails, or is it relatively easy to look at more?
Edit: right, also any email that gets written.
You can selfhost just IMAP storage, and pay an email service provider to receive and store your mail for you, periodically archiving it to your own long term storage and removing it from the provider.
I also have an old Proton Mail account that is used occasionally. Can't complain about that either.
I don't want my mail being scooped up by Google-scale orgs. Don't really have any other privacy requirements beyond that.
Your mileage might vary.
[1] https://github.com/ungoogled-software/ungoogled-chromium
Secure the top, let everything else trickle down.