• 0 Posts
  • 71 Comments
Joined 2 years ago
cake
Cake day: August 6th, 2023

help-circle
  • It’s impossible to de-google or meaningfully remove unwanted stuff from Smart TVs while keeping them usable for streaming purposes.

    What you want to do is factory reset, don’t connect to the internet, go into settings and turn off whatever you can, and then use a streaming box.

    Yes it’s an additional cost but it’s BETTER. The processors and memory in those TVs are lousy, the apps are often sluggish, the experience is simply not great. Frankly the hardware was built not to be usable for you, they are data collection platforms that include minimal low quality streaming experiences in order to collect data. No software is going to fix that.

    Want something that “just works” and supports all the major streamers? Get an Apple TV 4k. It’s pretty private but importantly no ads, clean interface, powerful hardware. Is it maximally private? No. But it is easy.

    Want to put in effort? You can get either a Dune-HD box (some have dual-OS without reboot where one is Netflix certified to get you full resolution while passing DRM checks while another is unlocked bootloader which you can install all kinds of things like Plex and Kodi on) or get some other Android streaming device of your choice (Walmart’s Onn brand 4k devices used to be very good and cheap though you might need to check as I heard rumors the latest devices can’t be unlocked).

    You’ll have a better experience on more powerful hardware and will never want to go back to the bad on-board TV experience.


  • Wait until you find out they offer apps with ties to:

    • FBI
    • US military
    • CIA
    • NSA
    • The most awful fascist ghouls on podcasts and youtube
    • The “israeli” state and its war criminal institutions.

    Curious then you pick on vague ties to China to fearmonger.

    I mean FFS Microsoft and Google are actively abetting the most documented genocide in a century. Where is the outrage from these garbage people over that? Where’s the push to help boycott and pressure them to stop assisting the slaughter? Children are being killed right now in Gaza with the help of these American companies and where are the stories encouraging people to stop using them?


  • This is ridiculous. I like the way it’s set up now. They tried “simpler” before and I hated it and turned it off. Along with the news they’re supposedly getting rid of tags for bookmarks (I have so many bookmarks without tags they’d be useless) I’m just feeling so much despair for the web right now.

    Also disabling showing HTTPS in the address bar as part of the URL is another negative change catering to what they believe is the lowest common denominator. Consider for a moment that browsers still support multiple protocols besides hypertext transfer.


  • IMO focus on purchasing physical content from creators or distributors who NEED to get paid.

    It’s one thing to foolishly throw money at these big companies for blurays of an already very successful series while they’re throwing their old libraries in the trash or ‘the vault’ or just shoveling most of their money towards low quality reality garbage.

    It’s another to buy a Criterion or BFI or Vinegar Syndrome bluray of something out of print that they need to recoup the costs of restoring and scanning.

    If someone buys a bluray of an MCU movie they are a chump, firstly for liking that stuff, secondly for giving Disney more money for it when those things already earn piles of cash in theaters and that alone would be enough to keep them paying salaries and producing that stuff.

    Spend money on independent film-makers/releases, on restorations, on series you like on the verge of cancellation.

    Sadly I think the conclusion is already written, physical media’s days are numbered, the big companies are going to shut down the overwhelming majority of bluray and dvd production within 5-10 years is my feeling because why sell you for $20-$30 a copy of something when they can get your rent in the form of streaming monthly payments for the rest of your natural life?

    And best of all with the rent they can push ads which further increase their revenue. That bluray is a one-time payment, ads for watching the movie on streaming are a continual revenue stream. I predict that they will either have completely killed off ad-free tiers of streaming to push most of their audience into an even bigger and more valuable ad pool to sell to advertisers OR the prices of the ad-free tiers will grow dramatically away from the ad-supported tiers. Right now it’s a few bucks a month, I suspect within 10 years it will be 170-300% the cost of the ad-supported version.


  • Use secure erase function which is built into the SATA and other specs, it applies a voltage spike to clear the cells of all held charges thus wiping them. This happens near instantly, it’ll be a process that will signal it’s finished within a minute and takes much less time than that.

    If you want to be extra paranoid I suppose you could follow that up by encrypting the entire (empty) drive and then doing it again though I’m not sure this has any benefit however it’s the closest to forcing the cells to be used again and then cleared again. However this does not guarantee that exhausted and worn out areas are flash are not potentially spared both. It’s unlikely for large amounts of data to be recovered from this unless your drive is failing or has been completely worn out but it’s also why if you ever store sensitive data on an SSD it’s preferable to do so in an encrypted form (such as encrypting the whole disk or partition).




  • Because their founder (Marlinspike) is probably under a National Security Letter, maybe it’s just that, maybe he’s done some crimes they’re also holding over him. If you look at his behavior it’s that of someone very paranoid that they’re going to be found out to be cooperating with the feds and get hit with charges for not upholding the bargain, someone straddling one or two big lies that have to be maintained to keep their life going. Very controlling of things they should be open about if they care about privacy as they claim. But exactly the behavior of someone under an NSL who’s terrified of getting hit with charges for that and maybe other things but who is expected to front and run a purported privacy first messenger. The secrecy, the refusal to allow others to operate their own servers, the antagonism towards federation, the long periods without publishing source code updates.

    This doesn’t necessarily mean that signal message content is compromised, the NSA primarily scrapes metadata and would most care about knowing who is talking to who and to put real names to those people and building graphs of networks of people. Other things like what times they talk can be inferred from upstream taps on signals servers without their knowledge or cooperation via traffic observation and correlation especially when paired with the fourteen eyes global intercept network. With a phone number it’s also a lot easier to pinpoint an exact device to hack using a cooperating (or hacked) telecom. Phone numbers can also be correlated to triangulated positions of devices, see who in a leftist protest network was A) heavily sending messages and B) attended that protest and left last and begin to infer things about structure and particular relationships.

    And those saying it has to do with spam prevention, that’s kind of nonsense. First I still get the occasional spam, second a phone number that can receive a confirmation text is something all these criminal organizations have access to which the average person doesn’t. Third it’s possible to prevent spam just by looking for people (especially new accounts under 120 days old) sending very small amounts of messages (1-3) to a very large amount of other users especially in a short amount of time. Third there’s no reason to keep the phone number tied to the account, a confirmation text could be required with a promise to delete the phone number immediately after (would still be technically useful to the NSA though less useful for keeping track of people changing numbers or using a burner for this who might be higher value targets).


  • A ton. Mozilla is already behind on all kinds of miscellaneous less used standards implementations compared to Chrome AFAIK. On top of that there are security fixes needed monthly and realistically you need to be able to push emergency patches within 48 hours or less (really 1/4 or 1/2 that) or people are going to flee because they got cryptolockered because of you.

    How quickly would sites be unsupported? Hard to say. Most likely large chunks of the internet would start blocking Mozilla user agents as an out of date security threat for their userbase before it actually ran into actual implementation problems. The problem would be that, websites and services no longer even bothering to try to support Mozilla and making changes that break things, and of course security holes and exploits which would likely eventually lead to no-click complete computer compromises and other very bad things. Once it falls far enough behind on standards a lot of sites will block it for that reason because they don’t want bug reports or to spend money chasing down an issue potentially caused by an out of date piece of software.

    Google or whoever owns Chrome would keep pushing new web standards at a fast pace to kill and bury any attempts to keep Firefox running. At that point there’s nothing really stopping them closed sourcing large parts of Chrome to kill privacy forks and lock down control of the web which most big websites would be fine with as Google’s interest is in getting through ads and preventing the end user from control over their own computer in favor of the interests of the website owner.

    It would be apocalyptic potentially for what remains of the open web and user freedom.


  • They’re not good, I admit that. But there is no better at present.

    Your choices are Google, Safari (Apple devices and OSes only), or Firefox. It’s as simple as that. Pretending otherwise is living in a fantasy land. There’s no easy road out of here realistically. New browser engines take years (perhaps the better part of a decade at this point) to make and the inherent complications of web standards and their volume means I regard things like Ladybird as a silly meme sucking up nerd and venture capital dollars rather than a serious endeavor.

    The effort to build a web browser from scratch today compared to 15 years ago has scaled massively and I think that’s intentional on the part of companies like Google and Microsoft to shut out the competition and to shut out small actors and to control the web for themselves and western governments.

    The last decent bits of Firefox are the ones holding back a tidal wave of bad things from coming to destroy the sickly remains of the open web in very quick fashion. Right now I can block ads, I can shut up my browser from phoning home, my browser isn’t made by an ad company, and it’s not made by a company that has a vested interest in completely airtight DRM because they own a video platform and/or are friends with big Hollywood studios (yes they implement DRM, no it’s not done as tightly as Chrome, the fact major streaming platforms restrict it to 720p should show you that).

    They’re not the hero we need, but they’re far from the worst villain and when they are gone much as I have criticized them we are going to be fucked because no one can replace them.

    The 90s ideals of an open internet that persisted into the 2000s that led to Firefox have vanished, replaced by various grifts that call themselves web 3.0. The illusion the liberal capitalist west was weaving of human rights and freedom which resulted in space for many good things is being clawed back now that their hegemony is under threat.

    Frankly I don’t see the EU or China or some large, benevolent, very wealthy organization stepping in to build a new browser that’s privacy respecting, not full of backdoors, not totally in the thrall of the worst corporate interests. And I don’t see Mozilla selling Firefox to some benevolent org. Not in the near term, in 8 years who can say but we’ll spend many horrible years wandering in the wilderness during that and the web will permanently enshittify in ways that Firefox could have at least slowed.

    I see two options in the present and they are Firefox somehow managing to continue to exist without completely compromising things to the point that librewolf devs and others give up because the soil is too toxic or it not doing that, collapsing entirely, stuffing itself full of ads and spyware that’s very hard to remove to attempt to stay afloat.

    It’s like shrugging at a law gutting union protections and saying “revolution, revolution, revolution” indifferently to the suffering coming down the pipe and the uncertainty when the conditions for what you want to happen aren’t near, when you’re staring down the barrel of worsened oppression and even the potential of salvation is years, a decade away. That’s how I regard people indifferent to Mozilla imploding.

    Do I wish there was a way to snatch Firefox away from them? Yes. But there isn’t. In fact if anyone was able to they could right now, it’s opensource and they could just fork and get to work and start making something better. The idea that the void will be filled by good things is “hand of god, hand of the markets” liberal capitalist brained thinking.

    Most people don’t give a shit about web privacy, about not seeing ads online, about controlling how websites display, about not having all their data sucked up or about companies pushing evil web standards that take away control and hand it to abusive governments and corporate actors so this isn’t going to lead to some revolutionary push-back, it’s going to lead to the collapse of the last militant hold-out for privacy advocates.

    Frankly I see a nightmare scenario where Chrome is bought by a company that takes it closed source (even partially) or buries the spyware and bad things in so deeply they can’t be removed by open source fork maintainers due to the burden while simultaneously Firefox either simply ceases to be developed or enshittifies and deploys its own ads and spying. At that point we’ll have nothing. There aren’t enough nerds who care about privacy to fund a privacy respecting, standards compliant web browser that manages to not be blocked by most websites. As it is if Firefox came out 5 years ago and wasn’t grandfathered in from their good old days of being a big boy player they probably wouldn’t have the sway they have on the internet standards council and would probably be blocked a lot more aggressively.

    Should Mozilla be restructured and stop acting in such a lousy fashion? Absolutely. Do I see any way for us random web users to force that? Not at all. It’s a lousy situation but one which can get much, much, much worse.


  • Literally the other way around.

    Mozilla can continue to be an irrelevant little NGO with a tiny little office in SF pestering people and shouting into the void and setting up booths at tech conventions on very, very, very little money. A few million a year, much less than they stand to be able to earn from their investment fund returns annually.

    Firefox on the other hand requires Mozilla’s hundreds of paid full time developers. Its codebase is nearly the size of Linux, as a browser it’s constantly patching security issues, adding in new features, fixing things that break for small amounts of the web, etc.

    There is simply no organization waiting in the wings that has the money and the interest in making a privacy-preserving web-browser that can just pick up that slack.


  • And with it the open web.

    If (and it’s still a big if) Google is forced to sell Chrome they’ll sell it to either Facebook, AltmanAI, Microsoft (lol), or else some shady tech company that has no reason to want to own it but is an even thinner rubber mask for the CIA/FBI/etc.

    This is why I’m sure it’ll happen (dooming hard). The US government wants web control and censorship and one big thing standing in the way is the open web Firefox fosters. Kill that off and the rest falls in line for corporate/government surveillance, control, and the end of anonymity and anything resembling free speech to the disliking of the aforementioned parties.



  • This is pointless burdening of small actors by big actors. On top of lets encrypt losing funding from the US government, it could easily collapse from strain like this. And then where are we? Back to the bad old days of very expensive certificates which will be even more-so with such a short validity period.

    Big tech doesn’t care, they never cared about your small site being encrypted against NSA spying or MITM by bad actors, they want everyone in their walled gardens and for people to spend as little time as possible outside of places like Facebook. Google will de-rank sites don’t implement encryption and if the costs for that go from free to quite expensive that pushes the free parts of the web like small forums, blogs, fediverse etc even further to the margins.

    Self-hosters who do things like hosting their own Jellyfin instance who require their own certs now have more renewals, more chances something breaks and if things like this push Let’s Encrypt under then that $5 porkbun domain you have for yourself and family is going to be $69 next year if you want to encrypt the traffic of all your linux isos being streamed.

    Better revocation processes and standards for browsers and apps to fetch and download revocation lists in a timely manner are needed, not this.

    This kind of frequency creates an incentive to set and forget automated processes and pay less attention to everything happening so when things break or security fails it’s catastrophic and not noticed.


  • Yes, absolutely. And they can drag Canonical into it as well if they wish though it’s harder. Being UK based doesn’t protect them from the long arm of US law including arresting any US personnel, freezing and seizing their funds, putting out arrest warrants for and harassing those in the UK with the fear of arrest and rendition to the US if they go to a third country (for a conference, vacation, etc, most would buckle rather than live under that). Additionally the US could sanction them for non-cooperation by making it illegal for US companies to sell them products and services, for US citizens to work for or aid them, etc.

    They can go after community led projects too, just send the feds over to the houses of some senior US developers and threaten and intimidate them, intimate their imminent arrest and prison sentence unless they stop contact and work with parties from whatever countries the US wishes to choose to name. Raid their houses, seize their electronics, detain them for hours in poor conditions. Lots of ways to apply pressure that doesn’t even have to stand up to extensive legal scrutiny (they can keep devices and things and the people would have to sue to get them back).

    The code itself is likely to exist in multiple places so if someone wanted to fork from say next week’s builds for an EU build they could and there would be little the US could do to stop that but they could stop cooperation and force these developers to apply technical measures to attempt to prevent downloads from IP addresses known to belong to sanctioned countries of their choosing.

    It’s not like the US can slam the door and take its Linux home and China and the EU and Russia are left with nothing, they’d still have old builds and code and could develop off of those though with broken international cooperation it would be a fragmented process prone to various teething issues.


  • Interesting project. Thanks for the link and I do appreciate it and could see some very good uses for that but it’s not quite what I meant.

    Unfortunately as it notes it works as a companion for reverse proxies so it doesn’t solve the big hurdle there which is handling secure and working flow (specifically ingress) of Jellyfin traffic into a network as a turn-key solution. All this does is change the authorization mechanism but my users don’t have an issue with writing down passwords and emails. Still leaves the burden of:

    • choosing and setting up the reverse proxy,
    • certificates for that,
    • paying for a domain so I can properly use certificates for encryption,
    • making sure that works,
    • chore of updating the reverse proxy, refreshing certs (and it breaking if we forget or the process fails), etc

    Which is a hassle and a half for technically proficient users and the point that most other people would give up.

    By contrast with Plex how many steps are there?

    1. Install (going to skip media library setup as Jellyfin requires that too so it’s assumed)
    2. Set up any port settings, open any relevant ports on firewall, enable remote access in setting with a tickbox
    3. Set up users
    4. Done, it now works and doesn’t need to be touched. It will handle connecting clients directly to the server. Users just need to install Plex client, login to their account and they have access.

    By contrast this still requires the hoster set up a reverse proxy (major hassle if done securely with certificates as well as an expense for a domain which works out to probably $5 a year), to then have their users point their jellyfin at a domain-name (possibly a hard to remember one as majesticstuffbox[.]xyz is a lot cheaper than the dot com/org/net equivalents or a shorter domain that’s more to the point), auth and so on. It’s many, many, many more steps and software and configurations and chances for the hosting party to mess something up.

    My point was I and many others would rather take the $5 we’d spend a year on a domain name and pay it for this kind of turn-key solution for ourselves and our users even if provided by a third party but that were Jellyfin to integrate this as an option it could provide some revenue for them and get the kinds of people who don’t want to mess with reverse proxies and certificates into their ecosystem and off Plex.



  • There is AFAIK no way to do this.

    Apple’s never open-sourced the APIs and interfaces and it only works on Macs and Windows. For this you will need to have either a Windows install (recommend separate drive so it doesn’t break Linux bootloader) or a persistent or not Windows VM with USB passthrough. I’m not even sure how well the VM situation works but it probably should. You don’t even have to have a license for Windows, you can just run it in the VM for this purpose alone but it does mean oh at least 40GB set aside on your drive for the VM image plus more if you want to do things like back-up the phone.


  • Jellyfin needs to partner with someone people can pay a very low and reasonable and/or one-time fee to enable remote streaming without the fuss of setting up either dangerous port-forwarding or the complexity of reverse proxies (paying for a domain-name, the set-up itself including certificates, keeping it updated for security purposes).

    And no a VPN is not a solution, the difficulty for non-technical users in setting up a VPN (if it’s even possible, on smart-tvs it’s almost always not, and I don’t think devices like AppleTV and other streaming boxes often support them) is too high and it’s an unwanted annoyance even for technical users.

    I’m not talking about streaming video’s through someone else’s servers or using their bandwidth. I’m talking about the connection phase of clients and servers where Plex acts like an enhanced dynamic DNS service with authentication. They have an agent on the local media server which sends to the remote web service of the third party the IP address, the port configured for use, the account or server name, etc. When a client tries to connect they go to this remote web service with the servername/username info, the web service authenticates them then gives them the current IP address and any other information necessary. It then sends some data to the local Jellyfin server about the connecting client to enable that connection and then the local media Jellyfin server and the client talk directly and stream directly.

    Importantly the cost of running this authentication and IP address tracking scheme would be minimal per Jellyfin server. You could charge $5/year for up to 20 unique remote clients and come out ahead with a slight profit which could be put back into Jellyfin development and things like their own hosting costs for code, etc. Even better if they offer lifetime for this at $60-$80 they’d get a decent chunk of cash up-front to use for development (with reasonable use restrictions per account so someone hosting stuff in Hetzner or whatever and serving 300 people with 400 devices will need to pay more because they’re clearly doing this for profit and can afford to throw some more money at Jellyfin).

    Until Jellyfin offers something that JUST WORKS like that it’s not going to be a replacement for Plex, whatever other improvements they offer to users it’s still a burden for the server runner to set up remote streaming in a way that isn’t either incredibly dangerous (port forwarding) OR either involves paying money to third parties AND/OR the trouble of running your own reverse proxy and/or involves walking users through complicated set-up process for each device that you have to repeat if you change anything major like your domain name when using a VPN.


  • Yeah GIMP is more than a decade behind Photoshop and a lot of other software in many respects.

    It’s frustrating. Basic things like content-aware fill for small spaces, not even AI generating huge things for large missing pieces but removing some text over a person’s cheek or plaid shirt, something in total 100x100 pixels big or so. Just doesn’t exist. You can clone stuff but it’s not aware of things like the gradient of a shadow that it should match or a highlight or other basic things so you’re left doing extensive work using layers and then cleaning it up to be visually acceptable using multiple tools over 10 minutes of time whereas Photoshop does it with one tool in an instant.


OSZAR »