• 2 Posts
  • 98 Comments
Joined 9 months ago
cake
Cake day: October 20th, 2023

help-circle
  • I can’t speak to their Password Management as I use Bitwarden for that

    But I am slowly but surely migrating myself away from gmail to (my own email at my own domain routed to) Proton. The webmail is very much comparable to gmail and, if you communicate with like minded people, it has decent support for signing and even encrypting email both to other proton mail users as well as to complete randos with just a password that you can send later. My only real complaint is that (… for some really good reasons) there is no easy to use exchange server and I need to run their mail bridge to use a desktop client like Thunderbird to send and maanage and (one day) back up emails.

    VPN? I switched over to this around the same time I decided I wanted to “take control” of my email and it works pretty well. Very easy to get some openvpn credentials that I can plug into whatever setup I want. And no extra fee for port forwarding unlike SOME providers. That said, my main complaint is that the port is semi-randomized which doesn’t play the nicest with my totally legit linux iso torrenting setup… But a quick docker ps and docker logs and then updating the config is pretty trivial and I only have to do it maybe once a week?

    The big elephant in the room is that, as you rightfully understand, you are still putting a LOT of trust. But that is actually why I like Proton. Because other companies pretend they are going to knife fight the CIA and the US Government on your behalf all while actively not acknowledging anything until we get a post mortem. Proton are VERY open about just how far they are willing to go to protect you (not very) and what YOU can do to mean that Proton can’t provide much useful information once the appropriate paperwork and legal actions have been filed.

    I wouldn’t trust a paid account with anything more sensitive than what really innovative stuff a friend did with a bun in the dumpster behind the Wendy’s the other night. But, hypothetically, if I needed to send an anonymous email? Third party VPN/Tor, clean hardware, and a free Protonmail account works great and I do trust Proton to give the absolute bare minimum in that case.


    And just for a bit of context. My “grand plan” is to migrate the vast majority of my correspondence and accounts to email addresses tied to one or more of my own domains. Currently I plan to use Protonmail for the mail server because I don’t want that smoke. But the point is that I control the email address so I can get my Heat on and walk away in 30 seconds (actually more like a few hours but…).

    Which is why the other aspect of that is that I want to back up the emails I actually want to save (rather than just EVERYTHING like those of us with older gmail accounts do) via a local client that I then archive to an encrypted volume on my NAS and (REDACTED) after that.




  • I guess I am not getting it.

    If you can access your files, you can copy your files. If the concern is that you only know how to connect from a full PC, consider plugging a laptop into the switch (or even just set up a VM).

    Hard to give much more help without knowing your actual setup. But one nasty solution is to ssh into the server then connect to the running container (or mount the same storage into a different one) if there are some shenanigans going on there.

    But yeah. My general rule of thumb is that if something needs to outlive the life of a container then it is being stored on the local filesystem or a zfs/ceph pool.



  • I selfhost my own nextcloud for notes and documents that I would like on my phone but not via google.

    It is not a google docs/gmail/whatever replacement. They’ve spent the past few years hardening it and pushing for all the hallmarks of enterprise first software (e.g. making it a complete fustercluck to not have a proper domain name) but you still have stability and performance issues and the occasional upgrade issue that fucks up everything


    I would also point out that if you aren’t selfhosting, what are you actually getting out of this? You are just spreading your data out to other companies who are often less transparent about how they monetize you.





  • The “vibe” doesn’t really matter. You are getting paid to do a job, you are gonna do it. You can’t refuse to write documents because you have to use Word instead of Google Docs or whatever.

    No, it really is the training. Because the most obnoxious thing in the work force is an old white guy. They can’t outright say “no”. But they will do everything in their power to talk about how EVERYTHING is a blocker and they can’t get any work done because nobody wanted to teach them something. Or nobody was able to answer the questions that they refuse to ask. And so forth.

    Having a database of training videos or even an outsourced consultant goes a long way toward “Hey Jon? Nobody gives a shit. Do your job”. Whereas having to link to just a document or explain something yourself is how they will actively refuse to ever retain any information.



  • My buddies and I have worked at companies that went through similar transitions and reversions.

    The issue is not the cost or even the ideology. It is the training and support. There are a LOT of really good training resources for MS Office and, at least for millennials, outright education in k-12. So, by switching to libre office or anything similar, you are suddenly putting a large burden on yourself and random enthusiast youtubers who will start advertising nordvpn partway through explaining what a pivot table is. Because the vast majority of people don’t know how to google “how to edit the footer for slides in Libre Office”

    And that RAPIDLY adds up to being a lot more expensive than even the full priced licenses from MS. your more technically competent staff suddenly have very large support burdens because “Oh, I just have a quick question” and that increases their burnout.

    That said, it is going to be really interesting in the next 5-10 years (… assuming the world doesn’t end in a series of thermonuclear explosions first) since gen-z are very much brought up on Google Docs and the like. So even MS Office will have a significant training overhead for new hires.


    At one of my other jobs we had to migrate a codebase from SVN to Git. it… was incredibly overdue and it was making for a greater burden on new hires who had to learn an antiquated toolset to contribute. But it was a genuine concern because most of the existing developers who understood “where the bodies were buried” had already “suffered through giving up on CVS for no good reason”. And we genuinely had to acknowledge that we would lose staff “on both sides” and, while I am not proud to admit it, more or less set up a few underperforming early career staff to be sacrificial lambs. Making it a point to let Old Fuck #5 know that the guy who was struggling to understanding how to write performant kernels was available to work through how to write a commit message. That way the rock stars who we were dependent on would not put in their notice.




  • Gotta love that Rossman has pivoted from “failed business owner” to “basically James Stephanie Sterling but with less nazi imagery”

    Shit like this REALLY annoys me. I am all for a discussion of the ethics of piracy… if people actually understand what ethics are (and, as has been demonstrated countless times, people don’t). But shit like this is about deciding when it is “fair” to pirate content and when not. And, considering it is Rossman, I assume he is goign to talk about how you should support companies that care about your rights or are small businesses and fuck larger businesses and the New York City government.

    But the reality: Whether you think piracy is or is not stealing is irrelavent. It is piracy whether you are pirating a game from a toddler with leukemia or Amazon after they rebranded to having the website be a giant picture of Bezos’s dong. It just becomes a matter of if you think that matters or if it is okay to hurt/“hurt” one of those companies.

    Which almost inevitably becomes about defining The Tragedy of the Commons.

    At the end of the day: it is piracy. We are pirates. Fucking own up to it.







  • Yeah. I have a LOT of issues with Tor’s design. And the philosophy and its tendency to be used for heinous shit like CSAM makes me just not want to deal with it. Why should I help mask the scum of the earth’s behavior?

    And while it has historically been used to protect some journalists and activists, Signal, twitter, and proper opsec/dedicated hardware have very much taken over for that. In large part because people have realized that masking your route to a destination doesn’t help if you are connecting from home and have been identified at the destination.

    But people get REALLY pissy about Tor. Likely because it makes them feel smart to be “one step farther”.