Random nerd who has an interest in computers, privacy, AI, videogames, and CDs. I also like dogs and horses.

Website: https://cambionn.nl/

Mastodon: https://mastodon.nl/@Cambion

  • 0 Posts
  • 19 Comments
Joined 3 years ago
cake
Cake day: June 8th, 2023

help-circle
  • I didn’t mean to say the translation might have said “Kursive”, just that the translators might have mixed that up due to the word existing (al be it rarely used) and being similar. Which as I said, is still horrible translating.

    It was just meant as an explanation what might have happened to make them translate it to that, especially if the translators aren’t native speakers. My partner is now learning Dutch and I noticed some study books are full of these kind of bad translations, both in using rarely used words and using simply the wrong words. And to add to that, Americans trying to do Dutch is even worse, especially on TV shows 🥲. Most of the time they feature “Dutch” it’s impossible to know what they’re trying yo say, and if you do understand it still makes no sense in grammar, the words used (and made up), nor the pronounciation. Might be a bit better for German as the language is more popular worldwide and at least you don’t have our “G” sound, but I wonder by how much. So I can totally see even a profesional non-native translator wrongly translating the english “cursive” to “kursiv”.


  • “Kursive” (with an “e”) technically means the same as “Schreibschrift” (aka handwriting developed for quick penning, generally attached). “Kursiv” (without “e”) in turn means “italic”. But despite being technically correct German it isn’t commonly used.

    It’s just like how in Dutch we do also have the word “italiek” for italic fonts, but it’s rare to see it used and we generally use “cursief” (whereas what is called cursive in English is called “schrijfletters” in Dutch). Both are technically correct Dutch, but the first you will pretty much never see used by native speakers.

    I guess American shows sometimes find these kind of rare-but-technically-correct words when translating and run with it without realising no one actually uses that word. Which is indeed bad translating.


  • It also works well for the “new to Linux but interested in it and tech-saffy enough to learn quickly” people. For those it’s an easier and fuller start-up than an install with the archinstall script that they can use right away while learning along the way. It makes it a good beginner distro for die-hard nerds, but I wouldn’t recommend it for those not interested or tech-saffy enough to handle such an approach.

    But yeah, I agree the main users are those who like the Archiness but want something that “just works” most of the time. Not necesarrily because they can’t maintain it otherwise, but because they don’t want too. The first group I mentioned can transfer into this one over time, while at other times switching to Arch itself or more thinker-friendly Archbased distros.

    That group is relatively big however, big enough to create some market at least. It’s why I still run it on many secundairy devices, less maintaining but keeps working. At the same time I know some who run it on their production machines for that, while thinkinger with Arch on secundary devices. Once they got a setup they like enough and figured it’s exact requirements, they alter Manjaro to it.

    I guess something like SteamOS is better for Archi but for nontech-savvy people. I can give it to my niece and she can use it, but due to it being immutable (unless purposely turning that off) and getting updates from Valve she won’t break it easily. That is; OS-wise. While actually running the games tends to “just work” most of the time, the times it doesn’t are too often and the thinkering then needed too complex to make it suitable for that group of people.



  • If you check the link I posted (which is the non-discussion thread that explained the situation) it has the updates. Most come from dennis1248. On Matrix he also confirmed those are the latest updates, altrough that was a while back already. I don’t check that Matrix chat that often. So while the owner (Phil) hasn’t replied publicly since, there are updates from the people who started the manifest about what’s happening behind the scenes since.

    Last update I know of was the one late June, mentioning nearly finishing all the legal paperwork for setting up the non-profit entity (where they updated us before to take longer than expected due to the complexity of writing legal stuff taking longer than expected).


  • Cambionn@feddit.nltolinuxmemes@lemmy.worldtil about manjaro
    link
    fedilink
    arrow-up
    5
    arrow-down
    1
    ·
    edit-2
    5 days ago

    Outside of what Hamsda said (to which I’ve added some context), the thing with Manjaro is also that it’s target is easy usage which attracts beginners. Now that isn’t bad per se (it was my first distro too, and I still run it on some machines. I’m not a hater) but it does become a thing when those people go to Arch-related spaces (like the Arch forum or the AUR comment section) asking Arch-people for help.

    For one, Manjaro isn’t Arch. It may be based on it, but it also has it’s differences. It’s better to ask on the Manjaro forums. Why some Manjaro users go bother the Arch forums I never understood. The Manjaro forum is very helpful, quick to react, and more appropiate. No reason to divert really…

    And secondary, Arch is a distro aimed at more advanced users and has a “know the basics, read the documentation, understand it, and try stuff yourself. And if you thén still don’t know you can ask” expectation. Since Manjaro attracts beginners, the questions they ask are often not only about a different distro, but on the level Arch expects you to be able to figure it out yourself making it rather a nuicance (after all, they’re asking beginner questions in a space for advanced users). Manjaro users doing that somewhat regularily gave it a bad reputation.


  • The “internal struggle” was actually related to the rest and (hopefully) sorted out the other issues.

    The tl;dr is that Manjaro was setup as a company with one owner who often didn’t do what he was supposed to and no one else had access to do it. This caused issues like the SSL stuff but also other things. Obviously this made quite some volunteers leave over time, but as the distro itself is actually quite nice also a bunch didn’t want to give up that easily. Those pretty much gave that one person the choice to transfer the distro to a new to-be-made non-profit (leaving only the commercial activities in the company) or they would leave (and likely fork it or something). He agreed and they’re now in the legal process of setting up the non-profit, where important things will not be in the hands of a single person.

    So all with all it was a bit messy, but it seems they got it sorted out now. That should also prevent issues like they’ve seen in the past. So with that I wouldn’t recommend against the distro. I still have it on some secundairy systems, where my main one (I need to say this naturally) got switched during the drama to run Arch (btw).

    You can read more here: https://forum.manjaro.org/t/manjaro-2-0-manifesto/186171



  • Average Joe wants an easy all-in-one solution. That’s what Google, Apple and Microsoft offer. An ecosystem. If you want to fight that, you need to be able to offer that. So that’s what Proton is doing.

    Of course it’s better to have it seperated. And the security and privacy nerds will likely keep doing that anyways. But Average Joe doesn’t want to take a hassle and rather looses privacy than do that.

    Issue is, things are only as secure as the least secure point. Average Joe using Google and Microsoft means your data also goes there when interacting. When Average Joe is swayed by a place that is privacy-friendly ánd convinient, it makes your weakest link also stronger.

    Meanwhile, Average Joe is also more save then when he was using Google or Microsoft services. Even when he would be less save than if he had his stuff seperated.

    It helps everyone.

    With that in mind, I applaud it. But I won’t use it. I use Proton for mail, Joplin for notes (encrypting them in Joplin and syncing with NextCloud), and my passwords are also elsewhere than ProtonPass.


  • For one, USA isn’t actually much better than China when it comes to tracking and privacy. They just have better PR about it. But in reality they equally suck.

    That asside. There isn’t some secret tracking chip, but any kind of wireless network will be used to track you by different parties. Cellulair, Wi-Fi (including Wi-Fi signaling when it’s “off”), Bluetooth, etc. This is a fact regardless of OS or where the phone is made, as tracking often already starts to occur by catching the signals you send out.

    As such, just degoogling won’t resolve tracking issues in and off itself, it’s just one of many steps to get less tracking.

    Phones physically in China, regardless off where it’s made, tend to get tracking software installed. Just take a burner if you ever go there. But that’s not hardware. And most “USA” phones are also made in China anyways…


  • TPM on my motherboard is forever disabled

    If that’s just to stop W11 that’s stupid. TPM chips are security related. Disabling them has some serious drawbacks.

    Now there are discussion on if you’d even want a TPM chip or not, and if you choose not to use it for such reasons it may be a well thought out decision. Then you won’t hear me complain. But to trow out security components just to prevent an update, without looking at the possible consequences, is stupid. There are better ways to prevent that anyways.


  • Funny. My grandpa has been using Thunderbird and Libre Office for years, and he never realised it until recently (and he uses it a lot). He recently had an issue for the first time and asked me as he was trying to fix it with Microsoft but didn’t get anywhere, and I had to break the news to him it wasn’t their product.

    I’m not the one who set it up for him btw. But whoever did so made it look as much as to make it easier for him to switch. Which worked as he had no clue and thought he got some free version or so.

    I do also use it, but my setup isn’t Microsoft-like per se. I’m rather happy with it tho.


  • My issue is more with trackers than ads anyways, altrough ads that block so much that using the site normally becomes a pain in the ass are the other extend which is sadly also getting more and more common. But sadly most websites and services that let you pay to get rid of ads will still put everything full of trackers…

    Also, there are quite some sites that just copy content or or have an AI write content, made to rank high in searches, then is putbfull of adds to make money. Those are automated money-farms, and deserve blockers.

    I block everything, ads and trackers alike. Somewhat regularily I’m on the web without and it’s always a great reminder why I normally do use them.

    But I also pay for multiple websites and services I use regularily despite them working fine without paying or having “free” alternatives. After all, nothing is free and I rather pay with money than with data. And I also want to be paid for my work, and I can only imagine so do others. So I do agree with you there, and I highly encourage people to pay for stuff.

    But I won’t feel bad for blocking that shit, also not on the websites I don’t financially support. Because most of the time they are the ones that made it impossible to use their website privacy-friendly without blocking stuff anyways, even if I’m willing to pay.




  • Privacy is not a black & white thing. Every step you take matters. And being entirely private without digital footprint is impossible unless you isolate yourself from the internet entirely.

    To answer your question. Yes, they spy on you. To what degree depends on the OS and your settings. But they always cost you some privacy.

    But it’s never useless to take other steps just because you don’t want to or can’t switch OS. Because you’ll still give them less data if you do. They might still have info on you. But the less, the better.

    Taking easier steps like switching mail provider and other services you use to privacy-minded ones are a good and easy start anyone can do. Replacing apps/programs on your system with FOSS or privacy-minded ones is another good one.

    Even the biggest noob can make a Proton account and use it instead of Gmail/Outlook. Use 1Password instead of your device/browser’s password manager. Use LibreOffice instead of MS Office. Check F-droid for apps before Google Play (and perhaps even use Aurora when you do need it). Use FireFox instead of Edge or Chrome. Install a FOSS keyboard on your phone. Get rid of Social Media. Use Signal instead of WhatsApp. Those are just some example of easy my-grandpa-can-do-this level of difficulty options that already greatly improve your privacy (in fact, after I installed it for him, my grandpa does many of these!). Is it as private as an extremely hardened custom device by a security expert? Nah, but it’s definitly much beter than a default device full of big-tech apps. Even if you just do 1 of them!

    Since every step counts, I think we should apploud people for caring and starting to take steps instead of deminish them for not going in to the max. Changes like this are slow, especially with a big mass of people. The more people show they care, the more privacy-minded alternatives grow and show up and the more normal it becomes to care about privacy.


  • Well outside of the general open source and E2EE stuff, there are a few more things.

    They’re under a non-profit foundation and charity to which donating is tax-deducatble. That means they have to publicice their financial numbers. Selling data would generate a sudden revenue, which would draw attention.

    They also regularily do external audits, both from external audit organisations as individuals. This list was made in august 2022, you can likely find a newer list somewhere. I just did a quick search for you. https://community.signalusers.org/t/overview-of-third-party-security-audits/13243

    Signal also runs perfectly fine without anything Google btw. It uses PlayServices only if you have it on your phone (otherwise it just uses WebSockets), as it preserves battery life. However, it doesn’t actually send data to Google over PlayServices. Instead it sends an empty notification, which wakes the phone and is recognised by Signal as a trigger to make it connect to Signal servers to grab data directly from there. If you wish, you can check this in the code yourself. I guess you may also be able to confirm this looking at network traffic from and to your phone.

    Also a note on the E2EE. Another important thing is that not only the message is encrypted, but also the metadata. Unlike most other chatapps like WhatsApp; who knows where you are, who you talk to, how often, etc. You could theoretically also check this by checking outgoing traffic if you wish.

    This also means that unless they somehow secretly have a copy of your private key, there is no data for them to sell anyways. The fact that even in court they’ve didn’t have data to show, them passing many external audits without this being a point (sometimes issues are found, which is normal. If audits are always perfect I’d be more warry. But never on this point afaik), and that nothing in the code nor internet traffic points to them possibly having this, makes me not that worried about the idea that they secretly got a copy of peoples private keys.

    So overal while it’s perhaps technically possible they secretly run something else on their server and build a back door to read your messages, they are many things that show they don’t, and literally nothing that would say they do. And neither does there seem to be any reason why, since they can’t sell it nor give it in court. So unless you believe they have some evil bigger plan, I don’t see the reason to doubt.

    And a little note. Privacy people can be crazy, and I say that in a positive way! If you can check it, people no doubt have, and issues would’ve been found. Yet many people deep into it still vouch for it. That says something. And the less crazy people profit of this. This is similar to why many big FOSS projects are considered safe even if you didn’t check all code yourself. And before you say “but if everyone thinks like that”, realise that the craziest don’t trust other people either. While smaller projects could hide perhaps, the real big/famous projects like Signal, Linux, LibreOffice, etc would fall trough as soon as they start doing shit.


  • Cambionn@feddit.nltoPrivacy@lemmy.mlBest VPNs
    link
    fedilink
    arrow-up
    1
    ·
    3 years ago

    Yup I got the whole Proton suit mainly for email and calendar, but use the rest too for specific use-cases.

    I also like that Proton has a few VPN servers with adblocker and tracking blocking built in, so you can use the default DNS and have the same settings as other users which helps with avoiding fingerprinting while still having an easy system wide adblocker and tracking blocker.