• 0 Posts
  • 872 Comments
Joined 8 months ago
cake
Cake day: February 18th, 2024

help-circle

  • I get all that, and that’s why I feel weird about it.

    Some of the stuff they do only works well with scale, though. And I definitely think at least some other leadership groups would abuse their market position assuming that their critical mass would be very difficult to displace. If they had just agreed to piracy shield, do you really think corporate customers would be scared off?

    If I was doing actual stuff state level actors care about, I might still assume they’re not “safe”, but as a normal person? The fact that pirates can use their services reasonably safely and reasonably effectively definitely gives me a level of confidence that they’re unlikely to use their position in a way that harms me, maliciously or recklessly. I have a VPS as well and will eventually use that as a tunnel instead, so it’s actually end to end encrypted and I control the keys, but their consistent pattern of behavior doesn’t make me feel that much urgency about it.



  • They have me in a weird spot, because I fundamentally don’t really like the sheer volume of information they are MITMing at all times, and don’t really like the idea of letting them do so for my small site.

    But their decisions with respect to security threats pretty consistently seem well measured and as minimally invasive as they can be (eg they have intervened and rewritten content as a result of a supply chain attack, but were very transparent that it was desperate measures, that they didn’t really want to do it, and only did it by default for the free users that were most likely not to know enough to enable it themselves). They’ve also pushed back against stuff like piracy shield trying to turn them into outright surveillance for private companies.












  • They’re a good actual mechanism for spyware, because they see all your traffic.

    Https means that they can’t see the actual contents without installing a root certificate, but they can see all the sites you visit and for how long. Reputable providers (at least the good ones) do not log any of this, but you should have a high level of trust in a provider to use their VPN, because they see a lot still.

    That doesn’t mean that they didn’t ban legit VPNs. I don’t know. But it doesn’t really qualify as “reporting news” without at least a list of the apps that were banned, because they’re providing no information at all about the legitimacy of the apps, and it’s a category appealing to bad actors.





  • There are Android ereaders. They’re mostly Chinese manufacturers, and I’ve heard more than one doesn’t follow the GPL properly with their modifications to Android, but the end result is freedom to use a variety of sources of books (including Libby and Hoopla from the library, among others).

    I haven’t played with parental controls to know if they’re easy to access, but my most current Boox came with the play store installed and it’s pretty easy to learn how to adjust the display settings for different apps with different types of content.