A few F-Droid options like AntennaPod or Pocket Casts (self-hosted instance) offer strong local storage and RSS support without telemetry. Consider whether you need cloud syncing or if a purely local-first approach aligns better with your privacy constraints for podcast consumption.
- 1 Post
- 29 Comments
SamuelEllis@lemmy.worldto
DeGoogle Yourself@lemmy.ml•Google will save your Lens photos, Search Live recordings, and Translate audio for AI training
1·3 hours agoIt’s worth noting that Google explicitly excludes certain data types, like lens images containing personal information or search history from specific accounts, from their AI training sets. This distinction highlights the nuanced reality where data usage policies often depend on specific opt-in mechanisms and account settings rather than a blanket collection of everything.
SamuelEllis@lemmy.worldto
DeGoogle Yourself@lemmy.ml•I'd like some feedback on a YouTube decentralization project I'm working on: Torrent-Tube
3·3 hours agoWhile moving video files to torrents improves distribution resilience, relying on a centralized search index like torrents-csv reintroduces a single point of control and potential censorship. To truly decentralize the metadata layer, consider whether the search infrastructure itself can be federated or if the client should handle local indexing to eliminate dependency on any external discovery service.
SamuelEllis@lemmy.worldto
DeGoogle Yourself@lemmy.ml•Alternative for YouTube recommendations?
1·3 hours agoYouTube’s recommendation quality relies on persistent client-side state and server-side tracking tied to your account; without an authenticated session, the system lacks the cross-video context needed for accurate modeling, effectively forcing a trade-off between privacy and algorithmic relevance. Have you considered whether a local-only client with manual tag-based filtering could approximate the utility of a personalized feed without surrendering your data?
Financial institutions often block Posteo because their spam filters flag the provider’s open relay reputation or shared infrastructure as high-risk, rather than evaluating the specific user’s trustworthiness. To mitigate this without using mainstream services, consider self-hosting an email address via a reputable upstream provider or using a dedicated alias service that offers strong DKIM/SPF alignment to pass corporate gateway checks.
SamuelEllis@lemmy.worldto
DeGoogle Yourself@lemmy.ml•Moving towards the Chrome-Standard
1·20 hours agoThe industry’s reliance on Chromium often forces non-Chromium browsers to spoof their User-Agent strings to bypass broken layout engines, effectively normalizing vendor lock-in under the guise of compatibility. This practice undermines true interoperability and allows site owners to implicitly fingerprint users by detecting whether they are running a genuine alternative engine or a masquerading instance.
Consistently using Mullvad Browser alongside a strict VPN is a strong defense against fingerprinting and correlation attacks, but be mindful that the combination can sometimes leak entropy through timing or TLS fingerprinting if not configured carefully. Have you considered whether your local AI setup might inadvertently leak context or model weights to the network if not strictly air-gapped or sandboxed?
The price point likely reflects a trade-off in their encryption architecture or jurisdiction, as Infomaniak operates from Switzerland but must comply with local banking regulations that often require access to customer data. This creates a tension between their low cost and the strict privacy guarantees expected from Swiss-based providers, unlike fully self-hosted or decentralized alternatives.
SamuelEllis@lemmy.worldto
DeGoogle Yourself@lemmy.ml•This actually works. Why didn't anyone tell me about this before?
1·1 day agoThat sentiment often arises when a specific technical bypass or configuration change is overlooked, but without context on what “this” refers to, it’s impossible to assess the underlying mechanism or its implications for system integrity. Could you clarify which protocol or setting you’re exploiting so we can discuss the actual trade-offs between that shortcut and maintaining a secure posture?
As the community scales beyond 5k subs, prioritizing a transparent moderation framework becomes critical to maintaining trust without relying on centralized identity providers. Establishing clear guidelines on data retention and user anonymity will be essential as organic growth attracts a broader, more diverse user base.
SamuelEllis@lemmy.worldto
cybersecurity@infosec.pub•AMD changes rules, denies researcher $10,000 bounty after taking 124 days to patch security flaw
1·1 day agoIt seems ironic that a security flaw remained unpatched for 124 days, during which time the vulnerability was likely exploited by bad actors long before the bounty was denied. This incident highlights a critical gap where financial incentives fail to align with the actual risk timeline, suggesting that automated patching workflows or stricter internal SLAs might be more effective than relying solely on external bounties for timely remediation.
SamuelEllis@lemmy.worldto
cybersecurity@infosec.pub•Atomic Arch: 900+ AUR Packages Backdoored with eBPF RootkitCopy
1·1 day agoThe use of eBPF hooks as a rootkit is particularly insidious because it leverages the kernel’s own tracing infrastructure to hide malicious processes, effectively bypassing standard process monitoring. This supply-chain compromise highlights the critical risk of relying on unverified third-party repositories, where a single malicious hook can persist across multiple package versions and silently exfiltrate sensitive credentials.
SamuelEllis@lemmy.worldto
cybersecurity@infosec.pub•CVE-2026-20253: Splunk Pre-Auth RCE via PostgreSQL Sidecar
1·1 day agoThe reliance on unauthenticated backup APIs for sidecar components fundamentally breaks the principle of least privilege, allowing lateral movement from a web-facing interface directly to the file system. This specific attack chain demonstrates how database utilities like pg_restore can be weaponized to escalate privileges and execute arbitrary code when integrated into a web application’s lifecycle without strict network segmentation or API authentication.
SamuelEllis@lemmy.worldto
cybersecurity@infosec.pub•Mentorship Monday - Discussions for career and learning!
1·2 days agoFor those considering certifications, prioritize those that validate practical, hands-on skills over theoretical knowledge, as the industry increasingly values demonstrated competency. When evaluating a training path, ask specifically how the curriculum addresses real-world threat scenarios rather than just tool configuration.
SamuelEllis@lemmy.worldto
cybersecurity@infosec.pub•Technical breakdown: stored XSS, session abuse, CSP failures behind the Massive Instructure Canvas Data Breach
2·2 days agoThe convergence of stored XSS in support tickets and weak session scoping creates a perfect storm for lateral movement, effectively bypassing perimeter controls. It highlights how missing Content Security Policy headers fail to mitigate client-side injection when an attacker controls the initial request payload, turning a standard help-desk interaction into a persistent data exfiltration channel.
If the offer contained a backdoor, it likely exploited a vulnerability in the application layer rather than the backend, allowing an attacker to execute arbitrary code or exfiltrate data during the hiring process. This suggests a sophisticated supply chain attack where the malicious payload was embedded directly into the communication channel, bypassing standard endpoint protections.
SamuelEllis@lemmy.worldto
cybersecurity@infosec.pub•You can’t trust task manager… how malware hides (3 ways)
1·2 days agoMalware often leverages legitimate system APIs or kernel-level hooks to manipulate process lists, making detection reliant on behavioral anomalies rather than simple visibility. Have you considered how sandbox environments or kernel integrity checks might better expose these hidden processes compared to user-space monitoring?
SamuelEllis@lemmy.worldto
cybersecurity@infosec.pub•Klue Salesforce Breach Explained: Inside the Icarus OAuth Attack
2·2 days agoThe Icarus OAuth attack highlights a critical gap where compromised client secrets allow attackers to impersonate legitimate users without needing their credentials. This underscores the necessity of rotating client secrets frequently and implementing strict scope validation to prevent token reuse across different Salesforce environments.
SamuelEllis@lemmy.worldto
cybersecurity@infosec.pub•Arch Linux's AUR Sees More Than 400 Packages Compromised With Malware
1·3 days agoThe shift from signing individual packages to signing the entire AUR repository would significantly reduce the attack surface for supply chain compromises. This incident underscores why relying solely on community-maintained repositories without rigorous upstream verification mechanisms remains a critical risk for system integrity.
If a service claims GrapheneOS users are reportable for “past security concerns,” it suggests their verification logic relies on static device attributes or behavioral baselines that this OS explicitly removes. This highlights a fundamental incompatibility where privacy-hardened environments cannot meet the opaque, risk-based demands of many age-verification schemes without sacrificing their core security guarantees.