mreiner
I’m not getting this, at least not yet.
Maybe it’s because I run Pi-hole; I know it filters out a TON of Roku’s telemetry and other traffic. Might be worth setting up Pi-hole on your network and see if stuff like that goes away?
Mozilla’s “least to most creepy” ranking is the best resource I’ve found so far:
https://foundation.mozilla.org/en/privacynotincluded/categories/cars/
I mean, if a car doesn’t see a cyclist until the last moment, swerves to avoid it, and hits something else, the cyclist being there created a dangerous situation for the driver.
Even just considering a driver hitting a cyclist, the driver still has to live with that outcome for the rest of their life. Unless your expectation is that the driver is a psychopath who only cares about the condition of their vehicle, which I suppose is a possibility.
When I had my homelab services exposed to the broader web, I enjoyed using Authelia with NGINX. It supported MFA and worked well enough.
That said, I HIGHLY suggest you expose as few of your home systems to the web as possible. Ideally, I would set up a VPN like WireGuard or OpenVPN and use that to connect into your LAN while on the go.
The more of your home network you expose to the web, the bigger your attack surface. If you can just turn on a VPN that already has strong authentication like asymmetric key pairs, you significantly reduce the ways someone can break into your home network while making as many (or few) of your home services available through that VPN as you want.
Respectfully, an article from four years ago that I cannot read in full without creating an account, which seems to just reference a calculator from FT that is over a decade old at this point (whose sources I also cannot seem to find) doesn’t impress me. Do you have anything more recent, preferably that sites sources, that you can share? I’m genuinely interested in what data is actually worth
Honest question:
If you feel these tools are essential and there are no other options (not sure I agree, but that seems to be the argument you were making; let me know if I am wrong), what is the alternative?
These things take money to keep the infrastructure running, pay staff, patch security vulnerabilities, and bring new features for those same communities to use. And they are also a public company, which means they have a legal responsibility to return money to shareholders.
I’m not defending Meta, I refuse to use their platforms and will not be buying any of their hardware. But if it takes money to keep the lights on (at a minimum), how does offering ads or a subscription equate to a false choice?
I also feel many don’t understand the full extent, either. They’re used to using fairly secure devices in their everyday life (often not realizing how much the software they install is also spying on them), so why wouldn’t these IoT things also be secure?
In my experience, it’s all very vague and ethereal until the risks are highlighted for them. “So what if Google can read all of my emails? What could they possibly do with that information, anyway; why should I care?” is an example of a portion of a real conversation I’ve had.
Thanks for the reminder to donate to Wikipedia!