Avatar

slock

slock@lemmy.world
Joined
0 posts • 11 comments
Direct message

Il y a aussi meteociel, qui expose directement les résultats des différents modèles, y compris maille géographique et temporelle assez fine (par forcément à 10 minutes, mais au moins à l’heure ). Point bonus, on peut choisir le modèle qui marche le mieux (vers ici, météo France est toujours à la ramasse, mais Arome s’en sort plutôt bien sur 24h)

permalink
report
parent
reply

Covid did hit the small villages and such very hard around here. These villages are mostly living on tourism, and are not exactly the most profitable. 2 years with huge drop in revenue closed down a lot of these unfortunately.

permalink
report
parent
reply

I’m a lefty too, I recently found the Lamy safary has a left handed version that I can actually use ! Their ink also dries rather quickly, so if you whish to give it a shot again, it’s been night and day for me. Much better than the overpriced crap they sell in general stores that I could never use, or that would simply go through the paper thanks to highly diluted ink…

permalink
report
parent
reply

That’s pretty much what DRM does, keeping us out of the inner working of stuff

permalink
report
reply

That’s pretty much what DRM does, keeping us out of the inner working of stuff

permalink
report
reply

I’ve seen this news published at a few different places, and IIRC they plan to use already existing exploits. You can read a bunch about what could potentially be used on the grapheneos website, specifically on how the modem and cellular network stack is very highly privileged on android at least, and it is very likely that most cellphones are vulnerable to some kind of code injection via a stingray, for example.

permalink
report
parent
reply

It is also a huge deal because since (at least in France) the government forced ISPs to log DNS queries, a lot of browsers (and latest android and iOSversion’s) have now migrated to DNS over https or TLS DNS, which means that the only clear text DNS query they can intercept is the one to fetch your secure DNS service address. Now, having a trusted CA installed in browsers means that they can also spoof the identity of this secure name service, and regain a bit of control.

They invested a lot in surveillance technology (for both good and bad reasons), and https, DNS and encrypted messaging / phone calls means this was all for nothing.

And yes, by being authorized as a trusted CA, you can effectively spoof pretty much anything by setting a proxy. Some tools even leverage this for app analysis. Look up mitmproxy for example, or squid. A lot of companies already do this to inspect inbound / outbound traffic.

permalink
report
parent
reply

It does, don’t remember the details but at one point I let a packet capture tool on my phone run for a few days and checked which apps phoned home. Gboard was one of them. You’d besurprisesd at the amount of network traffic for most apps between 2-4 am.

Just remove its network permissions, and it works fine (without the phoning home part) AFAIK other spell checkers / autocomplete aren’t quite there yet

permalink
report
reply

The massive influx of new ratings could also simply be linked to the fact that the game is included in this month’s humble choice, adding a ton of new players

permalink
report
reply

Graphene user here ! The privacy and security gains are quite huge. Play services are more or less regular apps, with the sandbox offering limited access. Some of the “advanced” security offered by graphene triggered a few times for me, sometime highlighting something sketchy in some apps.

Also, you can disable the internet permission for apps, which can effectively block a lot of stuff (ex : you install a supposedly offline game, but it stills asks for the permission: denied).

If your main concern is not depending too much on Google, your options are limited, and very, very flawed depending on how far you whish to go (went far down this rabbit hole, came back). One less “extreme” way, using graphene, is to install play services and everything dependent on a separate user account, and clone app from this account to the one you will use. Since alternate accounts are sandboxed and not running when not logged in, when you use your phone from the main account, you will effectively be almost goggle free.

Almost, because the main remaining privacy hole is notifications. A lot of things goes through GMS in order to reach your phone without melting your battery

permalink
report
reply