

How time-consuming would doing it yourself be, if anyone here has tried?


How time-consuming would doing it yourself be, if anyone here has tried?


In my opinion, the reward for rooting LineageOS is pretty limited for having to risk one of the more important aspects of the Android security model, since the base system is already decently clean. If you want to go the extra mile, you could try installing the LeOS GSI, which strips out the remaining pings to Google servers (see LineageOS column of the table).
Definitely double check if the build you use has anything weird configured, but modern LineageOS (and Android in general) should already have good encryption by default. Not sure if LineageOS already has a way to toggle per-app network access, but if not, take a look at RethinkDNS, does a fine job without root.
Not much you can do about the unlocked bootloader, but as long as you aren’t being targeted by some agency, sticking to trusted sources like F-Droid for apps will go a long way. I have a similar approach with two phones and minimal personal data stored on each, so I’d personally approve of those elements.
Faraday cage might be of interest with regard to the iPhone since those can still function as their own AirTags even when powered off. But modern phones are surprisingly sensitive to signals so the slightest imperfection, especially in cheap Faraday bags, could give you away. While you’re at it, make a threat model to see if Faraday cages are necessary for your needs.
Same, too many clocks, all getting out of sync, and some on power strips that get turned off periodically.


I was thinking something on those lines the other day. We like to say that Linux revives old computers, and I wouldn’t for a second consider putting Windows back on them, but I also have a case of hardware support so close, yet so far. I’ve two old laptops with nvidia chips from before the days of Optimus switiching, so you are forced to use the dGPU. Believe me, I wasted a whole weekend trying to make them use only integrated graphics. It was fine while they were supported under the proprietary nvidia driver, but as soon as support ended, nouveau became the only option and it absolutely crippled 3D performance, even on very old titles. Meanwhile, Windows still supports the old 340 driver needed for those graphics chips.
Mostly comes down to hardware vendors not bothering with Linux support and open-source in general. Which leaves support for affected devices down to volunteers having time to reverse-engineer a driver from scratch. To be clear, I don’t blame nouveau at all. It must have been a ton of work to even get the nouveau driver to its current state.


Another common mozilla L
Back in the early 2010s, I bought a new PC with Windows 8 on it. Hated the way it looked and the way it worked. I wanted my Start menu and Aero and Classic themes back. Led me to learning about Linux. But uxTheme and Classic Shell kept me happy for a couple more years.
Then I got a laptop with Windows 10. Felt my heart rate spike as I went through the settings and found out how much more hostile to user choice and privacy Microsoft had become. When the semi-annual updates kept undoing all my hard work debloating Windows, I decided it was time to begin using Linux in earnest.
At first, I had a dual-boot setup and jumped around between Ubuntu, Deepin, Arch, etc. Found myself booting into the Windows partition less than once a month, at which point I moved it out onto its own drive. Distro-hopping went on for about a year, after which I decided that Debian met all of my needs. Continued DE-hopping for about another year until settling on XFCE with Chicago95. Brought me enough joy to make a standardized setup in a VM, which I have since cloned to all of my computers except for the Windows laptop I keep around for work.


Mixed bag. I’m lucky enough that most of my work can be done on a Linux machine. Workplace does require us to bring our own devices, but the policy is extremely lax, no need to install any monitoring software or the like. Which lets me have a Linux desktop chilling on my desk.
But I do have to keep a laptop with Windows around. We sometimes have to work with overcomplicated Office documents that break on alternatives like LibreOffice or the occasional piece of proprietary software that needs direct USB access, which Wine cannot yet provide.
And me over here wanting to use parental controls to protect my elders haha
A win for you getting parental controls lifted, hopefully you can eventually prove to them that the phone is just fine (or even better) with your apps of choice.
My uncle has worked many years in IT and sometimes lectures me on digital privacy and security. But I got a glimpse of his phones and computers, it was disappointing. Bogus security apps and optimizations and a refusal to update Windows. Probably different situation with OP’s father, but quite emphasizes the importance of continuing education.


Check out zint




OP probably isn’t self-hosting it. I haven’t got around to self-hosting it either and:
The rate-limiting has hit once-reliable instances really hard in the past few months.


~/.drafts, in which my text editor taskbar shortcut script creates files YYMMDD_text_N. I passionately believe in eliminating the chore of manually naming my spur-of-the-moment notes and text files.
~/progs or ~/bin where loose programs not provided by my package manager reside.
If there’s a secondary drive, /media/disk1 as the mount point in fstab.


Seems fine if it only pops up with cursor activity or hovering. Agree if it’s permanently there though. When I use mpv, I have to configure it with some semblance of GUI controls or I’ll lose my mind.
As for specific UI needs, I have went at length to seamlessly theme my desktop like NT 4.0. I could use a fully libadwaita-themed system if I had to, but it just doesn’t spark the same joy that makes working on my computer just a bit more enjoyable.
If I had to go WiFi-only, there would probably be hours-long gaps when I am unreachable. So my compromise is to use a non-KYC data-only SIM. Even if VPN is left off, it routes traffic first to a datacenter far from my actual location, and there is no longer a route for unencrypted calls and SMS and the associated spam. I don’t have a habit of streaming media on the go, so the data lasts quite a while and there isn’t much of an urge to use public WiFi.
Doesn’t fully eliminate the problem as IMEI is still sent and the cellular modem is still a rogue black box, but a step in the right direction. Knowing that the cellular modem can run whatever code with deep privileges as it wishes, I try to keep as little of my business on my phone as I can, with the bulk of my workflow centered around my laptop. Don’t get me wrong, I don’t think this automatically makes me immune, but I do think it’s a neat little exercise. Perhaps one could abstract the problem of the modem by getting a separate wireless hotspot.
My friends and family have accepted that they either need to get Signal, XMPP, or Matrix or I will be largely unreachable. The only remaining need for SMS and GSM voice calls stems from work, which is all handled by my work phone that is powered down, or at least disconnected, once I leave for the day. It sucks that this is not the norm, but it looks like I am quite fortunate that my friends, family, and employer all tolerate this workflow.
Take a look at “IoT” SIM cards, they’re a bit expensive and data-only, but might not be subject to the same KYC regulations.
Can also endorse aptitude, but hopefully OP already has it installed prior to this issue. May have to manually install using dpkg if not. Whenever I run into issues like this, aptitude solves it 95% of the time, makes regular apt look like a baby helplessly crying.


Anyone else wanting to move to CoMaps but procrastinating because they’d have to go about downloading the maps again?


Wow! That’s much more that I would have thought. Can’t wait to liberate my dad’s phone over the holidays, he’s on board with me getting GrapheneOS on it. Will have to see what I can do to their home network as well though since mom’s stuck on a carrier-locked phone.
Minimal delay between a program releasing new features or bugfixes and you getting to use them. Even as an avid Debian user, sometimes I get bummed out when they freeze a package for release right before a feature I would have really liked makes it in.
As for security, there’s not a huge difference I’m aware of. On Debian, features stay where they are, but maintainers will backport just the security fixes of each package to the current stable release.
Reinstalling GRUB in chroot so it ‘registers’ with the BIOS when cloning an install of Linux