privacy.com cards and prepaid Visa/Mastercard I believe let you enter any address of your choice. Of course, privacy.com would still know and some vendors might be a bit more restrictive, especially towards the prepaid cards in recent years.
privacy.com cards and prepaid Visa/Mastercard I believe let you enter any address of your choice. Of course, privacy.com would still know and some vendors might be a bit more restrictive, especially towards the prepaid cards in recent years.
Isn’t the PO box merely to hide your identity from the seller rather than the post office? Not casting doubt on your approach though, just curious if there was anything more to be aware of since I too am thinking about signing up for a PO box.
It could have been many moons ago. But about ten years ago, Google rolled out an irresistible deal for schools that included the workspace suite and unlimited storage. The schools took it up passionately and this is how we got students opening up a Google Docs browser tab that consumes 540 MB of RAM just to jot down a note two sentences long, and schools stuck with Google even as they aggressively whittle away at the promised ‘unlimited’ storage.


Realistically, the software doing the phoning home would have to run on the streaming box; the AAA batteries in a remote would be drained within a matter of hours or days if it were to continuously record and send it back. Software phoning home is a concern with off-the-shelf boxes, but on a Linux mini PC, it’s equivalent to plugging in an external mic. Still good practice to do away with it if you don’t need it.


To his credit, Rob’s videos introduced me to cell phone privacy. But his products are all just pre-flashed off-the-shelf devices. The bespoke Brax phone models are merely rebranded mid-tier phones from a generic ODM. None of it is more secure than what GrapheneOS on a Pixel offers and all of the offerings have alternatives that are cheaper or better audited.


Just curious, what kind of batteries are powering the remote and if rechargeable, how often does it need charging? Not saying they wouldn’t do such things, still a good preventative measure, but I’d be surprised if it could sustain telemetry with only the power of AAA batteries in a typical remote.


You could make it about equivalent to the protections afforded by the typical BIOS password, i.e. the attacker must first disassemble your laptop to reflash the spi chip or pull the hard drive. A grub.cfg like so would do, assuming everything in encrypted partitions:
set prefix=(memdisk)/boot/grub
set superusers="myuser"
password_pbkdf2 myuser grub.pbkdf2.sha512.10000.<your hashed password>
cryptomount -u <UUID of LUKS container>
search.fs_uuid <UUID of the root filesystem under LUKS container> root cryptouuid/<UUID of LUKS container>
configfile ($root)/@rootfs/boot/grub/grub.cfg
Assuming you boot directly to GRUB or locked out the SeaBIOS boot device selector, then GRUB will only ever look for a boot device matching your disk’s UUID; attempting to do anything else aside from entering the LUKS passphrase will prompt for the GRUB password. You’d still have your own recovery path by pressing Esc, entering your GRUB password, and dropping to the GRUB shell. Bonus points for patching the GRUB code so it doesn’t echo the UUID of your disk.
No, it isn’t bulletproof against physical access. But yes, I had the same question you did when starting out with coreboot and this was the solution I came up with.


Through my entire stint having to use it in Europe, the closest I could find was a webview for the web client: https://f-droid.org/en/packages/io.kuenzler.whatsappwebtogo/
Sadly, they enforce use of the official client to create an account and resync whenever the web client session expires. Even once got locked out for using the official client downloaded from Aurora Store, apparently I ought to have to downloaded the APK directly from their website, if not from the play store.
Edit: I also think potential legal pressure also contributes to a FOSS client not existing. Last time someone tried making a feature-complete FOSS Instagram client, they stopped after a cease and desist from Meta.
Obligatory, I would have loved to go without anything Meta in the first place, but if you’ve spent any time around non-techy colleagues in Europe, you’ll know how much of an uphill battle it is.
The one piece of old tech I don’t miss are bulky charging bricks. I use my GaN USB-C charger whenever possible, sometimes with the help of adapters.
Focus follows mouse and unchecking the option to auto raise the active window. Couldn’t live without it and being used to it has made me extremely clumsy when I do pick up my Windows work laptop.
I change the taskbar clock to be a one-line MM/DD HH:MM:SS format, drop in my customized locale (based on en-US for maximum compatibility, but without having to deal with US formats and units that I’m not fond of), and point the taskbar shortcut for my text editor to a script that creates a pre-named file and launches the editor with autosave enabled. Because having to manually save and come up with a name for your spur-of-the-moment notes sucks, automatically generating 20260831_text_1 is so much better than a, b, a2, etc.
XFCE specific, I get rid of the second panel full of launchers. Acquired taste, but also Chicago95 theme and icon pack.


As others say, where the use cases are so specific to each machine, it’ll be a headache juggling all of those images if your needs and workflow change down the road.
But I’d be remiss to say I don’t practice a form of what you mention, I would go insane if I actually had to reinstall from distro defaults. I have a single perfected VM image with customizations and software common to all of my machines. And yes, if you were to go this route, there are little quirks to iron out manually each time I image to a new machine, even old and well-supported ones. Some just cosmetic, some preventing graphical output. Although still much less time than setting up from scratch.
It works well enough for me, but it also frankly leads to a poorly-documented system that will accumulate cruft with updates, and can’t propagate changes in the VM to my existing systems easily, so I’m interested too to see what other people here suggest. Particularly for those niche customizations that land outside of /home and /etc (e.g. /usr/fonts, packages not provided by the distro).
Look into threat modelling, we’re all striving for more privacy-friendly ways to keep in touch with people, and if you seal yourself off too early, you’ll suffocate.
I know my friends and colleagues well in person, they know that I’m a privacy nut, and we agree to not report me missing just because I’m unreachable on a particular day. But knowing that they SMS each other their plans and that I’m probably not a target of the state, I’m cool texting them things like when we’re eating out together.
Also don’t be disheartened, I keep at it even though my methods are nowhere near airtight. Even if every move of mine is known, the surveillance capitalists will at least know that I am flipping them off and trying my best to make their jobs hard.
First thing I always do is set icon scheme to have colors. I don’t know who thought monochrome for the tools was a good idea, but it takes me twice as long to find anything.


If I just learned of GOS now and didn’t have a Pixel, I would buy an unlocked unit cheap and used now. Motorola have gone quiet about their GOS phone in the months since the announcement. If it ends up flagship-priced, I’d have to settle for a used Pixel anyway.
But since I have a Pixel with GOS that is perfectly usable already, I’m holding out to see what Motorola comes up with. Either way, not too worried about specs since I don’t use my phone that much. Would be nice to have SD card, headphone jack (bonus ease of security points over Bluetooth and dongles), and replaceable battery, but have also learned to (begrudgingly) tolerate phones without those.


Same thing you suggested, plus a btrfs scrub to check integrity when finished. I suspect btrfs provides a more elegant mechanism for this, which I have been too lazy to look up.
I could never reinstall … I end up customizing so extensively that a few years ago, I centralized all of my customizations in a VM image that I clone if I do need a fresh install.
If those are your only copies, do buy extra HDDs first thing so you have at least a backup. Preferably then a third copy since otherwise, for a moment, only one copy would exist as you copy encrypted data back to the original drives. Technically, there are ways to encrypt in-place, but don’t ever do that when it’s your only copy of the data.
Overall, it would look like creating an empty partition on the new drive, creating an encrypted container on said partition (this intervening level differentiates it from an unencrypted data partition), creating the filesystem (formatting as ext4, btrfs, etc) within said container, and copying data into the encrypted filesystem.
LUKS is the best-supported encryption system for Linux. As an avid user of LUKS on nearly all of my internal and external drives, I highly recommend reading the Arch wiki entry: https://wiki.archlinux.org/title/Dm-crypt/Device_encryption. Section 4 teaches setting up the encrypted partition. Once everything is in place, most graphical file managers can handle detecting and opening the encrypted drives as well.
For non-boot drives, I’ve always used rsync to copy data over. If you use btrfs, then a btrfs scrub afterwards to double-check the copied files. I’ve never tried to see if I could rsync a root partition and leave it in a bootable state. Though I do have a way to migrate a non-encrypted root partition to encrypted without reinstalling, that’s a whole rabbit hole you are welcome to ask me about.
Get a feel for LUKS before you set up the root partition with encryption though, perhaps by setting up an encrypted install in a virtual machine. Recovering a non-booting encrypted install of Linux takes only a few extra commands compared to a non-encrypted one, but if you mess up encryption and lose the key, no amount of commands will save you. So before doing anything I mention here, always have backups.
Woah a huge flip phone!
Cool pairing of hardware in all seriousness. I too used to laugh at the inclusion of 3G/4G in select iPad models.
Would like it more than Signal ideally. But it’s hard enough already to get people over to Signal. Couldn’t justify how much battery its notification service drained for the few contacts (all nerdy close friends) I had there. That was over a year ago so I’m interested to hear if they fixed the power consumption issue.
For anonymity alone, no. You ought to at least aspire to live the nomad lifestyle first and put up with its challenges, then enjoy whatever anonymity comes from it as a bonus.
If you don’t mind apartment living, you could consider the arrangement I had at one point. Private landlord who didn’t run background checks, accepted payment in any reasonable form, many tenants, communal mailbox without apartment numbers or names required. Internet, utilities, etc. all rolled into rent and not individually metered. Might be harder to find but they exist.
My collection of hoarded media waits eagerly if this forces me to say goodbye to the internet outside of work obligations