• 1 Post
  • 601 Comments
Joined 2 years ago
cake
Cake day: June 16th, 2023

help-circle







  • Buddy, given your relatively basic questions and how you’re posting to every single fucking vaguely relared community, I would highly suggest you do some studying on just… basic computer concepts and how to use them. Not sure what resources are out there anymore, but maybe some basic “these are the parts of a computer, these are programs and how they work” stuff from the 90s. They used to do middle school classes on how to properly use google and other seaech engines to find trustworthy information for citing in research papers. I seriously suggest you start there.

    Then, after you understand the basics maybe you start trying to understand how all of that works in regards to security and the concept of trust in the software you install and run.

    Spoiler alert: Computers are not designed with any sort of “zero trust” architecture like you seem to be shocked that they don’t have. Things are not sandboxed, segmented, or otherwise prevented from accessing other stuff as a general rule.

    This is why one of the bare minimum basics is “don’t run anything you don’t trust”.


  • Harsh question: Do you have a real need to prevent this data from being collected, or are you investigating just for funsies best practice advice? There are a lot of posts like this where people overestimate the threat model they have and insist on needing to block things that are nearly impossible to, or at least have significant tradeoffs like you are dealing with now.

    Javascript is also not the only source that sites can use for these pieces of info from your machine. Local time in particular can be estimated by looking up the rough location of your IP address then matching to a time zone.


    Anyway.

    I would assume you could technically fork localCDN (replaces remote javascript libraries with local copies) and then manually edit the local javascript library copies to remove the calls you are concerned about.

    There’s also options like uBlock Origin’s methods of only whitelisting specific scripts. Much more flexible than NoScript. You can block scripts that are third party and only allow site specific ones fairly easily, without digging deep into the settings.

    Bear in mind that your specific combination of installed extensions can also be a unique identifier though.








  • So this is your project? Judging from your username here and the test messages shown in your screenshot here and on the Github. Nemesis.

    Brand new lemmy account with only this post on it.

    And the entire Github codebase is made up of a single commit of all the files 2 hours ago as of the time I’m commenting.

    As I’ve said before with similar posts from (I believe) other users/coders: just be up front about if something you’re posting was your weekend project or just something to fill out a portfolio.





  • Win? Like a fucking gameshow? That’s absolutely fucked.


    Edit:

    For anyone that happens to find this comment, the reality show was pitched to DHS. There’s no evidence it went past the point of someone going “Hey DHS I have this horrible idea I want to make money off of”. It’s kind of like getting a spam call about your car’s extended warranty and then CNN reporting “Wizardbeard making plans to extend car warranty”. You can find this in the CNN report linked below about it.

    Separately, Dr. Phil has been traveling with ICE, officially to get first hand experience for reporting on the situation for the right wing “news” channel he’s part of now.

    These could be related, but there’s no evidence so far that they actually are. ICE and DHS are so distressingly awful that we don’t need to speculate and stretch to find extra things to be disgusted about.