It’s dishonest to claim Kicksecure (even when all the hardening work is complete) is as secure as mobile platforms. Those have decades of work gone into hardening the security model.
Security is not just a checklist of features. Kicksecure’s sandboxing/MAC/verified boot/etc. isn’t even near iPhone/Android and there are numerous security enhancements in phones such as modern exploit mitigations or widespread memory safe languages that are not achievable with Kicksecure.
The claim that most Android devices have locked bootloaders is also dubious. Unlocking the bootloader and even using custom keys is part of the reference implementation.
OpenBazaar many users using it inside whonix , i get many questions about it. It would be nice if someone can contribute to fill the instructions about it.
But firstly can we have please wiki section for it? So that outside contributors can fill it as well.
I see here OpenBazaar in the wiki “Deprecated” section (dont know why):
Hmm… ZeroNet various websites always results in this error: “Content.JSON Download Failed”. JS allowed on 127.0.0.1 and can see a number of peers so not sure what the problem is. Maybe like I2P you have to let it run for a long time beforehand?
Logs also show for various website attempts: “ContentDb not initialized, load files from filesystem…”
Have you succeeded in Qubes-Whonix @Patrick. Does about:config need some more tweaking perhaps? The home page works okay.
PS @madaidan Don’t waste all your talents & time on those reddit trolls. It’s like screaming into the void.
Spend more time over here doing your great development work!
Maybe like I2P you have to let it run for a long time beforehand?
Dunno. Conceivable.
Logs also show for various website attempts: “ContentDb not initialized, load files from filesystem…”
Have you succeeded in Qubes-Whonix @Patrick. Does about:config need some more tweaking perhaps? The home page works okay.
Last time I tested no such changes were required. I’ve tested very
little actual ZeroNet websites. Official links only. That worked for me
at that time.
Whonix on USB search term has very poor results on search engines. No wiki page is suggested Related information System Configuration and Access - Kicksecure is really hard to find.
Because it shows that others managed to implement these features and it’s realistic to re-implement in Kicksecure - without adding any privacy issues or user freedom restrictions. It’s to tease and encourage other developers to catch up implementing some of the iPhone/Android security features in Linux (desktop) distributions too. If it gets added to Kicksecure that’s great, but if others focus on other Open Source Linux distributions that’s a net benefit too.
And if you’re wondering why it lists some disadvantages of iPhone/Android are listed, that’s to show in how many ways others are messing up. Tor create awareness of these issues (precondition for fix) and to not mess up in similar ways in future. Illustrating project goals, values, awareness.
Concept of Open/Free/Libre Software is great. However, since the inception of the 4 original essential software freedoms, other issues came up sometimes called tivoization, malicious feature, antifeature, tyrant software, treacherous computing or DRM (digital restrictions management). Also data portability, open databases, open source hardware, first mover effects, network effects, and more.
We have enough walls of texts. Some like tables, some don’t. In this case I found a table to be looking good.
A clear credit is given up front to the author: “The description of this procedure draws heavily upon the following guide: The Complete Guide to Secure Communications with the One Time Pad Cipher [archive]; all credits go to the author.”
A clear credit is given up front to the author: “The description of this procedure draws heavily upon the following guide: The Complete Guide to Secure Communications with the One Time Pad Cipher [archive]; all credits go to the author.”
To be on safe side, could you please make the authorship more explicit
by naming author and organization (or organization and author as
applicable)?
Most of it relies on Mixmaster (dead) or Nymservers (largely reliant on Mixmaster).
All that leaves is two sections re: reading newsgroups with NNTP clients (whatever that is, not familiar with it) and accessing NNTP servers anonymously for discussion groups (if that is even possible).
Overall, a lot cause - not worth editing to bring it up to scratch unless you have different views.
Mixmaster / remailer was actually for that context “just a bonus”.
Crossed out the mixmaster/remailer parts just now. Rest seems good enough.
It can be part of advanced documentation or even esoteric documentation as popularity of these things is low and declining.
I wasn’t sure Usenet discussion groups is nowadays completely dead, just full of spam bots which are forgotten be turned off, and just forgotten to be declared completely dead. Search results are dominated by commercial usenet providers (used for file sharing). But no, Usenet is still active. Found this list of some non-spam discussions: https://narkive.com (Usenet is not a website / web protocol. But there are a few gateways to preview contents of Usenet without having to use a news reader.) Usenet might also be interesting as an archive, research, history, whatnot as it had peak popularity in the 1990’s or so.
Could create a wiki template with an info (or warning) box which states that the content of that page is of a lower quality, and whatnot.