• 1 Post
  • 22 Comments
Joined 1 year ago
cake
Cake day: August 23rd, 2023

help-circle












  • Bilbo@jlai.lutoFrance@jlai.luAnnuaire Peertube
    link
    fedilink
    arrow-up
    0
    ·
    edit-2
    1 year ago

    Je compatis, les seules fois où je vois ces pubs YouTube c’est en utilisant un autre terminal qu’un des miens.

    Newpipe sur Android, Firefox + uBlock Origin sur PC

    Après, il reste les sponsors à la con du style SudVPN ou GIGN Shadow Legends


  • Bilbo@jlai.lutoFrance@jlai.luAnnuaire Peertube
    link
    fedilink
    arrow-up
    2
    ·
    edit-2
    1 year ago

    FAI = Fournisseur d’Accès à Internet.

    Tant que je n’ai pas d’IPv6 chez mon FAI, ou que peertube.sidh.bzh ne soit aussi disponible sur une IPv4, pas de solution pour moi. Je viens de tester, mon FAI mobile ne fournit pas d’IPv6 non plus 😧 !


  • Bilbo@jlai.lutoFrance@jlai.luAnnuaire Peertube
    link
    fedilink
    arrow-up
    3
    ·
    1 year ago

    Je viens de comprendre le problème : peertube.sidh.bzh n’est disponible qu’en IPv6, ce que mon FAI actuel ne fournit pas… Ce jour annoncé est enfin arrivé !

    $ dig A peertube.sidh.bzh
    [...]
    ;; Got answer:
    ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 48558
    ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
    [...]
    
    $ dig AAAA peertube.sidh.bzh
    [...]
    ;; Got answer:
    ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 56184
    ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
    [...]
    ;; ANSWER SECTION:
    peertube.sidh.bzh.      6699    IN      AAAA    2a01:cb19:a72:e600:82fa:5bff:fe51:ed4a
    [...]
    



  • I started typing a very long response explaining my risk model, how a malware on my mobile device will be a nightmare to my whole digital life, etc. Long story short, my case might differ from yours and I consider Izzy’s security not enough for me.

    I consider myself fairly educated in infosec. Security is layered, no single measure can give you assurance it will not fail.

    I suspect Google to perform automated reverse engineering on the Play store apps. F-Droid get the source, not the binaries. Much easier to look for sketchy behaviour if you’ve got the sources. Yes, Google sometimes get malware on the Play store, but it usually does not stay very long or affects a lot of their users.

    Izzy simply does not have the resources to do so, so they use VT as a “replacement”, which is not good enough for me; AV solutions have traditionally shitty engines for mobile apps.

    Also, Izzy is a much more confidential source for apps. Only a few (if any) security researchers will look at it. Even if someone finds a malware, I strongly doubt it will make news, even in IT security websites. Whereas the Play store or even F-droid…

    I don’t blame them nor anyone using them, I’m just saying the risk of potential malware on my phone is not worth the benefit of installing bleeding edge apps for me.


  • Because of the disclaimer on this page:

    DISCLAIMER: I have not thoroughly checked the .apk files available here. As stated above, they are directly taken from the repositories of their resp. developers. Some basic measures are taken, though (see the Security section below). Still, use this repo at your own risk: I will take no responsibility whatsoever for any damages which might occur as result (not saying there will be any, though). Further note the inclusion policy of this repo (see the link above) is slightly less strict than F-Droid’s.