• 1 Post
  • 19 Comments
Joined 1 year ago
cake
Cake day: July 4th, 2023

help-circle



  • Don’t over think it, start small, a home server. Then add stuff, you will see that it’s not that crazy.

    I personally have just one home server that locally creates encrypted backups and uploads them to backblaze.

    This gives me the privacy I need as everything is on my server that I own while also having the backups on a big reliable company.

    It’s not perfect but it fits my threat model





  • The computer probably has local security tools (such as an edr) that spy on you any way.

    You need to assume it is completely compromised.

    But… assuming this isn’t in violation of your company computer usage policy (which it very much might be and can put you in trouble) you can install any VPN (avoid spyware shit) and a different browser (ideally something a bit obscure, like librewolf) and this will bypass the MiTM as the the device that does the MiTM would be either:

    A) a network device that hijacks the HTTPS requests (VPN bypass this)

    B) the browser used by the company

    C) some other kind of software that atteches itself to all browsers via admin installed extensions (obscure browser might not be recognised by such software, be sure to check the installed extensions after letting the browser run for an hour)

    And once you are done you can check the certificate chain in the browser to confirm.