Eskating cyclist, gamer and enjoyer of anime. Probably an artist. Also I code sometimes, pretty much just to mod titanfall 2 tho.

Introverted, yet I enjoy discussion to a fault.

  • 2 Posts
  • 239 Comments
Joined 3 years ago
cake
Cake day: June 13th, 2023

help-circle

  • That’s not what I’m saying at all. I’m saying Collaboras implementation is fundamentally unfit for use.

    I used to host a CODE server.

    It ran like shit, because it works by rendering the viewport on the remote system, not the client. Instead you essentially send every input to the server, wait for it to render the change, and then send that back to the client. Collabora is like using office software through vnc. Except all the time.

    The responsiveness is atrocious. Especially if you try to use it over a less than ideal connection.

    But it’s just fucking text data. It shouldn’t require the same infrastructure as remote gaming to be usable. It should be able to handle multiple seconds of latency, and just sync back up without the user ever noticing.

    But it can’t. Because it RENDERS on the server. Which means the tiniest hiccup in the connection between server and user causes noticable issues.




  • Also food delivery.

    In Finland, there used to be “pizza-online” which was really just a directory and ordering system for restaurants that already did delivery themselves.

    They took a very small comission, as the site didn’t really do anything except connect restaurant and customer (and provide a review platform). For a long time, they didn’t even have an app.

    You’d log in, select a restaurant, browse their menu and place an order. The order goes to the restaurant, and after that the site’s job was done.

    It was massively succesful. Every hole in-the-wall pizza place was on there. Finding good food was easy and cheap, and the restaurants reached more customers than ever. And the platform including reviews led to competition in not just price, but quality.

    Then pizza-online sold to foodora, and they got shut down, and participating restaurant were no longer allowed to deliver themselves, and the cut taken by the platform skyrocketed.


  • Which this looks like it can be.

    If you don’t provide consent for the app stats, and don’t create an account (which you don’t actually have to) they don’t have a basis to track anything.

    Basically, what you want to look for in GDPR compliant privacy policies, is “we don’t keep/use the data”.

    That’s because of how GDPR defines “legitimate interest”.

    If you have a website, or handle ANY traffic, at all, under GDPR you actually cannot legally claim something like “we don’t collect your IP address”. Unless the user is behind a VPN, your server does at least for the duration of a users interaction, technically, know their IP. Which means you have to state you collect IPs as defined by “legitimate interest”.

    You can only then add that you don’t do anything with that data. Which this privacy policy does do.

    Basically, everything under “legitmate interest” is just “this is how the internet works” or otherwise self evident stuff, like if you write your email in a contact form, you’re providing your email for the purpose of being contacted.

    Everything that does not fall under “legitimate interest” under GDPR requires “explicit consent” meaning no such piece of data can be gathered without giving the user an explicit readable prompt, that either explains what is happening or links to the privacy policy.


  • “Legitimate interests” is the legal term used in GDPR to refer to things you can’t avoid collecting. Like someone’s email address when they create an account on your platform.

    You will find a mention in literally every single legally compliant privacy policy.

    This privacy policy is pretty much the bare minimum you have to have to be legally compliant in the EU, even if you literally never save anything or do anything with the data. Because just by having people visiting your website you technically “know” their IPs even if you don’t save them.

    If someone sends you an email, then you technically “collect” their name and address. If you sell something, then you technically “collect” customer transaction data.

    Literally every privacy policy that wants to be GDPR compliant has to mention “legitimate interest” and it literally just means “when you tell us stuff, that means we then know that stuff about you”.

    This privacy policy is pretty explicit about NOT doing anything beyond the bare minimum.

    It does allow them to collect their own statistics, but there is no clause allowing stats or other data to be personally identifiable (except for authentication), and more notably, that would allow data to be re-sold or shared.

    We do not collect usage data about other apps on your device or websites that are not our own.

    Smart Launcher’s app sorting feature is entirely optional. If you choose to enable it, we may collect information about the apps installed on your device, but only after obtaining your explicit consent. If you do not grant permission, no data will be collected. When collected, this data remains anonymous, as it is transmitted separately from any personally identifiable information. We use it solely to enhance your experience, and it is never shared with third parties.

    We only use technical cookies to ensure the proper functioning of our website and apps. These cookies do not track your activity for advertising purposes.

    If you log in to our services using third-party authentication providers (e.g., Google Login), we may collect personal information such as your email address and other information shared by the third-party provider based on your consent. This information is used solely for authentication purposes.

    Some features, like searching contacts, require access to your Address Book. We do not collect or share this data. This permission is optional and can be enabled or disabled at any time.

    The app may require access to your location, for example, to display the weather forecast. In such cases, we share your approximate location (city level) with the weather forecast provider to enable the service. This permission is optional and can be granted or revoked at any time.

    Access to Storage: The app may need access to your storage, for instance, to allow you to search for a specific picture or file, or to access the wallpaper in use. We do not collect or share this data. This permission is optional and can be granted or revoked at any time.

    Additionally, a GDPR compliant privacy policy must be exhaustive. Even with the device identifier, if the data-point isn’t in the list, they can’t legally collect it.

    That means the optional list of the apps you have installed that they use to develop their auto-categorization of apps, is about as bad as it gets. This isn’t covered by GDPRs definition of legitimate interest, which is why it requires explicit consent.

    (Smart launchers titular feature is that it will automatically let you navigate your apps by categories like games, financial, social, tools, etc.)




  • Some Lenovos only allow you to boot off USB via the “novo” button.

    It’s a pin-tool reset hole with a “U” shaped icon next to it. I’ve seen it hiding among the cooling intake holes on some models.

    Turn the laptop off, hit the novo button, and the laptop boots into a separate menu from the bios that among other things allows you to get to a boot device menu.

    I’ve also come across a case where secure boot would just refuse to boot stuff that didn’t already have matching keys in the bios. Disabling secure boot, everything worked, but turning it back on shit immediately broke. In that case it had stopped booting its NORMAL install of W11 because it had become too new. I had to discover that windows ships a tiny EFI executable signed with the old keys whose sole purpose is to slip the new keys into the BIOS for exactly such a situation.

    It’s also possible to circumvent the online requirement if you know how. The key combo is shift+f10 (or shift+fn+f10 depending on how the function keys are bound) to bring up cmd, after which you can run OOBE\BYPASSNRO to reboot into a mode that allows you to skip ms account setup.

    If you create the bootable USB with Rufus (which you unfortunately need windows to run 🫤), it boots into that mode from the start.




  • I don’t have a static IP, and I just make sure to never ever let my DHCP lease expire. My ISP provides the same IP to the same MAC when renewing the lease. My longest streak on the same IP was three years.

    As long as I always turn my router off by cutting the power, it won’t release the lease, so I keep my IP even through reboots. My last one didn’t release the lease at all, so it only ever got a new IP if it was off for over a day, or if I set a new MAC.

    When my IP does change, I’ve configured my DNS record to only last an hour. So updating the domain to point to a new IP only takes an hour to update.




  • MentalEdge@sopuli.xyztoSelfhosted@lemmy.worldDashboard for my servers
    link
    fedilink
    English
    arrow-up
    31
    ·
    edit-2
    6 months ago

    I just wrote my own.

    It’s a single html file with links to all my services, served at the root of my nginx server.

    This is like v12, I’ve edited it over the years as what I host has changed. Adding the embedded searxng bar, as well as links to uptime kuma and openspeedtest.

    Stuff only I need to access is behind the "Admin Menu" button:

    And it only works via lan/vpn.

    I’d be happy to let you copy it, provided you know how to edit it for your needs.



  • I’d like you to realize that “the USA who is the least likely country to implement these laws” is literally the opposite of current reality.

    They are making some of the greatest efforts to make legally mandated user and age tracking a thing, as well as legally mandated user identity based content-gating.


  • So this is not a concern to you?

    The fact that there are people in leadership positions that want this, and have reasons why they want this, is below note. And not worth opposing?

    This will lead to infrastructure, that should not exist, existing.

    That it can be avoided is not a solution. It should not be built in the first place.


  • Is your argument really “this won’t affect linux, so it doesn’t matter” ? At the very least, FOSS development by anyone in California will be a problem, as the law quite literally names “persons” as potentially liable.

    The reality remains, the US is the most thirsty for this kind of thing. Not the least.

    And they are already working on an even more overreaching version that will close loopholes in the current legalese.