Just wanted to share my setup and see if anyone has suggestions or feedback. Also share yours.

Phone : GrapheneOS(pixel 7a)

  1. No google play service on my main profile. Rethink DNS (NextDNS DoH) blocks ads, trackers, and all Google & Facebook DNS (except WhatsApp).

  2. Some FOSS apps like Aurora Store & NewPipe need Google servers, so I have excluded them in rethink dns.

  3. Work Profile (with Island) with GrapheneOS’ sandboxed Play Services, but I use it maybe once or twice a month only for apps that absolutely need it. It stays turned off most of the time. If an app works on main profile without any issues, will use it. If not, will try to use it in firefox (as lack of play services doesn’t matter). If only app is available (and not web version) and it doesn’t work on main profile, will use it in work profile.

  4. Hardened Firefox fork(Ironfox) for private browsing. Main Firefox for a few services where I have to stay logged in and don’t have apps or want to use their apps.

  5. Network & Sensor Restrictions: If an app works offline, I block its internet access. Also, disabled sensors for apps that don’t need them.

  6. Mostly use foss apps from f-droid(droidify).

  7. Email: moved from gmail to protonmail

PC/laptop: Arch linux kde on pc and fedora kde on laptop.

  1. Not much to say. Most used apps are firefox and Zed. I allow data collection on kde as I want them to improve it.

Home Server: Raspberry Pi 4B

  1. SSH hardening: Non standard ssh port(yes, I opened the port externally because I depend on my home server and need to access it remotely). SSH keys or password+totp, Fail2Ban, ufw.
  2. Services running: Arr setup(jellyfin, prowlarr, radarr,sonarr, qbittorrent), pihole, Immich, Authelia(for now). All data sensitive services behind authelia with totp.
  3. Nginx Geo-blocking: Only allows access from my country IPs
  4. Weekly backups because data loss sucks.

Network & Router: OpenWRT (TP-Link)

  1. Not much to say: Running default firewall rules with network-wide ad/tracker blocking via pihole and some ports opened.
  • Termight@lemmy.ml
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    4
    ·
    7 months ago

    Sharing privacy and security setups, the digital equivalent of leaving a detailed map to your treasure chest and then wondering why pirates are interested. True privacy, as a concept, becomes a rather slippery thing when you attempt to explain it publicly. It’s a paradox, isn’t it?

    I’ll share a “true” secure setup. Four laptops: secure communications, normal communications, a decoy, and an “airgap” (a computer that had never gone and would never go online).

    • The 8232 Project@lemmy.ml
      link
      fedilink
      arrow-up
      6
      ·
      edit-2
      7 months ago

      Sharing privacy and security setups, the digital equivalent of leaving a detailed map to your treasure chest and then wondering why pirates are interested.

      There’s actually two distinct ideas here:

      1. “Sharing your setup leads to insecurity” If this were true, then software being open source would make it insecure. It simply isn’t true, most of the time. While yes, making your setup public can lead to spotted flaws that can be exploited, in general it has no effect so long as you can trust the system you use. For example, I could give you my encrypted KeePass database file, and feel relatively certain that my passwords are safe. It isn’t a good idea for me to do that, because it leads to an increased attack surface, but until you manage to brute force the password for it or a zero day is found in how the database is stored, my passwords are still safe.

      2. “Sharing your setup makes you a target” To a degree, this can be true. The Streisand effect is evidence that this can happen. Again, though, as long as you anonymize some specific portions of your setup that can directly be used to exploit you, you will remain safe. I’ve shared my setup in the past (although it’s quite outdated by now), because I trust the way it is set up.

    • zwekihoyy@lemmy.ml
      link
      fedilink
      arrow-up
      1
      ·
      7 months ago

      security in obscurity is a farce. if your system fails upon techniques being revealed, it’s not very secure.

      • Termight@lemmy.ml
        link
        fedilink
        English
        arrow-up
        1
        ·
        7 months ago

        security in obscurity is a farce. if your system fails upon techniques being revealed, it’s not very secure.

        I agree yet it’s a supplementary benefit, not a substitute for genuine security.