If this is your first visit, be sure to
check out the FAQ. You will have to register
before you can post. To start viewing messages,
select the forum that you want to visit from the selection below.
If you have copied text output that contains formatting (colors, highlighting, etc.), please do not enclose it in QUOTE or CODE tags. Just right-click your mouse and choose "Paste Without Formatting" or similar (Paste as plain text).
The following Topic Prefixes are designated for use in Community Cafe:
DS (Distribution Showdown)
GN (Geek News)
KLD (Kubuntu or Linux Discussion)
TWC (The Water Cooler)
KUT (Kubuntu User Testimony)
NRD (Next Release Discussion)
While use is not required, doing so allows for efficient Filtering.
"A nation that is afraid to let its people judge the truth and falsehood in an open market is a nation that is afraid of its people.”
– John F. Kennedy, February 26, 1962.
Some backdoors even evade Linux. Since 2008, Intel’s chipsets have contained a separate always-on Management Engine computer that could not be disabled. The EFF described Intel ME as a “largely undocumented master controller for your CPU: it works with system firmware during boot and has direct access to system memory, the screen, keyboard and network.” Switch to an AMD processor? AMD has had the same capability in its PSP since 2013 as well. Who do you trust the most? Intel denies claims that the ME is spyware and AMD won't release the source code to PSP. Even if either did release the source code how could you confirm it is the entire source by compiling the source and comparing the binary with the released binary? You couldn't.
Besides being a backdoor for Intel, the NSA, CIA and who knows what other gov spook agencies, it is also a tool for hackers. They have been busy.
Despite many people with x86 computers trying, no one could disable ME. The closest successful attempt was likely the me-cleaner project.
ME was added to some Intel CPUs between 2008 and 2013, but it can be disabled because, of all who wanted to keep their security, the NSA asked Intel to give it a way to disable ME. They did: https://www.csoonline.com/article/32...o-the-nsa.html
Will I try it on my Acer Aspire V3-771G, which was made in 2012? Nope. I won't be upgrading or modifying the CPU or firmware on this puppy, either. This Orwellian world already has so many chains holding you back from your privacy and freedom that disabling the ME wouldn't help in the least. Besides, collectively, Apple, FB, M$, Twitter, Google and other major players have at least 2.5 million servers keeping track of your Internet activity using pixel bots, tracking cookies, and hexadecimal link codes like this one:
which is obviously an encrypted link which contains as much info about my computer, what site I came from, what my search request was and what page I would go to IF I clicked on that listing in the Google search results. And that is only the technologies we know about (besides ME and PSP).
Think of all the spying that is taking place through IoT devices, Echo DOT's, Siri, SmartTV's, surveillance cameras almost everywhere, the soon to be in place 5G networks, all linked together using Elon Musk's StarLink, or should I say "SkyNet"? And, it's ALL legal. You did sign or click through those EULA's didn't you? Those very same EULA and ToS in which you signed away all of your privacy rights, your rights of ownership, your Constitutional rights, and just about every other freedom you used to enjoy without Big Brother's allowance a/o supervision.
The disappointing fact is that on modern computers, it is impossible to completely disable ME. This is primarily due to the fact that this technology is responsible for initialization, power management, and launch of the main processor. Another complication lies in the fact that some data is hard-coded inside the PCH chip functioning as the southbridge on modern motherboards. The main method used by enthusiasts trying to disable ME is to remove everything "redundant" from the image while maintaining the computer's operability. But this is not so easy, because if built-in PCH code does not find ME modules in the flash memory or detects that they are damaged, the system will not start.
That paragraph triggered a memory I had about Gulf War I. It seems that the US gov had Texas Instruments put a back door into their printer firmware which was being marketed in the Middle East. Just as the invasion began a code was sent to all the TI printers in the Middle East to disable them. Instead of printing out orders commanders had to write them out manually, which delayed their response and introduced lots of confusion. Of course, articles appeared later "debunking" this scenario but considering what we've seen the last few years using disinformation to debunk the truth wasn't/isn't all that uncommon.
Now, my point. ALMOST ALL of the computers and peripheral equipment sold in America are made in China,which has the technical capability to add or embed kill codes in those computers and peripheral equipment. Say an extra ROM, about the size of a grain of rice, was setting on the logic board of, say, an internal HD, or wifi chip, or eth0, or the touchpad, or just about any component. It could even be embedded and hidden inside a PCB itself. IF a war between China and the US began how long would it take for China to disable all the IoT's stand-alone and embedded computers in the US and its allies? About 1 second. Just as long as it took the US military to kill a select group of Iraqi command and control printers.
"A nation that is afraid to let its people judge the truth and falsehood in an open market is a nation that is afraid of its people.”
– John F. Kennedy, February 26, 1962.
Yep, good stuff. I just received a new HP laptop, which of course came with Windows 10. Even though HP tends to be a bit more Linux friendly than many other makers, I still finished the Windows installation and then removed the Optane/SSD M.2 drive - and am keeping it for warranty purposes, if something should happen to the laptop. What a pain in the a** and I hated that Windows came with and actually installed Bitlocker without my consultation. I then bought a new Samsung 970 M.2 drive and installed Kubuntu (after a couple of hiccups!).
Now that doesn't mean that HP doesn't know anything about my system, as it has the Intel management engine junk on the motherboard, which is nearly impossible to eliminate even with most of the open source BIOS products becoming available. If they don't like what I'm doing, I'm not worried.
The next brick house on the left
Intel i7 11th Gen | 16GB | 1TB | KDE Plasma 5.27.11| Kubuntu 24.04 | 6.8.0-31-generic
Just a few minutes ago, while surfing YT, I came across this video. It makes my point succinctly. Especially notice the Internet tracking of browsing videos and sites like eBay, alibaba, aliexpress, otto, JD, Flipkart, Rakuten and other Amazon competitors, especially those overseas. All the guy did was buy 3 filters for his diesel and do some Internet browsing.
"A nation that is afraid to let its people judge the truth and falsehood in an open market is a nation that is afraid of its people.”
– John F. Kennedy, February 26, 1962.
GG, thanks for the links. Good info.
Agreed, Linux is not perfect, but I look at the alternatives...
I wonder how many Gmail users realize that Google mines their INBOX for purchase receipts and such in order to add to their dossier on them? Here's some alternative webmail services. I've used protonmail since 2015.
Gmail alternatives
Gmail may be convenient and popular, but there are three major problems:
Your inbox is used as a data collection tool. (Did you know Google tracks your purchasing history using the receipts in your inbox?)
Rather than seeing just emails, your email inbox is also used for ads and marketing.
When you remain logged in to your Gmail account, Google can easily track your activities online as you browse different websites, which may be hosting Google Analytics or Google ads (Adsense).
Here are ten alternatives to Gmail that do well in terms of privacy:
ProtonMail – based in Switzerland; free accounts up to 500 MB
Mailfence – based in Belgium; lots of features; free accounts up to 500 MB
Tutanota – based in Germany; very secure and private; free accounts up to 1 GB
Mailbox.org – based in Germany; €1/mo with 30 day free trial
Posteo – based in Germany; €1/mo with 14 day refund window
Runbox – based in Norway; lots of storage and features; $1.66/mo with 30 day free trial
CounterMail – based in Sweden; $4.00/mo with 7 day free trial
CTemplar – based in Iceland; free accounts up to 1 GB
Kolab Now – based in Switzerland; €4.41/mo with 30 day money-back guarantee
StartMail – based in Netherlands; $5.00/mo with 7 day free trial
Soverin – based in Netherlands; €3.25/mo with partial 30 day refund window
Thexyz – based in Canada; $1.95/mo with 30 day refund window
"A nation that is afraid to let its people judge the truth and falsehood in an open market is a nation that is afraid of its people.”
– John F. Kennedy, February 26, 1962.
My protonmail account was stolen, so make sure you use 2FA with that service.
How? Easy password? The site was hacked?
Pluto TV was hacked back in 2018 and my email account was among 3.2 mllion stolen. Pluto TV decided not to inform users of the breach. How nice of them.
"A nation that is afraid to let its people judge the truth and falsehood in an open market is a nation that is afraid of its people.”
– John F. Kennedy, February 26, 1962.
I don't know how. I use a password manager, so I can auto generate long passwords each time without having to worry about remembering them. One day my password just stopped working, I barely used the account so I didn't really pay much thought to it until some time later when I tried to access another site (epic game store) and had the same thing and it was a service I had used the protonmail account to sign up for. Only had a few free games on there and didn't log in much, so again I don't care but it's bit too much of a coincidence
Comment