[–] 26 points 3 weeks ago

How does Microsoft know which GDID is accessing which websites?

The document adds that Microsoft records also showed the GDID accessing “multiple sites” from servers at Tzulo, a web hosting provider, to help pull off the hack.

The GDID is one thing, but how is the connection to activities made? Is the GDID sent while making requests to a server (in this case Tzulo), which records it? But then it wouldn’t be microsoft records showing that. But if it isn‘t, how do you know which GDID visits a website? If Microsoft is collecting which website is visited on device and sending it off to their servers then the GDID is the smallest thing to worry about.

  • source
  • [–] 12 points 3 weeks ago (2 children)

    Why is there never any more detail how the GDID is then used to collect information?

    The complaint says Microsoft had records showing that on May 12, 2025, at 19:21 UTC, the GDID associated with Stokes’ computer “accessed, among other ngrok pages, 'https://dashboard[.]ngrok.com/signup,' the ngrok page to set up an ngrok account.”

    How do the records show a GDID in connection to the website?

  • source
  • [–] 27 points 1 month ago*

    Regarding OnlyOffice‘s legal claims, this is the response by the FSF, which is the copyright holder to the GPL licenses . It is their opinion, that these specific license additions by OnlyOffice are not legal.

    […] In the main repository of the OnlyOffice DocumentServer, we have found that the README file (and similar README files located in other OnlyOffice repositories) clearly state that the software is made available under the AGPLv3 in the "License" section. However, OnlyOffice then includes additional terms in the LICENSE file (and in some other LICENSE files in other repositories), as well as in license notices of individual source files. In utils.js, for example, it states: "Pursuant to Section 7(b) of the License you must retain the original Product logo when distributing the program." This obligation to "retain the original Product logo" is not included in Sec. 7(b) of the (A)GPLv3, nor in any other parts, as an (A)GPL-compliant additional term, and is therefore considered a further restriction of the (A)GPLv3. 

    The (A)GPLv3 makes it clear that it permits all licensees to remove any additional terms that are "further restrictions" under the (A)GPLv3. It states, "[i]f the Program as you received it, or any part of it, contains a notice stating that it is governed by this License along with a term that is a further restriction, you may remove that term." […]

  • source
  • [–] 1 point 6 months ago* (1 child)

    That does definitely replicate the feature of AirDrop more closely. Do you have any experience with it? Does it work reliably?

    A thing to look out for is Wifi Aware, which would enable the functionality if implemented. That is what was recently also used by google to enable android<->ios Airdrop

  • source
  • parent
  • context
  • [–] 7 points 6 months ago (3 children)

    As one other already mentioned, i would think about getting your own domain and using it with e.g. mailbox.org. That way you become less dependent on the provider, if you wanted to switch in the future.

  • source
  •  

    I am looking for some recommendations on how to secure the data of my physical servers (against physical theft), that I am about to set up. I am new to selfhosting but have a few years of experience running Linux on a desktop.

    My usecase is a simple debian(?) server at home with Paperless ngx and Tailscale for when I am away from home. 

    The question is how to encrypt the data while still being able to keep the server updated.

    Coming from Desktop my first thought was to simply enable FDE on install. But that would mean supplying the password everytime the server needs to reboot for an update. Could someone provide some insights on how often updates to debian require a reboot? 

    My second thought was to use an encrypted data partition. That way the server could reboot and I could use wireguard to ssh in and open the partition even when I am away from home for a longer time.

    I am open to other ideas!

     

    It is our goal to eventually have a similar offering so that a 100% open source, freedom-respecting alternative ecosystem is available for those who want it.

    Thunderbird Appointment

    Appointment is a scheduling tool that allows you to send a link to someone, allowing them to pick a time on your calendar to meet

    Thunderbird Send

    Send is the rebirth of Firefox Send

    Thunderbird Assist

    Assist is an experiment that, through a partnership with Flower AI will allow users to take advantage of AI features. The hope is that processing can be done on devices that can support the models

    Thundermail

    Thundermail is an email service. We want to provide email accounts to those that love Thunderbird, and we believe that we are capable of providing a better service than the other providers out there, that aligns with our values

     

    cross-posted from: https://feddit.org/post/8827678

    Support for FIDO2 (WebAuthn) two-step login on macOS is added with release v2025.2.1. This means you will be able to use a security key (e.g. Yubikey) as a second factor to protect your login.

    It is now supported on:

    • Desktop: Windows, MacOs
    • Browser extensions: all FIDO2 supported Browsers
    • Mobile apps: Android and iOS 13.3+
     

    Support for FIDO2 (WebAuthn) two-step login on macOS is added with release v2025.2.1. This means you will be able to use a security key (e.g. Yubikey) as a second factor to protect your login.

    It is now supported on:

    • Desktop: Windows, MacOs
    • Browser extensions: all FIDO2 supported Browsers
    • Mobile apps: Android and iOS 13.3+
     

    cross-posted from: https://feddit.org/post/3179293

    Install instructions for OpenSuse Tumbleweed/ MicroOs using Full Disk Encryption secured by a TPM2 chip and measured boot or a FIDO2 key.

    Nice to see OpenSuse pushing forward on securing the Linux Desktop with FDE and measured boot. Hope to see other distros following.

     

    I use 2 different computers in 2 different locations both running Universal Blue.

    I was wondering if there is any way to create a backup system where i could backup Computer1 over the internet to Computer2 and continue work like nothing happened with all the user data and installed applications being there. The goal is to only need to transfer the user data/applications and no system data (that should be the same for both because of Ublue, right?), to keep the backup size small.

    To be clear, i need help figuring out the backup part, not the transfering over the internet part.

    If I were to backup the directories on Computer1, which store user data, with for example borgbackup, could I restore them on Computer2 and have a working system? Or would there be conflicts because of more low level stuff missing like applications and configs? Which directories would I need and which could be excluded?

    Is there a better option? Any advice is appreciated!

    I also came across btrfs snapshot capabilities and thought they could possibly used for this. But as far as I understand it, that would mean transferring the whole system and not only the data and applications. Am i missing something?

    view more: next ›