If I were you, I’d knee before the Great Owl. Who?, you may ask. Exactly! Who!

  • 0 Posts
  • 13 Comments
Joined 4 months ago
cake
Cake day: May 12th, 2026

help-circle

  • Have you ever seen a “This site uses cookies, accept / reject”? This has a name, it’s called CONSENT.

    I’ll repeat: there’s something called CONSENT. I.e. the ability (and the right) for someone to CONSENT.

    Could one fight a non-consensual relationship, AI crawlers DDosing the hell out of the whole Web, by pushing non-consensual relationships, injection of third-party JS code programmed to solve cryptographic challenges without prior consent of the user?

    Because this is precisely my point when I criticize Cloudflare, Anubis, Google Recaptcha and whatever other “Proof-of-work anti-bot solution” out there.

    NONE of the mentioned solutions ask for user consent before proceeding with the challenge (e.g. “this site needs to check your browser through heavy computation, proceed / leave”). The “challenge” starts as soon as the page is accessed, as in, zero clicks required for them to start using the CPU (thus, my apologies, I called these things simply as “malware”, I should’ve called these things “zero-click attack”).

    To make things worse, the “challenge” can accommodate itself across multiple CPU cores by using JS SharedWorkers, thus effectively getting to using 100% of the CPU, regardless of any other parallel uses of CPU (e.g. other tabs opened at the background, or other software doing jobs). Using a 100% of CPU for a couple seconds, potentially minutes depending on the current difficulty level, WILL increase temp. Laptops are particularly sensitive to CPU temp due to lack of proper cooling, so it can easily get to 90C, which is a dangerous temp.

    And I’m unable to know beforehand if a website injects “anti-bot challenge” when I stumble upon a link on social media.

    My only PC is an Acer ES1-572, it got an Intel i5-7200U; if you look it up, you’ll realize it’s a decade-old laptop. I’m fucking unemployed so I can’t afford a new laptop. And if my laptop dies upon being literally fried by a long session of “checking your browser”, neither the webmasters nor the owners of the anti-bot solutions are going to give me reparation for the damage they indirectly inflicted onto my personal device. It’s, thus, on me. And still I’m the evil one? REALLY?!

    But, hey, don’t worry! If you didn’t read this part, I’ll repeat it again: I’m CLOSING every website that uses one of these tools. Differently from the non-consented push of a third-party JS, I AM NOT FORCING my way into websites. If you’re a webmaster, you just need to put something like “Cookie monster!” in your document.title and my userscript will auto close your website and I’ll never visit it anymore. Unless you’re going to buy me another laptop, you stay with your sacred website while I stay with my good ol’ laptop.

    Oh, and there’s the irony: those whirling machines at hyperscale data centers are designed for heavy computations such as those involved in PoW cryptographic challenges, and the AI techbros got “infinite money cheat” to spin up new ones… Techbros are likely laughing at the naivete of Anubis; Cloudflare, a corp with an AI suite of their own (another sweet irony; fight AI crawlers by feeding your content directly to another AI corp) are laughing at all the power and content being handed freely to them (sometimes webmasters are even paying for Cloudflare to be given content for their AI suite!). Meanwhile, me, an unemployed Brazilian, am compelled to avoid the so-called “modern web” if I don’t want my only old laptop to unwittingly become a dead weight… and I’m even accused of working for AI companies!

    !privacy@lemmy.ml


  • While Cloudflare, as well as Anubis and other “anti-bot solutions”, do behave like MitM, they only become a MitM in two situations:

    - When the webmaster injects one of those third-party malware into their website.
    - Very unlikely, when the network administrator (e.g. the wi-fi from a library or university) is deliberately acting as a MitM through a transparent proxy, and it’s somehow using Cloudflare.

    As for me, personally, I don’t see these anymore. I built myself an userscript (FireMonkey), targeted at every domain, programmed to do a window.close() (close the tab) if the title is one of the strings “Just a moment…” (Cloudflare), “Making sure you’re not a bot!” (Anubis), “Cookie monster!” (also Anubis), “Checking you are not a bot” (some Anubis fork) or “One more step” (Google recaptcha). If the title matches, the tab is closed before any non-consented cryptographic challenge (i.e. those “solutions” don’t even dare to ask for user consent before “checking the browser”, therefore it’s a non-consented relationship and a behavior indistinguishable that of a malware) starts to overwhelm my decade-old laptop CPU.

    Yes, this means I’m not having access to whatever content is behind the wannabe-cryptojacking tool, but if the webmaster does not respect my personal device and my right to consent (i must emphasize: all those “solutions” start straining the CPU with cryptographic challenges as soon as the user accesses the page, without asking for user consent beforehand, therefore it’s a non-consented relationship and a malware-like behavior), I can’t help but speed-run my search for the exit door. I’m not submitting myself and my personal device to malware (the webmaster pushing CF/Anubis/etc to non-consentedly run on my laptop ain’t gonna buy another laptop for me if mine died so I’m better as far as possible from their website).

    !privacy@lemmy.ml


  • I’ll check it, but… Doesn’t this risk rendering internet banking (for context, Brazilian banking) and government apps refusing to function? Last time I threatened to simply turn on developer mode (so to use things such as adb), gov.br stopped working for me (and it’s basically the 2FA app through which I’m expected to have access to public healthcare appointments, driver’s license, electoral/voter ID, etc).

    !privacy@lemmy.ml


  • It was suspiciously easy for me to uninstall it, too. I didn’t even need adb. I wonder if uninstalling this would break things systemwide.

    Needless to say I also turned off the “Google Play Protect”.

    Any info on whether there’s a risk that this uninstalling would risk breaking things?

    (I’d love to have a Linux phone or something similar; unfortunately I can neither afford one due to unemployment nor I could have it getting to me through the customs without being flagged by Brazilian telecommunications regulatory agency complaining about how it lacks a license to operate around here)

    !privacy@lemmy.ml


  • So sorry I’m new still, I’ll keep the links of YouTube off Lemmy from now on.

    Oh… I’m the one who must beg pardon, upon re-reading our exchange I noticed I sounded harsh, I truly didn’t mean to. It was intended as an advice, not just to you but to everyone reading as well. Please take the time you need, migration across platforms is never easy, and like I’m going to say in the following paragraphs, it’s definitely not a 1:1 migration.

    It would suck to stop following my favorite creators but it’s worth it if there are decent alternatives

    Yeah… that’s unfortunately a problem 🙁

    I used to watch hundreds of channels, including but not limited to ElectroBoom, Veritassium, Technology Connections, Practical Engineering, and similar STEM channels. I also used to produce some content myself (mostly technical experiments with steganography and novel ciphers, but also some esoteric content), even though my channel was very small and with the content often using Creative Commons licensing.

    As I was faced by increasing enshittification from Youtube, including but not limited to stumbling upon advertisement pitches verging the dangerous (malware, scam/bets, etc), I took this decision that was far from easy, especially due to how I used to enjoy the aforementioned channels.

    But then, it’s partly on those science communicators to keep themselves and their audiences captive of a monopolistic platform. If people migrated to something else en masse, similarly to how it happened regarding Twitter (people mostly migrated to Bluesky; not the perfect choice, considering there’s Mastodon right at the corner of the street, but at least people went from a monopoly on microblogging, to something “less monopolistic”).

    I, the one viewer less in their daily numbers, am mere dust in the wind, but if other people started doing the same, then it’d be a phenomenon that couldn’t be ignored; content creators often are where the audience is, and when (if) the audience makes this hard decision of going somewhere less monopolistic, either they follow their audience to the new place, or they’d be left with the “audience” from Google Gemini. Hence my active campaign to advise people to start boycotting Youtube, even though most of the valuable content is still kept hostage within Youtube hosting; content creators would likely follow if this exodus happened in a significant number.

    !privacy@lemmy.ml


  • It really pisses me off that people abandoned it in favor the evil that is Facebook. Support the good ones

    (… then proceeds with a Youtube, a Google’s platform, link)

    I mean, please don’t get me wrong, I definitely agree with everything you said. It’s just… we should also be doing a similar thing (supporting the good ones) when it comes to video platforms.

    PeerTube, for example, is part of the Fediverse we’re currently on. It really pisses me off whenever I see a Youtube link being shared through the Fediverse (and especially in a Lemmy community whose name is Privacy), given we do have alternatives.

    It’s been a little more than two years since I stopped using Youtube altogether (I don’t even use the alternative front-ends). My boycott against Youtube isn’t enough, because Youtube links keep popping up in Lemmy threads oftentimes. And because Lemmy would go a step further and try to embed the Youtube player in place of the hyperlink (therefore phoning Google automatically) when it’s a thread (not your case, yours appears as a hyperlink because it’s a comment), I had to manually add youtube.com and youtu.be iframe domains to my uBO network filtering.

    Goes without saying, I don’t have a Facebook, either.

    !privacy@lemmy.ml


  • - Wait until midnight.
    - Turn on the computer using the foot’s thumb finger.
    - Clean the mouse’s trackball while you hear the Windows XP’s starting song “trunn trun trunnn, trun-trunnnnnnn” in your bedroom, followed by some cracking noise foretelling an incoming cellphone call in your Nokia 3310.
    - Dial the ISP using the Windows XP’s “Dial-up connection” dialog
    - Spin up a Winamp playing the same “Numb” by “Linkin Park” (or “Bring me to life” by Evanescence, or “Fireflies” by Owl City, or several other classics) over and over again.
    - Spin up MSN Messenger and see that “Numb - Linkin Park” (or whatever song) as both your status message and your contacts’ as well.
    - Spin up Internet Explorer 6 and go to Orkut.
    - Oh, a new testimonial and two new scraps.
    - Also a new discussion thread in the community “Eu odeio acordar cedo”.
    - Got tired of Orkut communities, check if there’s anything new in “Buddy Poke” and “Happy Farm”.
    - Got tired of Orkut altogether, but Jake, my colleague from school, just made my MSN window to shook and sent me a Wink, inviting me to a match in Counter Strike. I plug it to the living room’s CRT TV using a convoluted connection.
    - My grandpa starts complaining about how I’m damaging the CRT TV with the pesky Computer-to-TV adapter.

    This won’t be coming back. Like, ever. The Alpha Gen and most of the GenZ will never be able to truly know what I’m taking about.

    So, please MySpace, don’t try to fool me with illusory hopes. Yahoo Messenger isn’t coming back. Limewire and E-mule’s “Every-Linkin-Park-album-ever-released.exe” aren’t, either. And it won’t be MySpace the one to bring that to life (pun intended). Since Harambe died, the world has never been the same. In the end, it doesn’t even matter.

    !technology@beehaw.org


  • To me, it has definitely nothing to do with system (KDE Plasma on Arch Linux) because Librewolf is the only piece of software in which accents don’t work. Even AppImage programs, which often lack a better integration with the X Session, have no problem with accents.

    Also, ABNT2 accents are correctly parsed by Waterfox, even by Basilisk and Pale Moon which I also got here, as well as by the original Firefox (which I keep for things such as internet banking), even though they all share the similar “under-the-hood” Gecko (Goanna in case of Pale Moon and Basilisk), so this problem is part of the Librewolf hardening.

    In fact, the very Librewolf FAQ mentions this:

    Other common problems brought by RFP include:
    […]
    - suppressed keyboard modifier events using alt-keys.

    These annoyances are intended to protect your privacy […]

    Problem is, even if RFP is turned off, this hardening keeps occurring, and it’s PITA having to spin up a KDE Kate just to type something I can type directly in all the other browsers (including in the Geminispace’s Lagrange browser and the TUI-based Lynx, both places in which accents wouldn’t be even expected to begin with). So while I still have Librewolf among my browser installations, I only use it for things such as news outlets and certain websites because this is where it thrives, keeping some resemblance of private navigation.

    !privacy@lemmy.ml


  • My problem with librewolf is that, despite having RFP (Resist Fingerprint) off, it doesn’t allow me typing accents from my ABNT2 (Brazilian) keyboard (I cannot type words such as “ração”, “óbvio”, “maltês”, etc, I have to type them using kde plasma then copy and paste inside the browser), as if librewolf were US-centric. The devs didn’t point me a solution when I opened an issue ticket, so I went with Waterfox instead. Waterfox allows me to type accents the way I’m accustomed as a Brazilian.

    !privacy@lemmy.ml



  • I’m not going to disclose my specific way, but numbers don’t need decimal digits to be expressed and parsed. An hypothetical example:

    Oh… ye shadow! Nahamah, my Mother

    Believe it or not, this is encoding the today’s date, 2026-07-26.

    Oh = 2 letters
    Elipsis = no letters, so 0
    ye = 2 letters
    shadow = 6 letters

    Nahamah = 7

    My = 2
    Mother = 6

    The funny part? I just conjured this technique during the composition of this very reply. It’s somehow easy for me to conjure atypical steganographic techniques, and I use steganography quite often IRL. In this way, I can literally write down my passwords and keep in my wallet, and absolutely nobody will get to figure out it’s meant to be a password.

    Luckily for FBI and other investigation agencies, I dont even think of visiting the USA, but good luck for any fed or cop trying to keep up with my plethora of steganographic techniques (and my neurodivergent brain) amidst plausible deniability if I ever did. Lol

    !privacy@lemmy.ml