Every point can be supported with an analogy bad enough
🇮🇹 🇪🇪 🖥
Every point can be supported with an analogy bad enough
Yep, my partner gave one for my birthday, it’s basically plug-and-play. It can automatically harvest credentials, spoof captive portals, etc. I bet that in most places nobody would question something like this hanging on the ceiling indeed.
Just FYI https://shop.hak5.org/products/wifi-pineapple. There are ready-made devices that can do basically what you are describing!
Encrypted DNS doesn’t solve everything. Handshake for TLS sessions is still in clear, you can usually see the SNI, and since we are talking about Wireless, usually this data is available to anybody who is in the vicinity, not just the network owner. This already means that you can see what sites someone is visiting, more or less. TLS 1.3 can mitigate some of this (for those who implement ESNI, but you don’t know that beforehand). Also TLS works until the user is not accepting invalid certificates prompts (HSTS doesn’t work for everything) and there are still tons of HTTP-based redirect (check mailing newsletters and see how many first send you to an HTTP site, for example) that can be used for MiTM attacks.
A VPN moves the trust to a single provider that you can choose, which is much better than trusting every single WiFi network you can attach to and the people connected to it, I would say.
Also if you pay for the VPN (I pay Proton), it’s not true that the company business is based on user data, they are based on subscriptions.
I read the post, hence my points. I am not really looking for answers, because I don’t have questions, I had observations. You on the other hand seem to have your whole opinion formed on this inaccurate post, and I would expect someone in your position to look for more perspectives, when you clearly are not. You seem instead on a crusade against the company (good for you), and even if all the post was true, because they spent too much on t-shirts, invested too much in AI products (that I repeat, are opt-in)? Because they don’t comply with a technicality of GDPR? Lol Ok, more power to you.
Also, what I mean by a subscription is that I cancel it and I am done. I didn’t invest in it in any shape or form, what I paid I consumed already, there is no feeling of wasting previous investment in a running subscription.
Judging from your attitude, your lack of content, your very annoying “homie”, your inability to address any point against the content of the article, I am guessing either you are the author and you are butthurt that is not taken as gospel, or you just have ulterior motives and you are here just to stir shit (instead of “spreading awareness”). Either way, I have already invested too much time writing responses to your silly comments. I will show you how good I am in avoiding the sunk cost fallacy and block you, despite the time invested in the conversation.
Cya
I answered with more stuff in other comments, but you didn’t address any of that anyway.
I personally have no brand faith, I am a happy customer and the moment the company doesn’t adhere to my principles I will dump it. There is no sunk cost as it’s a running subscription (you keep mentioning this, so I though I will say it).
That said, if I see someone claiming they have a “blase” approach to privacy or they don’t care about it, I will point out that this is complete bullshit. Using the missing “download my data” feature to support this claim is outright pathetic.
To be even more precise, as a socialist I don’t like many of Vlad’s ideas that tend towards libertarianism. That said, the company has a good amount of worker ownership, it operates on principles I currently respect and that are miles higher than the standard tech company. I am absolutely in favour of supporting positive business in a field where companies are disgusting on average, and in cases evil.
Now, if you have anything else than childish arguments I am happy to discuss them. I have pointed to a number of inaccuracies in the article, there are outdated data (like the number of employees) and subjective views from the author. You are posting this article everywhere like it’s some kind of holy grail of gotchas, when it’s not. There are some good points (financial reporting exists, is not 100% transparent - which is not due, the amount spent for the t-shirts was IMHO not a great idea, etc.), but the fundamental points against the company are shacky at best. As I said elsewhere, all the shpiel about AI etc. is fully addressed in kagi own site where they clearly explain what they mean, for example. The features are actually pretty nice, even for someone like me who is not a fan of LLMs, and the results are quite accurate (the post author claims they are almost always wrong) from my experience.
BTW my searches are unlimited :)
They don’t own the T-shirt factory. It is a simple sentence, they used a small Serbian (I think) company. The business entity is to import goods.
It’s a formal difference but shows how sloppy that post is.
So, again, sorry for trying to point out that the CEO of Kagi does NOT care about privacy, GDPR, or transparency!
Privacy != anonymity. They satisfy the most important aspects of the GDRP, like data and scope minimization, clear explanation of what data they collect and why, a fantastic privacy policy. They don’t let you download a file with your email address in it, woah.
That article is quite dense with inaccurate information (e.g. they own a T-shirt factory), and a lot of guesses. There is no need to listen to a random guy idea about kagi’s AI approach when they have that documented on their site.
Also, the “blase attitude to privacy” is because of a technicality of GDPR? (Not having the ability to download a file with your email address) I am a big fan of GDPR, and their privacy policy is the best I have seen (I read the pp of every product I use and I often choose products also based on it), so really I don’t care about the technical compliance to GDPR (I am not an auditor), but the substantial compliance.
All-in-all, the article raises some good points, but it is a very random opinion from a random person without any particular competencies in the matter. I would take it for what it is tbh
EDIT: To add a few more:
Source: see https://blog.kagi.com/what-is-next-for-kagi (published ~1 month after the linked post).
An article full of inaccuracies, but the most interesting bit is, all these conversations are possible because they clearly explain their views, which are publicly available on their website (for example, the philosophy behind the use of AI - which BTW is opt-in).
How is that an example of being opaque is beyond me.
FWIW, the default “programming” lens works quite well in Kagi, you can also create your own lens if you have a set of websites from which you routinely search info, and there are tons of bangs already (which can also be mapped to lenses BTW). In addition, you can downrank AI/SEO stuff when you find it (it is downranked by default in kagi), so that over time your results are quite clean.
I can’t really make an exhaustive comparison. I think k3s was a little too opinionated for my taste, with lots of rancher logic in it (paths, ingress, etc.). K0s was a little more “bare”, and I had some trouble in the past with k3s with upgrading (encountered some error), while with k0s so far (about 2 years) I never had issues. k0s also has some ansible role that eases operations, I don’t know if now also k3s does. Either way, they are quite similar overall so if one is working for you, rest assured you are not missing out.
Yeah, but you don’t need anything besides the runtime with kubernetes. Podman is completely unnecessary since kubelet does the container orchestration based on Kubernetes control plane. Running podman is like running docker, unnecessary attack surface for an API that is not used by anybody (in Kubernetes).
I run k0s at home, FWIW, tried k3s too :)
Why would anybody use podman for k8s…containerd is the default for years.
As someone from Rome, I feel you. Pickpocketing is somewhat an issue. In more than 20 years living in the city (before I moved) I never suffered from it, but it’s very common among tourists (especially in the underground and certain bus lines). It sucks and often police does nothing because by the time they catch the people (if they do), everything is gone anyway.
That said, beside pickpocketing Rome is very safe (or at least most of the places where a tourist would go, except maybe the surroundings of Termini station).
I agree, personally.
In general I feel the words are so abstract (blacklist and whitelist) that I can’t really see how someone will see some other meaning…
Nftables is the modern iptables FYI. Linux firewall.
Totally discussing useless stuff here, but green and red to me give the feeling of temporary actions (and possibly alternating). Intuitively sounds more like slowing and speeding than it does permanently blocking or allowing something.
Black and white have the polar opposite meaning. At this point allowlist and blocklist might be a simpler solution to the “problem”.
Sure! FYI, simplelogin can create aliases with prefix! I usually get service-{random 5 chars}@simplelogin.com, so you can still sort by folder using prefixes.
Many encryption algorithms rely on the assumption that the factorizations of numbers in prime numbers has an exponential cost and not a polynomial cost (I.e. is a NP problem and not P, and we don’t know if P != NP although many would bet on it). Whether there are infinite prime numbers or not is really irrelevant in the context you are mentioning, because encryption relies on factorizing finite numbers of relatively fixed sizes.
The problem is that for big numbers like n=p*q (where p and q are both prime) it’s expensive to recover p and q given n.
Note that actually more modern ciphers don’t rely on this (like elliptic curve crypto).