• 0 Posts
  • 110 Comments
Joined 2 years ago
cake
Cake day: June 8th, 2023

help-circle
  • Slow walking compliance is normal. It keeps assets liquid and processes & people in place as long as possible before making changes. It also prevents the cost of changing back and forth if a new rule is struck down before its final date.

    What will happen often is that a compliant procedure will be developed as soon as possible, but no changes will be made until absolutely necessary. That gives the organization maximum time to figure out other routes of compliance, fight the rule and continue at pace before they change.




  • The game changer is stock. Keep a bag of vegetable waste (and bones if you’re doing that) in the freezer. Fill to the max line then add cold water to that line as well. Add peppercorns, mustard seeds, whatever and 30 minutes gets you as good as the best store bought for ~free. An hour gets you restaurant style and 1:30 gets you basically rich, dark soup base. I used to roast bones and vegetable bits before boiling to get more color but that’s not required with the instant pot and you also aren’t running a big ol pot on the stove for hours.

    Most people don’t make their own stock because it takes so long and is heavily tied to frugality. When you’re getting basically a kitchen defining ingredient for free at the press of a button the calculus changes and also anyone you give food to will be genuinely amazed.

    The yoghurt function is good. I don’t eat enough yoghurt to use it but you’re getting homemade for basically the cost of milk.

    Mashed potatoes are fast too.


  • I can’t help you with the budget. That’s not enough money to buy a laptop new with that particular functionality.

    If you can tolerate getting something older (and your described use case doesn’t sound like it would prohibit an older device!), thinkpads, MacBooks and the like almost always have removable wireless and Bluetooth modules.

    These older devices are often a better choice than newer ones because they’re repairable and parts are plentiful and inexpensive. You will be much happier spending $200 on a used t480 or 2012 mbp than you will buying a new computer at that price.

    You need to yank the antennas too if you’re really a paranoiac, but if a killswitch would be enough then you’re very clearly not that person.












  • Yeah only use doh on router, expect per device security otherwise.

    I don’t use nextdns so I don’t know. Some mullvad stuff (like their http proxy!) is only functional when you’re using their vpn, but the doh server works fine without it.

    DNS over https makes a connection with the dns server using the encrypted https protocol. That means that when I want to go to hanksbuttplugemoprium.com my isp doesn’t see the request because it’s encrypted. Normally those requests get passed up the chain in plaintext and that’s a Big Problem.

    Like I said, I don’t know about nextdns, but it seems like it’s built around using dns level blocking.

    The problem with blocking stuff through dns at the router level (like pihole and nextdns and if you’re not careful with what you choose, mullvads doh) is that you might end up stopping normal legitimate internet use. I stopped using pihole and later uhh the one with home in the name for that reason. Shit didn’t work and people wouldn’t tell me when it happened so I couldn’t whitelist stuff.

    If you’re worried about your isp seeing dns requests and cataloging them, selling them or just blocking them and reporting you to the authorities, set up dns over https at the router level.

    What are you trying to accomplish?


  • You can pay for mullvad month to month by sending them five bucks and a piece of paper with your special number written on it in an envelope.

    Might make it more affordable.

    There is one thing you should probably change post haste (see what I did there?): get you one of those polarized privacy screen protectors and stop using biometrics. At least in the us biometrics aren’t protected by laws against unlawful search and compelled speech.



  • bloodfart@lemmy.mltoPrivacy@lemmy.mlHelp setting up Wi-Fi router
    link
    fedilink
    arrow-up
    2
    arrow-down
    3
    ·
    4 months ago

    Brand doesn’t matter. They’re all equally bad.

    There’s two passwords to change: your routers administrator password and your WiFi password.

    There’s mainly one setting to disable, but it’s often broken up into many across several parts of the device’s configuration page: wan administration or access to anything under any circumstances.

    The smart starting point with dns is: dns over https. It’s probably all you need so don’t worry about pihole or other stuff. You mentioned mullvad. Use theirs.

    These recommendations will provide a good baseline for security that doesn’t break the places you want to go on the internet. You could do more on the client side like use a vpn from your computer or configure your browser to use encrypted client hello and never store cookies or cache.