Note: This setup is both for my android and pc Edit: For those recommending paid services and selfhosting, I don’t have the money nor resources for either. Also it seams some people are confusing my android setup with my PC setup so I’ll write it down. Android: Brave(movies) + Ironfox, Search: Brave + DDG, VPN: Proton ( not always on), GPay = Cash, Auth= Aegis Auth, Pass: KeepassDX, PC: Firefox= Librewolf, VPN = No VPN (VERY slow internet), Search: Searxng + DDG, Pass: KeepassXC,
Should you change your DNS if you have your VPN on?
yes and no, ideally vpn also handles DNS querries but sometimes with faulty implementations DNS can leak. mullvad has a test in their website but only works for mullvad vpn.
i was using this site for testing, does the job
Would a faulty implementation be only if you did it manually? In other words, if I just go through the motions of turning on the VPN, theoretically there should be no leak right?
i don’t know exactly how it happens but somrtimes for example browser uses its own DNS and it leaks this way. mullvad adds a virtual network interface and forces all traffic through it and prevents leaks this way
Arch’s recent stance on age verification, and specifically how they said it, has made me switch off of Arch for good, which is… Unfortunate, since it was the first distro I truly loved. Gentoo is what I use now, but that’s a bit farther down the line. I don’t know a good rolling release distro that’s not super inconvenient, unfortunately.
Brave is… Not great. Bad, even. I prefer Vivaldi for my Chromium fork. Mullvad browser for my Firefox fork (I also just. Refuse to use Firefox proper anymore because of their AUP). Note that one of Mullvad’s CEOs donated to a Swedish far right party, so… Make that decision how you will. It’s a free browser, so… Meh.
My default search engine is Wikipedia. When I want to use a general search engine, order of operations is Marginalia, then Startpage, but SearXNG is a good one. I just found it a bit more inconsistent.
Tuta’s a good provider, I just needed a client because I don’t check my email otherwise. I’m on mailbox.org now because of that. They’re cheaper, and private email is kind of a farce anyway. Also mailbox is cheaper, assuming Tuta doesn’t have a free plan now. Given you said you’re not using paid apps, they might?
dont use brave
Can you tell me why? I found out ddg was just repackage bing results so I’ve been trying brave for now.
It includes a lot of crypto bullshit, and I believe the founder is a right wing weirdo, but don’t quote me on that.
To also point out the good stuff: their browser has some pretty good anti-fingerprinting and privacy measures build in.
Here’s a good summary of some of the shady practices that they’ve done by way of @cannedtuna@lemmy.world. It’s a summary of this article: https://thelibre.news/no-really-dont-use-brave/
-
- Brendan Eich donated to anti-LGBT political organizations, politicians, and initiatives such as CA Prop 8 which banned same-sex marriages.
-
- Brave promised to replace ads with privacy friendly ads that would actually pay publishers and even users with a volatile cryptocurrency while keeping a cut for themselves. This never actually came to life and was criticized as “blatantly illegal”.
-
- Brave collected donations for popular content creators without actually involving or seeking consent from said creators. In short they accepted donations in crypto for creators, but would only pay out if it reached a minimum value of $100. When called out, Brave said refunds were impossible.
-
2020 — Brave injects referral links when visiting crypto wallets
-
- Brave injected their own referral links for services such as Binance without informing users or asking permission.
-
- Brave turned their home screen image rotator into a place to serve ads, many of which were suspicious or crypto related.
-
- Brave added a Tor feature which exposed users DNS requests
-
- Brave refuses to disclose their crawler bot to websites since many websites want to block Brave Search. Brave will only chose not to crawl a website if it also blocks Google’s crawler.
-
2024 - So-called “privacy browser” deprecated advanced fingerprinting protection
-
- Brave removed a the Strict, Block Fingerprinting privacy feature from their browser.
-
- Brave paid for targeted ads for users searching for Firefox in the Play Store and ran a campaign to “Forget the Fox”. When called out on this the VP publicly denied it and claimed it was photo-shopped.
-
- The VP of Brave, Luke Mulks, frequently posts about all things crypto, from NFTs to FTX, and uses AI-gen images to promote them. He also frequently re-tweets right-wing activists.
-
- Brendan Eich’s feed also frequently contains right-wing content and Republican propaganda despite his claims to be “independent”.
2026 - “pay $60 to REMOVE our bloat features”
Oh? I haven’t used their browser since ~2018, good to know that I continue to have made the right decision. I now use librewolf on my desktop and IronFox on my phone
I jumped onboard in the beginning (2016?) when they would show you “tailored” ads in exchange for their crypto. I made about $30 or so before I got bored of the endless crypto scam ads, despite having that category disabled.
Then came the referral link scandal, and I went back to FF until I found Librewolf.
Thoughts on Vivaldi?
Still a proprietary black box you shouldn’t trust and chromium based so you reinforce the chromium monopoly
Agreed, but occasionally I have to use a site that doesn’t work properly on Firefox-based browsers. I mostly use Cromite to deal with that, but want a backup in case Cromite dies like its predecessor Bromite did.
have you tried to fake user-agent with Firefox? Most shitty sites I encountered which pull that off just do it for no reason whatsoever. They work perfectly fine in Firefox disguised as Chrome.
Firefox is my daily drive and I use Ungoogled Chromium for the rare times Firefox doesn’t work
If Firefox doesn’t work I just click away
Ty - I’ll give UC a try.
Why is vivaldi helping a chromium monopoly?
I understand it is based on chrome tech, and I guess that means it can use chrome extensions maybe? But how does it help chrome if people use it?
It uses Google’s browser engine called Chromium, which Chrome is based on. A lot of websites made to just function well on Chromium and maybe Safari
A lot of websites are made to just function well on Chromium and maybe Safari
Isn’t that more on the site creators? I have a handful of sites and web apps I don’t have a choice to simply avoid because of job-related requirements. I’ve tried a bunch of other approaches, but keeping a Chromium browser installed has, so far, been the least painful way to get through my normal work days.
With the market share of Chrome and Chrome-derived browsers Google basically single-handedly decides how the web works. They decide to implement some functionality, everybody needs to do the same, every other browser “vendor” has to implement it as well now. The consortium deciding about it theoretically is a fig leaf at that point.
Just use Firefox with uBlock Origin and PrivacyBadger.
uBlock and Privacy Badger should not be used together.
deleted by creator
Firefox needs to add tab groups on mobile first
Arch BTW… 😎
Would switch Organic Maps to its fork CoMaps. (See: this open letter)
And I would never recommend Brave as the first choice; it’s run by a shady corporation and reinforces Chromium’s hegemony.
I think it’d also be reasonable to add ProtonMail to email and Mullvad to VPN since you can have multiple.
How about OsmAnd? Is that still a decent project without world domination plans? I actually have CoMaps as well, but have sort of stuck to using OsmAnd.
I think OsmAnd is great, but I personally prefer the cleaner feel of CoMaps. Just preference.
Something I’d suggest if OsmAnd feels too cluttered for you is to change the settings; OsmAnd lets you change a lot, but one of the ones I do is to change “Map Style” to Osm-Carto.
Carto, for context, is the vector map that you’d find by going to the OSM website. Much cleaner color scheme, imo.
My problem with OsmAnd is that it’s so very slow. Like, you zoom in and it takes seconds to display the map.
“Takes seconds” seems like a strange experience. I remember OsmAnd years ago performed like that for me – clearly, painfully loading in the individual tiles. But nowdays, it smoothly transitions between LoD and has no problem smoothly scrubbing over e.g. a major city.
I’m using offline vector maps, for context.
Edit: Trying online tiles again, I’m assuming your problem can be resolved by switching to offline. You can have the offline data update automatically such that you don’t have to worry about it. CoMaps and Organic only use offline maps, which is why they’re similarly snappy to offline OsmAnd.
This is under Configure Map > Map Source, and you only need to download for the region (usually e.g. a province) that you’re using.
Not everyone uses a powerful smartphone.
«Works for me» is seldom a good advice. OsmAnd is perfect on my Google Pixel 4a (2020), but can’t run decently on my father’s Sony Xperia L3 (2019).«Works for me» is seldom a good advice.
That wasn’t the advice; the advice was “try offline tiles and see if that helps.” In their case, it didn’t, but it’s just covering arguably the most likely potential cause. The fact it wasn’t their problem doesn’t mean it wasn’t worth asking.
Sadly that’s not it, I was using offline maps.
I’m not entirely sure what’s the exact issue, but it only really occurs when trying to change LoD quickly. E.g. clicking on an inter-city bus route and zooming out to see it in its entirety or zooming back in. From 10 km to 500 m can take 3-4 seconds which is enough to feel sluggish if you’re doing it often.
Probably not the most popular use case but it can get frustrating after a while nonetheless
Tried it out, but since I was so used to the standard OsmAnd style it just felt wrong some way.
It really like how OsmAnd allows for so much customization e.g. in map styles
Yeah, OsmAnd is really good; it’s what I use as my daily driver. CoMaps/Organic to me feel too limited, but some people may like that.
(I use Vespucci for editing on Android.)
Its installed in my android head unit in my car, and it just works, and there’s a lot (and I mean a lot) of stuff it can do, so I really enjoy it as my daily driver (ha! Get it?) in my car.
Except OsmAnd hiding functionality behind a cloud with paywall.
Try the OsmAnd open-source version, which has all the OsmAnd+ features unlocked for free: https://f-droid.org/packages/net.osmand.plus/
So this version gets all the paid cloud features, too?
I’m not sure if I know all of the paid cloud features in the current version (and I don’t really want to download it). You can download unlimited maps, which made me switch back in the days.
Excellent. Ty for the open letter too. I hadn’t gotten around to understanding why there was a fallout, but now I know.
open source software ≠ privacy
though it is preferable. 3rd party verification of closed source can be accepted in some cases.
Any chance you found a way to encrypt local app caches?
What privacy concerns are there with using your ISP DNS? (honest question, not judging)
Your ISP can see what websites you visit. But even if you change DNS server it can still see that if you don’t use either a VPN or DoH/DoT.
So it’s a good idea to use DoH or DoT. It’s an improvement but it’s far from perfect because the DNS server you’ll pick will see what site you visit, you have to trust them. And your ISP still has other ways to see which site you visit.
deleted by creator
Yes, that’s why I ended with:
And your ISP still has other ways to see which site you visit.
Even with secure DNS they can still see the domain name with the SNI, which is probably more reliable than an IP address. Last I checked very few websites used ECH. I would still argue that it’s better to have encrypted DNS requests than non-encrypted ones.
In my country they implemented national wide surveillance in the network infrastructure and they keep track of everything Edit: that’s why internet is very slow
Depends where you are, and what laws your ISP is required to follow with regards to blocking/tracking. Personally I like Quad9.
ISPs not only have a monopoly on connectivity and bandwidth prices - which they severely abuse by the way, considering the actual operational costs - but they also have everything to gain on analyzing your traffic, DNS queries being one of them. They already have a bunch of personally identifiable information (PII) on you (full name, date of birth, banking information and, in some countries, even social security number). Linking that PII to your DNS requests (read: what websites you visit) and selling that to data brokers is a pretty low effort sweet deal. Long are the days gone when ISPs only provided Internet service.
Texts on the topic:
- https://mullvad.net/en/help/all-about-dns-servers-and-privacy
- https://labs.ripe.net/author/babak_farrokhi/is-your-isp-hijacking-your-dns-traffic/
- https://www.howtogeek.com/why-dns-betrays-your-privacy-and-how-dnscrypt-stops-it/
Videos on the topic:
dns requests flowing through your ISP means they know where you (want to) go and 3rd parties can potentially determine identity based on certain aspects (date time of request, how many, etc) can matter to law enforcement, surveillance/state efforts, hackers and beyond) because ISP may not govern well or, hell, wven sell those requests or just 3rs party manages it without your knowledge etc )
it’s better to have a known good dns provider that can offer a little trust but realistically nothing is 100%…
Close to what I normally use. I prefer CoMaps instead of Organic, Mullvad VPN instead of Proton & Artix instead of Arch.
Why Artix instead of the real Arch btw?
Artix doesn’t use systemd, iirc
For those recommendeding better services for cheaper prices, I use the free plan in all services, I don’t have money or resources to use a paid plan or to self host.
Pretty solid. Too solid in fact. How long ago did you start the process?
What alternative did you find for gmap?
2-3 months ago. Gmap has a lot of alternatives
I would go with SimpleX instead of Signal since it is very secure and you can self-host the server. There are no user IDs. Here is the official website: https://simplex.chat/
the onboarding for family & friends on simplex is too much - Ive had much better luck with deltachat
That is true. I have only managed to convince my wife to use it but I had to set it up for her. Now we can chat about what to eat for dinner securely though 😄
Harder to get people to switch the more obscure the app is. Other than that, I agree.
For normal usage and actually using a messaging app for what it’s intended (contacting people in your life), it’s far too obscure and non-streamlined tbh. Signal is more than good enough for the thread model of chatting with friends and family, and ppl you got to know online
For DNS I use Pi-hole with Unbound which is used to contact the DNS root servers directly and recursively find IP-addresses. The first lookup becomes a little bit slower than through say Google but the IP is then cached locally and then it actually becomes faster. This is also more private since it doesn’t require a third-party DNS resolver.
Check out ente as an alternative to Google Photos. I’ve been using them since 2023 when Google announced they own your photos and they were going to be
insteadingested into AI.Edit: typo. Looks great BTW. Good progress.
I’m not using ente because they have a cloud storage, the only safe storage is the one you have
this is not good. stuff like google calendar and photos are cloud service, a local app isn’t a replacement and there’s so many good ones. brave stuff just injects their affiliates and ads and has paid models, plus is led by someone with very questionable views. arch linux as windows replacement is objectively a bad choice as first linux distro. keepass is great but again offline.
yeah, if you want privacy, de-cloud. even google photos is private if you never connect to the internet. we should recommend less bad alternatives with comparable features, talk about compromises and use cases, and generally avoid making such eye catchy “privacy packs” which don’t work for most and are honestly a circle jerk for who already solved their privacy needs
also there’s no private AI. your local model is built on stolen data, so if you care about our privacy and not just your own stop using ai crap or kindly fuck off back to your favorite techbro
- If you object then recommend something or help.
- I only use Brave for movies because its faster and my internet is slow.
- Its not my first time using Linux, I’ve tried Ubuntu, CachyOS, and Arch and with them KDE, Hyprland, Gnome and many others.
- That’s what I’m trying to do, reduce cloud storage usage.
- I used this “eye catchy privacy packs” because its easy to make. (And its powered by ente)
- I know there is no private AI, I don’t use them often but i try and use ones with good privacy policy and I don’t have money to buy a powerful PC, hell even my phone is stronger
- Lastly If your this angry go and take a walk instead of crashing out at people and wasting their time. Edit: typo
i think my point kind of missed: i dont have specific recommendations unless an use case or a set of requirements is provided. most services from big providers are “catch all” because of budget and desire to capture market, privacy alternatives aren’t
i also misunderstood this as a recommendation for others rather than sharing own’s choices, so I’m sorry if I was annoyed for what I felt to be poor choices (and i feel these are for generic users trying to get free from big providers)
but really, drop brave
Who hurt you? I mean… all of your points are totally valid, and you seem to have profound IT knowledge. Great! But OP just wants to have his built evaluated, probably bc he wants to further improve… and you’re non-chalantly bombing him with strong words and more negativity than all of my toxic exes combined. Jeez xD

















