Rocksolid Light

Welcome to Rocksolid Light

mail  files  register  newsreader  groups  login

Message-ID:  

We can defeat gravity. The problem is the paperwork involved.


computers / alt.os.linux / recommended programs

SubjectAuthor
* recommended programsMarioCPPP
+- recommended programsCarlos E.R.
`* recommended programsDavid W. Hodgins
 `* recommended programsMarioCPPP
  `* recommended programsDavid W. Hodgins
   `* recommended programsMarioCPPP
    +* recommended programsDavid W. Hodgins
    |`* recommended programsCarlos E.R.
    | +- recommended programsDavid W. Hodgins
    | `* recommended programsJ.O. Aho
    |  `* recommended programsCarlos E.R.
    |   `- recommended programsJ.O. Aho
    `- recommended programsJ.O. Aho

1
recommended programs

<u1eirn$235qu$6@dont-email.me>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=2930&group=alt.os.linux#2930

  copy link   Newsgroups: alt.os.linux
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: NoliMihiFrangereMentulam@libero.it (MarioCPPP)
Newsgroups: alt.os.linux
Subject: recommended programs
Date: Sat, 15 Apr 2023 18:20:07 +0200
Organization: A noiseless patient Spider
Lines: 35
Message-ID: <u1eirn$235qu$6@dont-email.me>
Reply-To: MarioCCCP@CCCP.MIR
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Sat, 15 Apr 2023 16:20:07 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="82184731963aceac8dd7ab76049d6ff8";
logging-data="2201438"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+Tda93K+dZAAQaZLH0g3OI"
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101
Thunderbird/102.9.0
Cancel-Lock: sha1:9DpcPJkwkTRrdB9B/PwaOCeFWVA=
Content-Language: en-GB, it-IT
 by: MarioCPPP - Sat, 15 Apr 2023 16:20 UTC

I have discovered (yesterday) GNOME-ACTIVITY-JOURNAL

It is a Tracking SW that stores everything you do (even text
snippets one cuts/pastes from/to clipboard), opened files,
visited web, emails.

I am still far from exploiting its power (and dunno whether
or not it is possibile to filter off some useless things
stored, to reduce the amount of data to revise later), but
one thing is really "WORRYING" ... I installed it TODAY, and
it has made available activity traces dating back to more
than a month ago.

It seems that is able to tap to informations that the system
just stores by itself (where ? logs ? whose logs ?) or by
some of its services (SystemD logs ?). And I find it
somewhat worrying both the number of detailed traces of
usage stored and the fact that GNOME-ACTIVITY-JOURNAL does
not even ask for password to retrieve such info.

Apart from this, it seems a really powerful program and able
to improve "productivity" and daily schedule, recovering
suspended task, and finding past activities. So my
evaluation stays very positive on this program.

Now the problem I will inquiry over is : why and how much
usage traces I leave behind like a slime :D

--
1) Resistere, resistere, resistere.
2) Se tutti pagano le tasse, le tasse le pagano tutti
MarioCPPP

Re: recommended programs

<u1fc67$27941$2@dont-email.me>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=2933&group=alt.os.linux#2933

  copy link   Newsgroups: alt.os.linux
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: NoliMihiFrangereMentulam@libero.it (MarioCPPP)
Newsgroups: alt.os.linux
Subject: Re: recommended programs
Date: Sun, 16 Apr 2023 01:32:23 +0200
Organization: A noiseless patient Spider
Lines: 63
Message-ID: <u1fc67$27941$2@dont-email.me>
References: <u1eirn$235qu$6@dont-email.me>
<op.13gf6qrpa3w0dxdave@hodgins.homeip.net>
Reply-To: MarioCCCP@CCCP.MIR
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Sat, 15 Apr 2023 23:32:25 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="7fdc0548c2128223a587f9fc1a549fa1";
logging-data="2335873"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX190vGtRtehDSYgQQNnMeWu+"
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101
Thunderbird/102.9.0
Cancel-Lock: sha1:wPUoJNNAEMyOGsiRzLHrpTlz8SM=
Content-Language: en-GB, it-IT
In-Reply-To: <op.13gf6qrpa3w0dxdave@hodgins.homeip.net>
 by: MarioCPPP - Sat, 15 Apr 2023 23:32 UTC

On 15/04/23 20:26, David W. Hodgins wrote:
> On Sat, 15 Apr 2023 12:20:07 -0400, MarioCPPP
> <NoliMihiFrangereMentulam@libero.it> wrote:
>
>>
>> I have discovered (yesterday) GNOME-ACTIVITY-JOURNAL
>>
>> It is a Tracking SW that stores everything you do (even text
>> snippets one cuts/pastes from/to clipboard), opened files,
>> visited web, emails.
>>
>> I am still far from exploiting its power (and dunno whether
>> or not it is possibile to filter off some useless things
>> stored, to reduce the amount of data to revise later), but
>> one thing is really "WORRYING" ... I installed it TODAY, and
>> it has made available activity traces dating back to more
>> than a month ago.
>>
>> It seems that is able to tap to informations that the system
>> just stores by itself (where ? logs ? whose logs ?) or by
>> some of its services (SystemD logs ?). And I find it
>> somewhat worrying both the number of detailed traces of
>> usage stored and the fact that GNOME-ACTIVITY-JOURNAL does
>> not even ask for password to retrieve such info.
>>
>> Apart from this, it seems a really powerful program and able
>> to improve "productivity" and daily schedule, recovering
>> suspended task, and finding past activities. So my
>> evaluation stays very positive on this program.
>>
>> Now the problem I will inquiry over is : why and how much
>> usage traces I leave behind like a slime :D
>
> According to
> https://en.wikipedia.org/wiki/GNOME_Activity_Journal it uses
> https://wiki.archlinux.org/title/Zeitgeist which is what
> records the activity.

Maybe my English is poor enough not to be clear.
My perplexity arose not from the fact it relied on
Zeitgeist, but that it was able to exploit data well in
advance of its own install. Where such data came from ? Why
were they just in place to be fetched ? I dunno. But I am
completely ignorant which activities are normally LOGGED and
where and by who (I had suspected SystemD not because of
particular reasons, but since I knew it had its own journal,
not restricted to file system operations).

Have I been more clear ? The recordings turned up "from a
former past", as if sth was just recording before installing
Zeitgeist / gnome activity journal (zeitgeist was installed
contextually, as a dependency)

tnx for reply

>
> Regards, Dave Hodgins

--
1) Resistere, resistere, resistere.
2) Se tutti pagano le tasse, le tasse le pagano tutti
MarioCPPP

Re: recommended programs

<ph7sgjx2so.ln2@Telcontar.valinor>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=2935&group=alt.os.linux#2935

  copy link   Newsgroups: alt.os.linux
Path: i2pn2.org!rocksolid2!i2pn.org!weretis.net!feeder8.news.weretis.net!news.imp.ch!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: robin_listas@es.invalid (Carlos E.R.)
Newsgroups: alt.os.linux
Subject: Re: recommended programs
Date: Sun, 16 Apr 2023 05:44:25 +0200
Lines: 36
Message-ID: <ph7sgjx2so.ln2@Telcontar.valinor>
References: <u1eirn$235qu$6@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net 0bZ8KkxeTC1iU5l+X1iOHwjvWs7jkNdu3Fd1Bo/10Zf/iGBfHy
X-Orig-Path: Telcontar.valinor!not-for-mail
Cancel-Lock: sha1:tkG9iyI4j1X05H/m53UW1QCOJoI=
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101
Thunderbird/102.9.1
Content-Language: es-ES, en-CA
In-Reply-To: <u1eirn$235qu$6@dont-email.me>
 by: Carlos E.R. - Sun, 16 Apr 2023 03:44 UTC

On 2023-04-15 18:20, MarioCPPP wrote:
>
> I have discovered (yesterday) GNOME-ACTIVITY-JOURNAL
>
> It is a Tracking SW that stores everything you do (even text snippets
> one cuts/pastes from/to clipboard), opened files, visited web, emails.
>
> I am still far from exploiting its power (and dunno whether or not it is
> possibile to filter off some useless things stored, to reduce the amount
> of data to revise later), but one thing is really "WORRYING" ... I
> installed it TODAY, and it has made available activity traces dating
> back to more than a month ago.
>
> It seems that is able to tap to informations that the system just stores
> by itself (where ? logs ? whose logs ?) or by some of its services
> (SystemD logs ?). And I find it somewhat worrying both the number of
> detailed traces of usage stored and the fact that GNOME-ACTIVITY-JOURNAL
> does not even ask for password to retrieve such info.

Why should it? You already logged in, and it is your own data.

>
> Apart from this, it seems a really powerful program and able to improve
> "productivity" and daily schedule, recovering suspended task, and
> finding past activities. So my evaluation stays very positive on this
> program.
>
> Now the problem I will inquiry over is : why and how much usage traces I
> leave behind like a slime :D
>
>
>

--
Cheers, Carlos.

Re: recommended programs

<op.13gf6qrpa3w0dxdave@hodgins.homeip.net>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=2938&group=alt.os.linux#2938

  copy link   Newsgroups: alt.os.linux
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: dwhodgins@nomail.afraid.org (David W. Hodgins)
Newsgroups: alt.os.linux
Subject: Re: recommended programs
Date: Sat, 15 Apr 2023 14:26:40 -0400
Organization: A noiseless patient Spider
Lines: 35
Message-ID: <op.13gf6qrpa3w0dxdave@hodgins.homeip.net>
References: <u1eirn$235qu$6@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed; delsp=yes
Content-Transfer-Encoding: 8bit
Injection-Info: dont-email.me; posting-host="082c31f4dac90b7762713b00b53b6211";
logging-data="2258640"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19bJBru0a7J/qBfXQU6Rl67pn1W63mrsHA="
User-Agent: Opera Mail/12.16 (Linux)
Cancel-Lock: sha1:76zWTFaij4dJ1KtsQ/aZxAIGMks=
 by: David W. Hodgins - Sat, 15 Apr 2023 18:26 UTC

On Sat, 15 Apr 2023 12:20:07 -0400, MarioCPPP <NoliMihiFrangereMentulam@libero.it> wrote:

>
> I have discovered (yesterday) GNOME-ACTIVITY-JOURNAL
>
> It is a Tracking SW that stores everything you do (even text
> snippets one cuts/pastes from/to clipboard), opened files,
> visited web, emails.
>
> I am still far from exploiting its power (and dunno whether
> or not it is possibile to filter off some useless things
> stored, to reduce the amount of data to revise later), but
> one thing is really "WORRYING" ... I installed it TODAY, and
> it has made available activity traces dating back to more
> than a month ago.
>
> It seems that is able to tap to informations that the system
> just stores by itself (where ? logs ? whose logs ?) or by
> some of its services (SystemD logs ?). And I find it
> somewhat worrying both the number of detailed traces of
> usage stored and the fact that GNOME-ACTIVITY-JOURNAL does
> not even ask for password to retrieve such info.
>
> Apart from this, it seems a really powerful program and able
> to improve "productivity" and daily schedule, recovering
> suspended task, and finding past activities. So my
> evaluation stays very positive on this program.
>
> Now the problem I will inquiry over is : why and how much
> usage traces I leave behind like a slime :D

According to https://en.wikipedia.org/wiki/GNOME_Activity_Journal it uses
https://wiki.archlinux.org/title/Zeitgeist which is what records the activity.

Regards, Dave Hodgins

Re: recommended programs

<op.13g8domwa3w0dxdave@hodgins.homeip.net>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=2939&group=alt.os.linux#2939

  copy link   Newsgroups: alt.os.linux
Path: i2pn2.org!rocksolid2!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: dwhodgins@nomail.afraid.org (David W. Hodgins)
Newsgroups: alt.os.linux
Subject: Re: recommended programs
Date: Sun, 16 Apr 2023 00:35:38 -0400
Organization: A noiseless patient Spider
Lines: 28
Message-ID: <op.13g8domwa3w0dxdave@hodgins.homeip.net>
References: <u1eirn$235qu$6@dont-email.me>
<op.13gf6qrpa3w0dxdave@hodgins.homeip.net> <u1fc67$27941$2@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed; delsp=yes
Content-Transfer-Encoding: 8bit
Injection-Info: dont-email.me; posting-host="80aa2c53b9ce6356e3b0522ae4aea1cd";
logging-data="2548348"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19/sfcaUCIMAfOGGj+yGHXEcKjbpFSRXzg="
User-Agent: Opera Mail/12.16 (Linux)
Cancel-Lock: sha1:nh+PRqDuaFeUpM+Y4xf6yqQ6F08=
 by: David W. Hodgins - Sun, 16 Apr 2023 04:35 UTC

On Sat, 15 Apr 2023 19:32:23 -0400, MarioCPPP <NoliMihiFrangereMentulam@libero.it> wrote:
> Maybe my English is poor enough not to be clear.
> My perplexity arose not from the fact it relied on
> Zeitgeist, but that it was able to exploit data well in
> advance of its own install. Where such data came from ? Why
> were they just in place to be fetched ? I dunno. But I am
> completely ignorant which activities are normally LOGGED and
> where and by who (I had suspected SystemD not because of
> particular reasons, but since I knew it had its own journal,
> not restricted to file system operations).
>
> Have I been more clear ? The recordings turned up "from a
> former past", as if sth was just recording before installing
> Zeitgeist / gnome activity journal (zeitgeist was installed
> contextually, as a dependency)

If it's from prior to zeitgeist being installed, then it's getting most of
the history from the browser history and cache files.

Install the tree package if you haven't already, then open a terminal and
run "ls -l ./.mozilla/firefox/*.default/storage/default/|less" and the other
files "tree -ifa |grep firefox|less" shows.

Other browsers are similar. If you don't clear the cache and history or use
safe mode, everything is recorded. There is some in the journal, but not much
more than what rsyslog records.

Regards, Dave Hodgins

Re: recommended programs

<u248mt$3ve0v$1@dont-email.me>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=2972&group=alt.os.linux#2972

  copy link   Newsgroups: alt.os.linux
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: NoliMihiFrangereMentulam@libero.it (MarioCPPP)
Newsgroups: alt.os.linux
Subject: Re: recommended programs
Date: Sun, 23 Apr 2023 23:41:48 +0200
Organization: A noiseless patient Spider
Lines: 64
Message-ID: <u248mt$3ve0v$1@dont-email.me>
References: <u1eirn$235qu$6@dont-email.me>
<op.13gf6qrpa3w0dxdave@hodgins.homeip.net> <u1fc67$27941$2@dont-email.me>
<op.13g8domwa3w0dxdave@hodgins.homeip.net>
Reply-To: MarioCCCP@CCCP.MIR
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Sun, 23 Apr 2023 21:41:55 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="aabfb4399ed7955581ad378d445e444f";
logging-data="4175903"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18IJo6//5N0J4EkN+WDtWac"
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101
Thunderbird/102.10.0
Cancel-Lock: sha1:cV142bAEDZQf/7CxYRh6u5hDfXM=
Content-Language: en-GB, it-IT
In-Reply-To: <op.13g8domwa3w0dxdave@hodgins.homeip.net>
 by: MarioCPPP - Sun, 23 Apr 2023 21:41 UTC

On 16/04/23 06:35, David W. Hodgins wrote:
> On Sat, 15 Apr 2023 19:32:23 -0400, MarioCPPP
> <NoliMihiFrangereMentulam@libero.it> wrote:
>> Maybe my English is poor enough not to be clear.
>> My perplexity arose not from the fact it relied on
>> Zeitgeist, but that it was able to exploit data well in
>> advance of its own install. Where such data came from ? Why
>> were they just in place to be fetched ? I dunno. But I am
>> completely ignorant which activities are normally LOGGED and
>> where and by who (I had suspected SystemD not because of
>> particular reasons, but since I knew it had its own journal,
>> not restricted to file system operations).
>>
>> Have I been more clear ? The recordings turned up "from a
>> former past", as if sth was just recording before installing
>> Zeitgeist / gnome activity journal (zeitgeist was installed
>> contextually, as a dependency)
>
> If it's from prior to zeitgeist being installed, then it's
> getting most of
> the history from the browser history and cache files.
>
> Install the tree package if you haven't already, then open a
> terminal and
> run "ls -l
> ./.mozilla/firefox/*.default/storage/default/|less" and the
> other
> files "tree -ifa |grep firefox|less" shows.

tnx for competent advice.
I have sort of 7-8 browsers installed and sure, I save
everything.

But not only web-browsing data were found. Every cut/pasted
piece of text (from kate, LibreOffice, leafpad and other),
every folder opened, every video played with VLC or
SMPlayer, audio listened with clementine. Everything
conceivable seems to have left traces.
So I was wondering where from ... The browsers, yes, I knew
they cached a lot, because now I make manual backups with
FIND (including hidden dot files) and revise manually the
outcome in kate and refine the dirt with RegEx, and
regularly find a huge load of cached stuff under brower
abscribable paths.
But I did not expect that program was so smart in retrieving
everything ! It seems to be able to decode every particular
"format" used by all program installed, not just the place
the info are stored.
Seems more a FORENSIC TOOL than just a journaling utility !

>
> Other browsers are similar. If you don't clear the cache and
> history or use
> safe mode, everything is recorded. There is some in the
> journal, but not much
> more than what rsyslog records.
>
> Regards, Dave Hodgins

--
1) Resistere, resistere, resistere.
2) Se tutti pagano le tasse, le tasse le pagano tutti
MarioCPPP

Re: recommended programs

<op.13vlf9mua3w0dxdave@hodgins.homeip.net>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=2973&group=alt.os.linux#2973

  copy link   Newsgroups: alt.os.linux
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: dwhodgins@nomail.afraid.org (David W. Hodgins)
Newsgroups: alt.os.linux
Subject: Re: recommended programs
Date: Sun, 23 Apr 2023 18:44:23 -0400
Organization: A noiseless patient Spider
Lines: 44
Message-ID: <op.13vlf9mua3w0dxdave@hodgins.homeip.net>
References: <u1eirn$235qu$6@dont-email.me>
<op.13gf6qrpa3w0dxdave@hodgins.homeip.net> <u1fc67$27941$2@dont-email.me>
<op.13g8domwa3w0dxdave@hodgins.homeip.net> <u248mt$3ve0v$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed; delsp=yes
Content-Transfer-Encoding: 8bit
Injection-Info: dont-email.me; posting-host="50c754b17bee33306f6b6cda4dab0099";
logging-data="3600"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18UbTpB4Lge4NU4JZ/OhkCylubBXmDfjVE="
User-Agent: Opera Mail/12.16 (Linux)
Cancel-Lock: sha1:T/8YtYMY0AlXWhxE/Zcbwc5LOUo=
 by: David W. Hodgins - Sun, 23 Apr 2023 22:44 UTC

On Sun, 23 Apr 2023 17:41:48 -0400, MarioCPPP <NoliMihiFrangereMentulam@libero.it> wrote:
> tnx for competent advice.
> I have sort of 7-8 browsers installed and sure, I save
> everything.
>
> But not only web-browsing data were found. Every cut/pasted
> piece of text (from kate, LibreOffice, leafpad and other),
> every folder opened, every video played with VLC or
> SMPlayer, audio listened with clementine. Everything
> conceivable seems to have left traces.
> So I was wondering where from ... The browsers, yes, I knew
> they cached a lot, because now I make manual backups with
> FIND (including hidden dot files) and revise manually the
> outcome in kate and refine the dirt with RegEx, and
> regularly find a huge load of cached stuff under brower
> abscribable paths.
> But I did not expect that program was so smart in retrieving
> everything ! It seems to be able to decode every particular
> "format" used by all program installed, not just the place
> the info are stored.
> Seems more a FORENSIC TOOL than just a journaling utility !

Many programs store a list of recently opened files. Things from copy/paste
are not normally saved, but may be depending on the programs used and their
settings. Clipboard managers are an obvious case where the data is stored.
It depends on which desktop environment and clipboard program is being used
as to whether it's stored or not.

User data is stored in /home and /var with temporary things in /tmp and /run.

Programs can be designed to be easy to use, with lots of features or they can
be designed to be very secure. It's rare that user level programs are both easy
to use and highly secure.

Systems level programs tend to be designed to be secure, but are made as easy
as then can be while still secure. User level programs are generally designed
for ease of use with only as much security as can be gotten away with.

High security systems have as few programs installed as they can, and take extra
steps to minimize what's stored by them. Part of hardening a system is making
sure the number of programs installed (attack surface) is made as small as
possible.

Regards, Dave Hodgins

Re: recommended programs

<kamld6F96o5U1@mid.individual.net>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=2974&group=alt.os.linux#2974

  copy link   Newsgroups: alt.os.linux
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!news.mixmin.net!news2.arglkargh.de!news.karotte.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: user@example.net (J.O. Aho)
Newsgroups: alt.os.linux
Subject: Re: recommended programs
Date: Mon, 24 Apr 2023 08:20:22 +0200
Lines: 35
Message-ID: <kamld6F96o5U1@mid.individual.net>
References: <u1eirn$235qu$6@dont-email.me>
<op.13gf6qrpa3w0dxdave@hodgins.homeip.net> <u1fc67$27941$2@dont-email.me>
<op.13g8domwa3w0dxdave@hodgins.homeip.net> <u248mt$3ve0v$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net nKuMA+GMjn6yg9fWBI5DTQcg8o6ANDsO1oMvI/GPQFH8R5jH0o
Cancel-Lock: sha1:kA+MAtYZf2sEs75qEnv5XkiLp5Y=
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101
Thunderbird/102.10.0
Content-Language: en-US-large
In-Reply-To: <u248mt$3ve0v$1@dont-email.me>
 by: J.O. Aho - Mon, 24 Apr 2023 06:20 UTC

On 4/23/23 23:41, MarioCPPP wrote:

>>> where and by who (I had suspected SystemD not because of

what's this SystemD? something new?

> But not only web-browsing data were found. Every cut/pasted piece of
> text (from kate, LibreOffice, leafpad and other)

This depends on your clipboard settings and some applications may even
have their own clipboard history. For gnome I would recommend you
install Clipboard indicator/GPaste or similar so that you can edit your
history and in that regard getting a better control of your clipboard.

> every video played with VLC or SMPlayer, audio listened with clementine.

Those are from the individual applications logs. Take a look in the
applications configuration directory.

> But I did not expect that program was so smart in retrieving everything
> ! It seems to be able to decode every particular "format" used by all
> program installed, not just the place the info are stored.

Most applications do log in plain text, so not that difficult to get
information, people tend to think of similar log files, so it's just
matching a handful regex and you have covered like 95% of all log files.

--
//Aho

Re: recommended programs

<aquhhjxv64.ln2@Telcontar.valinor>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=2975&group=alt.os.linux#2975

  copy link   Newsgroups: alt.os.linux
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!lilly.ping.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: robin_listas@es.invalid (Carlos E.R.)
Newsgroups: alt.os.linux
Subject: Re: recommended programs
Date: Mon, 24 Apr 2023 11:30:18 +0200
Lines: 61
Message-ID: <aquhhjxv64.ln2@Telcontar.valinor>
References: <u1eirn$235qu$6@dont-email.me>
<op.13gf6qrpa3w0dxdave@hodgins.homeip.net> <u1fc67$27941$2@dont-email.me>
<op.13g8domwa3w0dxdave@hodgins.homeip.net> <u248mt$3ve0v$1@dont-email.me>
<op.13vlf9mua3w0dxdave@hodgins.homeip.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net g0ddEl695IvB0fEi/lLS6gO3SnXNSD0+4GSvOlKjYBVqzus7ra
X-Orig-Path: Telcontar.valinor!not-for-mail
Cancel-Lock: sha1:6ODw1Rl4DWsA3yEw3gj8sGZAslE=
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101
Thunderbird/102.9.1
Content-Language: es-ES, en-CA
In-Reply-To: <op.13vlf9mua3w0dxdave@hodgins.homeip.net>
 by: Carlos E.R. - Mon, 24 Apr 2023 09:30 UTC

On 2023-04-24 00:44, David W. Hodgins wrote:
> On Sun, 23 Apr 2023 17:41:48 -0400, MarioCPPP
> <NoliMihiFrangereMentulam@libero.it> wrote:
>> tnx for competent advice.
>> I have sort of 7-8 browsers installed and sure, I save
>> everything.
>>
>> But not only web-browsing data were found. Every cut/pasted
>> piece of text (from kate, LibreOffice, leafpad and other),
>> every folder opened, every video played with VLC or
>> SMPlayer, audio listened with clementine. Everything
>> conceivable seems to have left traces.
>> So I was wondering where from ... The browsers, yes, I knew
>> they cached a lot, because now I make manual backups with
>> FIND (including hidden dot files) and revise manually the
>> outcome in kate and refine the dirt with RegEx, and
>> regularly find a huge load of cached stuff under brower
>> abscribable paths.
>> But I did not expect that program was so smart in retrieving
>> everything ! It seems to be able to decode every particular
>> "format" used by all program installed, not just the place
>> the info are stored.
>> Seems more a FORENSIC TOOL than just a journaling utility !
>
> Many programs store a list of recently opened files. Things from copy/paste
> are not normally saved, but may be depending on the programs used and their
> settings. Clipboard managers are an obvious case where the data is stored.
> It depends on which desktop environment and clipboard program is being used
> as to whether it's stored or not.
>
> User data is stored in /home and /var with temporary things in /tmp and
> /run.
>
> Programs can be designed to be easy to use, with lots of features or
> they can be designed to be very secure. It's rare that user level
> programs are both easy to use and highly secure.
>
> Systems level programs tend to be designed to be secure, but are made
> as easy as then can be while still secure. User level programs are
> generally designed for ease of use with only as much security as can
> be gotten away with.
>
> High security systems have as few programs installed as they can,
> and take extra steps to minimize what's stored by them. Part of
> hardening a system is making sure the number of programs installed
> (attack surface) is made as small as possible.

Just remember than in Linux the login password only protects while the
system is running. If you have the hard disk in your hand, you can
access any file on it, no limits. Information is not encrypted or
otherwise protected. You can read mail from any user, all office files,
all logs.

If the system is running, then yes, the permission system will limit
what each user can do or read. But a program doesn't need your password
to collect your information.

--
Cheers, Carlos.

Re: recommended programs

<op.13wqrmvga3w0dxdave@hodgins.homeip.net>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=2976&group=alt.os.linux#2976

  copy link   Newsgroups: alt.os.linux
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: dwhodgins@nomail.afraid.org (David W. Hodgins)
Newsgroups: alt.os.linux
Subject: Re: recommended programs
Date: Mon, 24 Apr 2023 09:36:48 -0400
Organization: A noiseless patient Spider
Lines: 21
Message-ID: <op.13wqrmvga3w0dxdave@hodgins.homeip.net>
References: <u1eirn$235qu$6@dont-email.me>
<op.13gf6qrpa3w0dxdave@hodgins.homeip.net> <u1fc67$27941$2@dont-email.me>
<op.13g8domwa3w0dxdave@hodgins.homeip.net> <u248mt$3ve0v$1@dont-email.me>
<op.13vlf9mua3w0dxdave@hodgins.homeip.net> <aquhhjxv64.ln2@Telcontar.valinor>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed; delsp=yes
Content-Transfer-Encoding: 8bit
Injection-Info: dont-email.me; posting-host="50c754b17bee33306f6b6cda4dab0099";
logging-data="395906"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18W6+6hOzOCeH3X7nbDarjnkw/OF/pISng="
User-Agent: Opera Mail/12.16 (Linux)
Cancel-Lock: sha1:B2Q4mwvl/pFgjIKoNuUz/2ZIH3M=
 by: David W. Hodgins - Mon, 24 Apr 2023 13:36 UTC

On Mon, 24 Apr 2023 05:30:18 -0400, Carlos E.R. <robin_listas@es.invalid> wrote:
> On 2023-04-24 00:44, David W. Hodgins wrote:
>> High security systems have as few programs installed as they can,
>> and take extra steps to minimize what's stored by them. Part of
>> hardening a system is making sure the number of programs installed
>> (attack surface) is made as small as possible.
>
> Just remember than in Linux the login password only protects while the
> system is running. If you have the hard disk in your hand, you can
> access any file on it, no limits. Information is not encrypted or
> otherwise protected. You can read mail from any user, all office files,
> all logs.
>
> If the system is running, then yes, the permission system will limit
> what each user can do or read. But a program doesn't need your password
> to collect your information.

I only described part of the hardening process. Using encrypted file systems
is another part.

Regards, Dave Hodgins

Re: recommended programs

<kap8j0Flea0U1@mid.individual.net>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=2977&group=alt.os.linux#2977

  copy link   Newsgroups: alt.os.linux
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!news.mixmin.net!news2.arglkargh.de!news.karotte.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: user@example.net (J.O. Aho)
Newsgroups: alt.os.linux
Subject: Re: recommended programs
Date: Tue, 25 Apr 2023 08:00:00 +0200
Lines: 22
Message-ID: <kap8j0Flea0U1@mid.individual.net>
References: <u1eirn$235qu$6@dont-email.me>
<op.13gf6qrpa3w0dxdave@hodgins.homeip.net> <u1fc67$27941$2@dont-email.me>
<op.13g8domwa3w0dxdave@hodgins.homeip.net> <u248mt$3ve0v$1@dont-email.me>
<op.13vlf9mua3w0dxdave@hodgins.homeip.net> <aquhhjxv64.ln2@Telcontar.valinor>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net BI6CM0KgUr3Frsjx5NQJ3AM2uxTQgeVLWJOQeMQDaxJhcNGyZX
Cancel-Lock: sha1:Pj0nj9UWRIlUbv21IukFpJnFukA=
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101
Thunderbird/102.10.0
Content-Language: en-US-large
In-Reply-To: <aquhhjxv64.ln2@Telcontar.valinor>
 by: J.O. Aho - Tue, 25 Apr 2023 06:00 UTC

On 4/24/23 11:30, Carlos E.R. wrote:
> On 2023-04-24 00:44, David W. Hodgins wrote:

>> High security systems have as few programs installed as they can,
>> and take extra steps to minimize what's stored by them. Part of
>> hardening a system is making sure the number of programs installed
>> (attack surface) is made as small as possible.
>
> Just remember than in Linux the login password only protects while the
> system is running. If you have the hard disk in your hand, you can
> access any file on it, no limits. Information is not encrypted or
> otherwise protected. You can read mail from any user, all office files,
> all logs.

Not necessarily, fscrypt allows you to have encrypted home directories,
the data is encrypted as long as the user hasn't yet logged in. This has
also been done with luksfs a long time before fscrypt and the setup
works in a similar way.

--
//Aho

Re: recommended programs

<j58khjxgm3.ln2@Telcontar.valinor>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=2978&group=alt.os.linux#2978

  copy link   Newsgroups: alt.os.linux
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!lilly.ping.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: robin_listas@es.invalid (Carlos E.R.)
Newsgroups: alt.os.linux
Subject: Re: recommended programs
Date: Tue, 25 Apr 2023 08:22:11 +0200
Lines: 29
Message-ID: <j58khjxgm3.ln2@Telcontar.valinor>
References: <u1eirn$235qu$6@dont-email.me>
<op.13gf6qrpa3w0dxdave@hodgins.homeip.net> <u1fc67$27941$2@dont-email.me>
<op.13g8domwa3w0dxdave@hodgins.homeip.net> <u248mt$3ve0v$1@dont-email.me>
<op.13vlf9mua3w0dxdave@hodgins.homeip.net> <aquhhjxv64.ln2@Telcontar.valinor>
<kap8j0Flea0U1@mid.individual.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net gsovOUmWHrO15WhSBGPzKALp4U3WNPIaRVMxzEji5pGj3ey7CV
X-Orig-Path: Telcontar.valinor!not-for-mail
Cancel-Lock: sha1:JO/kveGUUw5NNON1DWBfEu1U+7c=
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101
Thunderbird/102.9.1
Content-Language: es-ES, en-CA
In-Reply-To: <kap8j0Flea0U1@mid.individual.net>
 by: Carlos E.R. - Tue, 25 Apr 2023 06:22 UTC

On 2023-04-25 08:00, J.O. Aho wrote:
> On 4/24/23 11:30, Carlos E.R. wrote:
>> On 2023-04-24 00:44, David W. Hodgins wrote:
>
>>> High security systems have as few programs installed as they can,
>>> and take extra steps to minimize what's stored by them. Part of
>>> hardening a system is making sure the number of programs installed
>>> (attack surface) is made as small as possible.
>>
>> Just remember than in Linux the login password only protects while the
>> system is running. If you have the hard disk in your hand, you can
>> access any file on it, no limits. Information is not encrypted or
>> otherwise protected. You can read mail from any user, all office
>> files, all logs.
>
> Not necessarily, fscrypt allows you to have encrypted home directories,
> the data is encrypted as long as the user hasn't yet logged in. This has
> also been done with luksfs a long time before fscrypt and the setup
> works in a similar way.

Of course you *can* encrypt home or partitions, but that is not the
default. When I say that "information is not encrypted" I mean that
applications do not use encryption to protect their data, config, log
files, etc. Heck, some applications do not even encrypt passwords!
(example: fetchmail, rsync).

--
Cheers, Carlos.

Re: recommended programs

<kaql3lFs7evU1@mid.individual.net>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=2984&group=alt.os.linux#2984

  copy link   Newsgroups: alt.os.linux
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!lilly.ping.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: user@example.net (J.O. Aho)
Newsgroups: alt.os.linux
Subject: Re: recommended programs
Date: Tue, 25 Apr 2023 20:39:49 +0200
Lines: 41
Message-ID: <kaql3lFs7evU1@mid.individual.net>
References: <u1eirn$235qu$6@dont-email.me>
<op.13gf6qrpa3w0dxdave@hodgins.homeip.net> <u1fc67$27941$2@dont-email.me>
<op.13g8domwa3w0dxdave@hodgins.homeip.net> <u248mt$3ve0v$1@dont-email.me>
<op.13vlf9mua3w0dxdave@hodgins.homeip.net> <aquhhjxv64.ln2@Telcontar.valinor>
<kap8j0Flea0U1@mid.individual.net> <j58khjxgm3.ln2@Telcontar.valinor>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net XlIFFpRihOBtAaf9hsJIqg5yEng4CK2DhEPzxESb8ncnUI6xBR
Cancel-Lock: sha1:D/NTmE0cEMlbvtYLSKPYfYXeBuU=
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101
Thunderbird/102.10.0
Content-Language: en-US-large
In-Reply-To: <j58khjxgm3.ln2@Telcontar.valinor>
 by: J.O. Aho - Tue, 25 Apr 2023 18:39 UTC

On 25/04/2023 08:22, Carlos E.R. wrote:
> On 2023-04-25 08:00, J.O. Aho wrote:
>> On 4/24/23 11:30, Carlos E.R. wrote:
>>> On 2023-04-24 00:44, David W. Hodgins wrote:
>>
>>>> High security systems have as few programs installed as they can,
>>>> and take extra steps to minimize what's stored by them. Part of
>>>> hardening a system is making sure the number of programs installed
>>>> (attack surface) is made as small as possible.
>>>
>>> Just remember than in Linux the login password only protects while
>>> the system is running. If you have the hard disk in your hand, you
>>> can access any file on it, no limits. Information is not encrypted or
>>> otherwise protected. You can read mail from any user, all office
>>> files, all logs.
>>
>> Not necessarily, fscrypt allows you to have encrypted home
>> directories, the data is encrypted as long as the user hasn't yet
>> logged in. This has also been done with luksfs a long time before
>> fscrypt and the setup works in a similar way.
>
> Of course you *can* encrypt home or partitions, but that is not the
> default.

Not at this moment, but the idea that RedHat with systemd is to make it
home directories to be able to both be transportable and encryptable.

> When I say that "information is not encrypted" I mean that
> applications do not use encryption to protect their data, config, log
> files, etc. Heck, some applications do not even encrypt passwords!
> (example: fetchmail, rsync).

Not everything is worth encrypt, but sure passwords should be but
fetchmail has a long history before encryption in transit was even
thought to be important, sadly it hasn't taken a step forward. One that
has is alpine.

--
//Aho

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor