Pixel 8 with GrapheneOS
Pixel 8 with GrapheneOS
Well it should be, because anyone who votes for Trump is voting to regress the country into an eventually authoritarian, fascist regime. It shouldn’t be a close race. It should be the majority voting to prevent that.
Default recommendation for new ex-Windows users is to use Linux Mint, it’s very simple and includes most things you need. Mint also has great documentation and community resources (forums, etc.), especially for beginners. It’s also based upon the most popular distro, which is Ubuntu. So there’s a high degree of Ubuntu compatibility, which is a plus.
After the distribution choice, there’s the desktop environment choice. Here, I’d recommend either the default one from Mint, which is called Cinnamon (use this if you don’t have a preference), or KDE Plasma as an alternative. Both are very similar to Windows, but more powerful in terms of customization and features. (Well, of course anything on Linux is very customizable already due to the open source nature, but these 2 already offer a lot of GUI customization options without any tinkering). It’s not recommended for a beginner to switch desktop environments, you can do that later on when you’re more comfortable with Linux. If you’re curious about the other desktop choices, try them out in a VM or separate system. At the beginning, always use the preinstalled desktop environment.
Only slight downside of Mint is that it still ships with X11 by default, which is the older graphical subsystem as the foundation of each desktop environment. Wayland is the new one [actually it’s just a set of protocols which the compositor implements, but that doesn’t matter here]. Many distros already use Wayland, but it’s still experimental on Mint. For many users, this will not make a difference in practice, which is good, but Wayland is more advanced and has more advanced features which will never land in X11, and also higher security. If you have any non-standard needs regarding things like HDR, adaptive VRR, different per-monitor refresh rates, no tearing, per-monitor scaling, good touch support, and other “advanced” things like that, chances are you’re better off with Wayland. Most users probably don’t need to care that much though.
Anyway, should you need a Wayland-based distro alternative, or generally a second distribution recommendation, I’d say Fedora. It’s also rather easy distro, maybe not as easy as Mint is, but also very user friendly and more ahead of the curve in comparison to Mint (newer kernel, newer packages, more frequent updates).
Most users will be fine using Mint as their first distro, though. Mint will also soon be updated to Wayland as well, it’s just a matter of time. Be sure to keep your system updated.
Gaming is actually easy on Linux but since most games are specifically written for Windows and the Windows stack (DirectX, etc.) and also primarily tested on Windows and many game devs don’t test on Linux, there are sometimes things that might not work out of the box or you might need to try different options or compatibility tool versions (e.g. experimental version of Proton, or GE-Proton, or things like that). But Valve and lots of other individuals are constantly improving the situation and fixing compatibility issues should any come up. Compatibility is generally super high these days (like around 90%) so most users will not have any problems, especially not if they are playing any kind of recent or popular games where there’s a lot of focus to get them to run well, but some specific things or titles still might not work. For example some unethical game studios (most notably Epic Games, Bungie, EA, Riot) utilize integrated anti-cheat tools in their games (most notably Fortnite, Valorant, LoL, Destiny 2, Battlefield) which deliberately block all Linux users, even though the games would technically run on Linux as well. You can and should check protondb.com for general Linux compatibility reports of a Steam game, and areweanticheatyet.com for Linux compatibility of games which include anti-cheat components. If you’re not sure, check both sites. An anti-cheat component often only exists for the multiplayer part of a game, not for the single-player part. Most single-player games do not have or need any anti-cheat components. Generally, do not install games on an NTFS partition or re-use your Windows-based NTFS partition for games. This can and will cause problems. Always install your games on Linux partitions like ext4, btrfs or xfs.
If you use dual-boot (Linux being installed on another partition alongside Windows), be sure to disable the “fast startup” option in Windows (somewhere in the power management settings). And if you have an issue of the clock being wrong after you boot the other OS, then you maybe want to configure Linux to write the time back into the hardware clock in your local time format, which is what Windows expects to find there. But you can also reconfigure Windows to write its time back in UTC format (registry setting), which might be the format Linux expects to read from the hardware clock. Not sure what Mint does by default. I’d say only look into this if you have problems of the clock being wrong after you boot from Windows to Linux or from Linux to Windows. If the clock is always right, then you don’t need to reconfigure anything. Just keep in mind that Windows by default writes back its time in local format, Linux in UTC format.
If you want to install additional software: If you come from Windows, you might be familiar with visiting websites of software then downloading a setup.exe/msi from there. That’s NOT how you install software on Linux. On Linux, you first look if there’s a package available for your distribution (use the preinstalled programs/tools for that). The primary place for this is your distro’s package repositories. Then you might check Flathub (the default Flatpak (distribution independent) package repository). You will find most software there already. If you don’t find it there, check any Mint community repositories. Afterwards, check if there’s an AppImage available (those are basically one file which contains all files needed for the program, no installation). If you still don’t find anything, ask on a Mint forum. You usually DO NOT install a software from its source code form or any installer/setup scripts, especially not as a beginner. This is an easy way to make it either too complicated or to break your system. Always try to find existing packages for your distro first (use the preinstalled programs/tools for that), then try the distro independent Flatpaks, then AppImages. You should find everything you need like that. When you think of installing software on Linux, think of how you’d install software on Android or iOS, you use an “App Store” or install an existing package (similar to .apk / .ipa) directly. Any other method is NOT recommended for a beginner. On Mint/Ubuntu/Debian, software package files have the .deb extension.
There’s a perceived unpopularity with these genres. However, some truly great games like Baldur’s Gate 3 are living proof that you can make a niche genre very popular. It’s just that almost no one tries, or doesn’t like the risk involved. That’s why you don’t see a lot of these genres anymore. Well, you DO see them, if you look close enough and include indie and A/AA titles, but a massive AAA title with big budget and advertising for those genres is pretty much non-existant (I’m not familiar of any other exception like BG3). I think big studios are unlikely to risk such things. Look for smaller game studios, they’re much more innovative and either keep “dead” genres alive or they try mixing genres in innovative ways.
Yes, it’s a dangerous combination of media/IT illiteracy/incompetence within the general public and profit-driven proprietary social media algorithms that only aim to keep people engaged for the longest time, no matter the content they are being served. And usually, the more extreme the content is, the higher the engagement, the more revenue to be made from serving ads to the users and selling their collected data. This currently leads to a rise of misinformation, anti-scientific thinking, and so on. Which just so happens to align with extreme right-wing ideologies.
Well with food something unusual at first feels weird but once you try it it might actually be good. I’ve had this experience quite a lot. Probably shows how much you’re conditioned to liking certain foods just because you’re used to them and grew up with them. So I’m not gonna judge how this would taste. But the first impression was like “ugh”.
MI is great, I played 1+2 when they were new (in the 90s), they were brilliant back then. These days, they’re probably still good point&click adventure games. There were some special editions or remasters which probably make them play well on modern machines. They belong to a long list of awesome LucasArts point&click adventures during the 90s and early 2000s. Most of these games are great. You should definitely try them out, especially if there are remasters available. But you can also play the originals using ScummVM most likely. Ron Gilbert is like the mastermind behind the series. He still creates adventure games to this day. And they’re all pretty good, but the genre is kind of niche these days. It wasn’t niche back then. It was just as big as action or soulslike games are today. The Monkey Island titles were probably the most successful or popular ones of the bunch. But there are some others which are equally good. Adventure games are rare these days but basically they are like puzzle games where you have to solve certain situations by combining items, finding items in the first place, trying different approaches, and so on. You kind of know once you’ve overcome a challenge when you were able to progress further in the game. There’s little to no handholding, but also little to no handholding needed. There’s one timing-based riddle in the original Monkey Island which I never liked that much, but it’s still a funny one. It’s not hard but it doesn’t really fit the genre well because nothing else is timing-based. It does fit the game’s art, setting and humor well though. The soundtrack is nice indeed. This is probably the most well-known track: https://invidious.nerdvpn.de/watch?v=FoT5qK6hpbw
Yes, but my post is for the people who DO care about privacy issues. I also don’t like the defeatist’s attitude. You can always start making things better. My post is for those who want to make a better informed decision, that’s all.
Well this whole area is mostly based on deceit. Like if they claim they MAY do something they will absolutely do it all the time, if they claim they aren’t getting anything from it, it just means they aren’t getting anything directly, but indirectly instead, or from a different involved party. I also like the message at the top of the page: “Under certain circumstances, you have rights under data protection laws in relation to your personal data.”. Under some circumstances you have rights. Which is weirdly accurate. Because in most circumstances, they will just sh*t on data protection rights. Which is also evident by everything being opt-out, rather than opt-in. And then, most likely, even when you disable everything, data will still flow somewhere. Then again, it’s an industry-wide problem. Not specific to Jagex.
Reasons are the data transmissions happening by default and Mozilla’s questionable inclusion of add-on things like Pocket. See for example:
https://www.kuketz-blog.de/mozilla-firefox-datensendeverhalten-desktop-version-browser-check-teil20/
vs.
https://www.kuketz-blog.de/librewolf-datensendeverhalten-desktop-version-browser-check-teil8/ and https://www.kuketz-blog.de/mullvad-browser-datensendeverhalten-desktop-version-browser-check-teil22/
You might need to translate the site to English. If you compare that, you can see why it’s easy to recommend the forks over the original. That said, you CAN configure Firefox to also behave well, but that takes an extra effort. It is far from there by default.
Well, they’re only doing what they announced already like 1-2 years ago. So we knew it was coming. This is also accompanied by Google making YouTube more restrictive when viewed with adblockers. Google is (somewhat late, to be honest) showing its teeth against users who block ads. I always expected it to happen but it took them quite some time. Probably they wanted to play the good guys for long enough until most users are dependent on their services, and now their proprietary trap is very effective.
On the desktop, you should switch to a good Firefox fork right now. Firefox can also be used but needs configuring before it’s good. The forks LibreWolf or Mullvad Browser are already very good out of the box. There’s the potential issue of the forks not being updated fast enough, but so far these two have been fast. Mullvad shares a lot of configuration with the Tor Browser, so using it may break some sites. LibreWolf might be “better” for the average user because of that, but otherwise I think Mullvad is the best Firefox fork overall.
On mobile, Firefox-based browsers aren’t recommended, because on Android, the sandboxing mechanism of Firefox is inferior to that of the Chromium-based browsers. And on iOS, all browsers (have to) run on Apple’s proprietary Webkit engine anyway, but well this is Apple we’re talking about so of course it’s all locked-down and restricted. It’s one of the reasons I don’t even like talking about Apple that much, just be aware that as an iOS user, your choice doesn’t mean as much when it comes to browsers, and your browser might not behave like you think it does on other platforms.
So on mobile, I’d suggest things like Brave, Cromite or Mull. Or Vanadium (GrapheneOS). If the browser doesn’t have built-in adblocking capability which sidesteps the MV3 restrictions, make sure to use an ad-blocking DNS server, so your browser doesn’t have to do it. But you still need it. Adblocking not only helps you retain your sanity when browsing the web in 2024, but it also proactively secures you against known and unknown security threats coming from ads. So adblocking is a security plus, a privacy plus, and a sanity plus. It’s absolutely mandatory. As long as the ad industry is as terrible as it is, you should continue using adblocks. All the time. On every device and on every browser.
The ad industry is itself to blame for this. There could in theory be such a thing like acceptable ads, but that would require ads to be static images/text, not fed by personal data, and not dynamically generated by random scripts which could compromise your security, and not overly annoying. Since that is probably never going to happen, you should never give up using adblockers. Since they basically fight you by reducing your security and privacy, you have a right to defend yourself via technical means.
Long-time GrapheneOS user here.
Can’t say anything about Motorola gestures.
Banking apps MIGHT not all work on GrapheneOS, if unsure check first, or ask on the GrapheneOS forum. I forgot the reasons but it’s probably something stupid like the banking app blocking any non-“Google-sanctioned” Android versions via the Play Integrity DRM kind of feature. It sucks, especially because GraphneOS is way more secure and private than any commercial Android, but what can you do, bad decisions are being done all the time.
GrapheneOS is my recommendation, it’s easy to install and can be used by tech-illiterate people as well because almost none of its security and privacy enhancing features require any special configuration work from the user or require advanced knowledge, it all happens mostly in the background with good default settings. Even for tech-savvy people this has the advantage of not requiring any tinkering or maintenance work, it feels like using any proprietary Android, just hardened and much more privacy-friendly.
You should still maybe be aware of these potential minor issues:
Some apps might refuse to work on any “unsanctioned” Android version via the Play Integrity thing, but so far this seems to be very rare (thankfully). If you find any, make sure to tell the developers that they should stop doing that.
Some apps might simply require Google Play services to be installed. On GrapheneOS, you can install them via the “Apps” app, and they will be slightly less terrible than they are on any other Android because they won’t run with full system rights, but instead they’ll be sandboxed and can be completely shut down by using the standard permissions system, which the user is blocked from doing on proprietary Android systems. But then again, if you must use them, then of course they’re going to require Network permission and they’ll use that to phone home to Google, as they always do on standard Androids as well. So it’s not recommended to install any proprietary apps from Google on top of GrapheneOS. Even though on Graphene, the amount of things an app is allowed to do is more limited compared to the huge amount of data an app can read and phone home on a propreitary Android system.
Some apps include certain widgets like Google maps which, again, require the respective app or Play services app to be installed as well. Depending on how these apps are written, they might simply fail completely when this dependency is not there. But so far, I’ve had luck, and some apps I’ve used which integrate a Google maps widget still worked without it. So it depends on the app and the quality of its developers.
When not having the Google play services installed (default), you won’t have access to Google’s push notification system in the cloud. Some apps, even some privacy-respecting apps like Signal, rely on that. Signal will work without, but then it uses a power-inefficient alternative based on websockets instead, which means Signal without Google play services drains your battery faster than it would otherwise. There are ways around this by using the Molly fork of Signal (Signal is open source and there is at least this one fork often being used as well) with the open source app “ntfy” and an either self-hosted or a privacy-respecting ntfy server instance somewhere to go along with it, which will then act as your own push notification server in the cloud. So you don’t need to contact Google’s stuff for that, and less connections overall to Google equals more privacy overall.
If you do decide to install the Google play services app on Graphene, make sure to allow it to run in the background. But, again, it’s not recommended to use any proprietary Google apps/services.
Once you have Graphene installed, be sure to use its integrated browser called Vanadium (a hardened Chromium fork) to download and install an “app store” of your choice. When I first started out, I installed the F-Droid apk first, then from within it Aurora as a Play Store client. Giving me access to a lot of open source and Play Store apps, respectively. F-Droid unfortunately has some potential disadvantages, which is why I recommend using Obtainium instead of the F-Droid client (you’ll still access the F-Droid repository sometimes because some APKs of open source apps are only hosted there, but at least you’ll avoid potential issues with the F-Droid frontend application then). Using Obtainium instead of F-Droid will be slightly more work at the beginning when compiling your needed open soruce applications, but afterwards it’s just as easy.
Make sure to configure a privacy-friendly and ad/tracker-blocking DNS server, as well as something like RethinkDNS or NetGuard Pro to control which apps are allowed to contact which hosts/IPs. Otherwise, while Graphene itself won’t violate your privacy, many apps will still do that (especially proprietary apps often contain several trackers).
If you need tutorial videos on how to install or initially configure Graphene, or Obtainium, watch the youtube channel “Side of Burritos”, excellent content.
If any of that sounds scary, it shouldn’t be. Most of these issues are really minor and it’s unlikely that you’ll be too negatively impacted by any of it, so give Graphene a try without Google services. There are great open source apps out there for all sorts of functionality. Just felt I should mention any potentially small pitfalls.
Other Android variants or ROMs are inferior to GrapheneOS in terms of security and privacy, unfortunately, so it’s best to buy a cheap Pixel (8th generation recommended due to strong hardware-based security) and install Graphene on it. Otherwise you’ll miss out on Graphene’s very strong security and privacy features. There are some other privacy and security oriented Android variants like Calyx or /e/OS or things like that, or even LineageOS, but they all, again, don’t reach up to Graphene’s level of security and privacy.
HTH
Arch breaking easily is such an over-exaggeration. I’ve run Arch so many years and the amount of tinkering I’ve had to do because of botched updaates is so minimal. Often times, they announce it on their main website even, with instructions on how to fix it. You also should have configured filesystem snapshots to easily revert after a bad update. Or have a USB installation medium ready to boot from and then repair/downgrade the affected bad package. That’s usually all there is to do, and it happens rarely.
If you have multiple problems after Arch upgrades, then I’d guess that’s a misconfiguration on your end, leading to unstable system behavior after updates. Arch doesn’t do any kind of hand-holding, you’re allowed to completely misconfigure and break your system, but then it’s also your own fault.
If you didn’t update for a while, you should probably update the archlinux-keyring package first, then do the rest of the updates. Otherwise, the other packages won’t be able to be updated when package signing keys changed in the meantime
So yeah, I wouldn’t recommend Arch for beginners, unless you really want to learn Linux the “hard way” and have a little bit of spare time and don’t mind reading on the Wiki, but still, Arch instability is kind of over-exaggeration. Arch is very stable for a rolling release distro, but you do have to do a little bit of maintenance every now and then. That’s the nature of rolling-release. I still wouldn’t call that unstable, though.
That doesn’t surprise me, and yes it was always because of anti-competitive practices, so I’m all for more neutrality, I’ll just add 2 shower thoughts:
Check out SyncThing for a peer2peer (device to device) solution which doesn’t necessarily need a server, but having an always-on device like a server is still great for using Syncthing as well. It’s easy to use, only slightly more involved than setting up Nextcloud or Dropbox or whatever. But all done via a web-based GUI. It works surprisingly well, stable and conflict-free for the complex syncing it has to do all the time. Basically you install SyncThing on all devices you want to keep in sync, and they will find each other via their IDs when they are online, and automatically sync all their directories which should be synced. Of course it’s open source and cross-platform too.
Probably because Google is actively and frequently banning many Piped or Invidious hosts, and is generally currently at war with “alternative frontends” to YouTube in an effort to make users browse YouTube directly and consume ads there, or buy YouTube Premium. This is in line with their current fight for more ad revenues across their products and services. You probably have to either search for another public instance which isn’t banned (yet) from accessing YouTube, or host your own instance.