# Anh Khoa > Anh Khoa's blog on privacy engineering, security engineering, and software development. Practical guidance for privacy-first, secure software systems. -------------------------------------------------------------------------------- title: "Privacy, Security & Software Engineering" url: https://anhkhoakz.github.io/index.md description: Privacy, security, and software engineering guidance by Anh Khoa. Practical insights for building secure, privacy-first software systems with evidence-aware approaches. -------------------------------------------------------------------------------- Privacy, security, and software engineering form the foundation of trustworthy digital systems in today's interconnected world. As technology evolves rapidly, engineers face increasing pressure to build applications that not only function correctly but also protect user data and resist sophisticated threats. This site provides practical guidance for professionals seeking to integrate privacy and security principles throughout the software development lifecycle. Privacy engineering begins with understanding data flows and user expectations. Before writing a single line of code, teams must conduct thorough privacy impact assessments to identify what personal information is collected, how it's used, and with whom it's shared. This proactive approach prevents costly redesigns later and ensures compliance with regulations like GDPR and CCPA. By documenting data processing activities early, developers create a clear roadmap for implementing appropriate safeguards. Secure architecture complements privacy efforts by establishing robust technical controls. A zero trust mindset assumes no component is inherently safe, requiring verification at every access point. Defense in depth layering multiple security controls ensures that if one measure fails, others continue to protect the system. Threat modeling during design phases helps anticipate potential attack vectors and implement countermeasures before vulnerabilities reach production. Systems development benefits immensely from integrating privacy and security from the start. Secure coding practices such as input validation, output encoding, and proper authentication prevent common vulnerabilities like injection attacks and cross-site scripting. Regular dependency scanning identifies risky third-party libraries before they introduce weaknesses. Automated security testing in CI/CD pipelines catches issues early, reducing remediation costs significantly compared to post-release fixes. Data minimization serves as a core principle connecting privacy and security. Collecting only essential information reduces both privacy risks and the attack surface available to malicious actors. When less data is stored, there's less to protect and less to potentially breach. This approach aligns with privacy by design principles while simultaneously improving security posture through reduced complexity. Encryption plays a vital role in protecting data both at rest and in transit. Strong cryptographic algorithms safeguard sensitive information from unauthorized access, while proper key management ensures that encryption keys themselves remain secure. Implementing perfect forward secrecy in communications prevents past sessions from being compromised if long-term keys are later exposed. Access control mechanisms enforce the principle of least privilege, ensuring users and systems only possess permissions necessary for their specific functions. Role-based access control (RBAC) simplifies permission management in large organizations, while attribute-based access control (ABAC) provides fine-grained granularity for complex scenarios. Regular access reviews prevent privilege creep over time. Audit logging and monitoring create essential visibility into system activities. Comprehensive logs enable detection of anomalous behavior that might indicate security incidents or privacy violations. Implementing real-time alerting on suspicious patterns allows rapid response to potential threats. Regular log reviews help identify trends and improve both security controls and privacy practices over time. Privacy-enhancing technologies offer advanced techniques for data protection. Differential privacy adds statistical noise to datasets, enabling useful analysis while preventing identification of individuals. Homomorphic encryption allows computation on encrypted data without decryption, maintaining confidentiality throughout processing. Secure multi-party computation enables multiple parties to jointly compute functions over their inputs while keeping those inputs private. Building secure, privacy-first software requires ongoing commitment rather than one-time effort. Regular security assessments, privacy audits, and penetration testing ensure controls remain effective against evolving threats. Staying informed about emerging vulnerabilities through threat intelligence feeds helps teams adapt defenses proactively. Continuous improvement cycles incorporate lessons learned from incidents and audits to strengthen systems over time. The intersection of privacy, security, and software engineering represents not just technical challenge but also ethical responsibility. Engineers hold significant power to shape how personal data is handled and protected. By prioritizing these principles from project inception, developers create systems that earn user trust, comply with regulations, and resist emerging threats. This site aims to equip professionals with the knowledge and tools necessary to build the next generation of trustworthy technology. What you will find here: - **Privacy** — practical techniques for data protection, privacy-by-design, and reducing unnecessary data collection. - **Security** — threat-aware setups, defensive security practices, and secure architecture patterns. - **Software engineering** — version control with Git, secure development workflows, and developer tools. This site is for engineers, privacy advocates, and anyone building or using software with a security-conscious mindset. Articles focus on real-world trade-offs, not theoretical perfection. -------------------------------------------------------------------------------- title: "Privacy" url: https://anhkhoakz.github.io/privacy/index.md description: Practical digital privacy guidance for browsers, operating systems, email, passwords, and everyday habits. -------------------------------------------------------------------------------- Privacy is about making deliberate choices for a specific threat model, not chasing perfect anonymity. These articles focus on practical changes that improve control over devices, accounts, and communications. ## Start Here - [A practical digital privacy checklist]({{< relref "blog/privacy-digital-life" >}}) - [Improve online privacy on a budget]({{< relref "blog/privacy-in-budget" >}}) - [Browsers for privacy and everyday use]({{< relref "blog/browsers-for-daily-using" >}}) - [How I configure Firefox for privacy]({{< relref "blog/how-I-configure-Firefox" >}}) - [Why email cannot provide strong privacy by default]({{< relref "blog/no-privacy-email" >}}) -------------------------------------------------------------------------------- title: "Security" url: https://anhkhoakz.github.io/security/index.md description: Threat-aware security notes about browsers, email, account protection, and practical defensive habits. -------------------------------------------------------------------------------- Security recommendations depend on what you are protecting and from whom. These notes explain trade-offs, limitations, and safer defaults without pretending that one tool fits every threat model. ## Related Articles - [Browsers for privacy and security]({{< relref "blog/browsers-for-daily-using" >}}) - [Configure Firefox with a threat-aware setup]({{< relref "blog/how-I-configure-Firefox" >}}) - [Email privacy and encrypted alternatives]({{< relref "blog/no-privacy-email" >}}) - [Improve online privacy on a budget]({{< relref "blog/privacy-in-budget" >}}) -------------------------------------------------------------------------------- title: "Software Engineering" url: https://anhkhoakz.github.io/software-engineering/index.md description: Software engineering notes about Git, development workflows, open-source software, and practical developer tools. -------------------------------------------------------------------------------- This topic covers the tools and habits that make software work easier to understand, maintain, and ship. The emphasis is on practical workflows and clear trade-offs rather than tool collecting. ## Related Articles - [Git explained: versioning, commits, and branching]({{< relref "blog/wtf-is-git" >}}) - [Useful macOS apps for developers]({{< relref "blog/useful-apps" >}}) -------------------------------------------------------------------------------- title: "About" url: https://anhkhoakz.github.io/about/index.md description: About Anh Khoa — software engineer focused on privacy engineering, security engineering, and building secure, privacy-first software systems. -------------------------------------------------------------------------------- Hello everyone! My name is Nguyễn Huỳnh Anh Khoa. I'm a graduate of [Ton Duc Thang University](https://tdtu.edu.vn/) with a degree in Software Engineering. I write about privacy, security, and software engineering. My work focuses on privacy engineering, secure software development, and application security. I care about building systems that respect user data by design. ## What I Work On - **Privacy engineering** — practical techniques for data protection, privacy-by-design, and reducing unnecessary data collection. - **Security engineering** — threat modeling, defensive security, account protection, and secure defaults. - **Software engineering** — version control with Git, development workflows, open-source tools, and clean architecture. ## Principles I believe in minimalism, stoicism, reading, programming, and adventure. These values shape how I build software and how I write. Minimalism helps focus on what matters. Stoicism teaches acceptance and resilience. Reading expands understanding. Programming creates useful things. ## Code Repositories You can find my public work on [SourceHut](https://sr.ht/~anhkhoakz/), [Codeberg](https://codeberg.org/anhkhoakz), and [GitHub](https://github.com/anhkhoakz). ## About This Website This site uses [Hugo](https://gohugo.io/) with the Bear Cub theme. It draws inspiration from [BearBlog](https://bearblog.dev/), [MidNight](https://midnight.pub/), and [Best Motherf\*cking website](https://bestmotherfucking.website/). The design is intentionally minimal. No heavy fonts. No unnecessary JavaScript. No tracking. It loads fast on any device and any network condition. ## Contact If you have questions or feedback, reach out via email. For a shorter update, see my [now page](/now/). -------------------------------------------------------------------------------- title: "Docs" url: https://anhkhoakz.github.io/docs/index.md description: Machine-readable endpoints and agent discovery documents published on this site: API catalog, OpenAPI, llms.txt, feeds, auth.md and skills. -------------------------------------------------------------------------------- # Machine-readable resources This site is static, public and read-only. Everything below is a plain `GET` with no authentication, designed so people, crawlers and automated agents can work with it. ## Discovery | Relation | URL | Notes | | --- | --- | --- | | `api-catalog` | [/.well-known/api-catalog](/.well-known/api-catalog) | API catalog, [RFC 9727](https://www.rfc-editor.org/rfc/rfc9727), `application/linkset+json` | | `service-desc` | [/openapi.json](/openapi.json) | [OpenAPI 3.1](https://spec.openapis.org/oas/v3.1.0) description of the content endpoints | | `service-doc` | [/docs/](/docs/) | This page | | `describedby` | [/llms.txt](/llms.txt) | Site index for language models | Every HTML response also carries these as `Link` response headers ([RFC 8288](https://www.rfc-editor.org/rfc/rfc8288)): ```http Link: ; rel="api-catalog"; type="application/linkset+json", ; rel="service-desc"; type="application/json", ; rel="service-doc"; type="text/html", ; rel="describedby"; type="text/plain" ``` ## Content endpoints | Endpoint | Format | Purpose | | --- | --- | --- | | [/llms.txt](/llms.txt) | Markdown | Site index: title, summary and important pages | | [/llms-full.txt](/llms-full.txt) | Markdown | Every published page and post in one file | | [/atom.xml](/atom.xml) | Atom 1.0 | Recent posts | | [/index.xml](/index.xml) | RSS 2.0 | Recent posts | | [/sitemap.xml](/sitemap.xml) | XML | Every canonical URL | | [/robots.txt](/robots.txt) | Text | Crawler rules, AI bot rules and Content Signals | ## Agent discovery documents | Document | URL | | --- | --- | | Auth.md (authentication notes) | [/auth.md](/auth.md) | | Agent Skills discovery index | [/.well-known/agent-skills/index.json](/.well-known/agent-skills/index.json) | | Web Bot Auth key directory (RFC 9421) | [/.well-known/http-message-signatures-directory](/.well-known/http-message-signatures-directory) | This origin has no OAuth authorization server, no MCP server and no A2A agent endpoint, so no OAuth, MCP or A2A discovery documents are published — advertising endpoints that do not exist would waste an agent's round trips. ## Content preferences `/robots.txt` declares [Content Signals](https://contentsignals.org/): ```http Content-Signal: ai-train=no, search=yes, ai-input=yes ``` Search and answer products may index and quote this material with attribution; training on it is not permitted. ## Authentication None is required — see [/auth.md](/auth.md) for credential use and the supported (anonymous) access methods. -------------------------------------------------------------------------------- title: "Now" url: https://anhkhoakz.github.io/now/index.md date: "2024-08-05" description: A short profile and the current focus of Anh Khoa's technical blog. -------------------------------------------------------------------------------- --- My name is Anh Khoa, a junior student majoring in Software Engineering at [Ton Duc Thang University](https://tdtu.edu.vn/). I am a fan of minimalism, stoicism, reading, programming, traveling, and adventure, and my philosophy of life is rooted in these principles. I strive to learn, grow, and improve in all aspects of my life, and I enjoy helping others and creating value for the community. I believe that minimalism is a way of life that helps us focus on the most important things in life. It helps us to let go of the unnecessary and focus on what is truly important, such as time, health, and relationships. Stoicism is a philosophy of life that helps us to become stronger and overcome challenges. It teaches us how to accept what we cannot change and focus on what we can change. I believe that reading is a great way to learn and expand our knowledge. It helps us to better understand the world around us and about ourselves. Programming is a great way to express our creativity. It helps us to create new and useful things. Traveling and adventure are a great way to experience new things and learn about different cultures. I believe that we can all make a difference in the world. We can help others by giving our time, talent, and money. We can create value for the community by participating in volunteer activities and community projects. I hope you find this website helpful. I will try to update it with new articles regularly. If you have any questions or feedback, please contact me. ## What's This Blog Doing? I write blogs about personal life, privacy on Internet, some tips I've learnt, and some rules I've followed. --- -------------------------------------------------------------------------------- title: "Blog" url: https://anhkhoakz.github.io/blog/index.md description: Articles by Anh Khoa about privacy, security, software engineering, and practical developer tools. -------------------------------------------------------------------------------- Articles by Anh Khoa about privacy, security, software engineering, and practical developer tools. -------------------------------------------------------------------------------- title: "Services" url: https://anhkhoakz.github.io/blog/services/index.md date: "2025-09-29" description: A personal list of online services and tools I use, with privacy and practical trade-offs in mind. -------------------------------------------------------------------------------- A collection of services that I use and recommend. ## AI [Grok](https://grok.com) [Perplexity](https://www.perplexity.ai) [ChatGPT](https://chatgpt.com) [NotebookLM](https://notebooklm.google.com) [Gemini](https://gemini.google.com/app) [Copilot](https://github.com/copilot) ## Text Paste [Private Bin snip.dssr.ch](https://snip.dssr.ch) [Private Bin bin.disroot.org](https://bin.disroot.org) [Source Hut Paste](https://paste.sr.ht) [Rentry](https://rentry.co) ## Send Files [SkySend](https://ch.skysend.ch/) [Wormhole](https://wormhole.app/) [Send](https://send.vis.ee/) ## Draw [Excalidraw](https://excalidraw.com/) [Drawio](https://drawio.framalab.org/) ## Meeting [Jitsi Meet](https://engagemedia.org/projects/jitsi-meet/) --- -------------------------------------------------------------------------------- title: "Digital Privacy: A Practical Checklist" url: https://anhkhoakz.github.io/blog/privacy-digital-life/index.md date: "2025-07-23" description: A practical digital privacy checklist covering operating systems, browsers, email, passwords, networking, and everyday habits. -------------------------------------------------------------------------------- --- This checklist is part of the [privacy guide]({{< relref "privacy" >}}). For account and communication risks, also see the [security topic guide]({{< relref "security" >}}). ## Operating System Anything, but please avoid ChromeOS, there is no way to achieve privacy within this operating system. ### MacOS - **Apple ID**: You can bypass the prompt to sign in to Apple ID, but it prevents you from using AppStore, iTunes, and iCloud,... It is NOT required to download & install system update, and install apps from outside the AppStore. - **FileVault**: This step is to apply full-disk encryption to your MacBook. You can keep the recovery key on iCloud, or let device display 24-digit which you will copy it, store on encrypted container. - **AntiVirus**: I personally don't use AntiVirus, but I'm not against it. - **HomeBrew**: You can install homebrew follow instructions on their [website](https://brew.sh/). After that, enter this commands: `brew analytics off` - **AntiMalware**: I recommend you to use [KnockKnock](https://objective-see.org/products/knockknock.html) to scan your MacBook for malware. {{< figure src="/images/blogs/privacy-digital-life/knockknock.webp" alt="KnockKnock prompt" width="1408" height="812" >}} After install, allow their permissions and "Start Scan". If you see anything process that you don't want it to run, just move it to Trash or rename it. - **Firewall**: I recommend you to use [LuLu](https://objective-see.org/products/lulu.html) The built-in firewall of MacOS only block incomming connections, it's good, but it will not conver all cases. Each time your applications which make an outgoing connections, it will prompt you like this image. {{< figure src="/images/blogs/privacy-digital-life/lulu-01.webp" alt="LuLu prompt" width="1330" height="859" >}} You will manually choose if it should connect to network. For example: You install a calculator and LuLu prompt you to allow outgoing connections? That's weird. - **Camera & Microphone**: I recommend you to use [OverSight](https://objective-see.org/products/oversight.html) This app is simple, each time an app use your camera or microphone, it will prompt you like this image. {{< figure src="/images/blogs/privacy-digital-life/oversight.webp" alt="OverSight prompt" width="1380" height="616" >}} You can have options to allow or block it. Which I think pretty useful for online meeting too. - **Verify the structure of the system files**: You can use [Onyx](https://www.titanium-software.fr/en/onyx.html) ### Windows - Windows Defender: I recommend you to use Windows Defender which is pre-installed on Windows. - Please don't use [CCleaner](https://www.ccleaner.com/), you can use [BleachBit](https://www.bleachbit.org/) instead. - Disable Telemetry: You can disable telemetry by using [O&O ShutUp10](https://oo-software.com/en/) - Uninstall software: Using [Bulk Crap Uninstaller](https://www.bcuninstaller.com/). ## Password You can check if you're vulnerable to password leakage by using [HaveIBeenPwned](https://haveibeenpwned.com/). I recommend you to use for online is [1Password](https://1password.com/), [Bitwarden](https://bitwarden.com/), and if you prefer offline, you can use [KeePassXC](https://keepassxc.org/). I strongly discourage you to use [LastPass](https://www.lastpass.com/). You only need to remember one password, which is your master password. And all other passwords should be generated by using built-in password generator, which is strong and unique. For reading & Source code: - [SP 800-63B](https://pages.nist.gov/800-63-4/sp800-63b.html) - [keepassxreboot/keepassxc](https://github.com/keepassxreboot/keepassxc) - [bitwarden/server](https://github.com/bitwarden/server) ## Two-Factor Authentication For the best case, you should use hardware token, such as Yubikey, Nitrokey,... If it is not possible, you can use software token, such as built-in password manager, Ente Auth, Aegis Authenticator. You shouldn't use SMS, Google Authenticator, Authy,... This is an extra-step to protect your account from being hacked if your password is compromised. A modern authentication is Passkeys, which is a combination of password and fingerprint. ## Browser By default, MacOS has Safari, and Windows has Edge. But seriously, you shouldn't use them. I recommend you to use Firefox, and follow my instruction from [How I Configure Firefox]({{< relref "how-i-configure-firefox.md" >}}). Forks of Firefox: [LibreWolf](https://librewolf.net/), [Mullvad Browser](https://mullvad.net/en/browser) Another option is [Brave](https://brave.com/). But it comes with a lot of cryptocurrency-things, so you have to modified it a lot. Forks of Chrome: [ungoogled-chromium](https://github.com/ungoogled-software/ungoogled-chromium) ### Extensions - [uMatrix](https://github.com/gorhill/uMatrix) - [uBlock Origin](https://github.com/gorhill/uBlock) (less features than uMatrix but easy to use) - Filter lists: - You need to read each filter list carefully, and you should know what it does. - Recommended: [DandelionSprout/LegitimateURLShortener](https://raw.githubusercontent.com/DandelionSprout/adfilt/master/LegitimateURLShortener.txt) - [Decentraleyes](https://git.synz.io/Synzvato/decentraleyes) ## DNS I will recommend you some DNS servers: - [Cloudflare](https://1.1.1.1/) - [Mullvad](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls) - [AdGuard](https://adguard-dns.io/en/public-dns.html) ## Email Please avoid using Gmail. Some name of providers: - [Disroot](https://disroot.org) - [Autistici](https://www.autistici.org) - [Cork.li](https://cock.li/) - [ProtonMail](https://proton.me/mail) - [Tuta](https://tuta.com) I have a big question mark on ProtonMail, and Tuta, because those don't allow you to use your own email client, which is potientially inject a JavaScript to steal your credentials. For existing emails, you can use [Mailvelope](https://mailvelope.com) or set a forwarding email. For masking emails, I currenly use [SimpleLogin](https://simplelogin.io), or you can choose [AnonAddy](https://addy.io) ## Communication Just use [Signal](https://signal.org), [Telegram](https://telegram.org) is considered as a popular one, but I'm not sure if it is really safe. ## File Sharing You can use [Nextcloud](https://nextcloud.com) or [Send](https://send.vis.ee/), another instance of Send is [SkySend](https://ch.skysend.ch/). ## Note Taking You can use [Standard Notes](https://standardnotes.com/) or [Notesnook](https://notesnook.com/) ## Check List You can check and download my privacy checklist from [PrivateBin](https://snip.dssr.ch/?885b681ec9cc1ec8#2jxMwRPQjnFBVKn37QtC2J5eR6gBr1A8UavR5F2zq5iN) or [SourceHut's Paste](https://paste.sr.ht/~anhkhoakz/89466b81d1144f0f98a0c2e69236af57bf5aeaaa). --- -------------------------------------------------------------------------------- title: "Git Explained: Versioning, Commits and Branching" url: https://anhkhoakz.github.io/blog/wtf-is-git/index.md date: "2025-04-21" description: Git explained through semantic versioning, Conventional Commits, branching models, and practical release workflows. -------------------------------------------------------------------------------- This article is part of the [software engineering guide]({{< relref "software-engineering" >}}). --- ## Semantic Versioning {{< figure src="/images/blogs/wtf-is-git/semver.webp" alt="Semantic Versioning" width="1000" height="600" >}} The three-part version number `MAJOR.MINOR.PATCH` is used by the software versioning system known as Semantic Versioning (SemVer). The meaning of each component of the version number is distinct: - **MAJOR** version is used for incompatible API modifications. - **MINOR** version is used for backwards-compatible functionality additions. - **PATCH** version is used for backwards-compatible bug fixes. ## Conventional Commits A specification for creating consistent commit messages is called Conventional Commits. It offers a set of guidelines for crafting readable and intelligible commit messages. A standard commit message has the following structure: ```plaintext [optional scope]: [optional body] [optional footer(s)] ``` - The change type (e.g., feat, fix, chore, documentation, style, refactor, perf, test) is indicated by the **type** field. - **optional scope**: A scope can be anything that indicates where the commit modification was made, such as the file name or component. - **description**: A brief explanation of the modification. - **optional body**: If required, a more thorough explanation of the modification. Additional information regarding the update, such as breaking changes or issues resolved, may be included in the optional footer or footers. A commit message could resemble this, for instance: - **optional footer**: Additional information that may be relevant to the commit, such as links to related issues or pull requests. ## Git Branching Model {{< figure src="/images/blogs/wtf-is-git/git-flow.webp" alt="Git Branching Model" width="1200" height="1600" >}} A collection of rules for handling branches in a Git repository is known as the Git Branching Model. It offers an organized method for branching and merging, which facilitates the management of code updates and releases. There are various kinds of branches in the model: The primary branch containing the code that is ready for production is called - **master**: This branch ought to be deployable and stable at all times. The branch where development takes place is called - **develop**: Before being made public, features are merged into this branch. - **feature**: New features have their own branches. When finished, they are integrated back into develop. The branches used to get ready for a new production release are referred to as **release**. They enable preparation and last-minute repairs. - **hotfix**: Branches made to promptly fix production-related problems. Both master and develop have been integrated back into them. - **bugfix**: Code bugs are fixed using branches. When finished, they are integrated back into develop. - **chore**: Branches for standard operations that don't impact the operation of the application. ## Tools - **[Git](https://git-scm.com/)** (of course?): Git is a free and open source distributed version control system designed to handle everything from small to very large projects with speed and efficiency. - **[petervanderdoes/gitflow-avh](https://github.com/petervanderdoes/gitflow-avh)**: AVH Edition of the git extensions to provide high-level repository operations for Vincent Driessen's branching model. - **[lisawolderiksen/git-commit-template.md](https://gist.github.com/lisawolderiksen/a7b99d94c92c6671181611be1641c733)**: A template for writing commit messages that follow the Conventional Commits specification. - **[semantic-release](https://semantic-release.gitbook.io/semantic-release/)**: Semantic-release automates the whole package release workflow including: determining the next version number, generating the release notes, and publishing the package. - **[actions/semantic-pull-request](https://github.com/marketplace/actions/semantic-pull-request)**: This is a GitHub Action that ensures that your pull request titles match the Conventional Commits spec. Typically, this is used in combination with a tool like semantic-release to automate releases. ### Resources Semantic Versioning 2.0.0 - [url](https://semver.org) Conventional Commits - [url](https://www.conventionalcommits.org/en/v1.0.0/) A successful Git branching model - [url](https://nvie.com/posts/a-successful-git-branching-model/) Using git-flow to automate your git branching workflow - [url](https://jeffkreeftmeijer.com/git-flow/) Gitflow workflow - [url](https://www.atlassian.com/git/tutorials/comparing-workflows/gitflow-workflow) --- -------------------------------------------------------------------------------- title: "Some Articles" url: https://anhkhoakz.github.io/blog/some-articles/index.md date: "2025-01-19" description: Some blogs that I have read & video that I have watched -------------------------------------------------------------------------------- --- ## Blogs You Are NOT Dumb, You Just Lack the Prerequisites - [url](https://lelouch.dev/blog/you-are-probably-not-dumb/) Building software to last forever - [url](https://herman.bearblog.dev/building-software-to-last-forever/) Principles of bad software design - [url](https://digdeeper.club/articles/design.xhtml) Best practices for writing code comments - [url](https://stackoverflow.blog/2021/12/23/best-practices-for-writing-code-comments/) Start Here — Everyday Commentary - [url](https://www.everydaycommentary.com/start-here) ## Videos You Suck at Investing. - [url](https://youtu.be/SbUkmysgXFs) 100+ Linux Things you Need to Know - [url](https://youtu.be/LKCVKw9CzFo) Why Some Projects Use Multiple Programming Languages - [url](https://youtu.be/XJC5WB2Bwrc) 10 Things I Regret About Node.js - Ryan Dahl - JSConf EU - [url](https://youtu.be/M3BM9TB-8yA) Leatherman ARC Sheath Build - [url](https://www.youtube.com/shorts/ZZzA4TSI7pI) --- -------------------------------------------------------------------------------- title: "Useful macOS Apps for Productivity, Privacy and Developers" url: https://anhkhoakz.github.io/blog/useful-apps/index.md date: "2024-02-14" description: A maintained list of useful macOS apps for productivity, privacy, and software development, including free and paid options. -------------------------------------------------------------------------------- This maintained list supports the [software engineering guide]({{< relref "software-engineering" >}}) with tools that fit a developer-oriented macOS workflow. --- This is a collection of helpful macOS programs that I use every day. There are free, premium, and freemium options available. I'll do my best to maintain this list current. ## Terms - **FOSS**: Software that is both free (as in freedom) and open-source - **Freemium**: Business model and software licensing scheme in which the basic form of a product is free of charge, and access to additional features requires payment ## Productivity - [Alfred](https://www.alfredapp.com/): (£59) Alfred is an award-winning app for macOS which boosts your efficiency with hotkeys, keywords, text expansion and more. - [DropOver](https://dropoverapp.com/): ($6.99) Dropover is a macOS utility that makes Drag and Drop easier. - [HazeOver](https://hazeover.com/): ($5.99) Turn distractions down and focus on your current task. - [Rectangle Pro](https://rectangleapp.com/pro): ($9.99) Superior window management on macOS. - [Stretchly](https://github.com/hovancik/stretchly): (FOSS) The break time reminder app. - [Shottr](https://shottr.cc/): ($12) Shottr is a tiny and fast mac screenshot tool with annotations, beautiful backgrounds, scrolling screenshots and cloud upload capabilities. - [Clop](https://lowtechguys.com/clop/): ($15) Image, video, PDF and clipboard optimiser. Copy large, paste small, send fast. ## Privacy & Security - [LuLu](https://github.com/objective-see/LuLu): (FOSS) LuLu is the free open-source macOS firewall. - [OverSight](https://github.com/objective-see/OverSight): (FOSS) OverSight monitors a mac's mic and webcam, alerting the user when the internal mic is activated, or whenever a process accesses the webcam. - [KnockKnock](https://github.com/objective-see/KnockKnock): (FOSS) Like AutoRuns ...but for macOS! ## Development - [Podman](https://github.com/containers/podman): (FOSS) A tool for managing OCI containers and pods. - [xh](https://github.com/ducaale/xh): (FOSS) Friendly and fast tool for sending HTTP requests. - [Ghostty](https://github.com/ghostty-org/ghostty): (FOSS) 👻 Ghostty is a fast, feature-rich, and cross-platform terminal emulator that uses platform-native UI and GPU acceleration. - [Visual Studio Code](https://code.visualstudio.com/): (FOSS) Your code editor. Redefined with AI. - [Cursor](https://www.cursor.com/): (Freemium) AI-powered coding assistant. - [SnippetLab](https://www.renfei.org/snippets-lab/): ($0) Keep Your Code At Your Fingertips. ## Utilities - [1Password](https://1password.com/): ($2.99/month) 1Password is so much more than a password manager. - [OpenKey](https://github.com/tuyenvm/OpenKey): (FOSS) Vietnamese Input for macOS, Windows and Linux - Bộ gõ Tiếng Việt nguồn mở đa nền tảng. - [Keka](https://github.com/aonez/Keka): (FOSS) The macOS file archiver. - [KeyboardCleanTool](https://folivora.ai/keyboardcleantool): ($0) KeyboardCleanTool is a super simple little tool which blocks all Keyboard and TouchBar input. - [Mac Mouse Fix](https://macmousefix.com/): ($2.99) Make Your $10 Mouse Better Than an Apple Trackpad! - [AppCleaner](https://freemacsoft.net/appcleaner/): (Free) AppCleaner is a small application which allows you to thoroughly uninstall unwanted apps. - [Ice](https://github.com/jordanbaird/Ice): (FOSS) Ice is a powerful menu bar management tool. - [Signal](https://signal.org/): (FOSS) Say "hello" to a different messaging experience. - [Stremio](https://www.stremio.com/): (FOSS) Stremio offers a secure, modern and seamless entertainment experience. ## Casks - [biome](https://github.com/biomejs/biome): A toolchain for web projects, aimed to provide functionalities to maintain them. Biome offers formatter and linter, usable via CLI and LSP. - [btop](https://github.com/aristocratos/btop): A monitor of resources - [bun](https://bun.sh/): A fast, all-in-one JavaScript runtime. [dotenv-linter](https://github.com/dotenv-linter/dotenv-linter):⚡️Lightning-fast linter for .env files. Written in Rust 🦀 - [eza](https://github.com/eza-community/eza): A modern alternative to ls - [fastfetch](https://github.com/fastfetch-cli/fastfetch): A maintained, feature-rich and performance oriented, neofetch like system information tool - [fd](https://github.com/sharkdp/fd): A simple, fast and user-friendly alternative to 'find' - [fnm](https://github.com/Schniz/fnm): 🚀 Fast and simple Node.js version manager, built in Rust - [folderify](https://github.com/lindenlab/folderify): A tool to convert a flat folder structure into a nested folder structure. - [fzf](https://github.com/junegunn/fzf): A command-line fuzzy finder written in Go - [git](https://git-scm.com/): A free and open source distributed version control system designed to handle everything from small to very large projects with speed and efficiency. - [git-delta](https://github.com/dandavison/delta): A syntax-highlighting pager for git, diff, grep, and blame output - [git-toolbelt](https://github.com/nvie/git-toolbelt/tree/main): A suite of useful Git commands that aid with scripting or every day command line usage - [git-extras](https://github.com/tj/git-extras): GIT utilities -- repo summary, repl, changelog population, author commit percentages and more - [hugo](https://gohugo.io/): A fast and flexible static site generator that's perfect for personal, organization, or business sites. - [hyperfine](https://github.com/sharkdp/hyperfine): A command-line benchmarking tool. - [jq](https://github.com/jqlang/jq): Command-line JSON processor - [just](https://github.com/casey/just): 🤖 Just a command runner - [lazydocker](https://github.com/jesseduffield/lazydocker): The lazier way to manage everything docker - [markdownlint-cli](https://github.com/igorshubovych/markdownlint-cli): MarkdownLint Command Line Interface - [minify](https://github.com/tdewolff/minify): Go minifiers for web formats - [neovim](https://neovim.io/): Vim-fork focused on extensibility and usability - [pandoc](https://pandoc.org/): A universal document converter - [rclone](https://rclone.org/): Rclone is a command-line program to manage files on cloud storage. - [ripgrep](https://github.com/BurntSushi/ripgrep): ripgrep recursively searches directories for a regex pattern while respecting your gitignore. - [ruff](https://github.com/astral-sh/ruff): An extremely fast Python linter and code formatter, written in Rust. - [shellcheck](https://github.com/koalaman/shellcheck): ShellCheck, a static analysis tool for shell scripts - [GNU Stow](https://www.gnu.org/software/stow/): GNU Stow is a symlink farm manager which takes distinct sets of software and/or data located in separate directories on the filesystem, and makes them all appear to be installed in a single directory tree. - [taplo](https://github.com/tamasfe/taplo): A TOML toolkit written in Rust - [tlrc](https://github.com/tldr-pages/tlrc): A tldr client written in Rust - [zellij](https://github.com/zellij-org/zellij/): A terminal workspace with batteries included - [tree-sitter](https://github.com/tree-sitter/tree-sitter): An incremental parsing system for programming tools - [uutils-coreutils](https://github.com/uutils/coreutils): Cross-platform Rust rewrite of the GNU coreutils - [uv](https://github.com/astral-sh/uv): An extremely fast Python package and project manager, written in Rust. - [yt-dlp](https://github.com/yt-dlp/yt-dlp): A feature-rich command-line audio/video downloader - [zadark](https://github.com/quaric/zadark): ZaDark is an extension that helps you enable Dark Mode for Zalo PC and Web. ZaDark is available on Windows, macOS, Chrome, Safari, Edge and Firefox. - [zoxide](https://github.com/ajeetdsouza/zoxide): A smarter cd command. Supports all major shells. ## Visual Studio Code Extensions These are the extensions I keep coming back to in day-to-day work. ### Javascript & Typescript - [xabikos.JavaScriptSnippets](https://marketplace.visualstudio.com/items/?itemName=xabikos.JavaScriptSnippets): Code snippets for JavaScript in ES6 syntax. - [wix.vscode-import-cost](https://marketplace.visualstudio.com/items/?itemName=wix.vscode-import-cost): Display import/require package size in the editor - [biomejs.biome](https://marketplace.visualstudio.com/items/?itemName=biomejs.biome): Toolchain of the web --- -------------------------------------------------------------------------------- title: "How I Configure Firefox for Privacy" url: https://anhkhoakz.github.io/blog/how-i-configure-firefox/index.md date: "2024-01-15" description: A practical Firefox privacy configuration guide covering profiles, user.js, overrides, updates, and extensions. -------------------------------------------------------------------------------- This is a supporting guide for the [privacy topic]({{< relref "privacy" >}}) and its [security notes]({{< relref "security" >}}). --- I've recommended to all of you [Browsers for Daily Using] ({{< relref "browsers-for-daily-using.md" >}}). This is not a tutorial; it's just how I configure Firefox. You can find more information in the [arkenfox wiki](https://github.com/arkenfox/user.js/wiki). ## Step 1: Install Firefox Download and install Firefox from [Mozilla's FTP website](https://ftp.mozilla.org/pub/firefox/releases). You can choose your OS and decide whether to include [EME](https://hsivonen.fi/eme/) or not. You can also select the language, but I recommend using the `en-US` version. This version downloads Mozilla Firefox without a [download token](https://bugzilla.mozilla.org/show_bug.cgi?id=1677497#c0). Don't worry about outdated versions; Firefox will automatically update when you first run it. ### Step 2: Obtaining User.js You can configure Firefox yourself by entering `about:config` into the address bar, but I'll make it easier for you. 1. Download a `user.js`. You can choose: - **Easy**: [Betterfox](https://github.com/yokoffing/Betterfox/) - **Medium**: [arkenfox](https://github.com/arkenfox/user.js/) - **Hard**: [Narsil](https://git.nixnet.services/Narsil/desktop_user.js/) You can download it using `git clone`, `curl -O`, or by clicking the `Download` button. Downloading a single `user.js` file is sufficient, but downloading the entire project is recommended. 2. Turn off your network. You don't want Firefox to make any [connections](https://sizeof.cat/post/web-browser-telemetry/#mozilla-firefox) when you first run it. 3. Start Firefox and enter `about:profiles` in the address bar. 4. Create a new profile and ensure it's marked as `Default Profile: yes`. 5. Copy the `Root Directory` and exit Firefox. 6. Navigate to your profile directory and delete all contents from the new profile: ```sh cd /path/to/your/profile && rm -rf * ``` 7. Copy the `user.js` file into the profile folder: ```sh cp /path/to/user.js /path/to/your/profile ``` ### Step 3: Customize User Overrides A `user.js` file is like a uniform; it is made to fit everyone but may not fit you perfectly. You'll need some configurations to make it work best for you. You can customize it by editing the `user.js` file directly or creating a `user-overrides.js` file to override specific settings. Here are some configurations I recommend for anyone using arkenfox: - `extensions.pocket.enabled`: `False` - `identity.fxaccounts.enabled`: `False` - `browser.preferences.moreFromMozilla`: `False` I'm currently using arkenfox for ease of use. You can check out my [`user-overrides.js`](https://paste.sr.ht/~anhkhoakz/928da4827f209d1963c125669e842a4e1ee3876a). However, as I mentioned, it will only fit my needs. For more tutorials, please follow [this guide](https://github.com/arkenfox/user.js/wiki/3.1-Overrides). ### Step 4: Install Updater Script Install [updater.sh](https://raw.githubusercontent.com/arkenfox/user.js/master/updater.sh) by following [these instructions](https://github.com/arkenfox/user.js/wiki/3.4-Apply-&-Update-&-Maintain). Download the required files: ```sh curl -O https://raw.githubusercontent.com/arkenfox/user.js/master/prefsCleaner.sh curl -O https://raw.githubusercontent.com/arkenfox/user.js/master/updater.sh ``` Set permissions and execute: ```sh chmod +x ./prefsCleaner.sh chmod +x ./updater.sh ./updater.sh ./prefsCleaner.sh ``` ### Step 5: Restart Firefox Restart Firefox now so the updated preferences and extensions load cleanly. ### Step 6: Install Essential Extensions Here are some essential extensions I recommend: 1. [uBlock Origin](https://github.com/gorhill/uBlock) 2. [Multi-Account Containers](https://github.com/mozilla/multi-account-containers) 3. [Skip Redirect](https://github.com/sblask/webextension-skip-redirect) Check out additional extensions [url](https://github.com/arkenfox/user.js/wiki/4.1-Extensions). ### Step 7: Choose a Search Engine Consider using alternative search engines such as [searx](https://searx.github.io/searx/). Learn more about search engine options [url](https://digdeeper.neocities.org/articles/search). ### Custom Version of Firefox For a hassle-free alternative, explore [Librewolf](https://librewolf.net/) as a custom version of Firefox. --- -------------------------------------------------------------------------------- title: "How to Improve Online Privacy on a Budget" url: https://anhkhoakz.github.io/blog/privacy-in-budget/index.md date: "2024-01-13" description: Practical ways to improve online privacy on a limited budget, from browsers and email to passwords and device settings. -------------------------------------------------------------------------------- This article is part of the [privacy guide]({{< relref "privacy" >}}), with practical steps that fit different budgets and threat models. As a software engineering student, I love the beauty of tech, but I'm also afraid of it. Technologies help us a lot in every aspect of life. But it also brings a data hunger from big tech companies. But there is always a solution. You can get more privacy, so big companies can't have information about you, or they have at least. ## Web-Browser You can opt out of Google Chrome by using [Firefox](https://ftp.mozilla.org/pub/firefox/releases/) and [Ungoogled-chromium](https://ungoogled-software.github.io/), I have a [detailed review]({{}}). You have to separate your activities. Creating multiple profiles for multiple purposes is a good idea. ## Email I know that a lot of universities give Gmail accounts to their students. It's an easy way for them. You can't switch email services when using school email, but you can choose an alternative for personal purposes. You can check out [Tuta](https://tuta.com/), [Proton](https://proton.me/). They have an easy way to register. If you want to have PGP by yourself, I strongly recommend it. You may look at [Disroot](https://disroot.org/), [Cock.li](https://cock.li/), [Autistici](https://www.autistici.org/), or even G-Mail with [Mailvelope](https://mailvelope.com/) You can check out the E-mail providers - which one to choose? [^1] article from [DigDeeper](https://digdeeper.club/) which can give you reviews and a lot of suggestions. You have to notice that you **never** use school email for personal work, creating accounts,... It's something about privacy and security: 1. Some schools block emails outside the organization. 2. They can delete your email accounts when you leave the university. 3. An administrator can easily reset the password. 4. They can gain unauthorized access to your email account. But you can choose the **_TrustNoOne_** plan by encrypting your email manually using PGP. The software you can use is [The GNU Privacy Guard](https://gnupg.org/). An email client would be nice: [Claws Mail](https://www.claws-mail.org/), [NeoMutt](https://neomutt.org/), and [ThunderBird](https://www.thunderbird.net/) (which should be [hardened](https://github.com/HorlogeSkynet/thunderbird-user.js) for privacy concerns). Email clients will help you: 1. Choose the program you like. Not depending on the provider's JavaScript. 2. The mail client will remain constant. Prevent being served malicious JavaScript. 3. POP3 allows you to keep control of your data in your hands. 4. The variety of features. 5. Support PGP properly. ## Real-Time Messaging Although Facebook Messenger, Viber, and WhatsApp come with a lot of features. But they are data-hungers, no matter how encrypted they are. Those encryptions can only protect you from attackers, not from those companies. You can switch to [Signal](https://signal.org/), it's an encrypted messaging platform that has a good reputation, doesn't store your messages, and is very easy to use. Persuading friends to switch to Signal is hard work, but if you try, you will notice how the data that those companies get from you will decrease. You can check out some alternatives like [SimpleX Chat](https://simplex.chat/), [Briar](https://briarproject.org/), [Session](https://getsession.org/), and [Element](https://element.io/). ## Password Manager I strongly recommend that you use a password manager. It's again something about privacy and security. It can help you avoid using the same passwords for multiple platforms, which will reduce the chance of being hacked. A password manager is good, but it's something about the company that developed that service. You should never use the built-in password manager in browsers; it's very easy to hack. The built-in password managers on Apple and Android devices are good, but they lack multi-platforms, which will lock you in their ecosystem. I will recommend using [Bitwarden](https://bitwarden.com/), it's free and open source. You can get their premium for only $10 a year. Some alternatives like: [ProtonPass](https://proton.me/pass), [KeePass](https://keepass.info/), [1Password](https://1password.com/). ## Operating System You can create a new user account that doesn't have root permission. Check out [privacy.sexy](https://privacy.sexy/), it'll help you turn off telemetry from the OS. You can also create multiple user accounts for multiple purposes, just like with a web browser. An online sync platform, a hard drive partition, or a USB will help you transfer files and data. Linux is the best for privacy, but not all of them. You can check out the [Desktop/PC article](https://www.privacyguides.org/en/desktop/) and [Operating Systems](https://www.privacytools.io/os) for more recommendations. Be aware of Ubuntu. The operating systems you are using on your phone are mostly iOS or Android. You can check out Graphene OS. For iOS devices, you don't have too many choices, but you can have some configurations. It doesn't matter which OS you're using; make sure that you have strong encryption on your device. For an external drive, like a self-host cloud, USB, or hard disk, you can use built-in encryption or third-party software like [VeraCrypt](https://veracrypt.eu/). ## Networking You can use VPNs from Cloudflare (red flag), Proton, Mullvad (the best). It will prevent network administrators from looking for what you're doing by encrypting the data flow, creating a fake IP address, ... But be cautious, because it will mark you as using a VPN. Using cellular data is not a bad option if you can't use a VPN; it will not replace a VPN, but it will protect you from hackers. But the service provider will know what you're doing. You can choose a DNS resolver from [Mullvad](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls) or [Quad9](https://www.quad9.net/support/set-up-guides). For anything on the internet, you should stay away from Cloudflare [^2]. I'll guide you on how to reduce the amount of Cloudflare in soon. ## Software Using school software for school work and personal software for personal work only. Instead of using Office 365, you can check out [LibreOffice](https://www.libreoffice.org/). For sync files, you can use encryption cloud storage from Proton, Tresorit, Filen, pCloud, IceDrive,... But for the most affordable, you can encrypt your files before uploading by using [Cryptomator](https://cryptomator.org/), [7-zip](https://7-zip.org/), [rclone](https://rclone.org/),... You can also check FOSS (Free and Open Source Software) alternatives for every application you're using. And should stay away from proprietary software [^3]. For code development, you can check out [VSCodium](https://vscodium.com/) to replace VSCode although it lacks of some features. Maybe it will get a long blog for software only. For more information, you can check out: [Open Source Alternative To](https://www.opensourcealternative.to/) Using `https://alternativeto.net/software/YOURPRODUCTNAME/?license=opensource` [^1]: E-mail providers - which one to choose?, (last visited Jan. 13, 2024). [^2]: deCloudflare, (last visited Jan. 13, 2024). [^3]: Proprietary Software Is Often Malware, (last visited Jan. 13, 2024). -------------------------------------------------------------------------------- title: "Browsers for Privacy and Everyday Use" url: https://anhkhoakz.github.io/blog/browsers-for-daily-using/index.md date: "2024-01-11" description: A practical comparison of Firefox, LibreWolf, Mullvad Browser, Ungoogled Chromium, and Brave with privacy and security trade-offs. -------------------------------------------------------------------------------- This comparison supports the [privacy guide]({{< relref "privacy" >}}) and the [security topic guide]({{< relref "security" >}}). - [Gecko Engine](#gecko-engine) - [Firefox, but hardened](#firefox-but-hardened) - [LibreWolf](#librewolf) - [Mullvad Browser](#mullvad-browser) - [Blink Engine](#blink-engine) - [Ungoogled Chromium](#ungoogled-chromium) - [Brave Browser](#brave-browser) - [Throium](#throium) - [Extensions](#extensions) - [Conclusion](#conclusion) There are 4 browser engines that have **active** status: WebKit, Blink, Gecko, and Goanna [^1]. In this blog, I'll delve into the two most popular: [Gecko (Firefox-based)](#gecko-engine) and [Blink (Chromium-based)](#blink-engine). ## Gecko Engine This section covers the Firefox-based browsers I trust most for privacy. ### Firefox, but Hardened This is my first choice when it comes to a browser for privacy. I love the Firefox browser, but I don't really like the way Mozilla develops it. You can download Firefox on [Mozilla's website](https://www.mozilla.org/firefox/). But I don't recommend it because of the download token [^5]. Firefox includes a unique download token in downloads from Mozilla's website . You can download it from [Mozilla's FTP website](https://ftp.mozilla.org/pub/firefox/releases/), by this way, you can choose any version of Firefox and download it without the token. You can decide whether the latest, extended support release, or EME-free version. The default Mozilla Firefox will come with a large amount of telemetry and add-ons, which you don't really love to use. For better privacy, you can config in `about:config` or use the `user.js` file, but it takes knowledge, time, and effort to review and make changes. So you will need a template to configure the browser. There are three levels of hardening Firefox: 1. Easy: [Betterfox](https://github.com/yokoffing/Betterfox) 2. Medium: [arkenfox](https://github.com/arkenfox/user.js) 3. Hard: [Narsil](https://codeberg.org/Narsil/user.js/src/branch/main/desktop) It depends on you to select which one is appropriate. Betterfox provides a slight change to Firefox, which doesn't affect the your experience too much. On the other hand, Narsil provides the maximum privacy and security on Firefox, but it will change the way you use Firefox. If you want balance, choose arkenfox, it's the gold standard for Firefox. For comparison, you can use the PowerShell script [Compare-UserJS](https://github.com/claustromaniac/Compare-UserJS) to pick the most appropriate for yourself. And because they're templates, they are not fit for your use case. So you'll need a `user-overrides.js` to have your own modifications; you can check out the documentation for this one at [the Arkenfox Wiki](https://github.com/arkenfox/user.js/wiki/3.1-Overrides). ### LibreWolf Home page: [LibreWolf](https://librewolf.net/) Modifications: [librewolf.cfg](https://codeberg.org/librewolf/settings/raw/branch/master/librewolf.cfg) This project brings a mindless way to use Firefox without worrying about how to configure it. It looks like Ungoogled Chromium to Google Chrome. But I have had some bad experiences when using it: 1. It's not able to use 1Password biometrics because it lacks a code signature [^2]. But it can work well with Bitwarden or KeePassXC. - I have the solution at: Extending support for trusted web browsers [^6]. 2. Lacking of auto-update capacities raises a concern about security and zero-day vulnerability [^7]. But it can be fixed by using packet manager or using [LibreWolf WinUpdater](https://codeberg.org/ltguillaume/librewolf-winupdater). So if you want a mindless way to use Firefox, don't use 1Password, and don't need a built-in updater, LibreWolf will be the best for you. ### Mullvad Browser Home page: [Mullvad Browser](https://mullvad.net/en/browser) Modifications: [Hard facts](https://mullvad.net/en/browser/hard-facts). > Mullvad Browser is a collaboration between Mullvad VPN and the Tor Project. This is the new one; I have not tried it yet, but it makes 0 connections in the initial. This should be a strong competitor to LibreWolf, comes with strong privacy and anti-fingerprinting features. It has 3 extensions built-in: uBlock Origin, NoScript, and Mullvad Browser Extension. It includes auto-updates and creating new identity features. ## Blink Engine This section covers Chromium-based options and where they fit in my setup. ### Ungoogled Chromium Home page: [ungoogled-chromium](https://ungoogled-software.github.io/) Modifications: [Configuration Files](https://github.com/ungoogled-software/ungoogled-chromium/blob/master/docs/design.md#configuration-files) > A lightweight approach to removing Google web service dependency This is Chromium, so it will provide you with a bunch of extensions that will make your life easier. It seems like this is the only browser based on chromiu, and I will recommend my friends use it. You just need to make some modifications, and it will work like Brave. You'll have to install [chromium-web-store extension](https://github.com/NeverDecaf/chromium-web-store) to be able to install extensions from the Chrome Web Store. Here are some `chrome://flags` I use: - #extension-mime-request-handling: `Always prompt for install` - #chrome-labs: `Disabled` ### Brave Browser This is the most popular browser when you know the word **privacy**, and choose an alternative to Google Chrome. But it has a lot of issues and features that make me don't want to use it anymore: 1. It has 7 connections when you first install it [^3]. 2. It adds a "referral code" to the file name in downloads from the Brave website [^4]. 3. They have sponsored ads on browsers. 4. Brave Rewards needs a KYC account to use it. I used the Brave browser, but I'm not happy with it anymore. Anything it provides is just a cut-off of some extensions. And if you have an extension, it will do better. However, anything is better than Chrome, and you can have [some configurations](https://www.privacyguides.org/en/desktop-browsers/#recommended-configuration_1) to make Brave more private. ### Throium Throium is the last browser in this roundup, and it is included for completeness. ## Extensions - [uBlock Origin](https://addons.mozilla.org/firefox/addon/ublock-origin/) (Blocking Mode: Medium; AdGuard URL Tracking Protection; [➗ Actually Legitimate URL Shortener Tool](https://raw.githubusercontent.com/DandelionSprout/adfilt/master/LegitimateURLShortener.txt)) - [CanvasBlocker](https://addons.mozilla.org/en-US/firefox/addon/canvasblocker/) (If you disable resistfingeprinting) - Skip Redirect - 1Password or BitWarden - SimpleLogin - Firefox Multi-Account Containers - LibRedirect - Dark Reader - Greasemonkey - Omnivore - Linguist - LanguageTool ## Conclusion In conclusion, there is absolutely no such thing as the best browser for anything. It depends on you; it will only have a less bad browser. You can base your decision on my article; it is just something I gathered from the Internet. In my case, I'll recommend using [Firefox hardened](#firefox-but-hardened) and [Ungoogled chromium](#ungoogled-chromium) because they fit my needs. However, the ideal choice varies for each user, and the goal is to find a browser that meets their unique criteria. [^1]: Comparison of browser engines, (last visited Jan. 11, 2024). [^5]: [meta] Support download token, (last visited Jan. 11, 2024). [^2]: 1Password and the LibreWolf browser, (last visited Jan. 11, 2024). [^6]: Extending support for trusted web browsers, (last visited Jan. 11, 2024). [^7]: Zero-day vulnerability,, (last visited Jan. 11, 2024). [^3]: Web Browser telemetry - 2021 edition, Brave, (last visited Jan. 11, 2024). [^4]: Brave's Use of Referral Codes, (last visited Jan. 11, 2024). -------------------------------------------------------------------------------- title: "Why Email Cannot Provide Strong Privacy by Default" url: https://anhkhoakz.github.io/blog/no-privacy-email/index.md date: "2024-01-10" description: Why email cannot provide strong privacy by default, and when encrypted messaging or PGP may be a better fit. -------------------------------------------------------------------------------- This article belongs with the [privacy guide]({{< relref "privacy" >}}) and [security topic guide]({{< relref "security" >}}). --- After reading blogs and watching videos, I've come to realize that email lacks inherent privacy and security features. Even if you host a personal OpenBSD email server in an undisclosed nuclear bunker with a crypto domain connected to Tor, your emails still traverse ISP networks and reside on third-party servers. While it's crucial to prioritize privacy and move away from mainstream providers like Google, achieving secure communication requires alternatives to traditional email protocols. Signal, Matrix, and similar platforms offer better options for long-term privacy and security compared to standard email services like Gmail and Outlook. It's important to acknowledge that trusting any company, regardless of claims about zero trust, encryption, or adherence to privacy laws, carries risks. Even with end-to-end encryption, companies can potentially compromise your security, making it essential to explore options beyond conventional email. For enhanced privacy, consider using [Signal](https://signal.org/) or exploring alternatives. However, always exercise caution and, if needed, encrypt your emails using PGP and mail client add-ons like Enigmail. Remember, the cloud is essentially someone else's computer, emphasizing the need for personal responsibility in securing your communications. In conclusion, don't blindly trust any email provider's assurances of robust encryption or privacy. Consider employing Pretty Good Privacy (PGP) for email encryption or opt for messaging apps specifically designed for secure communication, such as Signal or Briar. [Why Metadata Matters](https://ssd.eff.org/module/why-metadata-matters) [Michael Hayden Gleefully Admits: We Kill People Based On Metadata](https://rightedition.com/2014/05/13/michael-hayden-gleefully-admits-kill-people-based-metadata/) --- -------------------------------------------------------------------------------- title: "categories" url: https://anhkhoakz.github.io/categories/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "blog" url: https://anhkhoakz.github.io/categories/blog/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "browser" url: https://anhkhoakz.github.io/categories/browser/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "email" url: https://anhkhoakz.github.io/categories/email/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "messaging" url: https://anhkhoakz.github.io/categories/messaging/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "networking" url: https://anhkhoakz.github.io/categories/networking/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "operating-system" url: https://anhkhoakz.github.io/categories/operating-system/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "password-manager" url: https://anhkhoakz.github.io/categories/password-manager/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "privacy" url: https://anhkhoakz.github.io/categories/privacy/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "security" url: https://anhkhoakz.github.io/categories/security/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "software" url: https://anhkhoakz.github.io/categories/software/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "video" url: https://anhkhoakz.github.io/categories/video/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "web-browser" url: https://anhkhoakz.github.io/categories/web-browser/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "tags" url: https://anhkhoakz.github.io/tags/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "apps" url: https://anhkhoakz.github.io/tags/apps/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "email" url: https://anhkhoakz.github.io/tags/email/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "macos" url: https://anhkhoakz.github.io/tags/macos/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "messaging" url: https://anhkhoakz.github.io/tags/messaging/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "networking" url: https://anhkhoakz.github.io/tags/networking/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "operating-system" url: https://anhkhoakz.github.io/tags/operating-system/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "password-manager" url: https://anhkhoakz.github.io/tags/password-manager/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "privacy" url: https://anhkhoakz.github.io/tags/privacy/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "read" url: https://anhkhoakz.github.io/tags/read/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "security" url: https://anhkhoakz.github.io/tags/security/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "software" url: https://anhkhoakz.github.io/tags/software/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "watch" url: https://anhkhoakz.github.io/tags/watch/index.md -------------------------------------------------------------------------------- -------------------------------------------------------------------------------- title: "web-browser" url: https://anhkhoakz.github.io/tags/web-browser/index.md --------------------------------------------------------------------------------