bf1fdc4cff
{firefox,chromium} policy: PB exclude Disroot Mvim, Microsoft {Teams,Learn}
2024-04-12 14:24:31 +03:00
b1a0125674
unbound: add local-tlds.conf
2024-04-12 14:16:10 +03:00
0d4c40ba16
systemd: mark systemd-resolved.conf to be conflicting with avahi-daemon
2024-04-12 10:58:15 +03:00
73865c747d
root-auto-trust-anchor-file.conf -> debian-root-auto-trust-anchor-file.conf
...
Let's not overwrite files accidentally
2024-04-12 10:56:51 +03:00
0bac3a8ab0
chromium: add doh-quad9.json
2024-04-12 10:42:51 +03:00
e88c2a8067
etc: attempt to enable mDNS/LLMNR for systemd-{networkd,resolved} & NetworkManager
...
Some boolean fixing slipped in as well
2024-04-12 09:52:32 +03:00
4d4dc026fd
unbound: ipv6.conf -> prefer-ipv6.conf
...
more descriptive name
2024-04-12 09:19:02 +03:00
a7bb2f5ec8
etc/iwd/main.conf: update comments on DNS
2024-04-11 10:16:21 +03:00
80ac65acd1
systemd-resolved/README.md: enable doctoc
2024-04-11 10:06:18 +03:00
cce932960e
systemd-resolved/README.md: mention nordvpn.conf
2024-04-11 10:05:18 +03:00
a2e36f2a3b
systemd-resolved/README.md: remove EOL Ubuntu, fix booleans, note my actual DNS config
2024-04-11 10:03:53 +03:00
da6eab8dfc
systemd-resolved: use true/false as booleans (not yes/no) & remove repeated localhost
2024-04-11 10:02:49 +03:00
3009af55a6
resolved.conf.d/README.md: mention 00-defaults and dot-something being supposed to be used together
2024-04-10 15:09:31 +03:00
9a210c4bba
systemd-resolved: further decrease repeating, comment DNS-Over-TLS since it's in 00-defaults.conf already (+ local resolver)
2024-04-10 15:06:14 +03:00
f12d0ceb8a
systemd-resolved: don't repeat cache
2024-04-10 15:02:30 +03:00
241405c776
systemd-resolved: merge unbound.conf into 00-defaults.conf
2024-04-10 11:59:36 +03:00
f885dcd73a
chromium/recommended: disable Tor in Brave
2024-04-10 11:21:52 +03:00
4cfd7ab75f
chromium: add recommendation of disabling Brave rewards & wallet
2024-04-10 11:18:42 +03:00
2282429f94
brave: use boolean for disabling vpn
2024-04-10 11:16:55 +03:00
149cadfa41
firefox & chromium: add IPFS Companion
2024-04-10 11:03:19 +03:00
d7879eeb6b
chromium: update README with the two new files
2024-04-10 10:53:37 +03:00
450aac4c32
chromium: add disable-brave-vpn.json
2024-04-10 10:51:38 +03:00
35e1faaabc
chromium: add doh-quad9-ecs.json
2024-04-10 10:51:15 +03:00
4a08068634
unbound/cache: serve-expired: yes
...
I am unsure on whether this actually affects anything without setting the other expired options too
2024-04-07 19:44:10 +03:00
b03218c78b
unbound/cache.conf: add prefetch & prefetch-key
2024-04-07 17:34:36 +03:00
c034e016e8
firefox policy: add search engine suggestion urls
2024-04-05 14:04:14 +03:00
99c63d25fe
{firefox,chromium} policy: add OpenDyslexic
2024-04-04 14:27:43 +03:00
08ae59ed99
firefox policy: configure Homepage
2024-03-31 08:46:12 +03:00
a581ee2dd5
rm etc/sysctl.d/99-enable-ipv6.conf
...
Refer to crontab, yggdrasil.service.d and nordvpn.service.d
2024-03-29 08:57:35 +02:00
323dde1545
{firefox, chromium}: force install privacy pass
...
This is in hopes of reducing family member frustation with captchas should they happen
2024-03-29 08:32:44 +02:00
1d05061bb4
hack nordvpnd to work with yggdrasil
2024-03-29 07:58:44 +02:00
9fb90d4b30
chromium/README: mention fix-edge-search.json
2024-03-28 18:57:29 +02:00
80df53aa6a
chromium: move edge policy from recommended searches to managed/fix-edge-search.json
2024-03-28 18:53:15 +02:00
c5dd75077d
chromium: throw home enabling & search engines into recommended policy instead
2024-03-27 16:51:29 +02:00
860970df78
etc/init-browser-policies.bash: note recommended policies
2024-03-27 16:43:17 +02:00
58df0709f4
firefox policy README.md: note that search engines also work on nightly
2024-03-24 08:17:31 +02:00
e823810723
firefox: add search engine aliases
2024-03-24 08:16:20 +02:00
4bab0cbb6a
firefox: default to Brave Search
2024-03-24 08:15:43 +02:00
7b80c2bbc2
chromium/aminda-extensions.json: remove DuckDuckGo Privacy Essentials
2024-03-23 12:46:49 +02:00
d241993c0a
chromium/aminda-extensions.json: remove blank new tab
2024-03-23 12:40:23 +02:00
4a2fc137db
chromium: handle Microsoft Edge new tab page Bing search
2024-03-23 12:36:30 +02:00
3d038bf826
chromium policy README.md: add missing/renamed files
2024-03-23 12:15:21 +02:00
b7acf2daaa
chromium policy: add brave-search.json
2024-03-23 12:08:07 +02:00
c8ece6032a
chromium/duckduckgo.json: policy for using start.duckduckgo.com for searching
2024-03-23 11:55:06 +02:00
405d407c2a
firefox: add Brave Search Goggles
2024-03-21 17:21:30 +02:00
3e56346be0
firefox: add Brave Search
2024-03-20 18:53:18 +02:00
cc6dbceaff
{firefox,chromium} policy: add UpdateSWH
2024-03-14 20:25:06 +02:00
39b0f1d19a
{firefox,chromium} policy: disable PrivacyBadger on Element Web instances
2024-03-13 11:45:19 +02:00
c2c7d401dd
sudoers.d: add teamviewerd
2024-03-13 09:07:25 +02:00
a6c2c28727
etc/yum.repos.d: add teamviewer.repo
2024-03-13 09:02:40 +02:00
0729b8b681
chromium policy: add Chrome Remote Desktop
2024-03-13 08:46:10 +02:00
be8e2d655e
aminda-extensions.json: fix allowed_url paths (paths unsupported, must not contain /*
2024-03-13 08:45:30 +02:00
7d48ac8a1a
sysctl.d/99-enable-ipv6.conf: workaround NordVPN
2024-03-12 17:55:32 +02:00
5c1dce8d36
{firefox,chromium} policy: explicitly configure PrivacyBadger
...
I think all of these default to true anyway, but explicit is better than implicit is what they say
2024-03-12 10:15:15 +02:00
cfe02d26be
chromiun: allow wayback machine to function on archive.org by default
2024-03-10 07:59:27 +02:00
e4304fd641
chromium: block uBlock Origin from Chrome/Edge stores to avoid conflict with AdNauseam force_install
2024-03-09 15:54:13 +02:00
e35c477a71
firefox policy: block uBlock & uMatrix to avoid conflict with force_install AdNauseam
2024-03-09 15:45:02 +02:00
685b14c2f6
firefox policy: block wayback machine
2024-03-09 15:41:39 +02:00
26ecc69156
chromium policy: add doh-mullvad-base.json
2024-03-09 10:52:54 +02:00
ee36e24997
Chromium policy: add blank new tab
2024-03-09 10:52:31 +02:00
3eb921f212
chromium: adjust runtime_allowed_hosts for DDG as per Edge's behaviour
2024-03-09 10:30:22 +02:00
d7244eefc5
aminda-extensions.json: click to run wbm
2024-03-08 11:19:07 +02:00
5149b23598
browser policies: add wayback machine
2024-03-08 08:41:41 +02:00
16d6a3df09
browser policies: install Bias Finder
2024-03-08 08:29:54 +02:00
0f23d25647
firefox policy: add offline-qr-code-generator
2024-03-04 12:29:45 +02:00
f2e8b86665
browser policies: remove AdNauseam advancedSettings
2024-03-02 16:26:47 +02:00
6029869230
browsers: force_install Privacy Badger again
...
While this isn't the recommended configuration, Privacy Badger has the
widget replacements, automatic learning (enabled by default as per
this policy), canvas protection etc.
AdNauseam again can replace NoScript (that I previously removed from
the policies for too aggressive for basic users) and fails to click ads
for me anyway, so I think this is the best option for me.
2024-02-29 11:22:29 +02:00
d242b05e76
browser policies: ship AdNauseam in filterAuthorMode
2024-02-29 08:56:59 +02:00
e343e80858
Weaken protection for Ad Nauseam since I am already so unique/fingerprintable
2024-02-28 20:55:46 +02:00
2d7539b0ed
browser policies: install AdNauseam
2024-02-28 20:04:08 +02:00
2e4744bc90
Don't install NoScript on browsers automatically due to being a bit extreme on unsuspecting family members after self-reflection.
2024-02-27 09:44:28 +02:00
5c3e5e29b3
browser policies: add Terms of Service;Didn't Read
2024-02-26 12:20:47 +02:00
8b0e28f417
firefox policies: also keep sidebery installed
2024-02-24 11:08:48 +02:00
2620f975fc
add etc/dnf/protected.d/
...
I am plotting switching to systemd-bootd in hopes of getting my kernel version unfrozen
2024-02-23 11:37:48 +02:00
3498e0d830
firefox. fix peertube-companion ID
2024-02-23 08:59:50 +02:00
4ff3705df0
firefox: force install peertube companion as a stronger stance against youtube centralization
2024-02-22 19:55:17 +02:00
6afb099d1c
chromium: don't enable the labs button
...
It has nothing that interesting and is just distraction.
2024-02-21 09:52:00 +02:00
c6304ca36a
chromium/doh-dns0: allow fallback to system dns
2024-02-21 09:51:20 +02:00
04be9339d5
Chromium: restrict DuckDuckGo to itself and google.com
2024-02-20 14:59:56 +02:00
4dbfd94d90
{chromium,firefox}: force install (& pin in Chromium) Snowflake too
2024-02-19 18:00:06 +02:00
303f69a671
firefox: actually force_install tab suspender
2024-02-19 16:45:36 +02:00
0f95863ea2
systemd/earlyoom.service.d: conflicts, never-fail & dynamicuser=false
2024-02-18 19:44:32 +02:00
52b2dd1e69
Chromium policy README.md: linkify extensions
2024-02-17 18:25:37 +02:00
11baf2e142
Chromium README.md: add TODO/Inconsistencies
2024-02-16 19:47:58 +02:00
a1056807bf
firefox: add peertubeify
...
as indiewiki buddy kind of opened the door for it
2024-02-16 19:41:45 +02:00
67ddd26f71
browser policies: include indiewiki buddy
2024-02-16 17:13:33 +02:00
fe8ac1bbb7
unbound: remove blocklists, deprecated by Browser Policy
2024-02-15 20:47:34 +02:00
398cf45bdf
add etc/systemd/oomd.conf.d/
2024-02-14 20:26:10 +02:00
f4423b251f
etc: add firefox-esr for Debian
2024-02-14 11:25:44 +02:00
22426e858c
firefox & chromium policy READMEs: links to upstream on top
2024-02-12 17:10:51 +02:00
c55b2a6aed
{systemd-resolved,unbound}: utilize unfiltered dns0 since nordvpn is unlikely to filter either
2024-02-11 13:37:32 +02:00
75d8833b03
firefox/policies.json: fix DDG Start Description & Method
2024-02-11 13:33:27 +02:00
75b938f3ce
firefox policies: restore pocket, searchengines
2024-02-11 13:23:04 +02:00
3b99fd30b7
Chromium policy README.md: note the PrivacyPass domains
2024-02-11 13:13:13 +02:00
2b45c13960
Chromium policy README.md: add forgotten NoScript
2024-02-11 13:11:37 +02:00
121aedd2ff
chromium: add noscript
2024-02-10 12:39:19 +02:00
d37d9e8019
firefox policies: add noscript
2024-02-10 12:34:52 +02:00
e4d223ab42
chromium: default unpin snowflake & silk
2024-02-08 10:54:05 +02:00
da0ab06fdf
chromium: install DuckDuckGo by default
2024-02-08 10:46:30 +02:00
7afdc0e046
firefox: install DuckDuckGo by default
2024-02-08 10:42:34 +02:00