a14446ed71 
							
						 
					 
					
						
						
							
							unbound/dns-over-tls.conf: add Cloudflare, Mullvad & Control D  
						
						... 
						
						
						
						This is now practically https://www.privacyguides.org/en/dns/  plus Appliedprivacy 
						
						
					 
					
						2024-04-29 08:29:07 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							9430c59d5c 
							
						 
					 
					
						
						
							
							sway: map +Shift+Return to foot, so I have even less concerns about foot server  
						
						
						
						
					 
					
						2024-04-29 07:59:59 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							0ee83e9a90 
							
						 
					 
					
						
						
							
							chrony/sources: enable xleave with ~everything  
						
						... 
						
						
						
						I was unable to find much information about this, but see the previous commit and Brave Leo said
> Yes, it's generally acceptable to use interleaved mode with a public NTP (Network Time Protocol) server, as long as you comply with the server's usage policies. This mode allows for time synchronization while also providing a fallback if the primary time source fails. However, keep in mind that public NTP servers are often subject to heavy traffic, so they may not provide the most accurate or timely synchronization. 
						
						
					 
					
						2024-04-29 06:55:16 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							6f0184b519 
							
						 
					 
					
						
						
							
							chrony/sources/ntppool: enable xleave  
						
						... 
						
						
						
						From https://community.ntppool.org/t/chrony-conf-noclientlog-vs-clientloglimit/2263/4  I got the impression it's fine to do and the manual says it's compatible with the basic mode and xleave supporting servers may still reply in basic mode sometimes so this shouldn't break anything 
						
						
					 
					
						2024-04-29 06:51:27 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							0f66e552c1 
							
						 
					 
					
						
						
							
							Revert "nts-servers.sources: no preferring non-ISP servers"  
						
						... 
						
						
						
						This reverts commit ff1bc7b3babe9c3b8e74ae6fd396d2b1a2e85dcf. 
						
						
					 
					
						2024-04-28 20:08:42 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							4081c974bb 
							
						 
					 
					
						
						
							
							unbound/cache.conf: make the min ttl an hour in my quest to break DNS  
						
						
						
						
					 
					
						2024-04-28 19:15:42 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							23672028d5 
							
						 
					 
					
						
						
							
							unbound/ecs.conf: attempt to send larger subnets than default around  
						
						
						
						
					 
					
						2024-04-28 18:02:18 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							d64b4f2001 
							
						 
					 
					
						
						
							
							systemd-resolved: add DNA/Moi & Elisa DNS servers  
						
						... 
						
						
						
						I was unable to find authoritative source for what is Telia's DNS 
						
						
					 
					
						2024-04-28 16:14:30 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							581096257f 
							
						 
					 
					
						
						
							
							local/share/applications: add a desktop entry for briar  
						
						
						
						
					 
					
						2024-04-28 13:52:58 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							41b88b5cb9 
							
						 
					 
					
						
						
							
							sway/autostart-p2p-communication.conf: point briar to my wrapper  
						
						
						
						
					 
					
						2024-04-28 13:51:38 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							44e22716f9 
							
						 
					 
					
						
						
							
							chrony sources: make add .sample to local-servers.sources, make it more useful for me  
						
						
						
						
					 
					
						2024-04-28 10:02:31 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							18a04b1351 
							
						 
					 
					
						
						
							
							{firefox,chromium}: disable protections for one.one.one.one  
						
						... 
						
						
						
						For some reason they make connection to 1.1.1.1 appear as no or unreachable. 
						
						
					 
					
						2024-04-28 09:21:29 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							55dcb2f2cd 
							
						 
					 
					
						
						
							
							systemd-resolved/98-local-resolver.conf: fix comment talking about alphabet while everything is now numerals  
						
						
						
						
					 
					
						2024-04-28 09:17:07 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							35b99a6bc0 
							
						 
					 
					
						
						
							
							systemd-resolved: add 99-lan-resolver.conf.sample for trusted LANs  
						
						
						
						
					 
					
						2024-04-28 09:13:46 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							5ab33c154e 
							
						 
					 
					
						
						
							
							systemd-resolved: rename conf files to have a number prefix  
						
						
						
						
					 
					
						2024-04-28 09:13:20 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							9375b3c2b2 
							
						 
					 
					
						
						
							
							unbound: add dot-cloudflare.conf  
						
						
						
						
					 
					
						2024-04-27 21:22:28 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							2aa221b77f 
							
						 
					 
					
						
						
							
							unbound/cache: take the cache-min-ttl: 3000 challenge  
						
						... 
						
						
						
						It will not affect web browsers which are using DoH for ECH eliminating most of breakage and I am just curious on will anything outside of web browser suffer that. 
						
						
					 
					
						2024-04-27 18:35:22 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							652c11391f 
							
						 
					 
					
						
						
							
							unbound/cache.conf: explicitly set serve-expired-reply-ttl to 30  
						
						
						
						
					 
					
						2024-04-27 16:52:39 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							d3773468fa 
							
						 
					 
					
						
						
							
							chromium/policies: add doh-{disabled,google}.json  
						
						
						
						
					 
					
						2024-04-27 16:18:40 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							a083a9d704 
							
						 
					 
					
						
						
							
							unbound/cache: comment cache-min-ttl=900, add commented 3000  
						
						
						
						
					 
					
						2024-04-27 15:42:29 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							30a27f980d 
							
						 
					 
					
						
						
							
							unbound/cache.conf: RFC 8767ish configuration  
						
						
						
						
					 
					
						2024-04-27 15:00:12 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							813878a4de 
							
						 
					 
					
						
						
							
							systemd/{iwd,systemd-networkd}.service.d: add appropiate symlinks  
						
						
						
						
					 
					
						2024-04-27 12:25:00 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							c59fe1ae53 
							
						 
					 
					
						
						
							
							sudoers.d/nordvpnd: also allow restarting tor-client.service  
						
						... 
						
						
						
						I have a suspicion I am adding it to the script sooner or later 
						
						
					 
					
						2024-04-27 12:21:07 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							ef9c4acfc3 
							
						 
					 
					
						
						
							
							sudoers.d/nordvpnd: also allow restarting Tor  
						
						
						
						
					 
					
						2024-04-27 12:10:15 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							955e52f5af 
							
						 
					 
					
						
						
							
							yum.repos.d: add google-Chrome.repo to workaround their crontab disliking my system  
						
						
						
						
					 
					
						2024-04-27 10:21:20 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							8fe7ff55e6 
							
						 
					 
					
						
						
							
							chromium: add managed black-theme-colour & recommended apps-as-homepage, disable-default-browser-check  
						
						
						
						
					 
					
						2024-04-27 10:08:43 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							b76b7cac5c 
							
						 
					 
					
						
						
							
							systemd/user: review vpn wants, rm transmission-daemon copy-paste  
						
						
						
						
					 
					
						2024-04-27 08:34:46 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							2113b593e7 
							
						 
					 
					
						
						
							
							Chromium & Firefox: force Bitwarden (for passkeys)  
						
						
						
						
					 
					
						2024-04-27 08:32:39 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							da85d0d9c7 
							
						 
					 
					
						
						
							
							firefox & chromium: allow PrivacyPass attestor & Keyoxide.org  
						
						
						
						
					 
					
						2024-04-27 08:31:05 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							61dc3706ab 
							
						 
					 
					
						
						
							
							systemd/{chrony,i2pd,yggdrasil}.service.d/mullvad-exclude.conf: fix mistakes and Requires=  
						
						
						
						
					 
					
						2024-04-26 17:43:37 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							1b64bc5e13 
							
						 
					 
					
						
						
							
							systemd/service.d: fix typo & use Requires= where appropiate  
						
						
						
						
					 
					
						2024-04-26 17:38:33 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							db7de1c3e4 
							
						 
					 
					
						
						
							
							systemd/service.d/unbound-wanted.conf: break circular skipping by removing After=  
						
						
						
						
					 
					
						2024-04-26 17:35:31 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							7f410148e3 
							
						 
					 
					
						
						
							
							aminda-nocron-rebootish.service: repeat that dns should be running  
						
						
						
						
					 
					
						2024-04-26 16:13:39 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							1d7308e74e 
							
						 
					 
					
						
						
							
							unbound: explicitly enable ede and it's log  
						
						
						
						
					 
					
						2024-04-26 13:53:50 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							ed21eb03cd 
							
						 
					 
					
						
						
							
							.pre-commit-config.yaml: switch to rbubley's prettier mirror  
						
						
						
						
					 
					
						2024-04-26 13:25:45 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							2f585209e7 
							
						 
					 
					
						
						
							
							matterbridge-cleanup.timer: use more human friendly term minutely on OnCalendar=  
						
						
						
						
					 
					
						2024-04-26 13:21:20 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							65f58dc224 
							
						 
					 
					
						
						
							
							systemd: aminda-nocron-rebootish.{service,timer} is a delayed variant of -ish  
						
						
						
						
					 
					
						2024-04-26 13:16:33 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							c55b20a89a 
							
						 
					 
					
						
						
							
							move systemd user units from conf/systemd/user to etc/systemd/user  
						
						... 
						
						
						
						symlink remains to show what is the correct location 
						
						
					 
					
						2024-04-26 13:05:08 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							b36fe67bc3 
							
						 
					 
					
						
						
							
							systemd/user: attempt to flatpak-update-user.{service,timer}  
						
						
						
						
					 
					
						2024-04-26 13:03:05 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							b8f720fa7f 
							
						 
					 
					
						
						
							
							aminda-nocron-reboot.timer: fix typo in comment  
						
						
						
						
					 
					
						2024-04-26 12:48:47 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							9e38fdf223 
							
						 
					 
					
						
						
							
							aminda-nocron-reboot.timer: add RemainAfterElapse=false  
						
						
						
						
					 
					
						2024-04-26 12:37:55 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							90b64c9543 
							
						 
					 
					
						
						
							
							systemd: rename aminda-nocron -> aminda-nocron-reboot for clarity  
						
						... 
						
						
						
						also opens up aminda-nocron-hourly etc. 
						
						
					 
					
						2024-04-26 12:30:58 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							b0ec7cffde 
							
						 
					 
					
						
						
							
							chromium/README: EnableOnlineRevocationChecks does also enable CRL  
						
						
						
						
					 
					
						2024-04-26 11:27:11 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							16d2f74135 
							
						 
					 
					
						
						
							
							systemd/aminda-nocron.service: explicitly start DNS too  
						
						
						
						
					 
					
						2024-04-26 11:08:15 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							def77bc4c3 
							
						 
					 
					
						
						
							
							systemd: add aminmda-nocron.{service,timer} for my @reboot crontabs for cronless systems (SteamOS)  
						
						
						
						
					 
					
						2024-04-26 10:43:08 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							901dbfe138 
							
						 
					 
					
						
						
							
							etc/hosts: attempt to increase legibility by adding leading and trailing #  
						
						
						
						
					 
					
						2024-04-25 19:45:11 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							21b59adfd2 
							
						 
					 
					
						
						
							
							etc/hosts/hostname: copy Debian behaviour as a good practice  
						
						
						
						
					 
					
						2024-04-25 19:40:56 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							7c3da50491 
							
						 
					 
					
						
						
							
							{bash,zshrc}: prepare for alias  
						
						
						
						
					 
					
						2024-04-25 17:39:20 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							daae569442 
							
						 
					 
					
						
						
							
							chmod: fix SC quoting, add verbosity for less dangerous things  
						
						
						
						
					 
					
						2024-04-25 17:37:26 +03:00 
						 
				 
			
				
					
						
					 
					
						
						
							
							
								
									
								
							
						
						
						
							
						
						
							fb65f717fc 
							
						 
					 
					
						
						
							
							etc: cleanup symlinks/files handled by init-browser-policies.bash  
						
						... 
						
						
						
						They brought no value to me, just confused me in git forges by clicktrapping me and not following the symlinks 
						
						
					 
					
						2024-04-25 17:31:09 +03:00