Privacy

50695 readers
837 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 6 years ago
MODERATORS
276
277
 
 

(LONG RANT)-A public service announcement. I know it might be obvious since I am posting in Privacy. Most of you might know this already. But I have to rant. Just in case if this helps anybody. You can test this for yourself. Click on any, usually political posts, you will see nonstop arguing, then you will start getting more and more posts like that. Same thing with TikTok and Reddit for sure. The sites want you to engage more so you stay on there. Especially now in these crazy political times. I have grown very disgusted with this and have deleted every app I can think of that does it. It is also very bad for your mental health. Now, who knows what data they are trying to get from those sites too. And some sites require your phone number or some kind of stupid verification process. This will get worse, you might have to add your ID just to enter in more websites online eventually. It is happening already with age restricted adult sites and with Discord. But honestly, you should already be watching what your kids are doing anyway. There will always be parental control tools. Now, the social media apps sure don't help your child's mental health either. They could be talking to anybody on them, a very disturbing thought. With them also posting photos and videos. I would never let my child do that on any website. Too many creeps out there. Obviously, when they are an adult that is a different story. But, children being on sites like these is very harmful to their minds. Even kids apps, they can click on AI slop that might say the ABC's wrong or something like that. They have to be watched when you give them some random iPad. This whole rant might sound nuts, but I had to say it.

278
 
 

Starmer might be packing his bags, but the "Online Safety Act" is staying exactly where it is.

This isn't about safety; it’s a government-mandated monopoly. Private firms help write the laws, then "win" the contracts to sell the solutions. While the PM resigns, the "vicious circle" of corporate surveillance just keeps grinding forward.

279
 
 

Yes im aware that my search engine choice is not the best option.

280
 
 

A marked police van will be used outside major events or in crowded areas to live scan the faces of people walking past, in an Australian first.

The faces of people will be matched against a database of people with outstanding arrest warrants and registered child sex offenders, as well as missing persons.

"This is not about mass surveillance," [the police commissioner] said, "This is about specifying those in our community who are wanted by police."

While the trial only includes one marked van, the police commissioner is not ruling out further covert technology being used in the future, including at protests.

281
 
 

cross-posted from: https://lemmy.world/post/48515135

What could go wrong with forcing a data hungry AI company like Anthropic to force it's users to do ID verification?

https://techcrunch.com/2026/06/22/anthropic-says-claude-may-want-to-see-your-id

Meanwhile asylum-seekers are a great source for biometric data for the UK government: https://arstechnica.com/tech-policy/2026/06/the-uk-will-scan-asylum-seekers-faces-for-age-checks-despite-knowing-the-tech-is-flawed

As the West is trying to imitate totalitarian states as of late, they might be better advised to imitate their exports instead.

282
 
 

Have you tried them for privacy purposes? What are your experiences?

Here is mine. I've used the Visa prepaid cards. Where I live (USA) you can buy them "anonymously". Scare quotes because sure, nothing is 100% anonymous now. But you can buy them with cash and activate them without giving a phone #. Not quite as anonymous as cash, but close. It avoids the heavy data trail of a normal CC. And you can use them sometimes where you can't use cash.

But there's the prob. It's hit and miss if they work. Unfortunately, these are HUGE among scammers, so those scammer fucks poisoned the well. Some stores will flat out deny them. Other times, they work fine.

I've had probs at some point of sale terminals, others work OK. Ditto gas pumps. Seems to be no way to know which way it'll go without trying. Which means you gotta have another way to pay lined up.

I haven't tried them for online shopping yet.

283
 
 

If you are a Christian living in the Western United States, you have almost certainly been targeted with pro-Israel, anti-Palestine propaganda, paid for directly by the government of Benjamin Netanyahu. Your searches, location, and internet activity is being monitored by Israel, and your algorithms and search results across multiple platforms are being manipulated by Israeli government in what its American partner calls the “largest geofencing and targeted Christian digital campaign ever.”

Amid a massive drop in support from the Christian community, Israel is spending millions of dollars to target individuals entering churches or Christian colleges with ads, and paying pastors across the country to promote propaganda and false “anti-Palestinian” narratives every Sunday, documents filed with the United States’ Foreign Agents Registration Act (FARA) show.

The 86-page disclosure reveals that Israel is recruiting Hollywood celebrities and sports stars to promote the country, while also manipulating Christians’ social media feeds. And they are doing it by spying on you through your phone.

284
 
 

consumerrights.wiki/w/Leonardo_ELSAG_SignalTrace sjud.senate.ca.gov/content/bill-hearings/2026-bill-hearings/june-23-2026-bill-hearing

285
 
 

via https://old.reddit.com/r/privacy/comments/1ucesku/elsag_integrated_signal_intelligence_platform/

archived at https://web.archive.org/web/20260620122134/https://www.leonardocompany-us.com/lpr/elsag-signaltrace

ELSAG SignalTrace is a groundbreaking software system for law enforcement, designed to identify suspect people or vehicles, even when a license plate number is not known. This system integrates seamlessly with the ELSAG Enterprise Operations Center, our standard data management and analysis software.

This system uses strategically placed sensors to collect electronic communication patterns and identities of consumer electronics, like vehicle components, Bluetooth, RFID tags, and Wi-Fi. As the electronic devices emit signals, sensors in the SignalTrace software capture their identifying or categorizing details to create an additional data set to enhance the records captured by LPR cameras in the area.

Product Features

  • Identifies the movements of electronic devices, individuals, and vehicles
  • Stores data on the SignalTrace server where it can be queried and analyzed to aid investigations
  • Respects individuals’ privacy rights (does not decrypt or read content from devices)
  • Allows law enforcement to recognize a specific vehicle included in an electronic signature, without the license plate number
  • Reveals signatures frequently travelling together with an individual or vehicle, which can lead to the discovery of convoys and other movement and travel patterns
  • SignalTrace is effective in off-road areas such as in subways and malls
  • Performs with or without license plate readers at every collection site, allowing for a wider coverage area while keeping deployment costs down

How it works

As the devices emit signals, SignalTrace sites captures them and correlates them together, along with LPR data if present. The data collected shows what group of devices are travelling together. As part of investigations, algorithms can determine which specific mix of devices are predictably moving together. That specific mix of devices—linked by common time stamps and locations—are described as an electronic fingerprint and can aid in the identification of suspects or witnesses.

For example: while 70 cars in 100 may contain iPhones, only one will have an iPhone 13rev2, an Audi radio, a pair of Bose headphones, a Garmin sports watch, a key finder, and the license plate ABC-1234. The collection of data represented by these specific things is an electronic signature.

286
 
 

cross-posted from: https://lemmy.zip/post/66542364

No

I don't think so

287
 
 

cross-posted from: https://lemmy.world/post/48428963

I personally do, he actually risked his life to release information about the government spying on people. And there are for sure more advanced ways now. Even your phone is listening.

288
289
 
 

Meta has lobbied the U.S. Congress for legal immunity from child-harm claims tied to social media products such as Instagram, as it faces thousands of lawsuits from young users and their families, according to a source familiar with the matter and proposed legislative language reviewed by Reuters. If adopted by lawmakers and passed into law as part of the Kids Online Safety Act (KOSA) under consideration in the U.S. Senate, such a provision could undermine thousands of lawsuits against Meta and other online platforms over harms to children. Meta and Google's YouTube face a combined $6 million in damages after they lost the first case at trial early this year. While legislators have given no indication of adopting the language, the lobbying effort shows the kind of legal protections Meta is seeking amid the biggest attempt to regulate online platforms in the U.S. since the 1990s.

290
 
 

What a surprise when i discovered that you don't seem to need to backup Whatsapp messages any more. They apper to be stored on Meta servers. I'm sure it was not like this in the past? My wife left her GrapheneOS phone on the roof of the car and drove off. I managed to recover it but it had been ridden over by i car. So boight another pixel and installed Whatsapp again. She can't live without it as all her clients are on there. When i setup Whatsapp on new phone, all messages appered again, just like that. Spooky ... I think in the past it wasn't like that?

291
 
 

Just like the tools that the CIA or FBI have. But anybody could use it. It will know your address and even go as far as your social security number. Delete all your social media that has your personal photos on them, it will be used against you. By ai itself or the bad actors that use it. It is best to try to stay completely, anonymous.

292
 
 

I know Reddit now has a stupid rule or policy about new accounts posting or commenting. They punish new users for just trying to have a conversation. Why does Reddit hate privacy? Is it just in the system trying to filter out bots? Well, it is doing a shitty job since bots are still a high percentage there. Reddit banned me, even when I was on the new user friendly subs. I tried with multiple locations with a VPN too. This has to make people go to other platforms. Like I did, I moved here.

293
 
 

When talking about degoogle i always hear something to the effect of "but, my bank app bruh"

FUCK YO MUTHA FUCKIN BANK APP!!!

Like seriously, you lazy fuck head. You can use your fucking bank from this thing called a web browser. Some good examples are Firefox or Chromium.

If your bank does not allow you to use a website to manage your account, then SWITCH FUCKING BANKS!

I've heard that some people live in the European hellhole where you can't do banking from a website because of needing a phone to authenticate. In which case, buy yourself a cheap little ass Android phone that sits in a drawer powered off at all times unless you fucking need it.

You sorry excuse for a human being have no integrity because you talk like you want to maintain your sovereignty and then you're like, "oh, but it's too hard", so you do nothing.

-- vent over

294
 
 

[...]

In the new blog post, Google’s Matthew Forsythe confirms that the developer verification system is slated to come online on September 30 of this year. The initial deployment will be limited to countries with a high level of app scams: Brazil, Indonesia, Singapore, and Thailand.

[...]

Google released its new developer console back in March, inviting external developers the opportunity to pay $25 and verify their identities early. Developers who don’t register will find that their apps cannot be sideloaded on Google-certified Android devices once verification has rolled out. Google says that almost every app in the Play Store is now ready for the change, and a “large majority” of apps outside Google Play have completed verification.

[...]

Google says it will verify the apps in the following stores when it begins enforcing the new restrictions.

Google (Google Play)
Honor (HONOR App Market)
OPlus (OPPO App Market)
Samsung (Galaxy Store)
Transsion (Palm Store)
vivo (V-Appstore)
Xiaomi (GetApps)

[...]

The next step toward verifying apps will come this month as Google deploys a new system service on most certified devices. The package (com.google.android.verifier) will appear on phones and tablets running Android 8 or higher, allowing Google to block the installation of unverified apps. It will remain dormant until verification is activated in your specific region.

In July, Google plans to roll out the new developer APIs and begin testing for “limited distribution” accounts. This is Google’s solution for hobbyists who want to make their own apps and share them with a small group. Limited accounts won’t require a fee or government ID verification, but you can install these apps on up to 20 devices.

In August, the advanced flow will become available globally ahead of verification becoming mandatory in the first markets. As detailed a few months ago, the advanced flow will allow users to bypass verification, but the process isn’t easy. You’ll have to navigate to a buried menu, confirm you understand the risks multiple times, and wait a whole day before completing the process.

And that brings us to September, when Android devices in Brazil, Indonesia, Singapore, and Thailand will begin checking verification status before installing apps. However, things get murky after that. Google will undoubtedly monitor how verification works as millions of users are suddenly limited to verified apps, which could affect how it moves forward. Google says it intends to expand developer verification in 2027, eventually making it a global device policy.

295
 
 

I run 0807, a file host I host myself.

You drop a file, you get a short link, and you choose when it disappears.

I am posting it here because the whole thing is built around privacy, and because I would rather lay out the real threat model than call it "secure" and let you find the gaps later.

The privacy side:

  • No account, no sign up. An upload is not tied to any identity.
  • No ads, no third party trackers, no analytics. Nothing is loaded from outside domains, so no fonts or scripts phoning home.
  • The server does not log IP addresses or requests. The rate limiter holds an IP in memory for a few minutes to count requests, then forgets it. Nothing is written to disk.
  • Reachable over Tor through an onion service.
  • Auto delete by time (one hour to thirty days, or never) or after a chosen number of downloads.
  • Optional password on files and on text notes.
  • Files up to 20 GB.
  • Executable types like exe, bat and scripts are blocked so it cannot be used as a malware drop.

The honest part, which this community will and should ask about:

it is not end to end encrypted. The server can read what is stored, on purpose.

I want to be able to remove illegal uploads when they get reported, child sexual abuse material above all. A server that cannot see its own contents cannot act on those reports, and I am not willing to run one that cannot.

So I gave up that form of secrecy in exchange for being able to take that content down.

What that means for you in practice the password is casual access control, not protection from me as the operator or from anyone who breaks into the server.

If you need real confidentiality, encrypt the file on your own machine before uploading and share the key separately.

Treat 0807 as a way to move files around with self destructing links and no account, not as a vault for secrets you cannot afford to expose.

It is open source, and I host the code on my own server instead of GitHub, so there is no third party in that loop either.

You can read every line check the no logging claim yourself suggest a change, or open an issue all without an account:

SRC

Questions and criticism welcome. If you think the encryption tradeoff is the wrong call, I will read the argument

296
297
 
 

What's your recommendation for listening to music privately?

My requirements are: open source desktop/web (Linux) and android app. I also want basically every song I would ever want.

I'm willing to pay just not on agregious amount of money.

If you are posting your recommendation please care to include the tradeoffs or any annoyances you got from it.

Thanks all!

298
 
 

Hi, everyone. 👋

I'd like to move a few of my books from Amazon kindle app to an open source reader before closing the Amazon account. Preferably, I'd like moving to a European -based servive.

Curious about what my options would be? What is the procedure like? 🤷‍♂️

299
 
 

Hey you beautiful privacy scoundrels! You magnificently private rascals and scamps!

I used this tool for a long time. Well I found something new and wanted to share.

Firejail is an easy single shot sandboxer. It's easier than spinning up a whole ass VM. You can read about it if you wanna. What I wanted to share is, the network part of it. Which I never knew about before today!

There's an option called netlock. What it does is, it tracks any outgoing network IP the sandboxed app connects to for 60s. Then everything after that is blocked. That will print the block list it uses. You can edit it if you want, as a base. Adding or removing addresses, w/e. When you are happy, you can save and use it with the netfilter option.

It's great for let's say a podcast app, that will connect to one or a few IPs, but should not send anything to anywhere else. Or even apps that should be 100% local, and you want to keep honest apps honest.

You can do all that with a VM too, by using firewalls and w/e. But this is handy for one off uses. Cases you don't want a whole ass VM. If you trust an app to not be a trojan, but you don't totally trust where it might phone home to. You can make sure it of what it's doing. Like block analytics, but allowing a legit network endpoint for functionality.

Full docs here.

300
 
 

This now makes me wonder: is there a QR generator that maps out a grid of numbers and letters to help you draw it manually on graph paper with paper or pen or marker? That'd be kinda fun to use with this and completely baffle people in the wild by leaving literally E2E-encrypted messages for friends in public areas lolll.

view more: ‹ prev next ›