Privacy

50695 readers
786 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 6 years ago
MODERATORS
426
 
 

I’m excited to introduce Paperweight, a local-first open-source desktop app I’ve been building to help people understand and reduce their digital footprint.

Your inbox is a paper trail of every company that has ever had your data. Every account you created, every service you tried, every online purchase. It’s all connected to your email. Most people have 100+ accounts they’ve forgotten about, each a potential security, or privacy risk. For me the final push was the Odido data breach in the Netherlands. I hadn’t been a customer for more than 8 years, but all my data was still in their systems.

What it does:

  • Account inventory — Maps every company that has ever emailed you, with risks classifications and recommendations for action.
  • Bulk unsubscribe — Find and unsubscribe from any marketing and mailing lists (auto RFC 8058 where supported).
  • Breach alerts — Alerts when any company you’ve been in contact with has been breached (via HaveIBeenPwned).
  • GDPR requests — Generates pre-filled GDPR requests in multiple languages.

Supports Gmail, Outlook, Apple Mail, Proton (via Bridge) and any other email provider via IMAP.

Privacy approach:

Everything runs on your machine. Email content, credentials, and connection details never leave your device. No telemetry, no cloud sync, no analytics. The code is fully open source and auditable on GitHub.

Most alternatives in this space all require your to share your data through their services. Some of them have actually been caught selling your data. Paperweight is the only tool I’m aware of that does this entirely local and is open-source.

Website

Feedback welcome! Thanks

427
428
 
 
429
 
 
430
18
submitted 3 months ago* (last edited 3 months ago) by upstroke4448@lemmy.dbzer0.com to c/privacy@lemmy.ml
 
 

Seems like a useful secondary method to verify an apks certificate hash.

431
 
 

Hello, my vpn subscription will soon end so I am looking for reviews about good private VPN. I will probably stick with proton or try airvpn or PIA but I just wanna know if someone tried Geph VPN.

I didn't find any review on reddit or lemmy. Seems like a chinese VPN but if a VPN works well in China and has good privacy policies it's probably the winning combo.

432
 
 

If you are interested in privacy you are probably interested in password storage ... plus I wanted everyone to know about the inevitable future enshitification of this product. Spread the word and replacement recommendations are welcome too.

433
8
submitted 3 months ago* (last edited 3 months ago) by AuroraSine@lemmy.ml to c/privacy@lemmy.ml
 
 

Peace be upon you 🌹This is my new web project with all my works.

Aurora Shine | Privacy-First Portfolio

I decided to create this for 2 reasons. First of all, so you as a user can click on all my projects on one page. And second, so search engines can index all my websites at once. Have fun🌹

434
 
 

cross-posted from: https://piefed.world/c/tech/p/1132394/notice-given-to-parents-university-of-washington-researchers-wanted-preschool-teachers-t

First Photo TranscriptCultivate Learning

UNIVERSITY of WASHINGTON

Parent/Guardian Permission Form: Classroom Video Recording for Early Childhood Education Research

Dear Parent or Guardian,
Your child's classroom is participating in a research study led by Dr. Gail Joseph and the Cultivate Learning team at the University of Washington. The goal of this study is to better understand children's everyday learning experiences and to develop Al tools that can help assess classroom interaction quality. We are writing to ask for your permission to include your child in this study.

What Will Happen in the Classroom

With your permission, your child's lead teacher may wear a small teacher-worn camera that captures the teacher's approximate first-person perspective, and/or we may place a fixed video camera in the classroom. These videos simply capture the normal interactions between teachers and children during regular classroom activities. Recordings occur during morning program hours up to 150 minutes, up to 4 visits in one month. Your child will not be asked to do anything new or different. Their daily routine will stay exactly the same.

How Will the Video Recordings Be Used?

The video recordings may be used for the following purposes, but not limited to:

  1. Supporting Teachers Through Coaching and Al Tools. Videos will be used to develop and evaluate Al models for assessing classroom interaction quality. This involves multiple steps:
  • Human coding: Trained research staff will watch and code videos using validated classroom observation tools to evaluate the quality of teacher-child interactions.
  • Human-coded data from these videos will be used to train and improve Al models so they can more accurately identify high-quality teaching practices over time. Al tools will also analyze the same recordings to generate codes and justifications. Only the research team uses these coded videos to train secure, private Al models.
  • Teaching summary: After all recording sessions and coding are complete, teachers will receive a written observation summary based on human-coded scores, reviewed by a member of the research team.
  1. Research on Children's Learning Experiences. Video data will be used to study how individual children experience their classroom environment, including how often they interact with teachers and the quality of those interactions. This research aims to better understand what supports positive learning outcomes for young children. This may help your child's teacher provide the best classroom experiences to nurture your child's growth and learning.
  2. Research Publications & Conference Presentations. Short clips or images may be included in academic publications or presented at professional conferences to illustrate study findings. Children's identities will be protected whenever possible by using blurring faces and editing out the child's name in the audio.
  3. Project Demonstration Videos. Brief clips may be used in videos that explain how the Al system works. These clips will not publicly identify your child, and will be selected with care to respect children's privacy.
  4. Restricted-Access Research Dataset. Clips or related data may be shared in a secure, restricted research dataset to support future early childhood education research.

Second Photo Transcript

Al Processing and Data Security

Video data may be processed using cloud-based Al services. These services are accessed through restricted, authenticated API credentials and are governed by commercial data processing agreements that prohibit the use of submitted data for model training or product improvement. The specific Al tools and models used may evolve over the course of the study as technology advances; any such tools will be subject to equivalent or stronger data protection commitments. These tools do not publicly share, post, or reuse your child's data for any reason. Data may be retained by the provider for a limited period (e.g., up to 55 days) solely for internal monitoring, after which it is deleted. All video data is stored and managed in accordance with University of Washington data security policies.

Only authorized research team members and individuals from the UW or other agencies that may need to audit study records will be given access to identifiable video data. All activities comply with UW Institutional Review Board (IRB) approval and applicable FERPA regulations.

Video recordings of your child will never be posted online, shared publicly, or used for marketing. They are only for the research purposes described above. However, it is possible that someone who is not authorized to view the videos or study data will accidentally gain access to them despite our best efforts to protect your child's privacy.

Research staff are required by Washington State law to report any evidence of child abuse or neglect to the appropriate authorities.

The information that we obtain from your child for this study might be used for future studies. We may remove anything that might identify your child from the information. If we do so, the information may then be used for future research studies or given to another investigator without getting additional permission from you. It is also possible that in the future we may want to use or share study information that might identify your child. If we do, a review board will decide whether or not we need to get additional permission from you.

Your Rights

  • Participation is completely voluntary. You may decline or withdraw your child from the research at any time. Your decision will not affect your child's enrollment or standing in the program. - If you change your mind, simply let the teacher or research team know, and we will remove any recordings that include your child. Please note that if recordings have already been used in Al model training or grouped with other data prior to your withdrawal request, it may not be possible to remove your child's data**.

The document present participation as "completely voluntary" despite relying on an opt-out rather than an opt-in model. This raised logistical concerns among parents, with one noting they only discovered through questioning that opted-out children would wear stickers, leaving it unclear if they would still be filmed. Addressing these concerns, University of Washington News assistant director Jackson Holtz clarified that a single family's decision to opt out would actually exclude their entire classroom from the research. Ultimately, Holtz stated that this initial outreach was designed to gauge parent sentiment on AI, and based on the early negative feedback received, the university has entirely terminated the study and is notifying all participating sites. The university had taken down the section of its website describing the study, After 404 Media contacted them for comment.

Leak Source: 404 Media.

435
 
 

I got recommended a YouTube video that Discord published that only further deterred me from using it.

I would get a VPS but it is expensive, and I am lazy. Would you recommend any public servers?

436
 
 

Use a vpn with a Eu server. More sites like google will show a cookie popup with the "reject all cookies" option.

Reject all cookies if it exists. Otherwise accept cookies and then click on the :

shield icon > cookies and site data > delete (trash icon)

This is super useful when you want to read an article on some news website and it shows a cookie popup.

437
 
 

With stock and custom ROMs.

438
92
submitted 3 months ago* (last edited 3 months ago) by BillMangionee@lemmy.ml to c/privacy@lemmy.ml
 
 

Youtube Link

Let me know if the invidious link does not work or if this is off-topic.

439
 
 

Title. Suppose the mobile device is well supported by both.

440
 
 

cross-posted from: https://piefed.ca/c/canada/p/727265/signal-to-ottawa-we-ll-leave-canada-before-we-help-you-spy-on-users

Signal is drawing a hard line on the federal government’s proposed surveillance legislation: comply with Bill C-22 or leave the country. The secure messaging app says it would rather ditch the Canadian market than be forced to weaken the privacy protections it has built its reputation on. In an interview with The Globe and Mail

441
 
 

NordVPN

442
 
 

This really does feel like Patriot Act 2 - Corporate Boogaloo. America is quickly entering our "papers, please" era. Combined with NSPM-7 sounds like a great way to clamp down on dissent and normalize mass surveillance by targeting children. Which politicians, especially conservatives, seem to love to do. Probably because they aspire to be Epstein class.

443
 
 

Fauxx is an open-source Android privacy tool that poisons data broker and ad-tech profiles by generating continuous, plausible, off-demographic synthetic activity from your device. The goal is simple: make your real behavioral signal statistically indistinguishable from noise.

Not my project, but though this is really cool and worth sharing.

444
 
 

Heya,

How trustworthy is the local-only aspect of matter-protocol smart-home devices?

I see how the device -bridge-internet approach provides a filter and it's probably better than whitelabel http devices.

But are these really better for telemetry and spyware, when the firmware is still a black box?

Thanks in advance

445
 
 

cross-posted from: https://lemmy.today/post/52990902

Even if an employer doesn't require the new ID, remember the UK government said that all IDs will soon have to be verified digitally. That suggests the employer will send the ID image or data to a government server which will respond with whether the person is allowed to work. So all IDs will essentially be turned into digital IDs and the government can make individuals unemployable if they do something the government doesn't like.

446
 
 

Introduction (to this post)

A week ago there was a discussion on Lemmy shitpost community mentioning Obscura.
It acts as first hop to Mullvad. Fairly limited number of its servers.
As someone mentioned, it only supports macOS, iOS, and whatever does Wireguard.

So I tried to pay for it.
First, I am displeased that there's no way to just upload public key, but instead it generates entire config along with private key in browser.
Second, I can't see list of servers and ports like on Mullvad's site, and the reason is...
Third, only one combination of entry + exit node per config is possible. It seems to just assign a port on selected entry node to forward it to specified Mullvad exit node.

And there's just 3 slots!!!!!!!!!!

I can use same key with other config's combination, but if I remove the config, that port gets closed. So yeah, I can't just have many configs saved for different servers with the same private key.

But then I thought, is the public key allowed on all Mullvad servers? Yes it is.

After all, it should be just a hop through them.


Setting up Mullvad VPN client for Obscura

First, once you have Mullvad VPN installed, open the GUI, and create an account. Perhaps this step can be skipped, but that's a simple way to get the config created.

Next, quit the GUI and stop mullvad-daemon:

sudo systemctl stop mullvad-daemon

Now, open your Obscura Wireguard config in some text editor that you can copy from.
Next, open /etc/mullvad-vpn/device.json as root. E.g.:

sudo vim /etc/mullvad-vpn/device.json

Remove the account number, private key, IPv4, and IPv6 field values. I also removed the "id", though I don't know if that one would have caused issues.
If you keep the account number, you will just get expiration message.

Next, replace the private key, IPv4 and IPv6 with those from Obscura Wireguard config.

Here's an example of how that may look (data in example is invalid):
WG config:

# Exit: Mullvad ca-tor-wg-002 in Toronto, CA

[Interface]
PrivateKey = eNZ0Lr3jpE18o/KSVISHCi/wDWW5DgD6VCCEduKgkFI=
Address = 10.0.0.1/32, fc00:bbbb:bbbb:0:0:0:0:1/128
DNS = 10.64.0.1

[Peer]
PublicKey = iqZSgVlU9H67x/uYE5xsnzLCDXf7FL9iMfyKfl6WsV8=
AllowedIPs = 0.0.0.0/0, ::0/0
Endpoint = 95.173.193.232:46906
PersistentKeepalive = 15

Mullvad device.json:

{
  "logged_in": {
    "account_number": "",
    "device": {
      "id": "",
      "name": "obscura key",
      "wg_data": {
        "private_key": "eNZ0Lr3jpE18o/KSVISHCi/wDWW5DgD6VCCEduKgkFI=",
        "addresses": {
          "ipv4_address": "10.0.0.1/32",
          "ipv6_address": "fc00:bbbb:bbbb:0:0:0:0:1/128"
        },
        "created": "1970-01-01T00:00:00.000000000Z"
      },
      "hijack_dns": false,
      "created": "1970-01-01T00:00:00Z"
    }
  }
}

The name has no effect in this case, it's just what you see in the app. If the other fields matter, I don't know. I left them as they were.

Now you can once again start mullvad-daemon.

sudo systemctl start mullvad-daemon

You should now be able to connect to servers just as usual. But we have yet to add the Obscura server. The account page won't work, as there's no account.

Following the example above, we add an IP override for our exit node:

mullvad relay override set ipv4 ca-tor-wg-002 95.173.193.232

Lastly, we need to use the correct port. As per our example, in Mullvad app go to Settings -> VPN Settings -> Anti-censorship -> Wireguard port -> Custom -> enter 46906

Thankfully, these ports are also valid for Mullvad, so no extra switching will be needed.
You should now be able to connect to the Mullvad exit node via Obscura server, with Obscura account.

Multi-hop within Mullvad (a 3rd hop)

As the port for Obscura's server matters, we can only use it as an entry node. But yes, you can do that too.

Hopping madness

There's no point, but it's possible.
The Mullvad SOCKS5 will allow for, yes, a 4th hop.

And you can add TOR, for 7 hops (to regular sites)

What does that do? From this:

All the way to network quality of your teammates:

447
 
 

From important information about Google's abuse of power, to fun projects like the good old Snake. My code is clean.

NO GOOGLE TRACK: Here I have written down the information I collected about Google, especially Project Nimbus, which supported genocide. All information is backed by sources. The page also lists alternatives, as well as security measures using uBlock Origin and the about:config menu in Firefox and LibreWolf.

GHOST SEARCH: A Fun-Project where it looks like you are hacking Google and Bing to get answers undetected without giving them any data. So, a search engine of my dreams 😁. Don't worry, this is just a joke. You aren't hacking anything at all. The actual search is powered by Mojeek a privacy-friendly search engine that does not engage in profiling. Ghost Search is essentially my parody of DuckDuckGo & Startpage, which claim to be secure but get their answers from Microsoft and Google.

SNAKE-RETRO: Kids from the 80s and 90s probably know this. The good old Snake. Since we live in an era of tracking, even on retro game sites, I wanted to look back to a time when games were just games. So I thought, "Come on, dare to try making a retro game without any trackers," and I succeeded. Hope you have fun! 😊

All my projects are in German. Still, I hope you'll understand everything correctly thanks to your browser's automatic translation settings.

448
 
 

Linked article about a lawsuit in California. AI was used to transcribe conversations between patients and drs. Audio is sent to the cloud for processing. This is becoming very common in healthcare now. Some sources say 80% of physicians in the US and Canada use these.

They aren't suing under HIPAA. Rather, under some California state laws.

Company says it is HIPAA compliant. That's prob true. They prob also make a good faith effort to protect the data. But it is impossible.

This event happened in Ontario. An AI transcriber breached confidental pt data, inc diagnoses, treatment notes, etc.

AI bot sends confidential info to Ontario hospital patients after recording doctors’ meeting

Even with the best intentions, there are endless breaches from electronic health data systems.

Also. Merely knowing your convo between you and your dr is recorded can change how honest ppl will be with their dr. You prob trust your dr. But when everything you say them is recorded, you may not trust what happens after that.

Fortunately most drs will let pts opt out of these, if you ask.

449
 
 
450
 
 

cross-posted from: https://lemmy.world/post/46759202

Means nothing to me since I only use Mastodon, Lemmy and Bluesky (personally) ;)

view more: ‹ prev next ›