Privacy

50695 readers
786 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 6 years ago
MODERATORS
476
 
 

I find it hard to believe there aren’t threads about this already but I didn’t find anything when I searched …

I’m looking for a data SIM card for my mobile router (GL.inet MUDI V2) but I’m unsure of what to look for. I know that not all SIM cards will work and I’d rather not have to make a purchase to engage in trial and error.

I saw a T-mobile plan on bestmvno.com that claimed to have unlimited data (only) for $5/mo (Im in the US) but the description also mentioned text messaging (???) which tells me that it wouldn’t work for me but I’m not familiar with what I’m shopping for so I could be wrong.

Mobile router users: what are you using for your data only SIM cards?

477
 
 

A security researcher decompiled the White House’s new official app and found some alarming stuff buried in the code, including a hidden GPS tracking pipeline, JavaScript loaded from a random GitHub account, no SSL certificate pinning, and an in-app browser that silently strips cookie consent dialogs and paywalls from every page you visit.

478
 
 

Such a shitshow.

479
 
 

So years ago I made an account on an online shopping platform. I took pains to do it as privately as I could. Shipping address as PO box. Didn't use real name to sign up. Masked credit card for payment. Etc.

I had it for IDK like 6 years? 7 years? I didn't use it a LOT, but let's say once a month avg. Over those years I had 100% the best feedback rating. I never caused any prob to anyone. I acted in good faith.

Suddenly one day... account canceled. Contacted company. They said send us copy of your gov photo ID. I said how about no?

I know it was b/c my account triggered some predictive anti abuse system. Scammers do a lot of what I did. Diff is, I was not a scammer. I just wanted some privacy. Wasn't even buying anything embarrasing. Just normal shit.

I thought since I got 6+ yrs of history, spend like mid 4 digits of $$ total, zero probs, perfect feedback for 6 years, I figured hey maybe I wouldn't be lumped in. But fuck me sideways.

Funny thing is. I had an older acct under my real name. It had LESS total purcahse history. By a lot. I never submitted any ID to create it. It's still there. It still works. Diff is, it's tied to my home addy and real name. It didn't trigger anti-abuse prediction. ANd it is prediction! I never abused anything, and never would.

More and more, I can't participate in the world, if I try to protect myself from data brokers that collect every fucking thing I do.

I'm sorry. I just had to rant lol. What is your experience with online shopping, if you try to set it up not tied directly to your name, phone, & home addy?

480
 
 

I wouldn't detail my full set up but I use it for services where I need to login or identify myself to services.

481
 
 

A few days back I watched a SomeOrdinaryGamers video, in which he states to drive a Tesla car, despite expressing the obvious privacy concerns surrounding the built-in camera system; but doesn't seem to consider the privacy-impact to those around the vehicle, he chooses to drive through public streets. And another example being Rob Braxman, while ironically, both known to frequently criticize other public-facing, internet connected surveillance systems (like Ring for example).

If it was "just" a cabin camera, staring you straight in the face every time you drive your car (and you're somehow okay with that), it would still be a terrible look in context with your channel content, but at least it is contained to you personally. But knowingly driving these surveillance nightmares on wheels through public streets, subjecting others to that surveillance, while you represent pro-privacy channels online, is just inexcusably hypocritical to me. But perhaps it might just be me, so what are your thoughts?

482
483
484
 
 

hi everyone, We're on a mission to get as many people off Big Tech products as we can, and as many people away from the surveillance economy. And since that starts early we've made this page for parents to find the best tech tips to keep their children safe.

[Note on social media: we do not support a ban for social media, we think the tech companies should fix their products instead. But since that will probably never happen, and the best option - never use social media - is probably not practical for many families, we've listed alternatives on this page.]

We welcome any tips that parents here can share - stuff that's worked for you to keep your children safe from big tech. It doesn't have to be app alternatives - it can be habits / mindset stuff too. Or it could be stuff that's not worked / pitfalls.

Please also let us know if anything currently on the page looks wrong or misleading.

Be mindful that this is aimed at totally non-technical-minded parents.

Thank you!

485
486
 
 

I'm working on a self-hosted search service called Hister with the goal to reduce my dependence on online search engines.

Hister is a full text indexer for websites which saves all the visited pages rendered by your browser. It provides a flexible web (and terminal) search interface & query language to explore previously visited content with ease or quickly fall back to traditional search engines.

I've been using it for a few months and as my local index is growing I can avoid opening google/duckduckgo/kagi more and more frequently.

The project is still heavily under development with a growing community, but the current version is in a fairly usable state in my opinion, so I wanted to share it here - perhaps some of you find it useful as well. (Or at least have some constructive criticism =])

The code is AGPLv3 licensed, available at https://github.com/asciimoo/hister website: https://hister.org/ read-only demo: https://demo.hister.org/

About me: I develop privacy protecting and data liberating free software since 2008. I'm the author of Searx, Colly (https://github.com/gocolly/colly) and many more smaller free software/self-hosted projects (https://github.com/asciimoo).

487
488
 
 

CVE-2026-31431 ("Copy Fail") Meets Iran's Digital Blackout: A Match Made in Hell

While the world scrambles to patch one of the cleanest local privilege escalation bugs in recent memory, a large chunk of Iran's critical infrastructure is sitting there beautifully vulnerable — thanks to the regime's own "protective" internet blackout. The Technical Beauty of Copy Fail

CVE-2026-31431 is a high-severity (CVSS 7.8) logic flaw in the Linux kernel's cryptographic subsystem, specifically the algif_aead module and the authencesn template. It was introduced in 2017 with a performance optimization that accidentally allowed page cache pages (normally read-only for users) to end up in a writable destination scatterlist.

The primitive is terrifyingly simple:

An unprivileged local user opens an AF_ALG socket.
Binds it to authencesn(hmac(sha256),cbc(aes)).
Uses splice() in a clever way.
Achieves a controlled 4-byte write into the page cache of any readable file on the system.

That's it.

Researchers dropped a 732-byte Python script that weaponizes this to overwrite a setuid binary like /usr/bin/su, injects shellcode, and spawns a root shell. No disk writes. No races. No KASLR bypass needed. Works reliably across Ubuntu, RHEL, Amazon Linux, SUSE — basically every major distribution built since 2017. It even crosses container boundaries because the page cache is shared at the host level.

It's not flashy memory corruption. It's elegant. It's reliable. It's the kind of bug that makes security researchers weep with joy and defenders cry. Now Add Iran's Self-Imposed Digital Blackout

The regime proudly announces it's cutting internet access "due to cyber attacks." The real reason, of course, is fear of its own population. Connectivity gets throttled or severed, updates stop flowing, and systems remain frozen in their pre-disclosure state.

This creates the perfect storm:

Many Iranian government, military, and critical infrastructure servers are still running vulnerable kernels (4.14 through early 6.x series).
The "cyber attack" excuse conveniently prevents normal sysadmins from pulling the latest patches.
Anyone who already has a local shell whether a disgruntled insider, a compromised low-priv account, a previous breach, or a clever actor who got in before the blackout — now holds the keys to the kingdom with 732 bytes of Python.

Picture this dark comedy in action:

A low-level IT guy (or an opposition sympathizer, or a foreign operator) who still has internal network access runs the PoC. Four bytes later, /usr/bin/su is politely modified in memory. execve() and suddenly he's root on servers the regime thought were "protected" by disconnecting them from the outside world.

No C2 callbacks needed. No noisy exfiltration during the blackout. Just quiet persistence and lateral movement inside the isolated network. The digital iron curtain doesn't stop internal threats it amplifies them. The Ironic Masterpiece

The regime cuts the internet out of paranoia about its people, then leaves its infrastructure wide open to the exact kind of local escalation that paranoid regimes should fear most. It's like boarding up all the windows to stop outsiders from looking in, while leaving the front door unlocked and posting a sign that says "Free Root Access Inside."

In short: Copy Fail turns any local foothold into full root with almost zero effort. Iran's self-imposed isolation ensures that many systems won't see patches for days or weeks. The combination is comedy gold for anyone on the wrong side of the regime and a nightmare for those supposedly "securing" the infrastructure.

Stay patched, folks. And if you're running critical systems in a country currently experiencing a "cyber attack" blackout... good luck. You're going to need it more than most.

489
 
 

It works like omegle, but users stay silent and strive to go for the highest rating of their face.

Privacy policy says they dont store or sell data, but who knows https://omoggle.com/privacy

490
 
 

I have deployed a collection of independent smart contract protocols on Ethereum mainnet. Each one is finished infrastructure. No governance, no upgrade path, no owner. Ownership is renounced on all contracts. The contracts are deployed and the keys are gone.

This post is for the privacy angle. The full technical documentation is in the repo linked at the bottom.


Minimal data, by architecture

No protocol stores personally identifiable information. On-chain data is limited to cryptographic commitments, timestamps, addresses, and amounts. All sensitive data stays off-chain with the parties involved.

This is GDPR compliant by architecture, not by policy. There is no personal data to protect because the system is not designed to collect it. The deployer controls their own data. The user controls their own disclosure.


No operator, no capture

The contracts are deployed with renounced ownership. There is no entity that can be subpoenaed, pressured, or acquired. The privacy is structural, it holds regardless of what any individual, platform, or authority wants.

Most privacy tools rely on the trustworthiness of an operator. These protocols have no operator to make promises and no operator to break them.


Currency agnostic

Every protocol settles on Ethereum mainnet. What currency a user pays in is a platform decision. A platform can accept XMR, BTC, ETH, fiat, or any combination and convert to ETH at the platform layer before interacting with the protocol.

Combined with the atomic, hop-by-hop settlement structure, this means the payment trail fragments naturally across chains without any privacy feature being explicitly designed in. It is a structural consequence of currency agnosticism and independent atomic settlements.


Human rights and legal grounding

The right to private correspondence is not a crypto argument. It is a human rights argument.

Universal Declaration of Human Rights, Article 12 covers it. ECHR Article 8 covers it. GDPR covers it. A parcel dispatched between two parties with no central record of who sent what to whom is functionally identical to a sealed letter. The legal and moral precedent for protecting that is centuries old.

These protocols are built in that direction. Anyone arguing against this privacy model is arguing against the existing human rights framework.


Documentation, protocol repositories, template repositories, and orchestration examples:

https://github.com/pablo-chacon/the-substrate

491
 
 

cross-posted from: https://lemmy.world/post/46331006

It's ironic to see those same global elites who love partying with the likes of known & convicted child sex-trafficker Jeffrey Epstein now urging worldwide restrictions on E2E / VPN & promoting age, biometric, and identity verification online - all in the name of protecting children.

It’s also highly suspicious that so many of the world’s biggest countries are trying to implement this wider internet control at the same time.

Feels like a major push toward authoritarianism to me.

It's messed up how the people always have to fight to wrest any rights from those in power, and then fight even harder to keep them!

492
493
 
 

cross-posted from: https://mander.xyz/post/51386289

EFF is alarmed by recent laws in several states that have blocked public access to data collected by ALPRs, including, in some cases, information derived from ALPR data. We do not support pending bills in Arizona and Connecticut that would block the public oversight capabilities that ALPR information offers.

494
 
 

My app suddenly said "your account expires in two days". Weekend was around the corner and there is no way that I could receive one of their refill vouchers in time (I use this method for privacy). I reached out to them, asking them to add a few more days to my account so that all my devices don't get deleted when my account expires. I also emphasized, that they can of course subtract that amount of days from my next refill. I sent them my account number, encrypted with PGP, and within 12 hours, they replied: I added three more days. It's on the house. Have a good day! :)

That was really nice of them. :)

495
496
497
22
submitted 4 months ago* (last edited 1 week ago) by Anonymous@sopuli.xyz to c/privacy@lemmy.ml
 
 

A few questions that have been on my mind:

  • How do you handle apps that refuse to run on rooted/jailbroken phones or on devices without Google Play Services? Can microG, Xposed, or other tools help in practice? (F*ck Play Integrity and "Google Play license check"). Can I bypass those restrictions without rooting?

  • Have you ever rooted your phone? Any practical advice for someone considering it?

There is fact that in my country (Vietnam), banks are required to block banking apps from running on rooted or jailbroken phones. The State Bank of Vietnam introduced Circular 77/2025/TT‑NHNN, which mandates this.

Some other questions:

  • How is eID implemented in your country? Does your government require or strongly encourage using eID apps? Are they widely adopted? (I know the EU’s planned age‑verification app is a form of eID—or not really. Real examples are Germany’s AusweisApp and Vietnam’s VNeID. Anyway, that age‑verification law should not exist).

Any experiences or advice are appreciated. Thanks a lot.

498
 
 

Hello,

Im in the route of degoogling my life, just recently installed GraphaneOs. Where do you guys download apks? I need Synology apks like Synology Photos. I dont see if it is published on official website.

How you deal with that? How to avoid downloading malware by mistake?

499
 
 

cross-posted from: https://hexbear.net/post/8356680

cross-posted from: https://news.abolish.capital/post/45407

Common Dreams Logo

This story originally appeared in Common Dreams on April 27, 2026. It is shared here under a Creative Commons (CC BY-NC-ND 3.0) license.

An exchange of gunfire between an armed suspect and law enforcement outside the White House Correspondents’ Dinner on Saturday came days ahead of a deadline for extending far-reaching government surveillance powers, and President Donald Trump wasted no time in claiming that the attempted attack on the event proved that the FBI must be permitted to spy on Americans without obtaining warrants.

In an interview with Fox News Sunday, Trump repeated his previous remarks that he is “willing to give up [his] security” in favor of extending Section 702 of the Foreign Intelligence Surveillance Act (FISA), which is set to expire on Thursday—and suggested other Americans should do the same for “the safety of our nation.”

Section 702 allows US intelligence agencies to surveil the electronic communications of foreign nationals overseas without a warrant. Since some of the nearly 350,000 foreign nationals whose communications have been collected under the law are in touch with Americans, Section 702 allows for the collection of emails, text messages, and phone calls of US citizens.

Fox anchor Jacqui Heinrich emphasized that “we don’t know right now” whether the suspect in Saturday’s shooting, Cole Tomas Allen, “was radicalized” by a foreign individual or group, but asked whether the attack drove home “the importance of having these tools to protect our country from these kinds of threats.”

The president responded by complaining that former FBI Director James Comey used FISA to obtain warrants to surveil a former Trump aide as part of the agency’s investigation into the 2016 Trump presidential campaign’s communications with Russia, before saying FISA has been used in the US-Israeli war on Iran and in the US military’s invasion of Venezuela earlier this year.

“It’s really needed for national security,” said Trump. “Iran is decimated, and we got a lot of information by using FISA… I’m willing to give up my security for the military because ultimately that’s to me the highest cause is, you know, the safety of our nation.”

Pres. Trump, under prodding from Fox News, exploits White House Correspondents' Dinner shooting to push for Congress to approve FISA domestic spying program: "It's really needed for national security…"

He reiterates that he's willing to give up his liberties for safety. pic.twitter.com/tmcepp0Wgn

— Chris Menahan 🇺🇸 (@infolibnews) April 26, 2026

Jordan Liz, an associate professor of philosophy at San José State University, wrote last week in a column at Common Dreams that while Trump, Republican lawmakers, and US intelligence agencies “make sweeping claims about the terror attacks that Section 702 has prevented, there is little publicly available evidence to support this.”

“According to the Cato Institute, there is only one well-documented, independently corroborated case of Section 702 preventing a terrorist attack on American soil: the 2009 New York subway bombing plot,” wrote Liz. “In that case, Section 702 was used by the [National Security Agency] to track an exchange between an al-Qaeda courier and Najibullah Zazi, who was living in the US. The NSA passed this information to the FBI, which identified Zazi and disrupted the attack before it took place. Importantly, however, the NSA allegedly received the courier’s foreign email address from the government’s British intelligence partners. At best then, this success was a byproduct of productive intelligence sharing between allies. Rather than proving the necessity of Section 702, this incident underscores how Trump’s inane attacks against key US allies undermine our national security.”

The suspect in Saturday’s shooting is believed to have acted alone, and no evidence has been released that he was in communication with any foreign entities. A document he wrote alluded to his Christian beliefs and to reports of the administration’s abuse of immigrants in detention centers, its boat-bombing operations in the Caribbean Sea and eastern Pacific Ocean, and the bombing of an elementary school in Iran.

The president has been pushing in recent weeks for an extension of Section 702. The program was last reauthorized in 2024, and earlier this month two efforts to extend the program—one for 18 months and the other for five years—failed, with opponents objecting to a lack of privacy reforms and to a loophole allowing data brokers to sell private information about Americans to government agencies that have not obtained judicial approval to seize the data.

After those proposals failed, House Speaker Mike Johnson (R-La.) last week unveiled a new bill to extend Section 702 for three years and require the FBI to submit monthly reports on its reviews of Americans’ private data to an oversight official, as well as imposing penalties for abuse—provisions that were dismissed by privacy advocates.

The House Rules Committee was set to convene on Monday, a step toward advancing the new bill toward a vote in the House, and according to NPR, Rep. Jamie Raskin (D-Md.) circulated a memo late last week urging his colleagues to reject the Republicans’ latest proposal.

The bill, he wrote, “continues the disastrous policy of trusting the FBI to self-police and self-report its abuses of Section 702 and backdoor searches of Americans’ data… FBI agents can still collect, search, and review Americans’ communications without any review from a judge.”

Four Democrats in the House—Reps. Josh Gottheimer (D-NJ), Tom Suozzi (D-NJ), Marie Gluesencamp Perez (D-Wash.), and Jared Golden (D-Maine)—broke with the party and joined the GOP earlier this month in supporting a procedural vote to advance the reauthorization of Section 702, and privacy advocates are ramping up pressure on them to oppose the latest proposal for an extension.

“It all comes down to those four and where they are going to land,” Hajar Hammado, a senior policy adviser at Demand Progress, told The Intercept Monday, “and if they are going to continue to try to hand Trump and [White House homeland security adviser] Stephen Miller warrantless surveillance authorities without any sort of checks or reforms that make sure they’re not violating civil liberties.”


From The Real News Network via This RSS Feed.

500
 
 

Let's say, I sit down in a mall, open my laptop and connect to a secured mobile hotspot. Then I do it again next week after a reboot. What information would a nearby shop or a passive malicious hacker be able to find about my device? Does my device send out identifying information before joining, like a MAC address? Is this persistent, or randomized?

I intentionally haven't specified a distro, so if something only applies to some network managers, give some details.

Bonus points: what about Android phones?

view more: ‹ prev next ›