Privacy

50695 readers
638 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 6 years ago
MODERATORS
701
 
 
702
 
 

FreeTube wasn't loading a video, so I tried opening it in the YouTube website instead. Rather than being able to watch a 13 second video (here it is in case anyone wants to know), I managed to capture is one of the most dystopian screenshots I've personally seen. Every single element of this image is truly astounding if you look close enough and think about it for a moment.

13 seconds of your life now costs you even more time to prove you're not trying to scrape a video from a hundred billion dollar corporation with nearly infinite resources, advertisements and clickbait grabbing at your attention, every interaction logged and sold to thousands of data brokers, and you can't even show your appreciation without selling more information by creating an account. How did we get here?

703
 
 

This idiots going to get it banned

704
1
submitted 10 months ago* (last edited 10 months ago) by Charger8232@lemmy.ml to c/privacy@lemmy.ml
 
 

Introduction

I wanted to explain the structure of freedom, and why part of what constitutes a free society is the right to privacy. One of the most difficult parts of educating people on privacy is the confusion about what it actually is. People often confuse privacy with secrecy, privacy with anonymity, and privacy with security. I want to distinguish between multiple related terms and show the structure of how, in order to have a truly free society, you need the right to privacy.

What is privacy?

I want to be very clear about what privacy actually is and is not. Privacy is not hiding everything about yourself. Hiding things is secrecy. Privacy is not hiding who you are. Hiding who you are is anonymity. Privacy is not protecting your information. Protecting your information is security.

Privacy is the ability to choose what you share. That gives us our first clue about the structure of a free society. Secrecy relies on privacy, because if you can't choose what you share then you cannot keep secrets.

An example of secrecy would be hiding how much you make at your job. An example of privacy is choosing to exercise that secrecy. In the moments between someone asking you how much you make and telling them you don't feel comfortable sharing that, you take a moment to decide whether or not you want (or consent) to telling them. That is privacy.

Why the distinction?

The distinction between privacy and secrecy is incredibly important for making arguments about privacy. People may say "I have the ability to choose what I share, because I am able to choose your level of privacy if I want to." What they really mean is that they can choose your level of secrecy. You don't choose to be under surveillance, but you can choose to protect yourself from surveillance, not by hiding everything you do but by eliminating the things that are tracking you in the first place.

In reality, many people cannot choose the same level of secrecy. Privacy is eroded in the background, and many people don't realize how far surveillance really goes. Becoming secretive is not the solution, because that is the same as eliminating your free speech in the face of being persecuted. This is our second clue about the structure of a free society, because free speech relies on both privacy and secrecy.

What is security?

Security is, simply, measures taken to protect something. Encryption is an an example of security, because it is used to protect sensitive data from unwanted intrusion. I want to make a clear distinction between security and safety. Security protects you before an intrusion occurs, whereas safety protects you after an intrusion occurs.

An example of safety is a surveillance camera. A surveillance camera cannot stop a crime from occurring, but it can record evidence to convict a criminal after the fact. On the other hand, strong locks are an example of security, because they protect a store from being broken into before a theft takes place.

I deliberately call them surveillance cameras instead of security cameras, because safety is different from security. When the news talks about security measures, often times they are really referring to safety measures. Safety measures are often privacy invasive, because they usually require a level of data retention to be effective.

Security protects against unwanted intrusion. If there is unwanted intrusion on data, that means it was shared without consent. Because of that, if there is no security, there is no privacy either. That gives us our third clue about a free society. A free society does not need safety, it needs security, and privacy is not possible without security.

What is anonymity?

Anonymity means hiding your identity. Because it directly relies on hiding something, it's immediately obvious that anonymity relies on secrecy. Anonymity is the best defense against a corrupt government, because it allows us to speak up against corruption without fear of persecution. Even with perfect secrecy, we ourselves can still be convicted by exercising our right to privacy. This is the final piece we need to see what a free society relies on, because without a way to combat corruption, there is no way to be free.

What is freedom?

We've finally arrived at the final section, which puts together the pieces to show what is necessary for a free society. While this is only part of what freedom requires, it is not a part that can be ignored.

Freedom Pyramid

This pyramid of freedom shows the dependencies for each element. Security is the foundation that everything else is built on. Privacy relies on security to prevent unwanted violation of consent. Secrecy relies on privacy to prevent sharing without consent. Anonymity relies on secrecy to hide your identity. Finally, freedom relies on anonymity to fight against corruption.

You may notice safety is not on there. While safety can be good, it often violates some aspect of the pyramid. It isn't necessary for a free society. In fact, safety doesn't even need security. Surveillance cameras are breached all the time, but that doesn't change their purpose or effectiveness.

Conclusion

Privacy is essential for a free society, but it isn't the only essential liberty. Security is the foundation that privacy is built on, and even that is eroded away by conflating security with safety. Knowing the distinctions and relationships between the various elements is incredibly useful when speaking up about privacy, because even if you can defend every "nothing to hide" argument, people still tend to have a fundamental misunderstanding about what privacy really is.

Lack-of-AI Notice

I've been burned before, so I always try to mention that none of my content is AI generated. It isn't even AI assisted. Just because something is comprehensive and well-structured does not make it AI generated. Every word I write is my own. Thank you for your understanding.

This was my first time testing an easier way for me to create posts by first drafting them in Iotas. I had a couple hiccups such as forgetting to insert the image and forgetting to double newline paragraphs, but it worked alright.

705
706
 
 

Someone recently managed to get on a Microsoft Teams call with representatives from phone hacking company Cellebrite, and then leaked a screenshot of the company’s capabilities against many Google Pixel phones, according to a forum post about the leak and 404 Media’s review of the material.

The leak follows others obtained and verified by 404 Media over the last 18 months. Those leaks impacted both Cellebrite and its competitor Grayshift, now owned by Magnet Forensics. Both companies constantly hunt for techniques to unlock phones law enforcement have physical access to.

“You can Teams meeting with them. They tell everything. Still cannot extract esim on Pixel. Ask anything,” a user called rogueFed wrote on the GrapheneOS forum on Wednesday, speaking about what they learned about Cellebrite capabilities. GrapheneOS is a security- and privacy-focused Android-based operating system.

rogueFed then posted two screenshots of the Microsoft Teams call. The first was a Cellebrite Support Matrix, which lays out whether the company’s tech can, or can’t, unlock certain phones and under what conditions. The second screenshot was of a Cellebrite employee. 💡 Do you know anything else about phone unlocking technology? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.

According to another of rogueFed’s posts, the meeting took place in October. The meeting appears to have been a sales call. The employee is a “pre sales expert,” according to a profile available online.

The Support Matrix is focused on modern Google Pixel devices, including the Pixel 9 series. The screenshot does not include details on the Pixel 10, which is Google’s latest device. It discusses Cellebrite’s capabilities regarding ‘before first unlock’, or BFU, when a piece of phone unlocking tech tries to open a device before someone has typed in the phone’s passcode for the first time since being turned on. It also shows Cellebrite’s capabilities against after first unlock, or AFU, devices.
Screenshot via GrapheneOS forum.

The Support Matrix also shows Cellebrite’s capabilities against Pixel devices running GrapheneOS, with some differences between phones running that operating system and stock Android. Cellebrite does support, for example, Pixel 9 devices BFU. Meanwhile the screenshot indicates Cellebrite cannot unlock Pixel 9 devices running GrapheneOS BFU.

In a statement, Victor Cooper, senior director of corporate communications and content strategy at Cellebrite, told 404 Media “We do not disclose or publicize the specific capabilities of our technology. This practice is central to our security strategy, as revealing such details could provide potential criminals or malicious actors with an unintended advantage.” Google did not immediately respond to a request for comment.

GrapheneOS is a long running project which makes sizable security changes to an Android device. “GrapheneOS is focused on substance rather than branding and marketing. It doesn't take the typical approach of piling on a bunch of insecure features depending on the adversaries not knowing about them and regressing actual privacy/security. It's a very technical project building privacy and security into the OS rather than including assorted unhelpful frills or bundling subjective third party apps choices,” the project’s website reads.

As well as being used by the privacy and security conscious, criminals also turn to GrapheneOS. After the FBI secretly ran its own backdoored encrypted phone company for criminals, some drug traffickers and the people who sell technology to the underworld shifted to using GrapheneOS devices with Signal installed, according to interviews with phone sellers.

In their forum post, rogueFed wrote that the “meeting focused specific on GrapheneOS bypass capability.”

They added “very fresh info more coming.”

707
0
De-everything enough? (lemmy.blahaj.zone)
submitted 10 months ago* (last edited 10 months ago) by ori@lemmy.blahaj.zone to c/privacy@lemmy.ml
 
 

(I reposted this bc some applications were missing.) I had to install some apps because of school. Btw, can you say improvements that I can make? I can't install anything that isn't from playstore. Edit: Duolingo is now just a PWA

708
709
1
submitted 10 months ago* (last edited 10 months ago) by Charger8232@lemmy.ml to c/privacy@lemmy.ml
 
 

I've collected a lot of privacy tips over the years, ranging from somewhat common to very niche. After seeing this post, I wanted to share them, along with ways to mitigate each of them. I've tried to find sources for each of them, but some of them simply don't have good sources. You can help by finding good sources (Wikipedia, research papers) covering the specific topic. As with all my posts, this is not AI-generated, just well-structured.

Good sources

Glove Prints

Problem: Thin gloves like surgical gloves can still leave fingerprints on surfaces.

Source: https://en.wikipedia.org/wiki/Glove_prints

Mitigation: Wear thick, textured gloves

Main Hum

Problem: The hum of the electrical grid can be used to determine when, and sometimes where, an audio recording took place.

Source: https://en.wikipedia.org/wiki/Electrical_network_frequency_analysis

Mitigation: Only record audio in places far away from electrical appliances.

Stylometry

Problem: Your writing style can uniquely identify you.

Source: https://en.wikipedia.org/wiki/Stylometry

Mitigation: Use AI rewriting tools to obfuscate your writing style.

Infrared Glasses

Problem: Sunglasses don't block infrared cameras.

Source: https://www.reflectacles.com/irlenses

Solution: Buy infrared blocking/reflecting sunglasses such as Reflectacles.

Tracking Dots

Problem: Printers add tracking dots that identify which printer was used to print a document and when it was printed.

Source: https://en.wikipedia.org/wiki/Printer_tracking_dots

Mitigation: Use a printer that may not come with this feature (such as the upcoming Open Printer or use public printers like those found in libraries.

WiFi Motion

Problem: Wi-Fi routers are able to track motion under specific conditions.

Source: https://www.cognitivesystems.com/wifi-motion/ (and others)

Mitigation: Radio jammers may provide some protection against this, since the technology is still fragile.

PrintListener

Problem: Your fingerprint can be uncovered using the sound of your finger gliding across your screen.

Source: https://www.ndss-symposium.org/wp-content/uploads/2024-618-paper.pdf

Mitigation: Use a ballpoint pen with a stylus tip, which are somewhat common to find at most events.

Laser Microphone

Problem: You can record audio using the vibration of nearby objects, like windows.

Source: https://en.wikipedia.org/wiki/Laser_microphone

Mitigation: Have sensitive conversations in closed-off or soundproof rooms or outside in remote areas.

Keystroke Recording

Problem: Your keystrokes can be uncovered using audio recordings of typing.

Source: https://arxiv.org/pdf/2403.08740

Mitigation: Use virtual keyboards.

Typing Patterns

Problem: You can be identified based on your typing patterns.

Source: https://expertbeacon.com/your-typing-style-is-as-unique-as-your-fingerprint-heres-what-that-means/ (and others)

Mitigation: Type into a text editor and copy-paste into the form you want to submit.

Unshredder

Problem: Shredded documents can be reconstructed.

Source: https://www.unshredder.com/ (and others)

Mitigation: Burn sensitive documents or use piranha solution.

Microbial Cloud

Problem: You can be identified using your unique microbial cloud.

Source: https://peerj.com/articles/1258/

Mitigation: Shower obsessively, I'm not sure.

Gait Recognition

Problem: The way you walk can identify you.

Source: https://en.wikipedia.org/wiki/Gait_analysis

Mitigation: Place gravel in your shoes or intentionally walk funny.

Store Tracking

Problem: Stores track your location using Wi-Fi and Bluetooth signals from your device.

Source: https://en.wikipedia.org/wiki/Indoor_positioning_system (and others)

Mitigation: Disable Wi-Fi and Bluetooth when not in use.

Gyrophone

Problem: Gyroscopes can record audio

Source: https://crypto.stanford.edu/gyrophone/files/gyromic.pdf

Mitigation: Disable sensor permissions for apps that don't need it on GrapheneOS.

Camera Styles

Problem: Cameras can be identified using picture styles.

Source: https://www.scientificamerican.com/article/tracing-photos-back-to-the-camera-that-snapped-them/

Mitigation: Use Polaroid cameras or obfuscate pictures before sharing them.

Amazon Sidewalk

Problem: Offline Amazon devices can access the internet by communicating with nearby online Amazon devices.

Source: https://en.wikipedia.org/wiki/Amazon_Sidewalk

Mitigation: Don't use Amazon devices.

Deep-TEMPEST

Problem: Data sent over a wired connection (like HDMI) can be received wirelessly.

Source: https://arxiv.org/pdf/2407.09717

Mitigation: Use shielded cables or encrypt wired connections in transit.

Cartridge Memory

Problem: Offline printers exfiltrate data through ink cartridges.

Source: https://support.hp.com/us-en/document/ish_6681254-6681301-16

Mitigation: Use a printer that does not come with this feature (such as the upcoming Open Printer.

WhoFi

Problem: You can be identified based on how your body blocks Wi-Fi signals.

Source: https://www.theregister.com/2025/07/22/whofi_wifi_identifier/

Mitigation: Use a Radio jammer.

Stingray

Problem: Most phones are vulnerable to Stingray attacks.

Source: https://en.wikipedia.org/wiki/Stingray_phone_tracker

Mitigation: Use Rayhunter to detect Stingray attacks.

EICAR

Problem: Surveillance cameras can scan QR codes.

Source: https://www.linkedin.com/pulse/qr-code-car-hack-fun-impractical-w-garrett-myler

Mitigation: Some surveillance cameras will crash if they scan a QR code with an EICAR Anti-Virus Test File.

Pulse-Fi

Problem: Wi-Fi can measure your heartrate

Source: https://ieeexplore.ieee.org/abstract/document/11096342

Mitigation: Cover your skin to reduce effectiveness.

Mediocre sources

Security Envelopes

Problem: The contents of envelopes can be read without being opened by seeing through the paper.

Source: General knowledge.

Mitigation: Use security envelopes or thick packaging.

Branding

Problem: Even when fully covered, the clothing you wear can identify you.

Source: General knowledge.

Mitigation: Use plain unbranded clothing bought secondhand from yard sales or Goodwill.

Body Shape

Problem: Even when fully covered, your body shape can identify you.

Source: General knowledge.

Mitigation: Wear baggy black clothing like down jackets.

ID Address

Problem: State ID cards have your address listed on them.

Source: General knowledge.

Mitigation: Passports are valid photo IDs that do not have your address listed.

Bluetooth Contacts

Problem: Any Bluetooth device you pair your phone to can access your contacts.

Source: Various online discussions.

Mitigation: Use a phone that allows you to deny that permission when pairing Bluetooth devices.

Voice Changers

Problem: Voice changers can be reversed.

Source: Various online discussions.

Mitigation: Use voice changers that highly obfuscate your voice (beyond something like a pitch shift) or use a program that converts live speech-to-text into live text-to-speech.

Analog Speakers

Problem: Speakers can be used as microphones.

Source: Various online discussions. You can try this yourself by plugging a speaker into your microphone jack.

Mitigation: Use built-in speakers or remove all speakers entirely.

Spray Paint

Problem: Spray paint can't blackout surveillance camera lenses.

Source: Various online videos of failed criminals.

Mitigation: Use duct tape or other adhesives that are not only cheaper but provide better protection.

Censorship

Problem: Pixelated or blurred images can be reversed.

Source: Various reversal tools.

Mitigation: Censor information using solid boxes.

Bad sources

Radio

Problem: Receiving antennas can be geolocated using signal interference.

Source: I couldn't find a suitable source covering this specifically. This is a general source.

Mitigation: Receive media via offline methods.

Vehicle Telemetry

Problem: Cars will collect telemetry locally to be shared when you visit auto repair shops.

Source: I couldn't find a suitable source.

Mitigation: Use dumb cars or commute using bicycles, buses, etc.

Detaining

Problem: Police can detain you without a valid reason if you carry an ID.

Source: I couldn't find a suitable source.

Mitigation: Don't carry your ID unless you need to.

Copper Strips

Problem: Buildings can be wiretapped using microphones as thin as paint.

Source: I couldn't find a suitable source.

Mitigation: Have sensitive conversations in areas unlikely to be wiretapped, or buildings with plain concrete walls.

Biometric Unlock

Problem: Police don't require a warrant to unlock your phone using biometrics.

Source: Various sources have conflicting information.

Mitigation: Lock your phone without biometrics or use two-factor fingerprint unlock on GrapheneOS.

Pedometers

Problem: Pedometers can reveal information such as your religion.

Source: A website I still can't find.

Mitigation: Use dumb pedometers that don't include timestamps.

710
 
 

cross-posted from: https://techlore.tv/videos/watch/f8717a48-72c0-4505-bbbf-cee26080e44a

In this Techlore Talks episode, I sit down with Jose Briones to explore whether dumb phones really offer better privacy and how digital minimalism can transform your relationship with technology. Jose breaks down practical strategies for reducing screen time, the importance of device segmentation, and why mindset, not just hardware, matters most. Whether you're considering a dumb phone or looking to reclaim your focus, this conversation will challenge how you think about your devices. > > Techlore empowers individuals with practical digital privacy knowledge, security tools, and advocacy resources to protect your data and reclaim your digital identity. > > 📱 RESOURCES IN VIDEO: > • https://josebriones.org/ > • https://www.dumbphones.org/ > • https://www.youtube.com/c/josebriones > • Jose's interview of Henry: https://josebriones.substack.com/p/building-better-digital-habits > > 🔎 RELATED VIDEOS: > • https://www.youtube.com/watch?v=oyQuwUJgPPY > > ⏱️ TIMESTAMPS: > 00:00:00 INTRO > 00:01:24 DUMBPHONES + PRIVACY & DIGITAL RIGHTS > 00:03:56 WHY ARE DUMBPHONES BETTER FOR PRIVACY? > 00:05:48 DUMBPHONES VS. MINIMAL SMARTPHONES > 00:08:57 ADOPTING THE MINDSET > 00:13:41 ADJUSTING FOR ONLINE WORK > 00:18:21 HANDLING MISMATCHED EMOTIONS > 00:22:40 ARE OFFLINE ACTIVITIES IMPORTANT? > 00:26:12 FINDING A BALANCE WITH ONLINE WORK REQUIREMENTS > 00:30:16 DIGITAL MINIMALISM + HARDWARE > 00:35:21 DEVICES & WHERE TO START > 00:39:42 ENCRYPTED COMMUNICATION > 00:44:19 WHEN OUR CHOICES IMPACT OTHERS > 00:48:33 ARE WE ANTI-TECHNOLOGY? > 00:51:36 HENRY'S IDEAL PHONE > 00:54:41 CONTENT CREATION & CONSUMPTION > 00:57:44 HOW CAN PEOPLE FIND YOU? > 00:59:29 OUTRO > > 🔐 TECHLORE RESOURCES: > • Homepage: https://techlore.tech/ > • Go Incognito Course: https://techlore.tech/goincognito > • Forum: https://discuss.techlore.tech/ > • Privacy Tools: https://techlore.tech/resources > > 🧡 SUPPORT TECHLORE: > • All Methods: https://techlore.tech/support > • Patreon: https://www.patreon.com/techlore > • YouTube Memberships: https://www.youtube.com/channel/UCs6KfncB4OV6Vug4o_bzijg/join > > 📺 MORE TECHLORE: > • Surveillance Report: https://www.youtube.com/@surveillancereport > • Techlore Clips: https://www.youtube.com/@techloreclips > > 🌐 FOLLOW ELSEWHERE: > • PeerTube: https://techlore.tv/ > • Mastodon: https://social.lol/@techlore > • Bluesky: https://bsky.app/profile/techlore.tech > • Twitter: https://twitter.com/TechloreInc > • Telegram: https://t.me/techlorefeed

711
 
 
712
0
submitted 10 months ago* (last edited 10 months ago) by hellfire103@lemmy.ca to c/privacy@lemmy.ml
 
 

It's been a while since I made this post, so I think it's time for an update.

Items in italics are subsequent additions.

Remember these rules:

  • Be respectful! Some people are early on in their privacy journey, or have a lax threat model. Just because it doesn't align with yours, or uses some anti-privacy software, doesn't mean you can downvote them! Help them improve by giving suggestions on alternatives.
  • Don't promote proprietary software! Proprietary software, no matter how good it may seem, is against the community rules, and generally frowned upon. If you aren't sure, you can always ask! This is a place to learn. Don't downvote people just because they don't know!
  • Don't focus solely on me! Since this happened in one of @Charger8232@lemmy.ml's posts, I want to mention that this thread is not designed to pick apart only my setup. The point is to contribute your own and help others. That doesn't mean you can't still give suggestions for mine, but don't prioritize mine over another.
  • Be polite! This falls under "Be respectful", but be kind to everyone! Say please, thank you, and sorry. Lemmy is really good about this, but there will always be someone.

Here is my setup:

Web browsing

  • I use Mullvad Browser for general browsing, with uBlock Origin and NoScript.
  • I use FoxyProxy to route my connection over Tor or I2P when accessing a hidden service or eepsite.
  • I use Librewolf for general browsing on on my Raspberry Pi, as Mullvad has not yet been ported to aarch64.
  • I use a self-hosted SearXNG instance for web searches, though it isn't quite as reliable as MetaGer used to be.
  • I use Mullvad VPN at all times.
    • I only use their owned servers; not their rented ones.
    • I usually enable multihop, but it does cause issues.
    • I use their Shadowsocks proxy to connect while on eduroam.
  • I use NextDNS and Mullvad DNS interchangeably for extra content blocking.
  • I use Libredirect and UntrackMe to redirect me to alternative frontends for popular services (e.g. YouTube -> Invidious)
  • I use Vivaldi for society stuff, where the stupid web apps don't play nice with adblockers.

Desktop

  • I use several trusted Linux distributions on my PCs; currently:
    • Arch Linux
    • Debian
    • Raspbian
    • Alpine (pending installation)
    • Slackware
  • Apart from my Raspberry Pi, the UEFI/BIOS is password-protected on all of my machines.
  • I have enabled secure boot on my ThinkPad T480s (the only device I own that supports it).
  • I always carry a Tails USB, but I haven't yet had cause to use it.
  • I use full disk encryption (LUKS) on everything, and I have a VeraCrypted pen drive for special cases.
  • I cover most of my webcams with Blu-Tac or electrical tape.
    • My ThinkPad T480s supports disabling the webcams and microphone in the UEFI.
    • I trust the security in GrapheneOS enough not to to this on my phone, which would be inconvenient (although a case with camera covers would be nice once my Otterbox wears out).

Mobile

  • I use a Pixel 8 with GrapheneOS.
  • Again, I am always connected to Mullvad VPN.
  • I currently use Cromite, but I often switch between several private options. Suggestions with reasoning are most welcome.
    • Cromite is hardened according to PrivacyGuides.
  • I have Tor Browser installed, for when I need more protection or if I need to access a .onion
  • My passcode is simply the longest string of digits I can remember.
    • I used to use an alphanumeric passphrase, but it became rather inconvenient when I disabled biometric unlock.
  • Radios (i.e. WiFi, Bluetooth) are automatically disabled when they are not in use.

Messaging

  • I have managed to get my family and a few friends to use Signal, and I have one friend who I speak to over Tox (I am aware of why this isn't the most secure; he's had difficulty with other options)
  • I am forced to use Discord, sadly, as all three of my societies use it as their only form of communication (other than social media), as do several societies from other universities and as does one of my close friends.
  • With the exceptions of my grandma and my old high school group chat, I no-longer use WhatsApp.
  • Now that I'm out of student accommodation, I have been able to delete Snapchat (my old flatmates insisted on using it for the flat group chat). Good riddance.

Online accounts

  • I use KeePass to manage my passwords, which are synchronised between devices using Syncthing.
    • KeePassXC is the client I use on desktop.
    • On Android, I use KeePassDX.
  • I use Aegis and OTPClient to generate TOTPs. I also have a graphing calculator that can generate these, but it doesn't seem to work very well these days.
  • I have anonymised all of my social media accounts apart from my LinkedIn (I wish I didn't have this in the first place; something something capitalism) and an old Mastodon account I lost access to.

Video streaming

  • I use Invidious, yt-dlp, and mpv to watch YouTube videos.
  • I use PeerTube when possible (mainly to watch Veronica Explains, New Ellijay TV, Techlore, and The Linux Experiment).

AI

  • I played around with ChatGPT and DALL-E in the early '20s, but those days are behind me now.
  • I occasionally use Duck.ai for help with server stuff, but only when I'm desperate and out of options.

Social Media

  • The only non-FOSS social media I use is Tumblr, which is ranked B by ToS;DR.
  • I have a LinkedIn, but I don't really use it.
  • I am the media officer for one of my societies, but I have all of those nasty proprietary apps in a separate profile.

Email

  • I use Posteo as my main provider.
  • I have DuckDuckGo Email Protection as an alias service, which I use through Quacky.
  • I use my uni email (Outlook 365) and my society email (Gmail) through privacy-respecting clients; namely Evolution, KMail (if I'm running KDE), and FairEmail.

Shopping/Finance

  • I rarely make online purchases. I am certainly being tracked, but I'm simply not producing enough data in the first place for this to be a big problem.
  • For physical purchases, I am trying to use cash more often, but it makes my budget harder to manage.
  • The only recurring payment I make is to OVH, who provide my VPS and are known to be one of the better hosting providers from a privacy standpoint (though I imagine not the best).
  • I would use Monero for things like Mullvad, but I've had a hard time acquiring any.
  • I have joined several loyalty schemes, but I rarely use them as I shop at Aldi (specifically Aldi Süd), which doesn't have one.
    • The data collected by supermarkets when I use my loyalty cards is, in my opinion, a fair trade. They get some analytics, and I get discounted products. I am comfortable with this.

Music

  • I occasionally stream music on Bandcamp, but virtually everything I listen to is either on CD or a local file.
  • I occasionally use an MP3 stream to listen to KERRANG! Radio, Radio 4, Classic FM (for DanTDM's show), or my university's student radio station.
  • ~~I give Last.fm my listening data intentionally.~~
  • I use Libre.fm and ListenBrainz to track my listening habits.

TV shows

  • I use DVDs for most of my viewing, but I have sailed the high seas in the past
  • Some shows I enjoy (i.e. Helluva Boss) are released officially for free on YouTube (watched via Invidious).
  • My flat does have a smart TV, but its one of the older ones (sans bullshit) and not connected to the internet.
  • One of my flatmates is trying to set up a media server, which is nice.

Gaming

  • I generally don't game.
  • When playing Minecraft, I use PrismLauncher and I'm always sure to install the Anti-Telemetry mod.

Programming

  • I code using Micro. I also sometimes use Kate, but only if I'm running Plasma.
  • I use sourcehut and Codeberg to host my projects.

Productivity

  • I normally just use Markdown for note-taking and documents.
  • Next time I make a presentation, I will probably use Markdown slides (LibreOffice Impress isn't great, in my experience).
  • Spreadsheets are edited with LibreOffice Calc, but I tend to just use a text editor to write a CSV or TSV unless I need formulae.
  • One of my societies uses Trello and Google Docs for their stuff. However, I use these in their own profile on my phone, and in their own browser on desktop.
  • If there's anything really sensitive or really private I need to write, I just use a pen and paper. I also own a typewriter.

Misc

  • I use FreshRSS for news.
    • I use Capy Reader on my phone and Newsboat on desktop.
  • My local timezone just happens to be the same as UTC most of the time.
  • I use a non-smart, analogue watch (RIP PineTime).
  • I don't have a car, as I'm skint.
  • I use Bluetooth earbuds out of necessity. I'm still salty about Apple removing the headphone jack and then every other phone company (in this case, Google) following suit. However, they are basic earbuds which do not require an app, and so they should be more private than other similar models.
  • I will never use Amazon Echo or Google Home.

To-Do

  • Use cash more often
  • Try to get family to ditch Meta
  • Get grandparents to use Signal
  • Audit all systems with Lynis
  • Selectively clear cookies and site data every so often in Vivaldi (automate, if possible)

Thanks for reading!

713
714
 
 

I want to share an interesting cryptography paper which introduces "anamorphic encryption", where the ciphertext encrypts two messages. One is a message to reveal to a dictator, who wants the secret key and message to control the narrative. Behind it lies a hidden message, guarded behind a "double key", which is to communicate messages of intent secretly.

It's kind of like having a duress key to reveal, but instead you can send real messages with the real key.

For instance, an investigative journalist could encrypt a fake message "Everyone is content in our utopia" as a smokescreen to show to the dictator, while true messages like "Minorities are forced into labor camps" can be hidden in the anamorphically encrypted ciphertexts to notify the outside free press.

The authors argue that cryptosystems already in use supports the anamorphic mode, where you encrypt a normal-looking ciphertext which contains the hidden message.

Given that it has been 3 years since this paper, I think there would have been some applications of this technology. Do you guys know of any?

715
0
submitted 10 months ago* (last edited 10 months ago) by Dr_Vindaloo@lemmy.ml to c/privacy@lemmy.ml
 
 

I just realized that RT (dot com) is inaccessible when Mullvad is enabled, even with all content blockers turned off. It says the DNS lookup failed. I tried from various countries too.

This post is not about endorsing or condemning any particular site, I just want to know if anyone knows whether there could be a technical reason for this? Or are we just banning sites we don't like now?

Edit: Solved. RT is blocking some Mullvad nodes, not the other way around. Works with a random Albania server and I assume some others.

716
 
 

cross-posted from: https://lemmy.ml/post/37569557

The Free Software Foundation (FSF) today announced its project to bring mobile phone freedom to users. "Librephone" is an initiative to reverse-engineer obstacles preventing mobile phone freedom until its goal is achieved.

Librephone is a new initiative by the FSF with the goal of bringing full freedom to the mobile computing environment. The vast majority of software users around the world use a mobile phone as their primary computing device. After forty years of advocacy for computing freedom, the FSF will now work to bring the right to study, change, share, and modify the programs users depend on in their daily lives to mobile phones.

717
 
 

cross-posted from: https://lemmy.zip/post/50937678

https://archive.md/QMvAI

With just $800 in basic equipment, researchers found a stunning variety of data—including thousands of T-Mobile users’ calls and texts and even US military communications—sent by satellites unencrypted.

718
 
 

Over the past few years I have gone through a bunch of different apps and protocols to find the best one for "securely" communicating with my family and friends.

I ended up with the amazing XMPP protocol and my family/friends frequently use its clients to contact me.

Monal for IOS and Cheogram/Conversations/Quicksy for Android. The android app I install depends on if I can get F-Droid on their phone or not.

It's been great with OMEMO encryption and the clients/apps available for XMPP. But sometimes I have issues introducing people to it.

Jabber (friendly name for xmpp) sounds silly to say. The clients all have weird names. And after trying the Signal mobile app it feels more focused than what anyone in the XMPP community has whipped up.

But the capabilities of XMPP makes it better.

Signal Cons (immediete)

  • Centralized
  • Single app
  • Phone numbers

XMPP/Jabber Cons

  • Picking server
  • Apps are sort of less friendly

What really scares me about Signal is the centralization. Any nerd can easily host an XMPP server these days. But Signal from what I've heard really wants us to use their server.

If XMPP gets more attention I'm sure we can get people supporting projects and creating better apps.

I keep seeing people recommended Signal instead.

This is a bit of a tired ramble. What I wanna know is why anyone is preferring Signal over XMPP apps. I assume it might be not knowing about it. Tell me what you use to message people.

719
 
 

Obviously a lot of people here hide a lot of information. What is keeping you all from extreme stress considering the possibility that a government is spying on your actions despite strict privacy practices? Considering my current situation and my extreme threat model it feels like the privacy walls around me are closing in. I'm very paranoid. I do a lot of risky and dangerous shit on the internet. Every knock on my door and phone call feels like the police. I don't talk with others about what I do and I'm always hiding my internet activity from others. Any thoughts would be helpful

720
1
submitted 10 months ago* (last edited 10 months ago) by xoron@programming.dev to c/privacy@lemmy.ml
 
 

IMPORTANT NOTE - READ FIRST:

This is still a work-in-progress and a close-source project (This is what a honeypot would look like). To view the open source MVP version see here. NONE of my projects have been audited or reviewed. I provide them for testing and demo purposes only. NOT to replace your current messaging app (or any other app you use).

BE RESPONSIBLE WHEN USING UNAUDITED SOFTWARE... DO NOT USE FOR SENSITIVE PURPOSES.


Now that I've hit you over the head with caution...

Want to send encrypted WebRTC messages and video calls with no downloads, no sign-ups and no tracking?

This prototype uses WebRTC to establish an encrypted browser-to-browser connection. Everything is ephemeral and cleared when you refresh the page - true zerodata privacy!

Check out the pre-release demo here.

721
5
submitted 10 months ago* (last edited 10 months ago) by Charger8232@lemmy.ml to c/privacy@lemmy.ml
 
 

VPN Comparison

After making a post about comparing VPN providers, I received a lot of requested feedback. I've implemented most of the ideas I received.

Providers

Notes

  • I'm human. I make mistakes. I made multiple mistakes in my last post, and there may be some here. I've tried my best.
  • Pricing is sometimes weird. For example, a 1 year plan for Private Internet Access is 37.19€ first year and then auto-renews annually at 46.73€. By the way, they misspelled "annually". AirVPN has a 3 day pricing plan. For the instances when pricing is weird, I did what I felt was best on a case-by-case basis.
  • Tor is not a VPN, but there are multiple apps that allow you to use it like a VPN. They've released an official Tor VPN app for Android, and there is a verified Flatpak called Carburetor which you can use to use Tor like a VPN on secureblue (Linux). It's not unreasonable to add this to the list.
  • Some projects use different licenses for different platforms. For example, NordVPN has an open source Linux client. However, to call NordVPN open source would be like calling a meat sandwich vegan because the bread is vegan.
  • The age of a VPN isn't a good indicator of how secure it is. There could be a trustworthy VPN that's been around for 10 years but uses insecure, outdated code, and a new VPN that's been around for 10 days but uses up-to-date, modern code.
  • Some VPNs, like Surfshark VPN, operate in multiple countries. Legality may vary.
  • All of the VPNs claim a "no log" policy, but there's some I trust more than others to actually uphold that.
  • Tor is special in the port forwarding category, because it depends on what you're using port forwarding for. In some cases, Tor doesn't need port forwarding.
  • Tor technically doesn't have a WireGuard profile, but you could (probably?) create one.

Takeaways

  • If you don't mind the speed cost, Tor is a really good option to protect your IP address.
  • If you're on a budget, NymVPN, Private Internet Access, and Surfshark VPN are generally the cheapest. If you're paying month-by-month, Mullvad VPN still can't be beat.
  • If you want VPNs that go out of their way to collect as little information as possible, IVPN, Mullvad VPN, and NymVPN don't require any personal information to use. And Tor, of course.

ODS file: https://files.catbox.moe/cly0o6.ods

722
 
 

Let's imagine we live in a world the American government is not the American government so you can trust what American companies say when they talk about protecting your privacy and so on...

723
 
 

In a compelling, entertaining and accessible format, we present these negative awards to companies, organisations, and politicians. The BigBrotherAwards highlight privacy and data protection offenders in business and politics, or as the French paper Le Monde once put it, they are the “Oscars for data leeches”.

I can really recommend Digitalcourage and the event. I am not directly involved.

724
725
view more: ‹ prev next ›