Privacy

50695 readers
638 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 6 years ago
MODERATORS
726
1
submitted 10 months ago* (last edited 10 months ago) by thermogel@lemmy.ml to c/privacy@lemmy.ml
 
 

Our country needs more privacy conscious communities in order to resist against surveillace capitalism. Join to discuss Mexico-specific privacy discussions!

!privacidadmx@lemmy.ml 💚🤍❤️

727
 
 

For several years, I've entertained the idea of creating an online portfolio, but it's remained only an idea since I am not sure what I should put on it. What's a good way to decide what goes on the personally-identifiable portfolio and what should remain under pseudonyms?

728
1
submitted 10 months ago* (last edited 10 months ago) by Normo@lemdro.id to c/privacy@lemmy.ml
 
 

These are some practices which worked for me, You can adjust them to match your preferences. Feel free to add your own in the comments


  1. If you are forced to use something that is privacy invasive, Make it isolated from your actual profile. (Ex- Using a 2nd Browser profile, Using an alias to signup)

  1. Always use the services that you use from their official clients. Don't blindly trust 3rd party clients just because they claim that they are "more private", Do some research before using it.

  1. Don't mix up your work life with your personal life. Consider getting a second phone just for work purposes or you could use a second profile for work purposes if your phone has the ability to create multiple user profiles.

  1. Keep a habit of clearing the browser data once in a while. (You can make your browser automatically clear the browser data when closing but it can be kinda annoying when you have to log back into websites everytime)

  1. Strip away the metadata of your photos and documents when sharing them.

  1. Check connected apps/services regularly and revoke unused ones. (on Discord, GitHub, Matrix and etc.)

  1. Audit app permissions regularly (Some apps adds in new permissions or re-enables permissions over updates)

The old #3 tip got removed (The password one) because it served no additional protection and was pretty annoying. It was a mistake by me, sorry

729
3
VPN Comparison (lemmy.ml)
submitted 10 months ago* (last edited 10 months ago) by Charger8232@lemmy.ml to c/privacy@lemmy.ml
 
 

VPN Comparison

I made a spreadsheet comparing different open source VPN providers.

Part 2 here

Providers

Notes

  • Please do not start a flame war about Proton.
  • Please do not start a flame war about cryptocurrencies. Monero is the only cryptocurrency listed because of its privacy.
  • The very left column is the category for each row, the middle section is the various VPN providers, and the right section is which VPNs are the best in each category.
  • IVPN has two differing plans, which is why "Standard" and "Pro" are sometimes differentiated.
  • For accounts, "Generated" means a random identifier is created for you to act as your account, "Required" means you must sign up yourself. Proton VPN allows guest use under specific conditions (e.g. installed from the Google Play Store), but otherwise requires an account.
  • Switzerland is seen as more private than Sweden. Gibraltar is seen as privacy neutral.
  • All prices are in United States Dollars. Tax is not included.
  • Pricing is based on the price combination to achieve the exact time frame. For example, Proton VPN does not have a 3 year plan but you can achieve 3 years by combining a 2 year plan with a 1 year plan.
  • The availability section is security based. Availability is framed around a GrapheneOS and secureblue setup.
  • The Proton VPN Flatpak is unofficial, but based on the official code.
  • Availability on secureblue is based on the ujust install-vpn command. Security features must be disabled on secureblue in order to use the GUI for IVPN and Mullvad VPN, but not for Proton VPN. Mozilla VPN and NymVPN are available as Flatpaks, which are safer than layering packages.
  • I wanted to include more categories, such as which programming languages they are written in, connection speed, and security, but that became far too difficult and complex, so I decided to omit those categories.

Takeaways

  • NymVPN is very very new, but it's off to a strong start. It wins in almost every category. I actually hadn't heard of it until I started this project.
  • If you want a free VPN, Proton VPN is the only one here that meets that requirement.
  • If you want to pay week-by-week, IVPN is the only one that allows that.
  • If you're paying month-by-month on a budget, Mullvad VPN is the cheapest option.
  • NymVPN is the cheapest plan for anything past 1 month.
  • If you want to use Accrescent as your main app store, IVPN is the only VPN available there for now.
  • If you want to pay for a bundle of apps, including a VPN, Proton sells more than just a VPN.
  • Mozilla VPN is terrible. The only thing it has going for it is a verified Flatpak, but NymVPN also has that so it doesn't even matter.
730
731
 
 

Greetings, I need MFA and a few other things for work. I'd like to swap to a dumb phone on my off times. I don't want to constantly swap out a SIM as it eventually damages the card itself.

What are my options? And is there a dumb phone you recommended?

732
 
 

Let's say I want to bridge from WhatsApp or telegram to Matrix, have I gaibed something in terms of privacy? In which case would it make sense? Public group chats? Direct chats?

733
 
 

Have you had any privacy wins recently? Anything you've tried or tweaked to improve your privacy? Anyone who's listened to something you've said? Do you have any privacy enhancing projects or changes you're working on implementing

I managed to convert someone to Signal this week. Was having reception difficulties with a phone call (both of us in spotty areas) and after a drop out, managed to get them on board with Signal. A very notable quality improvement in the call which helped reinforce to them it was a good idea.

I'm going to work on setting up Pihole over the weekend.

Note: I did steal this topic idea from Techlore.

734
735
 
 

I’ve recently “moved” countries! And by that I of course mean the country I exit from online. I’m trying to keep a perma-VPN situation going.

YouTube loaded for me on my computer, where I’m logged in, even through uBlock Origin. But no luck on their locked down phone app, where I’m also logged in. Very weird. Shuffled servers a bit and still nothing. And I’m not talking about sports content which is always super locked down.

Anyone else facing this problem? Has this been the norm for a while in some exit countries? Is this just one of those wait for it to tide over situations that works itself out in the end?

Weirdly it loads shorts just fine.

I wonder at what point it would end up being better to just rent a VPS and wireguard into that.

In case your answer is “Just use Peertube!” my reply is Inshallah I will

736
 
 

This app has been under development for a few months now and is ready for use.

Should be available on Google play first. IOS in the works and released soon.

If your a developer who can contribute and make it even better that is welcomed it's still very early.

737
738
 
 

I've been a user of Mullvad for a while and love there stance on privacy. I really like how they have stayed focused. But recently I feel like there speeds have gotten way worse.

For example I may be able to get 150ish up and down without a VPN but once I add Mullvad it gets way slower. Still very useable for most tasks but limiting when I have bigger downloads. This is across several different networks to eliminate it just being an individual network problem.

Has anyone else been experiencing this?

739
 
 

The EU built a system called CounterR that essentially performs pre-crime thought surveillance. The TLDR is that an AI company, with direct input from half a dozen European police forces, built a tool that scrapes social media, forums, and other sources to assign citizens a score based on what they think as opposed to what they've actually done. The EC also has not released details of the project..

The report itself acknowledges that this sort of automated system "can trigger new fundamental rights risks that affect rights different than the protection of personal data and privacy."

The European Commission's White Paper on Al observes that Al-related processing of personal data can trigger new fundamental rights risks that affect rights different than the protection of personal data and privacy, such as the right to freedom of expression, and political freedoms - in particular when Al is used by online intermediaries to prioritise information and for content moderation.

The police were active co-developers, sitting in meetings to define the criteria and feeding real, anonymized data from their investigations to train the LLM. So now you have a feedback loop where police define the threat, the LLM learns it, and the police validate the results, with zero external oversight.

And of course, it's all shrouded in secrecy. The whole thing is confidential, the source code is proprietary so even partners can't audit it, and the ethics board is made up of the same people building the thing. There's no clear requirement to track false positives, so you could be flagged as a potential radical and never know why.

Regarding transparency of funded research, it must be noted that generally research proposals foresee Confidentiality of some results is often necessary, especially in the realm of security.

The cherry on top? The core technology, developed with public funds, was recently acquired by a private company, Logically, who can now sell this dystopian scoring system to whoever they want.

The citizens of the EU literally paid to build our own panopticon. The whole project is about normalizing the idea that the state gets to algorithmically monitor and judge your political beliefs before you ever commit a crime.

740
741
742
 
 

cross-posted from: https://lemmy.world/post/36982928

Tyler Robinson, the suspect of the Charlie Kirk's assassination, almost got away with it all. This is how the FBI really caught him. Support my independent work: / thehatedone

The FBI is telling you that the manhunt for the suspect of Charlie Kirk's assassination was a result of a historic investigation with the use of the most advanced intelligence techniques available to law enforcement.

But the reality will tell you a different story. A story that is now very well reported and reveals how the suspect was actually caught. In what's about to follow, I'll explain to you every detail of the surveillance and intelligence behind the manhunt for Tyler Robinson, the alleged shooter at Utah Valley. In reality, it is not clear whether anything the FBI did actually helped track down the suspect.

The most damning admission of this fact is that after a full day of endless investigation, full 24 hours after Charlie Kirk was shot, the FBI, Kash Patel and local law enforcement were so confused they had “no idea where” the suspect was and they weren’t even sure whether he still was in Utah or not.

By the time the police did finally catch Tyler Robinson, he was so far away from the scene of the shooting that had he simply kept running, he probably would’ve gone away with it. He was arrested 250 miles away, in his parental home in St. George, Utah, whole 33 hours after the shooting.

SOURCES [References available in the transcript: / how-they-really-140361439 ] [0] • Kash Patel discusses investigation into Ch...
[1] https://www.nytimes.com/2025/09/12/us... [2] https://www.nytimes.com/live/2025/09/... [3] https://www.tmz.com/2025/09/13/tyler-... [4] • Chilling Emergency Dispatch Audio Captured...
[5] https://news.sky.com/story/charlie-ki... [6] https://www.nytimes.com/interactive/2... [7] https://archive.is/K6rQw [8] https://archive.today/01VkR [9] https://www.nbcnews.com/news/us-news/... [10] https://archive.today/4BcVY [11] https://www.nytimes.com/2025/09/11/us... [12] https://x.com/UtahDPS/status/19662919... [13] https://www.economist.com/science-and... [14] https://www.technologyreview.com/2025... [15] • Tyler Robinson, suspect in fatal shooting ...
[16] • You Can Run but Not Hide: Improving Gait R...
[17] https://ieeexplore.ieee.org/abstract/... [18] https://arxiv.org/abs/2306.17206 [19] • Suspected Charlie Kirk shooter seen in sur...
[20] https://innovationcenter.msu.edu/who-... [21] https://www.tmz.com/2025/09/13/tyler-... [22] https://x.com/TMZ/status/196627181449... [23] https://marketplace.fedramp.gov/produ... [24] https://arxiv.org/abs/2505.04616 [25] https://arxiv.org/pdf/2310.15946 [26] https://openaccess.thecvf.com/content... [27] • Raw Video: Charlie Kirk shooting suspect a...
[28] https://www.bbc.com/news/articles/c20... [29] https://www.newsweek.com/tyler-robins...

743
 
 

I'm looking into installing a door lock w/ key pad at home for two use cases:

  1. I'm out of town and need to allow someone to enter my home, in an emergency or for any reason.
  2. Nice to have - "oh shit, did I lock the door" - ability to lock the door remotely from my phone, would also solve use case #1 by unlocking remotely.

If there are no privacy respecting / self hosted apps for remote control (use case #2), then a "dumb" electronic lock w/ key pad that enables me to set a PIN that I can give to a friend or neighbor in a pinch and then reset the PIN after I get home, that would be good enough. If no such keypad/electronic locks exist, then my backup plan is to just make a few copies of my key for trusted friends & family and/or hide a key, but I'd like to explore the keypad route.

744
745
 
 

I just installed Brave to have some different accs logged, and then I saw that addon... I'm running it right now but... did I just set a Tor relay? Really? It wasn't that easy before :S

746
747
748
749
 
 

The Private Conversation

The Threat Against the Cornerstone of Democracy and the Individual’s

Right to Choose Who Listens

Introduction

“Chat Control 2.0” is once again on the table, and one can’t help but wonder why our politicians are so eager to outlaw private conversation between citizens. This is not the first open letter written about this legislative proposal. Many people far more technically competent than I have addressed lawmakers and voiced strong criticism against it, often with detailed and well-reasoned arguments. Yet these arguments have mostly fallen on deaf ears. Since our elected representatives seem unwilling to listen to the experts, I am instead turning to you, the people, the very ones who will be affected. Time is short, but our democratic rights are not yet lost. We have had democracy for a very short time, as little as a few decades in some parts of Europe, The fact that it is so poorly protected, especially by those who are supposed to be its champions, is deeply tragic. Sitting in democracy’s front hall, they now cast their votes in the name of self-interest rather than in the name of the people. Let me make one thing absolutely clear right from the start: this legislative proposal uses children merely as a costume to conceal its true nature, to open up Sweden’s and the EU’s citizens to mass surveillance.

Perverse Argumentation

Every objection to the proposal is met with the same response: “We just want to protect the children.” This line is used to force opponents into a defensive position, where their moral intentions are questioned, instead of engaging them in a proper, mature debate. It is, quite simply, a deceitful form of argument. Consider this: If someone were to oppose locking all children in isolation without human contact until the age of 18, on the grounds that it would “protect them” from online harm or exploitation, one could respond with: “So you don’t want to protect the children?” Most of us would recognize how absurd that is. Just because someone opposes total isolation of children doesn’t mean they wish them harm.

Questionable Motivation and False Pretenses

Let’s take a closer look at two specific paragraphs from the proposal currently on the EU agenda, soon to be voted on. (2) “Those providers often being the only ones in a position to prevent or combat such abuse.” It has always been, and will continue to be, parents who are primarily in the position to prevent their children from coming to harm online. The widespread apathy toward digital literacy among parents and the general public, ongoing since the late 1990s, bears much of the blame for why adults today are so detached from what their children do on their devices and on the internet. Even today, in one of the world’s most digital societies, people still toss around phrases like, “I’m not good with technology,” “I’m technically incompetent,” or “I’m from the wrong generation to understand the internet.” But this isn’t a funny joke. Humanity sent people to the moon in 1969, radar was invented in 1904, and the internet has been publicly available for 30 years. Technology is not new. Of course, there should be moderation on platforms where children are expected to frequently interact, but to claim that technology companies are the only ones in a position to prevent harm to children online is an admission of impotence. It reveals, quite clearly, the staggering technical ignorance of those who support this proposal. If these lawmakers truly wanted to protect children from exploitation, and if this proposal wasn’t just a Trojan horse for mass surveillance, then why don’t they instead propose things like:

-Requiring parents to become digitally literate.

-Providing more resources to schools.

-Laws regulating children’s unsupervised use of the internet and smartphones.

-Support services for families and children targeted by grooming or online exploitation.

Or even active police protection for every child.

Why not? Because that would cost money! The cost of implementing this proposal will be astronomical, but that’s fine, because as a bonus, they’ll gain the ability to monitor the population. That is apparently priceless, unlike a child’s innocence, to which they’ve clearly assigned a monetary value. Of course, I care deeply about our children and want them to be safe. But I cannot leave my children alone in Sarek National Park and then claim that the only ones who could have prevented them from getting hurt were the park rangers, and therefore, the rangers must have the right to listen in on everyone hiking in the wilderness.

The Return of the Class Society

(12a) “In the light of the more limited risk of their use for the purpose of child sexual abuse and the need to preserve confidential information, including classified information, information covered by professional secrecy and trade secrets, electronic communications services that are not publicly available… should be excluded from the scope of this Regulation…” First, one must ask: how do the authors of this proposal even know how much CSAM (child sexual abuse material) passes through or within corporate internal communication systems? Moreover, they openly acknowledge here that there is a need to preserve confidentiality between two parties for communication that is not childporn.

But apparently, the individual citizen is not deemed worthy of this right. Companies, like feudal lords above the serfs, are placed above the individual. The proposal even carves out exemptions for what it calls “Bodies of Authority,” hammering home the vision of a return to a class-based society across Europe, where rights are stripped from ordinary citizens and reserved only for the so-called elite. There’s an even darker implication here. Let’s unpack it logically: • Lawmakers claim that encrypted communication is used by pedophiles to share child pornography. • Yet they want scanning to apply only to individual citizens, while they themselves are exempt. • Meaning: politicians want to retain the ability to freely share images and videos on the very platforms they describe as being “used” (and note they changed the wording from misused to used) for child pornography.

So, the only logical conclusion is that those who wrote, support, or vote for this law must either be pedophiles themselves, or wish to create an environment where such material can flow freely within the political and corporate elite, away from public scrutiny. Do I seriously believe all supporters of the bill are pedophiles? No. Most are likely just useful idiots serving those who stand to gain power or money from it. But history is filled with examples of immoral people seeking positions of authority precisely because those positions lack oversight, so they can indulge their perverse desires at others’ expense.

Returning to paragraph 12a, its wording “in the light of the more limited risk” essentially says: a certain acceptable amount of child pornography is tolerable, as long as corporate interests and trade secrets remain unharmed. In fact, if you read the paragraph literally, it implies that even a group like “The Berlin men who touch Boys. Inc.” could legally create a private organization and share child abuse material among themselves without oversight. Let me repeat this clearly: this law’s only purpose is to lay the groundwork for a new class-based society, one in which the individual is perpetually considered suspicious and therefore must be watched by the elite to maintain order. We cannot allow our elected officials to elevate themselves into a higher social class, standing above ordinary citizens.

A Tiger Without Teeth

We can ask more questions about this obsessive desire for surveillance. Suppose the law passes and comes into force. Let’s even ignore that only massive corporations will have the resources to implement this fantastical solution, and that it will not immediately expand into direct monitoring of all communication. Do these technically infantile politicians truly believe that criminals won’t adapt? That they won’t find new ways, like TOR, which already exists? But of course, they can’t touch TOR, because many national security agencies depend on it for their own secret communications and operations. I would even dare to say that the lawmakers probably don’t understand that it’s entirely possible for motivated and skilled groups to communicate secretly, in plain sight, online, using data that is neccesarily random. A law like this will be like pouring wine on a goose: a complete waste of money, leaving only an angry goose, and the total decay of democracy, of course.

The Unspoken Consequences

The proposal suggests that one or several technical systems (never explained in detail) will automatically scan all images and videos shared between private individuals, to detect known illegal material, but also to identify new, previously unknown material. First, this is not technically feasible today, not securely or reliably. Second, it means that this “AI,” which must be a generative model trained on known illegal material, will by definition be capable of generating new child pornography itself if the model is inverted. In other words, EU lawmakers want to build a child-porn-generating AI model trained on EU’s combined police databases. Now imagine you send a picture of your toddler playing in the bath, or smiling on a changing table, to their grandparents. A completely normal, innocent family photo. Would you want an unknown third party to have access to that image? Or for it to be absorbed into a generative AI that could then produce child pornography based on it? The supposed safety of such a system would rely entirely on the hope that no ill-intentioned individuals ever gain access. But no system is secure. Remember the Swedish Miljödata Data leak? Now imagine that instead of that data, it was all your private photos from every chat with your family, partner, and friends, open for anyone to search.

Clean Flour in the Wrong Bag

As historian Wilhelm Agrell once said: “Clean flour in the wrong bag; even the most innocent are caught in the machinery of a surveillance society, and this is nothing new.” He tells the story of April 29, 1978, when a carpenter named Torsten Leander parked his car at a schoolyard in Norrköping, not knowing that the area was reserved for attendees of a cultural association’s annual meeting. It wasn’t an offense, but a local security agent recorded all license plates, and Leander’s name ended up in secret police files. He had done nothing wrong, merely been unlucky enough to get caught in one of the Cold War’s invisible surveillance nets. It is not up to individuals to prove their innocence. Our justice system was never meant to work that way. Now imagine that same innocent family photo to the grandparents. If the automated scanner falsely flags it as child sexual abuse material, what happens? Studies show that AI-based image and facial recognition systems vary wildly in accuracy, sometimes over 90%, but in other cases as low as 36%. I wouldn’t board a plane with a pilot that inconsistent. Yet in this case, you could be wrongly branded a pedophile. Good luck clearing your name, even if the investigation is dropped.

The Broken Trust

If this law passes, the foundation of a new class society will be cemented. Along with it, public trust will be irreparably broken. How could we ever again trust our representatives, knowing that they so easily and ruthlessly discard our civil and human rights in the name of self-interest?

Final Words

I sincerely hope that you, the reader, found parts of this text absurd, because the truth is, the law being proposed is absurd. Under the banner of “think of the children,” it seeks to dismantle the very foundations of a democratic society. We cannot allow democracy to become a fleeting curiosity, a relic in the history books. Capacity takes time to build, but motivation can change overnight. We need only look across the Atlantic to see how quickly democracy can be dismantled. Laws once made with good intentions are now used to suppress free speech and democratic values. I know it’s tedious to read EU legislation and proposals, but these 209 pages could be what cements European democracy as nothing more than a historical chapter. The flour in your bag may be clean today, but who knows how it will be judged tomorrow? Today it’s legal to criticize your government. Tomorrow, it might not be.

, Folke Arbetsson

750
 
 

I know this might come across as a very impractical expectation but I wanted to hear from people who have a fulfilling career and also a sense for privacy: How did you do it?

I've recently had trouble finding a new job in the tech sector. So far I've been doing alright without LinkedIn, just directly applying to companies, but it seems less successful now. So I thought what the hell, might have to do this after all. After I've made an account I got quickly banned for logging in once from a VPN connection. Only way to get unbanned is to give my government ID to them - but that really rubs me the wrong way (so many leaks of IDs recently and all).

I'm remaining banned for the moment, contemplating what impact this might have on my career. It gives me a fair bit of anxiety, considering that my sense of where my boundaries are seems to be deemed unacceptable by the monopoly of international job markets. Should I just give in and send my ID? Am I delusional?

As always, I appreciate the discourse of this wonderfully decentralized community we have here on lemmy! ☺️

view more: ‹ prev next ›