Privacy

50695 readers
633 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 6 years ago
MODERATORS
801
 
 

Can someone tell me why an Android launcher should have Internet access..? Been on the hunt for a new launcher but am not installing software which I fail to see having to use the net to operate...just like keyboards...another one that has me scratch my head

802
1
submitted 11 months ago* (last edited 11 months ago) by spinning_disk_engineer@lemmy.ca to c/privacy@lemmy.ml
 
 

I use mailbox.org. Mailbox.org provides an "encrypted mailbox" feature, which PGP encrypts incoming unencrypted emails. The server can of course intercept incoming messages, but it can't look at the entire backlog unless it was compromised the entire time.

Alternatively, using POP3 instead of IMAP (at least with the default settings) deletes emails from the server after downloading, whenever my laptop is connected. Thus, the server can intercept incoming messages, but not the entire backlog.

Of course, both of these have downsides. The encrypted mailbox is PGP, so it misses important details like the subject lines and source addresses. Meanwhile, POP3 can leave my mail entirely unprotected for as long as I'm offline, and it also means that I can't access it from anything other than my laptop, and means that I have to do manual backups.

Which is more important in terms of security, or should I use both? I'm looking for the legal perspective of law enforcement (In Canada and Germany, home to myself and my email provider respectively), but also that of some hacker who's trying to get into my (and everyone else's) accounts.

Would there be a server software that I could use to download emails from mailbox.org over POP3 and then provide them to all my own devices over IMAP? That might, in some sense be the best of both worlds. Right now, I am using both POP3 and the encrypted mailbox, but convenience is definitely not optimal, so I'd like to change if it can be done safely.

803
 
 

And all service providers/hosts around the world are expected to comply.

Here's one summary of the looming access control measures.

Reading and understanding all this (and the linked sources) feels so.. difficult, obtuse, complex.

804
805
 
 
806
 
 

I was taking a quiz on D2L on Firefox (windows 11) while using ChatGPT to check my answers when all of a sudden my internet cut in and out. It caused my quiz tab to minimize while everything else stayed open. Then the tab said "internet connection restored".

This has happened twice and both times were during a quiz when I was using ChatGPT.

Is it right to assume that since this is my personal computer then they don't know what else I have on my desktop?

807
808
 
 

cross-posted from: https://lemmy.zip/post/48551495

809
 
 

We all hate google and youtube, but overall as a community we're all simultaneously lukewarm and non-committal about pushing towards using an alternative. I admittedly cling to invidious frontends for dear life.

It seems like whenever somebody asks for an alternative to youtube, they're offered Odysee and Peertube, but inevitably many others chime in about the shortcomings of both of those platforms.

Can we as a community come to a consensus as to which of these platforms should be pushed forward?

I don't even think it needs to be a binary choice. Obviously youtube cannot be immediately replaced for it's archival of educational and tutorial videos, but we can at least push newcomers towards using invidious frontends for those instances.

Maybe Odysee is better for some type of content over Peertube. Let's discuss which platform works best for what and try to be more active about sharing and promoting them not just to viewers but potential creators as well.

If you go to share a youtube link, try to see if that video exists on an alternate platform first and share that link instead. I think that's a good first step towards getting away from youtube in the privacy community.

But youtube alternatives are still very much on the fringe and I'm hoping this post will at least inspire some discussion about changing that.

810
811
 
 

So google now requires Id verification for submitting apps to android, what does it mean for Foss apps, for Foss stores like fdroid and for future development?

812
 
 

cross-posted from: https://programming.dev/post/37278389

Optical blur is an inherent property of any lens system and is challenging to model in modern cameras because of their complex optical elements. To tackle this challenge, we introduce a high‑dimensional neural representation of blur—the lens blur field—and a practical method for acquisition.

The lens blur field is a multilayer perceptron (MLP) designed to (1) accurately capture variations of the lens 2‑D point spread function over image‑plane location, focus setting, and optionally depth; and (2) represent these variations parametrically as a single, sensor‑specific function. The representation models the combined effects of defocus, diffraction, aberration, and accounts for sensor features such as pixel color filters and pixel‑specific micro‑lenses.

We provide a first‑of‑its‑kind dataset of 5‑D blur fields—for smartphone cameras, camera bodies equipped with a variety of lenses, etc. Finally, we show that acquired 5‑D blur fields are expressive and accurate enough to reveal, for the first time, differences in optical behavior of smartphone devices of the same make and model.

813
 
 

I have been finding more and more videos being recommended on my homepage which I search about even though my privacy paths I follow seem good enough. So this is how it goes:

  • I come across a term I don't know on a Lemmy post.
  • I open my browser, Cromite which has been set to priv.au, a searx instance, as the default search engine.
  • Search the word and don't even open any links to know, just reading the meaning of this term out from the subtexts present on search results.
  • And then I open YouTube and scroll a bit on homepage to find a video on that term.

This has happened to me twice in past few days and I am not understanding which service of mine is giving it away. To add more about my setup, I'm on mobile btw, using FUTO keyboard and using Duckduckgo VPN which blocks cross-app tracking. My mobile lemmy client is Voyager. I don't even interact with the post containing that term. I just open it up, read the post and the comments. No upvoting no commenting.

Who's the culprit here?

814
1
submitted 11 months ago* (last edited 11 months ago) by baxster@sopuli.xyz to c/privacy@lemmy.ml
 
 

The EU Commission is lying open on social media about chat control. Tomorrow EU governments debate about Chat control 2.0 Use the fightchatcontrol.eu email tool to make yourself heard

EUCommission Mastodon post

‘Danger to Democracy’ patrick-breyer

815
1
submitted 11 months ago* (last edited 11 months ago) by gpstarman@lemmy.today to c/privacy@lemmy.ml
 
 

I am currently using Librewolf.

But Zen & floorp browser looks beautiful.

What do you suggest?

I personally like the looks of Zen.

I would also appreciate any tips to make Zen more secure than it already is.

Edit: consider this too

Negative post about zen: https://www.reddit.com/r/LibreWolf/comments/1ezumu7/comment/ljnjx2b/

Positive post about zen: https://www.reddit.com/r/browsers/comments/1fz7j9s/comment/lqzklza/

816
 
 

San Francisco billionaire Chris Larsen once again has wielded his wallet to keep city residents under the eye of all-seeing police surveillance.

The San Francisco Police Commission, the Board of Supervisors, and Mayor Daniel Lurie have signed off on Larsen’s $9.4 million gift of a new Real-Time Investigations Center. The plan involves moving the city’s existing police tech hub from the public Hall of Justice not to the city’s brand-new police headquarters but instead to a sublet in the Financial District building of Ripple Labs, Larsen’s crypto-transfer company. Although the city reportedly won’t be paying for the space, the lease reportedly cost Ripple $2.3 million and will last until December 2026.

The deal will also include a $7.25 million gift from the San Francisco Police Community Foundation that Larsen created. Police foundations are semi-public fundraising arms of police departments that allow them to buy technology and gear that the city will not give them money for.

817
 
 

cross-posted from: https://programming.dev/post/37262246

More than twenty countries have signed on to the nonbinding Pall Mall Process Code of Practice for States since it was launched in April 2025 by the United Kingdom (UK) and France. Its focus is to “tackle the challenges posed by the proliferation and irresponsible use of commercial cyber intrusion capabilities (CCICs).” CCICs encompass a broad array of tools, including spyware—a kind of malicious software that allows “unauthorized remote access to an internet-enabled target device” for surveillance and/or data extraction. One of the pillars of the Code of Practice for States is accountability, under which countries are encouraged to establish or apply national frameworks to regulate the “development, facilitation, purchase, transfer, and use of” spyware.

Establishing new domestic frameworks or even analyzing which existing national or international frameworks apply to spyware-related activity will take significant time, likely years. Meanwhile, new instances of spyware abuses against journalists and other human rights defenders continue. It is therefore not surprising that the Code of Practice for States also recommends measures to incentivize responsible activity, encourage the use of export control and licensing frameworks, and provide support for victims. It is on one such measure for victim support that this report focuses: “procedures for those claiming redress as a result of the irresponsible use of CCICs, including ensuring access to effective judicial or non-judicial remedies.” Specifically, this report explores how existing tort law relating to abnormally dangerous activities in the United States and the UK could provide a ground for bringing cases related to spyware abuses.

Tort law allows individuals to take accountability into their own hands, which is especially important when processes to enact binding obligations on actors involved in developing and selling spyware can take years and there is no guarantee they will be successful. However, tort law differs by country and, within the United States, even by state. This makes research difficult and, at a larger scale, inconsistent. Additionally, litigation is very resource intensive both in terms of money and time and governments are typically shielded from civil liability. It is simply not possible for every victim of a spyware abuse to bring a case against the actor(s) responsible. In that sense, it is not recommended to rely exclusively on tort law for accountability, but to use it as a supplementary measure while continuing to pursue parallel efforts at regulation.

With that framing, this report looks at the possibility of bringing cases under strict liability for abnormally dangerous activities in California and the UK. These two jurisdictions were chosen because of the similarities in their legal systems, the fact that civil cases have been brought in California against spyware developers, and since the UK is one of the countries that launched the Pall Mall Process. The author is not aware of any previous cases brought under this theory of liability with respect to spyware. Given the six-factor definition of abnormally dangerous activities in California, the fact that a court decides whether an activity qualifies, and recent developments regarding jurisdiction over foreign defendants and significant damages awards, it could be possible, although still difficult, to bring a case there under this theory related to spyware harms. The development of the same doctrine in the UK, however, cautions against attempting this novel argument there. For UK plaintiffs, more research is needed on alternative grounds under tort.

818
 
 

The United States has emerged as the largest investor in commercial spyware—a global industry that has enabled the covert surveillance of journalists, human rights defenders, politicians, diplomats, and others, posing grave threats to human rights and national security.

819
1
Payment privacy (lemmy.zip)
submitted 11 months ago* (last edited 11 months ago) by jobbies@lemmy.zip to c/privacy@lemmy.ml
 
 

What are the options for increased privacy in how you pay for things where you live?

Cash is the obvious answer, but what about buying stuff online?

UK here. Thinking of ditching cards/contactless for good old cash. No idea about online payments - not doing anything illegal so might persevere with cards for now. Zero experience with crypto.

820
 
 

Was forced to use WhatsApp a while ago and didn't want to give Facebook my phone number.

Got a pretty cheap prepaid SIM, forced myself through the KYC, used it for close to a year without issues. Now they want me to top it up with at least 15€ to avoid cancelation. Surely there's a cheaper way?

Edit: Looking to buy one in Germany

821
 
 

I really don’t get why so many people are turning this into a privacy versus anonymity debate when the real problem is censorship.

Yes, Signal needs a phone number to sign up, but replacing that with an email or username doesn’t make it anonymous. The real issue is that governments are blocking the registration SMS, so people can’t even sign up for the app in the first place.

Sure, there are workarounds, but most people aren’t going to jump through all those extra hoops just to use an app. If we want to spread privacy, how do we do that when Signal's phone number requirement is actively working against us?

Instead of arguing over privacy versus anonymity, shouldn’t we focus on making sure everyone can access Signal without issues? What do you think?

822
 
 

I love the profile feature from GrapheneOS. The idea of having different profiles with different settings (one for all Google apps, one for non Google...etc) is very nice. But Graphene only works on Pixel. I dont have a Pixel so I am trying to replicate this profile behavior on an S24 - what I currently use.

Why do I want to do this?

  • Every where is turning into police states with very heavy censorships. In my country (not US), we start to see bullshit stuff like a cop would stop you in the middle of the road and demand you to open the phone. If they see things they dont like (could be as random as an app name), you'll get arrested. It is not as severe as a forensic test of the phone, but more like a road stop where they check your phone instead of your license.

  • it is nice to organize stuff.

What does Samsung have?

  • Secure Folder
  • Work Profile - can be setup with Shelter

What do I want to achieve?

  • a dummy profile with the bare minimum to run Google Play updates and other basic stuff.

  • All my important data will be in Secure Folder or Work profile.

What I plan to do:

  • setup the phone using a blank Google account. No emails or syncs whatsoever.

  • put all critical data (personal Google, bank apps, private emails, cloud storages, files, media...etc) in the Secure Folder. Locked using my own pass, and do not use Samsung Cloud. No Samsung account.

  • put frequently used personal data in Work Profile. These are things like messengers (Telegram, Signal, Whatsapp....etc), contacts, emails (not the private one).

I'm still new to this so appreciate any input.

823
824
825
 
 

cross-posted from: https://lemmy.zip/post/48322335

The EU is planning to strike a deal with the US that would let the Department of Homeland Security and other agencies search European databases to identify people posing “a threat to US security,” according to a proposal published by the European Commission at the end of July.

view more: ‹ prev next ›