Privacy

50695 readers
633 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 6 years ago
MODERATORS
826
 
 

I found this to be an interesting watch in layering security/ privacy rather than throwing the hail mary at a VPN and expecting it to keep you anonymous.

https://youtu.be/1opKW6X88og

827
 
 

Hi. I know the most privacy-oriented (and best-working) phone OS is GrapheneOS, but I was wondering about other, less well-known ones, such as VollaOS (modified Android), Sailfish OS or Ubuntu Touch. Are they private? Do they work? Can I run Android applications on them (VollaOS and SailfishOS) without too much effort? I like using Linux, but I rely on many Android apps, such as navigation, mobile banking, the Garmin app, and many others. Do you have any experience with these operating systems?

828
 
 

cross-posted from: https://lemmy.ml/post/35909566

SMH @ activists using techno-fascist platforms for communications during an operation subject to state-actor level interference. I thought we recognised and acknowledged this problem 15-20 years ago already.

https://xcancel.com/CraigMurrayOrg/status/1965431513320927706

829
 
 

cross-posted from: https://discuss.tchncs.de/post/44544181

I read about Google's decision of not releasing the firmware source code going forward. Is it still the case? If it is, should one purchase any Pixel 8/9/10 series in hope of keeping it for a long time?

I am planning to purchase a new Pixel 9 (used ones are not an option unfortunately) during the Black Friday or something. It will be a substantial amount but I am hoping it will be justified with amortisation.

Sorry if this is a dumb question, but I cannot find a clear cut answer in the forums.

830
 
 

cross-posted from: https://programming.dev/post/37138319

Full Report: “Shadows of Control”.

Investigation Partners

The investigation exposes how Pakistani authorities have obtained technology from foreign companies, through a covert global supply chain of sophisticated surveillance and censorship tools, particularly the new firewall (the Web Monitoring System [WMS 2.0]) and a Lawful Intercept Management System (LIMS). The report documents how the WMS firewall has evolved over time, initially using technology supplied by Canadian company Sandvine (now AppLogic Networks). Following Sandvine’s divestment in 2023, new technology from China-based Geedge Networks, utilising hardware and software components supplied by Niagara Networks from the U.S. and Thales from France, were used to create a new version of the firewall. The Lawful Intercept Management System (LIMS) uses technology from the German company, Utimaco, through an Emirati company called Datafusion.

831
832
 
 

cross-posted from: https://lemmy.world/post/35648744

Under pressure from Mark Zuckerberg and Sheryl Sandberg to monetize WhatsApp, he pushed back as Facebook questioned the encryption he'd helped build and laid the groundwork to show targeted ads and facilitate commercial messaging. Acton also walked away from Facebook a year before his final tranche of stock grants vested. "It was like, okay, well, you want to do these things I don"t want to do," Acton says. "It's better if I get out of your way. And I did." It was perhaps the most expensive moral stand in history. Acton took a screenshot of the stock price on his way out the door—the decision cost him $850 million.

833
834
835
 
 

It's one of the VPN products I saw on fdroid, but I couldn't find payment info and it says it's experimental. Has anyone tried it and have a baseline on how it is compared to other VPNs?

Also do they have payment methods? I couldn't find them last time I looked and I'm worried it's a free VPN

836
 
 

Considering the aforementioned options for my next phone, but I've heard mixed reports on their compatibility with carriers in the US. Has anyone here gotten either to work reliably in the US and how good is the signal if it's missing some cellular bands? I'm currently on a T-Mobile MVNO, but am open to switching to whichever carrier that might work best.

837
 
 

In the past, if you broke or lost your phone, your Signal message history was gone. This has been a challenge for people whose most important conversations happen on Signal. Think family photos, sweet messages, important documents, or anything else you don’t want to lose forever. This explains why the most common feature request has been backups; a way for people to get Signal messages back even if their phone is lost or damaged.

After careful design and development, we are now starting to roll out secure backups, an opt-in feature. This first phase is available in the latest beta release for Android. This will let us further test this feature in a limited setting, before it rolls out to iOS and Desktop in the near future.

Here, we’ll outline the basics of secure backups and provide a high-level overview about how they work and how we built a system that allows you to recover your Signal conversations while maintaining the highest bar for privacy and security.

Secure Backups 101

Secure backups let you save an archive of your Signal conversations in a privacy-preserving form, refreshed every day; giving you the ability to restore your chats even if you lose access to your phone. Signal’s secure backups are opt-in and, of course, end-to-end encrypted. So if you don’t want to create a secure backup archive of your Signal messages and media, you never have to use the feature.

If you do decide to opt in to secure backups, you’ll be able to securely back up all of your text messages and the last 45 days’ worth of media for free.

If you want to back up your media history beyond 45 days, as well as your message history, we also offer a paid subscription plan for US$1.99 per month.

This is the first time we’ve offered a paid feature. The reason we’re doing this is simple: media requires a lot of storage, and storing and transferring large amounts of data is expensive. As a nonprofit that refuses to collect or sell your data, Signal needs to cover those costs differently than other tech organizations that offer similar products but support themselves by selling ads and monetizing data.

Anatomy of Secure Backups: Privacy First, Always

At Signal, our commitment to privacy informs which features we build and the ways that we build them.

Using the same zero-knowledge technology that enables Signal groups to work without revealing intimate metadata, backup archives are stored without a direct link to a specific backup payment or Signal user account.

At the core of secure backups is a 64-character recovery key that is generated on your device. This key is yours and yours alone; it is never shared with Signal’s servers. Your recovery key is the only way to “unlock” your backup when you need to restore access to your messages. Losing it means losing access to your backup permanently, and Signal cannot help you recover it. You can generate a new key if you choose. We recommend storing this key securely (writing it down in a notebook or a secure password manager, for example).

These choices are part and parcel of Signal’s guiding mission to collect as close to no data as possible, and to make sure that any information that is required to make Signal robust and usable cannot be tied back to the people who depend on Signal. This is why wherever there’s a choice between security and any other objective, we’ve prioritized security.

Enabling Secure Backups

If you want to opt in to secure backups, you can do so from your Signal Settings menu. For now, only people running the latest beta version of Signal on Android will be able to opt in. But soon, we’ll be rolling this feature out across all platforms.

Once you’ve enabled secure backups, your device will automatically create a fresh secure backup archive every day, replacing the previous day’s archive. Only you can decrypt your backup archive, which will allow you to restore your message database (excluding view-once messages and messages scheduled to disappear within the next 24 hours). Because your secure backup archive is refreshed daily, anything you deleted in the past 24 hours, or any messages set to disappear are removed from the latest daily secure backup archive, as you intended.

Backing up, moving forward

We’re excited to introduce secure backups, making sure you can retain access to your Signal messages even when your phone is lost or destroyed. But secure backups aren’t the end of the road.

The technology that underpins this initial version of secure backups will also serve as the foundation for more secure backup options in the near future. Our future plans include letting you save a secure backup archive to the location of your choosing, alongside features that let you transfer your encrypted message history between Android, iOS, and Desktop devices.

Secure backups are available in today’s Android beta release. A full public release, along with iOS and Desktop support, is coming soon.

838
 
 

Some of the application processes are super invasive Some are hosted in hostile jurisdictions Some are ran by well meaning but incompetent admins Some log everything

Are there any that take privacy and security seriously?

839
 
 

base.dns.mullvad.net is my goto for devices that I don't manage often, like for family, but the last few days it will randomly just not respond for a few minutes and then suddenly be fine. I haven't seen any news about it and their server status is just for their VPNs. Anyone else noticing this or have any info?

840
 
 

Any one know a good custom rom for Fairphones? Is /e/OS a good option?

Are there downsides that arent realy known?

841
 
 

As Signal get your phone number. Can we considerate this application as private ? What's your thoughts about it ? I'm also using SimpleX, ElementX, Threema, but not much people using it...

Cheers

842
0
submitted 11 months ago* (last edited 11 months ago) by tad_lispy@europe.pub to c/privacy@lemmy.ml
 
 

The article alleges that Matrix:

  • has links to Israeli intelligence.
  • sends a lot of sensitive data to matrix.org servers, even when Synapse is self-hosted.

Is this information accurate?

To be clear, I'm not saying Matrix is bad. I'm still using it. I just want to know more about it and who's running the show, and hear other people's opinions and arguments. Thanks for all the insightful comments.

843
 
 

What do you recommend to use while taking into account chat control? I was thinking about self-hosting XMPP. I'd love to hear your advice

844
 
 

I’ve been seeing this more and more in comments, and it’s got me wondering just how big this issue really is. A lot of people feel trapped in apps like Discord, WhatsApp, and Instagram, but can’t get their friends to leave.

It’s really annoying when you suggest trying something new, whether it’s a different app or just not using these platforms so much but sometimes it can feel like no one wants to go first.

So I’m curious, what apps do you feel most trapped in? And have you tried convincing your friends to leave them? What happened? Is it an issue for you, or are you just going along with the flow?

Looking forward to hearing if this is as common as it feels!

845
1
The Pager (mander.xyz)
submitted 1 year ago* (last edited 1 year ago) by Sal@mander.xyz to c/privacy@lemmy.ml
 
 

I decided to purchase a one-way pager, a programmer, and a paging subscription to satisfy my curiosity about pagers.

In this post, I am explaining my thought process and describing some of what I have learned about how pagers work. This is especially relevant to the national paging network in the Netherlands, but hopefully others also find it interesting.

The cellular network

Cellphones give us the ability to reach others and to remain reachable regardless of our location if within a network's coverage. The network infrastructure is continuously evolving in ways that make it more efficient, secure, and reliable.

One way that the network becomes more efficient is by improving its device tracking abilities to reduce the amount of radio broadcasting resources needed to deliver data to the recipient. Security and reliability are improved by having two-way communication between the network and devices such that devices can be authenticated, data correctly encrypted, and message delivery confirmed.

A participant within this network must accept one or more of their device's unique identifiers (at the very least the IMSI, often also the IMEI) is associated with an approximate location.

Since I do not want to accept these terms, I do not carry a phone with a SIM card on me.

A burner phone and an emergency pre-paid SIM card gives me the opportunity to connect to the network in the case that I need to contact someone immediately.

However, this does not give the opportunity to others to reach me in the case that they need me or worry about me. This is not common, but there have been cases in which being reachable would have been good.

LoRa / Meshtastic

Last year I learned about LoRa radios and the Meshtastic network implementation. These devices allow one to send encrypted messages directly between devices. The range is decent, especially if there is a line-of-sight between devices. With Meshtastic it is possible to create a network of nodes that route messages, and to make use of tunnels over the internet to connect nodes that are very far apart.

So far, my favorite use-cases for Meshtastic are communicating with my partner as I approach an area to meet them, communication during festivals/events, and when travelling in a small town or camping.

It is a great tool in some contexts, but I cannot be reliably reached with it.

The Pager

I am currently living in the Netherlands and so what I say is most relevant to the Dutch paging network 'KPN Nationaal 3'. Messages are broadcast using POCSAG 1200 at 172.450 MHz. I know that the situation with paging networks vary across the world, with paging networks being no longer available in many countries, but I don't know the details. It may be that the system here is rather special and unique.

The paging network is considered a legacy broadcasting system. Messages to the network are broadcast by transmitters distributed across the full coverage range. The message that is broadcast contains the RIC (Receiver Identify Code) and the message in plain text.

Anyone with an SDR (Software Defined Radio) device can decode and log all of the unencrypted messages. Here is an example using SDRConnect + multimon-ng:

Using a programming interface, a user can select the RIC codes that they want their network-tuned pager to be responsive to. The pager will beep and display on the screen messages sent to that RIC. In my case, the seller of the pager assigned a new RIC from their pool to me and programmed the pager to listen to it.

A pager does not have a built-in transmitter, and so it does not reveal any information to the network.

A subscription to the paging network works the following way:

  • You get assigned your own 'RIC', which is publicly broadcast with every message
  • You get assigned a private number (0665xxxxxx)
  • While your subscription is active, you send an SMS or an e-mail to a specific address with your private number + message, and the network provider will broadcast it with the RIC as the recipient.

Then, anyone who knows your private number is able to reach a pager listening to your RIC. The public RIC is not enough information to request a message to be sent to you.

Registering to the network has a monthly cost (typical current pricing of 8 € - 20 €) depending on whether you want to be able to recieve text messages, numeric messages, or only make the pager beep. Your identity and banking information are known to the network provider. I was able to register as an individual without needing to provide any company information. I had to fill-in a short form and send it over e-mail with a photo of an ID to register.

So:

  • The network provider knows your identity
  • The service has a monthly cost
  • The unencrypted message content, when they are sent, and the recipient's RIC are public information
  • The network does not confirm delivery
  • Inefficient for the network (all transmitters broadcast every message)
  • Being a legacy system, the network may not remain alive for too long

But:

  • It is possible to reach you at all times without needing to broadcast your location to the network

The pager is a technology that I looked at early on when I started thinking about privacy and I quickly discarded the idea. Giving my identity to a network provider and broadcasting unencrypted messages publicly did not seem logical to me.

Today, I see the value of having a receive-only device that is supported by a network with national coverage. A paging message would contain only enough information for me to know how urgently I need to find a way to communicate - whether I need to activate the burner phone immediately, or whether I can spend some time to go find another way to communicate.

For me, it was a pleasant surprise to discover that this legacy system fills the specific gap of reachability without tracking.

I also recently became aware of the existence of paging networks that rely on volunteer HAM radio operators (like DAPNET), and would like to explore these systems in the future.

846
 
 

I'm planning on flashing LineageOS on my phone to debloat and to degoogle, and additionally to increase overall privacy but apparently from what I've heard here that it's not private enough or even at all?

I know about it being less secure because of the opened bootloader and the higher chances of you rooting to achieve what you want with a degoogled phone, but beyond that (especially privacy-wise) I don't know anything.

I've seen a video on how to degoogle it further, but surely it isn't all I need to do.

I need some education.


Unfortunately my phone is so obscure that it isn't supported by literally anything, but fortunately there's an unofficial port of LineageOS I found on Telegram, and that's the one I'll be using. So if you're thinking of suggesting another custom ROM, you're out of luck. Also you can't make me buy a Pixel - that thing ain't supported in my country (5G and others) and it's hella expensive as well.

847
1
submitted 1 year ago* (last edited 1 year ago) by trilobite@lemmy.ml to c/privacy@lemmy.ml
 
 

I've been working in the last few years of getting rid of big tech services. PayPal and Amazon are left. I've been questioning the need for PayPal in a world of virtual credit cards. My main reason for using it was security of purchase but I feel this need is no longer there. BTW, equivalent EU service to PayPal that is equally well accepted? Feels like this one may be more difficult to satisfy.

848
 
 

First of all, to anyone downvoting my Comments about /e/ being a piece of shit, because...

  • they advertise themselves as degoogled, but instead let you connect to Google/Microsoft/etc services

  • replace all the propriatery not at all Secure Services from Google, with.... Drumroll please.... Propriatery and not at all Secure Services from themselves and actively encourage it.

  • They are For-profit

  • and being MORE out of date then even Fairphones stock roms.

... I told you so. Dm your Instance admin, pay them to send the DB entries of your Downvotes on a Thumb drive (or anything else from SSD to 3.5 inchHDD, depending on your preferences), and shove it up your rectum.

But a TL;DR:

/E/ is not Private. They just switch one bad comany to another one.

849
850
 
 

It's inevitable....you people are going to have your Android given the iPhone treatment and you are going to LIKE IT! 🫨

Seriously though, alternatives? Grapheneos Mastodon page is a dumpster fire at times. One minute they are as ferocious as lions claiming they will never surrender.....the next they are lamenting that Google won't feed them and they need a new hardware supplier 🫩

CalyxOS folded quicker than a wet paper bag at a simple management shift! GrapheneOS and it's days are numbered

So what's the real option going forward?

view more: ‹ prev next ›