Privacy

50695 readers
633 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 6 years ago
MODERATORS
851
 
 

There are plenty of great reasons to act privately, but I admit, it's also a hobby for me.


(it's also a good answer if there was a specific reason)

852
 
 

Two former Harvard students are launching a pair of “always-on” AI-powered smart glasses that listen to, record, and transcribe every conversation and then display relevant information to the wearer in real time. 

“Our goal is to make glasses that make you super intelligent the moment you put them on,” said AnhPhu Nguyen, co-founder of Halo, a startup that’s developing the technology. 

Or, as his co-founder Caine Ardayfio put it, the glasses “give you infinite memory.” 

“The AI listens to every conversation you have and uses that knowledge to tell you what to say … kinda like IRL Cluely,” Ardayfio told TechCrunch, referring to the startup that claims to help users “cheat” on everything from job interviews to school exams.

853
854
 
 

Is this thing as sketchy as it seems? The organization seems to be positioning itself as a way to verify you're a real live human online, something about blockchain, doesn't store your data, etc. Does anyone know more about it? I'm interested in how they make money and/or who is funding this project. They say the right things but seem to be hiding who is supporting them.

855
 
 

I'm in a bit of a bind. I have to get TSA PreCheck, but I really don't want to give up my biometric data to the government. I've read that TSA PreCheck requires my fingerprints and possibly my photo (it's unclear). Interesting, though, is that when you're enrolled in PreCheck you do not get fingerprinted when passing through the airport.

So, I plan to fill in my fingerprints with superglue when I sign up for PreCheck. Weak fingerprints are a condition that affect a lot of people -- construction and farm workers, chemo patients, or some people just have it genetically -- so I don't think it will be too weird if my fingerprints don't show up well in the scan. From what I've read (FlyerTalk, Washington Post) you can still get PreCheck even if you have weak fingerprints. And, since they don't check my fingerprints at the airport, I'm not worried about ever having to match this scan.

My face is effectively a lost cause at this point, so I'm not gonna sweat that one.

My questions.

  • Is there any reason my fingerprint plan won't work?
  • The PreCheck sign-up process is run by private companies (Idemia, Telos, Clear) and I can choose which one to use. I am going to rule out Clear. Is there any advantage between using Idemia or Telos?
  • Is there anything else I should know before signing up?

EDIT: Wow, these replies are so useless, I had to check to make sure I wasn't on reddit!

856
 
 

What is a good comeback or argument towards people who say "But I have nothing to hide" when you try to information them that privacy is important?

857
 
 

So we know the UK, France, Sweden and Australia all have “pondered out loud” about getting platforms like Signal to allow backdoors into encrypted calls and messages.

This creates a sense of safety about these platforms being secure, because governments want to come after them.

Here’s a tinfoil hat take: Five Eyes is significantly reducing inter cooperation. The non-fascist parts of the alliance don’t want to share with the obvious authoritarian, but the authoritarian one used to share the fruits of their established backdoors with them, and now they don’t.

Note that the US isn’t asking signal for a backdoor. Why? Back in 2015-2016 (last years of Obama), Apple had a loud and visible feud with the FBI. Since the authoritarian came to power, this all disappeared from the media. Interestingly, 10 years have gone by since that moment, every single aspect of our lives has become more surveilled, and somehow the US govt has stopped trying to get into phones? *While the CEO is making hand deliveries of 24 karat gold bars to the Oval Office?

TLDR; I think a safe assumption that they are in our devices by now. Fundamentally people misunderstand encryption. Encryption is only as strong as the weakest link. If your signal chats are unencrypted for consumption on your device, then that’s when the unencrypted content can be captured.

For the longest time, Apple stored your iCloud backups encrypted. Looked good in marketing materials, until they casually admitted the decryption key is stored in the same cloud.

Combine this with ICE capturing citizens without due process. If you have a vanilla smart device, you’re doing the surveillance for them. /tinfoilhat

~this is OG content created by me, a Lemmy user. Please don’t go too .ml on me in the comments.~

858
859
 
 

In the past, I've heard about how Google can keep records of all your Google phone's past locations and text messages.

What about RCS messages which supposedly are encrypted from Android to Android? I know that it's possible that they secretly keep a log behind the scenes, but as far as the regular consumer knows is there any record being kept with regard to the contents of these RCS messages?

860
 
 

Hopefully ADP will be restored soon

861
 
 

This was bound to happen, and it’s ridiculous

862
 
 

Not particularly pleased about the decision when OpenVPN is the most supported protocol.

Meanwhile their competitor IVPN even does IPsec.

863
 
 

IceDrive lost thousands of my files without any notification. Their support escalated my ticket, then ghosted me for 2 weeks before closing it. I'm sharing a script to check if your files are actually backed up: https://github.com/rupumped/NicksAPPS/blob/main/Python/IceDriveVerification.py. Note that it requires argparse.

Usage: python IceDriveVerification.py C:\Documents C:\Photos C:\Projects --backup-root I:\

864
865
 
 

I only plan to use it for messaging in a couple of sports teams and event invitations.

I'm willing to take a lot of measures as long as they don't get the account blocked - no phone app, dedicated virtual machine+VPN to isolate from other internet activity, purchased fake phone number in signup, adding fake interests and life details. However, I won't provide any real ID/photos, are these needed for signup?

866
 
 
867
868
 
 

Main point of this post: Joplin+Syncthing initial setup can be a pain. First set up sync folder (the target folder for Joplin File System) on Syncthing. Then take main device offline (no sync). Then point Joplin towards target File System location on all devices, then enable encryption with same Master Pass on all devices. Finally write a test note on main device (where you might have other old notes imported from other services), then hit sync, then fire up Syncthing on main device to broadcast newest test file. Hit sync on all devices, disable fail-safe temporarily for first setup if prompted. If test is successful, import any old notes to main device and enjoy life as a certified hacker.

Background: So I am technologically handicapped, meaning the extent of my knowledge is limited to reading blogs or articles, with no coding experience. I have used Syncthing for a long time for music and ebooks syncing, and for a short period for Obsidian, but it always bothered me that Obsidian isn't FOSS or encrypted even though it's cool. Only recently discovered Joplin has encryption capabilities so I decided to dive in.

But first, I had to make the process harder for myself so I took out my dusty old 10 year old Dell laptop and installed Ubuntu (to support touchscreen), my first ever Linux experience. With the help of Gemini (dumb, I know) I got Syncthing and Joplin working on it. After 2 days of struggling to get the Sync to work without conflicts, I finally did it WOOHOO. Totally a hacker, that's me.

869
 
 

Just come across this. Haven't dug too deep but sounds like an interesting opportunity. I think it can only succeed if it is fully compliant with current systems. Seems to only be mobile clients. No desktop? Are big tech going to permit this to grow? It would shut down a data mining opportunity ...

870
 
 

I usually don’t try using coupons since many of the codes shown on websites don’t work, but I feel bad for not trying hard or smart enough. I’ve heard good things about Retailmenot, I haven’t tried it yet but I wondering if there are privacy trade-offs.

871
 
 

Ecosia, the tree-planting search engine from Berlin, and Qwant, France's privacy-focused search provider, announced a joint venture in November 2024 to develop their own European search index[^5][^6]. The partnership aims to reduce their dependence on Microsoft's Bing APIs, which both companies currently rely on for search results[^6].

The new venture, called European Search Perspective (EUP), is structured as a 50-50 ownership split between Ecosia and Qwant[^6]. Qwant's engineering team and existing search index development will transfer to EUP, with Qwant CEO Olivier Abecassis leading the joint venture[^6].

"The door is open and we are ready to talk to anyone," said Abecassis, while noting they want to "move as fast as possible" with their existing shareholders' support[^6]. The index will begin serving France-based search traffic for both engines by Q1 2025, expanding to cover "a significant portion" of German traffic by end of 2025[^6].

Rising API costs are a key motivator, following Microsoft's massive price hike for Bing's search APIs in 2023[^6]. However, neither company plans to completely stop using Bing or Google, instead aiming to diversify their technical foundation as generative AI takes a more central role in search[^6].

[^6]: TechCrunch - Ecosia and Qwant, two European search engines, join forces on an index to shrink reliance on Big Tech

872
873
 
 

I would spend the time to write this in my usual lovely article style, but I'm too upset to do that right now. To put it bluntly: email and phone numbers suck. They both need to die.

Emails

Security

Email, like many other protocols, was not originally designed with privacy or security in mind. You can get "less bad" email providers such as Proton Mail or Tuta Mail, but those only have basic privacy when contacting other emails using the same provider.

Email is one of many protocols designed in the early days of the internet before privacy and security were considered. Since then, there have been Band-Aid solutions added to email to give it some semblance of security, but it is still fundamentally insecure. It lacks many of the features that modern communication protocols like the Signal Protocol and SimpleX Chat Protocol have.

Aliases

One major flaw with emails is that people commonly use the same email for everything. That not only becomes a unique identifier, but it makes it nearly impossible to fight spam and puts all your accounts at risk if your email is breached.

A solution was created to fix this problem in the form of email aliasing services such as addy.io or SimpleLogin. These services allow you to create a large number of random email addresses that all forward to your real email address. This allows you to avoid using a unique identifier for every website, and block spam by simply disabling the email alias.

Email aliasing is great... when it's accepted. Many services have begun blocking email aliases because aliasing eliminates a unique identifier. People (allegedly) use aliasing to create multiple accounts to abuse free services.

Overuse

Email is required to sign up on almost every website. As mentioned previously, it has many security flaws and email aliasing only partially helps. Websites abuse the fact that emails are supposed to be a unique identifier, so they use it for things like multi-factor authentication or login alerts. Neither of those are what email was designed for, and you only end up putting your account at risk by using it compared to authenticator apps like Aegis Auth or Ente Auth.

Email is also used to sign up for news letters, receive shipping alerts, send sensitive information for jobs and job applications, contacting most businesses, even logging into some computers. All of these pose a risk if you don't use email aliasing or if your email is breached. What upsets me most is seeing open source software requiring email addresses, like GitLab, Codeberg, many Lemmy instances, etc. These shouldn't request anything past a username and a password.

Email overuse has gotten so bad that many disposable email services like Maildrop have been created in order to generate throwaway emails to get past authwall screens. These should never be used for real accounts because anyone can access them and, as I mentioned before, most websites will allow you to login only by verifying your email.

Anonymous Email

Email providers are being hit with mass sign-ups because of how often email is used. Because of this, many email providers block you from signing up if you are connected to a VPN or Tor. This means that in order to create a single email address to do almost anything across the internet, you must give away your IP address to the email provider first, effectively deanonymizing yourself. The internet was supposed to be built to be free, but giving away your personal information to access content doesn't sound very free to me.

Kill Emails

Emails are outdated, overused, and not private. They were never designed to be (ab)used the way they are right now. Even something as simple as setting up Git or GnuPG asks for your email, or signing up for a local event. This needs to stop. Using fake emails doesn't solve the underlying problem.

Phone Numbers

Gratis

If you thought free emails were bad, imagine paying to have your privacy disrespected. A single phone number will cost you a monthly subscription, even if you only need to receive a single text. Prepaid SIM cards are becoming a dying art, especially in the United States. Most mobile phone operators will make you buy and activate an eSIM, which requires an egregious amount of personal information to activate (including email). Most payphones have been abolished too, meaning you can hardly pay by the minute anymore.

Security

Phone numbers don't even pretend to be private or secure. It's sent unencrypted to anyone with a $15 antenna, and intercepted by almost every government in the world. Salt typhoon showed just how abysmal cellular security really is. RCS and iMessage are slight steps up in terms of privacy (providing at least some encryption), but it barely provides any protection.

Phone numbers in this respect are even worse than email. SS7 attacks can trivially intercept communications by anyone without any user interaction. That is an easy way to grab multi-factor authentication codes sent via SMS. Despite all of these known issues, people still insist on using phone numbers for almost everything.

Aliases

While not free, you can use services such as MySudo to create phone number aliases. These aliases are really just real phone numbers, all of which you own. Unfortunately, these phone numbers are VoIP numbers, which many services block.

Overuse

Like emails, phone numbers are used in a lot of applications. Because they cost money, they are a better unique identifier than emails, since people are less likely to own multiple. Phone numbers may be required to create accounts, apply for jobs, do almost anything government related, and much more. All of this is done unencrypted and intercepted.

My favorite: in many places, you have to use a phone to contact non-emergency services. The homeless and other people who can't afford phone numbers are unable to report crimes since there are no pay phones. Even visiting the police station in person will get you turned away and told that you must call (speaking from experience) no matter how much you try to convince them.

Thankfully, many times when a phone number is asked for you can put in a fake phone number without risk. For many applications, throwaway number services will also work. Applying for jobs, a lot of the time you will be asked for your phone number. If you simply inform them that you do not have a phone number, most will accept that or (at worst) give you a funny look. I would prefer email when applying for jobs anyways since you aren't sprung with a sudden call.

Anonymous Phone Numbers

The only way to get an anonymous phone number (without risking buying second hand) is to buy a burner phone with cash, a prepaid (e)SIM, and use as much fake information as possible (even the area code). This will easily run you $45+, and requires a subscription to keep using it. Beware that the phone you use it with may disrespect your privacy in other ways.

Kill Phone Numbers

Phone numbers are one of the least private and least secure methods of communication. It is under active mass surveillance, and costs way too much money. It's good to see younger generations moving away from phone numbers towards third party services (no matter how bad they are), because that means that there is hope of killing phone numbers once and for all.

Kill Both

Anyone can create an email. Anyone can buy a phone number. It should not be used as a unique identifier, and certainly should not be used for authentication purposes. We need to stop overusing insecure, nonprivate communications, and start normalizing using Signal usernames or SimpleX Chat addresses for general use. Currently, if you stick only those on your resume for your contact information, you will most likely not receive a message back. That needs to stop. Phone numbers and emails can get leaked and cause endless spam/scams compared to other forms of communication. There is no reason to keep using either option when so many better options are available.

Try to create a full software stack without using services that request your email or phone number, and you will begin to see just how bad the problem has gotten. Some services like Mullvad VPN and KYCnot.me have begun requiring no personal information at all to create an account, not even a password. They randomly generate account numbers to be used to login. I want to see more of that instead of...

spoiler

Please enter your first name.

  • Must be at least 3 characters.

Please enter your last name.

  • Must be at least 3 characters.

Please enter your date of birth.

  • You must be at least 13 years old.
  • The birthday we let you enter (01/01/1900) seems invalid.

Please enter your username.

  • That username is taken
  • Some characters are not allowed

Please enter a display name.

  • Some characters are not allowed, but the requirements are different from anything else.

Please enter your email.

Please enter your phone number.

  • We don't accept VoIP numbers.
  • We've also sent a code to +1 (555) 867-5309, because why not.

Please enter your password. We don't know what passkeys are.

  • Password must be longer
  • Password is too long. We don't know what hashing is.
  • Password must not contain these characters. We still don't know what hashing is.
  • Password must contain these characters. We don't know what a passphrase is.

Please enter your password again.

  • Passwords do not match.

  • [ ] I agree to the Terms of Service.

  • [ ] I agree to the Privacy Policy.

  • [ ] I agree that the information I entered is correct.

Sorry, you've been blocked. Your IP address has been flagged for abuse.

Please enable JavaScript to continue.

Something went wrong, and we couldn't create your account. Please start over.

Your account has been flagged as spam.

Please enable email or SMS 2FA before activating 2FA through an app.

Please verify your email or phone number every time you log in.

New Email: We noticed a new login. What's a VPN? Doesn't everyone store browser cookies forever?

All email notifications are enabled by default.

Please verify your email and phone number before deleting your account.

Your account information you requested to download will be emailed to you within 3-5 business days as if a human needs to approve it.

We've reset your password for no reason at all. Please verify your email or phone number to reset your password.

Lost access to your email or phone number? Tough luck. Please contact support.

Need to contact support? Email us or call us.

This call may (will) be monitored or (and) recorded for "quality and assurance purposes".

"Can you please verify your phone number?" ...you mean the phone number I'm calling you from?

874
 
 

Lol, saying you are "beginning a process designed to delete your data" is a very different thing to actually deleting your data.

875
 
 

Long story short here: I tried making Linux my main OS on my PC. I had it dual booted with Win 11 on a separate SSD. Win 11 was going to be solely for work purposes since it was crucial.

However I noticed that I had begun to migrate slowly back to Win 11 because I'm a gamer and Linux just doesn't get along with my graphics card, so games are almost impossible to play well.

I've succumbed to the idea that my PC will just solely run on Win 11. (I do use Linux on a laptop tho). So I got some debloat tools to shut off most of Microsoft's annoying spy shit and manually uninstalled the rest like Cortana. I also have pihole running on my raspi5 so my PC is connected to that, plus I use ProtonVPN. I use Firefox with plugins like ublock, privacy badger, etc.

I want to try to make Windows as private and away from Microsoft's prying eyes as much as possible. Got any other recommendations?

view more: ‹ prev next ›