Privacy

50695 readers
622 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 6 years ago
MODERATORS
901
 
 

cross-posted from: https://sh.itjust.works/post/42943610

Taken from the readme of the app on github:

The current release provides only basic functionality, with several key features to be introduced in future versions, including:

App and device verification based on Google Play Integrity API and Apple App Attestation

Additional issuance methods beyond the currently implemented eID based method.

These planned features align with the requirements and methods described in the Age Verification Profile.

There is an issue opened to remove this as it's basically telling us that to verify our age in the EU an American corporation has the last word, making it not only a privacy nightmare but a de-facto monopoly on the phone market that will leave out of the verification checks even the fairphone (european) with /e/os.

902
 
 

I need to start making plans for when I am gone, much sooner than I thought, and I realized our finances are pretty opaque to my spouse. Our bank account is shared, but there are other sites that only I have access to.

The easiest solution would be to physically write down logins and what needs done, put it in an envelope, and tell my family where that envelope is. I'm not thrilled about that, because I would have to shred and rewrite it every time I update a password or a URL changes, and it'd be vulnerable to nosy guests.

Putting it in a shared Google Doc would be easiest for everyone. But then Google has that data. Even supposing I trust a cloud SaaS provider not to misuse the data (which is a big 'if') I do not trust them to never have a data breach.

Self-hosting seems like the next step, except I expect my home server to be the first thing to collapse once I'm gone. Filing login info with an estate attorney would still require frequent updates. Putting a document on a flash drive risks data loss, but is what I'm leaning towards.

Is there a solution I'm missing?

903
0
submitted 1 year ago* (last edited 1 year ago) by hansolo@lemmy.today to c/privacy@lemmy.ml
 
 

I love Charger8232's idea of a Privacy Flag. However, I don't love the design they proposed. In their post, I explain my disagreements.

As a form of vexillographical discussion, I would like to propose another design as the flag under which we anonymously toil in secret (I wish).

First off, nods to Charger8232's design - 1400x900 dimensions, and use of EU's Dark Power Blue (#003399) color. Love it.

Where we differ:

Designs

A shield, representing how we must actively guard our privacy. A lock, obviously, to show we want security with our privacy, and a dove showing that we just want to be left the F alone and peacefully not be subject to a mass surveillance state. We're not trying to be sketchy or do illegal stuff, we just want to be peacefully left the F alone.

Colors

Again, same use of Dark Power Blue, representing freedom and a nod to the GDPR. White representing peace. Black representing how I don't want people to see me. Color of field: Redacted.

Extras

Stripes to make it a bit more visually interesting. A lack of EXIF and meta data as the subtle fait accompli.

The color scheme is similar to that of Estonia. While Estonia is a leader in the EU's digital governance space, this is unintentional. As much as I liked Espresso Macchiato in EuroVision this year, there's no direct nod to Estonia.

I didn't want to just say "uh, I don't like it" and complain without doing something. So here you go.

904
 
 

Privacy Flag

About

It has always bothered me that privacy has no unified symbol. Every community has their own take on how privacy should be visualized. I want to unify the privacy community across the internet. It is my belief that, with a universal symbol for privacy, we will grow stronger. We will have a symbol to represent us. We will have a flag to fly.

Icon

The icon is a clipart created by librarian Gordon Dylan Johnson which can be found here. The size of the icon is large enough to still fit if the flag is cropped to a square/circular aspect ratio.

Dimensions

The size of the flag is 140 by 90 centimeters. These dimensions are chosen because of the dimensions of a Tor Browser window (1400x900 pixels).

Colors

The color blue (Azure) was chosen because it symbolizes security, stability, and reliability. The exact shade of blue used is the same azure color used by the flag of Europe, because of GDPR.

Design

This flag follows the "Principals of design" for vexillography.

Use it!

Use this flag for group chats, communities, profiles, stickers, patches, articles, wallpapers, real flags, anything you want to! Spread it around so it becomes a global icon for privacy. Even put it on the Wikipedia page for privacy if you can!

905
 
 

Link to the list of extensions at the end of the article

906
0
submitted 1 year ago* (last edited 1 year ago) by moe93@lemmy.dbzer0.com to c/privacy@lemmy.ml
 
 

Considering the current intrusive cyber climate, what are the best ways to preserve privacy?

For example, I have been exclusively using a VPN connection network-wide at home setup on OpenWrt, which in turn has a PiHole as its DNS, with the PiHole using Unbound and NextDNS (redundant I know, but I use it to encrypt my requests more than anything else).

I also have Wireguard setup so I can VPN all my devices to my network while I am on the road (also have a NextDNS profile installed. Yes I know, it’s redundant).

I also basically have all my “smart” devices (TV, lightbulbs, air purifier, etc…) at home cutoff from the internet using OpenWrt’s firewall to prevent them from calling home.

I rotate web browsers frequently to try and attempt avoiding getting fingerprinted, not sure how useful that is.

I switched email providers to mailbox.org because f*** Google and Microsoft.

I also am hosting my own cloud drive on Nextcloud to avoid using services like GDrive, OneDrive, Dropbox, etc…

I own Apple devices which aren’t the best for privacy but migrating from a whole ecosystem that I have been embedded in for MANY years is easier said than done. Hopefully in the future that’s my next move.

I feel like there is a lot more I can do but I am not sure what else. I would appreciate any and all suggestions ya’ll might have.

EDIT: I’m not being too extreme with my caution as some comments are making it sound to be. I am a very average person who is privacy conscious yet realize being cut off from the internet and society is not realistic. I guess my threat model is your basic “day-to-day it’s non of your business who am I online or what I do, please don’t profile/fingerprint me, I am just a passerby” kinda threat model.

907
 
 

cross-posted from: https://lemmy.world/post/28567151

A few cards that I read about.

RBC virtual card, seems to do what I need. But it's available for business use only.

Robinhood Gold Card, only in the states.

Wise, not sure if exact limits are available.

Context: I recently purchased a hotel stay where a merchant charged my card for the advertised price on their website, the amount was then refunded. Then another merchant charged my card a higher amount (a few hundred) all in a few seconds of the original transaction.

Edit: I found Wise provides limits on their virtual cards. I have yet to test how this works and if the transaction is declined for Insufficient funds, does anyone have experience with this?

908
909
910
 
 

log into multiple google account in thunderbird

What information I might leak to google server if I issue log into multiple google account in thunderbird? ip of course but what else might be collected? It would be really great if someone could clarify whether the information below will be send to google when using their email service even through Thunderbird

  • device name
  • device model
  • ...

My main concern is that google will be able to know that I have logged into the same device with different accounts.

In addition, I plan to use VPN when using one google account but not the others. This can be achieved through profiling, but is there an option that I can simply manage all the accounts in one app but without my ip address being collected by several specific email service provider corresponding to several specific email?

thanks a lot!

911
912
 
 

Both auto-forwarding and auto-reply are paid features, which makes cancelling & switching much more difficult. Gmail is a breeze comparatively. I highly recommend against using their addresses (e.g. protonmail.com, proton.me, pm.me)

Email forwarding is available for everyone with a paid Proton Mail plan.

(source)

913
 
 

Looking for Privacy-Oriented Open-Source Android Browsers

I'm looking for a privacy-focused, open-source Android browser. Here are some options I've found:

  • IronFox
    • recommended by LibreWolf
  • Fennec
    • no repo
  • Waterfox
  • Vanadium
  • iceraven
    • most stars
    • https://lemmy.world/u/Thetimefarm@lemm.ee - As far as I know ironfox supports any extensions normal firefox mobile does, but neither give you access to the full full extensions store. Iceraven is the only mobile browser I know of that lets you use all the extensions that you can on desktop firefox.
  • bromite
    • no longer maintained
    • Bromite has a fingerprint randomization and Vanadium doesn't. But Vanadium has better security if you use Graphene. So yeah, for privacy Bromite might be better
  • cromite
    • Bromite fork
  • brave
    • controversial
  • duckduckgo

Is there any other browser out there that fits this criteria? Is there an even better choice? I’m particularly interested in ones that focus on privacy.


UPDATE: iceraven vs ironfox

https://www.reddit.com/r/browsers/comments/1lkagoz/iceraven_vs_ironfox_firefox_fork_for_android/

I use both! Ironfox is hardened to improve security as best as possible for a gecko based android browser and focuses mainly on preventing fingerprinting, similar to mullvad's browser. Because of these extra privacy protections some websites will be more prone to break or render goofy on ironfox, but luckily I haven't ran into that issue yet.

Iceraven just strips out mozilla's tracking and adds tons of extra extensions and customizability, but doesn't include the extra security hardening or fingerprint protection like ironfox does.

Both devs are very good at keeping up with releases imo.

So if you really need airtight fingerprint prevention, or want extra security hardening, I'd go with ironfox. Also just a note, even with ironfox's hardening, it's still not as secure as a chromium based browser. Some people have very strong opinions on the gecko vs chromium security debate so I'm just pointing that out as a disclaimer. If you're gonna be treading into websites where there's a significant risk of picking up something nefarious in the background, stick with a chromium based browser for those sites as a precaution. Just my 2 cents.


EDIT: in terms of popularity, privacy and functionality I guess the best choices are iceraven (based on firefox) as it has most stars on github and cromite (based on chromium) as brave is controversial


Solved Questions

I know that Brave is a bit controversial, but If Brave does something behind our backs wouldn’t we be able to know it since all the source code is out there? If it has some features we don’t like can’t we simply modify the source code?

@slackness

re: open source In theory: yes. In practice: maybe. It’ll probably eventually be caught by some researcher but unlike popular belief all open source code bases are not constantly being audited by the community. A random person can’t just read Brave source code for all platforms and accurately gauge if they’re doing something nefarious. It is very easy to hide stuff in code or misuse a protocol for evil purposes, etc.

You can modify the source code but as evident by the fact that there’s no Brave fork with crypto removed (there was one but their branding was too similar to Brave’s so they got sued), it’s not an easy feat to maintain that.


few questions

  • What is the difference between IronFox, Fennec, Waterfox and iceraven?

As far as I know ironfox supports any extensions normal firefox mobile does, but neither give you access to the full full extensions store. Iceraven is the only mobile browser I know of that lets you use all the extensions that you can on desktop firefox.

914
 
 

“To facilitate this vetting, all applicants for F, M and J non-immigrant visas will be asked to adjust the privacy settings on all their social media profiles to ‘public’”, the official said. “The enhanced social media vetting will ensure we are properly screening every single person attempting to visit our country.”

915
 
 

Meta devised an ingenious system (“localhost tracking”) that bypassed Android’s sandbox protections to identify you while browsing on your mobile phone — even if you used a VPN, the browser’s incognito mode, and refused or deleted cookies in every session.

This is the process through which Meta (Facebook/Instagram) managed to link what you do in your browser (for example, visiting a news site or an online store) with your real identity (your Facebook or Instagram account), even if you never logged into your account through the browser or anything like that.

Meta accomplishes this through two invisible channels that exchange information:

(i) The Facebook or Instagram app running in the background on your phone, even when you’re not using it.

(ii) Meta’s tracking scripts (the now-pulled illegal brainchild uncovered last week), which operate inside your mobile web browser.

916
 
 

Everyone talks about how evil browser fingerprinting is, and it is, but I don't get why people are only blaming the companies doing it and not putting equal blame on browsers for letting it happen.

Go to Am I Unique and look at the kind of data browsers let JavaScript access unconditionally with no user prompting. Here's a selection of ridiculous ones that pretty much no website needs:

  • Your operating system (Isn't the whole damn point of the internet that it's platform independent?)
  • Your CPU architecture (JS runs on the most virtual of virtual environments why the hell does it need to know what processor you have?)
  • Your JS interpreter's version and build ID
  • List of plugins you have installed
  • List of extensions you have installed
  • Your accelerometer and gyroscope (so any website can figure out what you're doing by analyzing how you move your phone, i.e. running vs walking vs driving vs standing still)
  • Your magnetic field sensor AKA the phone's compass (so websites can figure out which direction you're facing)
  • Your proximity sensor
  • Your keyboard layout
  • How your mouse moves every moment it's in the webpage window, including how far you scroll, what bit of text you hovered on or selected, both left and right clicks, etc.
  • Everything you type on your keyboard when the window is active. You don't need to be typing into a text box or anything, you can set a general event listener for keystrokes like you can for the mouse.

If you're wondering how sensors are used to fingerprint you, I think it has to do with manufacturing imperfections that skew their readings in unique ways for each device, but websites could just as easily straight up record those sensors without you knowing. It's not a lot of data all things considered so you likely wouldn't notice.

Also, canvas and webGL rendering differences are each more than enough to 100% identify your browser instance. Not a bit of effort put into making their results more consistent I guess.

All of these are accessible to any website by default. Actually, there's not even a way to turn most of these off. WHY?! All of these are niche features that only a tiny fraction of websites need. Browser companies know that fingerprinting is a problem and have done nothing about it. Not even Firefox.

Why is the web, where you're by far the most likely to execute malicious code, not built on zero trust policies? Let me allow the functionality I need on a per site basis.

Fuck everything about modern websites.

917
918
 
 

I want to move away from Google and was ready to make the shift to proton exactly the day before all that drama started about the CEO being a trump bootlicker and stuff…

Then I looked into some alternatives and haven’t moved yet. So I really can’t decide which one from tuta, Mailbox, kSuite or maybe still proton provides the best service. And recommendations or experiences y’all want to share to help me decide? :)

Either a good UI (web/iOS) or very good compatibility with third party apps, good spamfilters and maybe an integrated calendar would be important features.

919
 
 

before buying expensive routers check OpenWRT's table of hardware and buy one that is supported by the current OpenWRT release and has decent specs. There is a detailed installation guide for each supported device in the wiki too so there are no excuses it's dead simple. Free yourself from stupid hardware manufacturers and their planed obsolescence products.

920
0
submitted 1 year ago* (last edited 1 year ago) by someacnt@sh.itjust.works to c/privacy@lemmy.ml
 
 

My current phone is 7 years old, does not support recent android versions, and battery life is becoming atrocious. This feels like right time to change my phone.

Currently, I know of & am considering 3 options:

  • Google Pixel
  • iPhone
  • Samsung Galaxy

I heard that Pixel is the best choice for privacy, despite it being Google^TM. Should I go with it, and install Graphene OS or similar options? The very fact that the name "Google" is attached makes me nervous. Also, I don't think I can trust android, so I would have to install Graphene OS or the like. In the case, app support would be lacking, though.

I am considering iPhone as well, since it has "reputation" of being secure. Of course, Apple can access my data, but that might be a good enough compromise? Honestly, I don't know. It's the best supported option as well - lots of apps support iPhone.

Galaxy is just the one that I am the most familiar with (my current one is Galaxy S8). I don't trust it, though. Do they even make good hardware nowadays?

EDIT: Turns out, Pixel phones are poorly supported by local telecomm companies. It is relatively cheap though. Still worth it?

EDIT2: I heard that data & message is fine, but the call quality is impacted by lack of VoLTE compatibility.

921
 
 

I remember a time when visiting a website that opens a javacript dialog box asking for your name so the message "hi " could be displayed was baulked at.

Why does signal want a phone number to register? Is there a better alternative?

922
 
 
923
 
 

The Privacy Iceberg

This is original content. AI was not used anywhere except for the bottom right image, simply because I could not find one similar enough to what I needed. This took around 6 hours to make.

Transcription (for the visually impaired)

(I tried my best)

The background is an iceberg with 6 levels, denoting 6 different levels of privacy.

The tip of the iceberg is titled "The Brainwashed" with a quote beside it that says "I have nothing to hide". The logos depicted in this section are:

The surface section of the iceberg is titled "As seen on TV" with a quote beside it that says "This video is sponsored by...". The logos depicted in this section are:

An underwater section of the iceberg is titled "The Beginner" with a quote beside it that says "I don't like hackers and spying". The logos depicted in this section are:

A lower section of the iceberg is titled "The Privacy Enthusiast" with a quote beside it that says "I have nothing I want to show". The logos depicted in this section are:

An even lower section of the iceberg is titled "The Privacy Activist" with a quote beside it that says "Privacy is a human right". The logos depicted in this section are:

The lowest portion of the iceberg is titled "The Ghost". There is a quote beside it that has been intentionally redacted. The images depicted in this section are:

  • A cancel sign over a mobile phone, symbolizing "no electronics"
  • An illustration of a log cabin, symbolizing "living in a log cabin in the woods"
  • A picture of gold bars, symbolizing "paying only in gold"
  • A picture of a death certificate, symbolizing "faking your own death"
  • An AI generated picture of a person wearing a black hoodie, a baseball cap, a face mask, and reflective sunglasses, symbolizing "hiding ones identity in public"

End of transcription.

924
925
1
submitted 1 year ago* (last edited 1 year ago) by perishthethought@lemm.ee to c/privacy@lemmy.ml
 
 

Today, I’m excited to introduce Waterfox Private Search, now available in open beta. This represents an important step in our journey toward creating a more independent and privacy-respecting browsing experience.

Waterfox Private Search is a meta-search engine that I’ve developed with a clear goal: to eventually serve as the default search option for Waterfox, reducing our dependency on Microsoft and other intermediaries who typically serve as gatekeepers between you and your search results.

ETA: The search link:

https://search.waterfox.net/

view more: ‹ prev next ›