Privacy

50695 readers
595 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 6 years ago
MODERATORS
1051
 
 

Kenn Dahl says he has always been a careful driver. The owner of a software company near Seattle, he drives a leased Chevrolet Bolt. He’s never been responsible for an accident.

So Mr. Dahl, 65, was surprised in 2022 when the cost of his car insurance jumped by 21 percent. Quotes from other insurance companies were also high. One insurance agent told him his LexisNexis report was a factor.

LexisNexis is a New York-based global data broker with a “Risk Solutions” division that caters to the auto insurance industry and has traditionally kept tabs on car accidents and tickets. Upon Mr. Dahl’s request, LexisNexis sent him a 258-page “consumer disclosure report,” which it must provide per the Fair Credit Reporting Act.

What it contained stunned him: more than 130 pages detailing each time he or his wife had driven the Bolt over the previous six months. It included the dates of 640 trips, their start and end times, the distance driven and an accounting of any speeding, hard braking or sharp accelerations. The only thing it didn’t have is where they had driven the car.

On a Thursday morning in June for example, the car had been driven 7.33 miles in 18 minutes; there had been two rapid accelerations and two incidents of hard braking.

1052
 
 

Hello everyone, I was wondering if anyone knew of a FOSS editing app to use on PDFs, just to add text and and mark things out, I tried GNU image editor but it just works on images exclusively. Any ideas are appreciated, thanks.

1053
 
 
1054
 
 

I have no opinion and am just seeking clarification as an admin who occasionally gets complaints that I’m unsure how to address.

Thanks!

cc: @TheAnonymouseJoker@lemmy.ml (the most active !privacy@lemmy.ml mod)


Edit to add an example edge case: DuckDuckGo is proprietary, but is anyone going to argue against its promotion? Isn’t Proton Mail similarly only FOSS on the client side?

1055
 
 

I use Firefox whenever I can.

On first install of the browser I usually end up following a hardening guide which includes stuff like blocking cross site cookies, setting a few things in about:config to disable Pocket/etc, and installing uBlock Origin. I've taken what I consider a relatively balanced approach, I don't use anything like noScript, uMatrix, etc that ultimately just cost a lot of time fiddling to get the 10th website of the week working.

I've been more or less fine browsing the web this way for years, but around the start of 2024 I've started seeing way more "Access Denied" pages than I used to. I think part of it is Cloudflare or similar, but I don't know exactly what's changed or what's triggering it to occur.

It usually goes away and I can re access the site in 10-30 minutes as usual, but I've had it occur in really weird instances, such as trying to change my Minecraft skin and getting blocked by the website. The server block often goes away immediately if I switch my user agent, so I know that it has something to do with how I've got everything set up.

Not sure what anyone else's experience with this has been. I'd like to hear some of your thoughts and tips

1056
 
 

Hello all, recently wanted to signup for temporary permanent legit emailmid in gmail. It was asking me Phone number in process, i tried to use multiple numbers from regular online resources ( more than 30) but nothing worked. I don't want to give my personal phone number in real life to someone's unless Its I want to.

How do I sign up services where phone number is required ? Is there throw away phone number I can get ? Is there way to skip it all together ( not on Gmail for sure ) Your help be appreciated.

1057
 
 

A week or so ago, a blog post was posted in this Community calling out Mullvad for using GMail as their email provider. Wasn't the greatest blog post in the world and didn't approach Mullvad for comment or explanation. Anyway, looks like Mullvad heard about it and responded.

1058
 
 

Very interesting video about the tracking of cellular networks.

1059
 
 

TL;DR

Don't use snapchat

1060
 
 

Title

1061
 
 

My dog tore up the remote so we were forced to use the roku app to control the tv.

They’re showing ads on the remote app. It feels like we can never escape this dystopian hellacape.

1062
 
 

A PasswordCard is a credit card-sized card you keep in your wallet, which lets you pick very secure passwords for all your websites, without having to remember them! You just keep them with you, and even if your wallet does get stolen, the thief will still not know your actual passwords.

A very cute idea, well implemented.

Your PasswordCard has a unique grid of random letters and digits on it. The rows have different colors, and the columns different symbols. All you do is remember a combination of a symbol and a color, and then read the letters and digits from there. It couldn't be simpler!

A chain is only as strong as its weakest link. It's far safer to pick secure passwords and write them down, than it is to remember simple and easy to guess passwords. You already protect your wallet very well, and even if it does get stolen the thief will still not know which of the many thousands of possibilities on the card is your password.

1063
 
 

Looks like gitlab now requires account verification for new accounts in addition to email. Either phone number or credit card.

This applies both to accounts created with a working email or by logging in using your github account. You can't even verify your email until you go through step 1.

I don't know when this started, but at least for the last month or two judging from these posts in the forums.

Fun fact: I don't even want to host on gitlab, I just wanted to report bugs in some projects. So I'm locked out.

1064
 
 

Hello, could someone recommended a keyboard for android that is a bit smart in predictive typing? I used to like swiftkeybefore it was bought by microsoft. Not that swiftkey itself was much better but I was not so privy conscious at that time.

I recall swiftkey would require access to your texts and emails to train itself to your predictions.

Is there some similar foss keyboard where all the data then remains local?

I know swiftkey has an incognito mode, but then it stops learning from your typing.

1065
 
 
1066
 
 
1067
 
 

So I got Fairphone 4, with /e/ os, a couple of days ago. When I connected it to my NextDNS I saw that it was trying to connect to some weird addresses, like every 5-10 minutes. I searched Internet a bit and found out that it was something with snapdragon cpu and location services. I travel a lot and use Organic Maps for navigation, so location was enabled almost all day on the phone. I turned off location services and connections stopped, and everything was fine for a couple of days.

Today I came home, checked logs in NextDNS and saw that phone started doing the same connections almost constantly even with location turned off.

Can I do something about this, other than allowing these connections? These connections are probably so numerous because they are getting blocked. If I allowed them, phone would maybe call home once in a couple of hours. I would rather not allow them, but I don't want 20% of battery to be eaten by this.

1068
 
 

Like the title states looking for E2EE apps (Android and iOS) without going into much details or needs to be robust enough and easy to use for anyone and stable for operations that are susceptible to constant electronic warfare. I did some research and thought about replacing Signal with Molly and wondering if it will still work if Signal leaves the EU, but am also worried about its updates to patch vulnerabilities in a timely manner. I appreciate the help I am a “Jack of all trades and master of none” when it comes to these types of programs, but am also the go to currently in my unit since I am somewhat knowledgeable about exploits and attacks that can compromise systems would be great if there was an desktop as well (like Signal) and would also be nice if it was FOSS and auditable ( I know that’s kind of redundant ) I know it’s a tall order to ask but figured I would try. I really appreciate the help so much and hope I did things by the rules here and don’t get flamed if this has already been covered ( I searched but my skills with searching the fediverse is low

1069
 
 
  • second, i have no intention to use any services using cloudflare
  • how did i know_
    • fdroid_ settings_ repositories_ activate guardian project official relases
    • install torservices (alpha)
  • install privacy browser
    • settings_ proxy_ enable tor
  • visit *.lemmy.world
  • screenshot_ *.lemmy.world on cloudflare
1070
 
 

Originally I've download the signal app through playstore, but often it also get updates from Droid-ify(Fdroid client). Today its weird and I got this . Explain to me this.

On the Droid-ify the signal app is provided by: org.thoughtcrimes.securesms

1071
 
 

In a few weeks I'll do a workshop about security for people who are tech illiterate, I plan to teach about password managers and 2FA.

If I show the 2FA number codes, like the 123 456 ones that I have to paste when required, can that be a possible security breach for me? or is it save since is gonna change in a few seconds anyway?

1072
 
 

For open source messengers, you can check whether they actually encrypt your messages and whether the server has access to your encryption keys but what about WhatsApp? Since it's not open source, you can't be sure that the encryption keys aren't sent to the server, right? Has there been a case where a government was able to access WhatsApp chats without reading them from the phone itself?

1073
 
 

I see a lot of people, including friends and family, sharing URLs rife with tracking parameters.

I feel alone in making sure that I'm sharing the cleanest possible URLs to others. For example, checking if the URLs are shortened to hide plenty of tracking params.

Just need to vent, thanks for reading.

Edit: adding some context for future references.

By using url tracking params, tech companies can track who shares the content and who clicks on that specific shared urls. A simple but effective tracking method.

Try sharing Instagram post or YouTube video from the apps.

Instagram adds 'igshid=' . YouTube adds 'si='.

If you share the same IG or YouTube content from different accounts. The 'igshid', 'si' value will be different.

This can be used to tag who shares it, and who clicks on that specific url param value.

TikTok hides a ton of such params behind shortened url. Try expanding tiktok shared urls.

If you use android, use this app to expand, analyze and clean up urls https://github.com/TrianguloY/UrlChecker

If you use Firefox (you should), install ublock origin and add this url tracking filter maintained by adguard: https://raw.githubusercontent.com/AdguardTeam/FiltersRegistry/master/filters/filter_17_TrackParam/filter.txt

1074
1075
 
 

A viral TikTok account is doxing ordinary and otherwise anonymous people on the internet using off-the-shelf facial recognition technology, creating content and growing a following by taking advantage of a fundamental new truth: privacy is now essentially dead in public spaces.

view more: ‹ prev next ›