Privacy

31679 readers
209 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
1476
 
 

In the last couple of months I have noticed an increasing trend of supplying me search results that are completely unrelated to the current query and tie back to my location or previous searches. I can say this with a high degree of certainty this is without a doubt beyond the 100th instance this has happened.

My browser is configured against tracking and fingerprinting (in fact all my devices are) which would make it fairly difficult to retain any data unless they are profiling me.

1477
 
 

I like to try websites out before tying my identity to them. How do you do it? Simplelogin? I honestly won't manually make a new gmail for every new website I try and I to want the option to see what emails I get.

1478
 
 

He just posted this update today. I hope the best for his next chapter.

"I would never say the podcast will not return, as I get bored easily. I will say that it is on an indefinite "hiatus”."

1479
 
 

alright so basically; i have been working on a list of private browsers for a while and wanted to show it to people that know the topic better than me

ill.. just show the site (😭)

1480
 
 

Sometimes I want to get updates on a news story, and it's small or local so the coverage is sparse. I'd like to get an alert when a new news story or social media post is published.

I think google has something like this. A more private or self hosted one would be nice

1481
 
 

Is there a site like 'cover your tracks' for showing that websites can see what extensions I have (as opposed to other fingerprinting)? Thank you 🙃

1482
1483
16
Media Backups (lemmy.tf)
submitted 11 months ago* (last edited 11 months ago) by sabreW4K3@lemmy.tf to c/privacy@lemmy.ml
 
 

So I have a rather simple question, where do you all backup your music, movies and photos to that's stored on your NAS?

1484
 
 

Blur tools for Signal: if you take or edit photos of crowds or strangers with Signal, you can use our face blur tool to quickly hide people's biometric face data.

You can then export the photo from Signal if you want to post it publicly.

1485
1486
48
submitted 11 months ago* (last edited 11 months ago) by khoi@slrpnk.net to c/privacy@lemmy.ml
 
 

Is it really decentralized and private?

1487
 
 

Nothing Chats has already been pulled from Google Play over privacy issues / Nothing pulled the Nothing Chats beta from the Google Play store “until further notice” after reports that Sunbird sends messages in plain text.

1488
 
 

Things that make me angry about my current smartphone Samsung Galaxy S21Ultra on a Verizon plan is the mandatory software updates in which they install WITHOUT MY PERMISSION stupid apps like Netflix and addictive gambling games and stacking block games and Candy crush. God knows what else they install without my permission. I don't want any of it!

Next phone I buy I want to start with a clean slate, I'm not going to affiliate with any conglomerate like Verizon or AT&T or Sprint or T-Mobile etc, I prefer to go rogue somehow,

which smartphone do you recommend that has no bloatware and it's customizable?

1489
1490
 
 

In celebration of Bitcoin Black Friday 2023, we're offering a 10% discount on all BusKill cables sold between Nov 18 to Dec 03.

BusKill Bitcoin Black Friday Sale - Our Dead Man Switch Magnetic USB Breakaway cables are 10% off all orders paid with cryptocurrency
BusKill Bitcoin Black Friday Sale - Our Dead Man Switch Magnetic USB Breakaway cables are 10% off all orders paid with cryptocurrency

What is BusKill?

BusKill is a laptop kill-cord. It's a USB cable with a magnetic breakaway that you attach to your body and connect to your computer.

What is BusKill? (Explainer Video)
Watch the BusKill Explainer Video for more info youtube.com/v/qPwyoD_cQR4

If the connection between you to your computer is severed, then your device will lock, shutdown, or shred its encryption keys -- thus keeping your encrypted data safe from thieves that steal your device.

What is Bitcoin Black Friday?

Black Friday is ~1 month before Christmas, and it's the busiest shopping day in the US. The first "Bitcoin Friday" (launched by Jon Holmquist) was Nov 9th, 2012 (at the time, one bitcoin was ~$11). The following year, the two ideas merged to become Bitcoin Black Friday.

This year, we're joining Bitcoin Black Friday by offering our products at a 10% discount if you pay with cryptocurrency.

Why should I use cryptocurrencies?

We've always accepted cryptocurrencies because:

  1. They're more secure than pre-cryptocurrency payment methods
  2. They're a more egalitarian system than pre-cryptocurrency finance
  3. They're more environmentally friendly than pre-cryptocurrency financial systems
  4. The fees are less than pre-cryptocurrency transactions
  5. They allow for anonymous purchases online
  6. Their transactions are censorship-resistant

Security

Before cryptocurrencies, making an online transaction was horrendously insecure and backwards.

Diagram shows all the third parties that can steal your funds in a pull-based system: Merchant, Acquierer, Payment Processor, Switch, Issuer
"Conceptually, pull-based transactions are really not that different than giving three parties the password to your online banking service and trusting them to log in and take what they need. You have to trust the merchant, their IT supplier; the acquiring bank, their third-party processor; the card network; and your own card issuer---and everybody who works for them and has access to their systems. If a bad guy gets hold of your card details at any point in this process, they could drain your account.
The picture shows the scope of all the entities with access to your critical card information" source

Asymmetric cryptography has been available since the 1970s, but CNP (Card Not Present) transactions to this day still don't use public keys to sign transactions. Rather, you give your private keys (that is, your credit card number, expiry, etc) directly to the merchant and you authorize them to pull money out of your account (trusting that they take the right amount and not to loose those precious credentials).

Bitcoin flipped this around to actually make transactions secure. With bitcoin, you don't give others the keys to take money out of your account. Instead, transactions are push-based. You sign a transaction with your private keys, and those keys are shared with no-one.

Even today, pre-cryptocurrency transactions are abhorrently insecure. In the US or Europe, if someone knows your account number and bank, they can direct debit money out of your account. For the same reason, losses due to credit card theft is enormous. To quote Satoshi Nakamoto's criticism of pre-cryptocurrency transactions, "A certain percentage of fraud is accepted as unavoidable"

In fact, fraudulent transactions in the banking industry are so common that your bank will generally reimburse your account for any malicious transactions that you tell them about within 60-90 days. But if someone drains your account of all your money and you don't notice for 12 months? Too bad. All your money is gone.

Graphic shows a push-based model where a consumer pushes value directly to a merchant
In Bitcoin, transactions are push-based. source

Tokenization and 3DS are merely bandages on a fundamentally backwards, pull-based transaction model. But because bitcoin is push-based, it's magnitudes more secure.

Egalitarian

If you have a bank account, then you probably take a lot of things for granted. Like buying things online (with a credit card). Or getting cash when traveling abroad (from an ATM machine). Or taking out a loan so you can start a business.

Before crypto-currencies, it was very difficult to do these things unless you had a bank account. And in 2008 (the year with the first-ever bitcoin transaction), McKinsey & Company published a report concluding that half of the world's adult population is unbanked.

But with crypto-currencies, anyone with access to the internet and a computer or smart phone can use bitcoin to send and receive money online -- without needing to first obtain a bank account.

Environmentalism

The energy required to facilitate transactions in decentralized, blockchain-based cryptocurrencies like bitcoin is minuscule by comparison. And, most importantly, the amount of energy used to solve the proof-of-work problem does not grow as the number of transactions-per-second grows.

Traditional financial institutions require an enormous amount of overhead to facilitate transactions in their centralized networks. Unlike bitcoin, which was designed specifically to eliminate the unnecessary overhead created by a trusted third party, pre-cryptocurrency transactions required humans to verify transactions. These humans require office buildings. These office buildings require energy to build and maintain. And, most importantly, as the number of transactions-per-second grows on their network, the number of humans and office space also grows.

Bar Graph shows the comparison of energy usage of Bitcoin and various industries
Bitcoin versus other industries

yearly energy use, in TWh source |

This fact is often misunderstood because there's a lot of misinformation on the Internet that makes a few disingenuous modifications to the facts:

  1. They calculate the energy usage of the computers processing transactions only, maliciously omitting calculating the energy usage of the entire industry's infrastructure (eg energy used by office buildings)
  2. They calculate the energy usage per transaction, maliciously omitting the fact that the amount of energy expended by bitcoin miners is automatically adjusted by the proof-of-work algorithm (so energy usage does not increase as the network scales-up)
  3. They offer statistics about "energy usage" without mentioning the energy sources. It matters if the energy source is coal/nuclear/natural-gas or solar/wind/hydroelectric
"...estimates for what percentage of Bitcoin mining uses renewable energy vary widely. In December 2019, one report suggested that 73% of Bitcoin's energy consumption was carbon neutral, largely due to the abundance of hydro power in major mining hubs such as Southwest China and Scandinavia. On the other hand, the CCAF estimated in September 2020 that the figure is closer to 39%. But even if the lower number is correct, that's still almost twice as much [renewable energy sources] as the U.S. grid" Nic Carter Headshot
source: Harvard Business Review Nic Carter

The facts are that the energy usage of bitcoin is magnitudes less than the energy used by pre-cryptocurrency financial intuitions, that energy usage does not increase as the number of transactions processed by the network increases, and that mining bitcoin is often done with renewable energy.

The facts are that the energy usage of bitcoin is magnitudes less than the energy used by pre-cryptocurrency financial intuitions, that energy usage does not increase as the number of transactions processed by the network increases, and that mining bitcoin is often done with renewable energy.

Low Fees

The introduction to the Bitcoin White Paper (2008) clearly states that Bitcoin was created to reduce costs by using a distributed ledger (the blockchain) to eliminate the need for a trusted third party.

"Commerce on the Internet has come to rely almost exclusively on financial institutions serving as trusted third parties to process electronic payments. While the system works well enough for most transactions, it still suffers from the inherent weaknesses of the trust based model.
Completely non-reversible transactions are not really possible, since financial institutions cannot avoid mediating disputes. The cost of mediation increases transaction costs...
These costs and payment uncertainties can be avoided in person by using physical currency, but no mechanism exists to make payments over a communications channel without a trusted party.
What is needed is an electronic payment system based on cryptographic proof instead of trust, allowing any two willing parties to transact directly with each other without the need for a trusted third party. Transactions that are computationally impractical to reverse would protect sellers from fraud, and routine escrow mechanisms could easily be implemented to protect buyers. In this paper, we propose a solution to the double-spending problem using a peer-to-peer distributed timestamp server to generate computational proof of the chronological order of transactions." A hooded figure wearing a guy faux ask sits in lotus pose. Behind them is an illuminated personification of Bitcoin
source: Bitcoin Whitepaper Satoshi Nakamoto

At the time of writing, the average transaction fee for a bitcoin transaction is $0.06. And unlike pre-cryptocurrency transactions, you can increase or decrease the fee that you pay to increase or decrease the time it takes for the transaction to complete (at $0.06, it will get added to the blockchain in ~1 hour).

By comparison, the way to send funds internationally through the Internet via pre-cryptocurrency banks is via an international wire transfer. Fees very per bank, but they typically charge $15-$85 per transaction. And unlike bitcoin, wire transfers won't make move on nights and weekends, so they can take 1-7 days to complete.

Also, with bitcoin, that $0.06 transaction fee only applies when you're sending money. Many banks will also charge a fee for an incoming wire transfer. In bitcoin, there is no transaction fee to receive money.

Anonymity

Though early cryptocurrencies like Bitcoin don't ensure anonymity like newer privacy coins, ZCash and Monero were designed specifically to provide private transactions.

This allows our customers to purchase from us anonymously, which can be extremely important for activists and journalists whose lives are threatened by their adversaries.

Tweet from WikiLeaks that reads "WikiLeaks now accepts anonymous Bitcoin donations on 1HB5XMLmzFVj8ALj6mfBsbifRoD4miY36v"
WikiLeaks started accepting donations in Bitcoin 7 months after PayPal froze their account

We accept both ZCash and Monero. If you'd like us to accept another privacy coin, please contact us :)

Censorship-Resistant

Cryptocurrencies like bitcoin are peer-to-peer and permissionless. Transactions exchanging bitcoins occur directly between two parties. There is no middle-man that has the power to block, freeze, or reverse transactions. Before blockchains were used to maintain a public ledger and enable peer-to-peer transactions, we were dependent on big financial institutions to move money on our behalf through the internet. That antiquated system allowed them to censor transactions, such as donations made to media outlets reporting war crimes and donations to protest movements.

"For me, that is one of the coolest things about bitcoin...
People can potentially use it donate more anonymously to dissident groups and causes in a world where mass government surveillance threatens freedom of expression and certainly harms activists' ability to fundraise for their work, when people are afraid they could be targeted by a government for donating to a worthy cause." Evan Grer portrait
source Evan Greer

After PayPal froze WikiLeaks's donation account in 2010, WikiLeaks started accepting bicoin in 2011. From Occupy Wall Street to Ukraine, defenders of democracy have utilized permissionless cryptocurrencies to accept international donations without the risk of transactions made through financial institutions.

Buy BusKill with crypto

Don't risk loosing your crypto to a thief that steals your laptop. Get your own BusKill Cable at a 10% discount today!

Buy a BusKill Cable
https://buskill.in/buy

You can also buy a BusKill cable with bitcoin, monero, and other altcoins from our BusKill Store's .onion site.

Bitcoin Accepted Here

Monero Accepted Here


Stay safe,
The BusKill Team
https://www.buskill.in/
http://www.buskillvampfih2iucxhit3qp36i2zzql3u6pmkeafvlxs3tlmot5yad.onion

1491
 
 

No one tells you when you buy the car all of the shit you are agreeing to. This needs to be changed.

This car doesn't let you drive over 80mph. It reads speed limit signs and has a database apparently. The owners manual says it will provide that data to law enforcement.

This is insane. There needs to be awareness of this so people can, at the very least, know to ask before they buy. As it stands no one even knows this shit until they sign the papers and look at the owners manual.

1492
 
 

netflix.com is in the top5 domains on the entire network, and i have a Raspberry Pi running 24/7 (with AdGuard Home), most queries are from TV.

1493
 
 

So, I recently moved about 6 months ago. Have only given my real address and name to the DMV, Phone Company, Internet, and rental property(obviously knows my real address)

Ran Optery and found out that over 80 data brokers have my legit new address already.

Feeling like privacy is just some kind of wet dream at the moment. I do everything right, I think but no matter what the 4 companies I have given my information too will constantly sell my personal data no matter what.

It’s truly sad the direction America is going towards, all for some more money.

1494
30
submitted 11 months ago* (last edited 11 months ago) by Extrasvhx9he@lemmy.today to c/privacy@lemmy.ml
 
 

Hey just wondering if its a problem on my end but a self update notification indicating a newer version of signal keeps popping up. I already have the latest version of the apk, 6.40.4, installed from their website, but the notification does not go away. I click it and then it states the application has been updated but after a few minutes later it pops up again. Not sure where to ask this but I would assume this place is one of the best places to interact with people that also use signal's non-playstore apk. Is this a bug on my end or are you experiencing it too?

Edit: forgot to mention I'm on grapheneos if thats a factor

Edit 2: apparently it was already reported on github and I missed it

1495
23
submitted 11 months ago* (last edited 11 months ago) by rinze@infosec.pub to c/privacy@lemmy.ml
 
 

Real-Time Bidding (RTB) allows foreign states and non-state actors to obtain compromising sensitive personal data about key European personnel and leaders.

Key insights:

  • Our investigation highlights a widespread trade in data about sensitive European personnel and leaders that exposes them to blackmail, hacking and compromise, and undermines the security of their organisations and institutions.

  • These data flow from Real-Time Bidding (RTB), an advertising technology that is active on almost all websites and apps. RTB involves the broadcasting of sensitive data about people using those websites and apps to large numbers of other entities, without security measures to protect the data. This occurs billions of times a day.

  • Our examination of tens of thousands of pages of RTB data reveals that EU military personnel and political decision makers are targeted using RTB.

  • This report also reveals that Google and other RTB firms send RTB data about people in the U.S. to Russia and China, where national laws enable security agencies to access the data. RTB data are also broadcast widely within the EU in a free-for-all, which means that foreign and non-state actors can indirectly obtain them, too.

  • RTB data often include location data or time-stamps or other identifiers that make it relatively easy for bad actors to link them to specific individuals. Foreign states and non-state actors can use RTB to spy on target individuals’ financial problems, mental state, and compromising intimate secrets. Even if target individuals use secure devices, data about them will still flow via RTB from personal devices, their friends, family, and compromising personal contacts.

  • In addition, private surveillance companies in foreign countries deploy RTB data for surreptitious surveillance. We reveal “Patternz”, a previously unreported surveillance tool that uses RTB to profile 5 billion people, including the children of their targets.

  • Our examination of RTB data reveals Cambridge Analytica style psychological profiling of target individuals’ movements, financial problems, mental health problems and vulnerabilities, including if they are likely survivors of sexual abuse.

  • Real-Time Bidding's security flaw is a national security problem

1496
 
 

Their reply to my request to delete my data:

Thank you for your email requesting your right to be forgotten.

In order for us to carry out this request, we require proof of ID to ensure we only action requests made by the genuine owner of this email account. Acceptable forms of identification are,

  • Recent utility bill from the last 3 months (e.g. Gas, Electric)
  • Valid drivers License
  • TV License within the last 12 months
  • Council Tax Letter within the last 12 months
  • Title Deeds
1497
 
 

The National Telecommunication Monitoring Center in Bangladesh exposed a database to the open web. The types of data leaked online are extensive.

1498
 
 

My phone is no longer getting updates, so it's time to buy a new one. The hardware could easily last 1-2 more years but I'd have to replace the battery, which is a pain on my phone.

I'm looking for something that has long firmware support and some good privacy roms while not being worse than my current Oneplus 8 in any way. I don't care about cameras at all and I'm still mad about the missing headphone jacks, but unfortunately those don't seem to be coming back and I can survive without one.

So, the options are Fairphone 5 and Pixel 8 from what I found out. The Pixel 8 is a little small for my taste and with 256GB storage it's more expensive, but it does have grapheneOS, which I'd prefer because the app sandboxing would allow me to have peace of mind even if I have tracking apps sitting on my phone. I could use the proper play store and do IAPs without fiddling with aurora store. I use it already and it isn't great.

With the Fairphone, I'd get a replacable battery so I can buy a spare and swap instead of charging my phone. I used to do that with the good old S3 and it was great. MicroSD slot is also nice. But the ROM options are CalyxOS and /e/OS. I know Calyx has a nice firewall to keep tracking at bay and /e/OS is an LOS fork mainly focused on getting rid of google from what I know, but neither has as much protection as grapheneOS.

My main goal is to become less dependant on google while still being able to use google maps for my way to work. The traffic aware routing saves me 10 minutes every day so letting google know when I go to work is a fair deal.

So, any opinions or experiences with either? TIA

1499
 
 

Recently i noticed that even i don't have an account on caller id apps, still it shows my details from who saved my info on their phone who uses caller id apps.

1500
 
 

I understand what he does is only his preference but why does he not recommend using Mullvad anywhere in his books or podcasts and completely shills “Proton” for everything as if it’s the best source for everything privacy related.

In his book “Extreme Privacy” he also talks about using Cloudflare due to their no-logging policy for your DNS resolver.

“We will collect limited DNS query data that is sent to our 1.1.1.1 resolver. Our 1.1.1.1 resolver service does not log personal information, and the bulk of the limited non-personally identifiable query data is only stored for 25 hours.”

https://www.cloudflare.com/privacypolicy/

I just feel like something isn’t adding up, somewhere.

view more: ‹ prev next ›