Privacy

4010 readers
178 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 2 years ago
MODERATORS
1276
 
 

After the Tchap project based on Matrix, the French Prime Minister asks anyone in the gouvernement to use Olvid, the only app validated by the ANSSI, with metadata encryption and no centralised architecture nor contacts discovery. But only the front-ends are open source, not the back-end.

Source: https://www.politico.eu/article/france-requires-ministers-to-swap-whatsapp-signal-for-french-alternatives/

1277
 
 

Hey everyone,

I am currently using an old(er) HYPERSECU FIDO key, USB-A with a button, and I am looking to

  • secure my phone as well (NFC) and, if possible
  • add biometric authentication to the mix.

Are there good alternatives or better: upgrades to the YubiKey which do support NFC as well as biometrics and come with a USB-C?

Thanks for your time 👋

1278
 
 

cross-posted from: https://programming.dev/post/6272443

After trying different browsers on android I found Privacy Browser to be what I need. It have encrypted backups,Domain settings,jsless by default,Deleting all site data and Most usable UI. Only issue is It is based on webview and I am using system default webview as my device is nonrooted so how secure is to go this way?

1279
 
 

cross-posted from: https://programming.dev/post/6002270

Hi,

If you don't know how work the chain of trust for the httpS

You might want to watch this video https://invidious.privacydev.net/watch?v=qXLD2UHq2vk ( if you know a better one I'm all ears )

So in my point of view this system have some huge concerns !

  1. You need to relies to a preinstalled store certificate in your system or browser... Yeah but do you know those peoples ??!! it might seem weird, but actually you should TRUST people that YOU TRUST/KNOW !!

Here an extract from the certificate store om Firefox on Windows.

I do not know ( personally ) any of those COMMERCIAL company !

  1. Of course we could use Self-certificate but this is not protecting against Man-in-the-middle_attack . Instead of using a chain (so few 3th party involved , so increasing the attack surface ! ) why not using something simpler !? like for example
  • a DNS record that hold the HASH of the public key of the certificate of the website !
  • a decentralized or federated system where the browser could check those hash ?

Really I don't understand why we are still using a chain of trust that is

  1. not trusted
  2. increase the surface of attack
  3. super complex compare to my proposals ?

Cheers,

Why I don't use the term SSLBecause actually httpS now use TLS not anymore ssl https://en.wikipedia.org/wiki/Transport_Layer_Security

1280
 
 

With a new open letter of specialists and engineers against that hazardous project

https://nce.mpi-sp.org/index.php/s/cG88cptFdaDNyRr

1281
 
 

Just wanted to share kind of tutorial I wrote about flashing LineageOS on old smartphones to keen them up to date 📱

1282
 
 

Just wanted to share an old but still relevant publication about tools to use to protect our privacy, feel free to comment and share suggestions 😁

1283
1284
 
 

cross-posted from: https://fedia.io/m/disabled/t/346115

Banks have started capturing customers voice prints without consent. You call the bank and the robot’s greeting contains “your voice will be saved for verification purposes”. IIUC, these voice prints can be used artificially reconstruct your voice. So they could be exfiltrated by criminals who would then impersonate you.

I could be wrong about impersonation potential.. just fragments of my memory from what I’ve read. In any case, I don’t like my biometrics being collected without my control.

The countermeasure I have in mind is to call your bank using #Teletext (TTY). This is (was?) typically a special hardware appliance. As a linux user, TTY is what the text terminal is based on. So I have questions:

  1. can a linux machine with a modem be used to convert a voice conversation to text?

  2. how widespread are TTY services? Do most banks support that, or is it just a few giant banks?

  3. if street-wise privacy enthusiasts would theoretically start using TTY in substantial numbers, would it help the deaf community by increasing demand for TTY service, thus increasing the number of businesses that support it?

1285
 
 

Cross post from r/privacy

1286
 
 

Hi I recently reviewed my Google account settings on my phone. On exploring it I found that I can Remove almost every annoying tracker,I can delete my data,Remove services,Disable Personised ads etc.After giving it 20minutes of my day I found that Google do not deserve the Hate it gets from FOSS and PRIVACY Consious people.Is there some real reason why you should not use google products for privacy or It is just everybody want to live a Hacker's life.

1287
 
 

One of my go to list when I am searching for privacy respecting alternatives.

1288
0
submitted 2 years ago* (last edited 2 years ago) by danielintempesta@programming.dev to c/privacy@programming.dev
 
 

In my opinion, considering both usability and privacy:

  1. SearxNG/Searx (Selfhosted) +++++
  2. SearxNG (Trusted instances: searx.be, paulgo.io) ++++
  3. Brave Search +++
  4. DuckDuckGo +++
  5. Whoogle (Selfhosted) +++
  6. Kagi (credit card and name required) ++
  7. MetaGer ++
  8. Swisscows +
  9. StartPage +
  10. Qwant +
  11. Ecosia +
  12. Presearch +
  13. You . com +
  14. etools .ch ?

Avoid:

  • Google
  • Bing/Yahoo
  • ¿Phind?

More info: