276
53
submitted 2 months ago by cm0002@mander.xyz to c/privacy@programming.dev

[...]

In the new blog post, Google’s Matthew Forsythe confirms that the developer verification system is slated to come online on September 30 of this year. The initial deployment will be limited to countries with a high level of app scams: Brazil, Indonesia, Singapore, and Thailand.

[...]

Google released its new developer console back in March, inviting external developers the opportunity to pay $25 and verify their identities early. Developers who don’t register will find that their apps cannot be sideloaded on Google-certified Android devices once verification has rolled out. Google says that almost every app in the Play Store is now ready for the change, and a “large majority” of apps outside Google Play have completed verification.

[...]

Google says it will verify the apps in the following stores when it begins enforcing the new restrictions.

Google (Google Play)
Honor (HONOR App Market)
OPlus (OPPO App Market)
Samsung (Galaxy Store)
Transsion (Palm Store)
vivo (V-Appstore)
Xiaomi (GetApps)

[...]

The next step toward verifying apps will come this month as Google deploys a new system service on most certified devices. The package (com.google.android.verifier) will appear on phones and tablets running Android 8 or higher, allowing Google to block the installation of unverified apps. It will remain dormant until verification is activated in your specific region.

In July, Google plans to roll out the new developer APIs and begin testing for “limited distribution” accounts. This is Google’s solution for hobbyists who want to make their own apps and share them with a small group. Limited accounts won’t require a fee or government ID verification, but you can install these apps on up to 20 devices.

In August, the advanced flow will become available globally ahead of verification becoming mandatory in the first markets. As detailed a few months ago, the advanced flow will allow users to bypass verification, but the process isn’t easy. You’ll have to navigate to a buried menu, confirm you understand the risks multiple times, and wait a whole day before completing the process.

And that brings us to September, when Android devices in Brazil, Indonesia, Singapore, and Thailand will begin checking verification status before installing apps. However, things get murky after that. Google will undoubtedly monitor how verification works as millions of users are suddenly limited to verified apps, which could affect how it moves forward. Google says it intends to expand developer verification in 2027, eventually making it a global device policy.

277
23
submitted 2 months ago by cm0002@mander.xyz to c/privacy@programming.dev

I run 0807, a file host I host myself.

You drop a file, you get a short link, and you choose when it disappears.

I am posting it here because the whole thing is built around privacy, and because I would rather lay out the real threat model than call it "secure" and let you find the gaps later.

The privacy side:

  • No account, no sign up. An upload is not tied to any identity.
  • No ads, no third party trackers, no analytics. Nothing is loaded from outside domains, so no fonts or scripts phoning home.
  • The server does not log IP addresses or requests. The rate limiter holds an IP in memory for a few minutes to count requests, then forgets it. Nothing is written to disk.
  • Reachable over Tor through an onion service.
  • Auto delete by time (one hour to thirty days, or never) or after a chosen number of downloads.
  • Optional password on files and on text notes.
  • Files up to 20 GB.
  • Executable types like exe, bat and scripts are blocked so it cannot be used as a malware drop.

The honest part, which this community will and should ask about:

it is not end to end encrypted. The server can read what is stored, on purpose.

I want to be able to remove illegal uploads when they get reported, child sexual abuse material above all. A server that cannot see its own contents cannot act on those reports, and I am not willing to run one that cannot.

So I gave up that form of secrecy in exchange for being able to take that content down.

What that means for you in practice the password is casual access control, not protection from me as the operator or from anyone who breaks into the server.

If you need real confidentiality, encrypt the file on your own machine before uploading and share the key separately.

Treat 0807 as a way to move files around with self destructing links and no account, not as a vault for secrets you cannot afford to expose.

It is open source, and I host the code on my own server instead of GitHub, so there is no third party in that loop either.

You can read every line check the no logging claim yourself suggest a change, or open an issue all without an account:

SRC

OC by developer @0807@lemmy.world

278
33
submitted 2 months ago by Sunshine@piefed.ca to c/privacy@programming.dev
279
42
submitted 2 months ago by Sunshine@piefed.ca to c/privacy@programming.dev
280
37
submitted 2 months ago by Sunshine@piefed.ca to c/privacy@programming.dev
281
80
submitted 2 months ago by Sunshine@piefed.ca to c/privacy@programming.dev
282
33
submitted 2 months ago by Sunshine@piefed.ca to c/privacy@programming.dev
283
28
submitted 2 months ago by Sunshine@piefed.ca to c/privacy@programming.dev
284
21
submitted 2 months ago by cm0002@mander.xyz to c/privacy@programming.dev

This now makes me wonder: is there a QR generator that maps out a grid of numbers and letters to help you draw it manually on graph paper with paper or pen or marker? That'd be kinda fun to use with this and completely baffle people in the wild by leaving literally E2E-encrypted messages for friends in public areas lolll.

285
129
submitted 2 months ago by floofloof@lemmy.ca to c/privacy@programming.dev

cross-posted from: https://lemmy.world/post/48289957

Defense contractor Leonardo is promoting a new technology called SignalTrace that will package plate cameras with sensors that can scrape unique identifiers tied to your smart devices and make that data available to law enforcement.

Police, border security, and other government agencies already comprise Leonardo’s customer base, and with this technology, those clients seek to correlate footage from these cameras to phones, tablets, wearables, AirTags, and, naturally, the electronics inside cars themselves.

If SignalTrace can pick up your Bluetooth headphones, you can be sure it’ll also be looking out for your vehicle’s 5G hotspot, infotainment system, and even its tire pressure monitoring sensors. The company includes pet microchips as a potential entry point to tracking.

286
24
submitted 2 months ago by cm0002@mander.xyz to c/privacy@programming.dev
287
13
submitted 2 months ago by cm0002@mander.xyz to c/privacy@programming.dev
288
33
submitted 2 months ago by cm0002@mander.xyz to c/privacy@programming.dev
289
33
submitted 2 months ago by cm0002@mander.xyz to c/privacy@programming.dev

Fluxer v2 is out, mobile clients are open source, self-hosting is improving, and public development is moving back to GitHub.

290
46
submitted 2 months ago by cm0002@europe.pub to c/privacy@programming.dev
291
39
submitted 2 months ago by cm0002@europe.pub to c/privacy@programming.dev
292
14
293
27
submitted 2 months ago by cm0002@europe.pub to c/privacy@programming.dev
294
8
The Digital Imprimatur (www.fourmilab.ch)

A timely and relevant essay about the war on General Purpose computing.

295
98
submitted 2 months ago by cm0002@europe.pub to c/privacy@programming.dev

I have been using Bitwarden for around 7~ years. Subscription for this long too, at 10USD p/year. I will be switching due to lack of transparency, and would love to hear others thoughts on this.

The linked article goes into further detail, but here is a small summary that very much concern me / are sus:

  • that 10USD per year has gone up quietly . I just checked and I have no email telling me it's increased. It renews in like 2 months, so this is good timing for me
  • Originally Bitwarden had values as apart of the acronym "GRIT". Gratitude, Responsibility, Inclusion, and Transparency. They have changed the last two words to "Innovation, Trust"
  • There is now a new CEO, this was not announced and the only reason people outside of Bitwarden know is that someone saw this change on LinkedIn
  • The free tier momentarily disappeared from their product page for about a month (april14-may14). People were likely still able to make free accounts during this period. Bitwarden says it was a marketing mistake

The price hike is one thing, but for me the acronym change is most concerning, which is why I will be looking at another password manger (probably keepassxc)

296
114
submitted 2 months ago by cm0002@europe.pub to c/privacy@programming.dev

The reasons of his departure? Military AI, surveillance of Europeans, ethical principles erased.

René Mayrhofer has been protecting the security of your Android smartphone for nine years. He just quit Google for a reason that directly concerns you: the company signed a deal allowing the Pentagon to use its AI for classified operations, and the man who secured your smartphone believes these tools will “probably be used against” European citizens.

Here is the rest of article in French: https://www.lesnumeriques.com/societe-numerique/la-direction-a-perdu-toute-boussole-morale-le-chef-de-la-securite-d-android-claque-la-porte-de-google-n257431.html

297
365
submitted 2 months ago by cm0002@europe.pub to c/privacy@programming.dev

Transcription:

COUNTRIES THAT BAN OR RESTRICT VPN SERVICES: Iran, Belarus, Iraq, North Korea, Turkmenistan, China, Russia, Egypt, India, Myanmar, Oman... United Kingdom?

This is probably referring to this: https://www.independent.co.uk/extras/indybest/gadgets-tech/vpn-ban-uk-b2939311.html

An older post from Mulvad about their issues advertising in the UK: https://mullvad.net/en/and-then/uk

OC by @Armand1@lemmy.world

298
40
The “Nude” Ultimatum: Privacy is Dead (the.unknown-universe.co.uk)
submitted 2 months ago by cm0002@europe.pub to c/privacy@programming.dev

The UK government is giving Apple and Google three months to build on-device scanning infrastructure. This isn't about child safety; it's about the end of private devices and the death of the "nothing to hide" fallacy.

299
94
submitted 2 months ago by cm0002@europe.pub to c/privacy@programming.dev
300
18
submitted 2 months ago by cm0002@europe.pub to c/privacy@programming.dev
view more: ‹ prev next ›

Privacy

5082 readers
188 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 3 years ago
MODERATORS