351
16
submitted 3 months ago by cm0002@lemdro.id to c/privacy@programming.dev

TLDR: A new, widespread wave of cyberattacks is actively targeting Signal users, specifically aiming to compromise and steal account backups. Because Signal chats are end-to-end encrypted on device, hackers are shifting focus to where that data might be stored less securely (like cloud backups or via phishing/credential stuffing attacks to gain account access).

352
41
submitted 3 months ago by cm0002@lemdro.id to c/privacy@programming.dev
353
20
Passkeys (lemdro.id)
submitted 3 months ago by cm0002@lemdro.id to c/privacy@programming.dev

Do you people trust companies with passkeys?

I feel like big tech have started pushing for passkeys really hard lately. Microsoft has been asking me if I want to switch to passkeys pretty consistently. Google just automatically brings up the passkey registration fingerprint scan system dialogue every single time I've been signing in on Android. Without even asking if I want a passkey or not, it just does it without saying anything. I think the intention is pretty clear, an unknowing person sees the completely random fingerprint scan dialogue, doesn't think much of it, scans their fingerprint, a passkey gets created automatically.

Well, I fell for their trick. I've been avoiding the passkey dialogue pretty consistently for a while now, but just now I was signing in while distracted and accidentally tapped my finger on the scanner by reflex on the prompt. I guess I have a passkey now. Yay.

I did some digging on my Google account settings and the internet, and I couldnt find a way to completely remove the passkey. It seems you can only disable the use of passkeys, but the passkey itself remains. There is also a setting called "Skip password when possible", which is clearly what has been causing the non-stop passkey prompts. It's on by default. It's a shame I'm only aware of it now that its too late.

Theoretically, the passkey standart itself should be private and secure. Throughout the process, the biometric information used for the cryptographic challenges never leaves the device, and the server only gets access to a signature that has been signed with the client's private keys that it can use to authenticate but can't derive the private keys back from because of complicated math I didn't spend enough energy to understand. Google automatically syncs the passkeys with its private keys with E2EE in the Google Password Manager tied to the account, which is where I start to get uncomfortable because I can't bring myself to trust Google with E2EE.

What do you people think?

OQB @MrKoyun@lemmy.world

354
143
355
9

Cross posted from https://sh.itjust.works/post/60948229

A bill that would allow cameras inside nursing homes is waiting for Arizona lawmakers in the senate to bring it for a debate and vote.

356
9
submitted 3 months ago by cm0002@lemdro.id to c/privacy@programming.dev

A bill that would allow cameras inside nursing homes is waiting for Arizona lawmakers in the senate to bring it for a debate and vote.

357
34
submitted 3 months ago by cm0002@lemdro.id to c/privacy@programming.dev
358
77
submitted 3 months ago by XLE@piefed.social to c/privacy@programming.dev
359
24

Governor Tim Walz signed House File 4138 on Tuesday, turning Minnesota into the latest state to demand that social media platforms profile every user who logs on.

The law, which takes effect in July 2027, forces platforms with at least 10,000 account holders or $1 billion in annual revenue to estimate the age of all Minnesota users, obtain parental consent before anyone under 16 can hold an account, and disable a list of features the legislature has labeled “addictive.” It passed the state House 132-2 and the Senate 66-0.

360
156
submitted 3 months ago* (last edited 3 months ago) by cm0002@lemdro.id to c/privacy@programming.dev

I encountered this for the first time today while attempting to read something on archive.today.

I confirmed that decoding the qrcode using a computer and following the URL it contains is insufficient; the error it gave directed me here which is what the linked screenshot is of.

The old type of captcha remains available too, for now:

screenshot of text: Important: Mobile verification for Google Cloud Fraud Defense is an experimental challenge type in Preview. Visual and audio challenges are available as alternatives for users who can't complete mobile verification. To use them, click the Visual  or Audio  buttons.

OC writeup by @cypherpunks@lemmy.ml

361
38
submitted 3 months ago* (last edited 3 months ago) by beep@piefed.world to c/privacy@programming.dev
362
50
363
16
364
15

Consent will no longer be required for using data for AI development and statistical analysis purposes provided that the data does not identify individuals.

Specifically, companies will no longer need consent from individuals to collect public information on social media and other platforms, or to share corporate-held data with other companies.

365
30
366
58
submitted 3 months ago by cm0002@lemy.lol to c/privacy@programming.dev
367
12

The most valuable argument against privacy, is it being abused by criminals. It's foundational to the "I have nothing to hide" fallacy: waived by those, conditioned into believing, mass-surveillance being a proportional compromise; if potentially elevating their sense of "safety". What they fail to recognize however, is mass-surveillance simply being an escalation, of the fundamentally flawed enforcement model: responsible for their lack of confidence in it. Enforcement of laws should be the exception, not the rule; otherwise conflicting incentives are ought to be addressed first (primarily: large discrepancies in socio-economics, and in turn all that stems from it).

Crime prevention based on enforcement can only prove unsustainable: to be compensated for, using automated systems during technological abundance (which is now). These systems are incompatible with privacy, and more broadly speaking: tangible assurance, personal data isn't being collected without one's explicit consent (regardless of whether the "expectation of privacy" demoralization applies). My sympathy goes out to any well-intended officer, tasked with treating symptoms of an effective aristocracy: intolerant towards meaningful change, which would challenge its self-serving interests. Just a thought, which has been plaguing me for too long... :)

OC write up by @PierceTheBubble@lemmy.ml

368
5
369
76

For now, your encrypted messages have a lock on them.

Only you, and the person you're talking to, hold the key. Not the app. Not the company. Not the government. You probably don't think about it. That's the whole point — it just works.

Until, possibly, the end of this summer. Every messaging app in Canada would be required to build a second key.

With Bill C-22, the government would hold the copy. The lock you trust would no longer be a lock only you can open. It would be a lock the locksmith was ordered to duplicate.

Find and email your MP here to voice your opinion.

https://dontsurveil.me/c22/mp/

370
43
371
19

Bruno reached out to me mid-April with a suggestion to check out his privacy-first search engine tool Uruky. Uruky works on a subscription model, but one of my kids and I were able to test it out for free for a couple of months.
I normally do not test privacy tools on request, but rather focus on describing tools I've discovered myself and already use in daily life. Yet the email conversation between us evolved into quite a warm exchange about his projects, my blog, networks and privacy tools in general. Bruno, being a software engineer, helped me better understand how local networks work, which led to my article about running a Monero node.

372
54
373
5
374
261
Chat control (lemmy.nz)

Pandora's iPhone, by Stuart Carlson, 2016. Still spot-on in 2026:

A backdoor for the good guys simply does not exist. Once you build it, hackers walk through, authoritarian governments walk through, and the rest follows.

The UK is pressuring for chat control right now. EU Chat Control initiatives keep popping up. We need to keep saying NO to this!

375
42
submitted 3 months ago by cm0002@infosec.pub to c/privacy@programming.dev
view more: ‹ prev next ›

Privacy

5082 readers
267 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 3 years ago
MODERATORS