651
22
submitted 6 months ago by cm0002@infosec.pub to c/privacy@programming.dev

As the saying goes if it seems to be good to be true it is. But I wanted to be hopeful maybe just once more that maybe something could be great. Encrypted email with an unlimited sized inbox ?!!? Yes please !!!

Welp sadly it seems it’s once again to good to be true.

I made an account just to see how it was. I was immediately greeted with link to buy their premium for a year, using my initial email I selected. When I finally figured out how to say no I was able to use my “backup option” for free. I found this all too off putting. But no matter I wanted to keep going, maybe it’s just bad UI.

Moved onto my tracker test using a standard browser. And sadly it failed immediately. On the main info site atomic mail tries to use 6 trackers. Within the login / inbox they try to throw on another 3, one of their own scripts (maybe innocuous) and two from cloud flare. Those trackers are Google related !

For the privacy email they claim had no tracking I found this sinister.

I immediately deleted my account.

Unless someone can speak up to what those trackers are and why I shouldn’t worry I’ll recommend everyone avoid it.

Review by @64bithero@lemmy.world

652
10
submitted 6 months ago by cm0002@infosec.pub to c/privacy@programming.dev

Apparently this will include Linux...

653
17
submitted 6 months ago by cm0002@infosec.pub to c/privacy@programming.dev
654
101
submitted 6 months ago by cm0002@infosec.pub to c/privacy@programming.dev

“Telegram is not a private messenger. There’s nothing private about it. It’s the opposite. It’s a cloud messenger where every message you’ve ever sent or received is in plain text in a database that Telegram the organization controls and has access to it”

“It’s like a Russian oligarch starting an unencrypted version of WhatsApp, a pixel for pixel clone of WhatsApp. That should be kind of a difficult brand to operate. Somehow, they’ve done a really amazing job of convincing the whole world that this is an encrypted messaging app and that the founder is some kind of Russian dissident, even though he goes there once a month, the whole team lives in Russia, and their families are there.”

" What happened in France is they just chose not to respond to the subpoena. So that’s in violation of the law. And, he gets arrested in France, right? And everyone’s like, oh, France. But I think the key point is they have the data, like they can respond to the subpoenas where as Signal, for instance, doesn’t have access to the data and couldn’t respond to that same request.  To me it’s very obvious that Russia would’ve had a much less polite version of that conversation with Pavel Durov and the telegram team before this moment"

655
19
submitted 6 months ago* (last edited 6 months ago) by JubilantJaguar@lemmy.world to c/privacy@programming.dev

If we want to keep our personal computing private (i.e. data, communications, social life, everything), we need to fix this problem.

The web is what makes privacy possible on the desktop, but the desktop platform is slowly becoming irrelevant. IMO our last hope is to make web apps usable and popular on mobile. In theory it's feasible.

656
-10
submitted 6 months ago* (last edited 6 months ago) by xoron@programming.dev to c/privacy@programming.dev

IMPORTANT: AI is used in this project, so lets get that out of the way. im not sure how to quantify it. i use different AI models on different tasks in the code as well as the documentation. i dont want to mislead or inspire undue confidence in this implementation. its open-source for transparency. not ready for general use.

its always worth mentioning this project is far from finished and i hope with feedback i can make it better. i have put efforts towards directing it towards unit-tests, audit and formal-proofs. none of that is good-enough, but i hope they can compliment each other and can act as a starting point for verifying the implementation is correct. the functionality is built around the requirements of my project. it isnt professionally audited or reviewed. use responsibly.

my motivation on this project is that im mainly working on a p2p messaging app. i hope you can understand the pushback i get when i promote my messaging app as “secure”, so this transparency with the signal protocol is nessesary. im sure people have better things to do with their time than review unstable and unfinished code. i only put it out there for you to take a look if you’re interested. as a solo dev, there isnt anyone reviewing my code. if i dont share it like this, no one will come across it.

This project is unfinished so I could be sharing it too early, I wonder if I'm sharing it too late at the point I'm using it in my messaging app.


The implementation is in rust and compiles to WASM for browser-based usage.

The aim is for it to align with the official implementation (https://github.com/signalapp/libsignal). That version was not used because my use case required client side browser-based functionality and i struggled to achieve that in the official one where javascript is used but is targeting nodejs.

There are other nuances to my approach like using module federation, which led to me moving away from the official version.

This signal-protocol implementation is purpose-built for a p2p messaging app. i posted about it a couple months ago here: https://programming.dev/post/44280693

Messaging app demo: https://p2p.positive-intentions.com/iframe.html?globals=&id=demo-p2p-messaging--p-2-p-messaging&viewMode=story

IMPORTANT: it's worth repeating that this is not audited or reviewed. Its far from finished and I don't recommend you use it in your code. It's open source for transparency.


Edit:

Cryptography with AI isn't well received. Going to unlist the post.

657
-22
submitted 6 months ago by yoasif@lemmy.world to c/privacy@programming.dev
658
17
submitted 6 months ago by cm0002@infosec.pub to c/privacy@programming.dev

Tails 7.5, a new version of the privacy-focused Linux distro that routes all internet connections through the Tor network, is now available with an upgraded Tor Browser to 15.0.7 and an updated Tor client to 0.4.9.5. Plus, the browser’s home page is now simpler, reducing clutter and improving clarity for users.

Another highlight on this update is that the system now installs the Thunderbird mail client as Additional Software when both the Thunderbird feature and Additional Software are enabled in Persistent Storage.

This adjustment addresses a recurring issue: new Thunderbird releases from Mozilla often arrive soon after a Tails release, leaving users temporarily on an outdated version with known security vulnerabilities.

659
29

Source is free to access (and highly recommended).

This is downer news. But remember that you are not helpless if you live in (for example) the West. We still have lots of political power and individual freedom compared to most other people in the world. If we want to keep it, it's up to us to get involved in politics. At the very least by voting. Cynicism and hopelessness will not solve this.

660
12
submitted 6 months ago by cm0002@infosec.pub to c/privacy@programming.dev
661
184
submitted 6 months ago by cm0002@lemy.lol to c/privacy@programming.dev
662
57
submitted 6 months ago by XLE@piefed.social to c/privacy@programming.dev

cross-posted from: https://piefed.social/c/privacy/p/1813919/privacy-cell-service-provider-cape-was-created-by-former-palantir-employee-funded-by-an

Selections so you don't have to click through:

I’m proud to announce that we’ve raised $61 million from top investors like A* and Andreessen Horowitz to accelerate our work in building America’s privacy-focused mobile service.

At Palantir, where I started in technical roles more than 10 years ago, I learned about a wide array of vulnerabilities in the cellular network that present a threat not only to mission-focused organizations in government, but also to everyday people. I came to see mobile phones — and the networks that power them — as perhaps the largest risks to our privacy and security.

If you told Americans twenty years ago that corporations and governments would conspire to attach powerful tracking devices to nearly every adult worldwide, it would’ve sounded like science fiction. And yet, that’s not far from where we are today.

John Doyle, CEO and Founder of Cape, ran the national security business at Palantir and served in the U.S. Army Special Forces as a Green Beret.

663
128
submitted 6 months ago by Blaze@piefed.zip to c/privacy@programming.dev

Discord cut ties with its age-verification partner after exposed code fueled federal-reporting concerns, months after a breach hit 70,000 users.

664
3
You sure, Discord? (discord.com)
submitted 6 months ago by cm0002@lemy.lol to c/privacy@programming.dev
665
71
submitted 6 months ago* (last edited 6 months ago) by cm0002@lemy.lol to c/privacy@programming.dev

The creator of Nearby Glasses made the app after reading 404 Media's coverage of how people are using Meta's Ray-Bans smartglasses to film people without their knowledge or consent. “I consider it to be a tiny part of resistance against surveillance tech.”

Paywall Bypass Link https://archive.is/pmgAO

666
37

Persona maintains a public list of subprocessors aka third-party companies that process your personal data on their behalf. "If your data leaks? Persona’s Terms of Service cap their liability at $50 USD. Oh and you're also agreeing to a mandatory binding arbitration: you can't take them to court."

https://nitter.net/Shin_Haruko_/status/2025626328251470174#m

667
45
submitted 6 months ago by Blaze@piefed.zip to c/privacy@programming.dev
668
78
submitted 6 months ago* (last edited 6 months ago) by higgsboson@piefed.social to c/privacy@programming.dev
669
24
submitted 6 months ago by cm0002@lemy.lol to c/privacy@programming.dev

Source

Pipe line.

TerminalPhone is a single, self-contained Bash script that provides anonymous, end-to-end encrypted voice and text communication between two parties over the Tor network. It operates as a walkie-talkie: you record a voice message, and it is compressed, encrypted, and transmitted to the remote party as a single unit. You can also send encrypted text messages during a call. No server infrastructure, no accounts, no phone numbers. Your Tor hidden service .onion address is your identity.

CLI Interface

Compatible with termux using the termux API application. The native termux app does not have the ability to pipe audio directly to termux. We use termux API to pipe this audio directly to the application. Install termux API, then install the application. Option 5 will prompt you for microphone permissions.

670
87
submitted 6 months ago by cm0002@lemy.lol to c/privacy@programming.dev
671
44
submitted 6 months ago by cm0002@lemy.lol to c/privacy@programming.dev

Mullvad also pointed to other instances of alleged attempts to “escalate censorship and mass surveillance” in the UK, citing efforts to force Apple to install backdoors in its end-to-end encrypted cloud service, proposals that could introduce “client-side scanning and government spyware on all UK phones”, and government plans to fast-track legislation requiring identity verification for VPN use.

672
28
submitted 6 months ago by cm0002@lemy.lol to c/privacy@programming.dev
673
24
674
70
submitted 6 months ago by Blaze@piefed.zip to c/privacy@programming.dev

Meta is weighing facial recognition for its Ray-Ban smart glasses, raising serious privacy concerns, but potentially offering accessibility benefits for the visually impaired.

675
165
submitted 6 months ago by Blaze@piefed.zip to c/privacy@programming.dev
view more: ‹ prev next ›

Privacy

5085 readers
235 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 3 years ago
MODERATORS