851
18
submitted 8 months ago by cm0002@lemy.lol to c/privacy@programming.dev
852
17
submitted 8 months ago by Blaze@piefed.zip to c/privacy@programming.dev
853
14
submitted 8 months ago by Blaze@piefed.zip to c/privacy@programming.dev
854
32
submitted 8 months ago by cm0002@lemmy.cafe to c/privacy@programming.dev
855
21
submitted 8 months ago by cm0002@lemy.lol to c/privacy@programming.dev

Learned a lot from this essay/presentation. One point that I "liked" is how Trump and US based big tech virtually (pun intended) hold other countries hostage, either with export/import tariffs or by threatening to stop trade ("adapt this policy or forget about trading with us") or with sensitive data.

Also, this is the organization that he is working for. They have some tools for and guides on privacy too: https://www.eff.org/

856
107
submitted 8 months ago by Blaze@piefed.zip to c/privacy@programming.dev
857
37
submitted 8 months ago by Blaze@piefed.zip to c/privacy@programming.dev
858
40
submitted 8 months ago by Blaze@piefed.zip to c/privacy@programming.dev

cross-posted from: https://lemmy.ca/post/57669143

859
17

I came across this video: They Asked For My Name. I Said No.

She had to do a purchase online and used a :

  • Private mail box
  • Privacy.com to create a virtual card just for that purchase
  • SimpleLogin to create an email alias
  • Cloaked to get a virtual phone number

This all seemed a bit excessive to me, but I wonder in general how do privacy enthusiasts purchase things online from: a) Sites that they can "trust" b) Sites that they can't "trust"

And what about offline? Do you guys use things like Google / Apple Wallet? Do you carry physical cards? Or do you not use cards at all and just pay by cash?

--

I used to use Google Wallet, but I have switched to GrapheneOS so that no longer works, I need to substitute it to curve pay but I'm kinda considering maybe I don't need it at all? Perhaps just carry the card with me, instead of adding yet another company that sees all of my purchases accepting all the downsides that this will give me. Or just use cash.

As far as online purchases go, honestly I don't do anything special other than creating a disposable virtual card just for that purchase, which made me think maybe I'm exposing myself too much, especially on smaller sites that I can't trust. That being said, I don't really know what I would do to change that.

Thoughts?

860
11
GPG (gpg.fail)
861
10
OpenKeychain · OpenKeychain (www.openkeychain.org)
submitted 8 months ago by cm0002@toast.ooo to c/privacy@programming.dev

Sorry if this is yesterday's news to you all, but I just found out about this Android app that makes it easier - as in, less steps - to encrypt and send any message in a highlight-copy-paste fashion, with automatic integration in several e-mail front ends.

It still receives security updates and the repo is still maintained, but the app is no longer being actively developed to add new features. https://github.com/open-keychain/open-keychain

862
36
submitted 8 months ago by Blaze@piefed.zip to c/privacy@programming.dev

Earlier this year, both chambers of Congress passed the TAKE IT DOWN Act. This bill, while well-intentioned, gives powerful people a new legal tool to force online platforms to remove lawful speech that they simply don't like. The bill, sponsored by Senate Commerce Chair Ted Cruz (R-TX) and Rep....

863
41
submitted 8 months ago by cm0002@toast.ooo to c/privacy@programming.dev

Smart TVs with an internet connection: Lets grab screenshots and send them to cooperate analysis advertisement department.

864
33

The core insight here: privacy isn't this monolithic thing where you're either completely anonymous or completely exposed. The author breaks it down into these two approaches - tracking reduction and tracking evasion - and that distinction actually matters a ton in practice. Someone worried about targeted ads has completely different needs than someone trying to avoid state-level surveillance. Both are "privacy concerns" but they're worlds apart in terms of what you'd actually do about them.

The things that make you better at tracking reduction often make you worse at tracking evasion, and vice versa. It's not just that they're different approaches - they can actively undermine each other. This is the part that most privacy guides completely fail to explain, and it's why you see people with these Frankenstein browser setups that are actually less private than if they'd just picked one coherent strategy.

865
38
submitted 8 months ago by Sunshine@piefed.ca to c/privacy@programming.dev
866
234
submitted 8 months ago by cm0002@mander.xyz to c/privacy@programming.dev
867
167
submitted 8 months ago by Blaze@piefed.zip to c/privacy@programming.dev
868
120
submitted 8 months ago by Blaze@piefed.zip to c/privacy@programming.dev

With the Chat Control bill entering its final stage, the EU Council has been busy thinking about what a new data retention framework could look like.

869
19
submitted 8 months ago by Blaze@piefed.zip to c/privacy@programming.dev
870
18
submitted 8 months ago* (last edited 8 months ago) by InternetCitizen2@lemmy.world to c/privacy@programming.dev
871
19
submitted 8 months ago by cm0002@infosec.pub to c/privacy@programming.dev
 With over 3 billion users globally, mobile instant messaging apps have become indispensable for both personal and professional communication. Besides plain messaging, many services implement additional features such as delivery and read receipts informing a user when a message has successfully reached its target. This paper highlights that delivery receipts can pose significant privacy risks to users. We use specifically crafted messages that trigger delivery receipts allowing any user to be pinged without their knowledge or consent. By using this technique at high frequency, we demonstrate how an attacker could extract private information such as the online and activity status of a victim, e.g., screen on/off. Moreover, we can infer the number of currently active user devices and their operating system, as well as launch resource exhaustion attacks, such as draining a user's battery or data allowance, all without generating any notification on the target side. Due to the widespread adoption of vulnerable messengers (WhatsApp and Signal) and the fact that any user can be targeted simply by knowing their phone number, we argue for a design change to address this issue. 

easy-to-use implementation of the attack: https://github.com/gommzystudio/device-activity-tracker

signal developers discussion about it https://github.com/signalapp/Signal-Android/pull/14463 (WONTFIX)

872
305
submitted 8 months ago by cm0002@infosec.pub to c/privacy@programming.dev
873
20
submitted 8 months ago by cm0002@infosec.pub to c/privacy@programming.dev
874
97
submitted 8 months ago by Blaze@piefed.zip to c/privacy@programming.dev

The GDPR is Europe’s defence against digital oligarchy and child harm. Deregulation plans are misguided, say Johnny Ryan and Georg Riekeles

875
126
submitted 8 months ago by Blaze@piefed.zip to c/privacy@programming.dev
view more: ‹ prev next ›

Privacy

5091 readers
139 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 3 years ago
MODERATORS