FineCoatMummy

joined 5 months ago
[–] FineCoatMummy@sh.itjust.works 2 points 23 minutes ago

“there’s no expectation of privacy in public places”

In the US, the judicial system is shifting about that. Slowly! But it is. There is a name for this legal theory which I forgot now. The idea is, once you string together enough individual data points, they enjoy 4A protection. Even if any one by itself wouldn't rise to 4A level. That means while you don't have an expectation of privacy, you DO have an expectation the gov won't use all that data to surveil you without a warrant.

Ofc, that only binds the government. It does NOT bind private co's! Google. Meta. A million data brokers. Flock! So it only addresses part of the prob. Is it good? Yes! But we also need protection against private collectors. In meatspace, we cannot block Flocks and randos with smart glasses. Or the total data fusion that results.

being able to pay my gas bill

Have you considered running two browsers? That's what I do.

I use one for things that have to know me anyway. Bills, utilities. Banking. W/e. It's FF based. It's locked down against analytics and trackers. But not to extreme levels. Required sites still work.

The other, for looking up games on vintage board game sites. Movie/TV shows. News sites. Stuff that has no gd business knowing my ID. That browser is normally Tor. If a site blocks it, fine. It isn't essential b/c all my bills and essentials use the other one.

[–] FineCoatMummy@sh.itjust.works 1 points 23 hours ago

AluminumOS

Thanks, I did not even know about that.

Do. Not. Want.

and not break websites?

That's the hard part! IME the more private you try to make FF, the more sites will break. Well not just FF prob any browser, but I noticed it with FF when changing about:config stuff to ressist fingerprinters and improve other privacy. BTW, Edge works since Edge is Chromium with some MS shit slathered on.

There's a bunch you can tweak in about:config. Like blocking battery charge queries. turning off various telemetry from Moz. Resist fingerprinting. Cross site referrers. WebRTC. Disable Google Safebrowsing! More private search engine. But the more you change, the more sites will break. In the end, FF with all privacy tweaks, is essentially equal to Librewolf. So if you have probs with LW, prob same with FF.

I have complained to a local utility co that their site breaks in FF. Called them up. They basically told me they get so few FF users they don't care and they told me to install Chrome. Everyone is on one of 2 phone browers, or a few on desktop Chrome.

Which is the prob with losing too much market share. It's a downward spiral of irrelevancy. But we need ppl using non-Chrome browsers, or G will fuck the web even more than it already is.

There is a whole ass other topic about Identity Resolution on the web and how more and more sites will block you if the identity resolver they use can't peg your meatspace ID.

OP has a righteous rant.

It's why we must never give up control of Linux to BigTech. It's OSS, yah... But there are lotsa ways they can weasel. Ex, see Google's h/w attestation. Or co's trying to monopolize the ecosystem. Or legal attacks. Or subtle ways to wrestle control, that most ppl won't recognize until its too late.

There are LOTS of important contributions to Linux by big tech co's. That's fine and good. We need that! But that's as far as we can let it go. Contributions, good. Taking control, bad.

Linux is a tempting target, since it isn't yet vassalized. Vigilance is critical.

after which you can run OOBE\BYPASSNRO to reboot into a mode that allows you to skip ms account setup.

“But the plans were on display…”

“On display? I eventually had to go down to the cellar to find them.”

“That’s the display department.”

“With a flashlight.”

“Ah, well, the lights had probably gone.”

“So had the stairs.”

“But look, you found the notice, didn’t you?”

“Yes,” said Arthur, “yes I did. It was on display in the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying ‘Beware of the Leopard.”

I really wanna give that time to be stress tested against Celebrite tho. Celebrite was able to get into locked devices. For all but the latest gens of iPhones and Andoids, which have better h/w security features. Older models they can access.

If we see that Celebrite isn't able to break the new GOS Motorolas, that'll be good to learn.

[–] FineCoatMummy@sh.itjust.works 4 points 3 days ago (2 children)

you can be compelled to unlock with biometrics, but not a password

Yah, I've been trying to get my friends to use a pw rather than biometric unlock, for that exact reason.

I'm batting like 0 for 5, lol. Biometrics are just too convenient I guess. Plus they don't think it will impact them personally. Which is prob true. I still think it's best to use the way that preserves more civil rights. I just can't convince them.

[–] FineCoatMummy@sh.itjust.works 13 points 4 days ago (5 children)

I don't have those chops either. Also NAL. The wiki page says Tampering charges require there to be an ongoing investigation, which wasn't the case here, so I'm thinking it wouldn't apply. But! I wonder about spoliation. Spoliation before a case is brought, while not illegal per se, can result in negative inference,

spoliation inference is a negative evidentiary inference that a trier of fact can draw from a party's destruction of evidence that is relevant to an ongoing or reasonably foreseeable civil or criminal proceeding

Negative inference, to my NAL understanding, means the tampered evidence may be taken in the worst light for the defense. Here, it's all resting on flimsy and politically motivated pretext with no evidence. Still.

Needs an immigration lawyer to give an answer to this, but I'm thinking it may be legally safer to have strong encryption and refuse to unlock, rather than to wipe. Not unlocking isn't tampering, so no spoliation, but wiping might be. Well, safest of all is to use a burner. But next best, strong encryption + don't unlock. CBP can confescate the device, but they cannot compel you to produce a pw or unlock code.

Oh, thank you! Bookmarked it.

[–] FineCoatMummy@sh.itjust.works 11 points 4 days ago (3 children)

There has too been talk about Google using it to block desktop OSs like Linux. By requiring validation against a QR you have to scan from an Android or iOS phone.

https://reddthat.com/post/69062683

I swear I saw that URL 5 times before realizing it probably doesn't belong to Redhat.

[–] FineCoatMummy@sh.itjust.works 3 points 4 days ago (1 children)

Some agencies insist suspects do not have access to those rights if certain conditions apply, such as being within one hundred miles of a US border (such as a coast),

It seems kinda nuanced tho. From various sources, the rules look like this. Ofc sometimes the rules may not be followed, that's a separate issue. This is just the rules CBP has,

  1. CBP agents can, with no cause, perform a "basic search". That means looking through photos, text messages, call logs, and emails. But not using tools or forensic methods.

  2. CBP CANNOT compel you to unlock the device for them or produce a pw. They CAN confescate the device if you don't, tho.

  3. CBP agents CANNOT perform a forensic search without reasonable suspicion and a signoff from a supervisor. A forensic search is one that uses external tools, not just the agent eyeballing your photos and messages after you unlock it for them.

  4. CBP agents CAN perform a forsensic search with reasonable suspicion, and a supervisor signoff.

  5. CBP CANNOT access cloud data from your device. Only data on the device is in bounds.

  6. CBP MUST follow a special protocol if the owner asserts certain privileges, such as attorney client priviledge, or protected medical data.

This leaves travelers in a position where they CAN assert their 4A rights when it comes to data on the device. But it comes at a price. It may lead to the confescation of the device. That is coersive ofc, and many ppl won't want to. So in practice, many ppl will cooperate and unlock the dev for the agent. But if you really want to push back, you can, and they have to let you into the country still if you are a citizen.

 

Link from the local news org

Link says he's charged with petit larceny, which is a misdemeanor in USA. IDK where the destruction of property charges land.

He's receiving donations for his defense from across the country.

 

Posting some recent good or funny news to say happy 4th to my fellow Americans. And happy Canada Day to our friends to the north. Not sure about Flocks exactly, but I heard of ALPR use in Ontario, maybe other provs too.

Gizmodo: Flock Cameras Have a People-Love-Smashing-Them Problem. People just aren't being very nice to these mass surveillance devices. A sticker with the note, “Hahaha get wrecked ya surveilling f***s” was applied to one of the poles below the spot where it was cut.

Several ppl doing it have been caught, often due to other Flock camneras who follow their movements across their city.

Also 100's of stories out there about municipalities across dozens of states not renewing Flock contracts due to mounting public pressure. It's not univerally good, some are looking toward other vendors. But many are stopping ALPR completely too!

Jalopnik: Unsure With How To Cancel Service, City Officials Are Covering Flock Cameras With Trash Bags Until They Can Be Removed. Dayton, Ohio's utility poles are sporting new accessories this week in the form of a black trash bag. Police and local authorities are working to cover the controversial Flock cameras installed throughout the city as they try to figure out how to severe ties with the company.

Citizen engagement does help. We need to keep the momentum going. Pls get involved locally if you can! A hundred ppl showing up at a city council meeting to speak out against ALPRs carries more political weight than 10 thousand emails.

97
I de-IOT-ed an appliance! (sh.itjust.works)
submitted 3 weeks ago* (last edited 3 weeks ago) by FineCoatMummy@sh.itjust.works to c/privacy@lemmy.ml
 

Gonna vaguepost so I don't self dox too much. Had to replace a dead appliance this week. Got a lightly used replacement, no choice about which. It had a wifi spot build in. It would talk to any phone with the mfg app. No auth other than having the app installed! WTF.

You couldn't disable that! Well not thru the panel controls. Web says you can do it with the phone app. IF you make an account with the mfg for your appliance first. Rofl!

Maybe this approach will help others. What I did was, searched the schematics online. Most appliances, you can find it. Searching model number + schematic often works. There are sites that catalog them.

Using the schematic, I found a connector that powered the wifi. Unplugged that. Re-powered appliance. Confirmed wifi was gone.

My neighbors are not gonna hijack my appliance over wifi, so I wasn't worried about that. I guess it could find an open WAP and phone home. TBH it was mostly the principle of the thing tho! I don't want ANY n/w on my appliances, thank you. Ya know?

It's a tiny skirmish in the war against IOT. Editing here to quote Aragorn, who famously said about IOT, "There may come a day when my appliances connect to the internet. But it is not THIS day!"

 

We don't get a lot of privacy wins. Ya know? I'll take whatever we can get.

I linked the wiki page for this court case. As of me typing now, page hasn't been updated with the court decision. Prob will be soon. If you want the rawdog court document, it's here.

TLDR. SCOTUS just decided that geofence warrants require 4th amendment protection. For the non-USA peeps, 4A is protection against gov searches without a warrant granted with probable cause. The court decided that since everyone now carries a smartphone everywhere, and loc data is highly personal, police geofence requests require a judicial warrant. In the same way one is required for the police to search your home.

Before anybody goes off about how "this doesn't matter"... This does not restrict commercial data collection. Even so, it does matter. It is a step in a good direction, and will have real world impacts. It might even change the landscape around Flocks. Another positive step happened a while ago, in Carpenter vs the United States, about historical cell site location data.

 

Have you tried them for privacy purposes? What are your experiences?

Here is mine. I've used the Visa prepaid cards. Where I live (USA) you can buy them "anonymously". Scare quotes because sure, nothing is 100% anonymous now. But you can buy them with cash and activate them without giving a phone #. Not quite as anonymous as cash, but close. It avoids the heavy data trail of a normal CC. And you can use them sometimes where you can't use cash.

But there's the prob. It's hit and miss if they work. Unfortunately, these are HUGE among scammers, so those scammer fucks poisoned the well. Some stores will flat out deny them. Other times, they work fine.

I've had probs at some point of sale terminals, others work OK. Ditto gas pumps. Seems to be no way to know which way it'll go without trying. Which means you gotta have another way to pay lined up.

I haven't tried them for online shopping yet.

 

Hey you beautiful privacy scoundrels! You magnificently private rascals and scamps!

I used this tool for a long time. Well I found something new and wanted to share.

Firejail is an easy single shot sandboxer. It's easier than spinning up a whole ass VM. You can read about it if you wanna. What I wanted to share is, the network part of it. Which I never knew about before today!

There's an option called netlock. What it does is, it tracks any outgoing network IP the sandboxed app connects to for 60s. Then everything after that is blocked. That will print the block list it uses. You can edit it if you want, as a base. Adding or removing addresses, w/e. When you are happy, you can save and use it with the netfilter option.

It's great for let's say a podcast app, that will connect to one or a few IPs, but should not send anything to anywhere else. Or even apps that should be 100% local, and you want to keep honest apps honest.

You can do all that with a VM too, by using firewalls and w/e. But this is handy for one off uses. Cases you don't want a whole ass VM. If you trust an app to not be a trojan, but you don't totally trust where it might phone home to. You can make sure it of what it's doing. Like block analytics, but allowing a legit network endpoint for functionality.

Full docs here.

 

The promise of technology was to expand our horizons. In many ways, it kinda did. We got a lot of awesome shit. But we also got {waves hands vaguely at everything} this dystopia.

I love tech! But I hate techno-surveilance. There are things I don't do b/c of it. Or things I do less now.

For example. I wanted to volunteer on a trail maintaining crew. But they're all TF over FB and Tiktok. They put everyone's photos on there. Vids of ppl working. They coordinate on FB groups.

I give up conveniences like google maps. Esp when those conveniences come with baked in surveilance. My friends mock my paper map. But w/e.

I take less road trips than I want. I hate having all my travel logged by ALPR. Even driving an old ass car without onboard GPS.

Are there things you would do, but you don't, b/c of techno-dystopia? Or you do them less?

 

Lawsuit in California, plaintiffs vs the Mouse, about facial recogmition in theme parks.

“When American families and their children visit a theme park, let alone a brand that’s as ubiquitous as Disney, they shouldn’t sacrifice their privacy rights when they enter,” Yagman said in a statement. “And as facial recognition becomes more common, and it proliferates in public places, especially, it’s more important than ever that we protect people’s privacy rights, because there are civil rights implications and privacy implications to collecting someone’s biometric information, especially without adequate consent, which is what we’ve alleged.

Seems to be.. the Mouse provides a way to bypass those lines. But that way is obscure and unclear to guests. So most ppl don't even know it is hapepning. Let alone which lines can bypass it.

the park has small signs at some security checkpoints notifying guests of the facial recognition policy, “but the sign is adorned with red, green, yellow, and blue Mickey Mouse silhouettes and is very easy to miss.”

This tech is also common, maybe unavoidable? at many sporting events in the US now. Major stadiums, that sort of thing.

 

Linked article about a lawsuit in California. AI was used to transcribe conversations between patients and drs. Audio is sent to the cloud for processing. This is becoming very common in healthcare now. Some sources say 80% of physicians in the US and Canada use these.

They aren't suing under HIPAA. Rather, under some California state laws.

Company says it is HIPAA compliant. That's prob true. They prob also make a good faith effort to protect the data. But it is impossible.

This event happened in Ontario. An AI transcriber breached confidental pt data, inc diagnoses, treatment notes, etc.

AI bot sends confidential info to Ontario hospital patients after recording doctors’ meeting

Even with the best intentions, there are endless breaches from electronic health data systems.

Also. Merely knowing your convo between you and your dr is recorded can change how honest ppl will be with their dr. You prob trust your dr. But when everything you say them is recorded, you may not trust what happens after that.

Fortunately most drs will let pts opt out of these, if you ask.

 

From the Beeb.

Law-abiding citizens have "nothing to fear"

The guy falsely stopped said he will appeal the ruling.

I don't live in London or even UK but I hate that these systems are becoming unavoidable. At least if you ever leave your house, lol. As London, so eventually Chicago. As Chicago, so eventually every one horse town. We're building out a world of complete, unavoidable surveilence. Even where you WALK, now.

I hate it. I hate it, and it won't end well.

I'm glad poor Orwell didn't live to see his nightmare come true.

 

So years ago I made an account on an online shopping platform. I took pains to do it as privately as I could. Shipping address as PO box. Didn't use real name to sign up. Masked credit card for payment. Etc.

I had it for IDK like 6 years? 7 years? I didn't use it a LOT, but let's say once a month avg. Over those years I had 100% the best feedback rating. I never caused any prob to anyone. I acted in good faith.

Suddenly one day... account canceled. Contacted company. They said send us copy of your gov photo ID. I said how about no?

I know it was b/c my account triggered some predictive anti abuse system. Scammers do a lot of what I did. Diff is, I was not a scammer. I just wanted some privacy. Wasn't even buying anything embarrasing. Just normal shit.

I thought since I got 6+ yrs of history, spend like mid 4 digits of $$ total, zero probs, perfect feedback for 6 years, I figured hey maybe I wouldn't be lumped in. But fuck me sideways.

Funny thing is. I had an older acct under my real name. It had LESS total purcahse history. By a lot. I never submitted any ID to create it. It's still there. It still works. Diff is, it's tied to my home addy and real name. It didn't trigger anti-abuse prediction. ANd it is prediction! I never abused anything, and never would.

More and more, I can't participate in the world, if I try to protect myself from data brokers that collect every fucking thing I do.

I'm sorry. I just had to rant lol. What is your experience with online shopping, if you try to set it up not tied directly to your name, phone, & home addy?

 

I found this, it's about the data broker loophole. The problem is, in the US we have 4th Amendment protection against warantless searches. Many other nations, have a similar right, by another name. Canada has Section 8 of the Charter of Rights and Freedoms.

These are more and more bypassed by data brokers. The government purchases data from data brokers. Data it could not get without a warant in the past.

Maybe this is not as much a problem yet in Canada as in the US? I'm not sure, hope some Canadians can say how it is? But here in the US, it's a massive prob now.

Related: We Built a Surveillance State: What Now?

view more: next ›