1
 
 

I keep hearing bad stuff about proton, but I don’t really get most of it. Could someone please explain all of the controversy to me. Lastly, what are the best alternatives to all of their services?

2
 
 

I was orginally going to post to c/showerthoughts.... but then I thought it might fit in better here.

3
 
 

So I saw a post about Obscura VPN and went to do a deep dive and some reasearch on it. Then I came back to comment and the post was gone!

So, anyway, I wanted to share what I found since it actually is quite interesting and there are a few red flags.

Obscura is owned by Sovereign Engineering Inc. registered in the United States. Willingly chose to register the company in the US for some reason. This is a major issue due to the US being one of the few places in Five Eyes, and being able to issue log mandates and gag orders without allowing a company to get a lawyer and fight it.

The founder, Carl Dong, talks in multiple interviews about how his inspiration was the Chinese Great Firewall: https://www.truefans.fm/bit-buy-bit/6a980688566a94f95bc291b1?tab=transcript https://noderunners.network/en/media/podcasts/hell-money/bitcoin-core-dev-walks-away-to-battle-the-great-firewall-of-china-with-carl-dong/187302

They also take VC Investor money:

Yes, we do have VC investors.

This may be a concern when choosing between “Traditional VPN” providers (Single-Party Relays) since you need to trust them wholly.

However, I believe this is much less of a concern with Multi-Party Relays like Obscura since a MPR provider will never have both your personal info and your traffic.

Additionally, it is much easier to switch between VPN providers than it is to switch between “cloud drive” providers (for example) since VPN providers don’t store anything you’d need to transfer.

Source: https://discuss.privacyguides.net/t/mullvad-has-partnered-with-obscura-vpn/24860/175

And when asked who the investors were:

We specifically chose investors who’d be strongly supportive of our stance on Privacy and Digital Freedom, so I’m not sure they’d appreciate us listing their names on a public forum :sweat_smile:

Source: https://discuss.privacyguides.net/t/mullvad-has-partnered-with-obscura-vpn/24860/179

He refuses to answer.

I hope this info on them helps anyone who might have been considering them make their decision in a more informed manner.

4
5
submitted 2 days ago* (last edited 2 days ago) by to c/privacy@lemmy.ml
 
 

Free, open-source Lightroom-style RAW editor for Linux, Android, Windows and macOS. GPU-accelerated, non-destructive, with masks, HDR merge and local AI. - Duecki1/CalibRaw
(Lemmy's automatic link summary)

After a five year pause I finally bought a camera again to take up photography again. Back then - which might have been even further back, my memory is a bit fuzzy - I frantically looked for alternatives to the Adobe ecosystem, which both requires a subscription with a monthly fee and comes we the typical app trackers.

CalibRaw, which I just discovered, seems awesome!

BGIAFFDNMarQHkL.jpg

Canon FD  F/2.5  135.0mm  |  OM System OM-5  1/25s  ISO-200  

It asks for permissions to

  • post notifications: easy to block if you prefer to. This is the only permission flagged as "dangerous" by Muntashir Al-Islam's AppManager.
  • connect to the internet to check for updates: I block it with a root based firewall, but I guess you could block it with a hosts file or a firewall that uses your VPN slot too.
6
 
 

Five years of your social media just to visit the US on an ESTA, and 50,922 phone searches at the border in a single year with no suspicion needed. Part 1 of my Five Eyes series: who else gets to see it?

7
8
 
 

When using the noai domain + html instead of just providing the URL to the website a redirect website through Duckduckgo is provided.

Here's an example:

https://noai.duckduckgo.com/html?q=cloudflare+speedtest has:

https://noai.duckduckgo.com/l/?uddg=https%3A%2F%2Fspeed.cloudflare.com%2F&rut=7308a8bf028168b377d5ba5ac7f2669efd5d25f87445327fa6ba22aa5db85355 as the URL for the first result instead of speed.cloudflare.com.

That URL will change the window location with javascript to the correct website or HTML redirect if javascript is disabled. In the paramaters uddg is the URL to redirect to and rut is an identifier based on the URL it redirects to.

I'm not sure why it only happens with this specific combination of search, can anyone else check if this happens?

Also, I'm not sure if this is the correct community to post to but !duckduckgo@lemmy.world is dead and this is sort of privacy related because this can be used for tracking. Sorry if this is the wrong community for this kind of post.

9
submitted 5 days ago* (last edited 5 days ago) by to c/privacy@lemmy.ml
 
 
1.
👨📺🕊️📱⛔
🕊️📱➡️🤖🍏📱
🤖🍏📱📈
🕊️📱📉
2.
👶🧑‍🎨
👶💭🌐🖼️
👶🌐🖼️⛔
👶📺📱✅
3.
👨&🕊️📱
👨💭📺🕊️📱
🪪📱🔛🕊️📱⛔
👨📺🕊️📱⛔
🕊️📱⛔
4.
👶💭📺📱
📺📱👶⛔
👶1️⃣0️⃣💶➡️👩
👩🪪➡️👶📱
👶📺📱

(🕊️📱🟰🐏🐧, 🤖➖🇬)
(🕊️🟰🗽)
10
11
 
 

The title rhymes!

If you're begrudgingly using Aurora Store because you need it for whatever reason, there's a small thing you might want to be aware of to increase your privacy.

When selecting anonymous account, you're still sending some metadata to Google. As F-Droid warns on the Aurora Store page:

By default, the apps list and system details are sent to Google Play servers, which is likely enough data to fingerprint the device.

In other words - here be dragons.

If you're gonna do it though, along with the obvious precautions, you can use Tor strictly for the connection to Aurora Store. Here's how: download Orbot, go to orbot settings, general, enable power user mode. Go back to the main menu and note the Socks Port number (default 9050), click connect. Go into Aurora Store, settings, networking, click on proxy Url and enter

socks://127.0.0.1:9050

or whatever your socks port was. You can also type localhost rather than that IP most of the time (but I've seen the app bug out randomly).

Now you're connected through Tor without having it on system wide.

You're still giving valuable data to Google, but at least you're mixing yourself in with the pool of Tor users. Whether this can truly stop Google, who knows.

VPN is basically always blocked so if you're also using that, you'll need to enable split tunneling for Aurora Store (note this is technically a privacy risk).

Even still, Google will block Tor from time to time. You can play around with Orbot a bit to try making it less common, but Aurora Store is buggy at the best of times.

But I know people will use it anyways, so you might as well make things a bit more private. When possible, use Obtanium or F-Droid instead. F-Droid has built in Tor as well. There's probably a bunch of other stuff you can do, but this was the least documented bit I came across personally.

12
 
 

idk if someone already asked i cant sreach good bc my english is bad

threat moodel: surveillance captialism/policing doxxers, home and public network, isp,

i hate fingerprinting the most :enraged_face:

i love not having my ids connect to each other

i want to

**download videos/music/books/games (mostly pirated) (AND PLAY THEM)

moreno

chat/scroll normal websites (the ones aervage people use)

use javascript (every site wants it)

email encrypted**

tor browser is too slow is mullvad and vpn ok?

i cant post to r/privacy my account isnt old enough ((((

other privacy baed subreddits downvote bc of my bad spelling

13
 
 

I made up the title b/c the URL is to the court's finding. Doesn't have a title per se.

TLDR (ruling is 38 pages, so this is BRIEF gd!)

Driver was stopped for following too close. Officer gave warning, but no citation. Officer ran ALPR history, then searched car based on ALPR. Driver admitted to having marijuana in the vehicle, which officer said he didn't care about, and was only after hard drugs. ALPR history had driver driving a long distance for a short visit to the state.

Court ruled:

  1. Traffic stop was legal and justified by observed violation. Officer had reasonable basis to stop driver.

  2. The subsequent search was NOT constitutional, since officer did not have a warrant for ALPR data, and had no reasonable suspicion of criminal activity.

Result from ruling,

(Driver) has a reasonable expectation of privacy in the location data which tracked her movements over several weeks. .... The ALPR search was an unreasonable governmental intrusion of protected privacy rights.

Vehicle search result was quashed.

There's lots more nuance in the linked filing. Also citations. It's really good IMO. It balances the privacy of the driver's vehicle with the legit justification for the stop. It also notes how "persistent, dragnet surveilence" differs from other kinds. Kudos to judge Sara Hill for really digging in and understanding the privacy issues, esp around pg 28+ of the ruling.

It's long but totally worth a read. The case does not set a binding precedent.

The legal situation is FAR from perfect. But I hope just once we can have a thread where a ton of ppl don't immediately go, "this good privacy news is useless b/c it does not solve every single problem every single time!" It is evidence in favor of a slow but meaningful shift in ALPR jurisprudence. It stands along side recent SCOTUS rulings that also boost location data privacy, like Chatrie v United States and Carpenter v United States.

14
 
 

cross-posted from: https://lemmy.world/post/52666693

Another win for privacy <3

15
 
 

This is interesting and i'm already wondering how to fight this war. AI is really useful if used in the right way, like search engines once were. But how do you trick these systems to not profile you? I don't have any chatgpt account and only use the browser. Chatgpt has already told me it fingerprints the session but cant tell its me unless i tell it. Ha ha ... isn't a browser plugin that changes the fingerprint each session going to help? Also, how do i tell the browser to stop dishing out my data e.g. browser version, os version, etc.?

16
submitted 1 week ago* (last edited 1 week ago) by to c/privacy@lemmy.ml
 
 

Old man alert. Nerd alert. EXTREME snoozefest alert. You've been warned, continue reading at your own peril!

originally posted in /c/technology but was removed quickly, presumably because it's not considered a tech article or news. This is probably the better fit anyhow

For those who aren't familiar with the Brave browser, its history and controversies, or Gecko engine vs. Chromium engine (and loosely, Webkit), it's probably worth reading up on first. I'm writing this with the assumption that you know all of this stuff, because otherwise this post would be an even longer novel than it already is.

Brave recently released a paid version of their browser called Brave Origin which strips out a bunch of "features" like web3, AI, crypto, telemetry, etc.

It has a dedicated installer separate from the normal browser, except on mobile where the features can be batch disabled after verifying your license. You can also do it that way on the desktop version if you want to. Apparently a standalone android Origin app may be in the works, and the licensing system does seem to be relatively privacy preserving and not overly restrictive.

It's pretty damn expensive (except for Linux where it's free). And I must say that I feel like an outlier, because I strongly approve of this release and the direction I'm seeing the company take.

Let me state these right now:

  • Brave's controversies are real and they were completely unacceptable and they are a permanent mark on their reputation. It's no wonder many distrust them.
  • I'm fully aware that this still indirectly utilizes Google's work, and that Google creates open source projects, pumps a ton of money into them, gets a ton of contributers on board, and then starts introducing proprietary blobs which handicaps competition while effectively squeezing free work and investment out of others.
  • I love FOSS with all my heart.
  • I could add a bunch of disclaimers but I'll address them if I see something in the comments.

In a perfect world I would hate Brave's decision. In our current reality I think it's about the best move they could've made as a for-profit company outside of just creating their own browser engine. But there's a reason there are so few options for engines right now, and it's because it's really fucking complex to make one and it takes a fuckload of time, money, and resources. When somebody develops a genuine engine contender, I'll need to circle back.

Many of us use Firefox (or FF fork) with extensions. Many use ungoogled Chromium or other Chromoum forks. Obviously totally fine.

But there's a few issues with the current browser space, as I see them.

First is that the reality is, much of the web now treats Chrome (rather, the Chromium engine) as a first-class citizen. Some sites run significantly faster or more reliably on Chromium. Some sites require Chromium to fully function. For example, want to use the GrapheneOS web installer? You need a Chromium-based browser. Chromium has lots of features under the hood that the modern web utilizes. If this has never been a consideration for you, then this particular point is moot.

Second is that data harvesting and tracking is becoming wayyy more advanced than even some techies might know about - and let's be real, it's becoming pretty fucking exhausting to keep up with the growing pile of bullshit being thrown our way. It's also becoming harder and harder to stop. In both Gecko and Chromium you can, to varying degrees, install extensions, use browser forks, adjust settings, etc. to prevent much or even all of this. But the absolutely unfathomable amount of money being poured into violating your privacy needs hard, sustained, expensive work to fight in meaningful and new ways. One recent example I read about is brave implementing a new GPU anti-fingerprinting measure which is something I hadn't even considered before.

Third is that the Internet of today is just straight-up busted. Yes there are super cool projects in the works such as I2P that are trying to change that. But they're not reaching mass adoption any time soon. Most people can't even bother trying to leave for places like Lemmy and that's much less friction than I2P. I absolutely am not defeatist, and I fight this shit like the plague it is, but we also need to live our lives.

Fourth is that the way we use the internet varies. There's a lot of things we could do to make sure we're always maximally protected, but usually we find a balance. Stuff we daily drive, stuff we use when there's a specific need, stuff we're forced to use. If you're hardcore enough to do things to the max at all times then you don't even need to read this - you can browse in Mullvad Browser with (or without) a VPN or the Tor Browser, and supplement with OS and hardware privacy measures, etc... and you're likely better protected for it. But for me, and I suspect for many others, in typical daily use we want the right balance of speed, usability, privacy, and security.

Those "features" that brave bundles in are really shitty. But the mass market time and time again shows they'll put up with a lot of bullshit. And for most people you can just manually toggle the majority of these things off in the main browser for free, and it doesn't take more than a few minutes. These features, like it or not, pull in a lot more money than what most non-profits get when solely relying on donations. Hell, one of the huge things keeping Firefox propped up is their search engine deal with Google, not the donations.

Brave, like it or not, does provide some pretty compelling value in other places. First and foremost it's good to see people seeking out alternatives to Chrome for literally any reason. But they are admittedly super on-top of their Ad-blocking, anti-fingerprinting, other privacy features (like the shred tab button), and update cadence. They're the closest thing to a well-funded Chrome competitor that, unfortunately for our reality, runs on Chromium.

I get that it feels wrong to pay to remove features from your browser. But you know what, I'm sick of the micro transaction ad filled privacy invading bulls hit joke of an economy the internet has accepted at large. If it were up to me I would bring back freeware and shareware. Brave is the modern day WinRAR in an alternate universe where 7zip wasn't invented yet and the built in unzip still didn't support other formats.

I'm going to continue using my Gecko based browsers as I always have. But for when I want or need something from Chromium, I think Brave Origin is my new go-to. For me that's when I need certain hardware integration or I'm on a specific site, and chromium in my experience works very well with Android. One other thing I learned which to me is a definite plus, is that it was developed by the Ex-Ceo of Mozilla and creator of JavaScript (that was cool to learn, and that's one guy btw, not two).

For those who think this I'm suspiciously positive about Brave, I get it. I literally thought of brave as spyware until I read about Brave Origin. I think it's a sincere effort to correct course in a way that let's them operate at the level they need to maintain their product. For most people reading this who feel like trying Brave, they should just spend 5 minutes adjusting the browser settings. If you're clinically insane like me, and you actually resonated with this post, then maybe try it. And if you wanna buy it and chargeback or find a torrent or whatever, I don't really care.

I suppose this post is solely about Brave if we lived in a vacuum. But actually I think it's about sharing a mindset which I think can help the internet improve just a little bit, Brave or not.

Finally, let me end on a tangent about Alphabet Inc., mostly Google. That company is full of very smart sociopaths people who grabbed the internet by its collective ballsack, and while it may have felt good for a minute, they started squeezing them until you forgot what it feels like to have your balls flapping in the wind again. They made AOSP and then fucked us. They made Chromium and then fucked us. They did the heavy lifting for RCS and then fucked us. Google fucking sucks. And RIP to the word 'googol', you were robbed.

Honourable Webkit mention for Orion browser, and also their search engine Kagi which I fucking ADORE!

Tl;dr Brave Origin is alright, maybe try it, or don't.

17
 
 

Hey everyone!

Quick preamble: I'm going to be posting a proper bug report. In the spirit of GrapheneOS and this community (privacy) my details will be kind of generic here. Phone is a modern a-series Pixel.

Is anyone having notably more bugs in the last few days or so?

A few examples:

Fingerprint flickering on touch with erratic behaviour, the boot options after holding the side button do not register presses properly making it difficult to even reboot. I was stuck in this cycle for a few minutes. Fix on reboot.

Switching profiles lockscreen bug, when switching back to the owner profile, the home screen with app icons is displayed in the background of the lock screen for a few seconds, before switching back to the proper lock screen background.

Certain notifications, if timed just right while the screen shuts off, persist on the lock screen until they naturally fade.

Now that I'm typing these, they all seem to be related to the lockscreen in some way. Using default launcher.

So, anyone else experienced an uptick in bugginess lately? I read through the recent release notes and didn't see any obvious indicators, but I'm not certain.

Would like to hear from other GrapheneOS users!

Also, if you want to take your privacy and security seriously, please consider switching to GrapheneOS if you haven't already and are able to. It's the best we've got right now as far as privacy and security in a mobile OS goes.

Cheers!

18
19
 
 

More information in hackmeeting.org

20
21
 
 

Repo: https://github.com/ontoplano/ontoplano

Demo: https://demo.ontoplano.com/

  • modular (you can deactivate features you don't want to use)

  • integrable (Webhooks, REST API, MCP server)

Just one place to keep all your personal organisation data, easily integrable, in case you want to do something else with this data.

22
23
24
 
 

I shared Paperweight earlier here as it was being actively developed and still in beta. After almost 7 months, I'm excited to finally release Paperweight V1 as ready 🗿

Paperweight uses your inbox to map your digital footprint, then helps you take back control and delete your data.

Your email history contains traces of most of your online life. Accounts you created, companies you bought from, mailing lists you joined, services you forgot about, breaches, and personal information accumulated over the years.

Paperweight helps to map your footprint, take back control and delete your data. All locally on your computer.

V1 now includes:

  • discover accounts, companies and services connected to your email
  • find mailing lists and subscriptions
  • show known breaches affecting services you use
  • find personal information across your email history
  • bulk unsubscribe and clean up old email
  • create privacy and data deletion requests
  • manage multiple email accounts
  • connect to AI agents through MCP

It supports Gmail, Microsoft, Apple, custom IMAP and Proton Mail via Bridge.

The important part for me from the beginning was privacy. All your data stays on your computer. There is no Paperweight backend or external services processing your inbox.

It's also fully open source under MIT.

The free version now includes full-history scanning and discovery, so you can map and inspect your entire footprint. A Pro license makes it actionable. It gives you ease of use, compiled binaries and support and helps support (OSS) development.

Website: https://paperweight.email/
Source: https://github.com/wslyvh/paperweight

25
 
 

most e-commerce has all my personal info including KYC and my full product ratings, and recently i realized that i already given my full address, legal name, phone number, bad ratings and some photos, etc on this e-commerce. i tried contact the customer service but they said they cannot remove any of these data and its permanent.

should i worry about this?

view more: next ›