• 2 Posts
  • 72 Comments
Joined 1Y ago
cake
Cake day: Jun 15, 2023

help-circle
rss

That’s not how end to end encryption works.

Your scared of a slide to the right but already falling for their propaganda to undermine privacy by destroying encryption.


Here you go:

“Google makes the most secure phone. Including for securing your phone against Google.”

Its better then explaining you rather risk your data security then buy a phone from Google.


I like grapheneos the product.

The staff is super abrasive and they constantly attack other privacy projects. See the recent attacks on Jonah from privacy guides, or the attacks on calyx, or the bs with rossman that forced micay out of the spotlight.

They need to hire an outside professional to manage their PR. The way they communicate is their biggest flaw.



The app was bought out 9 months ago by some mystery company, isn’t actually open source, and you have not switched or made backups? I’m sorry, this is as much a user error as an issue with Raivo.


Let be honest, If your threat model is truly to escape the NSA you probably shouldn’t be risking being on social media.

I think part of the reason people dismiss the idea that someone could have that big of a threat model is in most cases it would be unbelievably bad opsec to risk talking about your threat model on social media or something like the privacy guides forum.


I really appreciate privacy articles that talk about threat modeling as it seems like its the biggest part of privacy people miss.


You shouldn’t be installing extensions on mullvad browser anyway. This completely ruins it’s anti fingerprinting measures, which is one of the biggest reasons to use the browser. If your going to install extensions use Firefox or Brave.


If someone can identify you through your lemmy username an admin isn’t going to save you from your terrible opsec practices.

Lemmy is a social media service. Act accordingly.


Why would “community vetted” imply FOSS?

Microsoft has a massive community of users and sysinternals is highly regarded amongst amateur and professional users alike. The term “community vetted” makes perfect sense in this context.


Another case of a user with terrible opsec that proton will end up being blamed for.


Mullvad, IVPN, Proton, AirVPN, or Windscribe are all fine. Depending on how much stock you put into audits the first three are probably a tier above for privacy.


What don’t you like about IVPN? Audited, open source, great reputation. I don’t even use them but seems odd to count them out.


“I’ve searched the web for my name, home, and phone number. Haven’t found anything on myself yet.”

All this means is your not very good at finding that info. You even stated there are 53 pending brokers, meaning that info is available online.

“Your information is already out there”

This is kind of an odd line of reasoning to hide behind. One one hand you are willing to pay to have your data removed, on the other hand you don’t mind a service actively handing over data because its “already out there”

Again this isnt specific to easyoptouts. Other data removal services do this as well. It would be less of an issue if once your data is removed its permanent but there is nothing stopping brokers from re-adding you, and now your on the radar of new brokers.


The only concern with easyoptouts is they will send requests to brokers they are not sure of, which can lead to data brokers who had no data on you now being sent it. This is not a specific problem for them, as other services do this as well.


You can go to inteltechniques and peruse their data removal guide. That is basically a massive list of brokers / sites that may have your data.

https://inteltechniques.com/workbook.html


What would even be the need for this extension? Safari automatically switches sites from HTTP to HTTPS if available.

This extension is kind of a fossil at this point as almost every browser does this on its own. Not to mention its not 2004, you shouldnt be running into a lot of http sites anyway.


Tor is the best option of anonymity but, its bad opsec that you really have to worry about. There is no platform that can save you from yourself.


I think you and your girlfriend should read about “threat modeling”. You need to figure out what you and her are trying to keep private and from whom. Without knowing that, its impossible to say if a VPN is a good solution.

For example if she is trying to hide her web traffic from her ISP then a VPN is a great solution, if she is trying to be annoymous on the web then a VPN won’t do much as you are still easily fingerprintable amongst other things.

People all to often act like privacy is some sort of list of sub items that you can check off like completing a quest in a MMO.

Each individual’s privacy goals are different, privacy is not a one size fits all problem or solution. Your girlfriends needs may be drastically different then your own.


I would break it up into different catagories.

Your interest in digital privacy is something you can use to talk about your interests and what drives you.

The skills you learned from it is something you could use to supplement how you have progressed other relevant skills for your degree or job your applying to. Be specific about what you did and what it taught you and how its relevant.


If your using a vpn its pretty much unavoidable. You could opt to use a vpn service that offers a static ip, since not sharing an ip with a bunch of other users will reduce your browser being flagged but, that comes with privacy trade off


Way more. Lineage is not a very good rom in terms of privacy and is an awful choice in terms of security. Both Divest and Calyx are better choices.

Lineage as the name implies is best suited for end of life phones that you need to keep working. Which i would avoid anyway as you are not getting any security updates leaving your phone extremely vulnerable.


If your not going to go with a pixel, the best alternative is a new samsung phone with Divest OS.

Samsung is the closest in terms of meeting GOS hardware requirements (it still doesn’t) and Divest OS is the next best privacy respecting ROM.



Its part of proton drive. Drive has a section for photos.


Proton offers a cloud photo storage similar to Googles but its all E2EE. A bit clunky compared to google but much more privacy friendly.


Id put it this way. Until lack of encryption is an issue for carriers and not a source of revenue, there wont be an incentive.


These all seem like pretty run-of-the-mill dns requests. Are there specific requests that give you some pause?




No. The 14 eyes fear mongering was always just marketing and not a legit reason to avoid a vpn.


Ahh i see.

Yeah it really slims down your VPN choices as having an IP address associated with your account makes it much more identifiable. So some providers wont offer them (such as mullvad).

It also usually costs more. The one I know offers a static IP is express VPN and ive heard Proton has plans on offering it. It looks like PIA offers it too.


If targeted correlation attacks are part of OPs threat model what OP is asking for isnt going to work anyway


It would be a lot easier to just use a vpn and hide your traffic from your ISP that way.


What info would an admin even have? Just my public ip and my email?


Just as i thought, posted by a 2 day old account. Better then the image throwup of 4 chan posts i guess but still dumb af


At that point you should probably use a cloud based solution anyway. Any decently secured system wouldn’t let you plug in a random usb drive anyway.

I had assumed the use case was more for travel not for trying to access sensitive data on systems that you have limited access.


Its available on linux mac and windows so id say it’s pretty portable. You could even keep unencrypted installers on the same thumb drive in case internet access is an issue.


Yeah i dont see how this would be better then a run of the mill thumb drive (that doesnt scream im worth stealing) and just creating a cryptomator vault on it.


What would i be searching for that’s so difficult to find that I would pay for Kagi? Especially when there are multiple options for good free search engines.



PSA - how to enable SponsorBlock extension on Mullvad Browser
Thought this might be helpful to others who use Mullvad Browser. Got to the advanced preferences and set webextensions.storage.sync.enabled to true.
fedilink