• 6 Posts
  • 10 Comments
Joined 1Y ago
cake
Cake day: Jun 25, 2023

help-circle
rss
Active combat against surveillance instead of passive defense
Examples of passive defenses against surveillance: * [Privacy Badger](https://privacybadger.org) * [uBlock Origin](https://github.com/gorhill/uBlock) * Using open source Linux rather than Microsoft Windows * etc. But why not actively combat surveillance instead of passively defending against it? Examples of active combat: * [AdNauseam](https://adnauseam.io) * [ScareMail](https://bengrosser.com/projects/scaremail/) * Emacs [spook.el](https://git.savannah.gnu.org/cgit/emacs.git/tree/lisp/play/spook.el?h=emacs-29.1.90) We must poison the data of those who are violating our privacy. Let us waste their time, increase their data storage costs, and waste their processing power. Let them drown in an ocean of data. Let them search for tiny needles in huge haystacks, with no way to distinguish between needles and hay. Some ideas: * Sending fake data to Google Analytics ([How does Google Analytics prevent fake data attacks against an entity's traffic?](https://security.stackexchange.com/questions/106892/how-does-google-analytics-prevent-fake-data-attacks-against-an-entitys-traffic)) * Create fake contacts lists to mislead those who are building social network graphs. * Encrypt lots of worthless data, store them in the cloud or send them by email. If the encrypted data is intercepted by any nosy entity, they will have to waste storage space while waiting to be able to break the encryption. What are some other possible methods? Let us turn the tables on those who have been violating our privacy. Why do we have to be on the defense? Let us waste their resources in the same way that they are wasting ours!
fedilink

What’s to stop the installer on Linux from configuring the service such that the service always runs on boot? e.g. systemctl enable malware.service.


If you did not enable end-to-end encryption for your WhatsApp backups on Google Drive, the US government could possibly compel Google to hand over your encrypted (but not end-to-end encrypted) backup, and compel Meta to hand over the decryption keys for the backup.

Details about how WhatsApp backup works: The Workings of WhatsApp’s Backups (and Why You Should Enable End-to-End Encrypted Backups).


Thank you for the feedback. I have added additional information to the original post. I hope that the additional information answers all your questions.


Should I always clear the web browser cache?
I am using Mozilla Firefox as my web browser. I have configured it to clear cookies, active logins, form & search history, and offline website data when I close Firefox. Should I also configure it to clear the cache? What are the privacy implications if I don't clear the cache? EDIT: additional information: * My goal is to reduce fingerprinting and tracking by websites. * I use Mozilla Firefox on my personal laptop that almost never leaves my residence. The laptop has full disk encryption. I am the only user of the laptop. * I don’t erase my web browser history. I want to keep browser history for my future reference.
fedilink


Why would I use this ChatGPT thing when I can self-host Llama 2 or Falcon, which is free and open source?


How to prevent keyboard and mouse fingerprinting in web browsers
If websites are able to track their users' typing behavior and mouse movements, then the websites may be able to use that data to fingerprint, track, and possibly identify their users. Is this a real privacy risk? If so, what are the methods to counter keyboard and mouse fingerprinting by websites? Note that I do not want to disable JavaScript.
fedilink


WhatsApp Web vs WhatsApp Android privacy
Does user privacy when using WhatsApp Web (`https://web.whatsapp.com`) differ substantially from using WhatsApp on Android? WhatsApp on Android has end-to-end encryption and (optional) encrypted backups. If I use WhatsApp Web, will Meta be able to see the contents of my WhatsApp messages?
fedilink

If and when Signal is packaged for F-Droid, how is the British government going to stop people in the UK from using Signal?



Chinese keyboard for Android?
Is there any open source and privacy-respecting Android keyboard for Chinese input? I want to avoid proprietary keyboards such as Gboard and Samsung Keyboard. Unfortunately, the open source Android keyboards that I found only support alphabetic input: * [OpenBoard](https://f-droid.org/packages/org.dslul.openboard.inputmethod.latin/) * [AnySoftKeyboard](https://f-droid.org/packages/com.menny.android.anysoftkeyboard/) * [Simple Keyboard](https://f-droid.org/packages/com.simplemobiletools.keyboard/) For Chinese input I would like pinyin input for both traditional characters and simplified characters. Handwriting input would be nice to have but it is not essential.
fedilink

Jami seems to have problems with message delivery. I was not able to send a message between my two Android phones. I have tried several times. Is anyone experiencing the same problem?

EDIT: here is a similar complaint: https://old.reddit.com/r/jami/comments/101cq00/why_is_jami_still_not_working/


Can uBlock Origin do everything that NoScript does?
I have installed both uBlock Origin and NoScript in Firefox. Does it make sense to use both at the same time? I was wondering whether or not uBlock Origin is able to do everything that NoScript does. If not, what does NoScript have that uBlock Origin does not?
fedilink

Why is Ecosia on the list?

Quoting from tosdr.org:

  • This service can view your browser history
  • This service may collect, use, and share location data
  • This service allows tracking via third-party cookies for purposes including targeted advertising
  • This service tracks which web page referred you to it
  • Your personal data is given to third parties

Doesn’t look privacy-respecting.