davel [he/him]
Pronouns he/him
Datetime Format RFC 3339
  • 2 Posts
  • 217 Comments
Joined 2Y ago
cake
Cake day: Jul 08, 2023

help-circle
rss

Chilling. The difference was like night and day.





ActivityPub DMs are not encrypted between servers

It is insofar as TLS/SSL/HTTPS encryption is used in transit. That’s what I mean by encrypted in transit.

i could read anyone’s DMs to users on other servers

If you’re an administrator for (WordPress) ActivityPub server A, you can see all the DMs coming to and leaving from your server, yes. And they’re not encrypted at rest, so you can read them any time. But how would you see DMs going between server B and server C, when your server isn’t involved in the transaction?


Surprisingly, Reddit is NOT on the list.

If they’re slurping all these other sites, I highly doubt they’re not slurping Reddit, too, even if it’s not on the list.

Fediverse (likely ActivityPub - possibly DMs between servers)

They would have to hack the individual servers to get at the DMs, because they’re encrypted in transit. All the public stuff is trivial to scrape.



I don’t see as any worse, necessarily. For all I know, Saudi Arabia was previously buying the data from Niantic piecemeal.

Forbes, 2016: How Niantic Is Profiting Off Tracking Where You Go While Playing ‘Pokémon GO’


You’d have to fill out the paperwork coming and going. If You Deposit a Lot of Cash, Does Your Bank Report It to the Government?

Depositing $10,000 or more in cash means your bank or credit union will report it to the federal government. The $10,000 threshold was created as part of the Bank Secrecy Act, passed by Congress in 1970, and adjusted with the Patriot Act in 2002.

The law is an effort to curb money laundering and other illegal activities. The threshold also includes withdrawals of more than $10,000.


Who’s enforcing whom to comply with what now?


Not a likely scenario but still possible. If one is serious about not getting “doxxed at any cost,” consider Mullvad browser.


  1. Don’t give your email address, or use a throwaway one when you join.
  2. Pick a username that’s unrelated to any others you’ve used.
  3. Use a VPN.
  4. Don’t reveal personal details in posts & comments.

I guess you didn’t get satisfactory answers from your first post, but you still haven’t clarified what you actually mean by your question. All Lemmy servers run Lemmy, so in some senses of the term, they’re all roughly equally private, which is to say not very, because all posts & comments are publicly scrapable, except for private messages.

https://lemmy.ml/:

A community of privacy and FOSS enthusiasts, run by Lemmy’s developers

What is Lemmy.ml



Depending on your threat model, not very important. What are the chances that 1) someone will have hacked Mullvad’s server and installed a compromised version of the browser, and 2) you happen to download the compromised version before the hack is discovered and mitigated? Also, the signature and the package appear to be on the same server, so what’s necessarily going to stop the hacker from updating the signature to match their hacked package? [Edit: It’s a GPG signature, not a simple hash signature, so I guess that’s so not trivial after all.]


This for-profit company saying that I am not the product doesn’t necessarily make it so, and it doesn’t explain what is the product or service being sold and to whom. And just as their Firefox counterpart changed their terms yesterday, they could change theirs tomorrow.

Mozilla hasn’t been moving in promising directions lately. Mozilla’s CEO doubles down on them being an advertising company now


Edit to add: https://github.com/mozilla/bedrock/commit/d459addab846d8144b61939b7f4310eb80c5470e


This doesn’t bode well at all: https://www.thunderbird.net/en-US/about/

Thunderbird operates in a separate, for-profit subsidiary of the Mozilla Foundation.

A free mail client from a for-profit company? What’s the revenue model? Sounds like I must be the product somehow.

The Thunderbird for-profit entity, MZLA Technologies Corporation, is distinct from the Firefox for-profit entity, Mozilla Corporation, and both are wholly owned by the non-profit entity, Mozilla Foundation.


These particular photos are of New York City.


That’s not sus, that’s what anyone ought to expect him to do, because it aligns with his bourgeois interests. Why would he stay on a non-corporate, federated social media platform when he and his bourgeois peers can’t control the narrative?



♬ Hello dd my old friend
I’ve come sudo with you again ♬




I didn’t notice it being down. I always go here to pick a healthy server: https://status.d420.de/


Reporter: [REDACTED]
Reason: Hostile

Reporter, is it hostile, or are you hoping to have the comment removed by gaming the reporting system and the mods?


For years and until very recently, every MacOS & iOS update would silently turn Wi-Fi and Bluetooth back on 😡


I haven’t seen a Bitly link in dog’s years and assumed it had died.


I suppose so, but I don’t see poisoning the LLM dataset in this way as a privacy thing, per se. It sounds more like performance art at best and futile pissing in the sea at worst.


All good 👍 and the EFF link you posted is a good jumping off point as well.


I didn’t say the EFF isn’t also knowledgeable, nor that we are more knowledgeable than them in all areas.

But we also didn’t just pull things out of our asses 3 seconds ago.


lemm.ml is “a community of privacy […] enthusiasts, run by Lemmy’s developers,” and, after over a century of US state propaganda, repressions, purges, and assassinations upon us, communists might know a thing or two about militancy against US state power, including protests.


Protests that upset the US federal government are serious business. Garden-variety privacy won’t do.

Why not Signal? » Good Alternatives



I don’t think they’ll be getting any more upvotes, unless they want to show me more of their alt accounts.


I don’t know why you put so much effort into your bullshit when no one reads deeply buried comments in a two day old post 🤷


Oh I see, the only people still here are you, me, and two of your alt accounts 😂 Admins can see votes, BTW.


They literally posted a video with actual victims confronting the government.

What are the time stamps of actual Uyghur victims speaking? Because if they’re there, I must have missed them.


And I provided links to actual people you deny existence of who have been personally impacted.

You didn’t provide links; you provided one link, to Hasan’s hatchet job, which doesn’t even interview any supposed Uyghur victims. But even if you had, testimonies are not hard evidence, as we’ve seen from Yeonmi Park and Nayirah al-Ṣabaḥ. The testimonies of “defectors” from US “enemy” states often suss: What’s the deal with defectors?



It doesn’t have access to all your keystrokes. An app can only harvest the keystrokes typed into it.


>According to software engineer and blogger, Paul Biggar, however, one key detail on the methods employed by the Lavender system that is often overlooked is the involvement of the messaging platform, WhatsApp. A major determining factor of the system’s identification is simply if an individual is in a WhatsApp group containing another suspected militant. > >Aside from the inaccuracy of the method and the moral question of targeting Palestinians based on shared WhatsApp groups or social media connections, there is also notably the doubt it brings to the platform being privacy-based and guaranteeing “end-to-end” encryption for messages. > >Stating that WhatsApp’s parent company, Meta, makes it complicit in Israel’s killing of “pre-crime” suspects in Gaza, Biggar accused the company of directly violating international humanitarian law, as well as its own public commitment to human rights. > >These revelations are the latest evidence of Meta – formerly Facebook – aiding in the suppression of Palestinian and pro-Palestinian voices, with the platform long having been criticised for taking significant steps to shut down dissent against Israeli and Zionist narratives. Those measures have included [permitting](https://www.middleeastmonitor.com/20231124-facebook-permitted-ads-calling-for-holocaust-against-palestinians/) adverts promoting a holocaust against Palestinians and even attempting to [flag](https://www.middleeastmonitor.com/20240213-meta-considers-flagging-zionist-as-hate-speech/) the word ‘Zionist’ as hate speech. >Questioning the accuracy of the report, a WhatsApp spokesperson told MEMO: “We have no information that these reports are accurate. WhatsApp has no backdoors and we do not provide bulk information to any government. For over a decade, Meta has provided consistent transparency reports and those include the limited circumstances when WhatsApp information has been requested. Our principles are firm – we carefully review, validate and respond to law enforcement requests based on applicable law and consistent with internationally recognized standards, including human rights.
fedilink

[META] This comm has a rule against promoting proprietary software. What does it mean? Is it being f
I have no opinion and am just seeking clarification as an admin who occasionally gets complaints that I’m unsure how to address. Thanks! cc: [@TheAnonymouseJoker@lemmy.ml](https://lemmy.ml/u/TheAnonymouseJoker) (the most active [!privacy@lemmy.ml](https://lemmy.ml/c/privacy) mod) --- Edit to add an example edge case: DuckDuckGo is proprietary, but is anyone going to argue against its promotion? Isn’t Proton Mail similarly only FOSS on the client side?
fedilink