Skip to main content

Search

Items tagged with: Privacy


Powers unhindered by UK Parliamentary scrutiny threaten freedom of expression.

With no need to demonstrate harm to children, governments could do as they please.

A Reform government could force ID checks to access LGBTQ content as part of their manifesto commitment “to end trans ideology” in schools.

#ageverification #privacy #freedomofexpression #internet #ukpolitics #ukpol


Far-reaching powers over Internet access are being rushed through.

Last minute amendments have been shoved into the UK Children’s Wellbeing and Schools Bill.

Ministers will be able to force anyone over 13 to use unsafe and unregulated age-ID services to access whatever content the government wants.

Find out more ⬇️

openrightsgroup.org/press-rele…

#ageverification #privacy #freedomofexpression #internet #ukpolitics #ukpol


Tools that summarize ToS etc


Do you have experience with any of these?

github.com/DavidHavoc/ToS-Read…

github.com/skamal23/ToS-Summar…

I'm interested in tools that highlight privacy invasive terms and conditions that are often hidden behind legal jargon or wrapped up in so much text that the end user is discouraged to actually read through the terms of service and/or the privacy policy.


They can't seem to help themselves with those internal memos 🤯:
"...reported that the company was considering adding facial recognition to its glasses. In an internal memo on the topic, a #Meta employee wrote that the timing to launch might be perfect: "We will launch during a dynamic political environment where many civil society groups that we would expect to attack us would have their resources focused on other concerns.""

businessinsider.com/meta-ray-b…

#Facebook #News #USA #US #privacy #tech


(Although remember that nothing is private on Mastodon. Your private mentions/direct messages are not end-to-end encrypted so your instance admins – and anyone hosting a hammer to their knees – could be reading them all. If you want to talk privately, use Signal or Delta Chat. Never share sensitive information on “private” messages on Mastodon. That goes double for our friends in Gaza.)

#mastodon #fediverse #activityPub #privacy #encryption


Burp Anonymizer


Pentesters of the world, quit accidentally training ChatGPT on your boss API keys
A must needed Burp Suite extension to improve your privacy in the AI world

Just released #BurpAnonymizer, a Burp Suite extension that redacts PII, credentials, tokens and other sensitive data from HTTP requests/responses.

With one click, safely share requests and responses in reports, presentations, team reviews, or AI workflows, without exposing secrets and minimizing manual redactions.

🔗 Explore it here: github.com/sv1sjp/BurpAnonymiz…

#CyberSecurity #BurpSuite #AppSec #Privacy #SecurityTools #web PortSwigger


Reddit and FaceID Verification


Reddit CEO says facial verification may be introduced. Ostensibly to prevent bots.

But we all know how dangerous this can be. But most likely Reddit users will just accept it.

Although they have a great free analogue right under their noses - Lemmy. Which is many times better than its competitor.

I wish more people would discover Lemmy, but that's unlikely.


Nope eYou nope nope


The platform I can trust ? When none of the current platforms I do trust have any cookies at all ? Or analytics?

I’ll stick with the Fediverse k? Thanks !


#Palantir extends reach into British state as it gets access to sensitive #FCA data | Palantir | The Guardian


What one Earth is the government thinking giving #PeterThiel and his cronies access to such sensitive data? Nothing good can come out of this.

theguardian.com/technology/202…

#UK #Politics #Privacy #DataProtection


Age verification compliance is another aberration of systemd. Luckily, there are alternative init systems and GNU/Linux distributions that care about your privacy.
itsfoss.com/news/systemd-age-v…
#systemd #privacy #runit #openRC


NaiHe – small encrypted chat for people who can't speak freely, looking for forks


Made a small end-to-end encrypted chat tool. No accounts, no phone numbers, you just self-host an MQTT broker and share a key with someone.
The part I think is actually useful: there's a clipboard mode where you type plaintext, it encrypts and copies to clipboard, then you paste the ciphertext into WeChat or email or whatever. The other person does the reverse. You don't even need to be using the same app.
ChaCha20-Poly1305, Argon2id, Rust + Tauri, ~5MB exe.
I know there are better tools for most threat models (Signal, Briar, SimpleX). This isn't trying to compete with them. It's for situations where you can't install a dedicated messenger or need to smuggle encrypted text through an existing channel.
No forward secrecy, no traffic obfuscation, not audited, Windows only. All documented in the README.
Unlicense. I won't maintain it. Fork it if it's useful to you.


haha “privacy and relevance.” You can’t put google in that list if the focus is on #privacy. Hell, given the recent revelations that google is rewriting headlines using AI, the definition of “relevance” is strained. Use google for search and you are just feeding AI slop to this AI spreadsheet. Compounded errors.

It will be a marvel if, after all the climate destroying AI emissions, it actually gets the right result.


The architecture of v1.2.X is built for self‑sufficiency: the only external dependency for AI is Ollama models, there is no need for Open WebUI or other services, SQL and statistics work fully offline, and your data stays on your computer when you use local AI models for processing: matasoft.hr/qtrendcontrol/inde… #Privacy #OnPrem #AI


out of the loop, what's the problem with signal?


i've just seen a comment in a post, in this very community, saying people trust signal because of missinformation (from what i could undertand).

if this is true, then i have a few questions:

-what menssaging app should i use for secure communications? i need an app that balances simplicity and security.

-how to explain it to my friends who use signal because i recomended?

-what this means for other apps in general?


GrapheneOS Foundation To Never Required ID or Other PII To Use GrapheneOS


cross-posted from: lemmy.ml/post/44781501

GrapheneOS will remain usable by anyone around the world without requiring personal information, identification or an account. GrapheneOS and our services will remain available internationally. If GrapheneOS devices can't be sold in a region due to their regulations, so be it.


A rogue #AI led to a serious security incident at #Meta

theverge.com/ai-artificial-int…

#cybersecurity #privacy


The old headline of the article said it all:
"As #Meta removes #privacy controls, #TikTok explains why it never had any"

No idea why they changed it 🤔
-Guess even big #News have to suck up to the algorithms ✅

fortune.com/2026/03/17/tiktok-…


Sheesh, the US is sure getting scary. Well, it's a good thing it would be impossible to trace Signal to someone via metadata like a phone number, right?


Even State Department-funded Human Rights Watch admits that authorities combine legal and illegal methods to obtain convictions: text.hrw.org/report/2018/01/09…

Combining dragnet surveillance with device hacking is intended in the design of both tools. Hence, State Department-funded Signal dupes you into handing over your identity as part of the population-centric mapping. In custody, your phone will be hacked when it is taken away if it's important.

xcancel.com/hannahcrileyy/stat…


Safeguards, in age verification law, in brazil.



Mass surveillance is on the rise. License plate reader cameras & tools meant for safety can also put people at risk, including those seeking reproductive health care or those targeted by ICE.

On the Future Knowledge #podcast, Cindy Cohn talks with Rainey Reitman about digital safety, surveillance, and why protecting yourself online matters.

🎧 Listen & subscribe ⬇️
futureknowledge.transistor.fm/…

@eff @internetarchive #Privacy #DigitalRights


Orion: a fantastic browser for IOS, Mac & Linux !


Not really a review more just a recommendation for those who might be interested.

Developed by the wonderful folks at Kagi Search! On IOS and Mac the app is designed off WebKit. And offers built in ad block and pretty strong telemetry block.

It also works with certain Chrome extensions.

I’ve been using it primarily on IOS. My only two gripes is the cookie clear on close doesn’t work and the logo really is just another butthole.

Certain sites freak out but I don’t want to lower the settings so it’s a compromise im ok with it.

If your on IOS might be worth checking out !

Haven’t tried the Linux version but I’m going to soon.


#introduction

Hi Mastodon 👋

We're Node Star — a publishing and community project building neighborhood mesh networks in Southern California and beyond.

We just published a free community playbook: "Own the Internet: Neighborhood Networks That Can't Be Shut Down."

Written for the person who wants to start, not the person who already knows how.

Download it free at
nodestar.net

Share it freely!

#MeshNetworking #DecentralizedWeb #EmergencyPreparedness #Web4 #FOSS #Privacy


volla, /e/, etc is a fucking shithole (or why simply renaming Google to volla will change nothing)


Once again, I have to remind everyone the difference between a replacement and an alternative.

  1. Yes, google is shit
  2. That dosent mean /e/, iode, and the rest is automatically better than google.

That being said, the volla attestation API is once again a google replacement. Not an alternative, but a „google” with another name. They are still just as vulnerable to corruption, court orders, etc as google is. Its like throwing out your Alexa for spying, but instead buying another Alexa, but instead of Amazon it's nozama. Look people, instead of unsecured s3 bucket 3, I use unsecured S3 bucket 4 that I'm sending my data through via http. Me so smarty pants

Once again, volla and their attestation will become just as big and corrupt as google. It is the job of the software to be designed in a way that it can't be abused like google is abusing their G services. This is not given with volla attestation. There is already an implemented software. Its called android attestation.


OSS Anti Surveillance: public tracker for OS-level age signaling and related surveillance mechanisms



Phony security rules will make India’s phones less safe


The Indian government has introduced countless rules supposedly to make smartphone safer. In reality, the rules will make phones less safe, and enable further mass surveillance and authoritarianism.


Master Browser Fingerprint Spoofing with Expert Techniques



Static + dynamic analysis of Signal's APK. The good news first: Signal is genuinely exceptional.

Rust core (libsignal_jni.so), post-quantum hybrid Double Ratchet (Kyber-1024 + X25519), Direct ByteBuffers with immediate zeroing after PIN/username hashing, Intel SGX attestation for SVR — MREnclave verification means even a compromised Signal server can't extract your PIN hash.

But two things stood out:

1. Firebase is always there. Google receives IP + notification timestamps regardless of message content. If you need metadata privacy, Signal still leaks presence data to Google's infrastructure.

2. Certificate revocation endpoints hit g.symcd.com in plaintext. An ISP or state-level observer can fingerprint Signal usage from DNS queries and HTTP traffic to those CAs — without touching message content.

Conclusion: strongest crypto engineering in consumer messaging. The attack surface isn't the cryptography. It's the operational dependencies.

Soon the full analysis

#infosec #AndroidSecurity #Signal #privacy #ReverseEngineering #postquantum #mobileforensics


If you're self-hosting for privacy, spend 10 minutes hardening your VPS first



Self-hosting dev tools as a privacy win: no more sending your data to random online tools



This is such an important issue! All universities, institutions, citizens & responsible communicators should be using a "communications platform that is accessible to all citizens, without the need for an account; an independent network not subject to [monetisation &] censorship due to opaque algorithms or political bias."
Thanks for this clear explanation!

#Fediverse #privacy #PublicGood


Russia’s crackdown on VPNs reaches new heights as internet restrictions intensify


As the UK, Australia, and other countries appear to be introducing ID requirements and banning anonymous access, Russia reveals it has the ability to block VPN access.

https://www.techradar.com/vpn/vpn-privacy-security/russias-crackdown-on-vpns-reaches-new-heights-as-internet-restrictions-intensify


49MB download: one NYTimes webpage



Hackers Expose The Massive Surveillance Stack Hiding Inside Your “Age Verification” Check



‘It beggars belief’: MoD sources warn Palantir’s role at heart of government is a threat to UK’s security



Q: Whatever happened to our promised Signal - WhatsApp compatibility?


The news first came in 2024, but it's been very quiet since.

I've been waiting this whole time to jettison WhatsApp from my phone.

Is it available only in some parts of the world? If so can I spoof it?

We know that adversarial interoperability works, so why have we not been able to make this work?

All else failing, are there any unofficial WhatsApp clients I can use to preserve my privacy?