Privacy

3378 readers
5 users here now

Welcome! This is a community for all those who are interested in protecting their privacy.

Rules

PS: Don't be a smartass and try to game the system, we'll know if you're breaking the rules when we see it!

  1. Be civil and no prejudice
  2. Don't promote big-tech software
  3. No apathy and defeatism for privacy (i.e. "They already have my data, why bother?")
  4. No reposting of news that was already posted
  5. No crypto, blockchain, NFTs
  6. No Xitter links (if absolutely necessary, use xcancel)

Related communities:

Some of these are only vaguely related, but great communities.

founded 8 months ago
MODERATORS
126
 
 

“To facilitate this vetting, all applicants for F, M and J non-immigrant visas will be asked to adjust the privacy settings on all their social media profiles to ‘public’”, the official said. “The enhanced social media vetting will ensure we are properly screening every single person attempting to visit our country.”

127
128
129
11
Threema promo codes (self.privacy)
submitted 1 month ago by WeAreAllOne to c/privacy
 
 

Hello everyone. I'm in the process of migrating approx 28 users to Threema. I would appreciate any spare promo codes that you might have. Many thanks!

130
131
132
 
 

This post contains a canary message that's cryptographically signed by the official BusKill PGP release key

BusKill Canary #010
The BusKill project just published their Warrant Canary #010
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Status: All good
Release: 2025-06-16
Period: 2025-06-01 to 2026-05-31
Expiry: 2026-06-30

Statements
==========

The BusKill Team who have digitally signed this file [1]
state the following:

1. The date of issue of this canary is July 16, 2025.

2. The current BusKill Signing Key (2020.07) is

   E0AF FF57 DC00 FBE0 5635  8761 4AE2 1E19 36CE 786A

3. We positively confirm, to the best of our knowledge, that the 
   integrity of our systems are sound: all our infrastructure is in our 
   control, we have not been compromised or suffered a data breach, we 
   have not disclosed any private keys, we have not introduced any 
   backdoors, and we have not been forced to modify our system to allow 
   access or information leakage to a third party in any way.

4. We plan to publish the next of these canary statements before the
   Expiry date listed above. Special note should be taken if no new
   canary is published by that time or if the list of statements changes
   without plausible explanation.

Special announcements
=====================

1. We are changing from twice-yearly to once-yearly canaries

Disclaimers and notes
=====================

This canary scheme is not infallible. Although signing the 
declaration makes it very difficult for a third party to produce 
arbitrary declarations, it does not prevent them from using force or 
other means, like blackmail or compromising the signers' laptops, to 
coerce us to produce false declarations.

The news feeds quoted below (Proof of freshness) serves to 
demonstrate that this canary could not have been created prior to the 
date stated. It shows that a series of canaries was not created in 
advance.

This declaration is merely a best effort and is provided without any 
guarantee or warranty. It is not legally binding in any way to 
anybody. None of the signers should be ever held legally responsible 
for any of the statements made here.

Proof of freshness
==================

16 Jun 25 19:17:39 UTC

Source: DER SPIEGEL - International (https://www.spiegel.de/international/index.rss)
"Teacher Li": Catching Up with the Most Effective Chinese Regime Opponent
Firing at the Desperate: Palestinians Killed as They Gather to Receive Relief Supplies

Source: NYT > World News (https://rss.nytimes.com/services/xml/rss/nyt/World.xml)
Live Updates: Israel Strikes Iranian State TV as It Expands Targets in Tehran
With No Clear Off-Ramp, Israel’s War With Iran May Last Weeks, Not Days

Source: BBC News - World (https://feeds.bbci.co.uk/news/world/rss.xml)
No further damage seen at Iran nuclear sites, global watchdog says
'Nowhere feels safe': Iranians on life under Israeli attacks

Source: Bitcoin Blockchain (https://blockchain.info/q/latesthash)
00000000000000000000f2c3a15949aac2f6d7bc153330a4fca496f68c8c4b21

Footnotes
=========

[1] https://docs.buskill.in/buskill-app/en/stable/security/pgpkeys.html

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEeY3BEB897EKK3hJNaLi8sMUCOQUFAmhQbsQACgkQaLi8sMUC
OQW6Ng//aVnkEMdWFTbwBkDD5k7i1+sdoX1XwigV/hYHoTBJqeIATbw3uvdqiQfx
/VY8sCJUFyLjAqSmEb7rXMjvVy0PFWP7zS4BJgGimEkNoIYRQBfY7txK9uD7ZJ1n
02ybYu7VwEoBJPtwmP4rp6Vpb5rVXmN//ezXDHteLvLEGTKSJ6X/O7tEPtUNbJmR
37KvkKPLY4txkm0z/3ChGVCicQPO9R7d+Xh2TUo9xXPyVneYTRhjSjWfwpcg0Z58
xW5KTGDbB09HMdrmWkl2aOQrf0GgHjPUapOXy1CB3NBR84j6Nsr2Pod3dOuS7moQ
VKnokMS6/dTTvoUbjUpSizDZu+Te2RYanV2I3gt5CHKDNhyFUh4EYOMPqje1dy8j
bf5I4p0qsZkRN12IvIQzDVKKq4guD7zQuagpWvi0d7OtNldT2lu7G2uWQ55WLej0
4QbFn7WCeEWyMXhQHYVYjY8QZPSIHTLHUBTm59+/CGEXYB9WeVi3g2sbD9Aasgod
Te7pm3SC4Sg+F8v7SCoPbxY9VXdCUREOsxPybYrtbFgkdnZwsb2YlN7UDJ9Lqz7i
GYMqX7JNpt7R+Zbp4TQCy1yQY4gNR4H2E1Z2o+3cRTygbUHV58/L0IJc+lO6oHJY
Sa4k/6pswal3CYJSu+imbRmhoFnpv1pFZ1ch2b8k8K/1q727NkU=
=1XvB
-----END PGP SIGNATURE-----

What is a Warrant Canary?

The BusKill team publishes cryptographically signed warrant canaries on an annual basis.

Although security is one of our top priorities, we might not be able to inform you of of a breach if served with a State-issued, secret subpoena (gag order).

The purpose of publishing these canary statements is to indicate to our users the integrity of our systems.

For more information about BusKill canaries, see:

To view all past canaries, see:

What is BusKill?

BusKill is a laptop kill-cord. It's a USB cable with a magnetic breakaway that you attach to your body and connect to your computer.

What is BusKill? (Explainer Video)
Watch the BusKill Explainer Video for more info youtube.com/v/qPwyoD_cQR4

If the connection between you to your computer is severed, then your device will lock, shutdown, or shred its encryption keys -- thus keeping your encrypted data safe from thieves that steal your device.

133
 
 

Cock.li confirmed the validity of the breach based on sample data and column structure, stating that the exposed dataset includes roughly 1,023,800 user records. The compromised fields include email addresses, timestamps of first and last webmail logins, failed login attempt data, language preferences, and serialized Roundcube user settings such as webmail signatures and interface configurations. Additionally, approximately 93,000 contact entries associated with around 10,400 users were leaked, containing names, email addresses, comments, and vCard data.

Not sure why people ever trusted a meme email provider in the first place...

134
135
 
 

Original question by @[email protected]

I'm looking to direct people to message me on >Signal, Matrix, etc. Any suggestions? Thanks in advance

136
 
 

cross-posted from: https://programming.dev/post/32339919

The Nectar project offers 'advanced data analysis' using a wide range of sensitive personal information

A controversial US spy tech firm has landed a contract with UK police to develop a surveillance network that will incorporate data about citizens’ political opinions, philosophical beliefs, health records and other sensitive personal information.

Documents obtained by i and Liberty Investigates show Palantir Technologies has partnered with police forces in the East of England to establish a “real-time data-sharing network” that includes the personal details of vulnerable victims, children and witnesses alongside suspects.

Trade union membership, sexual orientation and race are among the other types of personal information being processed.

The project has sparked alarm from campaigners who fear it will trample over Britons’ human rights and “facilitate dystopian predictive policing” and indiscriminate mass surveillance.

Numerous police forces have previously refused to confirm or deny their links with Palantir, citing risks to law enforcement and national security. However, forces in Bedfordshire and Leicestershire have recently confirmed working with the firm.

Liberty Investigates and i have learned that those projects involve processing data from more than a dozen UK police forces and will serve as a pilot for a potential national rollout of the tech giant’s data mining technology — which has reportedly been used by police forces in the US to predict future crimes.

137
138
 
 

Edit: Matrix isn't going freemium, it's introducing premium accounts to fund the matrix.org homeserver. Thank you for the corrections in the comments.

~~Matrix is going freemium~~ Matrix is introducing premium accounts and WhatsApp is adding ads, which is sparking the annual "time to leave [app]" threads.

Users don't care that much about privacy, but they do care about enshittification, so XMPP not being built for it shouldn't be a problem.

Meanwhile, I've heard for years that XMPP has solved a lot of the problems that lead more popular apps to fail.

Is it really just a marketing/UX/UI problem?

If XMPP had a killer app with all the features that Signal/Whatsapp/Telegram has, would it have as many users?

If not, why does it keep getting out-adopted by new apps and protocols?

139
 
 

Some good info for those getting started and to share with those who are now taking interest.

140
141
38
submitted 1 month ago* (last edited 1 month ago) by Yingwu to c/privacy
 
 

EDIT: I decided on Mailbox.org!

I'd like to use a third-party client like Thunderbird to handle my e-mails, which rules out both Tuta and Proton (I know Proton has their bridge, but I don't want to rely on it). I'm willing to compromise on my e-mails not being encrypted, as long as the e-mail provider has a reputation of caring about the customer's privacy. If I truly want to encrypt a message, I'll encrypt it myself. I've been looking at Mailbox.org, and while I've been hearing good things, people have also been complaining about their lack of support, outdated interface as well as that they don't enforce DKIM/DMARC which enables spoofing.

I would like to be able to use my own custom domain, but also to use their own domain for my e-mail aliases. EU-based only.

Any thoughts?

142
143
144
 
 

cross-posted from: https://lemmy.zip/post/41151237

Arrest of Alejandro Theodoro Orellana comes as federal officials have been defending ICE use of face masks against mounting criticism

145
 
 

Dark Web Interdiction Act of 2025

Here is the text of a bill introduced to Congress (US), ostensibly to combat the trafficking of opioids over "The Dark Web". There's a nice definition of "The Dark Web" at section 4.

I like the part where it says people are using "The Dark Web" both within the United States and "at the international border".

146
147
 
 

GrapheneOS statement on Mastodon: https://grapheneos.social/@GrapheneOS/114661914197695338

Calyx made an official statement on this development here: https://calyxos.org/news/2025/06/11/android-16-plans/

Concerning stuff. Hopefully a workaround or solution is found at some point, but if not, I'm already thinking of how to manage without them.

I can't see myself going back to a standard Android phone, so I suppose worse case scenario, I'd have to settle with LineageOS, or potentially abandon Android altogether and see if I can manage with discrete separate devices to fulfill the same needs, such as:

  • a pocketable mini-Linux PC like a MNT Pocket Reform, which has the ability to use cellular networks. Should be able to text, browse web, and maybe GPS? Alternatively, perhaps the Mecha Comet?
  • Small pocket-able dumb camera
  • MP3 player
  • Dumb-phone kept in a faraday bag when not in use?

EDIT:

Update on the situation from GrapheneOS in this thread (using Redlib, a proxy of Reddit)

The biggest problem for GrapheneOS is not the change to AOSP but rather our lead developer since 2022 being forcibly conscripted to fight in a war in April. That's why we've been asking for help since April.

In April, we were contacted by someone about upcoming changes to AOSP impacting us including the removal of device support in Android 16. We talked about it internally but didn't know if the information was credible. We prepared as much as we could for the Android 16 port but didn't know exactly what would happen with device support. If we had clearer information on it and knew it was accurate, we could have prepared much more in advanced.

Porting to Android 16 is required to continue shipping full Android privacy/security patches regardless of device. Only the latest stable release gets full privacy/security patches, which was the May release of Android 15 QPR2 and is not Android 16. Older releases only get backports.

Pixels also only have their driver and firmware patches for Android 16, although we're working on a release within the next 24 hours with backports of the most important firmware patches. We would normally have an experimental Android 16 release out already, if they hadn't made changes to AOSP.

There are further changes coming to AOSP. It is not only what is talked about there.

In another comment:

We're going to be continuing GrapheneOS but in the long term we'll need to shift to our own devices with an OEM partner.

It's not only Pixels which are going to be impacted. Pixels are still the only devices meeting our hardware requirements (https://grapheneos.org/faq#future-devices). It's clear we need our own hardware in partnership with an OEM that's serious about security and capable of delivering on it. We've had several attempts at OEM partnerships but they were unable to provide what we needed. It will cost millions of dollars to get a device meeting our basic requirements. We can do that, but we hoped for an OEM wanting to work with us instead of us needing to pay for everything through raising funds. We didn't end up finding a good OEM to work with that way so we'll do it the hard way.

148
149
150
view more: ‹ prev next ›