If you don’t know me, I make frequent write ups about privacy and security. I’ve covered some controversial topics in the past, such as whether or not Chromium is more secure than Firefox. Well, I will try my hand again at taking a look at some controversial topics.

I need ideas, though. So far, I would like to cover the controversy about Brave, controversy around Monero and other cryptocurrencies, and controversy around AI. These will be far easier to research and manage than Chromium vs. Firefox, for example. I’d like to know which ideas you have!

Which controversial privacy topics do you know of that you would like to see covered?

PLEASE DO NOT ARGUE ABOUT THEM IN THE COMMENTS!

Please save any debate for if/when I make a write up about the topic. Keep the comments clean, and simply upvote ideas you would like to see covered. I won’t be able to cover everything, so it helps bring attention!

Above all else, be kind, even if you don’t agree with an idea or topic :)

    • @[email protected]
      link
      fedilink
      English
      147 months ago

      Boy, I’m not a lawyer, but that sure feels like being forced to incriminate yourself.

    • @[email protected]
      link
      fedilink
      57 months ago

      Others take issue with the idea that technology might be allowed to trump legal process. In a 2015 California Law Review article arguing that forced decryption is necessary to balance individual rights and government power, Dan Terzian, presently an associate at Duane Morris LLP, argues that the EFF’s view is too expansive.

      “Scores of companies now encrypt their data,” Terzian wrote. “In the EFF’s alternate universe, these companies are effectively immune from discovery and subpoenas.”

      Only if you consider corporations persons. They’re not.

      Excellent suggestion, btw.

  • OneMeaningManyNames
    link
    fedilink
    English
    177 months ago
    1. Whether phones are listening or not

    2. What is the redacted part in the rationale to ban Tik Tok

    A note on the latter, it is presented as national security threat. They won’t say what it is. I presume because some of the shit they don’t want a foreign power doing is sth they very much do themselves.

      • OneMeaningManyNames
        link
        fedilink
        English
        27 months ago

        See, I am not the guy who will stop thinking for myself because experts say there is no evidence of sth. I am not saying that there is real time eavesdropping at all times, but I have not seen convincing arguments that a working microphone cannot be used for pushing ads by simple and widely available mechanisms. In fact, the sheer amount of people who complain about this should be considered evidence in itself, especially when they never had thought of a given topic before discussing it with someone. I have considered phone proximity and shared IP address but they don’t seem to make an exhaustive explanation. I think that some stories point to Meta doing this extensively, and that disallowing microphone access for Meta products alleviates the effect. Many privacy communities I believe they are infested by spooks and trolls pushing disinformation narratives, and one of them is that phones are NOT listening as a smart thing to say and/or believe. I might as well think that this is itself can be related to the redacted part in the rationale to ban Tik Tok. Having said that, I think that the only feasible to do this technically is by a regularly updated list of keywords, rather than other ways that would leave a processing or networking footprint.

  • @[email protected]
    link
    fedilink
    23
    edit-2
    7 months ago

    F-Droid not being trusted. They build and sign a developer’s code on their behalf, so there is a chance for injection there.

    There are reproducible builds, but I would argue it’s not taken seriously enough. Like right now nobody is publicly verifying Signal’s supposed reproducible Android builds and they’ve historically had problems keeping it working.

    Also how most (or all?) Play Store apps (including FOSS) contain proprietary code.

  • Zagorath
    link
    fedilink
    267 months ago

    There is no expectation of privacy in public.

    By which I mean that things like blurring a house from Street View are unreasonable.

      • Zagorath
        link
        fedilink
        English
        17 months ago

        Yeah, there’s a reason I added that clarifying second sentence. To be a little more nuanced (but still overly simplistic because I don’t feel like writing an enormous essay right now), I would say you don’t have any expectation of privacy by default in public, but that anything that might reasonably amount to stalking because it’s targeted tracking of an individual, even if it involves footage of someone in public, is certainly not ok.

        • @[email protected]
          link
          fedilink
          17 months ago

          The survivors will have more immediate concerns than invading my privacy and they will understand the value of their own privacy as well.

          • @[email protected]
            link
            fedilink
            English
            17 months ago

            Except if someone with the means wants to exert control over the survivors asap. there’s a class which was being busy building bunkers in the last decade or more

            • @[email protected]
              link
              fedilink
              17 months ago

              I’m sure their agents will taste delicious and they’ll carry great loot. Delicious long pig.

    • @[email protected]
      link
      fedilink
      English
      147 months ago

      IMO, blurring a house in Street View could lead to the Streisand effect, especially when 99% of all other property is unblurred.

      If you want to remain private, in the case of Street View, your best bet is to keep it as inconspicuous as possible, otherwise people will start looking closer and ask questions; the exact opposite of what you want, even if you have nothing to hide.

    • Zagorath
      link
      fedilink
      97 months ago

      I don’t even care about the privacy aspect per se. Phone number as user ID is a crappy UX that fundamentally does not work when international travel, multiple devices, or needing to get a number changed. It also doesn’t work for shared accounts or people who might want multiple identities.

      Some of these relate to privacy, secondarily, but my primary concern is the UX.

  • poVoq
    link
    fedilink
    317 months ago

    Signal as a centralized meta-data honeypot.

    • @[email protected]
      link
      fedilink
      37 months ago

      Oh boi I’m trying to get people to use simplex exactly because of this. I managed to bring most people to Signal and they’re cool with it because it just works, but I don’t trust them at all. Sure there was this court order where they didn’t have any user data except account created date and last active date, but since almost everybody uses either Google‘s or Apple‘s push notification servers turns out that doesn’t matter so much from what I undertstood.

      • @[email protected]
        link
        fedilink
        37 months ago

        You can use your own builds of Signal (or preferably Molly-FOSS) including a self-hosted server. You can bring your own push notification as well.

        • @[email protected]
          link
          fedilink
          17 months ago

          I think that’s really cool. Unfortunately most people won’t be doing that, they don’t even care that WhatsApp, etc. are scraping all their data :(

      • ᗪᗩᗰᑎ
        link
        fedilink
        37 months ago

        Google‘s or Apple‘s push notification servers turns out that doesn’t matter so much from what I undertstood.

        Can you elaborate? It’s my understanding that push notifications are only used to trigger Signal to check if there are messages - the message data and who/what triggered it is not being sent to Google/Apple. If you don’t trust push notifications, you can always use a De-google’d phone and the Signal APK which will fallback to polling the server; this will obviously impact battery life as the app needs to constantly be checking for new messages.

        • @[email protected]
          link
          fedilink
          27 months ago

          I‘m referring to them handing over the data to law enforcement of the US and other unknown governments.

          What exactly they hand over I can’t tell you, it might be harmless. In the case that they revealed they used push notifications data to identify a pedophile who was using some encrypted messaging service. I hope he gets what he deserves but for us it means we shouldn’t trust anything that uses Apple‘s or Google‘s push notification servers.

          Yeah I know about Molly etc., but the point is, no one I know is going to degoogle their phone and use that. It would be easier if they’d just use a more private, decentralized app that also doesn’t ask for a phone number ffs.

  • Sem
    link
    fedilink
    English
    107 months ago

    For me an AI topic is the hottest

  • propter_hog [any, any]
    link
    fedilink
    English
    87 months ago

    JavaScript canvas blocker add-ons (this one specifically comes to mind, because I’ve recently had to disable it since it makes life harder; is it worth the cost of admission, or is it a lot of effort for not a lot of reward?) Other types of privacy add-ons would be good to explore as well.

    • @[email protected]
      link
      fedilink
      27 months ago

      I installed such a plugin after reading about fingerprinting many years ago and have not ran into any problems yet. What issues have you encountered?

  • @[email protected]
    link
    fedilink
    67 months ago

    What about the issue of, the more accessible private browsing and messaging has become, the harder it has become to track down child porn producers.

    • @[email protected]
      link
      fedilink
      147 months ago

      It is a non issue, a fabulation of a pretext to strip away all your rights. Just look at all the gross politics wonks slinging pedophile accusations at each other all the time. How could anyone even believe this was anything other than the latest tool of character assassination after homo, commie and anarchistshave worn out their usefullness. Anyone going around yelling pediphile this pedophile that, recognize them for the troll that they are and tune them out, they have absolutely nothing valid to say.

  • @[email protected]
    link
    fedilink
    37
    edit-2
    7 months ago

    Matrix is defacto centralized around Matrix.org & servers they provide (where the cost of hosting makes it largely inaccessible to low-spec & medium-sized servers causing them to inevitably shut down & recommending users back to Matrix.org). All the metadata gets synced back to the mothership that was funded by Israeli intelligence. Avoid it.

    Cloudflare is a CIA front. They offer “free” DDoS protection + static proxy thereby giving Cloudflare the ability to MitM all TLS connections thru their servers. They convinced so many ‘developers’ via ‘influencers’ that every tiny site needs Cloudflare in front of it as a precaution/optimization, but it is an entirely premature optimization that doesn’t need to so widely deployed, but it is. 🤔

    Microsoft has always been an enemy but somehow managed to Trojan horse their way into the minds of developers again (neo-EEE) trying to centralize how software is created. Like we avoid Microsoft Windows, the rest of the Microsoft ecosystem should equally be avoided: Copilot, LinkedIn, Outlook, Exchange, Office, Teams, Azure, VSCode, npm, GitHub (Sponsors, Codespaces, Copilot). Literally none of these projects/services can’t be replaced to help protect the privacy of your clients, coworkers, contributors.

    • @[email protected]
      link
      fedilink
      English
      127 months ago

      Cloudflare is a CIA front. They offer “free” DDoS protection + static proxy thereby giving Cloudflare the ability to MitM all TLS connections thru their servers.

      I just started to learn about privacy in depth this year, and this little fact about Cloudflare has sat with me more than most things that I’ve learned. I feel like very few people think about the implications of Cloudflare’s practices. Even if its not a CIA front (I feel like it is), we should feel uncomfortable giving any private entity such power. Unrelated, but their crazy lava-lamp wall, as cool as it is, kinda gives me bad vibes lol.

      • @[email protected]
        link
        fedilink
        English
        37 months ago

        I learned about Cloudflare mitm quickly because when you use Tor browser you will see how many websites use cloudflare because you can’t access all those sites. So I did a little research about this problem about cloudflare and found out how serious and huge problem it is.

    • @[email protected]
      link
      fedilink
      8
      edit-2
      7 months ago

      Matrix originating in Israel made me decide not to use it. No way anything from that place isn’t spyware.

  • @[email protected]
    link
    fedilink
    27 months ago

    A global look at Short form video as the latest trend in mass misinformation campaigns, including which interest groups, or states conduct them and who they contract (from large scale to possibly unwitting small creators) to produce and post it. How it developed from prior trends, and where it might go next. Perhaps not particularly controversial (in the true sense of the word), but geopolitically worth looking at and discussing more in imo. Of course a privacy and security focus on this is very much integral to the issue by default. How the existing business models around the data involved (harvesting , auctioning etc) might play into this already , and in the years to come. As well as how other business is implicated. Good old “Follow the money” I guess .

  • @[email protected]
    link
    fedilink
    English
    327 months ago

    Browsing with JS disabled by default and expecting most sites to have basic functionality like “display this text”

  • @[email protected]
    link
    fedilink
    97 months ago

    Well, real privacy don¡t exist in the same moment you goes online. Google controls half the internet and MS and Apple the rest, direct or indirect. Even the Dark web isn’t so private as people think.

    An advanced user can reduce the privacy holes, gutting Windows, leaving it in an OS as is, the same with Google products, but also only up to a certain limit so as not to turn navigation into pure text or get blocked in most the pages. For this reason, we must focus on which data deserves to be protected or hidden and which are of a purely technical aspect that ensure the proper functioning of the sites we visit.

    I don’t care that the page knows what country I live in, but if it has to be avoided that it knows my address, I don’t care that it knows the OS I use and the exact resolution of my screen, since this helps the pages not to be out of order or download links take me to downloads for another OS.

    This is all data that matches millions of other users and is not a privacy issue. These problems arise with data that identifies the user directly, such as email addresses, which are unique and perfectly traceable, personal photos published on the Internet, bank details in these very convenient mobile payment apps, posting on Fakebook until when are we going to go pee or when we go on a vacation trip (surely some of the 5637 followers are very interested when your house is empty)…

    There is a lot that the user can do to have a certain privacy at the computer level, but the worst security hole is always the user themselves and the lack of common sense…