Em0nM4stodon, to random

“Why do you use Signal and all this Encryption!
Do you have anything to hide? 😡“

Yes! I do!

  • The color of my underwear
  • My friends’ cats photos
  • My failed gym class grades
  • My first attempt at "portrait"
  • The outcome of my last meal
  • The weird mole on my left toe
  • How much I cried watching Star Trek
  • How much cheese there is in my fridge
  • My failed knitting experiment
  • The horrible poem I just wrote
  • My bank card pin number
  • My social security number
  • My main password
  • The web search history for your birthday gift

Privacy is a Human Right! ✊

Not sharing publicly what you do not wish to share is your right! 🔒✨

🎉

semioticstandard, to privacy
@semioticstandard@wandering.shop avatar

You need to stop using Chrome NOW. It’s not hyperbole: Google just rolled out a change to Chrome that tracks the sites you visit, builds a profile, and shares that with any page you visit that asks.

This is real. It’s not tech bro conspiracy shit.

https://arstechnica.com/gadgets/2023/09/googles-widely-opposed-ad-platform-the-privacy-sandbox-launches-in-chrome

mysk, to infosec

Google has just updated its 2FA Authenticator app and added a much-needed feature: the ability to sync secrets across devices.

TL;DR: Don't turn it on.

The new update allows users to sign in with their Google Account and sync 2FA secrets across their iOS and Android devices.

We analyzed the network traffic when the app syncs the secrets, and it turns out the traffic is not end-to-end encrypted. As shown in the screenshots, this means that Google can see the secrets, likely even while they’re stored on their servers. There is no option to add a passphrase to protect the secrets, to make them accessible only by the user.

Why is this bad?

Every 2FA QR code contains a secret, or a seed, that’s used to generate the one-time codes. If someone else knows the secret, they can generate the same one-time codes and defeat 2FA protections. So, if there’s ever a data breach or if someone obtains access .... 🧵

image/jpeg
image/png
image/png

noellemitchell, (edited ) to meta
@noellemitchell@mstdn.social avatar

"... the website loads in a special browser built into the app, rather than your phone’s default browser. In 2022, privacy researcher Felix Krause found that Meta injects special “keylogging” JavaScript onto the website you’re visiting that allows the company to monitor everything you type and tap on, including passwords. Other apps including TikTok do the same thing."

What the hell?? This is so creepy.

https://gizmodo.com/meet-link-history-facebook-s-new-way-to-track-the-we-1851134018

kentbrew, to chrome
@kentbrew@xoxo.zone avatar

Infosec friends are unanimous: if you're using Chrome, you want to visit chrome://settings/adPrivacy and turn off Ad Topics, Site-Suggested Ads, and Ad Measurement.

IMPORTANT: you must do this for each of your Chrome profiles, since it's not a global setting.

hiramfromthechi, to privacy
@hiramfromthechi@mastodon.social avatar

Any device that needs to be off because it can't be trusted with your conversations should not exist in the first place.

Encryption With A Back Door Is NOT Encryption (ktetch.co.uk)

There’s been an increasing call in recent weeks and months for encryption to have government ‘backdoors’ put into them. This is a bad idea. No really, it’s an incredibly bad idea. Even if we took the assumption that it is a push that’s made with only the purest of intentions, and the government universal key is kept...

protonmail, to privacy
@protonmail@mastodon.social avatar

We thought Google hit rock bottom with .

Its new beta feature on Google Files for called “Smart Search" is the trap door.

This creepy new feature on by default & scans every file on your phone. Why is this bad? Because it could potentially ruin your life. (1/3)

ilumium, to Skydiving
@ilumium@eupolicy.social avatar

Holy shit, I thought I knew how evil the industry was but here we are:

Two-thirds of European websites just ignore your choice and track you anyways, researchers from found. 🤯

https://www.usenix.org/system/files/sec23winter-prepub-107-bouhoula.pdf

kaosailor, to privacy
@kaosailor@mastodon.online avatar

I'm still laughing 😂 yet still very incensed..

roy, to firefox

This December, if there’s one tech New Year’s resolution I’d encourage you to have, it’s switching to the only remaining ethical web browser, Firefox. According to recent posts on social media, Firefox’s market share is slipping. We should not let that happen. There are two main reasons why switching is important.

A red panda (firefox) resting on a tree branch.Red Panda” by Mathias Appel is marked with CC0 1.0.1. Privacy

Firefox is the only major browser not built by a company that makes money from advertising and/or selling your personal data. There’s been a lot of talk about websites tracking users using cookies, fingerprinting and other nefarious technologies that hurt your privacy. But owning the browser puts Google, Apple and Microsoft in a position where they don’t even need those tricks. We need to use browsers that are independent, and right now that means Firefox.

  1. Browser engine monopoly

Wikipedia lists four browser engines as being “active”. Browser engines are the bits that take a web page’s code and display it on your screen. Ideally, they conform to the official W3C standards, and display all elements as it describes. If that’s the case, web developers can easily write sites that work on all browsers. No proprietary vendor lock-in nonsense, just glorious open standards at work.

It’s happened before

In the early 2000’s, Internet Explorer had a massive 95% market share. This meant that many sites were only developed for use with IE. They’d use experimental features that IE supported, in favor of things from the official HTML standard. This was a very bad situation, which hindered the development of the World Wide Web.

Currenty, Chrome, Safari and Edge all use variations of the closely related Webkit and Blink engines. If we want to avoid another browser engine monopoly, we need to support Firefox, and its “Gecko” engine.

Firefox is actually really good

If Firefox would be a bad browser, I would not recommend you to switch. It’s fast, has a nice user interface, and feels every bit as modern and elegant as its competition. I’ve been using it as my main browser for a couple of years now, on Linux, Windows, MacOS and Android. As a web developer, I usually have at least three browsers open, but when I go look something up on the web, I pick Firefox.

So please, help save the web by using the best browser out there. It’s an easy thing to do, and it makes a big difference.

https://roytanck.com/2023/12/23/in-2024-please-switch-to-firefox/

#Firefox #privacy

davidrevoy, to firefox
@davidrevoy@framapiaf.org avatar
smallcircles, to privacy
@smallcircles@social.coop avatar

Yes, you can ditch now..

https://organicmaps.app

is here. Use it while offline and feel good about a -respecting app that doesn't suck you dry of your personal information. Based on this app is gonna blow out of the water (hopefully ;)

Tutanota, to Bulgaria
@Tutanota@mastodon.social avatar

📢 The EU Parliament will not be moving forward with chat control! The indiscriminate mass surveillance measures have been removed and secure end-to-end encryption will not be compromised! 🥳

💪Let's keep pushing for strong privacy rights!👇
https://tutanota.com/blog/chat-control

protonmail, to Futurology
@protonmail@mastodon.social avatar

So 's new app needs your health and fitness info. It also needs your browsing history and your location, and your purchases, and...well, it seems to need everything. If you want to get fully creeped out, here's the whole policy: https://privacycenter.instagram.com/policy/.

TiffyBelle, to privacy

Facebook turns over mother and daughter’s chat history to police resulting in abortion charges:

https://www.theverge.com/2022/8/10/23299502/facebook-chat-messenger-history-nebraska-teen-abortion-case

Stories like this remind us why being mindful of protecting one's privacy online is important and that "private" messages in the majority of places aren't private at all without end-to-end encryption.

Be mindful of what sensitive data you're relinquishing to companies.

stefano, to internet

I read that has launched and many don't understand why it's not fully usable via the web but only through a dedicated mobile app. Meta isn't interested in letting us talk but rather in collecting as much data as possible. Browsers have become (more) skilled at protecting us, while apps can have almost complete access to our mobile devices, gathering data that an average person couldn't even imagine. And our mobile devices have become the safe (or should I say, the exposed pantry?) of our lives.

dsoft, to privacy
@dsoft@techhub.social avatar

Consent-O-Matic is a browser extension that auto-responds to all the and similar consent popups with optimal user preferences.

Unlike the extension "I don't care about cookies" which just accepts all cookies, Consent-O-Matic clicks the prompts on your behalf to reject most of the cookies. You can also choose what to accept/reject in the preferences.

Available for Firefox, Chrome and others.

I've been using this on Firefox :firefox: for quite sometime now and it works great!

Their Github page has links to official extension stores: https://github.com/cavi-au/Consent-O-Matic#introduction

link: https://addons.mozilla.org/firefox/addon/consent-o-matic/

aral, to Bulgaria
@aral@mastodon.ar.al avatar

🚨 Another EU mass surveillance attempt. Will kill privacy on web. Must not pass. 🚨

“[A]ll web browsers distributed in Europe will be required to trust the certificate authorities and cryptographic keys selected by EU governments.

These changes radically expand the capability of EU governments to surveil their citizens by ensuring cryptographic keys under government control can be used to intercept encrypted web traffic across the EU.”

https://last-chance-for-eidas.org

WPalant, to chrome

We are currently witnessing the fallout from monopolization in the browser space. Back in 2007, Internet Explorer received much criticism for its phishing protection mechanism which transmitted all visited websites to Microsoft servers. Mozilla paired up with Google and designed a different system which performed most checks locally and preserved users’ privacy. That’s what healthy competition looks like.

Fast forward to 2023. Almost all web browsers in use are either Chrome or based on the Chromium browser engine. With the competition pretty much eliminated, Google is now pushing its “Enhanced Safe Browsing” down everyone’s throats – which is a nice sounding name for “every website you visit is sent to our servers.” The Internet Explorer approach from 2007 all over again, only that now it’s Google getting all this data. And they certainly won’t do anything evil with it. Yeah, sure.

Reminder: Firefox and Safari are the only remaining browsers worth noting which are not using Google’s browser engine.

https://www.bleepingcomputer.com/news/google/google-is-enabling-chrome-real-time-phishing-protection-for-everyone/

JamesBaker, to Bulgaria
@JamesBaker@social.openrightsgroup.org avatar

So it turns out Europol want the access to all the data that would be collected under plans to scan messages for CSAM. Confirming worst fears that child abuse is being used as an excuse for routine mass surveillance of all images and messages https://balkaninsight.com/2023/09/29/europol-sought-unlimited-data-access-in-online-child-sexual-abuse-regulation/ .

Em0nM4stodon, to random

Sometimes criminals close the door when plotting crimes.

“We should ban doors!” 🚫🚪

Sometimes criminals hide weapons under their clothes.

“We should ban clothes!” 🚫👖

🙃

Do not fall for these misguided arguments.

Most of the time people use end-to-end encrypted apps to talk about the most mundane things.

Sometimes vulnerable people use end-to-end encryption to protect themselves and stay safe.

We should keep and cherish encryption.

We should demand it everywhere.

End-to-end encryption protects our human right to privacy and safety.

We must fight for it! ✊🔒

megahertz, to privacy
@megahertz@mastodon.radio avatar

Privacy tip: When you sell or trade-in a vehicle, remember to erase all of your data from the in-car electronics. The car dealerships will NOT do this, although they should be required to.

This wasn’t done for the last few vehicles I’ve purchased. I know one previous owners name, where she lives, what her taste in music is, where her dad lives (and how often she visited him), and what restaurants she often went to. In the wrong hands, this is dangerous as hell.

Jeremiah, to privacy
@Jeremiah@alpaca.gold avatar

No car manufacturer passed Mozilla’s privacy audit, but Nissan’s is just absurd.

Consent to sale of your DNA implied by riding in the vehicle is a consent mechanism I would love to have a sassy US judge comment upon.

https://foundation.mozilla.org/en/privacynotincluded/nissan/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • Leos
  • Durango
  • ngwrru68w68
  • thenastyranch
  • magazineikmin
  • hgfsjryuu7
  • DreamBathrooms
  • Youngstown
  • slotface
  • vwfavf
  • PowerRangers
  • everett
  • kavyap
  • rosin
  • anitta
  • khanakhh
  • tacticalgear
  • InstantRegret
  • modclub
  • mdbf
  • ethstaker
  • osvaldo12
  • GTA5RPClips
  • cubers
  • tester
  • normalnudes
  • cisconetworking
  • provamag3
  • All magazines