Recent comments in /f/Privacy

Wingless wrote

Facebook is stupid, but ... it AMAZES me how quickly people bought into the idea that a telephone book in the hands of the government is essential law enforcement, a telephone book in the hands of bankers is great for the economy, a telephone book in the hands of spammers is a job creator, but a telephone book in the hands of grubby peasants who didn't pay money for it is HORRIBLE, because YOU, you SCUM, you might CALL SOMEBODY.

Without first typing it in the search box and registering your interest forever in Google's database, that is. Information that they can sell, use in advertising, or have you imprisoned with based on your contact's odious anti-government beliefs.

3

BlackWinnerYoshi wrote

Ah, of course, blaming the victim. Totally not Boomerbook's fault that they force you to give your phone number. Seriously though, why those 533 million people won't move out of Facebook at this point? I bet fifth of the monthly active users switching to decentralized social networks, such as Friendi.ca, will have a quite big impact on this centralized not-social network.

4

DeusExMachina wrote (edited )

I already use dns.watch . Doesn't block anything but everything is uncensored and they keep no logs so I kinda like it . But for my phone , your DNS would be useful ( kinda hard to get adblock on ios !) . And for your VPN , I just have some questions ( I actually use Mullvad , very good vpn btw) : Would you have P2P dedicated servers ? Do I need any personal informations to register ? What is one-month price ? Can I pay in cryptocurrencies or Cash ? Thanks for answering !

3

BlackWinnerYoshi wrote

I have a feeling that this was done intentionally: to hide the fact they're integrating some weird crypto thing into their (not) private messenger. I mean, Monero already exists, so why not make people learn about that? Instead, they're asking for your phone number, and they probably do a million other things wrong. It's just awful.

3

Rambler OP wrote

And yes, I'm aware of a bug with this site (RAMBLE) and linking to my invidious install. It fails to fetch the thumbnail / description / favicon from the site/pages linked and spits out a 500 Internal Server Error. It does it with a couple other sites too, so it's something I'm looking into.

3

riddler wrote

I hate instagram and the like. My gym posts updates on facebook and instagram. Every time I just want to figure out if their open or if anything changed it wants me to log in. I'm not giving my information to some evil company so I can just get status updates for a gym too small to justify hiring a web dev to keep their site up.

2

onion wrote

I knew about metadata but this was new to me

The different sensitivities of the photosites creates a type of imperceptible image watermark. Although unintentional, it acts like a fingerprint, unique to your camera’s sensor, which is imprinted onto every photo you take. Much like snowflakes, no two imaging sensors are alike.

In the digital image forensics community, this sensor fingerprint is known as "photo response non-uniformity". And it's "difficult to remove even when one tries", says Jessica Fridrich of Binghamton University in New York state. It's inherent to the sensor, as opposed to measures, such as photo metadata, that are "intentionally implemented", she explains.

This is good to know too. I always suspected that printers had something like this.

When considering these privacy issues, we might draw parallels with another technology. Many colour printers add secret tracking dots to documents: virtually invisible yellow dots that reveal a printer's serial number, as well as the date and time a document was printed

2

onion OP wrote (edited )

I have heard that the Thinkpad X200 is a good laptop for people who want to install libreboot and disable the Intel Management Engine.

This is another article about the IME. It lists libreboot compatible computers

Despite all Intel's efforts to make the Management Engine inescapable, software developers have had some success with preventing it from loading code. For instance, the Libreboot project disables the Management Engine by removing all the code that the Management Engine is supposed to load on some Thinkpad computers manufactured in 2008, including the R400, T400, T400s, T500, W500, X200, X200s, and X200T.

Also, many Intel computers manufactured in 2006 have the ancestor of the Management Engine which is disabled from the start, such as the Lenovo Thinkpads X60, X60s, X60 Tablet and T60, and many more.

https://www.fsf.org/blogs/sysadmin/the-management-engine-an-attack-on-computer-users-freedom

1

BlackWinnerYoshi wrote

Well, it has been previously blocked in Iran as well, so I think we can expect additional TLS proxies set up to avoid censorship. Or maybe you will be able to use existing TLS proxies, I don't know.

By the way, why did no one learn that centralized instant messaging apps can easily be blocked in this world of censorship? I really don't understand.

2

DcscZx5idox wrote (edited )

I recommend XMPP than Signal, especially for Chinese people. I think XMPP's main features are anyone can select from many servers and it have easy to use End-to-End Encryption implementation.

"Is Jabber accessible from China?" - reddit
libreddit. (webproxy frontend for reddit) URLs: clearnet, Tor

I'm in China and can access many XMPP servers, e.g. xmpp.jp, swissjabber.ch, chinwag.im, yax.im, disroot.org, member.fsf.org.

From what I understand about China's GFW, and I am American so no direct experience, it'll work at the beginning if you use TLS. Maybe not STARTTLS?

However, I do know that all VPNs will eventually stop working, forcing you to switch IP or protocol - the GFW has some basic machine learning. If all you do is connect to a specific IP, it'll start throttling connections to said address. It may do the same if it can't scrutinize the encrypted Jabber connection.

The bigger issue is that Jabber is still more complex to set up securely. That's probably why it doesn't have as much mindshare. Given that reputation, and the state of clients across platforms not all implementing the same features (not even equally well), it's harder to convince someone to deal with all of the headaches involved.

I actually had a plane get delayed in Shanghai, and I had no phone plan so the internet was my only option for communication back to the US. Couldn't use Facebook or Instagram. Forget Gmail, because even the Google homepage couldn't be accessed there. Hotmail said it delivered, but I found out the message didn't get received until about 3 weeks AFTER I arrived back in the US. Jabber was the only thing that DID actually work.

By comment on "Signal's open sourced server code hasn't been updated for over a year. Should we be concerned?"

Well, while open source does not mean it's secure, this is still a weird thing to do.

I would simply recommend to stop using Signal and start using XMPP with OMEMO encryption, since this is the gold standard of instant messengers, at least for me. You should especially stop using Signal because it requires your phone number, which immediately disqualifies it for a private messenger.

3