Recent comments in /f/Privacy
dontvisitmyintentions wrote (edited )
(generally speaking, facial recognition technology is notoriously less accurate for women and people of color)
Or maybe that just fits the narrative. White farmers don't get bailed out. Whites don't get the benefit of the doubt of fraud.
What is this South Africa? Not hardly.
mr4channer wrote
Reply to RockYou2021: largest password compilation of all time leaked online with 8.4 billion entries by Rambler
They just combined few password DB leaks and called it rockyou2021.
dontvisitmyintentions wrote (edited )
I've followed the kerfuffle from afar, reading the most popular articles and comments on the "LiberaChat" side. And one theme dominates these stories, like a poorly-written comic book (which is how all drama plays out on this side of the Current Year):
Rasengan pisses off the right people. Every bad decision he might have made makes me chuckle. This Korean dude might actually be based.
I can imagine good reasons for doing all the terrible things he does (like dropping a bespoke, byzantine ircd nobody else uses for something normal people can configure, an ircd which was even controversial a decade ago when there were more people hacking on ircds), but I don't need to. He angers the people who got so angry that they died their hairlogo trans colors and moved out of their parents' house so they could stay up late and put their dildos on a shelf. At least, I'm 41% sure that's what happened.
Edit: (two days later) It turns out they anonymize IPs now like Rizon and other mainstream networks do. Based.
vistingghost wrote
I don't want to lie about my UA but I have to change it in order to avoid Cloudflare's CAPTCHA. Cloudflare passes Tor Browser's UA for IP addresses of Tor exit nodes. Btw, Cloudflare distinguishes its users by TLS/SSL fingerprinting as well as by HTTP headers including UA. I must doubt that organizations encouraging TLS/SSL want fingerprinting more beyond security. Hey, Tor Project and EFF, don't be evil...
BlackWinnerYoshi wrote (edited )
Reply to comment by Wahaha in How Websites Know You're Lying About Your User-Agent by Rambler
Firefox usage fell by 1.02% from 2020-05 to 2021-05, so over the next three years, it should fall to about 0.3%, and I guess it's pretty much dead at this point, so it will merge with Chromium, I bet. Edit: I knew someone already said it.
Wahaha wrote
Reply to comment by BlackWinnerYoshi in How Websites Know You're Lying About Your User-Agent by Rambler
Calling it now, Firefox will move to Chrome's browser engine, too.
BlackWinnerYoshi wrote
Reply to comment by Wahaha in How Websites Know You're Lying About Your User-Agent by Rambler
But I usually can enable only some of the scripts. Besides, there are probably better ways of tracking someone, like cough the FLoCing FLoC. cough
But since I don't use Chromium browsers any more, they can't actually do that, and I doubt it's coming to Firefox, unless you count its inevitable death.
Wahaha wrote
Reply to comment by BlackWinnerYoshi in How Websites Know You're Lying About Your User-Agent by Rambler
Some sites only work by enabling scripts.
BlackWinnerYoshi wrote
Reply to comment by Wahaha in How Websites Know You're Lying About Your User-Agent by Rambler
I don't even change my user agent most of the time, so it just equals to what my browser is, but pretending to be Windows 10 while I actually have Windows 7, so it is Mozilla/5.0 (Windows NT 10.0; rv:91.0) Gecko/20100101 Firefox/91.0
currently (this is what LibreWolf does by default, btw).
So anyway, the only time the user agent differs from the defaults is when I want to enable a desktop version on mobile and when I want to bypass getting user agent blocked because I'm using Wget, so I usually just empty it (or set it to a browser user agent because it also gets blocked).
Also, since I block third party scripts with uMatrix by default, there's not much point to constantly changing the user agent because the trackers won't see it anyway.
DcscZx5idox wrote (edited )
The F-Droid (free software android app repository) team has decided to migrate from Freenode to OFTC.
https://f-droid.org/en/2021/06/10/important-community-update.html
Wahaha wrote
No single user-agent would protect your privacy anyway. What I do is to let my user-agent switch every ten minutes. Also, user-agent not only carries browser information, but also browser version and operating system.
Having scripts blocked per default also helps.
I don't mind websites knowing my user-agent is fake. I mind websites having the ability to track me based on my user-agent. Thus my user-agent changes automatically.
Wingless wrote
Reply to Firefox Hardening Guide | BlackGNU by benis
I don't understand AdNauseum. If it "clicks" on ads, isn't it allowing third parties to track your browsing all over the internet?
Wingless wrote (edited )
Reply to comment by Wahaha in RockYou2021: largest password compilation of all time leaked online with 8.4 billion entries by Rambler
I assume they add passwords to the next list...
The key thing for cracking passwords is, at some point it is way faster to search every password anybody has ever thought of, than to search every password anyone possibly could think of.
Yes, an honest site would just let you look up in the index starting with any string of letters, so you didn't have to give away your password in the process. Therefore, this is not an honest site. Q.E.D.
Faster proof: It's a site, from a company, on a computer. Therefore it is spying on you and selling your information. Q.E.D.
Wingless wrote
"Here, I'm going to give you this ID card to present everywhere you go in order to protect your privacy" -- and people believe them -- there really are no limits to stupidity!
Rambler OP wrote
Seems like the OG Freenode staff are working on https://libera.chat/ now.
liminal wrote
Reply to comment by BlackWinnerYoshi in 'Privacy Protecting' Car Location Data Seemingly Shows Where People Live, Work, and Go by Rambler
The fact that I prefer to use monero to move my funds doesn't imply that I wouldn't support laws mandating a more privacy-respecting way of making bank transfers. Even if I don't support companies marketing virtual assistants, I'm not immune to surveillance through Amazon devices.
Free market doesn't exist, the money always flow from the government, they get to decide who gets the bigger slice of the pie, and then cut a little space where people who don't know better can gamble their life away. Next time you are gonna tell me communism has nothing to do with the Soviet Union and maoist China, because that's not how it was supposed to work? These are ghosts from the past wich for some reason still haunt many people.
The state is evil, the market is evil, we must contain them both. When people will start to value real privacy, it will be too late. Right now Apple is plastering cities with commercials advertising the privacy granted by their phones, this is their main slogan: "privacy, that's iphone". After all these years, we are at this point, companies are selling the illusion of privacy, that's the kind of progress the market has brought us.
Who cares if people will start looking for real privacy, if when they'll do big companies will have already ammassed decades of data of any kind, do you think that won't be enough to control and debase billion of lives? It's not like they don't have enough already, they just need to get better at extracting value from it.
I said what would be the least we should expect, if you prefer to accept this state of affairs, until the masses won't start suddenly caring, I guess you are settling for even less than me.
BlackWinnerYoshi wrote
Reply to comment by liminal in 'Privacy Protecting' Car Location Data Seemingly Shows Where People Live, Work, and Go by Rambler
The only anonymous data is no data, but the government isn't going to help with that, so the only thing we can do is support companies that make the best products, like how the free market is supposed to work.
liminal wrote
Reply to comment by Wingless in 'Privacy Protecting' Car Location Data Seemingly Shows Where People Live, Work, and Go by Rambler
the guy who tapes you in the shower
So the carmakers? According to the article you agree to this kind of surveillance whenever you buy a modern cars, that's fucked up.
On another note, I think the least lawmakers should do is come up with a very strict definition of what constitutes "anonymized data", since that's another expressions that gets used to justify this kind of stuff.
Wingless wrote
Reply to 'Privacy Protecting' Car Location Data Seemingly Shows Where People Live, Work, and Go by Rambler
This is even worse than I expected. And the "solutions" are the classic BULLSHIT they feed us - "privacy" by means of not giving the data to people who don't pay money for it! ARE YOU KIDDING ME?
In order for a car to be driveable:
(a) It must have NO GODDAMNED TRANSPONDERS OF ANY KIND. (b) It must have NO SATELLITE LOCATION TRACKING CAPABILITIES. (c) It must have NO BUGS LISTENING TO YOUR CONVERSATIONS. And so on!
I added (c) because hell, there has to be an "anonymized" set of voice recordings for downloading from the same crooked auto manufacturers that set up this spy data sale!
Any company involved in PROVIDING the data resold by Otonomo needs to be named, shamed, boycotted, and obliterated. Maybe I can scrounge up an old Yugo instead, made in a free country. Otonomo isn't the problem, they're practically Chelsea Manning here. The problem is the guy who tapes you in the shower, not the one who shows you what he found on the online forum.
burnerben wrote
Reply to comment by BlackWinnerYoshi in Firefox Hardening Guide | BlackGNU by benis
this is fantastic info, copy paste this into a post and get Rambler to pin it on /f/privacy
Wahaha wrote
Reply to comment by BlackWinnerYoshi in RockYou2021: largest password compilation of all time leaked online with 8.4 billion entries by Rambler
Even if my online accounts got compromised, I don't think I would particularly care. What are they going to do, post mean things in my stead?
BlackWinnerYoshi wrote (edited )
Reply to Firefox Hardening Guide | BlackGNU by benis
This comment is probably the longest thing I wrote on [RAMBLE], maybe the longest from all users, but the TL;DR: use LibreWolf, since it has the tweaks recommended, and install some addons, especially uMatrix, WebRTC Control, LocalCDN. And others listed on the essentials privacy addons. Besides searX, you can use MetaGer and YaCy for search results from independent indexes. I really hope this summary is enough, since this entire thing is 8 000 characters long if you render it in plain text as UTF-8. Can you imagine it took me several hours to write this? Well, mostly because I was also distracted with other things, oh well, I guess enjoy the reading, or don't, just skip past it if you want
As burnerben said, you should use LibreWolf instead of hardening Firefox, especially since arkenfox' user.js doesn't disable all connections, which werwolf proves themselves by showing what you can tweak in about:config. Sure, LibreWolf enables autoupdating uBlock Origin lists by default and it relies on the evil Mozilla, but it's still the best Firefox fork if you really need one. Anyway, let's skip the entire profile nonsense and move to search engines.
They recommend searX, which I think is a good choice, especially after they released version 1.0.0 — but it does rely on Google and other search engines, which might bother some. It does, however, support searching with Mojeek and Wiby, which have fully independent indexes, although with weak results, so it's probably a good idea to enable those and whatever else you want. What about the other, less recommended options?
- MetaGer: not sure if I can count it as a metasearch engine, since, unlike searX, you don't get 70+ search engines, you only get four: Scopia (which is their index, and of course, it has weak results — but DuckDuckGo also has its own), Bing (like DuckDuckGo, but they also use yahoo*!*), and One News Page for both text and video (why are there two of them, especially since they're also in the News/Politics category?). That's just the Web category, of course, there's also Pictures (which exclusively uses Bing), Shopping (like how Pictures uses only one search engine, this one uses Kelkoo, which looks like it's useless), and News/Politics, but it's still nothing compared to searX. Also, I'm not sure if it's preferable over DuckDuckGo, since they: don't require JavaScreep, partially use their own indexes, have onion domains, store IP addresses, have somewhat good results, and don't share data with third parties.
- DuckDuckGo: if you don't trust DuckDuckGo, why do you list it? Actually, whatever, if you do want to use it, use the Lite version, as shown here.
- Qwant: is it actually private? Well, Qwant's privacy policy says that, besides the queries, it stores a “salted hash of the user’s IP address” and “the User Agent” for a week. Obviously, I remember that the only anonymous data is no data (yes, it is from DuckDuckGo, but you get my point), but it's still probably better than other search engines. Also, note the freetardist “non-free” notice because I don't know why would you want to say that otherwise, lol.
- Mojeek: I already mentioned it has an independent index, and it neither stores your IP address nor shares it with third parties. But again, there's that stupid “non-free” notice, even though it doesn't matter at all.
- YaCy: I think this one might be even better than Mojeek and Wiby combined, considering everyone can contribute, but I have no idea how do they compare.
Should you use any of those? Well, maybe MetaGer if you want its Scopia index and YaCy for P2P index, since the rest can be used with searX.
Now let's see their recommended addons:
- uBlock Origin: I think that uMatrix (which is mentioned, along with NoScript, but I don't recommend that because it's malicious and dishonest and it doesn't allow blocking other than global) is better because, by default, it relies on blocking entire classes instead of lists that need to be constantly updated. Also, it has well configured rules. Although, it only does basic content blocking, which might be an issue on sites like YouTube, where the scripts to load videos and ads are on the same site. So if you have to rely on them, it's probably a good idea to get uBlock Origin too, or Disconnect as an alternative.
- LocalCDN: like uMatrix, LocalCDN is an essential privacy addon, which supports more CDNs than Decentraleyes.
- Password manager choices: bitwarden looks like a pretty good choice, but the problem is that they have premium membership, which, if you don't have it, locks out options like TOTP, which aren't considered essential here, for some reason. Luckily, the community came to help and made vaultwarden, which doesn't have that. If you want an instance, LavaTech has one. But if you don't want to store passwords online, KeePassXC is probably a good option too, along with Syncthing if you have multiple devices. I don't recommend pass because it requires a terminal, which is ridiculous.
That's the essentials considered by them, but I think WebRTC Control should be there too, especially for those changing IP addresses, since WebRTC reveals your real one, even with Tor over VPN. Sure, the about:config tweaks do suggest disabling it, but those two settings might not be enough. What about other addons?
- Cookie AutoDelete: I think that first party isolation and disabling tracking cookies should be mostly enough, and you could be fingerprinted if you have many addons.
- ClearURLs: not only UTM tracks, but it's also annoying, so definitely get it. Although, I didn't notice any breakage from that addon back when I used it.
- Temporary Containers: this thing is just a fake initiative, and it's outclassed by uMatrix.
- ETag Stoppa: ETags are useless anyway, so get rid of them.
- CanvasBlocker: this one did break sites for me, but it's still useful if you need third party JavaScreep, which is what uMatrix blocks by default.
- xBrowserSync: like how you shouldn't sync passwords with Firefox Sync, you shouldn't sync your bookmarks with that too, so use this addon instead!
- AdNauseam: if you want to use sites like YouTube and tick off ad networks, use this along with uMatrix and hopefully, we'll destroy the cancer!
- Privacy Redirect: a better idea would be to use Redirector and set up regex rules for redirection, which makes it superior to that because you can add other sites too.
Also, I recommend checking the essentials privacy addons to see other useful addons.
Just to end this long comment, let me talk about the buttons below for a bit. FreeBSD is, well, probably better in website hosting because it has better security practises, unlike Linux. Discord is bad, and it's good they're promoting the Online Spyware Watchdog. No idea why they don't like the <blink> HTML element, I never used it. There's this “The Bible is an Anarchist Manifesto” thing that's controversial, apparently, and this comparison of Goolag Hrom and Internet Exploder is actually funny, and… oh no, the Vim editor (remember what I said about pass?). About Mastodon… why not just not use social media and connect to people directly instead? The last button is just promoting itself as a project “which tries to mimic the 80s multi users unix machines”. That's all.
BlackWinnerYoshi wrote
Reply to comment by Wahaha in RockYou2021: largest password compilation of all time leaked online with 8.4 billion entries by Rambler
To be honest, if you have an account on a just breached site and your data didn't got leaked, it's probably a good idea to change it anyway. I still use these kinds of tools, though, but mostly because I used to make accounts on lots of services, forget about them, then get reminded again by a breach, then I usually just download whatever data I had, if any, then remove the account and forget about services for however long. The shock when I found out I got my data leaked because of the Armor Games breach...
Wahaha wrote
Reply to RockYou2021: largest password compilation of all time leaked online with 8.4 billion entries by Rambler
users are recommended to immediately check if their passwords were included in the leak.
"We recommend you to add your password to the leak".
These tools have always been a head scratcher for me.
awdrifter wrote (edited )
Reply to TikTok Quietly Updated Privacy Policy to Collect Faceprints and Voiceprints by Rambler
Without the threat of being banned by Trump, the CCP owned DouYin will show their true intentions.