If you don’t know me, I make frequent write ups about privacy and security. I’ve covered some controversial topics in the past, such as whether or not Chromium is more secure than Firefox. Well, I will try my hand again at taking a look at some controversial topics.

I need ideas, though. So far, I would like to cover the controversy about Brave, controversy around Monero and other cryptocurrencies, and controversy around AI. These will be far easier to research and manage than Chromium vs. Firefox, for example. I’d like to know which ideas you have!

Which controversial privacy topics do you know of that you would like to see covered?

PLEASE DO NOT ARGUE ABOUT THEM IN THE COMMENTS!

Please save any debate for if/when I make a write up about the topic. Keep the comments clean, and simply upvote ideas you would like to see covered. I won’t be able to cover everything, so it helps bring attention!

Above all else, be kind, even if you don’t agree with an idea or topic :)

  • stellargmite@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    1 month ago

    A global look at Short form video as the latest trend in mass misinformation campaigns, including which interest groups, or states conduct them and who they contract (from large scale to possibly unwitting small creators) to produce and post it. How it developed from prior trends, and where it might go next. Perhaps not particularly controversial (in the true sense of the word), but geopolitically worth looking at and discussing more in imo. Of course a privacy and security focus on this is very much integral to the issue by default. How the existing business models around the data involved (harvesting , auctioning etc) might play into this already , and in the years to come. As well as how other business is implicated. Good old “Follow the money” I guess .

  • refalo@programming.dev
    link
    fedilink
    arrow-up
    0
    ·
    edit-2
    1 month ago

    F-Droid not being trusted. They build and sign a developer’s code on their behalf, so there is a chance for injection there.

    There are reproducible builds, but I would argue it’s not taken seriously enough. Like right now nobody is publicly verifying Signal’s supposed reproducible Android builds and they’ve historically had problems keeping it working.

    Also how most (or all?) Play Store apps (including FOSS) contain proprietary code.

    • sntx@lemm.ee
      link
      fedilink
      arrow-up
      0
      ·
      1 month ago

      83 Posts, 1626 Comments of completely unliked 0-bit information posts without metadata like time of post.

        • juliebean@lemm.ee
          link
          fedilink
          arrow-up
          0
          ·
          1 month ago

          that is generous of you. i’m on the same instance as them, and can find no discrepency between viewing your profile through lemm.ee vs on programming.dev

          alas, i think they’re just attacking their percieved quality of your posting, and it is not that they’re missing all of the good stuff.

  • bruhSoulz@lemmy.ml
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 month ago

    Its not private if it needs a phone number (cough SIGNAL cough)

    “Its to protect the kids”, “Its to fight terrorism”

    That one filthy muslim country banning VPN’s with the guise of it being impermissible (“haram”)

    • Zagorath@aussie.zone
      link
      fedilink
      arrow-up
      0
      ·
      1 month ago

      I don’t even care about the privacy aspect per se. Phone number as user ID is a crappy UX that fundamentally does not work when international travel, multiple devices, or needing to get a number changed. It also doesn’t work for shared accounts or people who might want multiple identities.

      Some of these relate to privacy, secondarily, but my primary concern is the UX.

  • OneMeaningManyNames@lemmy.ml
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 month ago
    1. Whether phones are listening or not

    2. What is the redacted part in the rationale to ban Tik Tok

    A note on the latter, it is presented as national security threat. They won’t say what it is. I presume because some of the shit they don’t want a foreign power doing is sth they very much do themselves.

      • OneMeaningManyNames@lemmy.ml
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 month ago

        See, I am not the guy who will stop thinking for myself because experts say there is no evidence of sth. I am not saying that there is real time eavesdropping at all times, but I have not seen convincing arguments that a working microphone cannot be used for pushing ads by simple and widely available mechanisms. In fact, the sheer amount of people who complain about this should be considered evidence in itself, especially when they never had thought of a given topic before discussing it with someone. I have considered phone proximity and shared IP address but they don’t seem to make an exhaustive explanation. I think that some stories point to Meta doing this extensively, and that disallowing microphone access for Meta products alleviates the effect. Many privacy communities I believe they are infested by spooks and trolls pushing disinformation narratives, and one of them is that phones are NOT listening as a smart thing to say and/or believe. I might as well think that this is itself can be related to the redacted part in the rationale to ban Tik Tok. Having said that, I think that the only feasible to do this technically is by a regularly updated list of keywords, rather than other ways that would leave a processing or networking footprint.

  • SpicyAnt@mander.xyz
    link
    fedilink
    arrow-up
    0
    ·
    1 month ago

    Step 1 of installing GrapheneOS for de-googling your life: Buy a Google Pixel phone

    Look - I know, I know. I get it. Google allows you to unlock the bootloader while maintaining the phone’s unique and excellent hardware security features. The argument makes sense. It is compelling. Other manufacturers do not give you this freedom. I am not arguing about that. I have a Pixel phone running GrapheneOS myself.

    However… It is just so very obviously ironic that one needs to trust Google’s hardware and purchase a Google product to de-google their life through GrapheneOS. I think that it is a perfectly valid position for someone to raise their eyebrows, laugh, and remain skeptical of the concept either because they do not want to support Google at all, or because they simply will not trust Google’s hardware.

    The reason why I think that this is “controversial” is because I have seen multiple instances of someone pointing out the irony, followed by someone getting defensive about it and making use of the technical security arguments in an attempt to patch up the irony.

    • bruhSoulz@lemmy.ml
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      This is entirely valid as a concern. In my matrix GC someone just said pixel and oneplus are best for modding and I was like… The whole point of me trying to degoogle is to contribute less to their economy, why would I buy their bs hardware😭☠️

    • N0x0n@lemmy.ml
      link
      fedilink
      arrow-up
      0
      ·
      1 month ago

      Yeah… An probably all big players have somehow backdoored their phone :/.

    • j4p@lemm.ee
      link
      fedilink
      arrow-up
      0
      ·
      1 month ago

      Bought a second hand Pixel 7 in like new condition at the time for $250 on back market (dropped it, bought another, still cheaper than the equivalent iPhone 14 lol). That at least means I am not financially contributing to Google, but I do agree that I don’t think there is a way to verify that the hardware is completely foolproof even if its the best option we currently have.

      I guess that’s true of any hardware though, and we have to make our assumptions based off known quantities such as Pixels’ unique hardware security features?

      But yeah, it’s a minefield out there. Let’s get carrier pigeons.

    • EngineerGaming@feddit.nl
      link
      fedilink
      arrow-up
      0
      ·
      1 month ago

      My issue with that is that Pixels are expensive, and in some places are not sold officially (meaning they can only be bought from smaller resellers with usually much less generous return policies). The newest models are outright unaffordable new. The only ones below $150 are either secondhand or out of support, so that’s what poor people are left with? Plus, no headphone jack.

      I use Graphene myself, but I dislike absolutism. I don’t in the slightest regret buying my Pixel even though $300 is a painful sum to spend on a phone (and it was on the cheaper end if we’re talking about up-to-date models!), but I know that my mother would never spend this much on a phone - so I look into Divest or Lineage on more common and affordable phones.

      • EngineerGaming@feddit.nl
        link
        fedilink
        arrow-up
        0
        ·
        1 month ago

        Yeah, there is a whole “separate OS”, but, to my knowledge, there hasn’t been evidence of it casually being able to collect arbitrary data from the actual phone’s OS.

        • interdimensionalmeme@lemmy.ml
          link
          fedilink
          arrow-up
          0
          ·
          1 month ago

          It has been made impossible to personally audit, the safe assumption, the null hypothesis is that it does until proven otherwise, which would be impossible and in any case implausible under our current surveillance capitalism.

  • toastal@lemmy.ml
    link
    fedilink
    arrow-up
    0
    ·
    1 month ago

    Matrix is defacto centralized around Matrix.org & servers they provide (where the cost of hosting makes it largely inaccessible to low-spec & medium-sized servers causing them to inevitably shut down & recommending users back to Matrix.org). All the metadata gets synced back to the mothership that was funded by Israeli intelligence. Avoid it.

    Cloudflare is a CIA front. They offer “free” DDoS protection + static proxy thereby giving Cloudflare the ability to MitM all TLS connections thru their servers. They convinced so many ‘developers’ via ‘influencers’ that every tiny site needs Cloudflare in front of it as a precaution/optimization, but it is an entirely premature optimization that doesn’t need to so widely deployed, but it is. 🤔

    Microsoft has always been an enemy but somehow managed to Trojan horse their way into the minds of developers again trying to centralize how software is created. Like we avoid Microsoft Windows, the rest of the Microsoft ecosystem should equally be avoided: Copilot, LinkedIn, Outlook, Exchange, Office, Teams, Azure, VSCode, npm, GitHub (Sponsors, Codespaces, Copilot). Literally none of these projects/services can’t be replaced to help protect the privacy of your clients, coworkers, contributors.

    • Chulk@lemmy.ml
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      Cloudflare is a CIA front. They offer “free” DDoS protection + static proxy thereby giving Cloudflare the ability to MitM all TLS connections thru their servers.

      I just started to learn about privacy in depth this year, and this little fact about Cloudflare has sat with me more than most things that I’ve learned. I feel like very few people think about the implications of Cloudflare’s practices. Even if its not a CIA front (I feel like it is), we should feel uncomfortable giving any private entity such power. Unrelated, but their crazy lava-lamp wall, as cool as it is, kinda gives me bad vibes lol.

      • chappedafloat@lemmy.wtf
        link
        fedilink
        English
        arrow-up
        0
        ·
        26 days ago

        I learned about Cloudflare mitm quickly because when you use Tor browser you will see how many websites use cloudflare because you can’t access all those sites. So I did a little research about this problem about cloudflare and found out how serious and huge problem it is.

  • Zagorath@aussie.zone
    link
    fedilink
    arrow-up
    0
    ·
    1 month ago

    There is no expectation of privacy in public.

    By which I mean that things like blurring a house from Street View are unreasonable.

    • shaserlark@sh.itjust.works
      link
      fedilink
      arrow-up
      0
      ·
      1 month ago

      Oh boi I’m trying to get people to use simplex exactly because of this. I managed to bring most people to Signal and they’re cool with it because it just works, but I don’t trust them at all. Sure there was this court order where they didn’t have any user data except account created date and last active date, but since almost everybody uses either Google‘s or Apple‘s push notification servers turns out that doesn’t matter so much from what I undertstood.

      • ᗪᗩᗰᑎ@lemmy.ml
        link
        fedilink
        arrow-up
        0
        ·
        1 month ago

        Google‘s or Apple‘s push notification servers turns out that doesn’t matter so much from what I undertstood.

        Can you elaborate? It’s my understanding that push notifications are only used to trigger Signal to check if there are messages - the message data and who/what triggered it is not being sent to Google/Apple. If you don’t trust push notifications, you can always use a De-google’d phone and the Signal APK which will fallback to polling the server; this will obviously impact battery life as the app needs to constantly be checking for new messages.

      • refalo@programming.dev
        link
        fedilink
        arrow-up
        0
        ·
        1 month ago

        You can use your own builds of Signal (or preferably Molly-FOSS) including a self-hosted server. You can bring your own push notification as well.

  • m_f@midwest.social
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 month ago

    Browsing with JS disabled by default and expecting most sites to have basic functionality like “display this text”

  • undefined@lemmy.hogru.ch
    link
    fedilink
    arrow-up
    0
    ·
    1 month ago

    Browser extensions aren’t the answer to preventing tracking (as apps and other processes outside the browser aren’t blocked)

      • undefined@lemmy.hogru.ch
        link
        fedilink
        arrow-up
        0
        ·
        edit-2
        1 month ago

        I use primarily DNS blocking myself, but it’s a custom solution that pulls in a ton of blocklists. I get tired of the “just use a browser extension” as the solution for everything, and any time I bring up IP/DNS-based solutions people say “but that doesn’t block everything” as if browser extensions do.

        • Zerush@lemmy.ml
          link
          fedilink
          arrow-up
          0
          ·
          1 month ago

          The biggest scam is with Browser VPN, they are simply proxies, good to watch country restricted movies but not for more. They don’t protect privacy, because they only can create the tunnel, after the browser is already connected to your ISP server. Bad in countries with dictatorship or teocracies with controlled servers, there only steganographic methods can help in comunications (Hidden messages in Photos, music, or even innocent text files)

          But normally 100% privacy isn’t possible, almost every actuation online can be tracked. You can only avoid the worst with your shitty PC against the server and AI power of big companies, goverments and secret services with their hacker squads. Tey can spy other goverments, they are swallowing this little geeks with their laptop and VPN in a breaktime if needed (China even employ savants (isle gifted autistic people) as hackers in their secret services)

          • undefined@lemmy.hogru.ch
            link
            fedilink
            arrow-up
            0
            ·
            1 month ago

            Hard agree, except I do have an issue with the last paragraph in that I think it’s far dumber than you’ve described.

            Simply blocking (a shit ton of) domains can really get you 99% of the way there. I’m a web developer and it’s stupid dumb how third-party stuff is hosted. It’s either exactly that (third party hosted) or a CNAME or a third party which is easily blocked.

            Look, I know how complex tracking and fingerprinting can be. But from my experience, it’s really not hard to block. Of course, I’m not really speaking to first party tracking where blocking would destroy the entire experience. But for the most part, you can prevent a profile being built about you (at least for tracking and advertising) by blocking with DNS.

            • chappedafloat@lemmy.wtf
              link
              fedilink
              English
              arrow-up
              0
              ·
              26 days ago

              Problem is first party tracking. Blocking is just against third parties. For first party tracking you are just going to have to use tor browser.

    • bruhSoulz@lemmy.ml
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      need a convenient solution to force traffic thru tor, doesnt tails have that? why isnt it commonplace tool?

    • acockworkorange@mander.xyz
      link
      fedilink
      arrow-up
      0
      ·
      1 month ago

      Others take issue with the idea that technology might be allowed to trump legal process. In a 2015 California Law Review article arguing that forced decryption is necessary to balance individual rights and government power, Dan Terzian, presently an associate at Duane Morris LLP, argues that the EFF’s view is too expansive.

      “Scores of companies now encrypt their data,” Terzian wrote. “In the EFF’s alternate universe, these companies are effectively immune from discovery and subpoenas.”

      Only if you consider corporations persons. They’re not.

      Excellent suggestion, btw.

  • gibson@sopuli.xyz
    link
    fedilink
    arrow-up
    0
    ·
    1 month ago

    Private gun ownership e.g. via home manufacture (not illegal contrary to popular belief) or p2p sale. Also mandated gun registries.

      • gibson@sopuli.xyz
        link
        fedilink
        arrow-up
        0
        ·
        edit-2
        1 month ago

        The post talks about software but does not specifically say online privacy. I think you’re right but I also think if I had asked about defeating facial recognition cameras I wouldn’t have been disregarded.

  • tehn00bi@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    1 month ago

    What about the issue of, the more accessible private browsing and messaging has become, the harder it has become to track down child porn producers.

    • interdimensionalmeme@lemmy.ml
      link
      fedilink
      arrow-up
      0
      ·
      1 month ago

      It is a non issue, a fabulation of a pretext to strip away all your rights. Just look at all the gross politics wonks slinging pedophile accusations at each other all the time. How could anyone even believe this was anything other than the latest tool of character assassination after homo, commie and anarchistshave worn out their usefullness. Anyone going around yelling pediphile this pedophile that, recognize them for the troll that they are and tune them out, they have absolutely nothing valid to say.