privacyguides

This magazine is from a federated server and may be incomplete. Browse more on the original instance.

const_void, in Brave is sunsetting strict fingerprint protection mode

Brave is trash. Just use Firefox.

Gooey0210,

Librewolf, librewolf to be precise

ExtremeDullard,
@ExtremeDullard@lemmy.sdf.org avatar

I would never use a browser provided by a company that dabbles in cryptocurrencies. Would you entrust your privacy to Sam Bankman-Fried?

madis,

The same approach would make sense in Firefox too though. And as far as I know, Firefox’s equivalent option is still about:config-only anyway.

amanneedsamaid, in Is there a good privacy respecting rss feed reader?

Read You on Android, and Newsboat on linux.

recreationalplacebos, in Is there a good privacy respecting rss feed reader?

On Android, I use Feeder and Nunti. Both are open source and available on f-droid.

merde,

feeder +1

Crewman,

+2

reddig33, (edited ) in Is there a good privacy respecting rss feed reader?

What platform? I find NetNewsWire to work well on iOS and MacOS. I haven’t heard anything privacy-invading about it. Its been around for years. It’s also open source and free on the app stores, so that means it’s been somewhat vetted.

taaz, in Securing Bluetooth Headphones

This is probably becuase the headphones have a bug that can be exploited - normally this should not be possible at all.

JBL does have an app (at least for my android), so I would recommend getting that and checking for any firmware upgrades.

Other then that there isn’t probably any easy way for you to prevent it (well except for the wired-only mode as you say - through lighting to jack and female jack to usb-c cables).

Melody,

You didn’t read the OP. Wired Is Not Possible

Furthermore I own a similar model, the 550BTs. The “Tune” line does not support USB Audio at the 5xx range of models

Additionally you must not chain adaptors as it will sound terrible and you will get the lowest quality output.

My 550BTs have included a 2.5mm -> 3.5mm jack cable and it has a 2.5mm Jack on it for wired audio output. An official Apple Lightning to 3.5mm jack dongle will work but the OP would rather not use cables…Therefore a Bluetooth model is probably needed.

I strongly recommend the 550BTs, and the 660NCs as well

smeg, in Android and iOS settings for better security and privacy

Looks like a good “best practices” sort of list. Would be nice if there was a bit more explanation as to why some of them are recommended (just because it’s good to understand why you’re disabling something rather than blindly following a guide), but still good!

awwwyissss,

Agreed. Disable 2G? Why? That might cost me connectivity in some places and I won’t remember to turn it back on.

smeg,

To add to that other (much more in-depth) comment, I remember reading on the GrapheneOS FAQs that disabling everything you’re not actively using will generally improve security as you’re reducing the number of potential ways for an attacker to get in (phrases like “attack vectors” and “surface area” were used).

On a separate note I didn’t even know 2G towers were still active anywhere; they’re shutting down the 3G ones here!

ForgottenFlux,

I’m not the writer of the article, but here’s an answer you can find on running a quick search.

According to this article from the Electronic Frontier Foundation (EFF):

What is 2G and why is it vulnerable?

2G is the second generation of mobile communications, created in 1991. It’s an old technology that at the time did not consider certain risk scenarios to protect its users. As years have gone, many vulnerabilities have been discovered in 2G and it’s companion SS7.

The primary problem with 2G stems from two facts. First, it uses weak encryption between the tower and device that can be cracked in real time by an attacker to intercept calls or text messages. In fact, the attacker can do this passively without ever transmitting a single packet. The second problem with 2G is that there is no authentication of the tower to the phone, which means that anyone can seamlessly impersonate a real 2G tower and your phone will never be the wiser.

Cell-site simulators sometimes work this way. They can exploit security flaws in 2G in order to intercept your communications. Even though many of the security flaws in 2G have been fixed in 4G, more advanced cell-site simulators can take advantage of remaining flaws to downgrade your connection to 2G, making your phone susceptible to the above attacks. This makes every user vulnerable—from journalists and activists to medical professionals, government officials, and law enforcement.

awwwyissss,

I appreciate that, thanks 🙏🏻 now I’m considering disabling 2G.

taladar, in Common misconceptions about privacy and security

Similarly, proprietary software can be secure despite being closed-source.

That depends entirely on your threat model and the kind of relationship you have with the software vendor. Software might be proprietary and closed source but e.g. you might be the only customer and did get to engage an auditor which could see the source code. Or it might be off-the-shelf software made in a country trying to spy on your company or country. In some of those cases it literally can not be secure for your threat model.

LWD, (edited ) in Common misconceptions about privacy and security

deleted_by_author

  • Loading...
  • j4k3,
    @j4k3@lemmy.world avatar

    Plus, not many are willing to compile or even try/have the skill to read in to the code. Even with something like Vanadium on GrapheneOS I’ve encountered eyebrow raising behaviors I do not like.

    degen,

    I’m curious since I’m using graphene. What have you encountered?

    j4k3,
    @j4k3@lemmy.world avatar

    Minor stuff. It leaves a tab open in vanadium after charging, there is no option to wipe all cache data automatically after exiting, there is not much granularity in what data is stored in cache or persistent storage, and there is no way to view the web source code easily.

    frefi, in In case you missed it: Fossify (A fork of Simple Mobile Tools)
    @frefi@lemmy.dbzer0.com avatar

    Wow, I did not know that happened to Simple Mobile Tools… Thank you for the heads up

    TheSkullFaceAce, in In case you missed it: Fossify (A fork of Simple Mobile Tools)
    @TheSkullFaceAce@lemmy.world avatar

    I love being able to just export my settings from the Simple Mobile Tools apps into the new Fossify apps. Makes the transition very simple

    Still waiting on Draw, Notes, SMS, and Voice Recorder to be released by Fossify

    original_reader, (edited ) in Proton Mail says that the new Outlook app for Windows is Microsoft's new data collection service

    Kinda OT, but writing about privacy and then presenting an abysmal way to opt out of 160+ trackers is pure, hypocritical, rich irony.

    Yes, I’m talking to you, ghacks.net.

    perviouslyiner,

    Especially when it’s not even the original article

    proton.me/…/outlook-is-microsofts-new-data-collec…

    Poutinetown, in Proton Mail says that the new Outlook app for Windows is Microsoft's new data collection service

    Any outlook alternative that doesn’t look pre-dotcom? I really liked the Microsoft Mail app for its simplicity and the ability to have multiple inboxes, it’s a shame it is being replaced by outlook.

    iturnedintoanewt,

    Evolution?

    ulkesh,
    @ulkesh@beehaw.org avatar

    Spark, Mailbird, eM Client, Mailspring.

    Most of the modern ones do store certain information on servers, though. Spark and Mailbird both do. Mailspring does as well if I recall correctly.

    Most modern mail app developers seem to think that it’s more important to do search indexing and account storage on a server for ease of use, and expect inherent trust, foregoing all sense of real privacy under the veil of “we’re not evil, we promise.”

    I’ve yet to find an email client that has a good modern look and feel, but doesn’t try to use server-side storage for some UX convenience factor.

    I want the look and feel and mail host integrations of Spark (OAuth, like GMail, or preconfigs of hosts like iCloud) with the dumb-pipe-ness of Thunderbird. That’s the email unicorn I’m after.

    MangoPenguin, in Proton Mail says that the new Outlook app for Windows is Microsoft's new data collection service
    @MangoPenguin@lemmy.blahaj.zone avatar

    It also sends your IMAP credentials to their servers and receives the mail there, it’s not done locally like the older versions.

    wreckedcarzz,
    @wreckedcarzz@lemmy.world avatar

    Fuuuuuck that~

    LWD, (edited )

    deleted_by_author

  • Loading...
  • hemko,

    The twisted reasoning is probably so that the users can access the emails anywhere with their live account (and so that MS can scrape those mails for all sorts of creepy shit)

    MangoPenguin,
    @MangoPenguin@lemmy.blahaj.zone avatar

    Just to do it, IMAP already covers using multiple devices on an email account.

    garrett,
    @garrett@infosec.pub avatar

    This is the worst part to me. All this just to “cloud sync” or something silly.

    petrescatraian,

    @MangoPenguin yet their free tier for their cloud services is still lacking...

    @Blaze

    Oha, in Proton Mail says that the new Outlook app for Windows is Microsoft's new data collection service

    It’s a microsoft product, What the fuck do you expect?

    Asudox, in Proton Mail says that the new Outlook app for Windows is Microsoft's new data collection service
    @Asudox@lemmy.world avatar

    no shit sherlock

  • All
  • Subscribed
  • Moderated
  • Favorites
  • privacyguides@lemmy.one
  • localhost
  • All magazines
  • Loading…
    Loading the web debug toolbar…
    Attempt #